Chat with us, powered by LiveChat Windows Digital Forensic - STUDENT SOLUTION USA

Windows Digital Forensic  -Writing

Zero days vulnerabilities in Digital Forensics… Please, discuss your views and ideas on how can we be prepared for zero day vulnerabilities and attacks. Share your views with your classmates and comment on at least two of your classmates’ posts.
msdf_531___week_5.pptx

Unformatted Attachment Preview

Windows Digital Forensics
MSDF-531
Dr. Scott Grimes
Week 5
Registry Analysis
• Registry Structure
• Name
• Type
• Data
Registry Analysis
• Registry Root Keys





HKEY_CLASSES_ROOT
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_CURRENT_USER
HKEY_CURRENT_CONFIG
Registry Analysis
• HKEY_LOCAL_MACHINE





SYSTEM
SOFTWARE
SAM
SECURITY
HARDWARE
Registry Analysis
• HKEY_USERS
• S-1-5-18
• SYSTEM PROFILE
• S-1-5-19
• LOCALSERVICE
• S-1-5-20
• NETWORK SERVICE
• S-1-5-21-…
• USER
• DEFAULT
• DEFAULT PROFILE FOR NEW USERS
Registry Analysis
• HKEY_CURRENT_USER
• POINTER TO THE CURRENT USER UNDER HKU
EVENT LOG Analysis
• Event logs can be easily accessed by looking at the Event Viewer
• Control PanelAll Control Panel ItemsAdministrative ToolsEvent Viewer
EVENT LOG Analysis
• Event Logs can assist us answering these questions





What happened?
When?
Who?
What systems are involved?
What resources are accessed?
EVENT LOG Analysis
• Security Log
• System Log
• Application Log
• Directory Service
• File Replication Server
• DNS Server
EVENT LOG Analysis
• New Event Logs can be summed up as…
• Setup
• Forwarded Events
• Application and Services
EVENT LOG Analysis
• Security Events Logs can be summed up as…









Account Logon
Account Mgmt
Logon Events
Directory Service
Object Access
Policy Change
Privilege Use
Process Tracking
System Events
EVENT LOG Analysis
• Security Events can have the following types…





Error
Warning
Information
Success Audit
Failure Audit
This Week’s Assignments…
• Reading Assignment:
• Chapters 7 and 8 in your textbook.
• Weekly Quiz:
• Chapter 7 & 8
• Discussion Assignment
• Week 5 Discussion
• Hands-on Assignment
• Week 5 Assignment: FTK Imager Assignment
Note: All Assignments are due by Sunday night at 11:59PM

Purchase answer to see full
attachment

 

error: Content is protected !!