daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

forensics.md (72902B)


      1 ---
      2 title: "Digital Forensics"
      3 description: "Cross-platform DFIR reference: acquisition, triage, artifacts, timelines and analysis commands."
      4 category: dfir
      5 tags: [dfir, forensics, incident-response]
      6 tools: [Autopsy, Sleuth Kit, plaso]
      7 difficulty: intermediate
      8 updated: "2026-08-09"
      9 source: "vault:DFIR/Forensics Cheatsheet.md"
     10 ---
     11 
     12 # Digital Forensics
     13 
     14 ---
     15 
     16 > **Note β€”** - πŸ“‹ Quick Reference Cheat Sheet
     17 > 
     18 > **Comprehensive forensic tool commands and workflows for Windows incident response.**
     19 > 
     20 > | # | Tool | Primary Use Case | Key Command | Notes |
     21 > |:--|:---|:---|:---|:---|
     22 > | 1 | **Volatility 3** | Memory forensics | `vol3 -f mem.bin windows.malfind` | Code injection detection |
     23 > | 2 | **MemProcFS** | Memory virtual filesystem | `memprocfs.exe -device mem.bin -forensic 1` | Browse memory as files |
     24 > | 3 | **CAPA** | Malware capability detection | `capa malware.exe` | Identifies malware behaviours |
     25 > | 4 | **YARA** | Pattern matching | `yara -r rules.yar directory/` | Signature-based detection |
     26 > | 5 | **PECmd** | Prefetch parsing | `PECmd.exe -d prefetch_dir --csv output/` | Execution evidence |
     27 > | 6 | **EvtxECmd** | Event log parsing | `EvtxECmd.exe -f Security.evtx --csv output/` | Windows event logs |
     28 > | 7 | **RECmd** | Registry parsing | `RECmd.exe -f SOFTWARE --bn batch.reb --csv output/` | Registry hive analysis |
     29 > | 8 | **AppCompatCacheParser** | ShimCache parsing | `AppCompatCacheParser.exe -f SYSTEM --csv output/` | Execution history |
     30 > | 9 | **AmcacheParser** | Amcache parsing | `AmcacheParser.exe -f Amcache.hve --csv output/` | SHA1 hashes + paths |
     31 > | 10 | **Hayabusa** | SIGMA threat hunting | `hayabusa csv-timeline -d evtx_dir -o timeline.csv` | Rapid log analysis |
     32 > | 11 | **Chainsaw** | Log hunting | `chainsaw hunt evtx_dir -s sigma_rules/` | SIGMA-based detection |
     33 > | 12 | **KAPE** | Artifact collection | `kape.exe --tsource C: --tdest D:\Evidence --target KapeTriage` | Rapid triage |
     34 > | 13 | **Timeline Explorer** | CSV visualization | GUI application | Large CSV analysis |
     35 > | 14 | **CertUtil** | Hash calculation | `certutil -hashfile file SHA256` | Evidence integrity |
     36 > 
     37 > ---
     38 > 
     39 > **Key Definitions:**
     40 > 1. **Prefetch**: Windows execution tracking files storing program run history and file access patterns
     41 > 2. **ShimCache**: Application Compatibility Cache tracking executed programs in SYSTEM registry
     42 > 3. **Amcache**: Registry hive containing program execution metadata including SHA1 hashes
     43 > 4. **Malfind**: Volatility plugin detecting code injection via memory protection anomalies
     44 > 5. **SIGMA Rules**: Generic signature format for log events translated to multiple SIEM formats
     45 > 6. **RWX Memory**: Read-Write-Execute memory regions indicating potential code injection
     46 > 7. **YARA**: Pattern matching tool using rules to identify malware families
     47 > 8. **DFIR**: Digital Forensics and Incident Response
     48 > 9. **EZ Tools**: Suite of forensic parsers by Eric Zimmerman (SANS)
     49 > 10. **Triage**: Rapid evidence collection and initial analysis
     50 
     51 ---
     52 
     53 ## Tool Source Credibility
     54 
     55 This guide integrates tools from **[SANS Institute](https://www.sans.org/tools)**, containing 100+ cybersecurity utilities maintained by recognized experts.
     56 
     57 **[Eric Zimmerman](https://ericzimmerman.github.io)** (former FBI Special Agent, SANS Principal Instructor) authored the majority of Windows artifact parsers referenced herein. **[Rob T. Lee](https://www.sans.org/profiles/robert-lee/)** (SANS Chief AI Officer) created the **[SIFT Workstation](https://www.sans.org/tools/sift-workstation)**, a comprehensive Ubuntu-based forensic distribution.
     58 
     59 **Tool Selection Criteria**:
     60 1. Active maintenance by recognized DFIR experts
     61 2. Wide adoption by law enforcement and enterprise security teams
     62 3. Free and open-source architecture enabling verification
     63 4. Designed for forensic soundness and court-admissible evidence
     64 5. Cross-platform compatibility where applicable
     65 
     66 ---
     67 
     68 ## Memory Forensics Fundamentals
     69 
     70 **Memory forensics** extracts digital artifacts from volatile memory (**[RAM](https://en.wikipedia.org/wiki/Random-access_memory)**) snapshots captured during or after incidents. Memory contains evidence unavailable on disk: running processes, network connections, injected code, decrypted data, and cryptographic keys.
     71 
     72 **Process injection** techniques (**[MITRE T1055](https://attack.mitre.org/techniques/T1055/)**) hide malicious code within legitimate processes, detectable via memory analysis. **[Cobalt Strike](https://www.cobaltstrike.com/)** Beacons commonly use reflective DLL injection into legitimate Windows processes (explorer.exe, svchost.exe).
     73 
     74 Memory analysis requires acquisition tools like **[WinPMEM](https://github.com/Velocidex/WinPmem)**, **[DumpIt](https://www.magnetforensics.com/)**, or **[FTK Imager](https://www.exterro.com/ftk-imager)** to create forensically sound memory dumps. Memory dumps range from 4GB to 64GB+ depending on system RAM, requiring sufficient storage and processing capacity.
     75 
     76 ---
     77 
     78 ## Memory Analysis Tools
     79 
     80 ### Volatility 3
     81 
     82 **Purpose:** Advanced memory forensics framework for extracting digital artifacts from volatile memory (RAM) dumps. Industry-standard tool supporting Windows, Linux, and macOS.
     83 
     84 **Source:** [Volatility Foundation](https://github.com/volatilityfoundation/volatility3)
     85 
     86 **Platforms:** Windows, Linux, macOS
     87 
     88 **Installation:**
     89 ```bash
     90 # Linux/macOS
     91 pip3 install volatility3
     92 
     93 # Windows
     94 pip install volatility3
     95 
     96 # From source
     97 git clone https://github.com/volatilityfoundation/volatility3.git
     98 cd volatility3
     99 pip3 install -r requirements.txt
    100 python3 setup.py install
    101 ```
    102 
    103 **Usage:**
    104 ```bash
    105 # Identify memory image profile (auto-detection in Vol3)
    106 vol3 -f <memory.bin> windows.info
    107 
    108 # Process enumeration
    109 vol3 -f <memory.bin> windows.pslist
    110 vol3 -f <memory.bin> windows.pstree
    111 vol3 -f <memory.bin> windows.cmdline
    112 
    113 # Code injection detection (critical for Cobalt Strike detection)
    114 vol3 -f <memory.bin> windows.malfind
    115 vol3 -f <memory.bin> windows.malfind --pid <PID>
    116 
    117 # Dump suspicious memory regions
    118 vol3 -f <memory.bin> -o <output_dir> windows.malfind --dump
    119 
    120 # Network connections
    121 vol3 -f <memory.bin> windows.netscan
    122 vol3 -f <memory.bin> windows.netstat
    123 
    124 # DLL analysis
    125 vol3 -f <memory.bin> windows.dlllist --pid <PID>
    126 vol3 -f <memory.bin> windows.ldrmodules
    127 
    128 # Handle analysis
    129 vol3 -f <memory.bin> windows.handles --pid <PID>
    130 
    131 # YARA scanning integration
    132 vol3 -f <memory.bin> windows.vadyarascan --yara-file <rules.yar>
    133 ```
    134 
    135 **Use Cases:**
    136 1. Detect process injection techniques (reflective DLL injection, process hollowing)
    137 2. Identify Cobalt Strike Beacons via malfind RWX memory regions
    138 3. Extract network connections to C2 infrastructure
    139 4. Recover command-line arguments revealing encoded payloads
    140 5. Identify loaded drivers and kernel modules
    141 
    142 **Integration:**
    143 1. Output can be piped to `grep`, `awk`, or Timeline Explorer
    144 2. Combine with YARA rules for signature-based detection
    145 3. Results can feed into timeline analysis with Plaso
    146 
    147 ---
    148 
    149 > **Note β€”** - Practical Application: Volatility 3 Memory Analysis
    150 > 
    151 > **Context**: Initial triage of memory dump to identify suspicious processes and code injection.
    152 > 
    153 > ```bash
    154 > # Step 1: Verify memory dump and identify system profile
    155 > vol3 -f memory.bin windows.info
    156 > ```
    157 > 
    158 > ```plaintext
    159 > Volatility 3 Framework 2.5.0
    160 > 
    161 > Variable        Value
    162 > Kernel Base     0xf8000xxxxx
    163 > DTB             0x1ab000
    164 > Symbols         ntkrnlmp.pdb
    165 > Is64Bit         True
    166 > IsPAE           False
    167 > layer_name      0 WindowsIntel32e
    168 > memory_layer    1 FileLayer
    169 > KdVersionBlock  0xf80002xxxxxx
    170 > Major/Minor     15.19041
    171 > MachineType     34404
    172 > KeNumberProcessors      4
    173 > SystemTime      2024-01-15 14:23:45
    174 > ```
    175 > 
    176 > **Output Analysis:**
    177 > 1. **Kernel Base**: Memory address of Windows kernelβ€”validates dump integrity
    178 > 2. **DTB (Directory Table Base)**: Physical address of page directory for virtual memory translation
    179 > 3. **Is64Bit**: Confirms architecture (x64 vs x86)
    180 > 4. **Major/Minor 15.19041**: Windows 10 Build 19041 (Version 2004)
    181 > 5. **SystemTime**: Timestamp when memory dump was created
    182 
    183 ---
    184 
    185 **Process Enumeration:**
    186 
    187 ```bash
    188 # List all processes
    189 vol3 -f memory.bin windows.pslist > pslist.txt
    190 
    191 # Generate process tree showing parent-child relationships
    192 vol3 -f memory.bin windows.pstree > pstree.txt
    193 
    194 # Extract command-line arguments (reveals PowerShell encoded commands)
    195 vol3 -f memory.bin windows.cmdline > cmdline.txt
    196 ```
    197 
    198 **Example Output:**
    199 ```plaintext
    200 PID     PPID    ImageFileName   Offset(V)       Threads Handles SessionId       Wow64   CreateTime      ExitTime
    201 
    202 4       0       System          0x8a0ba1c0      152     -       N/A     False   2024-01-15 08:00:00.000000      N/A
    203 392     4       smss.exe        0x8b3c4040      2       -       N/A     False   2024-01-15 08:00:01.000000      N/A
    204 512     504     csrss.exe       0x8e2a8580      9       -       0       False   2024-01-15 08:00:03.000000      N/A
    205 1432    1424    explorer.exe    0x8f1a2080      45      -       1       False   2024-01-15 08:05:12.000000      N/A
    206 2856    1432    powershell.exe  0x9a4b3580      12      -       1       False   2024-01-15 14:15:33.000000      N/A
    207 3104    2856    whoami.exe      0x9c2e1040      0       -       1       False   2024-01-15 14:15:41.000000      2024-01-15 14:15:42
    208 ```
    209 
    210 **Key Fields:**
    211 - **PID**: Process IDβ€”unique identifier
    212 - **PPID**: Parent Process IDβ€”reveals process spawning relationships
    213 - **ImageFileName**: Executable name
    214 - **CreateTime**: Process start timestamp
    215 - **SessionId**: User session (0=System, 1+=User sessions)
    216 
    217 **Red Flags:**
    218 1. Single-character executable names (a.exe, x.exe)
    219 2. Processes spawning from temp directories
    220 3. PowerShell spawned by unexpected parents (winword.exe, excel.exe)
    221 4. Multiple PowerShell instances with short lifespans
    222 
    223 ---
    224 
    225 **Code Injection Detection:**
    226 
    227 ```bash
    228 # Detect injected code via memory protection anomalies
    229 vol3 -f memory.bin windows.malfind > malfind.txt
    230 
    231 # Dump suspicious memory regions for analysis
    232 vol3 -f memory.bin -o dumps/ windows.malfind --dump
    233 
    234 # Target specific suspicious process
    235 vol3 -f memory.bin windows.malfind --pid 2856
    236 ```
    237 
    238 **Example Output:**
    239 ```plaintext
    240 PID     Process         Start VPN       End VPN         Tag     Protection      CommitCharge    PrivateMemory   File output     Hexdump Disasm
    241 
    242 2856    powershell.exe  0x2a40000       0x2a70000       VadS    PAGE_EXECUTE_READWRITE  192     1       Disabled        
    243 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 MZ..............
