[๋ฌธ์ ]
https://tryhackme.com/r/room/windowsforensics1
[๋ฌธ์ ํ์ด]
Task 1) Introduction to Computer Forensics for Windows
What is the most used Desktop Operationg System right now?
๋ต) Microsoft Windows
Task 2) Windows Registry and Forensics
What is the short form for HKEY_LOCAL_MACHINE?
๋ต) HKLM
Task3) Accessing registry hives offline
What is the path for the five main registry hives, DEFAULT, SAM, SECURITY, SOFTWARE, and SYSTEM?
๋ต) C:\Windows\System32\Config
What is the path for the AmCache hive?
๋ต) C:\Windows\AppCompat\Programs\Amcache.hve
Task 6) System Information and System Accounts
What is the Current Build Number of the machine whose data is being investigated?
๋ต: 19044
Which ControlSet contains the last known good configuration?
๋ต: 1
What is the Computer Name of the computer?
๋ต: THM-4N6
What is the value of the TimeZoneKeyName?
๋ต: Pakistan Standard Time
What is the DHCP IP address
๋ต: 192.168.100.58
What is the RID of the Guest User account?
๋ต: 501
Task 7) Usage or knowledge of files/folders
When was EZtools opened?
๋ต: 2021-15-01 13:00:34
At what time was My Computer last interacted with?
๋ต: 2021-12-01 13:06:47
What is the Absolute Path of the file opened using notepad.exe?
๋ต: C:\Program Files\Amazon\Ec2ConfigService\Settings
When was this file opened?
๋ต: 2021-11-30 10:56:19
Task 8) Evidence of Execution
How many times was the File Explorer launched?
๋ต: 26
What is another name for ShimCache?
๋ต: AppCompatCache
Which of the artifacts also saves SHA1 hashes of the executed programs?
๋ต: AmCache
Which of the artifacts saves the full path of the executed programs?
๋ต: BAM/DAM
Task 9) External Devices/USB device forensics
What is the serial number of the device from the manufacturer 'Kingston'?
๋ต: 1C6f654E59A3B0C179D366AE&0
What is the name of this device?
๋ต: Kingston Data Traveler 2.0 USB Device
What is the friendly name of the device from the manufacturer 'Kingston'?
๋ต: USB
Task 10) Hands-on Challenge
- ๋จผ์ RegistryExplorer์ run as administrator๋ก ํด์ ์คํํ๋ค.
- ๊ทธ๋ค์ C:\Windows\System32\Config ๋๋ ํฐ๋ฆฌ์์ SAM, SOFTWARE, SYSTEM์ ๋ก๋ํด์ผ ํ๋ค.
- SOFTWARE๋ SYSTEM์ ๋ก๋๋ฅผ ํ๋ผ๊ณ ํ๋ฉด "Dirty hive detected" ํ์ ์ด ๋จ๋ฉด "no"๋ฅผ ์ ํํ๊ณ "replay transaction logs against this hive" ํ์ ์ด ๋จ๋ฉด "yes"๋ฅผ ์ ํํ๋ค.
- ๊ทธ๋ค์ 1~3๋ฒ ๋ฌธ์ ๋ฅผ ํ๊ธฐ ์ํด SAM์์ Users ๊ฒฝ๋ก๋ฅผ ํ์ธํ์ต๋๋ค.
How many user create accounts are present on the system?
๋ต: 3
What is the username of the account that has never been logged in?
๋ต: thm-user2
What's the password hint for the user THM-4n6?
๋ต: count
* ์๋ ๋ฌธ์ ๋ค์ ๋ค์์ ์ด์ด์...
When was the file 'Changelog.txt' accessed?
What is the complete path from where the python 3.8.2 installer was run?
When was the USB device with the friendly name 'USB' last connected?