Upgrade to Pro — share decks privately, control downloads, hide ads and more …

SRUM Forensics

SRUM Forensics

Delving into the world of SRUM forensics.

Avatar for Veronica Schmitt

Veronica Schmitt

October 26, 2018
Tweet

More Decks by Veronica Schmitt

Other Decks in Technology

Transcript

  1. • Timestamps are in UTC in OLE format (64 bits)

    and FILETIME format (64 bits) • Network interfaces are specified as InterfaceLuid (NET_LUID)
  2. • Prefetch only retains last 8 start times, no record

    of prior runs • SRUM can tell you if an app was run or not
  3. • Utorrent and Ares downloading. • Network connected to and

    total downloads. • TOR being used • Veracrypt • Ccleaner being run. • OpenVPN being used • Skype Activity • Viber Chat Activity