    244 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 ........@.......
    245 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    246 00 00 00 00 00 00 00 00 00 00 00 00 f8 00 00 00 ................
    247 
    248 0x2a40000:      MZ      ; PE header signature
    249 0x2a40040:      PUSH RBP
    250 0x2a40041:      MOV RBP, RSP
    251 0x2a40044:      SUB RSP, 0x20
    252 ```
    253 
    254 **Indicators of Compromise:**
    255 1. **PAGE_EXECUTE_READWRITE**: RWX permissionsβ€”rare in legitimate code, common in injected payloads
    256 2. **MZ header (0x4d5a)**: PE file signature indicating reflective DLL injection
    257 3. **VadS tag**: Private memory allocation via VirtualAllocβ€”common injection technique
    258 4. **Disassembly shows prologue**: Standard x64 function prologue suggesting shellcode
    259 
    260 **Next Steps:**
    261 1. Dump flagged regions: `vol3 -f mem.bin -o dumps/ windows.malfind --dump`
    262 2. Analyze with CAPA: `capa dumps/pid.2856.vad.0x2a40000-0x2a70000.dmp`
    263 3. Scan with YARA: `yara cobalt_strike.yar dumps/`
    264 4. Extract strings: `strings -el dumps/*.dmp | grep -i "http\|sleep\|pipe"`
    265 
    266 ---
    267 
    268 **Network Connection Analysis:**
    269 
    270 ```bash
    271 # Extract all network connections (TCP/UDP)
    272 vol3 -f memory.bin windows.netscan > netscan.txt
    273 
    274 # Alternative plugin for different Windows versions
    275 vol3 -f memory.bin windows.netstat > netstat.txt
    276 ```
    277 
    278 **Example Output:**
    279 ```plaintext
    280 Offset          Proto   LocalAddr       LocalPort       ForeignAddr     ForeignPort     State           PID     Owner   Created
    281 
    282 0x9b2a4580      TCPv4   192.168.1.135   49823           185.220.101.5   443             ESTABLISHED     2856    powershell.exe  2024-01-15 14:15:35.000000
    283 0x9c1e3040      TCPv4   192.168.1.135   49824           10.10.10.100    445             ESTABLISHED     4       System  2024-01-15 14:18:12.000000
    284 0x9d4f1280      UDPv4   0.0.0.0         53              *               0                               1024    svchost.exe     2024-01-15 08:05:00.000000
    285 ```
    286 
    287 **Investigation Actions:**
    288 1. **185.220.101.5:443 from powershell.exe**: Suspicious HTTPS connectionβ€”potential C2 communication
    289 2. **10.10.10.100:445 from System**: SMB connection indicating lateral movement or file sharing
    290 3. Correlate foreign IPs with threat intelligence ([VirusTotal](https://www.virustotal.com/), [AbuseIPDB](https://www.abuseipdb.com/))
    291 4. Check **Event ID 3** ([Sysmon](https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon) Network Connection) for additional context
    292 
    293 ---
    294 
    295 ### MemProcFS
    296 
    297 **Purpose:** Revolutionary memory forensics tool mounting physical memory as a virtual file system, enabling intuitive navigation of memory artifacts using standard file browsers and command-line tools.
    298 
    299 **Source:** [MemProcFS GitHub](https://github.com/ufrisk/MemProcFS)
    300 
    301 **Platforms:** Windows (primary), Linux (partial support)
    302 
    303 **Prerequisites:**
    304 - Dokany File System Library (Windows): [Dokany Releases](https://github.com/dokan-dev/dokany/releases)
    305 
    306 **Installation:**
    307 ```bash
    308 # Windows - Download pre-compiled binaries
    309 # https://github.com/ufrisk/MemProcFS/releases
    310 
    311 # Install Dokany first (required for mounting)
    312 # Download DokanSetup.exe from Dokany releases
    313 
    314 # Extract MemProcFS and run from directory
    315 ```
    316 
    317 **Usage:**
    318 ```cmd
    319 :: Basic mount (default M: drive)
    320 memprocfs.exe -device <memory.bin>
    321 
    322 :: Mount with forensic mode (enables timeline, MFT extraction, NTFS analysis)
    323 memprocfs.exe -device <memory.bin> -forensic 1
    324 
    325 :: Mount with Elastic YARA rules
    326 memprocfs.exe -device <memory.bin> -forensic 1 -license-accept-elastic-license-2.0
    327 
    328 :: Custom YARA rules
    329 memprocfs.exe -device <memory.bin> -forensic 1 -forensic-yara-rules <rules.yar>
    330 
    331 :: With pagefile support
    332 memprocfs.exe -device <memory.bin> -pagefile0 pagefile.sys -pagefile1 swapfile.sys
    333 
    334 :: Live memory analysis (with WinPMEM driver)
    335 memprocfs.exe -device pmem
    336 ```
    337 
    338 ---
    339 
    340 > **Note β€”** - Virtual File System Structure
    341 > 
    342 > **Key Directories After Mounting:**
    343 > 
    344 > | Directory Path | Contents | Forensic Value |
    345 > |:--|:--|:--|
    346 > | `M:\forensic\csv\` | CSV exports (pslist, findevil, ntfs) | Import to Timeline Explorer |
    347 > | `M:\forensic\findevil\` | Automated malware detection results | Quick IOC identification |
    348 > | `M:\forensic\timeline\` | Process and activity timelines | Temporal analysis |
    349 > | `M:\forensic\yara\` | YARA scan results | Signature-based detection |
    350 > | `M:\forensic\ntfs\` | Reconstructed NTFS from memory | File system artifacts |
    351 > | `M:\name\<process.exe-PID>\` | Process-specific artifacts | Per-process deep dive |
    352 > | `M:\name\<process>\vmemd\` | Virtual memory dumps | Extract injected code |
    353 > | `M:\registry\hive_files\` | Extracted registry hives | Offline registry analysis |
    354 > | `M:\registry\HKLM\` | HKEY_LOCAL_MACHINE keys | System-wide settings |
    355 > | `M:\registry\HKCU\` | HKEY_CURRENT_USER keys | User-specific settings |
    356 > | `M:\sys\net\netstat.txt` | Network connections | C2 detection |
    357 > | `M:\sys\proc\pslist.txt` | Process list | Quick process review |
    358 > | `M:\pid\<PID>\` | Process by PID | Direct PID access |
    359 
    360 **Workflow Example:**
    361 1. Review `M:\forensic\findevil\findevil.txt` for automated IOC hits
    362 2. Open `M:\forensic\csv\findevil.csv` in Timeline Explorer
    363 3. Navigate to flagged process: `M:\name\powershell.exe-2856\`
    364 4. Review `cmdline.txt` for command-line arguments
    365 5. Check `M:\sys\net\netstat.txt` for network connections from PID 2856
    366 6. Copy registry hives from `M:\registry\hive_files\` to working directory
    367 7. Analyze with `RECmd.exe -f M:\registry\hive_files\SOFTWARE --bn batch.reb`
    368 
    369 ---
    370 
    371 ### CAPA
    372 
    373 **Purpose:** Automated malware capability identification tool by Mandiant/FLARE team. Identifies program capabilities by analyzing code against a rule set of known malicious behaviors, mapping findings to [MITRE ATT&CK](https://attack.mitre.org/).
    374 
    375 **Source:** [CAPA GitHub](https://github.com/mandiant/capa)
    376 
    377 **Platforms:** Windows, Linux, macOS
    378 
    379 **Installation:**
    380 ```bash
    381 # Python installation
    382 pip install flare-capa
    383 
    384 # Download standalone executable
    385 # https://github.com/mandiant/capa/releases
    386 ```
    387 
    388 **Usage:**
    389 ```bash
    390 # Basic analysis of executable
    391 capa <malware.exe>
    392 
    393 # Verbose output showing matched rules
    394 capa -v <malware.exe>
    395 
    396 # Very verbose (shows matched code locations)
    397 capa -vv <malware.exe>
    398 
    399 # Output as JSON for parsing
    400 capa -j <malware.exe> > capa_results.json
    401 
    402 # Analyse shellcode
    403 capa -f sc32 <shellcode.bin>    # 32-bit shellcode
    404 capa -f sc64 <shellcode.bin>    # 64-bit shellcode
    405 
    406 # Analyse memory dump regions extracted from malfind
    407 capa <malfind_dump.dmp>
    408 
    409 # Specify rules directory
    410 capa -r <rules_directory> <sample.exe>
    411 ```
    412 
    413 **Example Output:**
    414 ```
    415 +------------------------+----------------------------+
    416 | ATT&CK Tactic          | ATT&CK Technique           |
    417 |------------------------+----------------------------|
    418 | DEFENSE EVASION        | Obfuscated Files or Info   |
    419 | EXECUTION              | Command and Scripting      |
    420 | PERSISTENCE            | Registry Run Keys          |
    421 | PRIVILEGE ESCALATION   | Process Injection          |
    422 | COLLECTION             | Screen Capture             |
    423 | COMMAND AND CONTROL    | Encrypted Channel          |
    424 +------------------------+----------------------------+
    425 
    426 +-----------------------------+------------------------------+
    427 | Capability                  | Namespace                    |
    428 |-----------------------------+------------------------------|
    429 | encode data using XOR       | data-manipulation/encoding   |
    430 | receive data on TCP socket  | communication/tcp/receive    |
    431 | create process              | host-interaction/process     |
    432 | inject code into remote     | host-interaction/process/    |
    433 | process                     | inject                       |
    434 | create registry key         | host-interaction/registry    |
    435 | capture screenshot          | collection/screenshot        |
    436 | contain PE file             | executable/pe                |
    437 +-----------------------------+------------------------------+
    438 ```
    439 
    440 **Cobalt Strike Indicators:**
    441 1. Network socket creation (TCP/UDP)
    442 2. Process injection capabilities
    443 3. Named pipe creation (`\\.\pipe\msagent_*`)
    444 4. XOR encoding
    445 5. Sleep/jitter implementation
    446 
    447 ---
    448 
    449 ### YARA
    450 
    451 **Purpose:** Pattern matching tool for identifying and classifying malware based on textual or binary patterns. De facto standard for malware signature creation used by VirusTotal, AV vendors, and DFIR teams.
