How to do your own forensic investigation (4/4)

By neptune1212 April 26, 2024, 12:58 p.m.

Disconnect your VM from the network.

Picture

Locate your Logs folder.

Picture

All the tools will be downloadable from Eric Zimmerman's Tools website.

Picture

Parse the .evtx logs.

Picture

Locate your SRUDB.dat.

Picture

Parse them.

Picture

Locate your Prefetch.

Picture

Parse the Prefetch.

Picture

Get the ADS stream from the malware zip folder.

Picture

And finally parse the MFT. Now, have fun to understand how you have been powned ;) You can find a write-up here: https://github.com/wocsa/WOCSA_Ethical_Hacking_Workshop/blob/main/Forensic/Windows/Infostealer/writeup/writeup.md

Picture

Comments

Conversation

0

Please log in to add comments.