@port139 Blog

基本的にはデジタル・フォレンジックの技術について取り扱っていますが、記載内容には高確率で誤りが含まれる可能性があります。

Active Directory and ADTimeline(2)

Note:I translated Japanese into English using Google Translate.Thank you, Google. Summary: I created an Alice account, added it to the Domain admins group, and confirmed it on the timeline. Next, I created a Bob account and logged on to th…

Active Directory and ADTimeline(1)

Note:I translated Japanese into English using Google Translate.Thank you, Google. Summary: I added PC 1 to the example domain, but I could not find it on ADTimeline timeline. I created an Alice account and added it to the Domain Admins gro…

Active Directory and When-Changed (2)

Note:I translated Japanese into English using Google Translate.Thank you, Google. Summary: I got some comments on Twitter about the previous contents. So I did a simple test using DCshadow. Updates of SIDHistory etc. are explained in detai…

Active Directory When-Created and When-Changed (1)

Note:I translated Japanese into English using Google Translate.Thank you, Google. Summary: Active Directory accounts have "When-Created" and "When-Changed" attributes. I am checking when those attributes are updated. However, I just starte…

RDP and UserAssist (Win 10)

Note:I translated Japanese into English using Google Translate.Thank you, Google. Summary: Did you read "Daily Blog # 602: Solution Saturday 1/19/19"?, I read it and tested it on RDP connection. I ran the program via RDP and looked up the …

Task Scheduler Registry key and "Last Run Time"

Note:I translated Japanese into English using Google Translate.Thank you, Google. Summary: "Last Run Time" is displayed in the GUI of Task Scheduler, this value is saved in the registry. Several timestamps are stored in the "Dynamicinfo" v…

Windows 10 Storage sense and Recycle.bin

Note:I translated Japanese into English using Google Translate.Thank you, Google. Summary: I tested the Recycle.bin delete option of the Storage sense feature. Files in Recycle.bin are deleted by task SilentCleanup??. Sample JPEG file in R…

NTFS last access time and 1 hour (3)

Note:I translated Japanese into English using Google Translate.Thank you, Google. Summary: I confirmed that the latest Last Access Time is written to disk by accessing the file after 1 hour has elapsed. After one hour elapsed, when shuttin…

NTFS last access time and 1 hour (2)

Note:I translated Japanese into English using Google Translate.Thank you, Google. Summary: I used FTK Imager and Autopsy as a tool to check Last Access Time on NTFS volume. However, adding Local Drive did not produce the expected results.(…

NTFS last access time and 1 hour

Note:I translated Japanese into English using Google Translate.Thank you, Google. Summary: NTFS's Last Access Time resolution is one hour. ( I started the test on Win 10 ver 1803.) "fsutil file layout" command and PowerShell displays the l…

DisableLastAccess and 2 (System Managed, Disabled)

Note:I translated Japanese into English using Google Translate.Thank you, Google. I confirmed DisableLastAccess in verification environment. The size of C: is 40 GB.The value of DisableLastAccess was "2" and "Disabled"...."Disabled"??? I c…

Deleted Registry KEY and Timestamp

Note:I translated Japanese into English using Google Translate.Thank you, Google. Delete the registry key and check the time stamp.Create sample registry keys and values under SYSTEM. Last write timestamp:2018-12-09 05:33:00(UTC) Delete th…

USB and Amcache(2)

Note:I translated Japanese into English using Google Translate.Thank you, Google. This is the continuation of the Amcache test. I connected a USB memory and created an LNK file.Each LNK file targets the CLI and the GUI program that exist o…

USB and Amcache

Note:I translated Japanese into English using Google Translate.Thank you, Google. Have you seen the Amcache season of Forensic Lunch Test Kitchen? Unfortunately, I have not seen everything yet. I am planning to enjoy them at the weekend. a…

ReFS and File ID

Note:I translated Japanese into English using Google Translate.Thank you, Google. The File ID of ReFS looks different from NTFS. Using USN Journal, confirm the ReFS File ID. I enabled the USN Journal on the ReFS volume used for testing. Cr…