    452 
    453 **Source:** [YARA GitHub](https://github.com/VirusTotal/yara)
    454 
    455 **Platforms:** Windows, Linux, macOS
    456 
    457 **Installation:**
    458 ```bash
    459 # Linux
    460 sudo apt install yara
    461 
    462 # macOS
    463 brew install yara
    464 
    465 # Windows - Download from releases
    466 # https://github.com/VirusTotal/yara/releases
    467 
    468 # Python bindings
    469 pip install yara-python
    470 ```
    471 
    472 **Usage:**
    473 ```bash
    474 # Scan file with single rule
    475 yara <rules.yar> <target_file>
    476 
    477 # Scan directory recursively
    478 yara -r <rules.yar> <target_directory>
    479 
    480 # Scan with multiple rule files
    481 yara <rules1.yar> <rules2.yar> <target>
    482 
    483 # Print matching strings
    484 yara -s <rules.yar> <target>
    485 
    486 # Print metadata
    487 yara -m <rules.yar> <target>
    488 
    489 # Scan process memory (Linux)
    490 yara <rules.yar> -p <PID>
    491 
    492 # Fast mode (skip expensive scans)
    493 yara -f <rules.yar> <target>
    494 ```
    495 
    496 ---
    497 
    498 > **Note β€”** - Sample YARA Rule: Cobalt Strike Beacon Detection
    499 > 
    500 > ```yara
    501 > rule CobaltStrike_Beacon_x64
    502 > {
    503 >     meta:
    504 >         description = "Detects Cobalt Strike Beacon x64"
    505 >         author = "SANS DFIR Team"
    506 >         reference = "https://www.cobaltstrike.com"
    507 >         severity = "high"
    508 >         mitre_attack = "T1055, T1071"
    509 >         
    510 >     strings:
    511 >         // x64 shellcode prologue
    512 >         $magic_x64 = { FC 48 83 E4 F0 E8 }
    513 >         
    514 >         // Beacon configuration markers
    515 >         $config_marker = { 00 01 00 01 00 02 }
    516 >         
    517 >         // Configuration strings
    518 >         $sleeptime = "sleeptime" ascii
    519 >         $jitter = "jitter" ascii
    520 >         $watermark = "watermark" ascii
    521 >         $spawnto_x86 = "spawnto_x86" ascii
    522 >         $spawnto_x64 = "spawnto_x64" ascii
    523 >         
    524 >         // Named pipe pattern
    525 >         $pipe = "\\\\.\\pipe\\" ascii
    526 >         $msagent_pipe = "msagent_" ascii
    527 >         
    528 >         // HTTP headers
    529 >         $http_header = "User-Agent:" ascii
    530 >         $http_header2 = "Accept:" ascii
    531 >         
    532 >         // Beacon DLL names
    533 >         $beacon_dll = "beacon.dll" ascii nocase
    534 >         $beacon_x64 = "beacon.x64.dll" ascii nocase
    535 >         
    536 >     condition:
    537 >         uint16(0) == 0x5A4D and  // MZ header
    538 >         (
    539 >             $magic_x64 or
    540 >             (2 of ($config_marker, $sleeptime, $jitter, $watermark)) or
    541 >             (all of ($pipe, $msagent_pipe)) or
    542 >             any of ($beacon_dll, $beacon_x64)
    543 >         )
    544 > }
    545 > 
    546 > rule Reflective_DLL_Injection
    547 > {
    548 >     meta:
    549 >         description = "Detects reflective DLL injection"
    550 >         author = "SANS DFIR"
    551 >         mitre_attack = "T1055.001"
    552 >         
    553 >     strings:
    554 >         $mz = { 4D 5A }
    555 >         
    556 >         // Reflective loader signatures
    557 >         $reflective_loader1 = { 48 8B C4 48 89 58 08 48 89 68 10 48 89 70 18 }
    558 >         $reflective_loader2 = { 64 48 8B 04 25 60 00 00 00 }  // GS segment access
    559 >         
    560 >         // API resolution patterns
    561 >         $getprocaddress = "GetProcAddress" ascii
    562 >         $loadlibrary = "LoadLibraryA" ascii
    563 >         $virtualalloc = "VirtualAlloc" ascii
    564 >         
    565 >     condition:
    566 >         $mz at 0 and
    567 >         (
    568 >             any of ($reflective_loader*) or
    569 >             (all of ($getprocaddress, $loadlibrary, $virtualalloc))
    570 >         )
    571 > }
    572 > ```
    573 
    574 **YARA Rule Best Practices:**
    575 1. Always include metadata with ATT&CK mappings and severity
    576 2. Test rules against benign software to minimize false positives
    577 3. Use multiple string conditions for robustness
    578 4. Include both specific and generic indicators
    579 5. Document rule rationale in comments
    580 
    581 **Integration with Volatility 3:**
    582 ```bash
    583 # Scan all memory with YARA rules
    584 vol3 -f memory.bin windows.vadyarascan --yara-file cobalt_strike.yar
    585 
    586 # Scan specific process by PID
    587 vol3 -f memory.bin windows.vadyarascan --yara-file rules.yar --pid 2856
    588 
    589 # Multiple rule files
    590 vol3 -f memory.bin yarascan.YaraScan --yara-file combined_rules.yar
    591 
    592 # Output to file for analysis
    593 vol3 -f memory.bin windows.vadyarascan --yara-file rules.yar > yara_hits.txt
    594 ```
    595 
    596 ---
    597 
    598 ## Prefetch Analysis Tools
    599 
    600 ### PECmd (Prefetch Explorer Command Line) πŸ”΅ SANS Tool
    601 
    602 **Purpose:** Parse Windows Prefetch files to extract program execution evidence, including run counts, timestamps, and accessed files/directories.
    603 
    604 **Source:** [SANS PECmd](https://www.sans.org/tools/pecmd) | [Eric Zimmerman Tools](https://ericzimmerman.github.io)
    605 
    606 **Author:** Eric Zimmerman (SANS Principal Instructor)
    607 
    608 **Platforms:** Windows (native), Linux (via Wine/.NET)
    609 
    610 **Installation:**
    611 ```powershell
    612 # Windows - Download from Eric Zimmerman's GitHub
    613 # https://ericzimmerman.github.io/#!index.md
    614 
    615 # Use Get-ZimmermanTools PowerShell script for automated download
    616 [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
    617 Invoke-WebRequest -Uri "https://f001.backblazeb2.com/file/EricZimmermanTools/Get-ZimmermanTools.zip" -OutFile Get-ZimmermanTools.zip
    618 Expand-Archive Get-ZimmermanTools.zip
    619 .\Get-ZimmermanTools.ps1 -Dest "C:\Tools\Zimmerman"
    620 
    621 # Linux (requires .NET 6 runtime)
    622 wget https://dot.net/v1/dotnet-install.sh
    623 chmod +x dotnet-install.sh
    624 ./dotnet-install.sh --runtime dotnet --version 6.0.0
    625 ```
    626 
    627 **Usage:**
    628 ```cmd
    629 :: Parse single prefetch file
    630 PECmd.exe -f <file.pf>
    631 
    632 :: Parse directory of prefetch files with CSV output
    633 PECmd.exe -d <prefetch_directory> --csv <output_dir> --csvf Prefetch_Results.csv
    634 
    635 :: UK date formatting (dd/MM/yyyy HH:mm:ss)
    636 PECmd.exe -d <prefetch_directory> --csv <output_dir> --csvf Prefetch.csv --dt "dd/MM/yyyy HH:mm:ss"
    637 
    638 :: JSON output
    639 PECmd.exe -d <prefetch_directory> --json <output_dir>
    640 
    641 :: Quiet mode (faster processing)
    642 PECmd.exe -d <prefetch_directory> --csv <output_dir> -q
    643 
    644 :: Custom keyword highlighting (temp directories)
    645 PECmd.exe -d <prefetch_directory> -k "temp,appdata,downloads"
    646 ```
    647 
    648 **Expected Output:**
    649 - `*_Prefetch.csv` - Main results with executable name, run count, last 8 run times
    650 - `*_Prefetch_Timeline.csv` - Execution timeline for temporal analysis
    651 
    652 **Key CSV Fields:**
    653 
    654 |                |                                       |                               |
    655 | -------------- | ------------------------------------- | ----------------------------- |
    656 | Field          | Description                           | Forensic Value                |
    657 | ExecutableName | Name of executed program              | Identify reconnaissance tools |
    658 | RunCount       | Number of times program executed      | Frequency analysis            |
    659 | LastRun        | Most recent execution timestamp       | Timeline correlation          |
    660 | PreviousRun0-7 | Previous 7 execution timestamps       | Execution history             |
    661 | SourceFilename | Full path to executable               | Location analysis             |
    662 | FilesLoaded    | Files accessed during execution       | Payload identification        |
    663 | Directories    | Directories accessed during execution | Drop location discovery       |
    664 
    665 **Forensic Significance:**
    666 1. Windows 10 stores last 8 execution times
    667 2. Files/directories referenced reveal payload locations
    668 3. Single-character executable names often indicate malware
    669 4. Prefetch files survive across reboots
    670 
    671 ---
    672 
    673 ## Registry Analysis Tools
    674 
    675 ### RECmd (Registry Explorer Command Line) πŸ”΅ SANS Tool
    676 
    677 **Purpose:** Command-line registry parser with batch processing capabilities for extracting forensically significant data from Windows registry hive files.
    678 
    679 **Source:** [SANS RECmd](https://www.sans.org/tools/recmd) | [Eric Zimmerman Tools](https://ericzimmerman.github.io)
    680 
    681 **Author:** Eric Zimmerman
    682 
    683 **Platforms:** Windows (native), Linux (via .NET)
    684 
    685 **Usage:**
    686 ```cmd
    687 :: Parse with batch file (recommended for comprehensive analysis)
    688 RECmd.exe -f <registry_hive> --bn <batch_file.reb> --csv <output_dir> --csvf Results.csv
    689 
    690 :: Common batch files:
    691 :: - RECmd_Batch_MC.reb (Most Common artifacts)
    692 :: - RegistryASEPs.reb (Auto-Start Extensibility Points)
    693 
    694 :: Parse specific registry key
    695 RECmd.exe -f SOFTWARE --kn "Microsoft\Windows\CurrentVersion\Run" --csv <output_dir>
    696 
    697 :: Recover deleted entries
    698 RECmd.exe -f <hive> --recover --csv <output_dir>
    699 
    700 :: UK date format
    701 RECmd.exe -f <hive> --bn <batch.reb> --csv <output_dir> --dt "dd/MM/yyyy HH:mm:ss"
    702 
    703 :: Parse directory of hives
    704 RECmd.exe -d <hive_directory> --bn <batch.reb> --csv <output_dir>
    705 ```
    706 
    707 ---
    708 
    709 > **Note β€”** - Critical Registry Locations for DFIR
    710 > 
    711 > **Persistence Mechanisms (HKLM\SOFTWARE & NTUSER.DAT):**
    712 > 
    713 > | Registry Key | Hive | Purpose | Malware Usage |
    714 > |:--|:--|:--|:--|
    715 > | `Microsoft\Windows\CurrentVersion\Run` | SOFTWARE, NTUSER | Auto-start executables | **Primary persistence location** |
    716 > | `Microsoft\Windows\CurrentVersion\RunOnce` | SOFTWARE, NTUSER | Run once then delete entry | Single-execution payloads |
    717 > | `Microsoft\Windows\CurrentVersion\RunServices` | SOFTWARE | Run as service | Service-based persistence |
    718 > | `Microsoft\Windows\CurrentVersion\Policies\Explorer\Run` | SOFTWARE, NTUSER | Policy-based execution | Policy enforcement bypass |
    719 > | `Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit` | SOFTWARE | Userinit override | Replace userinit.exe |
    720 > | `Microsoft\Windows NT\CurrentVersion\Winlogon\Shell` | SOFTWARE | Shell override | Replace explorer.exe |
    721 > | `Microsoft\Windows NT\CurrentVersion\Image File Execution Options` | SOFTWARE | Debugger attachment | IFEO persistence |
    722 > 
    723 > **Services (HKLM\SYSTEM):**
    724 > 
    725 > | Registry Key | Purpose |
    726 > |:--|:--|
    727 > | `ControlSet001\Services` | Installed services |
    728 > | `ControlSet001\Services\<ServiceName>\ImagePath` | Service executable path |
    729 > | `ControlSet001\Services\<ServiceName>\Start` | Start type (2=Auto, 3=Manual, 4=Disabled) |
    730 > 
    731 > **System Information (HKLM\SYSTEM):**
    732 > 
    733 > | Registry Key | Information |
    734 > |:--|:--|
    735 > | `ControlSet001\Control\ComputerName\ComputerName` | Computer name |
    736 > | `ControlSet001\Control\TimeZoneInformation` | Timezone |
    737 > | `ControlSet001\Services\Tcpip\Parameters\Interfaces` | Network interfaces |
    738 
    739 ---
    740 
    741 ### Registry Explorer πŸ”΅ SANS Tool
    742 
    743 **Purpose:** GUI-based registry hive viewer and editor with advanced parsing capabilities, plugin support, and deleted entry recovery.
