Section 4.2: Timeline Analysis Overview Flashcards

1
Q

What is the forensic trinity inside a system?

A

Filesystem metadata, registry keys, and Windows artifacts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

For locations in timeline analysis to search for file downloads.

A

Open/Save MRU, emails, skype history, index.dat, & download sqlite.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Locations in timeline analysis to search program execution.

A

UserAssist, LastedVisited MRU, Run MRU, MUI Cache, Jumplists, prefetch, & shimcache.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Open/Save MRU and where can it be found?

A

This key tracks files that have been opened or saved within Windows shell dialog box. Location: NTUSER.DAT\Software\Microsofot\Current Version\ Explorer\ComDlg32\OpenSavePID1MRU

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the path for email attachments?

A

USER\AppData\Local\Microsoft\Outlook

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

To gather downloads.sqlite information for downloaded files for each browser, what similar paths do different browsers have?

A

Search in “AppData\Roaming” for any browser and dig till you find history sections.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are jump lists?

A

Jump lists is a task bar engineered to allow users to “jump” or access items they frequently or recently used quickly and easily. They are labeled by AppID.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the jump list path?

A

C:\Users\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is RunMRU Start-> Run? What is the path?

A

Whenever a user runs the Run command, it is recorded along with the user who did it. Path: NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the UserAssist? What is the path?

A

GUI-based programs launched from the desktop are tracked by the launcher. Path: NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are shellbags?

A

They track user window preferences to Explorer. It also tracks activity in a folder and files.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Path to find shellbags

A

NTUSER.DAT (USRCLASS.DAT)(Local Settings)\Software\Microsoft\Windows\Shell\Bags(BagsMRU)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Where is the NTUSER.DAT information when looking inside registry editor?

A

You gotta click the HKEY_USERS tab. Thats NTUSER.DAT.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are Office Recent Files? What is the path?

A

MS Office programs will track and built a recent files list to see the last file edited. Location: NTUSER.DAT\Software\Microsoft\Office\VERSION

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are LNK files? Where are they located?

A

They are shortcut files created by opening recent local or remote data files and documents. Location: \AppData\Roaming\Microsoft\Office\Recent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the WordWheelQuery and where is it located?

A

It logs keywords searched for from the Start menu bar. Location: NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery

17
Q

To search for Browser Search Terms and cookies, what is the common path to find them?

A

\AppData(Local)\Roaming\Microsoft\Windows\History(Cookies)

18
Q

Why is tracking USB usage important? What is the path?

A

I can find the time it was plugged in as well as the brand. The path: SYSTEM\CurrentControlSet\Enum\USB

19
Q

What does log ID 20001 identify inside the System log?

A

That a plug & play driver was installed. That can be a USB, Firewire, or any PCMCIA devices

20
Q

How do I do begin to look inside a timeline?

A

Use your scope and case knowledge to help form the answer (pivot point).

21
Q

What is Temporal Proximity? Why is it important to use this method?

A

Its searching for occurrences that happened before and after pivot points. Single artifacts MUST connect to other artifacts.

22
Q

What is the Pivot Point pyramid from highest to lowest.

A

Time of Incident, Network Activity, Process Activity, Name of File, User Account, & Activity.

23
Q

What is the timeline analysis process list?

A

Determine the timeline scope, narrow pivot points, determine timeline type, filter timeline, analyze timeline.