@port139 Blog

基本的にはデジタル・フォレンジックの技術について取り扱っていますが、記載内容には高確率で誤りが含まれる可能性があります。

USB and Amcache(2)

Note:I translated Japanese into English using Google Translate.
Thank you, Google.  

This is the continuation of the Amcache test.

 

I connected a USB memory and created an LNK file.
Each LNK file targets the CLI and the GUI program that exist on the USB memory.

f:id:hideakii:20181203072350p:plain

f:id:hideakii:20181203072709p:plain

f:id:hideakii:20181203073243p:plain

Run each LNK file and check the timestamp in the Sysmon event log.

f:id:hideakii:20181203073012p:plain

f:id:hideakii:20181203073403p:plain

I will wait until it is reflected in Amcahce. (The USB memory is still connected.)

Confirm the parse result.

There was no entry for F: drive in "20181203071331_Amcache_ShortCuts.csv".

 

Result of 20181203071313_Amcache_UnassociatedFileEntries.csv.

???, There is a record of the CLI program, Autorunsc.exe. (I want to test what happens when PowerShell etc. are embedded in LNK file.)

f:id:hideakii:20181203074130p:plain

And the record of the program deleted from F: drive has disappeared.(Record such as fte.exe does not exist.)

 

 

Result of 2018120307131331_Amcache_DevicePnps.csv.

f:id:hideakii:20181203073926p:plain

 

Verification environment: Windows 10 1803

Reference URL:

df-stream.com

 

f:id:hideakii:20181203072406j:plain