Refs and USN Journal(2)

Note:I translated Japanese into English using Google Translate.Thank you, Google. I got the Refs volume of Win10 1803 as E01 image. You can download it from the following URL. (That is the volume I tested last time.) Win10_1083_Refs.E01htt…

Refs and USN Journal

Note:I translated Japanese into English using Google Translate.Thank you, Google. A little while ago I learned that ReFS supports the USN Journal. How do I check the USN Journal on ReFS? Format E: drive with ReFS. Start the administrator c…

Audit PNP Activity and ID 6416

Note:I translated Japanese into English using Google Translate.Thank you, Google. When audit setting "Audit PNP Activity" is enabled on Windows 10, event ID 6416 is recorded. Auditing is not enabled for this item by default. Let's check th…

File System Tunneling and C:\

Note:I translated Japanese into English using Google Translate.Thank you, Google. Last week I enjoyed File System Tunneling.Unfortunately, I could not reproduce File System Tunneling with NTFS 'E: drive. This time I use the C: drive for te…

File System Tunneling and E:\

Note:I translated Japanese into English using Google Translate.Thank you, Google. iria_piyo has published some interesting verifications on File System Tunneling in the blog. I read those blogs and I wanted to see how the USN Journal was r…

Timestamp and USN_REASON_BASIC_INFO_CHANGE

Note:I translated Japanese into English using Google Translate.Thank you, Google. My question is Can I find timestamp changes using USN Journal? Let's try it.Enable USN Journal with volume E :. Copy the sample JPEG file to the E: drive, us…

Autopsy and Realloc

Note:I translated Japanese into English using Google Translate.Thank you, Google. Let's create a record labeled (realloc). Create Example folder and create several files in the folder. In the following, a long file name is set to create In…

Esentutl and File copy

Note:I translated Japanese into English using Google Translate.Thank you, Google. FireEye has released a report on APT 10's TTPs. I was interested in the method using ESENTUTL tool. https://www.fireeye.com/blog/threat-research/2018/09/apt1…

NTFS $ObjID and ObjectID

Note:I translated Japanese into English using Google Translate.Thank you, Google. Let's check NTFS $ObjID:$O and the deleted ObjectID. There is image files on the sample E: drive, but these files do not have an ObjectID. Browse the image f…

NTFS $LogFile and ObjectID

Note:I translated Japanese into English using Google Translate.Thank you, Google. Check the record of $LogFile when setting ObjectID.E: drive used for verification is newly formatted with NTFS. Copy the sample JPEG file to the E drive. Thi…

NTFS $LogFile and DataRun

Note:I translated Japanese into English using Google Translate.Thank you, Google. Use $LogFile to check overwriting of the cluster. Two images are used for the test. These two image files are almost the same size. Copy Dragonfly.jpg to for…

NTFS USN Journal and ObjectID

Note:I translated Japanese into English using Google Translate.Thank you, Google. Enable USN Journal on sample NTFS volumes and Copy Example.jpg to the Pictures folder. Check the status of ObjectID, ObjectID is not set. Using USN Analytics…

Jumplist and Clear File Explorer history

Note:I translated Japanese into English using Google Translate.Thank you, Google. Hop Step Jumplist. Display file 5f7b5f1e01b83767.automaticDestinations-ms with HEX.Only 'DestList' exists in this file. I started explorer and I looked up 4 …

Jumplist and File copy

Note:I translated Japanese into English using Google Translate.Thank you, Google. I did not know about the artifacts in the Jumplist mentioned below. http://www.hecfblog.com/2018/07/daily-blog-426-directory-copy-and-paste.html So new as of…

NTFS $REPARSE_POINT and Symbolic link(2)

Note:I translated Japanese into English using Google Translate.Thank you, Google. Last week I checked the symbolic link using the mklink command. The Symbolic link reparse data has a field of Print name, but the mklink command can not set …