recmd.md (28694B)
1 --- 2 title: "RECmd Registry Forensics" 3 description: "RECmd registry analysis workflow: batch files, keys of interest and evidence extraction." 4 category: dfir 5 tags: [dfir, registry, windows] 6 tools: [RECmd, Registry Explorer] 7 difficulty: advanced 8 updated: "2026-08-09" 9 source: "vault:DFIR/REDmd - Quick Cheat sheet.md" 10 --- 11 12 # RECmd Registry Forensics 13 14 ## Part 1: Quick Reference Cheat Sheet 15 16 ### Essential Command Templates 17 18 ```powershell 19 # UPDATE BATCH FILES 20 RECmd.exe --sync 21 22 # PARSE SINGLE HIVE 23 RECmd.exe -f <HIVE_PATH> --csv <OUT_DIR> --csvf <FILENAME>.csv --dt "dd/MM/yyyy HH:mm:ss" 24 25 # PARSE ALL HIVES IN DIRECTORY 26 RECmd.exe -d <HIVES_DIR> --csv <OUT_DIR> --dt "dd/MM/yyyy HH:mm:ss" 27 28 # RUN BATCH FILE (TRIAGE) 29 RECmd.exe -d <HIVES_DIR> --bn BatchExamples\DFIRBatch.reb --csv <OUT_DIR> --csvf Triage.csv --dt "dd/MM/yyyy HH:mm:ss" 30 31 # EXTRACT SPECIFIC KEY 32 RECmd.exe -f <HIVE_PATH> --kn "KeyPath\Here" --csv <OUT_DIR> --csvf Output.csv 33 34 # SEARCH FOR KEYWORD 35 RECmd.exe -f <HIVE_PATH> --sd "keyword" --csv <OUT_DIR> --csvf Search.csv 36 37 # RECOVER DELETED KEYS/VALUES (DEFAULT = ON) 38 RECmd.exe -f <HIVE_PATH> --recover true --csv <OUT_DIR> --csvf Recovered.csv 39 40 # REPLAY TRANSACTION LOGS (DEFAULT = ON) 41 RECmd.exe -f <HIVE_PATH> --nl false --csv <OUT_DIR> --csvf Clean.csv 42 ``` 43 44 --- 45 46 ### Critical Flags Reference 47 48 | Flag | Purpose | Example | 49 |------|---------|---------| 50 | `-f` | Single hive file | `-f C:\Evidence\SYSTEM` | 51 | `-d` | Directory (recursive) | `-d C:\Evidence\Hives` | 52 | `--bn` | Batch file | `--bn BatchExamples\DFIRBatch.reb` | 53 | `--csv` | Output directory | `--csv C:\Output\CSV` | 54 | `--csvf` | Override CSV filename | `--csvf SYSTEM_results.csv` | 55 | `--dt` | Date format (UK) | `--dt "dd/MM/yyyy HH:mm:ss"` | 56 | `--nl` | Ignore transaction logs | `--nl false` (default = replay logs) | 57 | `--recover` | Recover deleted data | `--recover true` (default = on) | 58 | `--kn` | Extract specific key | `--kn "ControlSet001\Services"` | 59 | `--vn` | Extract specific value | `--vn "ProductName"` | 60 | `--sa` | Search all | `--sa "malware.exe"` | 61 | `--sk` | Search key names | `--sk "Run"` | 62 | `--sv` | Search value names | `--sv "Path"` | 63 | `--sd` | Search value data | `--sd "C:\Windows"` | 64 | `--regex` | Enable regex search | `--regex --sd ".*\.exe$"` | 65 | `--vss` | Parse Volume Shadow Copies | `--vss` | 66 | `--q` | Quiet mode | `--q` | 67 68 --- 69 70 ### Batch Files Quick Reference 71 72 | Batch File | Purpose | Command | 73 |-----------|---------|---------| 74 | `DFIRBatch.reb` | Full triage (System Info, Execution, Persistence, User Activity) | `--bn BatchExamples\DFIRBatch.reb` | 75 | `RegistryASEPs.reb` | Persistence detection (~500 keys, ~400 values) | `--bn BatchExamples\RegistryASEPs.reb` | 76 | Custom `.reb` | Targeted extraction (USB, Run keys, etc.) | Create your own (see Part 6) | 77 78 --- 79 80 ### File Structure 81 82 ```text 83 <CASE_DIR>/ 84 ├── Tools/ 85 │ └── RECmd/ 86 │ ├── RECmd.exe 87 │ ├── RLA.exe # Transaction log replayer 88 │ └── BatchExamples/ 89 │ ├── DFIRBatch.reb 90 │ └── RegistryASEPs.reb 91 ├── Evidence/ 92 │ └── Hives/ 93 │ ├── SAM 94 │ ├── SECURITY 95 │ ├── SOFTWARE 96 │ ├── SYSTEM 97 │ ├── SYSTEM.LOG1 # Transaction logs 98 │ ├── SYSTEM.LOG2 99 │ └── NTUSER.DAT 100 └── Output/ 101 └── CSV/ 102 ``` 103 104 --- 105 106 ## Part 2: Workflow for Your Hive Set 107 108 ### Setup (One-Time) 109 110 ```powershell 111 # 1. Create folder structure 112 mkdir C:\Cases\MyCase\Tools\RECmd 113 mkdir C:\Cases\MyCase\Evidence\Hives 114 mkdir C:\Cases\MyCase\Output\CSV 115 116 # 2. Download RECmd to Tools\RECmd folder 117 # Source: https://ericzimmerman.github.io/#!index.md 118 119 # 3. Copy your hives to Evidence\Hives: 120 # - SAM 121 # - SECURITY 122 # - SOFTWARE 123 # - SYSTEM (+ SYSTEM.LOG1, SYSTEM.LOG2 if available) 124 # - NTUSER.DAT 125 126 # 4. Update batch files 127 cd C:\Cases\MyCase\Tools\RECmd 128 RECmd.exe --sync 129 ``` 130 131 --- 132 133 ### Workflow 1: Fast Triage (5 minutes) 134 135 **Objective:** Get high-value artefacts immediately. 