    744 
    745 **Source:** [Eric Zimmerman Tools](https://ericzimmerman.github.io)
    746 
    747 **Author:** Eric Zimmerman
    748 
    749 **Platforms:** Windows
    750 
    751 **Usage:**
    752 1. Launch Registry Explorer
    753 2. File β†’ Load Hive β†’ Select registry hive file
    754 3. Navigate to keys of interest
    755 4. Use Bookmarks for common forensic locations
    756 5. Export findings via File β†’ Export
    757 
    758 **Key Features:**
    759 1. Handles dirty/corrupt hives from memory extraction
    760 2. Shows deleted keys and values
    761 3. Timestamps on all keys
    762 4. Plugin support for specialized parsing
    763 5. Bookmark system for common forensic keys
    764 
    765 ---
    766 
    767 ### AppCompatCacheParser πŸ”΅ SANS Tool
    768 
    769 **Purpose:** Parse Application Compatibility Cache (ShimCache) from SYSTEM registry hive to extract program execution evidence.
    770 
    771 **Source:** [SANS AppCompatCacheParser](https://www.sans.org/tools/appcompatcacheparser) | [Eric Zimmerman Tools](https://ericzimmerman.github.io)
    772 
    773 **Author:** Eric Zimmerman
    774 
    775 **Usage:**
    776 ```cmd
    777 :: Parse SYSTEM hive
    778 AppCompatCacheParser.exe -f <SYSTEM_hive> --csv <output_dir> --csvf ShimCache.csv
    779 
    780 :: UK date format
    781 AppCompatCacheParser.exe -f <SYSTEM_hive> --csv <output_dir> --dt "dd/MM/yyyy HH:mm:ss"
    782 ```
    783 
    784 **Forensic Significance:**
    785 1. Contains executable path and last modification timestamp
    786 2. Entry order reflects approximate execution order
    787 3. Survives reboots (unlike prefetch which can be disabled)
    788 4. Windows 7+ includes executed flag
    789 
    790 **CSV Output Fields:**
    791 
    792 |                        |                                     |                                             |
    793 | ---------------------- | ----------------------------------- | ------------------------------------------- |
    794 | Field                  | Description                         | Forensic Value                              |
    795 | **CacheEntryPosition** | Position in cache (1 = most recent) | Relative execution order                    |
    796 | **Path**               | Full executable path                | Identify execution location                 |
    797 | **LastModified**       | File last modification timestamp    | File modification time (NOT execution time) |
    798 | **Executed**           | Executed flag (Windows 7+)          | Confirms execution vs touched by Explorer   |
    799 | **ControlSet**         | ControlSet number (001, 002)        | Validate active ControlSet                  |
    800 
    801 
    802 ---
    803 
    804 ### AmcacheParser πŸ”΅ SANS Tool
    805 
    806 **Purpose:** Parse Amcache.hve to extract program execution metadata including SHA1 hashes, file paths, and execution timestamps.
    807 
    808 **Source:** [SANS AmcacheParser](https://www.sans.org/tools/amcacheparser) | [Eric Zimmerman Tools](https://ericzimmerman.github.io)
    809 
    810 **Author:** Eric Zimmerman
    811 
    812 **Usage:**
    813 ```cmd
    814 :: Parse Amcache.hve
    815 AmcacheParser.exe -f <Amcache.hve> --csv <output_dir> --csvf Amcache.csv
    816 
    817 :: Include unassociated file entries
    818 AmcacheParser.exe -f <Amcache.hve> --csv <output_dir> -i
    819 
    820 :: UK date format
    821 AmcacheParser.exe -f <Amcache.hve> --csv <output_dir> --dt "dd/MM/yyyy HH:mm:ss"
    822 ```
    823 
    824 **Key Output Fields:**
    825 1. SHA1 hash (for VirusTotal lookup)
    826 2. File path
    827 3. First execution timestamp
    828 4. File size
    829 5. Publisher information
    830 
    831 **VirusTotal Batch Lookup:**
    832 ```powershell
    833 # Extract SHA1 hashes from CSV
    834 Import-Csv Amcache.csv | Select-Object -Unique SHA1 | Export-Csv -Path hashes_only.csv
    835 
    836 # Lookup on VirusTotal (requires API key)
    837 # Use vt-cli or web interface batch upload
    838 ```
    839 
    840 ---
    841 
    842 ## Event Log Analysis Tools
    843 
    844 ### EvtxECmd πŸ”΅ SANS Tool
    845 
    846 **Purpose:** Parse Windows Event Log files (.evtx) to CSV/JSON with extensive event mapping and filtering capabilities.
    847 
    848 **Source:** [SANS EvtxECmd](https://www.sans.org/tools/evtxecmd) | [Eric Zimmerman Tools](https://ericzimmerman.github.io)
    849 
    850 **Author:** Eric Zimmerman
    851 
    852 **Usage:**
    853 ```cmd
    854 :: Parse single event log
    855 EvtxECmd.exe -f <Security.evtx> --csv <output_dir> --csvf Security.csv
    856 
    857 :: Parse with UK date format
    858 EvtxECmd.exe -f <Security.evtx> --csv <output_dir> --csvf Security.csv --dt "dd/MM/yyyy HH:mm:ss"
    859 
    860 :: Parse directory of logs
    861 EvtxECmd.exe -d <EventLogs_directory> --csv <output_dir>
    862 
    863 :: JSON output
    864 EvtxECmd.exe -f <Security.evtx> --json <output_dir>
    865 
    866 :: Include maps for enriched parsing
    867 EvtxECmd.exe -f <Security.evtx> --csv <output_dir> --maps <maps_directory>
    868 ```
    869 
    870 ---
    871 
    872 > **Note β€”** - Critical Windows Event IDs Reference
    873 > 
    874 > **Security Log Events:**
    875 > 
    876 > | Event ID | Category | Description | Forensic Value |
    877 > |:--|:--|:--|:--|
    878 > | **4624** | Authentication | Successful logon | Identify user sessions, Type 3=Network, Type 10=RDP |
    879 > | **4625** | Authentication | Failed logon | Brute force attempts, credential spraying |
    880 > | **4672** | Privilege | Special privileges assigned | Administrator logon, SYSTEM access |
    881 > | **4688** | Execution | Process creation | Command lines (if auditing enabled) |
    882 > | **4648** | Authentication | Explicit credentials used | Lateral movement with `runas` or Pass-the-Hash |
    883 > | **4768** | Kerberos | TGT requested | Initial authentication to domain controller |
    884 > | **4769** | Kerberos | Service ticket requested | Kerberoasting detection |
    885 > | **4776** | Authentication | NTLM authentication | Identify NTLM usage for lateral movement |
    886 > | **1102** | Audit | Security log cleared | Anti-forensics, tampering |
    887 > | **4720** | Account Management | User account created | Persistence, privilege escalation |
    888 > | **4732** | Group Management | User added to local group | Privilege escalation (Administrators group) |
    889 > 
    890 > **System Log Events:**
    891 > 
    892 > | Event ID | Category | Description | Forensic Value |
    893 > |:--|:--|:--|:--|
    894 > | **7045** | Service | New service installed | Malware persistence, lateral movement tools |
    895 > | **7040** | Service | Service start type changed | Persistence mechanism modification |
    896 > | **104** | Audit | System log cleared | Anti-forensics |
    897 > | **1** | Kernel | System boot | Establish system uptime, reboot timeline |
    898 > | **6005** | Event Log | Event Log service started | System boot confirmation |
    899 > | **6006** | Event Log | Event Log service stopped | System shutdown |
    900 > 
    901 > **PowerShell Operational Log:**
    902 > 
    903 > | Event ID | Category | Description | Forensic Value |
    904 > |:--|:--|:--|:--|
    905 > | **4103** | Pipeline | Module logging | Commands executed via PowerShell |
    906 > | **4104** | Script Block | Script block logging | Full PowerShell script content |
    907 > | **4105** | Script Start | Script execution started | Script start timestamp |
    908 > | **4106** | Script Stop | Script execution stopped | Script end timestamp |
    909 
    910 **Logon Type Reference (Event ID 4624):**
    911 
    912 | Type | Name | Description | Attack Relevance |
    913 |:--|:--|:--|:--|
    914 | **2** | Interactive | Local console logon | Physical or console access |
    915 | **3** | Network | Network logon (SMB, file shares) | **Lateral movement primary indicator** |
    916 | **4** | Batch | Scheduled task | Persistence via scheduled tasks |
    917 | **5** | Service | Service logon | Malicious service installation |
    918 | **7** | Unlock | Workstation unlock | User activity tracking |
    919 | **10** | RemoteInteractive | RDP/Terminal Services | **Remote access, lateral movement** |
    920 | **11** | CachedInteractive | Logon with cached credentials | Offline authentication |
    921 
    922 ---
    923 
    924 ### Hayabusa
    925 
    926 **Purpose:** SIGMA-based threat hunting and fast forensics timeline generator for Windows event logs.
    927 
    928 **Source:** [Hayabusa GitHub](https://github.com/Yamato-Security/hayabusa)
    929 
    930 **Platforms:** Windows, Linux, macOS
    931 
    932 **Installation:**
    933 ```bash
    934 # Download pre-compiled binary
    935 # https://github.com/Yamato-Security/hayabusa/releases
    936 
    937 # Or compile from source
    938 git clone https://github.com/Yamato-Security/hayabusa.git
    939 cd hayabusa
    940 cargo build --release
    941 ```
    942 
    943 **Usage:**
    944 ```bash
    945 # Run against event logs directory
    946 hayabusa csv-timeline -d <evtx_directory> -o timeline.csv
    947 
    948 # With SIGMA rules
    949 hayabusa csv-timeline -d <evtx_directory> -o timeline.csv --enable-all-rules
    950 
    951 # JSON output
    952 hayabusa json-timeline -d <evtx_directory> -o timeline.json
    953 
    954 # Metrics summary
    955 hayabusa metrics -d <evtx_directory>
    956 ```
    957 
    958 **Example Output:**
    959 ```plaintext
    960 Hayabusa v2.7.0 - Fast Windows Event Log Forensics Timeline Generator
    961 
    962 Loading detection rules...
    963 Loaded 3,245 SIGMA rules
    964 
    965 Processing event logs in D:\Evidence\EventLogs\LAPTOP-135
    966 
    967 Found event logs:
    968   Security.evtx (15,234 events)
    969   System.evtx (8,456 events)
    970   Microsoft-Windows-PowerShell%4Operational.evtx (1,234 events)
    971   Microsoft-Windows-Sysmon%4Operational.evtx (3,456 events)
    972 
    973 Processing events... β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ 100%
    974 
    975 Detection Summary:
    976   Total events processed: 28,380
    977   Detections: 127
    978     Critical: 5
    979     High: 23
    980     Medium: 67
    981     Low: 32
    982 
    983 Timeline saved to: D:\Output\hayabusa_timeline.csv
    984 
    985 Top 5 Detections:
    986   1. PowerShell Base64 Encoded Command (12 hits)
    987   2. Suspicious Process Creation Chain (8 hits)
    988   3. Network Connection to Suspicious IP (5 hits)
    989   4. Credential Dumping via LSASS Access (3 hits)
    990   5. Lateral Movement via PSExec (2 hits)
    991 ```
    992 
    993 **Key Detections for Cobalt Strike:**
    994 1. **PowerShell Base64 Encoded Command**: Encoded payload execution
    995 2. **Process Creation with Suspicious Command Line**: Reconnaissance tools
    996 3. **Network Connection from Script Host**: C2 beaconing from PowerShell
    997 4. **Suspicious Named Pipe Creation**: Beacon named pipes (`\\.\pipe\msagent_*`)
    998 5. **LSASS Memory Access**: Credential dumping
    999 6. **PSExec Service Installation**: Lateral movement
   1000 
   1001 ---
   1002 
   1003 ### Chainsaw
   1004 
   1005 **Purpose:** Rapidly search and hunt through Windows event logs using SIGMA detection rules and custom Chainsaw queries.
   1006 
   1007 **Source:** [Chainsaw GitHub](https://github.com/WithSecureLabs/chainsaw)
   1008 
   1009 **Platforms:** Windows, Linux, macOS
   1010 
   1011 **Installation:**
   1012 ```bash
   1013 # Download from releases
   1014 # https://github.com/WithSecureLabs/chainsaw/releases
   1015 
   1016 # Or cargo install
   1017 cargo install chainsaw
   1018 ```
   1019 
   1020 **Usage:**
   1021 ```bash
   1022 # Hunt with SIGMA rules
   1023 chainsaw hunt <evtx_directory> -s <sigma_rules> --mapping <mapping.yml>
   1024 
   1025 # Search for specific strings
   1026 chainsaw search <evtx_directory> -s "powershell" -s "mimikatz"
   1027 
   1028 # Dump all events to JSON
   1029 chainsaw dump <evtx_directory> -o output.json
   1030 ```
   1031 
   1032 ---
   1033 
   1034 ## Cross-Platform Supporting Tools
   1035 
   1036 ### SIFT Workstation πŸ”΅ SANS Tool
   1037 
   1038 **Purpose:** Complete Ubuntu-based forensic distribution with pre-installed tools for incident response and digital forensics.
   1039 
   1040 **Source:** [SANS SIFT Workstation](https://www.sans.org/tools/sift-workstation)
   1041 
   1042 **Author:** Rob T. Lee (SANS Chief AI Officer)
   1043 
   1044 **Platforms:** Ubuntu Linux (VM recommended)
   1045 
   1046 **Installation:**
   1047 ```bash
   1048 # Method 1: Download OVA/VMware image from SANS
   1049 # https://www.sans.org/tools/sift-workstation
   1050 
   1051 # Method 2: Install on existing Ubuntu
   1052 wget https://github.com/teamdfir/sift-cli/releases/download/v1.14.0/sift-cli-linux
   1053 chmod +x sift-cli-linux
   1054 sudo ./sift-cli-linux install
   1055 
   1056 # Default credentials
   1057 # Username: sansforensics
   1058 # Password: forensics
   1059 ```
   1060 
   1061 **Included Tools:**
   1062 1. Volatility Framework
   1063 2. The Sleuth Kit & Autopsy
   1064 3. Eric Zimmerman's Tools
   1065 4. Plaso/Log2Timeline
   1066 5. RegRipper
   1067 6. Bulk Extractor
   1068 7. And 100+ additional forensic utilities
   1069 
   1070 ---
   1071 
   1072 ### KAPE (Kroll Artifact Parser and Extractor) πŸ”΅ SANS Tool
   1073 
   1074 **Purpose:** Triage tool for rapid collection and processing of forensic artifacts. Combines targeted collection (Targets) with automated processing (Modules).
   1075 
   1076 **Source:** [SANS KAPE](https://www.sans.org/tools/kape) | [Kroll KAPE](https://www.kroll.com/en/services/cyber-risk/incident-response-litigation-support/kroll-artifact-parser-extractor-kape)
   1077 
   1078 **Author:** Eric Zimmerman
   1079 
   1080 **Platforms:** Windows
   1081 
   1082 **Installation:**
   1083 ```powershell
   1084 # Download from Kroll website (requires registration)
   1085 # https://www.kroll.com/en/services/cyber-risk/kape
   1086 
   1087 # Sync with GitHub for latest targets/modules
   1088 kape.exe --sync
   1089 ```
   1090 
   1091 **Usage:**
   1092 ```cmd
   1093 :: Collect common triage artifacts
   1094 kape.exe --tsource C: --tdest D:\Evidence --target KapeTriage
   1095 
   1096 :: Process collected artifacts
   1097 kape.exe --msource D:\Evidence --mdest D:\Processed --module !EZParser
   1098 
   1099 :: Collect and process in one command
   1100 kape.exe --tsource C: --tdest D:\Evidence --target KapeTriage --mdest D:\Processed --module !EZParser
   1101 
   1102 :: Specific target collection
   1103 kape.exe --tsource C: --tdest D:\Evidence --target Prefetch,EventLogs,Registry
   1104 ```
   1105 
   1106 **Common Targets:**
   1107 1. `KapeTriage` - Comprehensive triage collection
   1108 2. `Prefetch` - Prefetch files
   1109 3. `EventLogs` - Windows Event Logs
   1110 4. `Registry` - Registry hives
   1111 5. `AmcacheAndShimcache` - Execution evidence
   1112 
   1113 ---
   1114 
   1115 ### Timeline Explorer πŸ”΅ SANS Tool
   1116 
   1117 **Purpose:** Advanced CSV and Excel viewer designed for forensic timeline analysis with filtering, grouping, and visualization capabilities.
   1118 
   1119 **Source:** [Eric Zimmerman Tools](https://ericzimmerman.github.io)
   1120 
   1121 **Author:** Eric Zimmerman
   1122 
   1123 **Platforms:** Windows
   1124 
   1125 **Usage:**
   1126 1. Launch Timeline Explorer
   1127 2. Open CSV file (supports drag-and-drop)
   1128 3. Use column filters to narrow results
   1129 4. Group by columns for pattern identification
   1130 5. Tag interesting rows with Ctrl+T
   1131 6. Export filtered results
   1132 
   1133 **Key Features:**
   1134 1. Handles very large CSV files
   1135 2. Column-based filtering
   1136 3. Row grouping and expansion
   1137 4. Conditional formatting
   1138 5. Persistent column configurations
   1139 6. Native date/time parsing
   1140 
   1141 ---
   1142 
   1143 ### Plaso/Log2Timeline πŸ”΅ SANS Tool
   1144 
   1145 **Purpose:** Super timeline creation tool that extracts timestamps from various artifact sources and aggregates them into a unified timeline.
   1146 
   1147 **Source:** [Plaso GitHub](https://github.com/log2timeline/plaso)
   1148 
   1149 **Platforms:** Linux, Windows, macOS
   1150 
   1151 **Installation:**
   1152 ```bash
   1153 # Linux (Ubuntu/Debian)
   1154 sudo add-apt-repository ppa:gift/stable
   1155 sudo apt update
   1156 sudo apt install plaso-tools
   1157 
   1158 # Docker
   1159 docker pull log2timeline/plaso
   1160 
   1161 # pip
   1162 pip install plaso
   1163 ```
   1164 
   1165 **Usage:**
   1166 ```bash
   1167 # Create timeline from disk image
   1168 log2timeline.py --parsers win7 timeline.plaso <evidence_image>
   1169 
   1170 # Process to CSV
   1171 psort.py -o l2tcsv timeline.plaso -w supertimeline.csv
   1172 
   1173 # Filter by date range
   1174 psort.py timeline.plaso "date > '2024-01-01' AND date < '2024-01-31'" -w filtered.csv
   1175 ```
   1176 
   1177 ---
   1178 
   1179 ### CertUtil (Windows Built-in)
   1180 
   1181 **Purpose:** Windows certificate utility that includes hash calculation capabilities for evidence integrity verification.
