Professional Documents
Culture Documents
: (junghmi@korea.ac.kr)
1. Registry Forensics 2. Shellbag Information 3. Experimental Analysis of Shellbag updating
4. Causality between User actions & Shellbag updating
Registry Forensics
3/28
1. Registry Forensics
Registry Forensics
Registry
, , , ,
Registry
Restore Point Registry Snapshot !
Registry
Papers (2009)
Identifying newly updated data values of MRU Keys between registry snapshots
Fifth annual IFIP WG 11.9 international conference on digital forensics
A comparative methodology for the reconstruction of digital events using Windows Restore Points
Digital Investigation
Authors
Yuandong Zhu, Pavel Gladyshev, Joshua James Center for Cybercrime Investigation, University College Dublin, Ireland
Digital Forensic Research Center
4/28
Shellbag Information
5/28
2. Shellbag Information
Shellbag
, (window) ,
6/28
2. Shellbag Information
Shellbag
2000, XP, 2003
HKCU\Software\Microsoft\Windows\Shell HKCU\Software\Microsoft\Windows\ShellNoRoam
Vista, 7
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell
7/28
2. Shellbag Information
(Desktop)
[Programs] Test
Modification
Creation
LastAccess 5000
8/28
2. Shellbag Information
CLSID List (Windows Class Identifiers)
9/28
2. Shellbag Information
Shellbag Cleaner ?
10/28
2. Shellbag Information
11/28
2. Shellbag Information
Folders MRU Key Folders MRU Item Folders Display Key
12/28
13/28
Yes
Yes
Close
Yes
No
Open
Yes
No
Close
No
Both
Open
No
Both
Close
Results
Experiment 9 (Closing a folder when the registry contain the MAX(5000) of Display keys)
Shellbag ? No Desktop Folder ? Both User Actions Close Results
- Update target folders and all parent folders MRUListEx value - NodeSlot value = 1 (Bags\1\Shell)
15/28
16/28
17/28
18/28
4
(existing) Shellbag MRU item () , MRU key, MRU item, Display key
19/28
20/28
Rule 2
A folders Display key was created or updated A folder type 2
Rule 3
A folders MRU key, MRU item, Display key X Type 2 was never occurred on A folder !
Rule 4
A folders MRU items position As parent folders items position
21/28
Rule 6
snapshot A folders MRU keys timestamp MRU items position X The first items position
Rule 7
snapshot A folders MRU keys timestamp MRU items position (, fitst item )
Rule 8
snapshot A folders MRU keys values , timestamp MRU items position
Digital Forensic Research Center
22/28
23/28
Case Study
24/28
6. Case Study
25/28
Conclusion
26/28
7. Conclusion
Shellbag Information 9 Rule TraceHunter (http://tracehunter.com/)
Windows XP
Digital Forensic Research Center
27/28
Q&A
28/28