Other Flashcards
Payload
the information to be covertly communicated. In other words, the message you want to hide.
Carrier
The signal, stream, or file in which a payload is hidden
Channel
The type of medium used. This may be a passive channel, such as photos, video, sound files.
Steganalysis
the process of analyzing a file or files for hidden content. FTK and Encase both check for steganography.
Cryptographic Hashes
How many systems, including Microsoft Windows, store passwords. “password” > 8BS09394820IKSKDF909DF99230 then it is stored in the SAM (Security Accounts Manager) file in the Windows System directory.
Rainbow Tables
Every letter combination “under the rainbow” files used to crack hashes. OPHCRACK took depends on rainbow tables. Ophcrack is very successful at cracking windows local machine passwords.
Security log
the most important log from a forensics point of view. It has both successful and unsuccessful login events
Application log
contains various events logged by applications or programs. Many applications record their errors here.
System log
contains events logged by Windows system components. This includes events like driver failures.
Registry
contains information that Windows continually references during operation, such as profiles for each use, the applications installed on the computer and the types of documents that each can create.
Registry Hive
HKEY_LOCAL_MACHINE\SAM Sam, Sam.log, Sam.sav
HKEY_LOCAL_MACHINE_\Security Security, Security.log, Security.sav
HKEY_LOCAL_MACHINE\Software Software, Software.log, Software.sav
HKEY_LOCAL_MACHINE\System System, System.alt, System.log, System.sav
HKEY_CURRENT_CONFIG System System.alt, System.log, System.sav, Ntuser.dat,
Ntuser.dat.log
Mac OS command prompt
BASH shell so you can execute Linux commands.
HFS+
preferred file system for quite some time for Mac OS, one you will likely encounter when doing forensic examinations of Apple computers.
APFS Apple File System
created for MacOS 10.13 and later versions. Larger storage than HFS+
GUID Partition Table
is used primarily with computers that have an Intel-based processor. Requires OS X v10.4 or later