   1182 
   1183 **Platforms:** Windows (built-in)
   1184 
   1185 **Usage:**
   1186 ```cmd
   1187 :: Generate SHA-256 hash
   1188 certutil -hashfile <file> SHA256
   1189 
   1190 :: Generate MD5 hash
   1191 certutil -hashfile <file> MD5
   1192 
   1193 :: Batch hash all files recursively
   1194 forfiles /s /c "cmd /c certutil -hashfile @path SHA256 >> all_hashes.txt"
   1195 ```
   1196 
   1197 ---
   1198 
   1199 ## Investigation Workflows
   1200 
   1201 ### Workflow 1: Memory Dump Analysis
   1202 
   1203 ```
   1204 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
   1205 β”‚                    MEMORY DUMP ANALYSIS                        β”‚
   1206 β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
   1207 β”‚                                                                 β”‚
   1208 β”‚  1. EVIDENCE INTEGRITY                                         β”‚
   1209 β”‚     β”œβ”€β”€ certutil -hashfile memory.bin SHA256                   β”‚
   1210 β”‚     └── Document hash in chain of custody                      β”‚
   1211 β”‚                                                                 β”‚
   1212 β”‚  2. INITIAL TRIAGE (Choose One)                                β”‚
   1213 β”‚     β”œβ”€β”€ MemProcFS: memprocfs.exe -device memory.bin -forensic 1β”‚
   1214 β”‚     β”‚   └── Browse M:\forensic\findevil.txt for quick IOCs     β”‚
   1215 β”‚     └── Volatility: vol3 -f memory.bin windows.info            β”‚
   1216 β”‚                                                                 β”‚
   1217 β”‚  3. PROCESS ANALYSIS                                           β”‚
   1218 β”‚     β”œβ”€β”€ vol3 -f memory.bin windows.pslist > pslist.txt         β”‚
   1219 β”‚     β”œβ”€β”€ vol3 -f memory.bin windows.pstree > pstree.txt         β”‚
   1220 β”‚     └── vol3 -f memory.bin windows.cmdline > cmdline.txt       β”‚
   1221 β”‚                                                                 β”‚
   1222 β”‚  4. CODE INJECTION DETECTION                                   β”‚
   1223 β”‚     β”œβ”€β”€ vol3 -f memory.bin windows.malfind > malfind.txt       β”‚
   1224 β”‚     β”œβ”€β”€ vol3 -f memory.bin -o dumps windows.malfind --dump     β”‚
   1225 β”‚     └── Look for: RWX permissions, MZ headers, shellcode       β”‚
   1226 β”‚                                                                 β”‚
   1227 β”‚  5. NETWORK ANALYSIS                                           β”‚
   1228 β”‚     β”œβ”€β”€ vol3 -f memory.bin windows.netscan > netscan.txt       β”‚
   1229 β”‚     └── Correlate connections with suspicious processes        β”‚
   1230 β”‚                                                                 β”‚
   1231 β”‚  6. MALWARE CAPABILITY ANALYSIS                                β”‚
   1232 β”‚     β”œβ”€β”€ capa <malfind_dump.bin> > capabilities.txt             β”‚
   1233 β”‚     └── yara cobalt_strike.yar <malfind_dump.bin>              β”‚
   1234 β”‚                                                                 β”‚
   1235 β”‚  7. DLL & HANDLE ANALYSIS                                      β”‚
   1236 β”‚     β”œβ”€β”€ vol3 -f memory.bin windows.dlllist --pid <suspicious>  β”‚
   1237 β”‚     └── vol3 -f memory.bin windows.handles --pid <suspicious>  β”‚
   1238 β”‚                                                                 β”‚
   1239 β”‚  8. TIMELINE CORRELATION                                       β”‚
   1240 β”‚     └── Cross-reference findings with prefetch, evtx, network  β”‚
   1241 β”‚                                                                 β”‚
   1242 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
   1243 ```
   1244 
   1245 **IOC Indicators to Look For:**
   1246 1. PowerShell with `-enc` or `-encodedcommand` parameters
   1247 2. Processes spawning from unusual parents (e.g., Excel β†’ cmd.exe)
   1248 3. RWX memory regions in legitimate processes (e.g., MsMpEng.exe)
   1249 4. Connections to known bad IPs or unusual ports
   1250 5. Single-character executable names
   1251 6. Processes running from temp directories
   1252 
   1253 ---
   1254 
   1255 ### Workflow 2: Event Log Analysis
   1256 
   1257 ```
   1258 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
   1259 β”‚                    EVENT LOG ANALYSIS                          β”‚
   1260 β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
   1261 β”‚                                                                 β”‚
   1262 β”‚  1. PARSE LOGS TO CSV                                          β”‚
   1263 β”‚     β”œβ”€β”€ EvtxECmd.exe -f Security.evtx --csv <output>           β”‚
   1264 β”‚     β”œβ”€β”€ EvtxECmd.exe -f System.evtx --csv <output>             β”‚
   1265 β”‚     └── EvtxECmd.exe -f *PowerShell*.evtx --csv <output>       β”‚
   1266 β”‚                                                                 β”‚
   1267 β”‚  2. THREAT HUNTING                                             β”‚
   1268 β”‚     β”œβ”€β”€ Hayabusa: hayabusa csv-timeline -d <logs> -o timeline  β”‚
   1269 β”‚     └── Chainsaw: chainsaw hunt <logs> -s <sigma_rules>        β”‚
   1270 β”‚                                                                 β”‚
   1271 β”‚  3. AUTHENTICATION ANALYSIS                                    β”‚
   1272 β”‚     β”œβ”€β”€ Filter EventID 4624 (Successful logons)                β”‚
   1273 β”‚     β”œβ”€β”€ Filter EventID 4625 (Failed logons)                    β”‚
   1274 β”‚     β”œβ”€β”€ Look for Type 3 logons (network) between hosts         β”‚
   1275 β”‚     └── Identify 4672 events (special privileges)              β”‚
   1276 β”‚                                                                 β”‚
   1277 β”‚  4. PROCESS CREATION (if auditing enabled)                     β”‚
   1278 β”‚     └── Filter EventID 4688 for command lines                  β”‚
   1279 β”‚                                                                 β”‚
   1280 β”‚  5. POWERSHELL ANALYSIS                                        β”‚
   1281 β”‚     β”œβ”€β”€ Filter EventID 4104 (Script Block Logging)             β”‚
   1282 β”‚     └── Search for: -enc, FromBase64, DownloadString, IEX      β”‚
   1283 β”‚                                                                 β”‚
   1284 β”‚  6. SERVICE INSTALLATION                                       β”‚
   1285 β”‚     β”œβ”€β”€ Filter EventID 7045 (New service installed)            β”‚
   1286 β”‚     └── Look for unusual service names/paths                   β”‚
   1287 β”‚                                                                 β”‚
   1288 β”‚  7. LOG CLEARING DETECTION                                     β”‚
   1289 β”‚     β”œβ”€β”€ Filter EventID 1102 (Security log cleared)             β”‚
   1290 β”‚     └── Filter EventID 104 (System log cleared)                β”‚
   1291 β”‚                                                                 β”‚
   1292 β”‚  8. VISUALISE IN TIMELINE EXPLORER                             β”‚
   1293 β”‚     └── Open CSVs, group by EventID, filter by timeframe       β”‚
   1294 β”‚                                                                 β”‚
   1295 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
   1296 ```
   1297 
   1298 ---
   1299 
   1300 ### Workflow 3: Registry Analysis
   1301 
   1302 ```
   1303 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
   1304 β”‚                    REGISTRY ANALYSIS                           β”‚
   1305 β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
   1306 β”‚                                                                 β”‚
   1307 β”‚  1. PERSISTENCE MECHANISMS                                     β”‚
   1308 β”‚     β”œβ”€β”€ RECmd.exe -f SOFTWARE --kn "...\\CurrentVersion\\Run"    β”‚
   1309 β”‚     β”œβ”€β”€ RECmd.exe -f NTUSER.DAT --kn "...\\CurrentVersion\\Run"  β”‚
   1310 β”‚     └── Check RunOnce, RunServices, Userinit                   β”‚
   1311 β”‚                                                                 β”‚
   1312 β”‚  2. SERVICE ANALYSIS                                           β”‚
   1313 β”‚     β”œβ”€β”€ RECmd.exe -f SYSTEM --kn "ControlSet001\\Services"      β”‚
   1314 β”‚     └── Look for unusual ImagePath values                      β”‚
   1315 β”‚                                                                 β”‚
   1316 β”‚  3. EXECUTION EVIDENCE                                         β”‚
   1317 β”‚     β”œβ”€β”€ AppCompatCacheParser.exe -f SYSTEM --csv <output>      β”‚
   1318 β”‚     β”œβ”€β”€ AmcacheParser.exe -f Amcache.hve --csv <output>        β”‚
   1319 β”‚     └── Cross-reference with Prefetch                          β”‚
   1320 β”‚                                                                 β”‚
   1321 β”‚  4. DELETED ENTRY RECOVERY                                     β”‚
   1322 β”‚     └── RECmd.exe -f <hive> --recover --csv <output>           β”‚
   1323 β”‚                                                                 β”‚
   1324 β”‚  5. BATCH PROCESSING                                           β”‚
   1325 β”‚     └── RECmd.exe -f <hive> --bn RECmd_Batch_MC.reb --csv      β”‚
   1326 β”‚                                                                 β”‚
   1327 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
   1328 ```
   1329 
   1330 ---
   1331 
   1332 ### Workflow 4: Complete Investigation Timeline
   1333 
   1334 ```
   1335 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
   1336 β”‚               MASTER TIMELINE CREATION                         β”‚
   1337 β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
   1338 β”‚                                                                 β”‚
   1339 β”‚  1. COLLECT TIMESTAMPS FROM ALL SOURCES                        β”‚
   1340 β”‚     β”œβ”€β”€ Prefetch: PECmd -d <dir> --csv <output>                β”‚
   1341 β”‚     β”œβ”€β”€ Event Logs: EvtxECmd -d <dir> --csv <output>           β”‚
   1342 β”‚     β”œβ”€β”€ Registry: AppCompatCacheParser, AmcacheParser          β”‚
   1343 β”‚     β”œβ”€β”€ Memory: vol3 timeline, MemProcFS forensic              β”‚
   1344 β”‚     └── Network: tshark extraction                             β”‚
   1345 β”‚                                                                 β”‚
   1346 β”‚  2. NORMALISE TIMESTAMPS                                       β”‚
   1347 β”‚     β”œβ”€β”€ Ensure consistent timezone (UTC recommended)           β”‚
   1348 β”‚     └── Use consistent date format (--dt "dd/MM/yyyy HH:mm:ss")β”‚
   1349 β”‚                                                                 β”‚
   1350 β”‚  3. MERGE INTO UNIFIED TIMELINE                                β”‚
   1351 β”‚     β”œβ”€β”€ Option A: PowerShell script to combine CSVs            β”‚
   1352 β”‚     └── Option B: Plaso for automatic super timeline           β”‚
   1353 β”‚                                                                 β”‚
   1354 β”‚  4. ANALYSE IN TIMELINE EXPLORER                               β”‚
   1355 β”‚     β”œβ”€β”€ Sort by timestamp                                      β”‚
   1356 β”‚     β”œβ”€β”€ Filter by timeframe of interest                        β”‚
   1357 β”‚     β”œβ”€β”€ Group by source for pattern identification             β”‚
   1358 β”‚     └── Tag key events with Ctrl+T                             β”‚
   1359 β”‚                                                                 β”‚
   1360 β”‚  5. VALIDATE AGAINST KNOWN FACTS                               β”‚
   1361 β”‚     β”œβ”€β”€ Confirm initial access timestamp                       β”‚
   1362 β”‚     β”œβ”€β”€ Verify lateral movement timing                         β”‚
   1363 β”‚     └── Document discrepancies                                 β”‚
   1364 β”‚                                                                 β”‚
   1365 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
   1366 ```
   1367 
   1368 ---
   1369 
   1370 ## Advanced Integration Techniques
   1371 
   1372 ### YARA Rules with Volatility
   1373 
   1374 ```bash
   1375 # Create comprehensive rule file
   1376 cat << 'EOF' > cobalt_strike_memory.yar
   1377 rule CobaltStrike_Beacon_x64
   1378 {
   1379     meta:
   1380         description = "Cobalt Strike Beacon x64"
   1381         author = "DFIR Team"
   1382     strings:
   1383         $a1 = { 4C 8B DC 49 89 5B 08 49 89 6B 10 49 89 73 18 }
   1384         $a2 = { 48 89 5C 24 08 48 89 74 24 10 57 48 83 EC 20 }
   1385         $s1 = "beacon.dll" ascii
   1386         $s2 = "beacon.x64.dll" ascii
   1387     condition:
   1388         any of them
   1389 }
   1390 
   1391 rule Reflective_Loader
   1392 {
   1393     meta:
   1394         description = "Reflective DLL Loader"
   1395     strings:
   1396         $mz = { 4D 5A }
   1397         $reflective = { 48 8B C4 48 89 58 08 48 89 68 10 48 89 70 18 }
   1398     condition:
   1399         $mz at 0 and $reflective
   1400 }
   1401 EOF
   1402 
   1403 # Run against memory dump
   1404 vol3 -f memory.bin windows.vadyarascan --yara-file cobalt_strike_memory.yar
   1405 ```
   1406 
   1407 ---
   1408 
   1409 ### Automated Multi-Host Processing
   1410 
   1411 ```powershell
   1412 # Process multiple hosts with EZ Tools
   1413 $hosts = @("LAPTOP-135", "WORKSTATION-969", "DESKTOP-841")
   1414 $evidencePath = "D:\Evidence\ForensicsLab_S1\Working"
   1415 $outputPath = "D:\Output"
   1416 
   1417 foreach ($host in $hosts) {
   1418     # Create output directory
   1419     New-Item -ItemType Directory -Force -Path "$outputPath\$host\Memory"
   1420     New-Item -ItemType Directory -Force -Path "$outputPath\$host\EventLogs"
   1421     New-Item -ItemType Directory -Force -Path "$outputPath\$host\Prefetch"
   1422     New-Item -ItemType Directory -Force -Path "$outputPath\$host\Registry"
   1423     
   1424     # Process Prefetch
   1425     PECmd.exe -d "$evidencePath\Prefetch\$host" --csv "$outputPath\$host\Prefetch" `
   1426         --csvf "Prefetch_$host.csv" --dt "dd/MM/yyyy HH:mm:ss"
   1427     
   1428     # Process Event Logs
   1429     EvtxECmd.exe -d "$evidencePath\EventLogs\$host" --csv "$outputPath\$host\EventLogs" `
   1430         --dt "dd/MM/yyyy HH:mm:ss"
   1431     
   1432     # Process Registry
   1433     RECmd.exe -f "$evidencePath\Registry\$host\SOFTWARE" `
   1434         --bn "RECmd_Batch_MC.reb" --csv "$outputPath\$host\Registry" `
   1435         --dt "dd/MM/yyyy HH:mm:ss"
   1436     
   1437     # Process ShimCache
   1438     AppCompatCacheParser.exe -f "$evidencePath\Registry\$host\SYSTEM" `
   1439         --csv "$outputPath\$host\Registry" --csvf "ShimCache_$host.csv" `
   1440         --dt "dd/MM/yyyy HH:mm:ss"
   1441     
   1442     # Process Amcache
   1443     AmcacheParser.exe -f "$evidencePath\Registry\$host\Amcache.hve" `
   1444         --csv "$outputPath\$host\Registry" --csvf "Amcache_$host.csv" `
   1445         --dt "dd/MM/yyyy HH:mm:ss"
