Windows Forensics, part 2 Flashcards

1
Q

What hives do you find in the Registry? (5)

A
  • SAM
  • SYSTEM
  • SECURITY
  • SOFTWARE
  • NTUSER.DAT
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What do you find in the SAM hive?

A

User info “database”
F value = timestamps
V= user name, RID

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What do you find in the SECURITY hive?

A

security policy settings, contains system SID (security ID)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What do you find in the SYSTEM hive?

A

Vast amount of system info and config info

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What do you find in the SOFTWARE hive?

A

software/OS config. and info.
example:
Allow X to be run or not, disable functionality Y in X..

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What do you find in the NTUSER.dat ?

A

File created upon user creation, timestamps and preferences

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Where is the registry located in windows?

A

C:\Windows\System32\config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What hives to you find in the Event Logs? (3 + 2)

A
  • System
  • Application
  • Security
  • Setup
  • Forwarded events
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What information can you find in the Event Logs?

A
  • Date and time for events
  • User account responsible for event
  • Computer responsible for event
  • usernames, computer names, IP addresses and applications related to the event
  • Event ID
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What do you find under Local files? (8)

A
  • Linked files
  • Prefetched files
  • Printer files
  • Thumbnail.db
  • Recycle bin
  • Pagefile.sys
  • Hiberfile.sys
  • Installed programs
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a Linked file?

A

simply shortcuts with .LNK extension which points to another file or folder.
Link file has timestamps like create date, modified date and last accessed date.
They may also contain user ID and path to target

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are prefetched files?

A

Files that contail .exe + DLL information of a program, speeds up the process. It has a maximum of 128 files, when reached it automatically deleted the 96 least used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Explain Installed files

A

Installed files on a computer might reveal info about programs that has been running on the computer in question.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

That is the thumbnail cache /thumbnails.db?

A

Automatically created in folder when user chooses to view in thumbnail view. It retains thumbnails of deleted files, beneficial for an examiner!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What do you find in printer files?

A

Windows sends data to printer in RAW or Enhanced metafile formats, both formats result in creation of 2 complementary files if system is set to spool print jobs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What can you find in the Recyle Bin?

A

deleted files are not really deleted, but moved to the recycle bin. When moved the file is renamed with a prefix D for deleted, followed by original drive location, incremented number and original file extension.
example: Dc3.txt

17
Q

What is Pagefiles?

A

Pagefile.sys keeps the data swapped out of RAM (Random Access Memory)
You might find passwords, email addresses and IP addresses

18
Q

What is Hibernation files?

A

Similar to Pagefile.sys, as an active swap space hiberfil.sys is a repository for contents of RAM when a system i hibernated.

19
Q

What can you find out from Restore Points?

A
  • reveal connection to a specific domain
  • examine the data contained in registry hives backed up in past RPs to find domain information
  • Help in making time line of the connection to the specified domain
20
Q

What is a shadow copy?

A

a technology that can create a backup or snapshot of a system, files or folders even when they are in use