Professional Documents
Culture Documents
Week 9 Lab
Copyright 2012, John McCash. This work may be copied, modified, displayed and distributed under conditions set forth in the Creative Commons AttributionNoncommercial License. To view a copy of this license, visit http://creativecommons.org/licenses/by-nc/2.0/ or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.
Vshadowmount (Linux)
Galetta (cookies) Pasco (cache) Id32 (generic index.dat parser) Mandiant Web Historian (Windows only)
sudo bash
Created desktop folder Restore_Point_Test manually created a shadow copy Copied a file into the folder manually created a 2nd shadow copy Removed file and added another of similar size manually created a 3rd shadow copy Removed 2nd file Logically imaged C: with FTK Imager
Win7_VSC_Restore_Point_Test.E01
Examine the folders under the three mounted restore points for the files I created in C:\Users\SANSForensics408\Desktop\Restore_Point_Test
xp_dblake.dd mounted
Run galetta against all of the Donald Blake users cookie files
Run galetta against all of the Donald Blake users cookie files
Galetta
Look at the __utma Google Analytics cookies for various websites, & decode the dates using dcode.exe on the Windows SIFT Kit From this, what were three different dates when the subject visited winzip.com? Run 1183244089, 1231967273, & 1231967349 through dcode to get the associated UNIX Text timestamp values
XXXX Hash of clients domain RRRR Random unique ID for client FFFF Date of first visit to site (probably following the last clear of cookies) PPPP Timestamp of previous (last) visit CCCC Current timestamp N Number of sessions since first visit (Incremented each time new session started after first)
Run pasco against the dblake Internet Explorer Cache index.dat file
Open OpenOffice Insert -> Sheet from file Check the tab delimited box After importing, reformat column widths and select wrap on Sort all below header by column D (ACCESS TIME)
Id is in the Linux SIFT Kit according to the docs, but I cant find it Download from http://tzworks.net/download_links. php Both Linux & Windows versions are available
Open OpenOffice Insert -> Sheet from file Check the comma delimited box After importing, reformat column widths and select wrap on Sort all below header by columns C (access date) and D (acess time)
Questions?
17