136 137 ```powershell 138 cd C:\Cases\MyCase\Tools\RECmd 139 140 # Run DFIRBatch against all hives 141 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --bn BatchExamples\DFIRBatch.reb --csv C:\Cases\MyCase\Output\CSV --csvf Triage.csv --q --dt "dd/MM/yyyy HH:mm:ss" 142 ``` 143 144 **Output:** Single CSV file `Triage.csv` containing: 145 - System info (OS version, hostname, timezone) 146 - User accounts (SAM) 147 - Program execution (ShimCache, BAM/DAM, UserAssist) 148 - Persistence (Run keys, services, scheduled tasks) 149 - USB devices (USBSTOR, mounted devices) 150 - User activity (RecentDocs, TypedPaths, searches) 151 152 **Review in Timeline Explorer:** 153 1. Open `C:\Cases\MyCase\Output\CSV\Triage.csv` 154 2. Filter by `Category` column: `Program Execution`, `Persistence`, `User Activity`, `Devices` 155 156 --- 157 158 ### Workflow 2: Hive-by-Hive Deep Dive 159 160 #### SAM Hive: User Accounts 161 162 **What you'll find:** Local user accounts (username, RID, SID), last login times, logon counts, password policies, group membership. 163 164 ```powershell 165 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SAM --csv C:\Cases\MyCase\Output\CSV --csvf SAM.csv --dt "dd/MM/yyyy HH:mm:ss" 166 ``` 167 168 **Key artefacts to review:** 169 170 | KeyPath | What to look for | 171 |---------|------------------| 172 | `SAM\Domains\Account\Users\000001F4` | RID 500 = Built-in Administrator account | 173 | `SAM\Domains\Account\Users\<RID>` | Check `LastWriteTime` = account creation/modification | 174 | Value: `F` | Account metadata (flags, lockout) | 175 | Value: `V` | Username | 176 177 **Red flags:** 178 - New local admin accounts (RID 500 group membership) 179 - Accounts with zero logon count but recent `LastWriteTime` (re-enabled?) 180 - Disabled accounts with activity timestamps 181 182 --- 183 184 #### SECURITY Hive: Audit Configuration 185 186 **What you'll find:** Security policies, audit settings, LSA secrets (structure only; data encrypted). 187 188 ```powershell 189 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SECURITY --csv C:\Cases\MyCase\Output\CSV --csvf SECURITY.csv --dt "dd/MM/yyyy HH:mm:ss" 190 ``` 191 192 **Key artefacts:** 193 194 | KeyPath | What to look for | 195 |---------|------------------| 196 | `Policy\PolAdtEv` | Audit policy bitmask (disabled = evasion) | 197 | `Policy\Secrets` | LSA secrets structure (data encrypted) | 198 199 > **Note —** Limited forensic value for offline analysis; most data encrypted. 200 201 --- 202 203 #### SOFTWARE Hive: System Configuration & Persistence 204 205 **What you'll find:** OS version, hostname, install date, installed software, persistence mechanisms (Run keys, scheduled tasks), user profile paths (ProfileList), network shares (MountPoints2). 206 207 ```powershell 208 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --bn BatchExamples\DFIRBatch.reb --csv C:\Cases\MyCase\Output\CSV --csvf SOFTWARE.csv --dt "dd/MM/yyyy HH:mm:ss" 209 ``` 210 211 **Key artefacts to review:** 212 213 | KeyPath | What to look for | 214 |---------|------------------| 215 | `Microsoft\Windows NT\CurrentVersion` | `ProductName`, `ReleaseId`, `InstallDate` | 216 | `Microsoft\Windows\CurrentVersion\Run` | Machine-wide auto-start entries | 217 | `Microsoft\Windows\CurrentVersion\RunOnce` | One-time execution entries | 218 | `Wow6432Node\Microsoft\Windows\CurrentVersion\Run` | 32-bit persistence on 64-bit systems | 219 | `Microsoft\Windows NT\CurrentVersion\ProfileList` | User SIDs → Profile paths (e.g., `C:\Users\JohnDoe`) | 220 | `Microsoft\Windows\CurrentVersion\Uninstall` | Installed software (`DisplayName`, `InstallDate`) | 221 | `Microsoft\Windows\CurrentVersion\Explorer\MountPoints2` | Mapped drives, UNC shares | 222 223 **Persistence hunt:** 224 225 ```powershell 226 # Extract all Run keys 227 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --kn "Microsoft\Windows\CurrentVersion\Run" --csv C:\Cases\MyCase\Output\CSV --csvf Run_keys.csv --dt "dd/MM/yyyy HH:mm:ss" 228 229 # Search for suspect paths 230 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --sd "AppData\Roaming" --csv C:\Cases\MyCase\Output\CSV --csvf Suspect_paths.csv 231 ``` 232 233 **Red flags:** 234 - Obfuscated Run key values (Base64, PowerShell encoded commands) 235 - Non-standard paths (`C:\Temp`, `C:\ProgramData`, user AppData) 236 - Recently modified Run keys (check `LastWriteTime`) 237 238 --- 239 240 #### SYSTEM Hive: Hardware, Services, USB Devices, Execution 241 242 **What you'll find:** Services, USB device history (USBSTOR, mounted devices), ShimCache (file existence, NOT execution proof), BAM/DAM (execution evidence with timestamps), network configuration, timezone. 243 244 ```powershell 245 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --bn BatchExamples\DFIRBatch.reb --csv C:\Cases\MyCase\Output\CSV --csvf SYSTEM.csv --dt "dd/MM/yyyy HH:mm:ss" 246 ``` 247 248 **Key artefacts to review:** 249 250 | KeyPath | What to look for | 251 |---------|------------------| 252 | `ControlSet001\Enum\USBSTOR` | USB storage devices (VID, PID, serial number) | 253 | `ControlSet001\Enum\USB` | All USB devices (including non-storage) | 254 | `MountedDevices` | Drive letters → Device serial numbers | 255 | `ControlSet001\Services` | Service binaries (check `ImagePath`, `Start` type) | 256 | `ControlSet001\Control\Session Manager\AppCompatCache` | ShimCache: file paths, modified times, sizes | 257 | `ControlSet001\Services\bam\State\UserSettings\<SID>` | BAM: execution timestamps (Win10 1709+) | 258 | `ControlSet001\Services\dam\State\UserSettings\<SID>` | DAM: Desktop Activity Moderator | 259 | `ControlSet001\Control\TimeZoneInformation` | Timezone, DST settings | 260 | `Select` | `Current` = active ControlSet number | 261 262 **USB device extraction:** 263 264 ```powershell 265 # Extract USB storage devices 266 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "ControlSet001\Enum\USBSTOR" --csv C:\Cases\MyCase\Output\CSV --csvf USB_STOR.csv 267 268 # Extract all USB devices 269 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "ControlSet001\Enum\USB" --csv C:\Cases\MyCase\Output\CSV --csvf USB_all.csv 270 271 # Extract mounted devices 272 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "MountedDevices" --csv C:\Cases\MyCase\Output\CSV --csvf Mounted.csv 273 ``` 274 275 **Execution evidence (BAM/DAM):** 276 277 ```powershell 278 # Extract BAM (Win10 1709+) 279 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "ControlSet001\Services\bam\State\UserSettings" --csv C:\Cases\MyCase\Output\CSV --csvf BAM.csv --dt "dd/MM/yyyy HH:mm:ss" 280 281 # Extract DAM 282 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "ControlSet001\Services\dam\State\UserSettings" --csv C:\Cases\MyCase\Output\CSV --csvf DAM.csv --dt "dd/MM/yyyy HH:mm:ss" 283 ``` 284 285 **Review BAM/DAM output:** 286 - Each subkey = User SID (cross-reference with SOFTWARE\ProfileList) 287 - Value names = Hex timestamps 288 - Value data = Executable full path 289 - **This is STRONG execution evidence** 290 291 **ShimCache extraction:** 292 293 ```powershell 294 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "ControlSet001\Control\Session Manager\AppCompatCache" --csv C:\Cases\MyCase\Output\CSV --csvf ShimCache.csv --dt "dd/MM/yyyy HH:mm:ss" 295 ``` 296 297 **ShimCache caveats:** 298 - **Does NOT prove execution**, only file existence 299 - `LastModified` = file timestamp, NOT execution time 300 - Useful for: identifying suspect file paths, confirming file presence (even if deleted) 301 302 **Red flags:** 303 - Unusual service binaries (non-System32 paths, renamed system tools) 304 - USB devices connected during incident timeframe (check `LastWriteTime` on USBSTOR keys) 305 - BAM/DAM entries for known malware paths 306 - ShimCache entries for staging directories (`C:\Temp`, `C:\Users\Public`) 307 308 --- 309 310 #### NTUSER.DAT Hive: User Activity 311 312 **What you'll find:** Recently opened files (RecentDocs), program execution (UserAssist), folder access history (ShellBags), typed paths, search terms (WordWheelQuery), Office documents with macros enabled (TrustRecords). 313 314 ```powershell 315 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\NTUSER.DAT --bn BatchExamples\DFIRBatch.reb --csv C:\Cases\MyCase\Output\CSV --csvf NTUSER.csv --dt "dd/MM/yyyy HH:mm:ss" 316 ``` 317 318 **Key artefacts to review:** 319 320 | KeyPath | What to look for | 321 |---------|------------------| 322 | `Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\<GUID>\Count` | GUI program execution (ROT13 encoded) | 323 | `Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs` | Recently opened files by extension | 324 | `Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU` | Open/Save dialog history | 325 | `Software\Microsoft\Windows\Shell\BagMRU` | Folder access history (ShellBags) | 326 | `Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths` | Paths typed into Explorer address bar | 327 | `Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU` | Commands in Win+R Run dialog | 328 | `Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery` | Windows Search queries | 329 | `Software\Microsoft\Office\<Version>\<App>\Security\Trusted Documents\TrustRecords` | Office files with macros enabled | 330 331 **UserAssist extraction:** 332 333 ```powershell 334 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\NTUSER.DAT --kn "Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist" --csv C:\Cases\MyCase\Output\CSV --csvf UserAssist.csv 335 ``` 336 337 **UserAssist decoding:** 338 - Value names are ROT13 encoded (e.g., `HRZR_PGYFRFFVATF` = `UEME_PGULESSFVATS`) 339 - Timeline Explorer auto-decodes 340 - Manual: use an online ROT13 decoder 341 - Value data contains: execution count, last execution timestamp 342 343 **RecentDocs extraction:** 344 345 ```powershell 346 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\NTUSER.DAT --kn "Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs" --csv C:\Cases\MyCase\Output\CSV --csvf RecentDocs.csv 347 ``` 348 349 **ShellBags extraction:** 350 351 ```powershell 352 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\NTUSER.DAT --kn "Software\Microsoft\Windows\Shell\BagMRU" --csv C:\Cases\MyCase\Output\CSV --csvf ShellBags.csv 353 ``` 354 355 **Search terms extraction:** 356 357 ```powershell 358 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\NTUSER.DAT --kn "Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery" --csv C:\Cases\MyCase\Output\CSV --csvf Searches.csv 359 ``` 360 361 **Red flags:** 362 - Searches for anti-forensics tools ("delete logs", "wipe files") 363 - Execution of tools from USB/external drives (UserAssist) 364 - Recently opened files with suspect extensions (`.exe`, `.bat`, `.ps1` in RecentDocs) 365 - Office TrustRecords for phishing document paths (e.g., `Downloads\invoice.docm`) 366 - TypedPaths/RunMRU containing attacker commands (e.g., `powershell.exe -enc <Base64>`) 367 368 **Multiple NTUSER.DAT files (multi-user system):** 369 370 ```powershell 371 # 1. Get user list from SOFTWARE hive 372 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --kn "Microsoft\Windows NT\CurrentVersion\ProfileList" --csv C:\Cases\MyCase\Output\CSV --csvf Users.csv 373 374 # 2. Process each user's NTUSER.DAT (example for JohnDoe) 375 RECmd.exe -f "C:\Users\JohnDoe\NTUSER.DAT" --bn BatchExamples\DFIRBatch.reb --csv C:\Cases\MyCase\Output\CSV --csvf NTUSER_JohnDoe.csv 376 377 # 3. Repeat for additional users 378 RECmd.exe -f "C:\Users\JaneSmith\NTUSER.DAT" --bn BatchExamples\DFIRBatch.reb --csv C:\Cases\MyCase\Output\CSV --csvf NTUSER_JaneSmith.csv 379 ``` 380 381 --- 382 383 ### Workflow 3: Persistence Hunting 384 385 **Objective:** Identify all auto-start locations (ASEPs). 386 387 ```powershell 388 # Run RegistryASEPs batch (Troy Larson) 389 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --bn BatchExamples\RegistryASEPs.reb --csv C:\Cases\MyCase\Output\CSV --csvf Persistence.csv --dt "dd/MM/yyyy HH:mm:ss" 390 ``` 391 392 **Output:** ~500 registry keys, ~400 values covering Run/RunOnce keys (machine + user), services, scheduled tasks, Winlogon entries, Image File Execution Options, AppInit_DLLs, browser helper objects (BHOs), startup folder paths. 393 394 **Timeline Explorer review:** 395 1. Open `Persistence.csv` 396 2. Filter by `Category` = "Persistence" or "Autoruns" 397 3. Sort by `LastWriteTime` (most recent first) 398 4. Focus on: unknown/unsigned binaries, non-standard paths, Base64/encoded commands, timestamps matching incident timeframe 399 400 --- 401 402 ### Workflow 4: Keyword Search Across All Hives 403 404 **Scenario:** Search for specific IOC (e.g., `malware.exe`). 405 406 ```powershell 407 # Search all value data for keyword 408 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --sd "malware.exe" --csv C:\Cases\MyCase\Output\CSV --csvf Search_malware.csv 409 410 # Search with regex (all .exe files in Temp) 411 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --regex --sd "C:\\\\Temp\\\\.*\\.exe" --csv C:\Cases\MyCase\Output\CSV --csvf Search_Temp_EXE.csv 412 413 # Search key names 414 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --sk "Run" --csv C:\Cases\MyCase\Output\CSV --csvf Search_Run_keys.csv 415 416 # Search value names 417 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --sv "ImagePath" --csv C:\Cases\MyCase\Output\CSV --csvf Search_ImagePath.csv 418 ``` 419 420 --- 421 422 ## Part 3: Recovering Deleted Registry Data 423 424 ### Understanding Deleted Data 425 426 Registry deletion behaviour: 427 - Deleted keys/values are NOT immediately removed from hive file 428 - Marked as "deleted" in hive structure but data remains until overwritten 429 - RECmd can recover deleted entries using `--recover` switch (DEFAULT = ON) 430 431 What can be recovered: deleted registry keys, deleted values, slack space (residual data in unused hive blocks). 432 433 --- 434 435 ### Method 1: Automatic Recovery (Default) 436 437 ```powershell 438 # Recovery is ON by default 439 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --csv C:\Cases\MyCase\Output\CSV --csvf SOFTWARE_recovered.csv 440 441 # Explicitly enable (same as default) 442 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --recover true --csv C:\Cases\MyCase\Output\CSV --csvf SOFTWARE_recovered.csv 443 ``` 444 445 Identifying recovered data in CSV output: check `IsDeleted` column (if present in plugin output); deleted keys show in output with timestamps but marked as removed. 446 447 --- 448 449 ### Method 2: Search Slack Space 450 451 Slack space = unused portions of hive file blocks containing residual deleted data. 452 453 ```powershell 454 # Search slack space for keyword 455 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --ss --sd "deleted_value" --csv C:\Cases\MyCase\Output\CSV --csvf Slack_search.csv 456 457 # Search all (keys + values + data + slack) 458 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --sa "keyword" --csv C:\Cases\MyCase\Output\CSV --csvf All_search.csv 459 ``` 460 461 --- 462 463 ### Method 3: Transaction Log Replay (Clean Dirty Hives) 464 465 **Scenario:** Hive is "dirty" (not cleanly shut down) and transaction logs exist. 466 467 Transaction logs: `*.LOG1`, `*.LOG2` files contain uncommitted changes. 468 469 RECmd behaviour: 470 - `--nl false` (DEFAULT) = replays transaction logs → clean hive data 471 - `--nl true` = ignores transaction logs → may miss recent data 472 473 **Check for transaction logs:** 474 475 ```powershell 476 # Example: SYSTEM hive 477 dir C:\Cases\MyCase\Evidence\Hives\SYSTEM* 478 # Expected files: SYSTEM, SYSTEM.LOG1, SYSTEM.LOG2 479 ``` 480 481 **Parse with transaction log replay:** 482 483 ```powershell 484 # Ensure .LOG1 and .LOG2 are in same directory as hive 485 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --nl false --csv C:\Cases\MyCase\Output\CSV --csvf SYSTEM_clean.csv 486 ``` 487 488 **If transaction logs are missing:** 489 490 ```powershell 491 # Parse without transaction logs (may be incomplete) 492 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --nl true --csv C:\Cases\MyCase\Output\CSV --csvf SYSTEM_dirty.csv 493 ``` 494 495 **Alternative: Use RLA.exe to create clean hive** (RLA.exe = Registry Log Analyser, included with RECmd). 496 497 ```powershell 498 # Replay transaction logs and output clean hive 499 cd C:\Cases\MyCase\Tools\RECmd 500 RLA.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --out C:\Cases\MyCase\Evidence\Hives\Clean 501 502 # Output: C:\Cases\MyCase\Evidence\Hives\Clean\SYSTEM (clean copy) 503 504 # Now parse clean hive with RECmd 505 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\Clean\SYSTEM --csv C:\Cases\MyCase\Output\CSV --csvf SYSTEM_clean.csv 506 507 # RLA for entire directory 508 RLA.exe -d C:\Cases\MyCase\Evidence\Hives --out C:\Cases\MyCase\Evidence\Hives\Clean 509 ``` 510 511 --- 512 513 ### Method 4: Volume Shadow Copy Analysis 514 515 **Scenario:** Recover historical registry states from VSS snapshots. Prerequisite: VSS snapshots must exist on evidence drive. 516 517 ```powershell 518 # Parse hive + all VSS snapshots 519 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --vss --csv C:\Cases\MyCase\Output\CSV --csvf SOFTWARE_VSS.csv --dt "dd/MM/yyyy HH:mm:ss" 520 521 # Or entire directory with VSS 522 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --vss --csv C:\Cases\MyCase\Output\CSV --csvf All_VSS.csv 523 ``` 524 525 Output: separate entries for each VSS snapshot; timestamped filenames show VSS creation date; compare current hive vs historical snapshots to identify deleted/modified keys. 526 527 --- 528 529 ### Recovery Checklist 530 531 - [ ] **Transaction logs present?** If YES: run with `--nl false` (default). If NO: run with `--nl true` (accept incomplete data), or use RLA.exe to attempt recovery. 532 - [ ] **Recover deleted keys/values** — run with `--recover true` (default); review CSV output for deleted entries. 533 - [ ] **Search slack space** — use `--ss` flag with search keywords; look for residual deleted data. 534 - [ ] **Volume Shadow Copies available?** — use `--vss` to parse historical snapshots; compare current vs historical states. 535 - [ ] **Output verification** — check CSV row count (compare with/without `--recover`); review `LastWriteTime` timestamps for anomalies; cross-reference with known-good baselines. 536 537 --- 538 539 ## Part 4: Troubleshooting 540 541 | Problem | Cause | Solution | 542 |---------|-------|----------| 543 | `Unable to open file` | File locked, wrong path, permissions | Run as Administrator, verify path, close Registry Editor | 544 | `Hive is dirty` | Missing transaction logs | Supply `.LOG1`/`.LOG2` files OR use RLA.exe OR run with `--nl true` | 545 | Empty CSV output | Batch HiveType mismatch | Check batch file `HiveType` matches hive (e.g., NTUSER batch on NTUSER.DAT) | 546 | ROT13 encoded values | Raw UserAssist output | Open CSV in Timeline Explorer (auto-decodes) | 547 | `Out of memory` | Large hive + `--details` | Remove `--details`, use `--q`, increase system RAM | 548 | Fewer rows without `--nl false` | Missing transaction log data | Ensure `.LOG1`/`.LOG2` present and `--nl false` used | 549 550 ### Quick Fixes 551 552 ```powershell 553 # Check hive file is readable 554 icacls C:\Cases\MyCase\Evidence\Hives\SYSTEM 555 556 # Verify batch file exists 557 dir C:\Cases\MyCase\Tools\RECmd\BatchExamples\DFIRBatch.reb 558 559 # Test single key extraction (troubleshooting) 560 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --kn "Microsoft\Windows NT\CurrentVersion" --csv C:\Cases\MyCase\Output\CSV --csvf Test.csv 561 ``` 562 563 --- 564 565 ## Part 5: Integration with Prefetch (PECmd) 566 567 **Scenario:** Confirm program execution using multiple artefacts. 568 569 ```powershell 570 # Step 1: Extract prefetch with PECmd 571 PECmd.exe -d C:\Cases\MyCase\Evidence\Prefetch --csv C:\Cases\MyCase\Output\CSV --csvf Prefetch.csv 572 573 # Step 2: Extract BAM/DAM from SYSTEM hive 574 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "ControlSet001\Services\bam\State\UserSettings" --csv C:\Cases\MyCase\Output\CSV --csvf BAM.csv 575 576 # Step 3: Extract ShimCache from SYSTEM hive 577 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "ControlSet001\Control\Session Manager\AppCompatCache" --csv C:\Cases\MyCase\Output\CSV --csvf ShimCache.csv 578 579 # Step 4: Extract UserAssist from NTUSER.DAT 580 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\NTUSER.DAT --kn "Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist" --csv C:\Cases\MyCase\Output\CSV --csvf UserAssist.csv 581 ``` 582 583 **Step 5: Correlate in Timeline Explorer** 584 585 | Artefact | Evidence Type | Timestamp Meaning | Correlation Key | 586 |---------|---------------|-------------------|----------------| 587 | **Prefetch** | Execution | Last 8 run times | `ExecutableName` | 588 | **BAM/DAM** | Execution | Last execution time (per user SID) | Full path + SID | 589 | **ShimCache** | File existence | File modified time (NOT execution) | Full path | 590 | **UserAssist** | Execution (GUI apps) | Last execution time + run count | Executable name (ROT13 decoded) | 591 592 Cross-referencing ShimCache (file created/modified), BAM (execution + SID), Prefetch (execution + run count), and UserAssist (execution + run count) around the same timestamp yields strong corroboration of execution by a specific user. 593 594 --- 595 596 ## Part 6: Custom Batch File Creation 597 598 ### USB-Only Batch File 599 600 Create `USB_Triage.reb`: 601 602 ```yaml 603 Description: USB device history extraction 604 Author: YourName 605 Version: 1.0 606 Id: USB_Triage_001 607 Keys: 608 - Description: USB storage devices 609 HiveType: SYSTEM 610 Category: Devices 611 KeyPath: ControlSet001\Enum\USBSTOR 612 Recursive: true 613 Comment: "VID, PID, serial number, FriendlyName" 614 615 - Description: All USB devices 616 HiveType: SYSTEM 617 Category: Devices 618 KeyPath: ControlSet001\Enum\USB 619 Recursive: true 620 Comment: "Includes non-storage USB devices" 621 622 - Description: Mounted devices 623 HiveType: SYSTEM 624 Category: Devices 625 KeyPath: MountedDevices 626 Recursive: false 627 Comment: "Drive letter to device mapping" 628 ``` 629 630 ```powershell 631 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --bn USB_Triage.reb --csv C:\Cases\MyCase\Output\CSV --csvf USB.csv 632 ``` 633 634 --- 635 636 ### Persistence-Only Batch File 637 638 Create `Persistence_Triage.reb`: 639 640 ```yaml 641 Description: Persistence triage (Run keys + Services) 642 Author: YourName 643 Version: 1.0 644 Id: Persistence_Triage_001 645 Keys: 646 - Description: Run keys (machine) 647 HiveType: SOFTWARE 648 Category: Persistence 649 KeyPath: Microsoft\Windows\CurrentVersion\Run 650 Recursive: false 651 652 - Description: RunOnce keys (machine) 653 HiveType: SOFTWARE 654 Category: Persistence 655 KeyPath: Microsoft\Windows\CurrentVersion\RunOnce 656 Recursive: false 657 658 - Description: Run keys (user) 659 HiveType: NTUSER 660 Category: Persistence 661 KeyPath: Software\Microsoft\Windows\CurrentVersion\Run 662 Recursive: false 663 664 - Description: Services 665 HiveType: SYSTEM 666 Category: Persistence 667 KeyPath: ControlSet001\Services 668 Recursive: true 669 Comment: "Check ImagePath for unusual binaries" 670 ``` 671 672 ```powershell 673 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --bn Persistence_Triage.reb --csv C:\Cases\MyCase\Output\CSV --csvf Persistence_Quick.csv 674 ``` 675 676 --- 677 678 ## Part 7: Final Checklist 679 680 **Pre-Analysis:** 681 - [ ] RECmd.exe version verified (run `RECmd.exe` with no args) 682 - [ ] Batch files updated (`RECmd.exe --sync`) 683 - [ ] Hive files copied to evidence folder 684 - [ ] Transaction logs (`.LOG1`, `.LOG2`) present alongside hives 685 - [ ] Output directory created 686 687 **Triage Execution:** 688 - [ ] Run DFIRBatch against all hives 689 - [ ] Open CSV in Timeline Explorer 690 - [ ] Filter by Category: Program Execution, Persistence, User Activity, Devices 691 - [ ] Export high-priority findings to report 692 693 **Deep Dive:** 694 - [ ] SAM: User accounts, logon times, RIDs 695 - [ ] SECURITY: Audit policies (limited offline value) 696 - [ ] SOFTWARE: OS info, Run keys, ProfileList, installed software 697 - [ ] SYSTEM: USB devices, ShimCache, BAM/DAM, services, timezone 698 - [ ] NTUSER.DAT: UserAssist, RecentDocs, ShellBags, searches, typed paths 699 700 **Recovery & Correlation:** 701 - [ ] Verify transaction logs replayed (`--nl false`) 702 - [ ] Recover deleted keys/values (`--recover true`) 703 - [ ] Search slack space for deleted data (`--ss`) 704 - [ ] Parse VSS snapshots if available (`--vss`) 705 - [ ] Correlate with PECmd prefetch output 706 - [ ] Build execution timeline (Prefetch + BAM/DAM + UserAssist + ShimCache) 707 708 **Quality Assurance:** 709 - [ ] CSV row counts reasonable (not empty) 710 - [ ] Timestamps in expected range (not year 1601 or 9999) 711 - [ ] Timezone verified (SYSTEM\TimeZoneInformation) 712 - [ ] Multiple NTUSER.DAT files processed (multi-user systems) 713 - [ ] BAM/DAM SIDs mapped to usernames (via ProfileList) 714 715 --- 716 717 ## Quick Command Summary 718 719 ```powershell 720 # TRIAGE: All hives, DFIRBatch, UK timestamps 721 RECmd.exe -d <HIVES_DIR> --bn BatchExamples\DFIRBatch.reb --csv <OUT_DIR> --csvf Triage.csv --q --dt "dd/MM/yyyy HH:mm:ss" 722 723 # SINGLE HIVE: SOFTWARE example 724 RECmd.exe -f <HIVES_DIR>\SOFTWARE --csv <OUT_DIR> --csvf SOFTWARE.csv --dt "dd/MM/yyyy HH:mm:ss" 725 726 # PERSISTENCE: RegistryASEPs batch 727 RECmd.exe -d <HIVES_DIR> --bn BatchExamples\RegistryASEPs.reb --csv <OUT_DIR> --csvf Persistence.csv 728 729 # USB DEVICES: Extract from SYSTEM 730 RECmd.exe -f <HIVES_DIR>\SYSTEM --kn "ControlSet001\Enum\USBSTOR" --csv <OUT_DIR> --csvf USB.csv 731 732 # BAM EXECUTION: Extract from SYSTEM (Win10 1709+) 733 RECmd.exe -f <HIVES_DIR>\SYSTEM --kn "ControlSet001\Services\bam\State\UserSettings" --csv <OUT_DIR> --csvf BAM.csv 734 735 # USERASSIST: Extract from NTUSER.DAT 736 RECmd.exe -f <HIVES_DIR>\NTUSER.DAT --kn "Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist" --csv <OUT_DIR> --csvf UserAssist.csv 737 738 # SEARCH: Keyword across all hives 739 RECmd.exe -d <HIVES_DIR> --sd "malware.exe" --csv <OUT_DIR> --csvf Search.csv 740 741 # RECOVERY: Clean dirty hive with transaction logs 742 RECmd.exe -f <HIVES_DIR>\SYSTEM --nl false --recover true --csv <OUT_DIR> --csvf SYSTEM_recovered.csv 743 744 # RLA: Create clean hive from transaction logs 745 RLA.exe -f <HIVES_DIR>\SYSTEM --out <HIVES_DIR>\Clean 746 ``` 747 748 **Sources:** 749 - RECmd GitHub: https://github.com/EricZimmerman/RECmd 750 - Eric Zimmerman Tools: https://ericzimmerman.github.io/ 751 - SANS Windows Forensics Poster: https://www.sans.org/posters/windows-forensic-analysis/