Windows Artifacts
Tip
AWSãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training AWS Red Team Expert (ARTE)
GCPãããã³ã°ãåŠã³ãå®è·µããïŒHackTricks Training GCP Red Team Expert (GRTE)
Azureãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training Azure Red Team Expert (AzRTE)
HackTricksããµããŒããã
- ãµãã¹ã¯ãªãã·ã§ã³ãã©ã³ã確èªããŠãã ããïŒ
- **ð¬ Discordã°ã«ãŒããŸãã¯ãã¬ã°ã©ã ã°ã«ãŒãã«åå ããããTwitter ðŠ @hacktricks_liveããã©ããŒããŠãã ããã
- HackTricksããã³HackTricks Cloudã®GitHubãªããžããªã«PRãæåºããŠãããã³ã°ããªãã¯ãå ±æããŠãã ããã
Generic Windows Artifacts
Windows 10 Notifications
ãã¹ \Users\<username>\AppData\Local\Microsoft\Windows\Notifications ã«ã¯ãããŒã¿ããŒã¹ appdb.datïŒWindows ã¢ãããŒãµãªãŒåïŒãŸã㯠wpndatabase.dbïŒWindows ã¢ãããŒãµãªãŒåŸïŒããããŸãã
ãã® SQLite ããŒã¿ããŒã¹å
ã«ã¯ãè峿·±ãããŒã¿ãå«ãå¯èœæ§ã®ãããã¹ãŠã®éç¥ïŒXML 圢åŒïŒã® Notification ããŒãã«ããããŸãã
Timeline
Timeline ã¯ã蚪åãããŠã§ãããŒãžãç·šéããææžãå®è¡ããã¢ããªã±ãŒã·ã§ã³ã® æç³»åå±¥æŽ ãæäŸãã Windows ã®ç¹åŸŽã§ãã
ããŒã¿ããŒã¹ã¯ããã¹ \Users\<username>\AppData\Local\ConnectedDevicesPlatform\<id>\ActivitiesCache.db ã«ãããŸãããã®ããŒã¿ããŒã¹ã¯ãSQLite ããŒã«ãŸãã¯ããŒã« WxTCmd ã䜿çšããŠéãããšãã§ãã2ã€ã®ãã¡ã€ã«ãçæãããããã¯ããŒã« TimeLine Explorer ã§éãããšãã§ããŸãã
ADS (Alternate Data Streams)
ããŠã³ããŒãããããã¡ã€ã«ã«ã¯ãADS Zone.Identifier ãå«ãŸããŠãããã©ã®ããã« intranetãinternet ãªã©ãã ããŠã³ããŒããããã ã瀺ããŠããŸããäžéšã®ãœãããŠã§ã¢ïŒãã©ãŠã¶ãªã©ïŒã¯ããã¡ã€ã«ãããŠã³ããŒããããURLãªã©ãããã«å€ãã®æ å ±ãæäŸããããšããããããŸãã
File Backups
Recycle Bin
Vista/Win7/Win8/Win10 ã§ã¯ãRecycle Bin ã¯ãã©ã€ãã®ã«ãŒãã«ãããã©ã«ã㌠$Recycle.bin ã«ãããŸãïŒC:\$Recycle.binïŒã
ãã®ãã©ã«ããŒå
ã§ãã¡ã€ã«ãåé€ããããšã2ã€ã®ç¹å®ã®ãã¡ã€ã«ãäœæãããŸãïŒ
$I{id}: ãã¡ã€ã«æ å ±ïŒåé€ãããæ¥æïŒ$R{id}: ãã¡ã€ã«ã®å 容
.png)
ãããã®ãã¡ã€ã«ãããã°ãããŒã« Rifiuti ã䜿çšããŠåé€ããããã¡ã€ã«ã®å
ã®ã¢ãã¬ã¹ãšå逿¥æãååŸã§ããŸãïŒVista â Win10 ã«ã¯ rifiuti-vista.exe ã䜿çšïŒã
.\rifiuti-vista.exe C:\Users\student\Desktop\Recycle
 (1) (1) (1).png)
ããªã¥ãŒã ã·ã£ããŠã³ããŒ
ã·ã£ããŠã³ããŒã¯ãMicrosoft Windowsã«å«ãŸããæè¡ã§ãã³ã³ãã¥ãŒã¿ãã¡ã€ã«ãããªã¥ãŒã ã®ããã¯ã¢ããã³ããŒãã¹ãããã·ã§ãããäœæã§ããŸãããããã¯äœ¿çšäžã§ãã£ãŠãäœæå¯èœã§ãã
ãããã®ããã¯ã¢ããã¯éåžžããã¡ã€ã«ã·ã¹ãã ã®ã«ãŒããã \System Volume Informationã«ãããååã¯ä»¥äžã®ç»åã«ç€ºãããŠããUIDã§æ§æãããŠããŸãã
.png)
ArsenalImageMounterã䜿çšããŠãã©ã¬ã³ãžãã¯ã€ã¡ãŒãžãããŠã³ããããšãããŒã«ShadowCopyViewã䜿çšããŠã·ã£ããŠã³ããŒãæ€æ»ããã·ã£ããŠã³ããŒã®ããã¯ã¢ãããããã¡ã€ã«ãæœåºããããšãã§ããŸãã
.png)
ã¬ãžã¹ããªãšã³ããªHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BackupRestoreã«ã¯ãããã¯ã¢ããããªããã¡ã€ã«ãšããŒãå«ãŸããŠããŸãã
.png)
ã¬ãžã¹ããªHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSSã«ã¯ãããªã¥ãŒã ã·ã£ããŠã³ããŒã«é¢ããæ§ææ
å ±ãå«ãŸããŠããŸãã
Officeèªåä¿åãã¡ã€ã«
