26
Real Forensics The hard way

Real Forensics

Embed Size (px)

DESCRIPTION

Real Forensics. The hard way. Data Recovery. What data/evidence can you retrieve from a hard drive. Usually dd is good enough Sometimes real help is needed. Real Help. Hard Drive recovered from Columbia Shuttle accident February 1, 2003 400 Mbyte - PowerPoint PPT Presentation

Citation preview

Real Forensics

The hard way

Data Recovery

• What data/evidence can you retrieve from a hard drive.

• Usually dd is good enough

• Sometimes real help is needed

Real Help

• Hard Drive recovered from Columbia Shuttle accident

• February 1, 2003

• 400 Mbyte http://www.sciam.com/article.cfm?id=hard-drive-recovered-from-columbia

• 99% of the data was recovered from a Xenon shear thinning experiment

Hard Drive Mounted on Plate

HDD Internals

Ontrack Data Recovery

• Probably:– Remove the platters and cleaned them.

– Rebuilt the Spindle assembly

– Mounted in a new case

– Exercised in a clean room

Hard Drive Architecture

HDD Capacity

10,000

`2015

MRU Lists

Most Recently Used Lists

Best Known

• HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs

• A MRU list for about every application

• Used by the app to list your last accessed docs from that app.

PowerPoint

Which was the last one?

First Second

RunMRUMost recently run programs the the Run Command.

cmdregeditmsconfig

Typed URLsHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs

Opened and Saved MRUsChronological list of Opened/Saved files

Opened and Saved MRUsVia File Extensions

.exe’s

Apps Associated with a File Extension

ComDlg32

Search AssistantSubkeys are for different search approaches:

5001 – Internet Search Assistant5603 – XP file search5604 – “word or phrase in a file”

System Restore Points

• Restore the system to a previous state

• Restore Points built in the background– Trigged by installation of apps/drivers

(unsigned)– Done once a day by default

What gets restored

• Registry

• Local profiles

• COM+ database

• WFP DLL cache

• WMI database

• IIS database

What doesn’t.

• DRM

• WPA settings

• SAM hive

• User-created data stored in the user profile

• Contents of redirected folders

System Restore ConfigurationRestore Point updates in seconds = 1 day

Retention of Restore Points in seconds

Lab 6.1

• Determine MRUs• Typed URLs

• Recent files opened/viewed by app» Order viewed

• Latest searches

• What apps were recently run from cmd.exe