@port139 Blog

基本的にはデジタル・フォレンジックの技術について取り扱っていますが、記載内容には高確率で誤りが含まれる可能性があります。

2018-09-01から1ヶ月間の記事一覧

Timestamp and USN_REASON_BASIC_INFO_CHANGE

Note:I translated Japanese into English using Google Translate.Thank you, Google. My question is Can I find timestamp changes using USN Journal? Let's try it.Enable USN Journal with volume E :. Copy the sample JPEG file to the E: drive, us…

Autopsy and Realloc

Note:I translated Japanese into English using Google Translate.Thank you, Google. Let's create a record labeled (realloc). Create Example folder and create several files in the folder. In the following, a long file name is set to create In…

Esentutl and File copy

Note:I translated Japanese into English using Google Translate.Thank you, Google. FireEye has released a report on APT 10's TTPs. I was interested in the method using ESENTUTL tool. https://www.fireeye.com/blog/threat-research/2018/09/apt1…

NTFS $ObjID and ObjectID

Note:I translated Japanese into English using Google Translate.Thank you, Google. Let's check NTFS $ObjID:$O and the deleted ObjectID. There is image files on the sample E: drive, but these files do not have an ObjectID. Browse the image f…

NTFS $LogFile and ObjectID

Note:I translated Japanese into English using Google Translate.Thank you, Google. Check the record of $LogFile when setting ObjectID.E: drive used for verification is newly formatted with NTFS. Copy the sample JPEG file to the E drive. Thi…