Officeã®èªåä¿åãã¡ã€ã«ã¯æ¬¡ã®å Žæã«ãããŸã: C:\Usuarios\\AppData\Roaming\Microsoft{Excel|Word|Powerpoint}\
ã·ã§ã«ã¢ã€ãã
ã·ã§ã«ã¢ã€ãã ã¯ãå¥ã®ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ããæ¹æ³ã«é¢ããæ å ±ãå«ãã¢ã€ãã ã§ãã
æè¿ã®ææž (LNK)
Windowsã¯ããŠãŒã¶ãŒã次ã®å Žæã§ãã¡ã€ã«ãéãã䜿çšããããŸãã¯äœæãããšãã«ããããã®ã·ã§ãŒãã«ãããèªåçã«****äœæããŸã:
- Win7-Win10:
C:\Users\\AppData\Roaming\Microsoft\Windows\Recent\ - Office:
C:\Users\\AppData\Roaming\Microsoft\Office\Recent\
ãã©ã«ããŒãäœæããããšããã©ã«ããŒãžã®ãªã³ã¯ã芪ãã©ã«ããŒãžã®ãªã³ã¯ãããã³ç¥ç¶ãã©ã«ããŒãžã®ãªã³ã¯ãäœæãããŸãã
ãããã®èªåçã«äœæããããªã³ã¯ãã¡ã€ã«ã¯ããã¡ã€ã«ããã©ã«ããŒããMAC ã¿ã€ã ãããªã¥ãŒã æ å ±ãããã³ã¿ãŒã²ãããã¡ã€ã«ã®ãã©ã«ããŒã«é¢ããæ å ±ãå«ãã§ããŸãããã®æ å ±ã¯ããã¡ã€ã«ãåé€ãããå Žåã«ããããå埩ããã®ã«åœ¹ç«ã¡ãŸãã
ãŸãããªã³ã¯ãã¡ã€ã«ã®äœææ¥ã¯ãå ã®ãã¡ã€ã«ãæåã«äœ¿çšãããæéã§ããããªã³ã¯ãã¡ã€ã«ã®æçµæŽæ°æ¥ã¯ãå ã®ãã¡ã€ã«ã䜿çšãããæåŸã®æéã§ãã
ãããã®ãã¡ã€ã«ãæ€æ»ããã«ã¯ãLinkParserã䜿çšã§ããŸãã
ãã®ããŒã«ã§ã¯ã2ã»ããã®ã¿ã€ã ã¹ã¿ã³ããèŠã€ãããŸã:
- æåã®ã»ãã:
- FileModifiedDate
- FileAccessDate
- FileCreationDate
- 2çªç®ã®ã»ãã:
- LinkModifiedDate
- LinkAccessDate
- LinkCreationDate
æåã®ã»ããã®ã¿ã€ã ã¹ã¿ã³ãã¯ãã¡ã€ã«èªäœã®ã¿ã€ã ã¹ã¿ã³ããåç §ããŸãã2çªç®ã®ã»ããã¯ãªã³ã¯ããããã¡ã€ã«ã®ã¿ã€ã ã¹ã¿ã³ããåç §ããŸãã
åãæ å ±ã¯ãWindows CLIããŒã«LECmd.exeãå®è¡ããããšã§ååŸã§ããŸãã
LECmd.exe -d C:\Users\student\Desktop\LNKs --csv C:\Users\student\Desktop\LNKs
ãã®å Žåãæ å ±ã¯CSVãã¡ã€ã«ã«ä¿åãããŸãã
ãžã£ã³ããªã¹ã
ããã¯ã¢ããªã±ãŒã·ã§ã³ããšã«ç€ºãããæè¿ã®ãã¡ã€ã«ã§ããåã¢ããªã±ãŒã·ã§ã³ã§ã¢ã¯ã»ã¹ã§ããã¢ããªã±ãŒã·ã§ã³ã«ãã£ãŠäœ¿çšãããæè¿ã®ãã¡ã€ã«ã®ãªã¹ãã§ãããããã¯èªåçã«äœæãããããã«ã¹ã¿ã ã§äœæãããããšããããŸãã
èªåçã«äœæããããžã£ã³ããªã¹ãã¯ãC:\Users\{username}\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\ã«ä¿åãããŸãããžã£ã³ããªã¹ãã¯ãæåã®IDãã¢ããªã±ãŒã·ã§ã³ã®IDã§ãã{id}.autmaticDestinations-msãšãã圢åŒã§åœåãããŸãã
ã«ã¹ã¿ã ãžã£ã³ããªã¹ãã¯ãC:\Users\{username}\AppData\Roaming\Microsoft\Windows\Recent\CustomDestination\ã«ä¿åãããéåžžã¯ãã¡ã€ã«ã«éèŠãªããšãèµ·ãã£ãããã«ã¢ããªã±ãŒã·ã§ã³ã«ãã£ãŠäœæãããŸãïŒãæ°ã«å
¥ããšããŠããŒã¯ãããŠãããããããŸããïŒã
ä»»æã®ãžã£ã³ããªã¹ãã®äœææéã¯ããã¡ã€ã«ãæåã«ã¢ã¯ã»ã¹ãããæéã瀺ããä¿®æ£æéã¯æåŸã«ã¢ã¯ã»ã¹ãããæéã瀺ããŸãã
ãžã£ã³ããªã¹ãã¯JumplistExplorerã䜿çšããŠèª¿æ»ã§ããŸãã
.png)
ïŒJumplistExplorerã«ãã£ãŠæäŸãããã¿ã€ã ã¹ã¿ã³ãã¯ããžã£ã³ããªã¹ããã¡ã€ã«èªäœã«é¢é£ããŠããŸãïŒ
ã·ã§ã«ããã°
ãã®ãªã³ã¯ããã©ããŒããŠã·ã§ã«ããã°ã«ã€ããŠåŠãã§ãã ããã
Windows USBã®äœ¿çš
USBããã€ã¹ã䜿çšãããããšãç¹å®ããããšã¯ã以äžã®äœæã«ãã£ãŠå¯èœã§ãïŒ
- Windows Recent Folder
- Microsoft Office Recent Folder
- ãžã£ã³ããªã¹ã
äžéšã®LNKãã¡ã€ã«ã¯ãå ã®ãã¹ãæãã®ã§ã¯ãªããWPDNSEãã©ã«ããŒãæããŠããŸãïŒ
.png)
WPDNSEãã©ã«ããŒå ã®ãã¡ã€ã«ã¯å ã®ãã¡ã€ã«ã®ã³ããŒã§ãããPCã®åèµ·åã§ã¯çãæ®ãããGUIDã¯ã·ã§ã«ããã°ããååŸãããŸãã
ã¬ãžã¹ããªæ å ±
ãã®ããŒãžããã§ãã¯ã㊠USBæ¥ç¶ããã€ã¹ã«é¢ããè峿·±ãæ å ±ãå«ãã¬ãžã¹ããªããŒãåŠãã§ãã ããã
