log2timeline Since 2009 - SANS
log2timeline Since 2009 - SANS
log2timeline Since 2009 - SANS
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
<strong>SANS</strong> 2011 Digital Forensics and Incident Response Summit<br />
The old method<br />
timescanner z ZONE d MNTPOINT w BODYFILE<br />
fls r m C: IMAGE >> BODYFILE<br />
regtime.pl m HKLM-SYSTEM r<br />
MNTPOINT/WINDOWS/System32/config/system >> BODYFILE<br />
regtime.pl m HKLM-SAM r<br />
MNTPOINT/WINDOWS/System32/config/SAM>> BODYFILE<br />
regtime.pl m HKLM-SECURITYr<br />
MNTPOINT/WINDOWS/System32/config/SECURITY >> BODYFILE<br />
regtime.pl m HKLM-SOFTWAREr<br />
MNTPOINT/WINDOWS/System32/config/software >> BODYFILE<br />
mactime d b BODYYFILE z ZONE DATE_RANGE > CSVFILE