Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
SRUM Forensics
Search
Sponsored
·
Ship Features Fearlessly
Turn features on and off without deploys. Used by thousands of Ruby developers.
→
Veronica Schmitt
October 26, 2018
Technology
0
660
SRUM Forensics
Delving into the world of SRUM forensics.
Veronica Schmitt
October 26, 2018
Tweet
Share
More Decks by Veronica Schmitt
See All by Veronica Schmitt
The Autopsy of the PHOENIX X36 Hemodialysis System
velandra666
2
1.1k
Other Decks in Technology
See All in Technology
Bill One 開発エンジニア 紹介資料
sansan33
PRO
5
18k
Escape from Excel方眼紙 ~マークダウンで繋ぐ、人とAIの架け橋~ /nikkei-tech-talk44
nikkei_engineer_recruiting
0
190
AIエージェント勉強会第3回 エージェンティックAIの時代がやってきた
ymiya55
0
100
LLMに何を任せ、何を任せないか
cap120
10
4.1k
品質を経営にどう語るか #jassttokyo / Communicating the Strategic Value of Quality to Executive Leadership
kyonmm
PRO
3
1.2k
Phase03_ドキュメント管理
overflowinc
0
2.3k
AI時代のIssue駆動開発のススメ
moongift
PRO
0
150
Phase09_自動化_仕組み化
overflowinc
0
1.5k
ABEMAのバグバウンティの取り組み
kurochan
1
610
Phase06_ClaudeCode実践
overflowinc
0
1.8k
データマネジメント戦略Night - 4社のリアルを語る会
ktatsuya
1
210
Goのerror型がシンプルであることの恩恵について理解する
yamatai1212
1
300
Featured
See All Featured
Sam Torres - BigQuery for SEOs
techseoconnect
PRO
0
220
Abbi's Birthday
coloredviolet
2
5.6k
The Limits of Empathy - UXLibs8
cassininazir
1
270
Become a Pro
speakerdeck
PRO
31
5.9k
Let's Do A Bunch of Simple Stuff to Make Websites Faster
chriscoyier
508
140k
The SEO Collaboration Effect
kristinabergwall1
0
400
A brief & incomplete history of UX Design for the World Wide Web: 1989–2019
jct
1
330
How To Speak Unicorn (iThemes Webinar)
marktimemedia
1
410
Distributed Sagas: A Protocol for Coordinating Microservices
caitiem20
333
22k
The World Runs on Bad Software
bkeepers
PRO
72
12k
New Earth Scene 8
popppiees
1
1.8k
Leading Effective Engineering Teams in the AI Era
addyosmani
9
1.8k
Transcript
Veronica Schmitt
whoami Veronica Schmitt P01z0n_P1x13 Slides Published online: • https://medium.com/ •
@P01z0n_P1x13 •
[email protected]
• www.dfirlabs.com
None
What does it monitor? 1 3 5 2 4
• • • • • • •
NOT AVAILABLE
None
None
None
SRUM Energy Usage (Long Term)
None
None
None
None
• Timestamps are in UTC in OLE format (64 bits)
and FILETIME format (64 bits) • Network interfaces are specified as InterfaceLuid (NET_LUID)
None
None
Prefetch file records start time of process, not duration
• Prefetch only retains last 8 start times, no record
of prior runs • SRUM can tell you if an app was run or not
None
Downloads to Ares and Utorrent and he was running OpenVPN
Application Resource Manager
None
None
Energy Usage
Well, what did we find...
• Utorrent and Ares downloading. • Network connected to and
total downloads. • TOR being used • Veracrypt • Ccleaner being run. • OpenVPN being used • Skype Activity • Viber Chat Activity
Using srum-dump-master https://github.com/MarkBaggett/srum-dump LET'S DO THIS
None