setupapi
USBæ¥ç¶ãè¡ãããæå»ã«é¢ããã¿ã€ã ã¹ã¿ã³ããååŸããã«ã¯ãC:\Windows\inf\setupapi.dev.logãã¡ã€ã«ã確èªããŠãã ããïŒSection startãæ€çŽ¢ïŒã
 (2) (2) (2) (2) (2) (2) (2) (3) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (10) (14) (2).png)
USB Detective
USBDetectiveã¯ãç»åã«æ¥ç¶ãããUSBããã€ã¹ã«é¢ããæ å ±ãååŸããããã«äœ¿çšã§ããŸãã
.png)
ãã©ã°ã¢ã³ããã¬ã€ã®ã¯ãªãŒã³ã¢ãã
ããã©ã°ã¢ã³ããã¬ã€ã®ã¯ãªãŒã³ã¢ããããšããŠç¥ãããã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯ã¯ãäž»ã«å€ããã©ã€ããŒããŒãžã§ã³ã®åé€ãç®çãšããŠããŸããææ°ã®ãã©ã€ããŒããã±ãŒãžããŒãžã§ã³ãä¿æãããšããæå®ãããç®çãšã¯å¯Ÿç §çã«ããªã³ã©ã€ã³ãœãŒã¹ã¯ãéå»30æ¥éã«éã¢ã¯ãã£ããªãã©ã€ããŒã察象ã«ããŠããããšã瀺åããŠããŸãããããã£ãŠãéå»30æ¥éã«æ¥ç¶ãããŠããªããªã ãŒããã«ããã€ã¹ã®ãã©ã€ããŒã¯åé€ãããå¯èœæ§ããããŸãã
ã¿ã¹ã¯ã¯æ¬¡ã®ãã¹ã«ãããŸãïŒC:\Windows\System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanupã
ã¿ã¹ã¯ã®å
容ã瀺ãã¹ã¯ãªãŒã³ã·ã§ãããæäŸãããŠããŸãïŒ 
ã¿ã¹ã¯ã®äž»èŠã³ã³ããŒãã³ããšèšå®ïŒ
- pnpclean.dllïŒãã®DLLã¯å®éã®ã¯ãªãŒã³ã¢ããããã»ã¹ãæ åœããŸãã
- UseUnifiedSchedulingEngineïŒ
TRUEã«èšå®ãããŠãããäžè¬çãªã¿ã¹ã¯ã¹ã±ãžã¥ãŒãªã³ã°ãšã³ãžã³ã®äœ¿çšã瀺ããŸãã - MaintenanceSettingsïŒ
- Period (âP1Mâ)ïŒã¿ã¹ã¯ã¹ã±ãžã¥ãŒã©ã«ã宿çãªèªåã¡ã³ããã³ã¹äžã«æ¯æã¯ãªãŒã³ã¢ããã¿ã¹ã¯ãéå§ããããæç€ºããŸãã
- Deadline (âP2Mâ)ïŒã¿ã¹ã¯ã¹ã±ãžã¥ãŒã©ã«ãã¿ã¹ã¯ã2ãæé£ç¶ã§å€±æããå Žåãç·æ¥èªåã¡ã³ããã³ã¹äžã«ã¿ã¹ã¯ãå®è¡ããããæç€ºããŸãã
ãã®æ§æã«ããããã©ã€ããŒã®å®æçãªã¡ã³ããã³ã¹ãšã¯ãªãŒã³ã¢ããã確ä¿ãããé£ç¶çãªå€±æãçºçããå Žåã«ã¿ã¹ã¯ãå詊è¡ããããã®èŠå®ãèšããããŠããŸãã
詳现ã«ã€ããŠã¯ã次ã確èªããŠãã ããïŒ https://blog.1234n6.com/2018/07/windows-plug-and-play-cleanup.html
ã¡ãŒã«
ã¡ãŒã«ã«ã¯2ã€ã®è峿·±ãéšåããããŸãïŒããããŒãšã¡ãŒã«ã®å 容ãããããŒã«ã¯æ¬¡ã®ãããªæ å ±ãå«ãŸããŠããŸãïŒ
- 誰ãã¡ãŒã«ãéä¿¡ãããïŒã¡ãŒã«ã¢ãã¬ã¹ãIPãã¡ãŒã«ãµãŒããŒããªãã€ã¬ã¯ãããã¡ãŒã«ïŒ
- ãã€ã¡ãŒã«ãéä¿¡ãããã
ãŸããReferencesããã³In-Reply-ToããããŒå
ã«ã¯ã¡ãã»ãŒãžã®IDãå«ãŸããŠããŸãïŒ
.png)
Windowsã¡ãŒã«ã¢ããª
ãã®ã¢ããªã±ãŒã·ã§ã³ã¯ãã¡ãŒã«ãHTMLãŸãã¯ããã¹ã圢åŒã§ä¿åããŸããã¡ãŒã«ã¯ã\Users\<username>\AppData\Local\Comms\Unistore\data\3\å
ã®ãµããã©ã«ããŒã«ãããŸããã¡ãŒã«ã¯.datæ¡åŒµåã§ä¿åãããŸãã
ã¡ãŒã«ã®ã¡ã¿ããŒã¿ãšé£çµ¡å
ã¯ãEDBããŒã¿ããŒã¹å
ã«ãããŸãïŒ\Users\<username>\AppData\Local\Comms\UnistoreDB\store.vol
ãã¡ã€ã«ã®æ¡åŒµåã.volãã.edbã«å€æŽãããšãããŒã«ESEDatabaseViewã䜿çšããŠéãããšãã§ããŸããMessageããŒãã«å
ã§ã¡ãŒã«ãèŠãããšãã§ããŸãã
Microsoft Outlook
ExchangeãµãŒããŒãŸãã¯Outlookã¯ã©ã€ã¢ã³ãã䜿çšããããšãããã€ãã®MAPIããããŒãååšããŸãïŒ
Mapi-Client-Submit-TimeïŒã¡ãŒã«ãéä¿¡ããããšãã®ã·ã¹ãã ã®æéMapi-Conversation-IndexïŒã¹ã¬ããã®åã¡ãã»ãŒãžã®æ°ãšåã¡ãã»ãŒãžã®ã¿ã€ã ã¹ã¿ã³ãMapi-Entry-IDïŒã¡ãã»ãŒãžèå¥åãMappi-Message-Flagsããã³Pr_last_Verb-ExecutedïŒMAPIã¯ã©ã€ã¢ã³ãã«é¢ããæ å ±ïŒã¡ãã»ãŒãžã¯èªãŸãããïŒæªèªãïŒå¿çããããïŒãªãã€ã¬ã¯ãããããïŒäžåšãïŒïŒ
