SIFT WORKSTATION - SANS Computer Forensics - SANS Institute
SIFT WORKSTATION - SANS Computer Forensics - SANS Institute
SIFT WORKSTATION - SANS Computer Forensics - SANS Institute
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
MEMORY ANALYSIS<br />
<br />
Supported commands<br />
<br />
Scan for connection objects<br />
<br />
list of open les process<br />
Convert hibernation le<br />
Dump process<br />
<br />
list of running processes<br />
Scan for socket objects<br />
<br />
Proles<br />
VistaSP0x86 - A Prole for Windows Vista SP0 x86<br />
VistaSP1x86 - A Prole for Windows Vista SP1 x86<br />
VistaSP2x86 - A Prole for Windows Vista SP2 x86<br />
Win2K8SP1x86 - A Prole for Windows 2008 SP1 x86<br />
Cheat Sheet<br />
RECOVER DELETED REGISTRY KEYS<br />
<br />
<br />
<br />
<br />
RECOVERING DATA<br />
Create Unallocated Image (deleted data) using <br />
<br />
Create Slack Image Using dls (for FAT and NTFS)<br />
<br />
Foremost Carves out les based on headers and footers<br />
= raw data, slack space, memory, unallocated space<br />
<br />
Signd - search for a binary value at a given oset (-o)<br />
start search at byte<br />
<br />
SLEUTHKIT TOOLS<br />
File System Layer Tools (Partition Information)<br />
fsstat Displays details about the le system <br />
Data Layer Tools (Block or Cluster)<br />
blkcat Displays the contents of a disk block <br />
blkls Lists contents of deleted disk blocks <br />
blkcalc Maps between dd images and blkls results <br />
blkstat Display allocation status of block <br />
MetaData Layer Tools (Inode, MFT, or Directry Entry)<br />
ils Displays inode details <br />
istat Displays information about a specic inode <br />
icat Displays contents of blocks allocated to an inode <br />
ind Determine which inode contains a specic block <br />
Filename Layer Tools<br />
Win2K8SP2x86 - A Prole for Windows 2008 SP2 x86<br />
Win7SP0x86 - A Prole for Windows 7 SP0 x86<br />
WinXPSP2x86 - A Prole for Windows XP SP2<br />
WinXPSP3x86 - A Prole for windows XP SP3<br />
s Displays deleted le entries in a directory inode <br />
nd Find the lename that using the inode <br />
18<br />
@sansforensics http://computer-forensics.sans.org/blog