   1446 }
   1447 
   1448 Write-Host "Processing complete for all hosts."
   1449 ```
   1450 
   1451 ---
   1452 
   1453 ### Handling Corrupted Artifacts
   1454 
   1455 ```powershell
   1456 # Memory dumps may be incomplete - use Volatility recovery options
   1457 vol3 -f <corrupted_memory.bin> windows.pslist 2>&1 | Tee-Object -FilePath error_log.txt
   1458 
   1459 # For corrupted registry hives - use Registry Explorer (tolerant of dirty hives)
   1460 # Or use RECmd with --recover flag
   1461 RECmd.exe -f <dirty_hive> --recover --csv <output>
   1462 
   1463 # For truncated prefetch files
   1464 PECmd.exe -f <file.pf> 2>&1 | Tee-Object -FilePath pf_errors.txt
   1465 # PECmd will process what it can and report errors
   1466 
   1467 # Validate evidence integrity before and after analysis
   1468 certutil -hashfile <evidence_file> SHA256 > pre_analysis_hash.txt
   1469 # After analysis
   1470 certutil -hashfile <evidence_file> SHA256 > post_analysis_hash.txt
   1471 fc pre_analysis_hash.txt post_analysis_hash.txt
   1472 ```
   1473 
   1474 ---
   1475 
   1476 ## SANS Tools Quick Reference
   1477 
   1478 | Tool | Purpose | Author | Download |
   1479 |------|---------|--------|----------|
   1480 | **SIFT Workstation** | Complete forensic Linux distro | Rob T. Lee | https://www.sans.org/tools/sift-workstation |
   1481 | **KAPE** | Artifact collection & processing | Eric Zimmerman | https://www.sans.org/tools/kape |
   1482 | **PECmd** | Prefetch parser | Eric Zimmerman | https://ericzimmerman.github.io |
   1483 | **EvtxECmd** | Event log parser | Eric Zimmerman | https://ericzimmerman.github.io |
   1484 | **RECmd** | Registry command-line parser | Eric Zimmerman | https://ericzimmerman.github.io |
   1485 | **Registry Explorer** | Registry GUI viewer | Eric Zimmerman | https://ericzimmerman.github.io |
   1486 | **AppCompatCacheParser** | ShimCache parser | Eric Zimmerman | https://ericzimmerman.github.io |
   1487 | **AmcacheParser** | Amcache parser with hashes | Eric Zimmerman | https://ericzimmerman.github.io |
   1488 | **Timeline Explorer** | CSV/Excel forensic viewer | Eric Zimmerman | https://ericzimmerman.github.io |
   1489 | **MFTECmd** | MFT parser | Eric Zimmerman | https://ericzimmerman.github.io |
   1490 | **JLECmd** | Jump List parser | Eric Zimmerman | https://ericzimmerman.github.io |
   1491 | **LECmd** | LNK file parser | Eric Zimmerman | https://ericzimmerman.github.io |
   1492 | **SBECmd** | ShellBags parser | Eric Zimmerman | https://ericzimmerman.github.io |
   1493 | **APOLLO** | iOS/macOS artefact parser | Sarah Edwards | https://www.sans.org/tools/apollo |
   1494 | **Android Triage** | Android artefact collection | Mattia Epifani | https://www.sans.org/tools/android-triage |
   1495 
   1496 ---
   1497 
   1498 ## Additional Industry-Standard Tools
   1499 
   1500 **Memory Analysis (Beyond Volatility):**
   1501 
   1502 | Tool | Purpose | Source |
   1503 |------|---------|--------|
   1504 | **Rekall** | Memory forensics framework (deprecated but useful for older images) | https://github.com/google/rekall |
   1505 | **WinDbg** | Microsoft debugger for crash dump analysis | Microsoft Store |
   1506 | **Redline** | Memory and IOC analysis (FireEye/Mandiant) | https://www.fireeye.com/services/freeware/redline.html |
   1507 
   1508 **Event Log Analysis (Beyond EvtxECmd):**
   1509 
   1510 | Tool | Purpose | Source |
   1511 |------|---------|--------|
   1512 | **Zircolite** | SIGMA-based EVTX detection | https://github.com/wagga40/Zircolite |
   1513 | **DeepBlueCLI** | PowerShell-based threat hunting | https://github.com/sans-blue-team/DeepBlueCLI |
   1514 | **LogParser** | SQL-like queries on logs | Microsoft |
   1515 
   1516 **Network Forensics:**
   1517 
   1518 | Tool | Purpose | Source |
   1519 |------|---------|--------|
   1520 | **Wireshark/tshark** | Packet capture and analysis | https://www.wireshark.org |
   1521 | **NetworkMiner** | Network forensic analysis | https://www.netresec.com |
   1522 | **Zeek (Bro)** | Network security monitoring | https://zeek.org |
   1523 
   1524 **Timeline Analysis:**
   1525 
   1526 | Tool | Purpose | Source |
   1527 |------|---------|--------|
   1528 | **Plaso/Log2Timeline** | Super timeline creation | https://github.com/log2timeline/plaso |
   1529 | **Timesketch** | Collaborative timeline analysis | https://timesketch.org |
   1530 
   1531 ---
   1532 
   1533 ## Command Reference Card
   1534 
   1535 ### Hash Verification
   1536 ```cmd
   1537 certutil -hashfile <file> SHA256
   1538 certutil -hashfile <file> MD5
   1539 ```
   1540 
   1541 ### Volatility 3 Essential Commands
   1542 ```bash
   1543 vol3 -f <mem> windows.info
   1544 vol3 -f <mem> windows.pslist
   1545 vol3 -f <mem> windows.pstree
   1546 vol3 -f <mem> windows.cmdline
   1547 vol3 -f <mem> windows.malfind
   1548 vol3 -f <mem> windows.netscan
   1549 vol3 -f <mem> windows.dlllist --pid <PID>
   1550 vol3 -f <mem> windows.handles --pid <PID>
   1551 vol3 -f <mem> windows.vadyarascan --yara-file <rules.yar>
   1552 ```
   1553 
   1554 ### MemProcFS
   1555 ```cmd
   1556 memprocfs.exe -device <mem> -forensic 1
   1557 memprocfs.exe -device <mem> -forensic 1 -license-accept-elastic-license-2.0
   1558 ```
   1559 
   1560 ### Eric Zimmerman Tools
   1561 ```cmd
   1562 PECmd.exe -d <prefetch_dir> --csv <out> --dt "dd/MM/yyyy HH:mm:ss"
   1563 EvtxECmd.exe -f <evtx> --csv <out> --dt "dd/MM/yyyy HH:mm:ss"
   1564 RECmd.exe -f <hive> --bn RECmd_Batch_MC.reb --csv <out>
   1565 AppCompatCacheParser.exe -f <SYSTEM> --csv <out>
   1566 AmcacheParser.exe -f <Amcache.hve> --csv <out>
   1567 ```
   1568 
   1569 ### YARA
   1570 ```bash
   1571 yara -r <rules.yar> <target_directory>
   1572 yara -s <rules.yar> <file>  # Print matching strings
   1573 ```
   1574 
   1575 ### CAPA
   1576 ```bash
   1577 capa <executable>
   1578 capa -vv <executable>  # Very verbose
   1579 capa -j <executable> > results.json
   1580 ```
   1581 
   1582 ---
   1583 
   1584 ## References & Further Reading
   1585 
   1586 **Official Documentation:**
   1587 1. [SANS Tools Repository](https://www.sans.org/tools) β€” Complete collection of SANS forensic tools
   1588 2. [Eric Zimmerman's Tools](https://ericzimmerman.github.io) β€” Complete EZ Tools suite
   1589 3. [Volatility Foundation](https://github.com/volatilityfoundation/volatility3) β€” Volatility 3 framework
   1590 4. [MemProcFS GitHub](https://github.com/ufrisk/MemProcFS) β€” Memory process file system
   1591 5. [CAPA GitHub](https://github.com/mandiant/capa) β€” Mandiant malware capability detector
   1592 6. [YARA Documentation](https://yara.readthedocs.io/) β€” Official YARA docs
   1593 7. [Hayabusa GitHub](https://github.com/Yamato-Security/hayabusa) β€” SIGMA-based threat hunting
   1594 8. [Chainsaw GitHub](https://github.com/WithSecureLabs/chainsaw) β€” Log hunting tool
   1595 
   1596 **DFIR Learning Resources:**
   1597 1. [SANS DFIR Blog](https://www.sans.org/blog/?focus-area=digital-forensics) β€” Latest DFIR techniques
   1598 2. [13Cubed YouTube](https://www.youtube.com/c/13Cubed) β€” Forensic tool tutorials
   1599 3. [HackTricks](https://book.hacktricks.xyz/) β€” Penetration testing and forensics
   1600 4. [Ultimate Windows Security](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/) β€” Event ID encyclopedia
   1601 
   1602 **MITRE ATT&CK:**
   1603 1. [MITRE ATT&CK Framework](https://attack.mitre.org/) β€” Adversary tactics and techniques
   1604 2. [T1055: Process Injection](https://attack.mitre.org/techniques/T1055/) β€” Process injection techniques
   1605 3. [T1059: Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059/) β€” PowerShell, cmd.exe
   1606 
   1607 **Cobalt Strike Detection:**
   1608 1. [Cobalt Strike Detection](https://thedfirreport.com/category/cobalt-strike/) β€” Real-world Beacon analysis
   1609 2. [Detecting Cobalt Strike with Memory Forensics](https://www.volexity.com/blog/2021/12/09/detecting-cobalt-strike-with-memory-forensics/) β€” Volexity research
   1610 
   1611 ---
   1612 
   1613 #HTB-Academy #DFIR #Digital-Forensics #Incident-Response #Memory-Analysis #Volatility #MemProcFS #CAPA #YARA #SANS-Tools #EZ-Tools #PECmd #EvtxECmd #RECmd #AppCompatCacheParser #AmcacheParser #Prefetch #Registry #Event-Logs #Hayabusa #Chainsaw #KAPE #Timeline-Explorer #Plaso #Malware-Analysis #Windows-Forensics #SIFT-Workstation #MITRE-T1055 #MITRE-T1059 #MITRE-T1547 #Cobalt-Strike #Process-Injection #Timeline-Analysis #Artifact-Parsing #CPTS #CDSA #Medium
   1614 
   1615 
   1616 ------
   1617 
   1618 # Running MemprocFS on mac with FUSE
   1619    1. Navigate to the `files` directory:
   1620 ```bash
   1621 cd /Users/daemon1/DigitalForensics/Tools/memprocfs/files
   1622 ```
   1623    2. Ensure the mount point exists:
   1624 ```bash
   1625 mkdir -p mnt
   1626 ```
   1627    3. Run `memprocfs`:
   1628 ```bash
   1629 ./memprocfs -device ../../../Working/CMP416-2202336-CW2/WORKSTATION-969/memory/memory.bin -forensic 1 -forensic-yara-rules ../../yara-rules/index.yar -mount mnt/
   1630 ```
   1631 `-disable-python -v` if you need to
   1632 
   1633 ---
   1634 
   1635 ## Key Updates & Enhancements to Add
   1636 
   1637 ### **Volatility 3 Updates (v2.26.0 - Feature Parity Release, May 2025)**
   1638 
   1639 **Major Changes:**