Microsoft Outlookã¯ã©ã€ã¢ã³ãã§ã¯ãéä¿¡/åä¿¡ããããã¹ãŠã®ã¡ãã»ãŒãžãé£çµ¡å ããŒã¿ãããã³ã«ã¬ã³ããŒããŒã¿ã¯ã次ã®å Žæã«ããPSTãã¡ã€ã«ã«ä¿åãããŸãïŒ
%USERPROFILE%\Local Settings\Application Data\Microsoft\OutlookïŒWinXPïŒ%USERPROFILE%\AppData\Local\Microsoft\Outlook
ã¬ãžã¹ããªãã¹HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlookã¯ã䜿çšãããŠãããã¡ã€ã«ã瀺ããŠããŸãã
PSTãã¡ã€ã«ã¯ãããŒã«Kernel PST Viewerã䜿çšããŠéãããšãã§ããŸãã
.png)
Microsoft Outlook OSTãã¡ã€ã«
OSTãã¡ã€ã«ã¯ãMicrosoft OutlookãIMAPãŸãã¯ExchangeãµãŒããŒã§æ§æããããšçæãããPSTãã¡ã€ã«ãšåæ§ã®æ å ±ãä¿åããŸãããã®ãã¡ã€ã«ã¯ãµãŒããŒãšåæãããéå»12ãæéã®ããŒã¿ãä¿æããæå€§ãµã€ãºã¯50GBã§ãPSTãã¡ã€ã«ãšåããã£ã¬ã¯ããªã«ãããŸããOSTãã¡ã€ã«ã衚瀺ããã«ã¯ãKernel OST viewerãå©çšã§ããŸãã
æ·»ä»ãã¡ã€ã«ã®ååŸ
倱ãããæ·»ä»ãã¡ã€ã«ã¯ã以äžããå埩å¯èœã§ãïŒ
- IE10ã®å ŽåïŒ
%APPDATA%\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook - IE11以éã®å ŽåïŒ
%APPDATA%\Local\Microsoft\InetCache\Content.Outlook
Thunderbird MBOXãã¡ã€ã«
Thunderbirdã¯MBOXãã¡ã€ã«ã䜿çšããŠããŒã¿ãä¿åããUsers\%USERNAME%\AppData\Roaming\Thunderbird\Profilesã«ãããŸãã
ç»åãµã ãã€ã«
- Windows XPããã³8-8.1ïŒãµã ãã€ã«ãå«ããã©ã«ããŒã«ã¢ã¯ã»ã¹ãããšãåé€åŸãç»åãã¬ãã¥ãŒãä¿åãã
thumbs.dbãã¡ã€ã«ãçæãããŸãã - Windows 7/10ïŒUNCãã¹ãä»ããŠãããã¯ãŒã¯äžã§ã¢ã¯ã»ã¹ããããš
thumbs.dbãäœæãããŸãã - Windows Vista以éïŒãµã ãã€ã«ãã¬ãã¥ãŒã¯
%userprofile%\AppData\Local\Microsoft\Windows\Explorerã«éäžããthumbcache_xxx.dbãšããååã®ãã¡ã€ã«ãäœæãããŸããThumbsviewerããã³ThumbCache Viewerã¯ããããã®ãã¡ã€ã«ã衚瀺ããããã®ããŒã«ã§ãã
Windowsã¬ãžã¹ããªæ å ±
Windowsã¬ãžã¹ããªã¯ãåºç¯ãªã·ã¹ãã ããã³ãŠãŒã¶ãŒæŽ»åããŒã¿ãä¿åããæ¬¡ã®ãã¡ã€ã«ã«å«ãŸããŠããŸãïŒ
%windir%\System32\Configã¯ãããŸããŸãªHKEY_LOCAL_MACHINEãµãããŒçšã§ãã%UserProfile%{User}\NTUSER.DATã¯ãHKEY_CURRENT_USERçšã§ãã- Windows Vista以éã®ããŒãžã§ã³ã¯ã
%Windir%\System32\Config\RegBack\ã«HKEY_LOCAL_MACHINEã¬ãžã¹ããªãã¡ã€ã«ã®ããã¯ã¢ãããä¿åããŸãã - ããã«ãããã°ã©ã å®è¡æ
å ±ã¯ãWindows Vistaããã³Windows 2008 Server以éã®
%UserProfile%\{User}\AppData\Local\Microsoft\Windows\USERCLASS.DATã«ä¿åãããŸãã
ããŒã«
ã¬ãžã¹ããªãã¡ã€ã«ãåæããããã«åœ¹ç«ã€ããŒã«ãããã€ããããŸãïŒ
- ã¬ãžã¹ããªãšãã£ã¿ïŒWindowsã«ã€ã³ã¹ããŒã«ãããŠããŸããçŸåšã®ã»ãã·ã§ã³ã®Windowsã¬ãžã¹ããªãããã²ãŒãããããã®GUIã§ãã
- Registry ExplorerïŒã¬ãžã¹ããªãã¡ã€ã«ãããŒãããGUIã§ããã²ãŒãããããšãå¯èœã«ããŸãããŸããè峿·±ãæ å ±ãæã€ããŒããã€ã©ã€ãããããã¯ããŒã¯ãå«ãŸããŠããŸãã
- RegRipperïŒåã³ãããŒããããã¬ãžã¹ããªãããã²ãŒãããããã®GUIãæã¡ãããŒããããã¬ãžã¹ããªå ã®è峿·±ãæ å ±ããã€ã©ã€ããããã©ã°ã€ã³ãå«ãŸããŠããŸãã
- Windows Registry RecoveryïŒã¬ãžã¹ããªããéèŠãªæ å ±ãæœåºããããšãã§ããå¥ã®GUIã¢ããªã±ãŒã·ã§ã³ã§ãã
åé€ãããèŠçŽ ã®å埩
ããŒãåé€ããããšããã®ããã«ããŒã¯ãããŸãããå æããŠããã¹ããŒã¹ãå¿ èŠã«ãªããŸã§åé€ãããŸããããããã£ãŠãRegistry Explorerã®ãããªããŒã«ã䜿çšãããšããããã®åé€ãããããŒãå埩ããããšãå¯èœã§ãã
æçµæžãèŸŒã¿æé
åããŒ-å€ã«ã¯ãæåŸã«ä¿®æ£ãããæéã瀺ãã¿ã€ã ã¹ã¿ã³ããå«ãŸããŠããŸãã
SAM
ãã¡ã€ã«/ãã€ãSAMã«ã¯ãã·ã¹ãã ã®ãŠãŒã¶ãŒãã°ã«ãŒããããã³ãŠãŒã¶ãŒãã¹ã¯ãŒãã®ããã·ã¥ãå«ãŸããŠããŸãã
SAM\Domains\Account\Usersã§ããŠãŒã¶ãŒåãRIDãæçµãã°ã€ã³ãæçµå€±æãã°ãªã³ããã°ã€ã³ã«ãŠã³ã¿ãŒããã¹ã¯ãŒãããªã·ãŒãããã³ã¢ã«ãŠã³ããäœæãããææãååŸã§ããŸããããã·ã¥ãååŸããã«ã¯ããã¡ã€ã«/ãã€ãSYSTEMãå¿
èŠã§ãã
Windowsã¬ãžã¹ããªã®è峿·±ããšã³ããª
Interesting Windows Registry Keys
å®è¡ãããããã°ã©ã
åºæ¬çãªWindowsããã»ã¹
ãã®æçš¿ã§ã¯ãçãããåäœãæ€åºããããã®äžè¬çãªWindowsããã»ã¹ã«ã€ããŠåŠã¶ããšãã§ããŸãã
Windows Recent APPs
ã¬ãžã¹ããªNTUSER.DATå
ã®ãã¹Software\Microsoft\Current Version\Search\RecentAppsã«ã¯ãå®è¡ãããã¢ããªã±ãŒã·ã§ã³ãæåŸã«å®è¡ãããæéãããã³èµ·åãããåæ°ã«é¢ããæ
å ±ãå«ããµãããŒããããŸãã
BAMïŒããã¯ã°ã©ãŠã³ãã¢ã¯ãã£ããã£ã¢ãã¬ãŒã¿ãŒïŒ
ã¬ãžã¹ããªãšãã£ã¿ã§SYSTEMãã¡ã€ã«ãéãããã¹SYSTEM\CurrentControlSet\Services\bam\UserSettings\{SID}å
ã§ãåãŠãŒã¶ãŒã«ãã£ãŠå®è¡ãããã¢ããªã±ãŒã·ã§ã³ã«é¢ããæ
å ±ïŒãã¹å
ã®{SID}ã«æ³šæïŒãšå®è¡ãããæéãèŠã€ããããšãã§ããŸãïŒæéã¯ã¬ãžã¹ããªã®ããŒã¿å€å
ã«ãããŸãïŒã
Windowsããªãã§ãã
ããªãã§ããã¯ãã³ã³ãã¥ãŒã¿ããŠãŒã¶ãŒãè¿ãå°æ¥ã«ã¢ã¯ã»ã¹ããå¯èœæ§ã®ããã³ã³ãã³ãã衚瀺ããããã«å¿ èŠãªãªãœãŒã¹ãéãã«ååŸããããšãå¯èœã«ããæè¡ã§ããããã«ããããªãœãŒã¹ã«è¿ éã«ã¢ã¯ã»ã¹ã§ããŸãã
Windowsããªãã§ããã¯ãå®è¡ãããããã°ã©ã ã®ãã£ãã·ã¥ãäœæããŠãããéãããŒãã§ããããã«ããŸãããããã®ãã£ãã·ã¥ã¯ã次ã®ãã¹å
ã«.pfãã¡ã€ã«ãšããŠäœæãããŸãïŒC:\Windows\PrefetchãXP/VISTA/WIN7ã§ã¯128ãã¡ã€ã«ãWin8/Win10ã§ã¯1024ãã¡ã€ã«ã®å¶éããããŸãã
ãã¡ã€ã«åã¯{program_name}-{hash}.pfãšããŠäœæãããŸãïŒããã·ã¥ã¯å®è¡å¯èœãã¡ã€ã«ã®ãã¹ãšåŒæ°ã«åºã¥ããŠããŸãïŒãW10ã§ã¯ããããã®ãã¡ã€ã«ã¯å§çž®ãããŠããŸãããã¡ã€ã«ã®ååšã¯ãããã°ã©ã ãå®è¡ãããããšã瀺ããŠããŸãã
ãã¡ã€ã«C:\Windows\Prefetch\Layout.iniã«ã¯ãããªãã§ããããããã¡ã€ã«ã®ãã©ã«ããŒã®ååãå«ãŸããŠããŸãããã®ãã¡ã€ã«ã«ã¯ãå®è¡åæ°ãå®è¡æ¥ãããã³ããã°ã©ã ã«ãã£ãŠéããã**ãã¡ã€ã«ã«é¢ããæ
å ±ãå«ãŸããŠããŸãã
ãããã®ãã¡ã€ã«ã調æ»ããã«ã¯ãããŒã«PEcmd.exeã䜿çšã§ããŸãã
.\PECmd.exe -d C:\Users\student\Desktop\Prefetch --html "C:\Users\student\Desktop\out_folder"
.png)
Superprefetch
Superprefetchã¯ã次ã«èªã¿èŸŒãŸãããã®ãäºæž¬ããããšã«ãã£ãŠããã°ã©ã ãããéãèªã¿èŸŒããšããåãç®çãæã£ãŠããŸããããããããã¯prefetchãµãŒãã¹ã®ä»£ããã«ã¯ãªããŸããã
ãã®ãµãŒãã¹ã¯ãC:\Windows\Prefetch\Ag*.dbã«ããŒã¿ããŒã¹ãã¡ã€ã«ãçæããŸãã
ãããã®ããŒã¿ããŒã¹ã«ã¯ãããã°ã©ã ã®ååãå®è¡åæ°ãéããããã¡ã€ã«ãã¢ã¯ã»ã¹ãããããªã¥ãŒã ãå®å šãªãã¹ãæéæ ãããã³ã¿ã€ã ã¹ã¿ã³ããå«ãŸããŠããŸãã
ãã®æ å ±ã«ã¯ãããŒã«CrowdResponseã䜿çšããŠã¢ã¯ã»ã¹ã§ããŸãã
SRUM
System Resource Usage Monitor (SRUM)ã¯ãããã»ã¹ã«ãã£ãŠæ¶è²»ããããªãœãŒã¹ãç£èŠããŸããããã¯W8ã§ç»å ŽããC:\Windows\System32\sru\SRUDB.datã«ESEããŒã¿ããŒã¹ãšããŠããŒã¿ãä¿åããŸãã
以äžã®æ å ±ãæäŸããŸãïŒ
- AppIDãšãã¹
- ããã»ã¹ãå®è¡ãããŠãŒã¶ãŒ
- éä¿¡ãã€ã
- åä¿¡ãã€ã
- ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ãŒã¹
- æ¥ç¶ã®æç¶æé
- ããã»ã¹ã®æç¶æé
ãã®æ å ±ã¯60åããšã«æŽæ°ãããŸãã
ãã®ãã¡ã€ã«ããæ¥ä»ãååŸããã«ã¯ãããŒã«srum_dumpã䜿çšã§ããŸãã
.\srum_dump.exe -i C:\Users\student\Desktop\SRUDB.dat -t SRUM_TEMPLATE.xlsx -o C:\Users\student\Desktop\srum
AppCompatCache (ShimCache)
AppCompatCacheãå¥å ShimCache ã¯ãMicrosoft ã«ãã£ãŠéçºããã Application Compatibility Database ã®äžéšã§ãããã¢ããªã±ãŒã·ã§ã³ã®äºææ§ã®åé¡ã«å¯ŸåŠããããã®ãã®ã§ãããã®ã·ã¹ãã ã³ã³ããŒãã³ãã¯ã以äžã®ãã¡ã€ã«ã¡ã¿ããŒã¿ã®ããŸããŸãªæ å ±ãèšé²ããŸãã
- ãã¡ã€ã«ã®ãã«ãã¹
- ãã¡ã€ã«ã®ãµã€ãº
- $Standard_Information (SI) ã®æçµæŽæ°æå»
- ShimCache ã®æçµæŽæ°æå»
- ããã»ã¹å®è¡ãã©ã°
ãã®ããŒã¿ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ããŒãžã§ã³ã«åºã¥ããŠç¹å®ã®å Žæã«ã¬ãžã¹ããªå ã«ä¿åãããŸãã
- XP ã®å ŽåãããŒã¿ã¯
SYSTEM\CurrentControlSet\Control\SessionManager\Appcompatibility\AppcompatCacheã«ä¿åããã96 ãšã³ããªã®å®¹éããããŸãã - Server 2003 ããã³ Windows ããŒãžã§ã³ 2008ã2012ã2016ã7ã8ã10 ã®å Žåãã¹ãã¬ãŒãžãã¹ã¯
SYSTEM\CurrentControlSet\Control\SessionManager\AppcompatCache\AppCompatCacheã§ããããããã 512 ããã³ 1024 ãšã³ããªãå容ããŸãã
ä¿åãããæ å ±ãè§£æããã«ã¯ãAppCompatCacheParser tool ã®äœ¿çšãæšå¥šãããŸãã
.png)
Amcache
Amcache.hve ãã¡ã€ã«ã¯ãã·ã¹ãã äžã§å®è¡ãããã¢ããªã±ãŒã·ã§ã³ã®è©³çްãèšé²ããã¬ãžã¹ããªãã€ãã§ããéåžžãC:\Windows\AppCompat\Programas\Amcache.hve ã«ãããŸãã
ãã®ãã¡ã€ã«ã¯ãæè¿å®è¡ãããããã»ã¹ã®èšé²ãä¿åããŠãããå®è¡å¯èœãã¡ã€ã«ãžã®ãã¹ããã® SHA1 ããã·ã¥ãå«ãã§ããŸãããã®æ å ±ã¯ãã·ã¹ãã äžã®ã¢ããªã±ãŒã·ã§ã³ã®æŽ»åã远跡ããããã«éåžžã«è²Žéã§ãã
Amcache.hve ããããŒã¿ãæœåºããŠåæããã«ã¯ãAmcacheParser ããŒã«ã䜿çšã§ããŸãã以äžã®ã³ãã³ãã¯ãAmcacheParser ã䜿çšã㊠Amcache.hve ãã¡ã€ã«ã®å 容ãè§£æããçµæã CSV 圢åŒã§åºåããæ¹æ³ã®äŸã§ãã
AmcacheParser.exe -f C:\Users\genericUser\Desktop\Amcache.hve --csv C:\Users\genericUser\Desktop\outputFolder
çæãããCSVãã¡ã€ã«ã®äžã§ãAmcache_Unassociated file entriesã¯ãæªé¢é£ãã¡ã€ã«ãšã³ããªã«é¢ããè±å¯ãªæ
å ±ãæäŸãããããç¹ã«æ³šç®ã«å€ããŸãã
æãè峿·±ãCVSãã¡ã€ã«ã¯ãAmcache_Unassociated file entriesã§ãã
RecentFileCache
ãã®ã¢ãŒãã£ãã¡ã¯ãã¯W7ã®C:\Windows\AppCompat\Programs\RecentFileCache.bcfã«ã®ã¿ååšããããã€ãã®ãã€ããªã®æè¿ã®å®è¡ã«é¢ããæ
å ±ãå«ãã§ããŸãã
ãã¡ã€ã«ãè§£æããã«ã¯ãããŒã«RecentFileCacheParseã䜿çšã§ããŸãã
ã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯
ãããã¯C:\Windows\TasksãŸãã¯C:\Windows\System32\Tasksããæœåºã§ããXMLãšããŠèªã¿åãããšãã§ããŸãã
ãµãŒãã¹
ãããã¯ã¬ãžã¹ããªã®SYSTEM\ControlSet001\Servicesã«èŠã€ããããšãã§ããŸããäœãå®è¡ããããããã€å®è¡ãããããèŠãããšãã§ããŸãã
Windows Store
ã€ã³ã¹ããŒã«ãããã¢ããªã±ãŒã·ã§ã³ã¯\ProgramData\Microsoft\Windows\AppRepository\ã«ãããŸãããã®ãªããžããªã«ã¯ãããŒã¿ããŒã¹**StateRepository-Machine.srdå
ã«ã·ã¹ãã ã«ã€ã³ã¹ããŒã«ãããåã¢ããªã±ãŒã·ã§ã³ã®ãã°**ããããŸãã
ãã®ããŒã¿ããŒã¹ã®ã¢ããªã±ãŒã·ã§ã³ããŒãã«å ã«ã¯ããApplication IDãããPackageNumberãããDisplay Nameããšããåãããããããã®åã«ã¯ãã¬ã€ã³ã¹ããŒã«ãããã¢ããªã±ãŒã·ã§ã³ãšã€ã³ã¹ããŒã«ãããã¢ããªã±ãŒã·ã§ã³ã«é¢ããæ å ±ãå«ãŸããŠãããã€ã³ã¹ããŒã«ãããã¢ããªã±ãŒã·ã§ã³ã®IDã¯é£ç¶ããŠãããããããã€ãã®ã¢ããªã±ãŒã·ã§ã³ãã¢ã³ã€ã³ã¹ããŒã«ããããã©ããã確èªã§ããŸãã
