Upgrade to Pro — share decks privately, control downloads, hide ads and more …

SRUM Forensics

SRUM Forensics

Delving into the world of SRUM forensics.

Veronica Schmitt

October 26, 2018
Tweet

More Decks by Veronica Schmitt

Other Decks in Technology

Transcript

  1. • Timestamps are in UTC in OLE format (64 bits)

    and FILETIME format (64 bits) • Network interfaces are specified as InterfaceLuid (NET_LUID)
  2. • Prefetch only retains last 8 start times, no record

    of prior runs • SRUM can tell you if an app was run or not
  3. • Utorrent and Ares downloading. • Network connected to and

    total downloads. • TOR being used • Veracrypt • Ccleaner being run. • OpenVPN being used • Skype Activity • Viber Chat Activity