12.07.2013 Views

SIFT WORKSTATION - SANS Computer Forensics - SANS Institute

SIFT WORKSTATION - SANS Computer Forensics - SANS Institute

SIFT WORKSTATION - SANS Computer Forensics - SANS Institute

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

MEMORY ANALYSIS<br />

<br />

Supported commands<br />

<br />

Scan for connection objects<br />

<br />

list of open les process<br />

Convert hibernation le<br />

Dump process<br />

<br />

list of running processes<br />

Scan for socket objects<br />

<br />

Proles<br />

VistaSP0x86 - A Prole for Windows Vista SP0 x86<br />

VistaSP1x86 - A Prole for Windows Vista SP1 x86<br />

VistaSP2x86 - A Prole for Windows Vista SP2 x86<br />

Win2K8SP1x86 - A Prole for Windows 2008 SP1 x86<br />

Cheat Sheet<br />

RECOVER DELETED REGISTRY KEYS<br />

<br />

<br />

<br />

<br />

RECOVERING DATA<br />

Create Unallocated Image (deleted data) using <br />

<br />

Create Slack Image Using dls (for FAT and NTFS)<br />

<br />

Foremost Carves out les based on headers and footers<br />

= raw data, slack space, memory, unallocated space<br />

<br />

Signd - search for a binary value at a given oset (-o)<br />

start search at byte<br />

<br />

SLEUTHKIT TOOLS<br />

File System Layer Tools (Partition Information)<br />

fsstat Displays details about the le system <br />

Data Layer Tools (Block or Cluster)<br />

blkcat Displays the contents of a disk block <br />

blkls Lists contents of deleted disk blocks <br />

blkcalc Maps between dd images and blkls results <br />

blkstat Display allocation status of block <br />

MetaData Layer Tools (Inode, MFT, or Directry Entry)<br />

ils Displays inode details <br />

istat Displays information about a specic inode <br />

icat Displays contents of blocks allocated to an inode <br />

ind Determine which inode contains a specic block <br />

Filename Layer Tools<br />

Win2K8SP2x86 - A Prole for Windows 2008 SP2 x86<br />

Win7SP0x86 - A Prole for Windows 7 SP0 x86<br />

WinXPSP2x86 - A Prole for Windows XP SP2<br />

WinXPSP3x86 - A Prole for windows XP SP3<br />

s Displays deleted le entries in a directory inode <br />

nd Find the lename that using the inode <br />

18<br />

@sansforensics http://computer-forensics.sans.org/blog

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!