ã€ã³ã¹ããŒã«ãããã¢ããªã±ãŒã·ã§ã³ã¯ãã¬ãžã¹ããªãã¹Software\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\å
ã§ãèŠã€ããããšãã§ããŸãããŸããã¢ã³ã€ã³ã¹ããŒã«ãããã¢ããªã±ãŒã·ã§ã³ã¯Software\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deleted\ã«ãããŸãã
Windowsã€ãã³ã
Windowsã€ãã³ãã«è¡šç€ºãããæ å ±ã¯æ¬¡ã®ãšããã§ãïŒ
- äœãèµ·ãã£ãã
- ã¿ã€ã ã¹ã¿ã³ãïŒUTC + 0ïŒ
- é¢äžãããŠãŒã¶ãŒ
- é¢äžãããã¹ãïŒãã¹ãåãIPïŒ
- ã¢ã¯ã»ã¹ãããè³ç£ïŒãã¡ã€ã«ããã©ã«ããŒãããªã³ã¿ãŒããµãŒãã¹ïŒ
ãã°ã¯ãWindows Vista以åã¯C:\Windows\System32\configã«ãããWindows Vista以éã¯C:\Windows\System32\winevt\Logsã«ãããŸããWindows Vista以åã¯ã€ãã³ããã°ã¯ãã€ããªåœ¢åŒã§ããã以éã¯XML圢åŒã§ã.evtxæ¡åŒµåã䜿çšããŠããŸãã
ã€ãã³ããã¡ã€ã«ã®å Žæã¯ãSYSTEMã¬ãžã¹ããªã®**HKLM\SYSTEM\CurrentControlSet\services\EventLog\{Application|System|Security}**ã§èŠã€ããããšãã§ããŸãã
ãããã¯Windowsã€ãã³ããã¥ãŒã¢ïŒeventvwr.mscïŒãŸãã¯Event Log Explorer ã Evtx Explorer/EvtxECmdã䜿çšããŠèŠèŠåã§ããŸãã
Windowsã»ãã¥ãªãã£ã€ãã³ããã°ã®çè§£
ã¢ã¯ã»ã¹ã€ãã³ãã¯ãC:\Windows\System32\winevt\Security.evtxã«ããã»ãã¥ãªãã£æ§æãã¡ã€ã«ã«èšé²ãããŸãããã®ãã¡ã€ã«ã®ãµã€ãºã¯èª¿æŽå¯èœã§ã容éã«éãããšå€ãã€ãã³ããäžæžããããŸããèšé²ãããã€ãã³ãã«ã¯ããŠãŒã¶ãŒãã°ã€ã³ãšãã°ãªãããŠãŒã¶ãŒã¢ã¯ã·ã§ã³ãã»ãã¥ãªãã£èšå®ã®å€æŽããã¡ã€ã«ããã©ã«ããŒãããã³å
±æè³ç£ãžã®ã¢ã¯ã»ã¹ãå«ãŸããŸãã
ãŠãŒã¶ãŒèªèšŒã®ããã®äž»èŠãªã€ãã³ãIDïŒ
- EventID 4624: ãŠãŒã¶ãŒãæ£åžžã«èªèšŒãããããšã瀺ããŸãã
- EventID 4625: èªèšŒã®å€±æã瀺ããŸãã
- EventIDs 4634/4647: ãŠãŒã¶ãŒãã°ãªãã€ãã³ãã衚ããŸãã
- EventID 4672: 管çè æš©éã§ã®ãã°ã€ã³ã瀺ããŸãã
EventID 4634/4647å ã®ãµãã¿ã€ãïŒ
- ã€ã³ã¿ã©ã¯ãã£ã (2): çŽæ¥ãŠãŒã¶ãŒãã°ã€ã³ã
- ãããã¯ãŒã¯ (3): å ±æãã©ã«ããŒãžã®ã¢ã¯ã»ã¹ã
- ããã (4): ãããããã»ã¹ã®å®è¡ã
- ãµãŒãã¹ (5): ãµãŒãã¹ã®èµ·åã
- ãããã· (6): ãããã·èªèšŒã
- ã¢ã³ãã㯠(7): ãã¹ã¯ãŒãã§ç»é¢ãè§£é€ãããŸããã
- ãããã¯ãŒã¯ã¯ãªã¢ããã¹ã (8): IISããã®ã¯ãªã¢ããã¹ããã¹ã¯ãŒãã®éä¿¡ã
- æ°ããè³æ Œæ å ± (9): ã¢ã¯ã»ã¹ã®ããã«ç°ãªãè³æ Œæ å ±ã䜿çšã
- ãªã¢ãŒãã€ã³ã¿ã©ã¯ãã£ã (10): ãªã¢ãŒããã¹ã¯ããããŸãã¯ã¿ãŒããã«ãµãŒãã¹ã®ãã°ã€ã³ã
- ãã£ãã·ã¥ã€ã³ã¿ã©ã¯ãã£ã (11): ãã¡ã€ã³ã³ã³ãããŒã©ãŒã«é£çµ¡ããã«ãã£ãã·ã¥ãããè³æ Œæ å ±ã§ãã°ã€ã³ã
- ãã£ãã·ã¥ãªã¢ãŒãã€ã³ã¿ã©ã¯ãã£ã (12): ãã£ãã·ã¥ãããè³æ Œæ å ±ã§ã®ãªã¢ãŒããã°ã€ã³ã
- ãã£ãã·ã¥ã¢ã³ãã㯠(13): ãã£ãã·ã¥ãããè³æ Œæ å ±ã§ã®è§£é€ã
EventID 4625ã®ã¹ããŒã¿ã¹ããã³ãµãã¹ããŒã¿ã¹ã³ãŒãïŒ
- 0xC0000064: ãŠãŒã¶ãŒåãååšããªã - ãŠãŒã¶ãŒååææ»æã瀺ãå¯èœæ§ããããŸãã
- 0xC000006A: æ£ãããŠãŒã¶ãŒåã ããã¹ã¯ãŒããééã£ãŠãã - ãã¹ã¯ãŒãæšæž¬ãŸãã¯ãã«ãŒããã©ãŒã¹æ»æã®å¯èœæ§ã
- 0xC0000234: ãŠãŒã¶ãŒã¢ã«ãŠã³ããããã¯ã¢ãŠããããŠãã - è€æ°ã®å€±æãããã°ã€ã³ã«ç¶ããã«ãŒããã©ãŒã¹æ»æã®å¯èœæ§ã
- 0xC0000072: ã¢ã«ãŠã³ããç¡å¹ - ç¡å¹ãªã¢ã«ãŠã³ããžã®äžæ£ã¢ã¯ã»ã¹ã®è©Šã¿ã
- 0xC000006F: èš±å¯ãããæéå€ã®ãã°ãªã³ - èšå®ããããã°ã€ã³æéå€ã®ã¢ã¯ã»ã¹ã®è©Šã¿ã瀺ããäžæ£ã¢ã¯ã»ã¹ã®å¯èœæ§ããããŸãã
