Forensics Flashcards

1
Q

Program Execution Artifacts (7)

A

UserAssist, Shimcache, Windows 10 Timeline, RecentApps, Jump Lists, System Resource Usage Monitor, Prefetch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Deleted File/File Knowledge Artifacts (4)

A

Thumbscache, IE/Edge file, Word Wheel Query, Recycle Bin

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Network Activity Artifacts (4)

A

Cookies, Network History, Browser Search Terms, System Resource Usage Monitor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

File/Folder Opening Artifacts (6)

A

Recent Files, Shell Bags, LNK Files, IE/Edge file, Jump Lists, Prefetch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Account Usage Artifacts (2)

A

Event Logs, RDP Usage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

External Device/USB Artifacts (2)

A

Volume Serial Number, Shortcut (LNK) Files

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Browser Usage Artifacts (5)

A

History, Cookies, Flash and Super Cookies, Session Restore, Google Analytics Cookies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

File Download Artifacts (4)

A

Email Attachments, Browser Artifacts, Downloads, ADS Zone.Identifier

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

UserAssist

A

Tracks GUI based programs launched from Desktop

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Windows 10 Timeline

A

Tracks recently used applications and files. Accessible via Win+tab.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Recent Apps

A

Tracks GUI Program execution launched on Win10.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Shimcache

A

Tracks Windows application compatability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

System Resource Usage Manager

A

Records histroical system performance. Applications run + user account, bytes sent per application per hour

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Prefetch

A

Increases performance of a system by pre-loading code of commonly used applications.

C:\Windows\Prefetch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Thumbscache

A

Database of thumbnails of pictures, documents, folders, etc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

IE/Edge History

A

IE/Edge also tracks file access

17
Q

Word Wheel Query

A

Key words searched for on the start bar of WIn 7.

18
Q

ADS Zone Identifier

A

ADS added to files that are downloaded from the internet.

19
Q

Shell Bags

A

Tracks folder access

In USRCLASS.DAT

20
Q

Shortcut (LNK) files

A

Automatically generated when opening files.

21
Q

Flash/Super Cookies

A

Cookies that are more persistant. Almost never cleared and have no expiration date.

22
Q

Mac Cooties

A

Files containing Apple Extended Metadata (AEM is put into ADS on system architectures that support ADS such as NTFS)

23
Q

Windows Registry Hives and locations

A

HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS

24
Q

HKEY_LOCAL_MACHINE Contents and location

A
Windows\system32\config\
HKEY_LOCAL_MACHINE\SYSTEM:
HKEY_LOCAL_MACHINE\SAM:
HKEY_LOCAL_MACHINE\SECURITY:
HKEY_LOCAL_MACHINE\SOFTWARE: