forensics.md (72902B)
1 --- 2 title: "Digital Forensics" 3 description: "Cross-platform DFIR reference: acquisition, triage, artifacts, timelines and analysis commands." 4 category: dfir 5 tags: [dfir, forensics, incident-response] 6 tools: [Autopsy, Sleuth Kit, plaso] 7 difficulty: intermediate 8 updated: "2026-08-09" 9 source: "vault:DFIR/Forensics Cheatsheet.md" 10 --- 11 12 # Digital Forensics 13 14 --- 15 16 > **Note β** - π Quick Reference Cheat Sheet 17 > 18 > **Comprehensive forensic tool commands and workflows for Windows incident response.** 19 > 20 > | # | Tool | Primary Use Case | Key Command | Notes | 21 > |:--|:---|:---|:---|:---| 22 > | 1 | **Volatility 3** | Memory forensics | `vol3 -f mem.bin windows.malfind` | Code injection detection | 23 > | 2 | **MemProcFS** | Memory virtual filesystem | `memprocfs.exe -device mem.bin -forensic 1` | Browse memory as files | 24 > | 3 | **CAPA** | Malware capability detection | `capa malware.exe` | Identifies malware behaviours | 25 > | 4 | **YARA** | Pattern matching | `yara -r rules.yar directory/` | Signature-based detection | 26 > | 5 | **PECmd** | Prefetch parsing | `PECmd.exe -d prefetch_dir --csv output/` | Execution evidence | 27 > | 6 | **EvtxECmd** | Event log parsing | `EvtxECmd.exe -f Security.evtx --csv output/` | Windows event logs | 28 > | 7 | **RECmd** | Registry parsing | `RECmd.exe -f SOFTWARE --bn batch.reb --csv output/` | Registry hive analysis | 29 > | 8 | **AppCompatCacheParser** | ShimCache parsing | `AppCompatCacheParser.exe -f SYSTEM --csv output/` | Execution history | 30 > | 9 | **AmcacheParser** | Amcache parsing | `AmcacheParser.exe -f Amcache.hve --csv output/` | SHA1 hashes + paths | 31 > | 10 | **Hayabusa** | SIGMA threat hunting | `hayabusa csv-timeline -d evtx_dir -o timeline.csv` | Rapid log analysis | 32 > | 11 | **Chainsaw** | Log hunting | `chainsaw hunt evtx_dir -s sigma_rules/` | SIGMA-based detection | 33 > | 12 | **KAPE** | Artifact collection | `kape.exe --tsource C: --tdest D:\Evidence --target KapeTriage` | Rapid triage | 34 > | 13 | **Timeline Explorer** | CSV visualization | GUI application | Large CSV analysis | 35 > | 14 | **CertUtil** | Hash calculation | `certutil -hashfile file SHA256` | Evidence integrity | 36 > 37 > --- 38 > 39 > **Key Definitions:** 40 > 1. **Prefetch**: Windows execution tracking files storing program run history and file access patterns 41 > 2. **ShimCache**: Application Compatibility Cache tracking executed programs in SYSTEM registry 42 > 3. **Amcache**: Registry hive containing program execution metadata including SHA1 hashes 43 > 4. **Malfind**: Volatility plugin detecting code injection via memory protection anomalies 44 > 5. **SIGMA Rules**: Generic signature format for log events translated to multiple SIEM formats 45 > 6. **RWX Memory**: Read-Write-Execute memory regions indicating potential code injection 46 > 7. **YARA**: Pattern matching tool using rules to identify malware families 47 > 8. **DFIR**: Digital Forensics and Incident Response 48 > 9. **EZ Tools**: Suite of forensic parsers by Eric Zimmerman (SANS) 49 > 10. **Triage**: Rapid evidence collection and initial analysis 50 51 --- 52 53 ## Tool Source Credibility 54 55 This guide integrates tools from **[SANS Institute](https://www.sans.org/tools)**, containing 100+ cybersecurity utilities maintained by recognized experts. 56 57 **[Eric Zimmerman](https://ericzimmerman.github.io)** (former FBI Special Agent, SANS Principal Instructor) authored the majority of Windows artifact parsers referenced herein. **[Rob T. Lee](https://www.sans.org/profiles/robert-lee/)** (SANS Chief AI Officer) created the **[SIFT Workstation](https://www.sans.org/tools/sift-workstation)**, a comprehensive Ubuntu-based forensic distribution. 58 59 **Tool Selection Criteria**: 60 1. Active maintenance by recognized DFIR experts 61 2. Wide adoption by law enforcement and enterprise security teams 62 3. Free and open-source architecture enabling verification 63 4. Designed for forensic soundness and court-admissible evidence 64 5. Cross-platform compatibility where applicable 65 66 --- 67 68 ## Memory Forensics Fundamentals 69 70 **Memory forensics** extracts digital artifacts from volatile memory (**[RAM](https://en.wikipedia.org/wiki/Random-access_memory)**) snapshots captured during or after incidents. Memory contains evidence unavailable on disk: running processes, network connections, injected code, decrypted data, and cryptographic keys. 71 72 **Process injection** techniques (**[MITRE T1055](https://attack.mitre.org/techniques/T1055/)**) hide malicious code within legitimate processes, detectable via memory analysis. **[Cobalt Strike](https://www.cobaltstrike.com/)** Beacons commonly use reflective DLL injection into legitimate Windows processes (explorer.exe, svchost.exe). 73 74 Memory analysis requires acquisition tools like **[WinPMEM](https://github.com/Velocidex/WinPmem)**, **[DumpIt](https://www.magnetforensics.com/)**, or **[FTK Imager](https://www.exterro.com/ftk-imager)** to create forensically sound memory dumps. Memory dumps range from 4GB to 64GB+ depending on system RAM, requiring sufficient storage and processing capacity. 75 76 --- 77 78 ## Memory Analysis Tools 79 80 ### Volatility 3 81 82 **Purpose:** Advanced memory forensics framework for extracting digital artifacts from volatile memory (RAM) dumps. Industry-standard tool supporting Windows, Linux, and macOS. 83 84 **Source:** [Volatility Foundation](https://github.com/volatilityfoundation/volatility3) 85 86 **Platforms:** Windows, Linux, macOS 87 88 **Installation:** 89 ```bash 90 # Linux/macOS 91 pip3 install volatility3 92 93 # Windows 94 pip install volatility3 95 96 # From source 97 git clone https://github.com/volatilityfoundation/volatility3.git 98 cd volatility3 99 pip3 install -r requirements.txt 100 python3 setup.py install 101 ``` 102 103 **Usage:** 104 ```bash 105 # Identify memory image profile (auto-detection in Vol3) 106 vol3 -f <memory.bin> windows.info 107 108 # Process enumeration 109 vol3 -f <memory.bin> windows.pslist 110 vol3 -f <memory.bin> windows.pstree 111 vol3 -f <memory.bin> windows.cmdline 112 113 # Code injection detection (critical for Cobalt Strike detection) 114 vol3 -f <memory.bin> windows.malfind 115 vol3 -f <memory.bin> windows.malfind --pid <PID> 116 117 # Dump suspicious memory regions 118 vol3 -f <memory.bin> -o <output_dir> windows.malfind --dump 119 120 # Network connections 121 vol3 -f <memory.bin> windows.netscan 122 vol3 -f <memory.bin> windows.netstat 123 124 # DLL analysis 125 vol3 -f <memory.bin> windows.dlllist --pid <PID> 126 vol3 -f <memory.bin> windows.ldrmodules 127 128 # Handle analysis 129 vol3 -f <memory.bin> windows.handles --pid <PID> 130 131 # YARA scanning integration 132 vol3 -f <memory.bin> windows.vadyarascan --yara-file <rules.yar> 133 ``` 134 135 **Use Cases:** 136 1. Detect process injection techniques (reflective DLL injection, process hollowing) 137 2. Identify Cobalt Strike Beacons via malfind RWX memory regions 138 3. Extract network connections to C2 infrastructure 139 4. Recover command-line arguments revealing encoded payloads 140 5. Identify loaded drivers and kernel modules 141 142 **Integration:** 143 1. Output can be piped to `grep`, `awk`, or Timeline Explorer 144 2. Combine with YARA rules for signature-based detection 145 3. Results can feed into timeline analysis with Plaso 146 147 --- 148 149 > **Note β** - Practical Application: Volatility 3 Memory Analysis 150 > 151 > **Context**: Initial triage of memory dump to identify suspicious processes and code injection. 152 > 153 > ```bash 154 > # Step 1: Verify memory dump and identify system profile 155 > vol3 -f memory.bin windows.info 156 > ``` 157 > 158 > ```plaintext 159 > Volatility 3 Framework 2.5.0 160 > 161 > Variable Value 162 > Kernel Base 0xf8000xxxxx 163 > DTB 0x1ab000 164 > Symbols ntkrnlmp.pdb 165 > Is64Bit True 166 > IsPAE False 167 > layer_name 0 WindowsIntel32e 168 > memory_layer 1 FileLayer 169 > KdVersionBlock 0xf80002xxxxxx 170 > Major/Minor 15.19041 171 > MachineType 34404 172 > KeNumberProcessors 4 173 > SystemTime 2024-01-15 14:23:45 174 > ``` 175 > 176 > **Output Analysis:** 177 > 1. **Kernel Base**: Memory address of Windows kernelβvalidates dump integrity 178 > 2. **DTB (Directory Table Base)**: Physical address of page directory for virtual memory translation 179 > 3. **Is64Bit**: Confirms architecture (x64 vs x86) 180 > 4. **Major/Minor 15.19041**: Windows 10 Build 19041 (Version 2004) 181 > 5. **SystemTime**: Timestamp when memory dump was created 182 183 --- 184 185 **Process Enumeration:** 186 187 ```bash 188 # List all processes 189 vol3 -f memory.bin windows.pslist > pslist.txt 190 191 # Generate process tree showing parent-child relationships 192 vol3 -f memory.bin windows.pstree > pstree.txt 193 194 # Extract command-line arguments (reveals PowerShell encoded commands) 195 vol3 -f memory.bin windows.cmdline > cmdline.txt 196 ``` 197 198 **Example Output:** 199 ```plaintext 200 PID PPID ImageFileName Offset(V) Threads Handles SessionId Wow64 CreateTime ExitTime 201 202 4 0 System 0x8a0ba1c0 152 - N/A False 2024-01-15 08:00:00.000000 N/A 203 392 4 smss.exe 0x8b3c4040 2 - N/A False 2024-01-15 08:00:01.000000 N/A 204 512 504 csrss.exe 0x8e2a8580 9 - 0 False 2024-01-15 08:00:03.000000 N/A 205 1432 1424 explorer.exe 0x8f1a2080 45 - 1 False 2024-01-15 08:05:12.000000 N/A 206 2856 1432 powershell.exe 0x9a4b3580 12 - 1 False 2024-01-15 14:15:33.000000 N/A 207 3104 2856 whoami.exe 0x9c2e1040 0 - 1 False 2024-01-15 14:15:41.000000 2024-01-15 14:15:42 208 ``` 209 210 **Key Fields:** 211 - **PID**: Process IDβunique identifier 212 - **PPID**: Parent Process IDβreveals process spawning relationships 213 - **ImageFileName**: Executable name 214 - **CreateTime**: Process start timestamp 215 - **SessionId**: User session (0=System, 1+=User sessions) 216 217 **Red Flags:** 218 1. Single-character executable names (a.exe, x.exe) 219 2. Processes spawning from temp directories 220 3. PowerShell spawned by unexpected parents (winword.exe, excel.exe) 221 4. Multiple PowerShell instances with short lifespans 222 223 --- 224 225 **Code Injection Detection:** 226 227 ```bash 228 # Detect injected code via memory protection anomalies 229 vol3 -f memory.bin windows.malfind > malfind.txt 230 231 # Dump suspicious memory regions for analysis 232 vol3 -f memory.bin -o dumps/ windows.malfind --dump 233 234 # Target specific suspicious process 235 vol3 -f memory.bin windows.malfind --pid 2856 236 ``` 237 238 **Example Output:** 239 ```plaintext 240 PID Process Start VPN End VPN Tag Protection CommitCharge PrivateMemory File output Hexdump Disasm 241 242 2856 powershell.exe 0x2a40000 0x2a70000 VadS PAGE_EXECUTE_READWRITE 192 1 Disabled 243 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 MZ.............. 244 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 ........@....... 245 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 246 00 00 00 00 00 00 00 00 00 00 00 00 f8 00 00 00 ................ 247 248 0x2a40000: MZ ; PE header signature 249 0x2a40040: PUSH RBP 250 0x2a40041: MOV RBP, RSP 251 0x2a40044: SUB RSP, 0x20 252 ``` 253 254 **Indicators of Compromise:** 255 1. **PAGE_EXECUTE_READWRITE**: RWX permissionsβrare in legitimate code, common in injected payloads 256 2. **MZ header (0x4d5a)**: PE file signature indicating reflective DLL injection 257 3. **VadS tag**: Private memory allocation via VirtualAllocβcommon injection technique 258 4. **Disassembly shows prologue**: Standard x64 function prologue suggesting shellcode 259 260 **Next Steps:** 261 1. Dump flagged regions: `vol3 -f mem.bin -o dumps/ windows.malfind --dump` 262 2. Analyze with CAPA: `capa dumps/pid.2856.vad.0x2a40000-0x2a70000.dmp` 263 3. Scan with YARA: `yara cobalt_strike.yar dumps/` 264 4. Extract strings: `strings -el dumps/*.dmp | grep -i "http\|sleep\|pipe"` 265 266 --- 267 268 **Network Connection Analysis:** 269 270 ```bash 271 # Extract all network connections (TCP/UDP) 272 vol3 -f memory.bin windows.netscan > netscan.txt 273 274 # Alternative plugin for different Windows versions 275 vol3 -f memory.bin windows.netstat > netstat.txt 276 ``` 277 278 **Example Output:** 279 ```plaintext 280 Offset Proto LocalAddr LocalPort ForeignAddr ForeignPort State PID Owner Created 281 282 0x9b2a4580 TCPv4 192.168.1.135 49823 185.220.101.5 443 ESTABLISHED 2856 powershell.exe 2024-01-15 14:15:35.000000 283 0x9c1e3040 TCPv4 192.168.1.135 49824 10.10.10.100 445 ESTABLISHED 4 System 2024-01-15 14:18:12.000000 284 0x9d4f1280 UDPv4 0.0.0.0 53 * 0 1024 svchost.exe 2024-01-15 08:05:00.000000 285 ``` 286 287 **Investigation Actions:** 288 1. **185.220.101.5:443 from powershell.exe**: Suspicious HTTPS connectionβpotential C2 communication 289 2. **10.10.10.100:445 from System**: SMB connection indicating lateral movement or file sharing 290 3. Correlate foreign IPs with threat intelligence ([VirusTotal](https://www.virustotal.com/), [AbuseIPDB](https://www.abuseipdb.com/)) 291 4. Check **Event ID 3** ([Sysmon](https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon) Network Connection) for additional context 292 293 --- 294 295 ### MemProcFS 296 297 **Purpose:** Revolutionary memory forensics tool mounting physical memory as a virtual file system, enabling intuitive navigation of memory artifacts using standard file browsers and command-line tools. 298 299 **Source:** [MemProcFS GitHub](https://github.com/ufrisk/MemProcFS) 300 301 **Platforms:** Windows (primary), Linux (partial support) 302 303 **Prerequisites:** 304 - Dokany File System Library (Windows): [Dokany Releases](https://github.com/dokan-dev/dokany/releases) 305 306 **Installation:** 307 ```bash 308 # Windows - Download pre-compiled binaries 309 # https://github.com/ufrisk/MemProcFS/releases 310 311 # Install Dokany first (required for mounting) 312 # Download DokanSetup.exe from Dokany releases 313 314 # Extract MemProcFS and run from directory 315 ``` 316 317 **Usage:** 318 ```cmd 319 :: Basic mount (default M: drive) 320 memprocfs.exe -device <memory.bin> 321 322 :: Mount with forensic mode (enables timeline, MFT extraction, NTFS analysis) 323 memprocfs.exe -device <memory.bin> -forensic 1 324 325 :: Mount with Elastic YARA rules 326 memprocfs.exe -device <memory.bin> -forensic 1 -license-accept-elastic-license-2.0 327 328 :: Custom YARA rules 329 memprocfs.exe -device <memory.bin> -forensic 1 -forensic-yara-rules <rules.yar> 330 331 :: With pagefile support 332 memprocfs.exe -device <memory.bin> -pagefile0 pagefile.sys -pagefile1 swapfile.sys 333 334 :: Live memory analysis (with WinPMEM driver) 335 memprocfs.exe -device pmem 336 ``` 337 338 --- 339 340 > **Note β** - Virtual File System Structure 341 > 342 > **Key Directories After Mounting:** 343 > 344 > | Directory Path | Contents | Forensic Value | 345 > |:--|:--|:--| 346 > | `M:\forensic\csv\` | CSV exports (pslist, findevil, ntfs) | Import to Timeline Explorer | 347 > | `M:\forensic\findevil\` | Automated malware detection results | Quick IOC identification | 348 > | `M:\forensic\timeline\` | Process and activity timelines | Temporal analysis | 349 > | `M:\forensic\yara\` | YARA scan results | Signature-based detection | 350 > | `M:\forensic\ntfs\` | Reconstructed NTFS from memory | File system artifacts | 351 > | `M:\name\<process.exe-PID>\` | Process-specific artifacts | Per-process deep dive | 352 > | `M:\name\<process>\vmemd\` | Virtual memory dumps | Extract injected code | 353 > | `M:\registry\hive_files\` | Extracted registry hives | Offline registry analysis | 354 > | `M:\registry\HKLM\` | HKEY_LOCAL_MACHINE keys | System-wide settings | 355 > | `M:\registry\HKCU\` | HKEY_CURRENT_USER keys | User-specific settings | 356 > | `M:\sys\net\netstat.txt` | Network connections | C2 detection | 357 > | `M:\sys\proc\pslist.txt` | Process list | Quick process review | 358 > | `M:\pid\<PID>\` | Process by PID | Direct PID access | 359 360 **Workflow Example:** 361 1. Review `M:\forensic\findevil\findevil.txt` for automated IOC hits 362 2. Open `M:\forensic\csv\findevil.csv` in Timeline Explorer 363 3. Navigate to flagged process: `M:\name\powershell.exe-2856\` 364 4. Review `cmdline.txt` for command-line arguments 365 5. Check `M:\sys\net\netstat.txt` for network connections from PID 2856 366 6. Copy registry hives from `M:\registry\hive_files\` to working directory 367 7. Analyze with `RECmd.exe -f M:\registry\hive_files\SOFTWARE --bn batch.reb` 368 369 --- 370 371 ### CAPA 372 373 **Purpose:** Automated malware capability identification tool by Mandiant/FLARE team. Identifies program capabilities by analyzing code against a rule set of known malicious behaviors, mapping findings to [MITRE ATT&CK](https://attack.mitre.org/). 