   1640 - **Volatility 2 is now officially deprecated** - The GitHub repository has been archived
   1641 - **No more `--profile` argument required** - Volatility 3 automatically detects OS versions
   1642 - **New `--filters` flag** - Column-specific filtering without grep/awk
   1643 - **Unified output formats** - All plugins support csv, json, jsonl, pretty output via `-r` option
   1644 - **Consistent data extraction** - All plugins use `-o` for output directory and `--dump` option
   1645 
   1646 **New Plugins (Add to your commands):**
   1647 
   1648 ```bash
   1649 # New Windows plugins (v2.26.0)
   1650 vol3 -f <mem> windows.hollowprocesses      # Detect process hollowing
   1651 vol3 -f <mem> windows.psxview              # Cross-reference process lists (hidden process detection)
   1652 vol3 -f <mem> windows.suspicious_threads   # Find suspicious userland threads
   1653 vol3 -f <mem> windows.suspended_threads    # Enumerate suspended threads
   1654 vol3 -f <mem> windows.direct_system_calls  # Detect direct syscalls (EDR bypass)
   1655 vol3 -f <mem> windows.indirect_system_calls # Detect indirect syscalls
   1656 vol3 -f <mem> windows.shimcachemem         # ShimCache from memory
   1657 vol3 -f <mem> windows.scheduled_tasks      # Decode scheduled tasks from registry
   1658 vol3 -f <mem> windows.svclist              # List services from doubly-linked list
   1659 vol3 -f <mem> windows.svcdiff              # Compare services (walking vs scanning) for rootkit detection
   1660 vol3 -f <mem> windows.processghosting      # Detect process ghosting technique
   1661 vol3 -f <mem> windows.pedump               # Extract PE files from specific addresses
   1662 
   1663 # New filtering example
   1664 vol3 -f <mem> --filters "ImageFileName=powershell" windows.pslist
   1665 vol3 -f <mem> --filters "Start VPN=0x1000000" windows.vadinfo
   1666 
   1667 # Pretty output (aligned tables)
   1668 vol3 -f <mem> -r pretty windows.pslist
   1669 ```
   1670 
   1671 ---
   1672 
   1673 ### **MemProcFS Updates (v5.15 - Latest, June 2025)**
   1674 
   1675 **New Features to Add:**
   1676 
   1677 | Version | Key Features |
   1678 |---------|-------------|
   1679 | v5.15 | Linux LeechAgent support (gRPC), **High Entropy detection** in FindEvil, DNS cache parsing |
   1680 | v5.14 | **macOS support**, Linux clang compilation |
   1681 | v5.13 | Console module, File recovery improvements, **Callstack parsing for x64 processes** |
   1682 | v5.12 | New APIs for Kernel Objects, Drivers and Devices |
   1683 | v5.10 | Windows 11 24H2 support, **Hibernation file support**, Prefetch parsing, Sysinfo module, Eventlog module |
   1684 | v5.9 | FindEvil shows Windows Defender AV detections, Proxmox dump support |
   1685 
   1686 **Updated Commands:**
   1687 
   1688 ```cmd
   1689 :: New sysinfo module for easy system info
   1690 memprocfs.exe -device <mem> -forensic 1
   1691 :: Then browse M:\forensic\sysinfo\
   1692 
   1693 :: DNS cache parsing (new in v5.15)
   1694 :: Available at M:\forensic\dns\
   1695 
   1696 :: Eventlog module (v5.10+)
   1697 :: Available at M:\forensic\eventlog\
   1698 
   1699 :: Console module (v5.13+)
   1700 :: Available at M:\name\<process>\console\
   1701 
   1702 :: High entropy detection
   1703 :: FindEvil now flags high entropy regions (potential packed/encrypted code)
   1704 ```
   1705 
   1706 **New Virtual File System Directories:**
   1707 
   1708 | Directory | Contents | Version Added |
   1709 |-----------|----------|---------------|
   1710 | `M:\forensic\sysinfo\` | Easy-to-read system information | v5.10 |
   1711 | `M:\forensic\eventlog\` | Convenient event log access | v5.10 |
   1712 | `M:\forensic\dns\` | DNS cache entries | v5.15 |
   1713 | `M:\name\<proc>\console\` | Console buffer contents | v5.13 |
   1714 | `M:\name\<proc>\callstack\` | x64 user-mode callstacks | v5.13 |
   1715 
   1716 ---
   1717 
   1718 ### **Hayabusa Updates (v3.3.0 - Latest, May 2025)**
   1719 
   1720 **Major New Features:**
   1721 
   1722 ```bash
   1723 # New "Emergency" alert level for critical systems (v3.1.0+)
   1724 # Add critical system names to config/critical_systems.txt
   1725 # Alerts are automatically elevated one level on those systems
   1726 
   1727 # Auto-detect domain controllers and file servers
   1728 hayabusa config-critical-systems -d <evtx_dir>
   1729 
   1730 # Extract and decode Base64 strings (v3.0.0+)
   1731 hayabusa extract-base64 -d <evtx_dir> -o base64_decoded.csv
   1732 
   1733 # Log metrics command (v2.19.0+)
   1734 hayabusa log-metrics -d <evtx_dir> -o log_metrics.csv
   1735 
   1736 # Tab-separated output for field info
   1737 hayabusa csv-timeline -d <evtx_dir> -o timeline.csv -S
   1738 
   1739 # Sigma V2 correlation rules support (v3.0.0+)
   1740 # - temporal (Temporal Proximity)
   1741 # - temporal_ordered (Temporal Ordered Proximity)
   1742 # - expand field modifiers
   1743 
   1744 # XOR-encoded rules to bypass AV false positives (v2.18.0+)
   1745 # Use live-response packages from releases
   1746 ```
   1747 
   1748 **New Command Summary:**
   1749 
   1750 | Command | Purpose | Version |
   1751 |---------|---------|---------|
   1752 | `extract-base64` | Extract and decode Base64 from events | v3.0.0 |
   1753 | `expand-list` | List placeholder names for expand rules | v3.0.0 |
   1754 | `log-metrics` | Get .evtx file information | v2.19.0 |
   1755 | `config-critical-systems` | Auto-find DCs and file servers | v3.1.0 |
   1756 
   1757 **Performance Improvements:**
   1758 - Low memory mode enabled by default
   1759 - Significantly faster `logon-summary` with channel filtering
   1760 - `search` command no longer sorts by default (use `-s` to sort)
   1761 
   1762 ---
   1763 
   1764 ### **KAPE Updates (2024-2025)**
   1765 
   1766 **Key Compound Targets:**
   1767 
   1768 | Target | Description |
   1769 |--------|-------------|
   1770 | `KapeTriage` | Comprehensive triage - Registry, Event Logs, Prefetch, Amcache, etc. |
   1771 | `!BasicCollection` | Essential forensic artifacts |
   1772 | `!SANS_Triage` | SANS-recommended artifact set |
   1773 | `EvidenceOfExecution` | Prefetch, RecentFileCache, AmCache, SysCache |
   1774 
   1775 **Key Compound Modules:**
   1776 
   1777 | Module | Description |
   1778 |--------|-------------|
   1779 | `!EZParser` | All Eric Zimmerman tools against collected artifacts |
   1780 | `Mini_Timeline` | Generate timeline using TLN tools |
   1781 
   1782 **New Command Examples:**
   1783 
   1784 ```cmd
   1785 :: Collect with KapeTriage and process with EZParser
   1786 kape.exe --tsource C: --tdest D:\Evidence --target KapeTriage --mdest D:\Processed --module !EZParser
   1787 
   1788 :: Output to VHDX container
   1789 kape.exe --tsource C: --tdest D:\Evidence --target KapeTriage --vhdx Evidence_Container
   1790 
   1791 :: Include Volume Shadow Copies
   1792 kape.exe --tsource C: --tdest D:\Evidence --target KapeTriage --vss
   1793 
   1794 :: Sync targets and modules to latest
   1795 kape.exe --sync
   1796 ```
   1797 
   1798 ---
   1799 
   1800 ### **New Tools to Add**
   1801 
   1802 #### **Velociraptor**
   1803 **Purpose:** Enterprise-wide endpoint visibility and DFIR platform. Integrates with Hayabusa for scalable threat hunting.
   1804 
   1805 **Source:** [Velociraptor](https://docs.velociraptor.app/)
   1806 
   1807 ```yaml
   1808 # Hayabusa artifact for Velociraptor
   1809 # Allows enterprise-wide Windows event log analysis
   1810 # Retroactively creates SIEM-like visibility
   1811 ```
   1812 
   1813 #### **Zircolite**
   1814 **Purpose:** Standalone SIGMA-based detection tool for EVTX, Auditd, Sysmon for Linux, and more.
   1815 
   1816 **Source:** [Zircolite GitHub](https://github.com/wagga40/Zircolite)
   1817 
   1818 ```bash
   1819 # Scan with SIGMA rules
   1820 python3 zircolite.py --evtx <evtx_dir> --ruleset rules/rules_windows_generic.json
   1821 ```
   1822 
   1823 #### **DeepBlueCLI**
   1824 **Purpose:** PowerShell-based threat hunting in Windows event logs.
   1825 
   1826 **Source:** [DeepBlueCLI GitHub](https://github.com/sans-blue-team/DeepBlueCLI)
   1827 
   1828 ```powershell
   1829 # Analyze Security log
   1830 .\DeepBlue.ps1 .\Security.evtx
   1831 ```
   1832 
   1833 ---
   1834 
   1835 ### **Updated MITRE ATT&CK Techniques**
   1836 
   1837 Add these commonly detected techniques:
   1838 
   1839 | Technique ID | Name | Detection Method |
   1840 |-------------|------|------------------|
   1841 | **T1055.012** | Process Hollowing | `windows.hollowprocesses` (Vol3) |
   1842 | **T1055.001** | DLL Injection | `windows.malfind` + `windows.ldrmodules` |
   1843 | **T1134** | Access Token Manipulation | `windows.privileges` |
   1844 | **T1218** | System Binary Proxy Execution | Hayabusa SIGMA rules |
   1845 | **T1562.001** | Disable Security Tools | Event ID 1102, 7045 |
   1846 
   1847 ---
   1848 
   1849 ### **Updated Quick Reference Table**
   1850 
   1851 Replace your existing table with this expanded version:
   1852 
   1853 | # | Tool | Primary Use | Key Command | Notes |
   1854 |:--|:-----|:------------|:------------|:------|
   1855 | 1 | **Volatility 3** (v2.26) | Memory forensics | `vol3 -f mem.bin windows.hollowprocesses` | Process hollowing detection |
   1856 | 2 | **MemProcFS** (v5.15) | Memory VFS | `memprocfs.exe -device mem.