- 0xC0000070: ã¯ãŒã¯ã¹ããŒã·ã§ã³å¶éã®éå - äžæ£ãªå Žæããã®ãã°ã€ã³ã®è©Šã¿ã®å¯èœæ§ã
- 0xC0000193: ã¢ã«ãŠã³ãã®æå¹æéåã - æå¹æéåãã®ãŠãŒã¶ãŒã¢ã«ãŠã³ããžã®ã¢ã¯ã»ã¹ã®è©Šã¿ã
- 0xC0000071: ãã¹ã¯ãŒãã®æå¹æéåã - å€ããã¹ã¯ãŒãã§ã®ãã°ã€ã³ã®è©Šã¿ã
- 0xC0000133: æéåæã®åé¡ - ã¯ã©ã€ã¢ã³ããšãµãŒããŒéã®å€§ããªæéã®äžäžèŽã¯ããã¹ã»ã¶ã»ãã±ããã®ãããªããé«åºŠãªæ»æã瀺ãå¯èœæ§ããããŸãã
- 0xC0000224: 匷å¶çãªãã¹ã¯ãŒã倿Žãå¿ èŠ - é »ç¹ãªåŒ·å¶å€æŽã¯ãã¢ã«ãŠã³ãã»ãã¥ãªãã£ãäžå®å®ã«ããããšãã詊ã¿ã瀺åãããããããŸããã
- 0xC0000225: ã»ãã¥ãªãã£ã®åé¡ã§ã¯ãªããã·ã¹ãã ãã°ã瀺ããŸãã
- 0xC000015b: æåŠããããã°ãªã³ã¿ã€ã - ãµãŒãã¹ãã°ãªã³ãå®è¡ããããšãããŠãŒã¶ãŒãªã©ãäžæ£ãªãã°ãªã³ã¿ã€ãã§ã®ã¢ã¯ã»ã¹è©Šè¡ã
EventID 4616ïŒ
- æé倿Ž: ã·ã¹ãã æéã®å€æŽãã€ãã³ãã®ã¿ã€ã ã©ã€ã³ãé ãå¯èœæ§ããããŸãã
EventID 6005ããã³6006ïŒ
- ã·ã¹ãã ã®èµ·åãšã·ã£ããããŠã³: EventID 6005ã¯ã·ã¹ãã ã®èµ·åã瀺ããEventID 6006ã¯ã·ã£ããããŠã³ã瀺ããŸãã
EventID 1102ïŒ
- ãã°åé€: ã»ãã¥ãªãã£ãã°ãã¯ãªã¢ãããããšã¯ãéæ³è¡çºãé èœããããã®èµ€ä¿¡å·ã§ãã
USBããã€ã¹ãã©ããã³ã°ã®ããã®ã€ãã³ãIDïŒ
- 20001 / 20003 / 10000: USBããã€ã¹ã®æåã®æ¥ç¶ã
- 10100: USBãã©ã€ããŒã®æŽæ°ã
- EventID 112: USBããã€ã¹æ¿å ¥ã®æéã
ãããã®ãã°ã€ã³ã¿ã€ããè³æ Œæ å ±ãã³ãã®æ©äŒãã·ãã¥ã¬ãŒãããå®çšçãªäŸã«ã€ããŠã¯ãAltered Securityã®è©³çްã¬ã€ããåç §ããŠãã ããã
ã€ãã³ãã®è©³çްãã¹ããŒã¿ã¹ããã³ãµãã¹ããŒã¿ã¹ã³ãŒãã¯ãç¹ã«Event ID 4625ã§ã®ã€ãã³ãã®åå ã«é¢ãããããªãæŽå¯ãæäŸããŸãã
Windowsã€ãã³ãã®å埩
åé€ãããWindowsã€ãã³ããå埩ããå¯èœæ§ãé«ããããã«ãçãããã³ã³ãã¥ãŒã¿ã®é»æºãçŽæ¥æããŠã·ã£ããããŠã³ããããšããå§ãããŸããBulk_extractorã¯ã.evtxæ¡åŒµåãæå®ããå埩ããŒã«ã§ããããã®ãããªã€ãã³ããå埩ããããšããéã«æšå¥šãããŸãã
Windowsã€ãã³ããéããŠäžè¬çãªæ»æãç¹å®ãã
äžè¬çãªãµã€ããŒæ»æãç¹å®ããããã«Windowsã€ãã³ãIDãå©çšããå æ¬çãªã¬ã€ãã«ã€ããŠã¯ãRed Team Recipeã蚪ããŠãã ããã
ãã«ãŒããã©ãŒã¹æ»æ
è€æ°ã®EventID 4625ã¬ã³ãŒãã«ãã£ãŠèå¥ãããæ»æãæåããå Žåã¯EventID 4624ãç¶ããŸãã
æé倿Ž
EventID 4616ã«ãã£ãŠèšé²ãããã·ã¹ãã æéã®å€æŽã¯ãã©ã¬ã³ãžãã¯åæãè€éã«ããå¯èœæ§ããããŸãã
USBããã€ã¹ãã©ããã³ã°
USBããã€ã¹ãã©ããã³ã°ã«åœ¹ç«ã€ã·ã¹ãã ã€ãã³ãIDã«ã¯ãåå䜿çšã®ããã®20001/20003/10000ããã©ã€ããŒæŽæ°ã®ããã®10100ãæ¿å ¥ã¿ã€ã ã¹ã¿ã³ãã®ããã®EventID 112ãå«ãŸããŸãã
ã·ã¹ãã 黿ºã€ãã³ã
EventID 6005ã¯ã·ã¹ãã ã®èµ·åã瀺ããEventID 6006ã¯ã·ã£ããããŠã³ã瀺ããŸãã
ãã°åé€
ã»ãã¥ãªãã£EventID 1102ã¯ãã°ã®åé€ã瀺ãããã©ã¬ã³ãžãã¯åæã«ãšã£ãŠéèŠãªã€ãã³ãã§ãã
Tip
AWSãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training AWS Red Team Expert (ARTE)
GCPãããã³ã°ãåŠã³ãå®è·µããïŒHackTricks Training GCP Red Team Expert (GRTE)
Azureãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training Azure Red Team Expert (AzRTE)
HackTricksããµããŒããã
- ãµãã¹ã¯ãªãã·ã§ã³ãã©ã³ã確èªããŠãã ããïŒ
- **ð¬ Discordã°ã«ãŒããŸãã¯ãã¬ã°ã©ã ã°ã«ãŒãã«åå ããããTwitter ðŠ @hacktricks_liveããã©ããŒããŠãã ããã
- HackTricksããã³HackTricks Cloudã®GitHubãªããžããªã«PRãæåºããŠãããã³ã°ããªãã¯ãå ±æããŠãã ããã