374 375 **Source:** [CAPA GitHub](https://github.com/mandiant/capa) 376 377 **Platforms:** Windows, Linux, macOS 378 379 **Installation:** 380 ```bash 381 # Python installation 382 pip install flare-capa 383 384 # Download standalone executable 385 # https://github.com/mandiant/capa/releases 386 ``` 387 388 **Usage:** 389 ```bash 390 # Basic analysis of executable 391 capa <malware.exe> 392 393 # Verbose output showing matched rules 394 capa -v <malware.exe> 395 396 # Very verbose (shows matched code locations) 397 capa -vv <malware.exe> 398 399 # Output as JSON for parsing 400 capa -j <malware.exe> > capa_results.json 401 402 # Analyse shellcode 403 capa -f sc32 <shellcode.bin> # 32-bit shellcode 404 capa -f sc64 <shellcode.bin> # 64-bit shellcode 405 406 # Analyse memory dump regions extracted from malfind 407 capa <malfind_dump.dmp> 408 409 # Specify rules directory 410 capa -r <rules_directory> <sample.exe> 411 ``` 412 413 **Example Output:** 414 ``` 415 +------------------------+----------------------------+ 416 | ATT&CK Tactic | ATT&CK Technique | 417 |------------------------+----------------------------| 418 | DEFENSE EVASION | Obfuscated Files or Info | 419 | EXECUTION | Command and Scripting | 420 | PERSISTENCE | Registry Run Keys | 421 | PRIVILEGE ESCALATION | Process Injection | 422 | COLLECTION | Screen Capture | 423 | COMMAND AND CONTROL | Encrypted Channel | 424 +------------------------+----------------------------+ 425 426 +-----------------------------+------------------------------+ 427 | Capability | Namespace | 428 |-----------------------------+------------------------------| 429 | encode data using XOR | data-manipulation/encoding | 430 | receive data on TCP socket | communication/tcp/receive | 431 | create process | host-interaction/process | 432 | inject code into remote | host-interaction/process/ | 433 | process | inject | 434 | create registry key | host-interaction/registry | 435 | capture screenshot | collection/screenshot | 436 | contain PE file | executable/pe | 437 +-----------------------------+------------------------------+ 438 ``` 439 440 **Cobalt Strike Indicators:** 441 1. Network socket creation (TCP/UDP) 442 2. Process injection capabilities 443 3. Named pipe creation (`\\.\pipe\msagent_*`) 444 4. XOR encoding 445 5. Sleep/jitter implementation 446 447 --- 448 449 ### YARA 450 451 **Purpose:** Pattern matching tool for identifying and classifying malware based on textual or binary patterns. De facto standard for malware signature creation used by VirusTotal, AV vendors, and DFIR teams. 452 453 **Source:** [YARA GitHub](https://github.com/VirusTotal/yara) 454 455 **Platforms:** Windows, Linux, macOS 456 457 **Installation:** 458 ```bash 459 # Linux 460 sudo apt install yara 461 462 # macOS 463 brew install yara 464 465 # Windows - Download from releases 466 # https://github.com/VirusTotal/yara/releases 467 468 # Python bindings 469 pip install yara-python 470 ``` 471 472 **Usage:** 473 ```bash 474 # Scan file with single rule 475 yara <rules.yar> <target_file> 476 477 # Scan directory recursively 478 yara -r <rules.yar> <target_directory> 479 480 # Scan with multiple rule files 481 yara <rules1.yar> <rules2.yar> <target> 482 483 # Print matching strings 484 yara -s <rules.yar> <target> 485 486 # Print metadata 487 yara -m <rules.yar> <target> 488 489 # Scan process memory (Linux) 490 yara <rules.yar> -p <PID> 491 492 # Fast mode (skip expensive scans) 493 yara -f <rules.yar> <target> 494 ``` 495 496 --- 497 498 > **Note β** - Sample YARA Rule: Cobalt Strike Beacon Detection 499 > 500 > ```yara 501 > rule CobaltStrike_Beacon_x64 502 > { 503 > meta: 504 > description = "Detects Cobalt Strike Beacon x64" 505 > author = "SANS DFIR Team" 506 > reference = "https://www.cobaltstrike.com" 507 > severity = "high" 508 > mitre_attack = "T1055, T1071" 509 > 510 > strings: 511 > // x64 shellcode prologue 512 > $magic_x64 = { FC 48 83 E4 F0 E8 } 513 > 514 > // Beacon configuration markers 515 > $config_marker = { 00 01 00 01 00 02 } 516 > 517 > // Configuration strings 518 > $sleeptime = "sleeptime" ascii 519 > $jitter = "jitter" ascii 520 > $watermark = "watermark" ascii 521 > $spawnto_x86 = "spawnto_x86" ascii 522 > $spawnto_x64 = "spawnto_x64" ascii 523 > 524 > // Named pipe pattern 525 > $pipe = "\\\\.\\pipe\\" ascii 526 > $msagent_pipe = "msagent_" ascii 527 > 528 > // HTTP headers 529 > $http_header = "User-Agent:" ascii 530 > $http_header2 = "Accept:" ascii 531 > 532 > // Beacon DLL names 533 > $beacon_dll = "beacon.dll" ascii nocase 534 > $beacon_x64 = "beacon.x64.dll" ascii nocase 535 > 536 > condition: 537 > uint16(0) == 0x5A4D and // MZ header 538 > ( 539 > $magic_x64 or 540 > (2 of ($config_marker, $sleeptime, $jitter, $watermark)) or 541 > (all of ($pipe, $msagent_pipe)) or 542 > any of ($beacon_dll, $beacon_x64) 543 > ) 544 > } 545 > 546 > rule Reflective_DLL_Injection 547 > { 548 > meta: 549 > description = "Detects reflective DLL injection" 550 > author = "SANS DFIR" 551 > mitre_attack = "T1055.001" 552 > 553 > strings: 554 > $mz = { 4D 5A } 555 > 556 > // Reflective loader signatures 557 > $reflective_loader1 = { 48 8B C4 48 89 58 08 48 89 68 10 48 89 70 18 } 558 > $reflective_loader2 = { 64 48 8B 04 25 60 00 00 00 } // GS segment access 559 > 560 > // API resolution patterns 561 > $getprocaddress = "GetProcAddress" ascii 562 > $loadlibrary = "LoadLibraryA" ascii 563 > $virtualalloc = "VirtualAlloc" ascii 564 > 565 > condition: 566 > $mz at 0 and 567 > ( 568 > any of ($reflective_loader*) or 569 > (all of ($getprocaddress, $loadlibrary, $virtualalloc)) 570 > ) 571 > } 572 > ``` 573 574 **YARA Rule Best Practices:** 575 1. Always include metadata with ATT&CK mappings and severity 576 2. Test rules against benign software to minimize false positives 577 3. Use multiple string conditions for robustness 578 4. Include both specific and generic indicators 579 5. Document rule rationale in comments 580 581 **Integration with Volatility 3:** 582 ```bash 583 # Scan all memory with YARA rules 584 vol3 -f memory.bin windows.vadyarascan --yara-file cobalt_strike.yar 585 586 # Scan specific process by PID 587 vol3 -f memory.bin windows.vadyarascan --yara-file rules.yar --pid 2856 588 589 # Multiple rule files 590 vol3 -f memory.bin yarascan.YaraScan --yara-file combined_rules.yar 591 592 # Output to file for analysis 593 vol3 -f memory.bin windows.vadyarascan --yara-file rules.yar > yara_hits.txt 594 ``` 595 596 --- 597 598 ## Prefetch Analysis Tools 599 600 ### PECmd (Prefetch Explorer Command Line) π΅ SANS Tool 601 602 **Purpose:** Parse Windows Prefetch files to extract program execution evidence, including run counts, timestamps, and accessed files/directories. 603 604 **Source:** [SANS PECmd](https://www.sans.org/tools/pecmd) | [Eric Zimmerman Tools](https://ericzimmerman.github.io) 605 606 **Author:** Eric Zimmerman (SANS Principal Instructor) 607 608 **Platforms:** Windows (native), Linux (via Wine/.NET) 609 610 **Installation:** 611 ```powershell 612 # Windows - Download from Eric Zimmerman's GitHub 613 # https://ericzimmerman.github.io/#!index.md 614 615 # Use Get-ZimmermanTools PowerShell script for automated download 616 [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 617 Invoke-WebRequest -Uri "https://f001.backblazeb2.com/file/EricZimmermanTools/Get-ZimmermanTools.zip" -OutFile Get-ZimmermanTools.zip 618 Expand-Archive Get-ZimmermanTools.zip 619 .\Get-ZimmermanTools.ps1 -Dest "C:\Tools\Zimmerman" 620 621 # Linux (requires .NET 6 runtime) 622 wget https://dot.net/v1/dotnet-install.sh 623 chmod +x dotnet-install.sh 624 ./dotnet-install.sh --runtime dotnet --version 6.0.0 625 ``` 626 627 **Usage:** 628 ```cmd 629 :: Parse single prefetch file 630 PECmd.exe -f <file.pf> 631 632 :: Parse directory of prefetch files with CSV output 633 PECmd.exe -d <prefetch_directory> --csv <output_dir> --csvf Prefetch_Results.csv 634 635 :: UK date formatting (dd/MM/yyyy HH:mm:ss) 636 PECmd.exe -d <prefetch_directory> --csv <output_dir> --csvf Prefetch.csv --dt "dd/MM/yyyy HH:mm:ss" 637 638 :: JSON output 639 PECmd.exe -d <prefetch_directory> --json <output_dir> 640 641 :: Quiet mode (faster processing) 642 PECmd.exe -d <prefetch_directory> --csv <output_dir> -q 643 644 :: Custom keyword highlighting (temp directories) 645 PECmd.exe -d <prefetch_directory> -k "temp,appdata,downloads" 646 ``` 647 648 **Expected Output:** 649 - `*_Prefetch.csv` - Main results with executable name, run count, last 8 run times 650 - `*_Prefetch_Timeline.csv` - Execution timeline for temporal analysis 651 652 **Key CSV Fields:** 653 654 | | | | 655 | -------------- | ------------------------------------- | ----------------------------- | 656 | Field | Description | Forensic Value | 657 | ExecutableName | Name of executed program | Identify reconnaissance tools | 658 | RunCount | Number of times program executed | Frequency analysis | 659 | LastRun | Most recent execution timestamp | Timeline correlation | 660 | PreviousRun0-7 | Previous 7 execution timestamps | Execution history | 661 | SourceFilename | Full path to executable | Location analysis | 662 | FilesLoaded | Files accessed during execution | Payload identification | 663 | Directories | Directories accessed during execution | Drop location discovery | 664 665 **Forensic Significance:** 666 1. Windows 10 stores last 8 execution times 667 2. Files/directories referenced reveal payload locations 668 3. Single-character executable names often indicate malware 669 4. Prefetch files survive across reboots 670 671 --- 672 673 ## Registry Analysis Tools 674 675 ### RECmd (Registry Explorer Command Line) π΅ SANS Tool 676 677 **Purpose:** Command-line registry parser with batch processing capabilities for extracting forensically significant data from Windows registry hive files. 678 679 **Source:** [SANS RECmd](https://www.sans.org/tools/recmd) | [Eric Zimmerman Tools](https://ericzimmerman.github.io) 680 681 **Author:** Eric Zimmerman 682 683 **Platforms:** Windows (native), Linux (via .NET) 684 685 **Usage:** 686 ```cmd 687 :: Parse with batch file (recommended for comprehensive analysis) 688 RECmd.exe -f <registry_hive> --bn <batch_file.reb> --csv <output_dir> --csvf Results.csv 689 690 :: Common batch files: 691 :: - RECmd_Batch_MC.reb (Most Common artifacts) 692 :: - RegistryASEPs.reb (Auto-Start Extensibility Points) 693 694 :: Parse specific registry key 695 RECmd.exe -f SOFTWARE --kn "Microsoft\Windows\CurrentVersion\Run" --csv <output_dir> 696 697 :: Recover deleted entries 698 RECmd.exe -f <hive> --recover --csv <output_dir> 699 700 :: UK date format 701 RECmd.exe -f <hive> --bn <batch.reb> --csv <output_dir> --dt "dd/MM/yyyy HH:mm:ss" 702 703 :: Parse directory of hives 704 RECmd.exe -d <hive_directory> --bn <batch.reb> --csv <output_dir> 705 ``` 706 707 --- 708 709 > **Note β** - Critical Registry Locations for DFIR 710 > 711 > **Persistence Mechanisms (HKLM\SOFTWARE & NTUSER.DAT):** 712 > 713 > | Registry Key | Hive | Purpose | Malware Usage | 714 > |:--|:--|:--|:--| 715 > | `Microsoft\Windows\CurrentVersion\Run` | SOFTWARE, NTUSER | Auto-start executables | **Primary persistence location** | 716 > | `Microsoft\Windows\CurrentVersion\RunOnce` | SOFTWARE, NTUSER | Run once then delete entry | Single-execution payloads | 717 > | `Microsoft\Windows\CurrentVersion\RunServices` | SOFTWARE | Run as service | Service-based persistence | 718 > | `Microsoft\Windows\CurrentVersion\Policies\Explorer\Run` | SOFTWARE, NTUSER | Policy-based execution | Policy enforcement bypass | 719 > | `Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit` | SOFTWARE | Userinit override | Replace userinit.exe | 720 > | `Microsoft\Windows NT\CurrentVersion\Winlogon\Shell` | SOFTWARE | Shell override | Replace explorer.exe | 721 > | `Microsoft\Windows NT\CurrentVersion\Image File Execution Options` | SOFTWARE | Debugger attachment | IFEO persistence | 722 > 723 > **Services (HKLM\SYSTEM):** 724 > 725 > | Registry Key | Purpose | 726 > |:--|:--| 727 > | `ControlSet001\Services` | Installed services | 728 > | `ControlSet001\Services\<ServiceName>\ImagePath` | Service executable path | 729 > | `ControlSet001\Services\<ServiceName>\Start` | Start type (2=Auto, 3=Manual, 4=Disabled) | 730 > 731 > **System Information (HKLM\SYSTEM):** 732 > 733 > | Registry Key | Information | 734 > |:--|:--| 735 > | `ControlSet001\Control\ComputerName\ComputerName` | Computer name | 736 > | `ControlSet001\Control\TimeZoneInformation` | Timezone | 737 > | `ControlSet001\Services\Tcpip\Parameters\Interfaces` | Network interfaces | 738 739 --- 740 741 ### Registry Explorer π΅ SANS Tool 742 743 **Purpose:** GUI-based registry hive viewer and editor with advanced parsing capabilities, plugin support, and deleted entry recovery. 744 745 **Source:** [Eric Zimmerman Tools](https://ericzimmerman.github.io) 746 747 **Author:** Eric Zimmerman 748 749 **Platforms:** Windows 750 751 **Usage:** 752 1. Launch Registry Explorer 753 2. File β Load Hive β Select registry hive file 754 3. Navigate to keys of interest 755 4. Use Bookmarks for common forensic locations 756 5. Export findings via File β Export 757 758 **Key Features:** 759 1. Handles dirty/corrupt hives from memory extraction 760 2. Shows deleted keys and values 761 3. Timestamps on all keys 762 4. Plugin support for specialized parsing 763 5. Bookmark system for common forensic keys 764 765 --- 766 767 ### AppCompatCacheParser π΅ SANS Tool 768 769 **Purpose:** Parse Application Compatibility Cache (ShimCache) from SYSTEM registry hive to extract program execution evidence. 770 771 **Source:** [SANS AppCompatCacheParser](https://www.sans.org/tools/appcompatcacheparser) | [Eric Zimmerman Tools](https://ericzimmerman.github.io) 772 773 **Author:** Eric Zimmerman 774 775 **Usage:** 776 ```cmd 777 :: Parse SYSTEM hive 778 AppCompatCacheParser.exe -f <SYSTEM_hive> --csv <output_dir> --csvf ShimCache.csv 779 780 :: UK date format 781 AppCompatCacheParser.exe -f <SYSTEM_hive> --csv <output_dir> --dt "dd/MM/yyyy HH:mm:ss" 782 ``` 783 784 **Forensic Significance:** 785 1. Contains executable path and last modification timestamp 786 2. Entry order reflects approximate execution order 787 3. Survives reboots (unlike prefetch which can be disabled) 788 4. Windows 7+ includes executed flag 789 790 **CSV Output Fields:** 791 792 | | | | 793 | ---------------------- | ----------------------------------- | ------------------------------------------- | 794 | Field | Description | Forensic Value | 795 | **CacheEntryPosition** | Position in cache (1 = most recent) | Relative execution order | 796 | **Path** | Full executable path | Identify execution location | 797 | **LastModified** | File last modification timestamp | File modification time (NOT execution time) | 798 | **Executed** | Executed flag (Windows 7+) | Confirms execution vs touched by Explorer | 799 | **ControlSet** | ControlSet number (001, 002) | Validate active ControlSet | 800 801 802 --- 803 804 ### AmcacheParser π΅ SANS Tool 805 806 **Purpose:** Parse Amcache.hve to extract program execution metadata including SHA1 hashes, file paths, and execution timestamps. 807 808 **Source:** [SANS AmcacheParser](https://www.sans.org/tools/amcacheparser) | [Eric Zimmerman Tools](https://ericzimmerman.github.io) 809 810 **Author:** Eric Zimmerman 811 812 **Usage:** 813 ```cmd 814 :: Parse Amcache.hve 815 AmcacheParser.exe -f <Amcache.hve> --csv <output_dir> --csvf Amcache.csv 816 817 :: Include unassociated file entries 818 AmcacheParser.exe -f <Amcache.hve> --csv <output_dir> -i 819 820 :: UK date format 821 AmcacheParser.exe -f <Amcache.hve> --csv <output_dir> --dt "dd/MM/yyyy HH:mm:ss" 822 ``` 823 824 **Key Output Fields:** 825 1. SHA1 hash (for VirusTotal lookup) 826 2. File path 827 3. First execution timestamp 828 4. File size 829 5. Publisher information 830 831 **VirusTotal Batch Lookup:** 832 ```powershell 833 # Extract SHA1 hashes from CSV 834 Import-Csv Amcache.csv | Select-Object -Unique SHA1 | Export-Csv -Path hashes_only.csv 835 836 # Lookup on VirusTotal (requires API key) 837 # Use vt-cli or web interface batch upload 838 ``` 839 840 --- 841 842 ## Event Log Analysis Tools 843 844 ### EvtxECmd π΅ SANS Tool 845 846 **Purpose:** Parse Windows Event Log files (.evtx) to CSV/JSON with extensive event mapping and filtering capabilities. 847 848 **Source:** [SANS EvtxECmd](https://www.sans.org/tools/evtxecmd) | [Eric Zimmerman Tools](https://ericzimmerman.github.io) 849 850 **Author:** Eric Zimmerman 851 852 **Usage:** 853 ```cmd 854 :: Parse single event log 855 EvtxECmd.exe -f <Security.evtx> --csv <output_dir> --csvf Security.csv 856 857 :: Parse with UK date format 858 EvtxECmd.exe -f <Security.evtx> --csv <output_dir> --csvf Security.csv --dt "dd/MM/yyyy HH:mm:ss" 859 860 :: Parse directory of logs 861 EvtxECmd.exe -d <EventLogs_directory> --csv <output_dir> 862 863 :: JSON output 864 EvtxECmd.exe -f <Security.evtx> --json <output_dir> 865 866 :: Include maps for enriched parsing 867 EvtxECmd.exe -f <Security.evtx> --csv <output_dir> --maps <maps_directory> 868 ``` 869 870 --- 871 872 > **Note β** - Critical Windows Event IDs Reference 873 > 874 > **Security Log Events:** 875 > 876 > | Event ID | Category | Description | Forensic Value | 877 > |:--|:--|:--|:--| 878 > | **4624** | Authentication | Successful logon | Identify user sessions, Type 3=Network, Type 10=RDP | 879 > | **4625** | Authentication | Failed logon | Brute force attempts, credential spraying | 880 > | **4672** | Privilege | Special privileges assigned | Administrator logon, SYSTEM access | 881 > | **4688** | Execution | Process creation | Command lines (if auditing enabled) | 882 > | **4648** | Authentication | Explicit credentials used | Lateral movement with `runas` or Pass-the-Hash | 883 > | **4768** | Kerberos | TGT requested | Initial authentication to domain controller | 884 > | **4769** | Kerberos | Service ticket requested | Kerberoasting detection | 885 > | **4776** | Authentication | NTLM authentication | Identify NTLM usage for lateral movement | 886 > | **1102** | Audit | Security log cleared | Anti-forensics, tampering | 887 > | **4720** | Account Management | User account created | Persistence, privilege escalation | 888 > | **4732** | Group Management | User added to local group | Privilege escalation (Administrators group) | 889 > 890 > **System Log Events:** 891 > 892 > | Event ID | Category | Description | Forensic Value | 893 > |:--|:--|:--|:--| 894 > | **7045** | Service | New service installed | Malware persistence, lateral movement tools | 895 > | **7040** | Service | Service start type changed | Persistence mechanism modification | 896 > | **104** | Audit | System log cleared | Anti-forensics | 897 > | **1** | Kernel | System boot | Establish system uptime, reboot timeline | 898 > | **6005** | Event Log | Event Log service started | System boot confirmation | 899 > | **6006** | Event Log | Event Log service stopped | System shutdown | 900 > 901 > **PowerShell Operational Log:** 902 > 903 > | Event ID | Category | Description | Forensic Value | 904 > |:--|:--|:--|:--| 905 > | **4103** | Pipeline | Module logging | Commands executed via PowerShell | 906 > | **4104** | Script Block | Script block logging | Full PowerShell script content | 907 > | **4105** | Script Start | Script execution started | Script start timestamp | 908 > | **4106** | Script Stop | Script execution stopped | Script end timestamp | 909 910 **Logon Type Reference (Event ID 4624):** 911 912 | Type | Name | Description | Attack Relevance | 913 |:--|:--|:--|:--| 914 | **2** | Interactive | Local console logon | Physical or console access | 915 | **3** | Network | Network logon (SMB, file shares) | **Lateral movement primary indicator** | 916 | **4** | Batch | Scheduled task | Persistence via scheduled tasks | 917 | **5** | Service | Service logon | Malicious service installation | 918 | **7** | Unlock | Workstation unlock | User activity tracking | 919 | **10** | RemoteInteractive | RDP/Terminal Services | **Remote access, lateral movement** | 920 | **11** | CachedInteractive | Logon with cached credentials | Offline authentication | 921 922 --- 923 924 ### Hayabusa 925 926 **Purpose:** SIGMA-based threat hunting and fast forensics timeline generator for Windows event logs. 927 928 **Source:** [Hayabusa GitHub](https://github.com/Yamato-Security/hayabusa) 929 930 **Platforms:** Windows, Linux, macOS 931 932 **Installation:** 933 ```bash 934 # Download pre-compiled binary 935 # https://github.com/Yamato-Security/hayabusa/releases 936 937 # Or compile from source 938 git clone https://github.com/Yamato-Security/hayabusa.git 939 cd hayabusa 940 cargo build --release 941 ``` 942 943 **Usage:** 944 ```bash 945 # Run against event logs directory 946 hayabusa csv-timeline -d <evtx_directory> -o timeline.csv 947 948 # With SIGMA rules 949 hayabusa csv-timeline -d <evtx_directory> -o timeline.csv --enable-all-rules 950 951 # JSON output 952 hayabusa json-timeline -d <evtx_directory> -o timeline.json 953 954 # Metrics summary 955 hayabusa metrics -d <evtx_directory> 956 ``` 957 958 **Example Output:** 959 ```plaintext 960 Hayabusa v2.7.0 - Fast Windows Event Log Forensics Timeline Generator 961 962 Loading detection rules... 963 Loaded 3,245 SIGMA rules 964 965 Processing event logs in D:\Evidence\EventLogs\LAPTOP-135 966 967 Found event logs: 968 Security.evtx (15,234 events) 969 System.evtx (8,456 events) 970 Microsoft-Windows-PowerShell%4Operational.evtx (1,234 events) 971 Microsoft-Windows-Sysmon%4Operational.evtx (3,456 events) 972 973 Processing events... ββββββββββββββββββββ 100% 974 975 Detection Summary: 976 Total events processed: 28,380 977 Detections: 127 978 Critical: 5 979 High: 23 980 Medium: 67 981 Low: 32 982 983 Timeline saved to: D:\Output\hayabusa_timeline.csv 984 985 Top 5 Detections: 986 1. PowerShell Base64 Encoded Command (12 hits) 987 2. Suspicious Process Creation Chain (8 hits) 988 3. Network Connection to Suspicious IP (5 hits) 989 4. Credential Dumping via LSASS Access (3 hits) 990 5. Lateral Movement via PSExec (2 hits) 991 ``` 992 993 **Key Detections for Cobalt Strike:** 994 1. **PowerShell Base64 Encoded Command**: Encoded payload execution 995 2. **Process Creation with Suspicious Command Line**: Reconnaissance tools 996 3. **Network Connection from Script Host**: C2 beaconing from PowerShell 997 4. **Suspicious Named Pipe Creation**: Beacon named pipes (`\\.\pipe\msagent_*`) 998 5. **LSASS Memory Access**: Credential dumping 999 6. **PSExec Service Installation**: Lateral movement 1000 1001 --- 1002 1003 ### Chainsaw 1004 1005 **Purpose:** Rapidly search and hunt through Windows event logs using SIGMA detection rules and custom Chainsaw queries. 1006 1007 **Source:** [Chainsaw GitHub](https://github.com/WithSecureLabs/chainsaw) 1008 1009 **Platforms:** Windows, Linux, macOS 1010 1011 **Installation:** 1012 ```bash 1013 # Download from releases 1014 # https://github.com/WithSecureLabs/chainsaw/releases 1015 1016 # Or cargo install 1017 cargo install chainsaw 1018 ``` 1019 1020 **Usage:** 1021 ```bash 1022 # Hunt with SIGMA rules 1023 chainsaw hunt <evtx_directory> -s <sigma_rules> --mapping <mapping.yml> 1024 1025 # Search for specific strings 1026 chainsaw search <evtx_directory> -s "powershell" -s "mimikatz" 1027 1028 # Dump all events to JSON 1029 chainsaw dump <evtx_directory> -o output.json 1030 ``` 1031 1032 --- 1033 1034 ## Cross-Platform Supporting Tools 1035 1036 ### SIFT Workstation π΅ SANS Tool 1037 1038 **Purpose:** Complete Ubuntu-based forensic distribution with pre-installed tools for incident response and digital forensics. 1039 1040 **Source:** [SANS SIFT Workstation](https://www.sans.org/tools/sift-workstation) 1041 1042 **Author:** Rob T. Lee (SANS Chief AI Officer) 1043 1044 **Platforms:** Ubuntu Linux (VM recommended) 1045 1046 **Installation:** 1047 ```bash 1048 # Method 1: Download OVA/VMware image from SANS 1049 # https://www.sans.org/tools/sift-workstation 1050 1051 # Method 2: Install on existing Ubuntu 1052 wget https://github.com/teamdfir/sift-cli/releases/download/v1.14.0/sift-cli-linux 1053 chmod +x sift-cli-linux 1054 sudo ./sift-cli-linux install 1055 1056 # Default credentials 1057 # Username: sansforensics 1058 # Password: forensics 1059 ``` 1060 1061 **Included Tools:** 1062 1. Volatility Framework 1063 2. The Sleuth Kit & Autopsy 1064 3. Eric Zimmerman's Tools 1065 4. Plaso/Log2Timeline 1066 5. RegRipper 1067 6. Bulk Extractor 1068 7. And 100+ additional forensic utilities 1069 1070 --- 1071 1072 ### KAPE (Kroll Artifact Parser and Extractor) π΅ SANS Tool 1073 1074 **Purpose:** Triage tool for rapid collection and processing of forensic artifacts. Combines targeted collection (Targets) with automated processing (Modules). 1075 1076 **Source:** [SANS KAPE](https://www.sans.org/tools/kape) | [Kroll KAPE](https://www.kroll.com/en/services/cyber-risk/incident-response-litigation-support/kroll-artifact-parser-extractor-kape) 1077 1078 **Author:** Eric Zimmerman 1079 1080 **Platforms:** Windows 1081 1082 **Installation:** 1083 ```powershell 1084 # Download from Kroll website (requires registration) 1085 # https://www.kroll.com/en/services/cyber-risk/kape 1086 1087 # Sync with GitHub for latest targets/modules 1088 kape.exe --sync 1089 ``` 1090 1091 **Usage:** 1092 ```cmd 1093 :: Collect common triage artifacts 1094 kape.exe --tsource C: --tdest D:\Evidence --target KapeTriage 1095 1096 :: Process collected artifacts 1097 kape.exe --msource D:\Evidence --mdest D:\Processed --module !EZParser 1098 1099 :: Collect and process in one command 1100 kape.exe --tsource C: --tdest D:\Evidence --target KapeTriage --mdest D:\Processed --module !EZParser 1101 1102 :: Specific target collection 1103 kape.exe --tsource C: --tdest D:\Evidence --target Prefetch,EventLogs,Registry 1104 ``` 1105 1106 **Common Targets:** 1107 1. `KapeTriage` - Comprehensive triage collection 1108 2. `Prefetch` - Prefetch files 1109 3. `EventLogs` - Windows Event Logs 1110 4. `Registry` - Registry hives 1111 5. `AmcacheAndShimcache` - Execution evidence 1112 1113 --- 1114 1115 ### Timeline Explorer π΅ SANS Tool 1116 1117 **Purpose:** Advanced CSV and Excel viewer designed for forensic timeline analysis with filtering, grouping, and visualization capabilities. 1118 1119 **Source:** [Eric Zimmerman Tools](https://ericzimmerman.github.io) 1120 1121 **Author:** Eric Zimmerman 1122 1123 **Platforms:** Windows 1124 1125 **Usage:** 1126 1. Launch Timeline Explorer 1127 2. Open CSV file (supports drag-and-drop) 1128 3. Use column filters to narrow results 1129 4. Group by columns for pattern identification 1130 5. Tag interesting rows with Ctrl+T 1131 6. Export filtered results 1132 1133 **Key Features:** 1134 1. Handles very large CSV files 1135 2. Column-based filtering 1136 3. Row grouping and expansion 1137 4. Conditional formatting 1138 5. Persistent column configurations 1139 6. Native date/time parsing 1140 1141 --- 1142 1143 ### Plaso/Log2Timeline π΅ SANS Tool 1144 1145 **Purpose:** Super timeline creation tool that extracts timestamps from various artifact sources and aggregates them into a unified timeline. 1146 1147 **Source:** [Plaso GitHub](https://github.com/log2timeline/plaso) 1148 1149 **Platforms:** Linux, Windows, macOS 1150 1151 **Installation:** 1152 ```bash 1153 # Linux (Ubuntu/Debian) 1154 sudo add-apt-repository ppa:gift/stable 1155 sudo apt update 1156 sudo apt install plaso-tools 1157 1158 # Docker 1159 docker pull log2timeline/plaso 1160 1161 # pip 1162 pip install plaso 1163 ``` 1164 1165 **Usage:** 1166 ```bash 1167 # Create timeline from disk image 1168 log2timeline.py --parsers win7 timeline.plaso <evidence_image> 1169 1170 # Process to CSV 1171 psort.py -o l2tcsv timeline.plaso -w supertimeline.csv 1172 1173 # Filter by date range 1174 psort.py timeline.plaso "date > '2024-01-01' AND date < '2024-01-31'" -w filtered.csv 1175 ``` 1176 1177 --- 1178 1179 ### CertUtil (Windows Built-in) 1180 1181 **Purpose:** Windows certificate utility that includes hash calculation capabilities for evidence integrity verification. 1182 1183 **Platforms:** Windows (built-in) 1184 1185 **Usage:** 1186 ```cmd 1187 :: Generate SHA-256 hash 1188 certutil -hashfile <file> SHA256 1189 1190 :: Generate MD5 hash 1191 certutil -hashfile <file> MD5 1192 1193 :: Batch hash all files recursively 1194 forfiles /s /c "cmd /c certutil -hashfile @path SHA256 >> all_hashes.txt" 1195 ``` 1196 1197 --- 1198 1199 ## Investigation Workflows 1200 1201 ### Workflow 1: Memory Dump Analysis 1202 1203 ``` 1204 βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 1205 β MEMORY DUMP ANALYSIS β 1206 βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€ 1207 β β 1208 β 1. EVIDENCE INTEGRITY β 1209 β βββ certutil -hashfile memory.bin SHA256 β 1210 β βββ Document hash in chain of custody β 1211 β β 1212 β 2. INITIAL TRIAGE (Choose One) β 1213 β βββ MemProcFS: memprocfs.exe -device memory.bin -forensic 1β 1214 β β βββ Browse M:\forensic\findevil.txt for quick IOCs β 1215 β βββ Volatility: vol3 -f memory.bin windows.info β 1216 β β 1217 β 3. PROCESS ANALYSIS β 1218 β βββ vol3 -f memory.bin windows.pslist > pslist.txt β 1219 β βββ vol3 -f memory.bin windows.pstree > pstree.txt β 1220 β βββ vol3 -f memory.bin windows.cmdline > cmdline.txt β 1221 β β 1222 β 4. CODE INJECTION DETECTION β 1223 β βββ vol3 -f memory.bin windows.malfind > malfind.txt β 1224 β βββ vol3 -f memory.bin -o dumps windows.malfind --dump β 1225 β βββ Look for: RWX permissions, MZ headers, shellcode β 1226 β β 1227 β 5. NETWORK ANALYSIS β 1228 β βββ vol3 -f memory.bin windows.netscan > netscan.txt β 1229 β βββ Correlate connections with suspicious processes β 1230 β β 1231 β 6. MALWARE CAPABILITY ANALYSIS β 1232 β βββ capa <malfind_dump.bin> > capabilities.txt β 1233 β βββ yara cobalt_strike.yar <malfind_dump.bin> β 1234 β β 1235 β 7. DLL & HANDLE ANALYSIS β 1236 β βββ vol3 -f memory.bin windows.dlllist --pid <suspicious> β 1237 β βββ vol3 -f memory.bin windows.handles --pid <suspicious> β 1238 β β 1239 β 8. TIMELINE CORRELATION β 1240 β βββ Cross-reference findings with prefetch, evtx, network β 1241 β β 1242 βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 1243 ``` 1244 1245 **IOC Indicators to Look For:** 1246 1. PowerShell with `-enc` or `-encodedcommand` parameters 1247 2. Processes spawning from unusual parents (e.g., Excel β cmd.exe) 1248 3. RWX memory regions in legitimate processes (e.g., MsMpEng.exe) 1249 4. Connections to known bad IPs or unusual ports 1250 5. Single-character executable names 1251 6. Processes running from temp directories 1252 1253 --- 1254 1255 ### Workflow 2: Event Log Analysis 1256 1257 ``` 1258 βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 1259 β EVENT LOG ANALYSIS β 1260 βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€ 1261 β β 1262 β 1. PARSE LOGS TO CSV β 1263 β βββ EvtxECmd.exe -f Security.evtx --csv <output> β 1264 β βββ EvtxECmd.exe -f System.evtx --csv <output> β 1265 β βββ EvtxECmd.exe -f *PowerShell*.evtx --csv <output> β 1266 β β 1267 β 2. THREAT HUNTING β 1268 β βββ Hayabusa: hayabusa csv-timeline -d <logs> -o timeline β 1269 β βββ Chainsaw: chainsaw hunt <logs> -s <sigma_rules> β 1270 β β 1271 β 3. AUTHENTICATION ANALYSIS β 1272 β βββ Filter EventID 4624 (Successful logons) β 1273 β βββ Filter EventID 4625 (Failed logons) β 1274 β βββ Look for Type 3 logons (network) between hosts β 1275 β βββ Identify 4672 events (special privileges) β 1276 β β 1277 β 4. PROCESS CREATION (if auditing enabled) β 1278 β βββ Filter EventID 4688 for command lines β 1279 β β 1280 β 5. POWERSHELL ANALYSIS β 1281 β βββ Filter EventID 4104 (Script Block Logging) β 1282 β βββ Search for: -enc, FromBase64, DownloadString, IEX β 1283 β β 1284 β 6. SERVICE INSTALLATION β 1285 β βββ Filter EventID 7045 (New service installed) β 1286 β βββ Look for unusual service names/paths β 1287 β β 1288 β 7. LOG CLEARING DETECTION β 1289 β βββ Filter EventID 1102 (Security log cleared) β 1290 β βββ Filter EventID 104 (System log cleared) β 1291 β β 1292 β 8. VISUALISE IN TIMELINE EXPLORER β 1293 β βββ Open CSVs, group by EventID, filter by timeframe β 1294 β β 1295 βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 1296 ``` 1297 1298 --- 1299 1300 ### Workflow 3: Registry Analysis 1301 1302 ``` 1303 βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 1304 β REGISTRY ANALYSIS β 1305 βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€ 1306 β β 1307 β 1. PERSISTENCE MECHANISMS β 1308 β βββ RECmd.exe -f SOFTWARE --kn "...\\CurrentVersion\\Run" β 1309 β βββ RECmd.exe -f NTUSER.DAT --kn "...\\CurrentVersion\\Run" β 1310 β βββ Check RunOnce, RunServices, Userinit β 1311 β β 1312 β 2. SERVICE ANALYSIS β 1313 β βββ RECmd.exe -f SYSTEM --kn "ControlSet001\\Services" β 1314 β βββ Look for unusual ImagePath values β 1315 β β 1316 β 3. EXECUTION EVIDENCE β 1317 β βββ AppCompatCacheParser.exe -f SYSTEM --csv <output> β 1318 β βββ AmcacheParser.exe -f Amcache.hve --csv <output> β 1319 β βββ Cross-reference with Prefetch β 1320 β β 1321 β 4. DELETED ENTRY RECOVERY β 1322 β βββ RECmd.exe -f <hive> --recover --csv <output> β 1323 β β 1324 β 5. BATCH PROCESSING β 1325 β βββ RECmd.exe -f <hive> --bn RECmd_Batch_MC.reb --csv β 1326 β β 1327 βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 1328 ``` 1329 1330 --- 1331 1332 ### Workflow 4: Complete Investigation Timeline 1333 1334 ``` 1335 βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 1336 β MASTER TIMELINE CREATION β 1337 βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€ 1338 β β 1339 β 1. COLLECT TIMESTAMPS FROM ALL SOURCES β 1340 β βββ Prefetch: PECmd -d <dir> --csv <output> β 1341 β βββ Event Logs: EvtxECmd -d <dir> --csv <output> β 1342 β βββ Registry: AppCompatCacheParser, AmcacheParser β 1343 β βββ Memory: vol3 timeline, MemProcFS forensic β 1344 β βββ Network: tshark extraction β 1345 β β 1346 β 2. NORMALISE TIMESTAMPS β 1347 β βββ Ensure consistent timezone (UTC recommended) β 1348 β βββ Use consistent date format (--dt "dd/MM/yyyy HH:mm:ss")β 1349 β β 1350 β 3. MERGE INTO UNIFIED TIMELINE β 1351 β βββ Option A: PowerShell script to combine CSVs β 1352 β βββ Option B: Plaso for automatic super timeline β 1353 β β 1354 β 4. ANALYSE IN TIMELINE EXPLORER β 1355 β βββ Sort by timestamp β 1356 β βββ Filter by timeframe of interest β 1357 β βββ Group by source for pattern identification β 1358 β βββ Tag key events with Ctrl+T β 1359 β β 1360 β 5. VALIDATE AGAINST KNOWN FACTS β 1361 β βββ Confirm initial access timestamp β 1362 β βββ Verify lateral movement timing β 1363 β βββ Document discrepancies β 1364 β β 1365 βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 1366 ``` 1367 1368 --- 1369 1370 ## Advanced Integration Techniques 1371 1372 ### YARA Rules with Volatility 1373 1374 ```bash 1375 # Create comprehensive rule file 1376 cat << 'EOF' > cobalt_strike_memory.yar 1377 rule CobaltStrike_Beacon_x64 1378 { 1379 meta: 1380 description = "Cobalt Strike Beacon x64" 1381 author = "DFIR Team" 1382 strings: 1383 $a1 = { 4C 8B DC 49 89 5B 08 49 89 6B 10 49 89 73 18 } 1384 $a2 = { 48 89 5C 24 08 48 89 74 24 10 57 48 83 EC 20 } 1385 $s1 = "beacon.dll" ascii 1386 $s2 = "beacon.x64.dll" ascii 1387 condition: 1388 any of them 1389 } 1390 1391 rule Reflective_Loader 1392 { 1393 meta: 1394 description = "Reflective DLL Loader" 1395 strings: 1396 $mz = { 4D 5A } 1397 $reflective = { 48 8B C4 48 89 58 08 48 89 68 10 48 89 70 18 } 1398 condition: 1399 $mz at 0 and $reflective 1400 } 1401 EOF 1402 1403 # Run against memory dump 1404 vol3 -f memory.bin windows.vadyarascan --yara-file cobalt_strike_memory.yar 1405 ``` 1406 1407 --- 1408 1409 ### Automated Multi-Host Processing 1410 1411 ```powershell 1412 # Process multiple hosts with EZ Tools 1413 $hosts = @("LAPTOP-135", "WORKSTATION-969", "DESKTOP-841") 1414 $evidencePath = "D:\Evidence\ForensicsLab_S1\Working" 1415 $outputPath = "D:\Output" 1416 1417 foreach ($host in $hosts) { 1418 # Create output directory 1419 New-Item -ItemType Directory -Force -Path "$outputPath\$host\Memory" 1420 New-Item -ItemType Directory -Force -Path "$outputPath\$host\EventLogs" 1421 New-Item -ItemType Directory -Force -Path "$outputPath\$host\Prefetch" 1422 New-Item -ItemType Directory -Force -Path "$outputPath\$host\Registry" 1423 1424 # Process Prefetch 1425 PECmd.exe -d "$evidencePath\Prefetch\$host" --csv "$outputPath\$host\Prefetch" ` 1426 --csvf "Prefetch_$host.csv" --dt "dd/MM/yyyy HH:mm:ss" 1427 1428 # Process Event Logs 1429 EvtxECmd.exe -d "$evidencePath\EventLogs\$host" --csv "$outputPath\$host\EventLogs" ` 1430 --dt "dd/MM/yyyy HH:mm:ss" 1431 1432 # Process Registry 1433 RECmd.exe -f "$evidencePath\Registry\$host\SOFTWARE" ` 1434 --bn "RECmd_Batch_MC.reb" --csv "$outputPath\$host\Registry" ` 1435 --dt "dd/MM/yyyy HH:mm:ss" 1436 1437 # Process ShimCache 1438 AppCompatCacheParser.exe -f "$evidencePath\Registry\$host\SYSTEM" ` 1439 --csv "$outputPath\$host\Registry" --csvf "ShimCache_$host.csv" ` 1440 --dt "dd/MM/yyyy HH:mm:ss" 1441 1442 # Process Amcache 1443 AmcacheParser.exe -f "$evidencePath\Registry\$host\Amcache.hve" ` 1444 --csv "$outputPath\$host\Registry" --csvf "Amcache_$host.csv" ` 1445 --dt "dd/MM/yyyy HH:mm:ss" 1446 } 1447 1448 Write-Host "Processing complete for all hosts." 