Windows取证分析基础 |
您所在的位置:网站首页 › db-wal文件解析 › Windows取证分析基础 |
windows 时间规则
1)internet explorer IE8-9: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\index.dat IE10-11: %USERPROFILE%\AppData\Local\Microsoft\Windows\WebCache\WebCacheV*.dat2)firefox v3-25: %userprofile%\AppData\Roaming\Mozilla\ Firefox\Profiles\.default\downloads.sqlite v26+: %userprofile%\AppData\Roaming\Mozilla\ Firefox\Profiles\.default\places.sqlite Table:moz_annos3)chrome Win7/8/10: %USERPROFILE%\AppData\Local\Google\Chrome\User Data\Default\History 下载(firefox,internet Explorer)管理器1)firefox XP: %userprofile%\Application Data\Mozilla\ Firefox\Profiles\.default\downloads.sqlite Win7/8/10: %userprofile%\AppData\Roaming\Mozilla\ Firefox\Profiles\.default\downloads.sqlite2)Internet Explorer IE8-9: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\ IEDownloadHistory\ IE10-11: %USERPROFILE%\AppData\Local\Microsoft\Windows\WebCache\ WebCacheV*.dat ADS Zone.Identifier(备用数据流)从XP SP2开始,当文件通过浏览器从“Internet区域”下载到NTFS卷时,会向文件中添加备用数据流。 程序执行1)Internet Explorer IE6-7: %USERPROFILE%\Local Settings\History\History.IE5 IE8-9: %USERPROFILE%\AppData\Local\Microsoft\Windows\History\ History.IE5 IE10, 11, Edge: %USERPROFILE%\AppData\Local\Microsoft\Windows\ WebCache\WebCacheV*.dat2)Firefox XP: %USERPROFILE%\Application Data\Mozilla\Firefox\Profiles\.default\places.sqlite Win7/8/10: %USERPROFILE%\AppData\Roaming\Mozilla\Firefox\ Profiles\.default\places.sqlite3)Chrome XP: %USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default\History Win7/8/10: %USERPROFILE%\AppData\Local\Google\Chrome\User Data\ Default\History4)QQ浏览器 %USERPROFILE%\AppData\Local\Tencent\QQBrowser\User Data\Default\History 书签信息1)Internet Explorer HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders下Favorites键值 Edge: %USERPROFILE%\AppData\Local\Packages\microsoft. microsoftedge_\AC\MicrosoftEdge\Cookies2)Firefox XP: %USERPROFILE%\Application Data\Mozilla\Firefox\Profiles\.default\places.sqlite Win7/8/10: %USERPROFILE%\AppData\Roaming\Mozilla\Firefox\ Profiles\.default\places.sqlite3)Chrome XP: %USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default\Bookmarks Win7/8/10: %USERPROFILE%\AppData\Local\Google\Chrome\User Data\ Default\Bookmarks4)QQ浏览器 %USERPROFILE%\AppData\Local\Tencent\QQBrowser\User Data\Default\QQ号\Bookmarks_01 %USERPROFILE%\AppData\Local\Tencent\QQBrowser\User Data\Default\Bookmarks_01 cookies1)Internet Explorer IE8-9: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Cookies IE10: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Cookies IE11: %USERPROFILE%\AppData\Local\Microsoft\Windows\INetCookies Edge: %USERPROFILE%\AppData\Local\Packages\microsoft. microsoftedge_\AC\MicrosoftEdge\Cookies2)Firefox XP: %USERPROFILE%\Application Data\Mozilla\Firefox\Profiles\.default\cookies.sqlite Win7/8/10: %USERPROFILE%\AppData\Roaming\Mozilla\Firefox\ Profiles\.default\cookies.sqlite3)Chrome XP: %USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\ Win7/8/10: %USERPROFILE%\AppData\Local\Google\Chrome\User Data\ Default\Local Storage\4)QQ浏览器 %USERPROFILE%\AppData\Local\Tencent\QQBrowser\User Data\Default\Cookies 缓存1)Internet Explorer IE8-9: %USERPROFILE%\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 IE10: %USERPROFILE%\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 IE11: %USERPROFILE%\AppData\Local\Microsoft\Windows\INetCache\IE Edge: %USERPROFILE%\AppData\Local\Packages\microsoft.microsoftedge_\AC\MicrosoftEdge\Cache2)Firefox XP: %USERPROFILE%\Local Settings\ApplicationData\Mozilla\Firefox\ Profiles\.default\Cache Win7/8/10: %USERPROFILE%\AppData\Local\Mozilla\Firefox\ Profiles\.default\Cache3)Chrome XP: %USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache - data_# and f_###### Win7/8/10: %USERPROFILE%\AppData\Local\Google\Chrome\User Data\ Default\Cache\ - data_# and f_###### flash和超级cookies Win7/8/10: %APPDATA%\Roaming\Macromedia\FlashPlayer\#SharedObjects\ 会话还原1)Internet Explorer Win7/8/10: %USERPROFILE%/AppData/Local/Microsoft/Internet Explorer/ Recovery2)Firefox Win7/8/10: %USERPROFILE%\AppData\Roaming\Mozilla\Firefox\Profiles\.default\sessionstore.js3)Chrome Win7/8/10: %USERPROFILE%\AppData\Local\Google\Chrome\User Data\ Default\ ## 文件=当前会话,当前打开的标签,最后一次会话,最后的标签 外部设备/USB使用1)即插即用日志文件(第一次) XP: C:\Windows\setupapi.log Win7/8/10: C:\Windows\inf\setupapi.dev.log2)(第一次,最后一次,拔出)(在Win7/8/10) System Hive: \CurrentControlSet\Enum\USBSTOR\Ven_Prod_Version\USBSerial#\Properties\ {83da6326-97a6-4088-9453-a19231573b29}\#### 0064 = 第一次安装(Win7-10) 0066 = 最后一次连接 (Win8-10) 0067 = 最后一次拔出 (Win8-10) 用户 查找GUID从SYSTEM\MountedDevices NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ MountPoints2 pnP 事件 Win7/8/10: %system root%\System32\winevt\logs\System.evtx 卷序列号 SOFTWARE\Microsoft\WindowsNT\CurrentVersion\ ENDMgmt 驱动器号和卷名 XP: 找到ParentIdPrefix – SYSTEM\CurrentControlSet\Enum\ USBSTOR Win7/8/10: SOFTWARE\Microsoft\Windows Portable Devices\Devices SYSTEM\MountedDevices 文件快捷方式(LNK) XP: %USERPROFILE%\Recent Win7/8/10: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\ Recent %USERPROFILE%\AppData\Roaming\Microsoft\Office\Recent 账户使用情况1)Internet Explorer IE6-8: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Cookies IE10: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Cookies IE11: %USERPROFILE%\AppData\Local\Microsoft\Windows\InetCookies2)Firefox XP: %USERPROFILE%\Application Data\Mozilla\Firefox\Profiles\.default\ cookies.sqlite Win7/8/10: %USERPROFILE%\AppData\Roaming\Mozilla\Firefox\Profiles\.default\cookies.sqlite3)Chrome XP: %USERPROFILE%\Local Settings\ApplicationData\Google\Chrome\User Data\Default\ Local Storage Win7/8/10: %USERPROFILE%\AppData\Local\Google\Chrome\User Data\Default\Local Storage 网络历史 Win7/8/10 SOFTWARE HIVE: • SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged • SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Managed • SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Nla\Cache 无线局域网事件日志 Microsoft-Windows-WLAN-AutoConfig Operational.evtx 浏览器搜索记录 Internet Explorer IE6-7: %USERPROFILE%\Local Settings\History\History.IE5 IE8-9: %USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5 IE10-11: %USERPROFILE%\AppData\Local\Microsoft\Windows\WebCache\WebCacheV*.dat Firefox XP: %userprofile%\Application Data\Mozilla\Firefox\Profiles\.default\places.sqlite Win7/8/10: %userprofile%\AppData\Roaming\Mozilla\Firefox\Profiles\.default\places.sqlite 系统资源利用率管理器(SRUM)(无线网络) • SOFTWARE\Microsoft\WindowsNT\CurrentVersion\SRUM\Extensions • {973F5D5C-1D90-4944-BE8E-24B94231A174} = Windows Network Data Usage Monitor • {DD6636C4-8929-4683-974E-22C046A43763} = Windows Network Connectivity Usage Monitor • SOFTWARE\Microsoft\WlanSvc\Interfaces\ C:\Windows\System32\SRU\本文转自公众号:效率源 原文地址:https://mp.weixin.qq.com/s/NKHbVSFdHGrdDu-Gd3F_Hw |
今日新闻 |
推荐新闻 |
CopyRight 2018-2019 办公设备维修网 版权所有 豫ICP备15022753号-3 |