Windows SRUM Forensics

Поділитися
Вставка
  • Опубліковано 25 лип 2024
  • As a continuation of the "Introduction to Windows Forensics" series, this video introduces the System Resource Utilization Monitor (SRUM). This artifact is often left unmentioned by many forensics books and online resources. SRUM was first introduced in Windows 8, and was a new feature designed to track system resource utilization such as CPU cycles, network activity, power consumption, etc. We can use the data collected by SRUM to paint a picture of a user’s activity, and even correlate that activity with network-related events, data transfer, processes, and more.
    Introduction to Windows Forensics:
    • Introduction to Window...
    System Resource Utilization Monitor:
    isc.sans.edu/forums/diary/Sys...
    srum-dump:
    github.com/MarkBaggett/srum-dump
    SRUM Forensics (Yogesh Khatri, Champlain College):
    www.sans.org/summit-archives/...
    #Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics
  • Наука та технологія

КОМЕНТАРІ • 23

  • @glassfrog3
    @glassfrog3 7 років тому

    Thanks Richard for another great video. This is an artefact I wasn't actually familiar with so your explanations are very helpful! I will definitely take your advice and do some further research, thanks for the links

  • @user-good_day_
    @user-good_day_ 5 років тому +3

    Thank you for greate SRUM tutorial

  • @mdyousufuddin
    @mdyousufuddin 2 роки тому +2

    It was very useful. Excellent. Any video on Windows Sandbox Forensics

    • @13Cubed
      @13Cubed  2 роки тому

      Not yet - but that's on my suggestion list.

  • @jamiekomodo1751
    @jamiekomodo1751 3 роки тому +2

    OK video for general procedure. I have to say, though, that I can't see what is being typed in those dark screens with small fonts, and I'm on a desktop too -- not mobile device. I know I can just review the tools command line, but if you're going to be making demo videos and you have a high resolution screen, you might want to zoom in or make cmd window large enough to see. Just a suggestion.

    • @13Cubed
      @13Cubed  3 роки тому +1

      This is a very old episode. You'll find that the production quality has greatly increased for newer ones.

    • @CM-tw2oj
      @CM-tw2oj 2 роки тому +1

      Change video res to HD and this issue is fixed.

  • @zelenko2064
    @zelenko2064 3 роки тому

    how did you manage to put these files like "SAM" or "SYSTEM"
    please

  • @samjohn1098
    @samjohn1098 Рік тому

    Nice one, quick question how do we identify to which IP or Domain name the nc.exe moved the data ?

    • @13Cubed
      @13Cubed  Рік тому

      You'd have to grab that information from netstat, and match up the PID of the nc.exe process (assuming it's active at the time). Or, you could potentially extract that information from a memory capture of the machine with a Volatility plugin like netscan.

  • @matteov.7072
    @matteov.7072 6 років тому

    Hi I use Windows 10, can you Explain to me why in all sheets my User SID are NONE?

  • @TheMindfulEdge1
    @TheMindfulEdge1 Рік тому

    How do you convert the BytesOutBound to more readable format. e.g. Mb, Gb ?

    • @13Cubed
      @13Cubed  Рік тому

      You could apply an Excel formula to divide the bytes by 1,048,576. This would convert it to MB, as that's the exact number of bytes in a megabyte.

  • @mouadzehari1724
    @mouadzehari1724 Рік тому +1

    In my case i can simply copy paste the file (tested in Windows 10&11)

  • @0Trance0
    @0Trance0 Рік тому

    Any idea what foreground CPU time is in? Is that seconds ?!?

    • @13Cubed
      @13Cubed  Рік тому

      It's milliseconds (ms), as I recall.

  • @robertboles7418
    @robertboles7418 5 років тому

    Nerd alert if you laughed out loud (1/2 point if you snorted,) at this spot.
    ua-cam.com/video/Uw8n4_o-ETM/v-deo.html
    Ok. Ok. Guilty.

  • @cdielearn3710
    @cdielearn3710 10 місяців тому

    its very bad quality and not handy for study

    • @13Cubed
      @13Cubed  10 місяців тому

      It's 2.5K QHD resolution with clear audio. Admittedly, the text isn't nearly big enough, but that was an earlier video and I was still learning the process. But, hey, thanks for the feedback!

    • @AlistairEwingforensic-services
      @AlistairEwingforensic-services Місяць тому

      V
      Change the quality using the cog icon numbnuts; don't blame this guy for making free content.

  • @tunivol6626
    @tunivol6626 Рік тому +1

    i simply used ROBOCOPY to copy the file with the /B specified .

    • @13Cubed
      @13Cubed  Рік тому

      Interesting -- I had not tried that. Thanks for sharing!