1449 ``` 1450 1451 --- 1452 1453 ### Handling Corrupted Artifacts 1454 1455 ```powershell 1456 # Memory dumps may be incomplete - use Volatility recovery options 1457 vol3 -f <corrupted_memory.bin> windows.pslist 2>&1 | Tee-Object -FilePath error_log.txt 1458 1459 # For corrupted registry hives - use Registry Explorer (tolerant of dirty hives) 1460 # Or use RECmd with --recover flag 1461 RECmd.exe -f <dirty_hive> --recover --csv <output> 1462 1463 # For truncated prefetch files 1464 PECmd.exe -f <file.pf> 2>&1 | Tee-Object -FilePath pf_errors.txt 1465 # PECmd will process what it can and report errors 1466 1467 # Validate evidence integrity before and after analysis 1468 certutil -hashfile <evidence_file> SHA256 > pre_analysis_hash.txt 1469 # After analysis 1470 certutil -hashfile <evidence_file> SHA256 > post_analysis_hash.txt 1471 fc pre_analysis_hash.txt post_analysis_hash.txt 1472 ``` 1473 1474 --- 1475 1476 ## SANS Tools Quick Reference 1477 1478 | Tool | Purpose | Author | Download | 1479 |------|---------|--------|----------| 1480 | **SIFT Workstation** | Complete forensic Linux distro | Rob T. Lee | https://www.sans.org/tools/sift-workstation | 1481 | **KAPE** | Artifact collection & processing | Eric Zimmerman | https://www.sans.org/tools/kape | 1482 | **PECmd** | Prefetch parser | Eric Zimmerman | https://ericzimmerman.github.io | 1483 | **EvtxECmd** | Event log parser | Eric Zimmerman | https://ericzimmerman.github.io | 1484 | **RECmd** | Registry command-line parser | Eric Zimmerman | https://ericzimmerman.github.io | 1485 | **Registry Explorer** | Registry GUI viewer | Eric Zimmerman | https://ericzimmerman.github.io | 1486 | **AppCompatCacheParser** | ShimCache parser | Eric Zimmerman | https://ericzimmerman.github.io | 1487 | **AmcacheParser** | Amcache parser with hashes | Eric Zimmerman | https://ericzimmerman.github.io | 1488 | **Timeline Explorer** | CSV/Excel forensic viewer | Eric Zimmerman | https://ericzimmerman.github.io | 1489 | **MFTECmd** | MFT parser | Eric Zimmerman | https://ericzimmerman.github.io | 1490 | **JLECmd** | Jump List parser | Eric Zimmerman | https://ericzimmerman.github.io | 1491 | **LECmd** | LNK file parser | Eric Zimmerman | https://ericzimmerman.github.io | 1492 | **SBECmd** | ShellBags parser | Eric Zimmerman | https://ericzimmerman.github.io | 1493 | **APOLLO** | iOS/macOS artefact parser | Sarah Edwards | https://www.sans.org/tools/apollo | 1494 | **Android Triage** | Android artefact collection | Mattia Epifani | https://www.sans.org/tools/android-triage | 1495 1496 --- 1497 1498 ## Additional Industry-Standard Tools 1499 1500 **Memory Analysis (Beyond Volatility):** 1501 1502 | Tool | Purpose | Source | 1503 |------|---------|--------| 1504 | **Rekall** | Memory forensics framework (deprecated but useful for older images) | https://github.com/google/rekall | 1505 | **WinDbg** | Microsoft debugger for crash dump analysis | Microsoft Store | 1506 | **Redline** | Memory and IOC analysis (FireEye/Mandiant) | https://www.fireeye.com/services/freeware/redline.html | 1507 1508 **Event Log Analysis (Beyond EvtxECmd):** 1509 1510 | Tool | Purpose | Source | 1511 |------|---------|--------| 1512 | **Zircolite** | SIGMA-based EVTX detection | https://github.com/wagga40/Zircolite | 1513 | **DeepBlueCLI** | PowerShell-based threat hunting | https://github.com/sans-blue-team/DeepBlueCLI | 1514 | **LogParser** | SQL-like queries on logs | Microsoft | 1515 1516 **Network Forensics:** 1517 1518 | Tool | Purpose | Source | 1519 |------|---------|--------| 1520 | **Wireshark/tshark** | Packet capture and analysis | https://www.wireshark.org | 1521 | **NetworkMiner** | Network forensic analysis | https://www.netresec.com | 1522 | **Zeek (Bro)** | Network security monitoring | https://zeek.org | 1523 1524 **Timeline Analysis:** 1525 1526 | Tool | Purpose | Source | 1527 |------|---------|--------| 1528 | **Plaso/Log2Timeline** | Super timeline creation | https://github.com/log2timeline/plaso | 1529 | **Timesketch** | Collaborative timeline analysis | https://timesketch.org | 1530 1531 --- 1532 1533 ## Command Reference Card 1534 1535 ### Hash Verification 1536 ```cmd 1537 certutil -hashfile <file> SHA256 1538 certutil -hashfile <file> MD5 1539 ``` 1540 1541 ### Volatility 3 Essential Commands 1542 ```bash 1543 vol3 -f <mem> windows.info 1544 vol3 -f <mem> windows.pslist 1545 vol3 -f <mem> windows.pstree 1546 vol3 -f <mem> windows.cmdline 1547 vol3 -f <mem> windows.malfind 1548 vol3 -f <mem> windows.netscan 1549 vol3 -f <mem> windows.dlllist --pid <PID> 1550 vol3 -f <mem> windows.handles --pid <PID> 1551 vol3 -f <mem> windows.vadyarascan --yara-file <rules.yar> 1552 ``` 1553 1554 ### MemProcFS 1555 ```cmd 1556 memprocfs.exe -device <mem> -forensic 1 1557 memprocfs.exe -device <mem> -forensic 1 -license-accept-elastic-license-2.0 1558 ``` 1559 1560 ### Eric Zimmerman Tools 1561 ```cmd 1562 PECmd.exe -d <prefetch_dir> --csv <out> --dt "dd/MM/yyyy HH:mm:ss" 1563 EvtxECmd.exe -f <evtx> --csv <out> --dt "dd/MM/yyyy HH:mm:ss" 1564 RECmd.exe -f <hive> --bn RECmd_Batch_MC.reb --csv <out> 1565 AppCompatCacheParser.exe -f <SYSTEM> --csv <out> 1566 AmcacheParser.exe -f <Amcache.hve> --csv <out> 1567 ``` 1568 1569 ### YARA 1570 ```bash 1571 yara -r <rules.yar> <target_directory> 1572 yara -s <rules.yar> <file> # Print matching strings 1573 ``` 1574 1575 ### CAPA 1576 ```bash 1577 capa <executable> 1578 capa -vv <executable> # Very verbose 1579 capa -j <executable> > results.json 1580 ``` 1581 1582 --- 1583 1584 ## References & Further Reading 1585 1586 **Official Documentation:** 1587 1. [SANS Tools Repository](https://www.sans.org/tools) β Complete collection of SANS forensic tools 1588 2. [Eric Zimmerman's Tools](https://ericzimmerman.github.io) β Complete EZ Tools suite 1589 3. [Volatility Foundation](https://github.com/volatilityfoundation/volatility3) β Volatility 3 framework 1590 4. [MemProcFS GitHub](https://github.com/ufrisk/MemProcFS) β Memory process file system 1591 5. [CAPA GitHub](https://github.com/mandiant/capa) β Mandiant malware capability detector 1592 6. [YARA Documentation](https://yara.readthedocs.io/) β Official YARA docs 1593 7. [Hayabusa GitHub](https://github.com/Yamato-Security/hayabusa) β SIGMA-based threat hunting 1594 8. [Chainsaw GitHub](https://github.com/WithSecureLabs/chainsaw) β Log hunting tool 1595 1596 **DFIR Learning Resources:** 1597 1. [SANS DFIR Blog](https://www.sans.org/blog/?focus-area=digital-forensics) β Latest DFIR techniques 1598 2. [13Cubed YouTube](https://www.youtube.com/c/13Cubed) β Forensic tool tutorials 1599 3. [HackTricks](https://book.hacktricks.xyz/) β Penetration testing and forensics 1600 4. [Ultimate Windows Security](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/) β Event ID encyclopedia 1601 1602 **MITRE ATT&CK:** 1603 1. [MITRE ATT&CK Framework](https://attack.mitre.org/) β Adversary tactics and techniques 1604 2. [T1055: Process Injection](https://attack.mitre.org/techniques/T1055/) β Process injection techniques 1605 3. [T1059: Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059/) β PowerShell, cmd.exe 1606 1607 **Cobalt Strike Detection:** 1608 1. [Cobalt Strike Detection](https://thedfirreport.com/category/cobalt-strike/) β Real-world Beacon analysis 1609 2. [Detecting Cobalt Strike with Memory Forensics](https://www.volexity.com/blog/2021/12/09/detecting-cobalt-strike-with-memory-forensics/) β Volexity research 1610 1611 --- 1612 1613 #HTB-Academy #DFIR #Digital-Forensics #Incident-Response #Memory-Analysis #Volatility #MemProcFS #CAPA #YARA #SANS-Tools #EZ-Tools #PECmd #EvtxECmd #RECmd #AppCompatCacheParser #AmcacheParser #Prefetch #Registry #Event-Logs #Hayabusa #Chainsaw #KAPE #Timeline-Explorer #Plaso #Malware-Analysis #Windows-Forensics #SIFT-Workstation #MITRE-T1055 #MITRE-T1059 #MITRE-T1547 #Cobalt-Strike #Process-Injection #Timeline-Analysis #Artifact-Parsing #CPTS #CDSA #Medium 1614 1615 1616 ------ 1617 1618 # Running MemprocFS on mac with FUSE 1619 1. Navigate to the `files` directory: 1620 ```bash 1621 cd /Users/daemon1/DigitalForensics/Tools/memprocfs/files 1622 ``` 1623 2. Ensure the mount point exists: 1624 ```bash 1625 mkdir -p mnt 1626 ``` 1627 3. Run `memprocfs`: 1628 ```bash 1629 ./memprocfs -device ../../../Working/CMP416-2202336-CW2/WORKSTATION-969/memory/memory.bin -forensic 1 -forensic-yara-rules ../../yara-rules/index.yar -mount mnt/ 1630 ``` 1631 `-disable-python -v` if you need to 1632 1633 --- 1634 1635 ## Key Updates & Enhancements to Add 1636 1637 ### **Volatility 3 Updates (v2.26.0 - Feature Parity Release, May 2025)** 1638 1639 **Major Changes:** 1640 - **Volatility 2 is now officially deprecated** - The GitHub repository has been archived 1641 - **No more `--profile` argument required** - Volatility 3 automatically detects OS versions 1642 - **New `--filters` flag** - Column-specific filtering without grep/awk 1643 - **Unified output formats** - All plugins support csv, json, jsonl, pretty output via `-r` option 1644 - **Consistent data extraction** - All plugins use `-o` for output directory and `--dump` option 1645 1646 **New Plugins (Add to your commands):** 1647 1648 ```bash 1649 # New Windows plugins (v2.26.0) 1650 vol3 -f <mem> windows.hollowprocesses # Detect process hollowing 1651 vol3 -f <mem> windows.psxview # Cross-reference process lists (hidden process detection) 1652 vol3 -f <mem> windows.suspicious_threads # Find suspicious userland threads 1653 vol3 -f <mem> windows.suspended_threads # Enumerate suspended threads 1654 vol3 -f <mem> windows.direct_system_calls # Detect direct syscalls (EDR bypass) 1655 vol3 -f <mem> windows.indirect_system_calls # Detect indirect syscalls 1656 vol3 -f <mem> windows.shimcachemem # ShimCache from memory 1657 vol3 -f <mem> windows.scheduled_tasks # Decode scheduled tasks from registry 1658 vol3 -f <mem> windows.svclist # List services from doubly-linked list 1659 vol3 -f <mem> windows.svcdiff # Compare services (walking vs scanning) for rootkit detection 1660 vol3 -f <mem> windows.processghosting # Detect process ghosting technique 1661 vol3 -f <mem> windows.pedump # Extract PE files from specific addresses 1662 1663 # New filtering example 1664 vol3 -f <mem> --filters "ImageFileName=powershell" windows.pslist 1665 vol3 -f <mem> --filters "Start VPN=0x1000000" windows.vadinfo 1666 1667 # Pretty output (aligned tables) 1668 vol3 -f <mem> -r pretty windows.pslist 1669 ``` 1670 1671 --- 1672 1673 ### **MemProcFS Updates (v5.15 - Latest, June 2025)** 1674 1675 **New Features to Add:** 1676 1677 | Version | Key Features | 1678 |---------|-------------| 1679 | v5.15 | Linux LeechAgent support (gRPC), **High Entropy detection** in FindEvil, DNS cache parsing | 1680 | v5.14 | **macOS support**, Linux clang compilation | 1681 | v5.13 | Console module, File recovery improvements, **Callstack parsing for x64 processes** | 1682 | v5.12 | New APIs for Kernel Objects, Drivers and Devices | 1683 | v5.10 | Windows 11 24H2 support, **Hibernation file support**, Prefetch parsing, Sysinfo module, Eventlog module | 1684 | v5.9 | FindEvil shows Windows Defender AV detections, Proxmox dump support | 1685 1686 **Updated Commands:** 1687 1688 ```cmd 1689 :: New sysinfo module for easy system info 1690 memprocfs.exe -device <mem> -forensic 1 1691 :: Then browse M:\forensic\sysinfo\ 1692 1693 :: DNS cache parsing (new in v5.15) 1694 :: Available at M:\forensic\dns\ 1695 1696 :: Eventlog module (v5.10+) 1697 :: Available at M:\forensic\eventlog\ 1698 1699 :: Console module (v5.13+) 1700 :: Available at M:\name\<process>\console\ 1701 1702 :: High entropy detection 1703 :: FindEvil now flags high entropy regions (potential packed/encrypted code) 1704 ``` 1705 1706 **New Virtual File System Directories:** 1707 1708 | Directory | Contents | Version Added | 1709 |-----------|----------|---------------| 1710 | `M:\forensic\sysinfo\` | Easy-to-read system information | v5.10 | 1711 | `M:\forensic\eventlog\` | Convenient event log access | v5.10 | 1712 | `M:\forensic\dns\` | DNS cache entries | v5.15 | 1713 | `M:\name\<proc>\console\` | Console buffer contents | v5.13 | 1714 | `M:\name\<proc>\callstack\` | x64 user-mode callstacks | v5.13 | 1715 1716 --- 1717 1718 ### **Hayabusa Updates (v3.3.0 - Latest, May 2025)** 1719 1720 **Major New Features:** 1721 1722 ```bash 1723 # New "Emergency" alert level for critical systems (v3.1.0+) 1724 # Add critical system names to config/critical_systems.txt 1725 # Alerts are automatically elevated one level on those systems 1726 1727 # Auto-detect domain controllers and file servers 1728 hayabusa config-critical-systems -d <evtx_dir> 1729 1730 # Extract and decode Base64 strings (v3.0.0+) 1731 hayabusa extract-base64 -d <evtx_dir> -o base64_decoded.csv 1732 1733 # Log metrics command (v2.19.0+) 1734 hayabusa log-metrics -d <evtx_dir> -o log_metrics.csv 1735 1736 # Tab-separated output for field info 1737 hayabusa csv-timeline -d <evtx_dir> -o timeline.csv -S 1738 1739 # Sigma V2 correlation rules support (v3.0.0+) 1740 # - temporal (Temporal Proximity) 1741 # - temporal_ordered (Temporal Ordered Proximity) 1742 # - expand field modifiers 1743 1744 # XOR-encoded rules to bypass AV false positives (v2.18.0+) 1745 # Use live-response packages from releases 1746 ``` 1747 1748 **New Command Summary:** 1749 1750 | Command | Purpose | Version | 1751 |---------|---------|---------| 1752 | `extract-base64` | Extract and decode Base64 from events | v3.0.0 | 1753 | `expand-list` | List placeholder names for expand rules | v3.0.0 | 1754 | `log-metrics` | Get .evtx file information | v2.19.0 | 1755 | `config-critical-systems` | Auto-find DCs and file servers | v3.1.0 | 1756 1757 **Performance Improvements:** 1758 - Low memory mode enabled by default 1759 - Significantly faster `logon-summary` with channel filtering 1760 - `search` command no longer sorts by default (use `-s` to sort) 1761 1762 --- 1763 1764 ### **KAPE Updates (2024-2025)** 1765 1766 **Key Compound Targets:** 1767 1768 | Target | Description | 1769 |--------|-------------| 1770 | `KapeTriage` | Comprehensive triage - Registry, Event Logs, Prefetch, Amcache, etc. | 1771 | `!BasicCollection` | Essential forensic artifacts | 1772 | `!SANS_Triage` | SANS-recommended artifact set | 1773 | `EvidenceOfExecution` | Prefetch, RecentFileCache, AmCache, SysCache | 1774 1775 **Key Compound Modules:** 1776 1777 | Module | Description | 1778 |--------|-------------| 1779 | `!EZParser` | All Eric Zimmerman tools against collected artifacts | 1780 | `Mini_Timeline` | Generate timeline using TLN tools | 1781 1782 **New Command Examples:** 1783 1784 ```cmd 1785 :: Collect with KapeTriage and process with EZParser 1786 kape.exe --tsource C: --tdest D:\Evidence --target KapeTriage --mdest D:\Processed --module !EZParser 1787 1788 :: Output to VHDX container 1789 kape.exe --tsource C: --tdest D:\Evidence --target KapeTriage --vhdx Evidence_Container 1790 1791 :: Include Volume Shadow Copies 1792 kape.exe --tsource C: --tdest D:\Evidence --target KapeTriage --vss 1793 1794 :: Sync targets and modules to latest 1795 kape.exe --sync 1796 ``` 1797 1798 --- 1799 1800 ### **New Tools to Add** 1801 1802 #### **Velociraptor** 1803 **Purpose:** Enterprise-wide endpoint visibility and DFIR platform. Integrates with Hayabusa for scalable threat hunting. 1804 1805 **Source:** [Velociraptor](https://docs.velociraptor.app/) 1806 1807 ```yaml 1808 # Hayabusa artifact for Velociraptor 1809 # Allows enterprise-wide Windows event log analysis 1810 # Retroactively creates SIEM-like visibility 1811 ``` 1812 1813 #### **Zircolite** 1814 **Purpose:** Standalone SIGMA-based detection tool for EVTX, Auditd, Sysmon for Linux, and more. 1815 1816 **Source:** [Zircolite GitHub](https://github.com/wagga40/Zircolite) 1817 1818 ```bash 1819 # Scan with SIGMA rules 1820 python3 zircolite.py --evtx <evtx_dir> --ruleset rules/rules_windows_generic.json 1821 ``` 1822 1823 #### **DeepBlueCLI** 1824 **Purpose:** PowerShell-based threat hunting in Windows event logs. 1825 1826 **Source:** [DeepBlueCLI GitHub](https://github.com/sans-blue-team/DeepBlueCLI) 1827 1828 ```powershell 1829 # Analyze Security log 1830 .\DeepBlue.ps1 .\Security.evtx 1831 ``` 1832 1833 --- 1834 1835 ### **Updated MITRE ATT&CK Techniques** 1836 1837 Add these commonly detected techniques: 1838 1839 | Technique ID | Name | Detection Method | 1840 |-------------|------|------------------| 1841 | **T1055.012** | Process Hollowing | `windows.hollowprocesses` (Vol3) | 1842 | **T1055.001** | DLL Injection | `windows.malfind` + `windows.ldrmodules` | 1843 | **T1134** | Access Token Manipulation | `windows.privileges` | 1844 | **T1218** | System Binary Proxy Execution | Hayabusa SIGMA rules | 1845 | **T1562.001** | Disable Security Tools | Event ID 1102, 7045 | 1846 1847 --- 1848 1849 ### **Updated Quick Reference Table** 1850 1851 Replace your existing table with this expanded version: 1852 1853 | # | Tool | Primary Use | Key Command | Notes | 1854 |:--|:-----|:------------|:------------|:------| 1855 | 1 | **Volatility 3** (v2.26) | Memory forensics | `vol3 -f mem.bin windows.hollowprocesses` | Process hollowing detection | 1856 | 2 | **MemProcFS** (v5.15) | Memory VFS | `memprocfs.exe -device mem.