Meta tags:
Headings (most frequently used words):
esentutl, exe, dfir, on, log, get, ps1, you, follow, us, observations, additional, and, installation, the, mountain, rdp, event, locked, file, access, using, installing, volatility, windows, more, automation, zimmermantools, start, imageparsing, long, distance, runner, what, standin, there, for, recent, posts, prior, current, sources, closing, ese, database, files, uses, of, final, thoughts, execution, so, how, do, started,
Text of the page (most frequently used words):
the (261), and (107), this (73), you (59), that (55), for (41), are (38), #windows (32), file (29), can (29), script (29), event (26), with (23), from (23), files (23), not (23), exe (22), will (22), have (21), was (21), log (20), tools (20), but (19), there (19), rdp (18), these (18), using (17), any (17), install (17), get (16), like (16), ps1 (16), volatility (16), powershell (16), also (15), which (15), run (15), when (15), start (13), other (13), need (13), use (13), download (13), com (12), what (12), github (12), option (12), logged (12), esentutl (11), 2018 (11), see (11), shadow (11), copy (11), dfir (10), imageparsing (10), more (10), out (10), image (10), each (10), volume (10), save (10), some (10), one (10), https (10), logs (10), running (9), into (9), folder (9), copies (9), location (9), python (9), database (9), dat (9), login (9), 1149 (9), blog (8), october (8), great (8), really (8), way (8), while (8), output (8), tool (8), command (8), type (8), against (8), hindsight (8), mount (8), only (8), following (8), history (8), profiles (8), options (8), vss (8), webcachev01 (8), authentication (8), access (7), recent (7), here (7), them (7), cases (7), your (7), just (7), same (7), about (7), two (7), mounted (7), used (7), parsing (7), arsenal (7), default (7), doesn (7), all (7), versions (7), select (7), right (7), open (7), data (7), good (7), during (7), operating (7), started (6), comment (6), zimmermantools (6), uncategorized (6), mike (6), cary (6), artifacts (6), how (6), they (6), know (6), had (6), before (6), forensics (6), post (6), then (6), vsc (6), additional (6), note (6), line (6), has (6), sift (6), currently (6), issue (6), path (6), allows (6), allow (6), done (6), system (6), eric (6), available (6), sans (6), source (6), being (6), prior (6), systems (6), testing (6), ese (6), vssrec (6), successful (6), comments (5), mountain (5), now (5), free (5), locked (5), find (5), scripts (5), most (5), well (5), let (5), work (5), couple (5), found (5), should (5), process (5), browsinghistoryview (5), example (5), ftk (5), switch (5), zimmerman (5), even (5), got (5), chrome (5), sure (5), extract (5), saved (5), click (5), set (5), forensic (5), does (5), edge (5), course (5), featured (5), installation (5), dependencies (5), pip (5), previous (5), server (5), nla (5), connection (5), connecting (5), failed (5), wordpress (4), name (4), installing (4), new (4), few (4), feel (4), think (4), may (4), still (4), want (4), who (4), been (4), doing (4), things (4), minutes (4), thanks (4), update (4), point (4), display (4), able (4), user (4), both (4), above (4), don (4), parameter (4), directory (4), mft (4), without (4), another (4), make (4), execution (4), internet (4), did (4), executionpolicy (4), program (4), installed (4), investigation (4), leave (4), memory (4), commands (4), compiled (4), pycrypto (4), transaction (4), written (4), later (4), connections (4), operational (4), required (3), write (3), content (3), account (3), follow (3), entry (3), once (3), various (3), job (3), created (3), over (3), months (3), anything (3), always (3), than (3), reading (3), last (3), love (3), would (3), lot (3), those (3), recently (3), detail (3), vscs (3), listed (3), seen (3), important (3), looking (3), help (3), built (3), images (3), dblake (3), hindsightpath (3), nirsoft (3), executes (3), parameters (3), change (3), workstation (3), network (3), method (3), shellbags (3), points (3), vscmount (3), grab (3), parse (3), changes (3), executable (3), familiar (3), execute (3), unblock (3), policy (3), remotesigned (3), prompt (3), browser (3), issues (3), setup (3), etc (3), very (3), working (3), below (3), provide (3), latest (3), several (3), vol (3), org (3), error (3), where (3), page (3), www (3), releases (3), require (3), provides (3), copying (3), databases (3), force (3), attempts (3), client (3), enabled (3), terminalservices (3), remoteconnectionmanager (3), logon (3), security (3), host (3), device (3), occurs (3), observed (3), desktop (3), logins (3), followed (3), 4624 (3), site (2), website (2), sign (2), subscribed (2), subscribe (2), already (2), create (2), automation (2), minute (2), least (2), entries (2), along (2), discuss (2), daily (2), workflow (2), reach (2), pretty (2), common (2), else (2), world (2), stuff (2), share (2), others (2), useful (2), year (2), never (2), blogged (2), principle (2), community (2), seems (2), people (2), ideas (2), field (2), part (2), getting (2), applies (2), put (2), won (2), his (2), suggestions (2), questions (2), hopefully (2), next (2), add (2), contains (2), subdirectory (2), parsed (2), navigate (2), structure (2), explorer (2), though (2), their (2), sbecmd (2), root (2), examples (2), better (2), off (2), needed (2), imagepath (2), outpath (2), toolpath (2), nirsoftpath (2), specified (2), locations (2), launch (2), administrator (2), imager (2), detect (2), mounting (2), missing (2), causes (2), ability (2), manually (2), its (2), lose (2), capability (2), dirty (2), downside (2), certain (2), give (2), temporary (2), anywhere (2), different (2), edit (2), aren (2), first (2), properties (2), local (2), grayfold3d (2), posh (2), triage (2), notes (2), profile (2), keep (2), mind (2), earlier (2), downloaded (2), shortly (2), automates (2), ago (2), time (2), applications (2), firefox (2), present (2), information (2), identify (2), multiple (2), little (2), particularly (2), covered (2), check (2), hives (2), take (2), addition (2), easy (2), feedback (2), console (2), entering (2), outdir (2), specify (2), either (2), might (2), helpful (2), richard (2), 13cubed (2), channel (2), ran (2), cause (2), away (2), syntax (2), cheat (2), sheet (2), digital (2), pdf (2), info (2), gives (2), links (2), binary (2), ujson (2), binaries (2), openpyxl (2), dropbox (2), link (2), case (2), microsoft (2), compiler (2), code (2), plugins (2), details (2), look (2), functionality (2), contain (2), build (2), builds (2), uses (2), structures (2), between (2), december (2), final (2), thoughts (2), investigations (2), teams (2), activity (2), auditing (2), because (2), potential (2), flushed (2), could (2), replay (2), immediately (2), copied (2), much (2), thought (2), disabled (2), admin (2), 1803 (2), win (2), 2016 (2), performing (2), dump (2), limited (2), 2019 (2), brute (2), connect (2), 1158 (2), level (2), credentials (2), after (2), series (2), discovered (2), established (2), previously (2), unfortunately (2), sources (2), observations (2), 4625 (2), events (2), whether (2), successfully (2), spot (2), non (2), rfc (2), 1918 (2), address (2), exposed (2), remote (2), home (2), design, email, loading, collapse, bar, manage, subscriptions, view, reader, report, privacy, posts, planning, putting, something, month, expect, highlighting, presenting, enjoy, including, past, helped, peaks, interest, imposter, syndrome, across, technology, fields, tend, everyone, knows, many, anyone, probably, far, experience, around, years, infrastructure, switching, position, man, mean, maybe, rest, participation, inequality, based, small, percentage, contributors, true, contributing, sharing, takes, place, ask, prominent, bloggers, instructors, tips, theme, advice, incident, response, phil, moore, operates, thisweekin4n6, thinkdfir, extolling, merits, stood, encouraged, move, forward, long, distance, runner, standin, progress, hoping, regripper, parsers, combine, dedupe, primary, imageparsing_detailed, streams, imageparsing_commands, arguments, executed, artifact, processed_vsc, mounted_vsc_, perform, actions, completely, individual, respective, exceptions, screenshot, organized, review, drive, explicitly, stating, our, stated, setting, saves, forces, since, caveats, attempt, alert, due, recognizing, reparse, loop, endlessly, excluded, detects, unc, offer, automatically, pick, typically, own, mftecmd, works, hive, bypassed, holding, shift, down, mounter, favorite, extracting, harlan, carvey, contents, ise, modify, signed, unblocked, typing, located, dist, parses, chocolatey, places, recommendation, show, ericzimmerman, awesome, led, runs, big, saver, released, mounts, updated, added, outstanding, shows, simplicity, quickly, areas, focus, application, entire, consuming, tries, commercial, coverage, definitely, mix, gui, shell, items, registry, master, table, plan, cover, future, for500, enjoyed, training, took, ondemand, soak, material, reasonable, pace, labs, apply, topics, headaches, send, message, twitter, alternatively, launched, navigating, alternative, begin, downloading, executing, edited, steps, area, highlighted, desired, prevents, unsigned, wanted, discussed, requirements, must, realized, extraction, pain, together, automate, ensure, week, hope, finally, say, davis, youtube, ton, videos, covers, kali, linux, watched, knew, him, interested, video, resource, media, newer, dependency, imaging, library, pil, graphics, unable, wasn, chose, indicating, installer, too, sketchy, selecting, installers, py2, umip8ndplytwzj1, aaddlrsrpjl1cm1vpvaxc5jza, lst, yara, easiest, stopped, posting, visual, gdabah, distorm, distorm3, extracted, archive, support, enable, shown, utilize, instructions, highly, recommend, explains, verify, release, numbers, 15063, 16299, 17134, 17763, volatilityfoundation, handle, differences, significant, enough, fail, return, incomplete, unreadable, results, trying, analyze, dumps, value, red, sam, ntds, dit, introducing, outside, blue, creation, turns, ntuser, 2015, double, edged, sword, deleted, records, yet, purged, concern, article, ins, outs, exports, v01, miss, under, scenarios, happen, opened, navigated, contained, directly, simple, terms, instead, ram, says, possibly, potentially, documentation, esedatabaseview, browsing, leading, initially, grabbing, isn, service, backup, snapshot, talk, strike, received, taking, distinctions, sounds, try, extensible, storage, engine, maintenance, operations, such, wondering, export, interesting, solution, collect, live, processes, utilities, stored, cannot, native, cmdlets, xcopy, item, robocopy, february, lookout, configurations, tip, editing, notepad, text, editior, paste, enablecredsspsupport, closing, devices, generate, touched, discussing, recorded, requires, authenticate, tell, screen, attacker, accounts, domain, performed, timeline, identifying, remotedesktopservices, rdpcorets, 131, associated, exist, sbs, 2011, 2008, version, 2012, reviewing, please, accounted, tested, noticed, unsuccessful, succeeded, 261, attempting, current, failures, localsessionmanager, observe, reconnects, securitycatnip, catching, original, varied, depending, session, reconnected, occurring, soon, entered, interpretation, indicated, connected, made, valuable, gave, means, mentioned, presence, indicator, indicate, occurred, downloads, rdp_flowchart, ponderthebits, related, identification, tracking, refer, whenever, refresher, logging, explaining, gets, stages, logoff, disconnect, reconnect, involving, behavior, search, contrary, documented, blogs, days, pass, detection, technique, scan, port, forwarding, users, contact, menu, skip,
Text of the page (random words):
in the original post event id 21 and 22 new connections are logged in the terminalservices localsessionmanager operational log for failed logins event id 1149 would be followed by event id 4625 in the windows security log an important point is that event id 4625 for login failures is not logged by default in desktop operating systems like windows 7 8 recent versions of win 10 have these enabled by default current observations during a recent investigation i noticed that event id 1149 was not being logged when the login was unsuccessful this was observed when connecting to a windows 10 device if the login succeeded the 1149 event was logged as seen previously in both cases event id 261 is logged in the ts remoteconnectionmanager operational log but unfortunately this doesn t give us any information on who was attempting to connect after performing some additional testing and reviewing notes from previous cases i ve found the following please note not all operating systems or os versions are accounted for here as i tested what i had available event id 1149 was not logged prior to successful authentication and only occurs if authentication is successful on the following operating systems windows server 2012 windows server 2016 windows 7 windows 8 1 windows 10 version 1803 event id 1149 was logged prior to successful authentication on the following operating systems windows server 2008 windows sbs server 2011 additional log sources i performed a timeline of the event logs after a series of failed and successful rdp connections to see if anything else was logged that might be helpful in identifying failed rdp login attempts i discovered that the remotedesktopservices rdpcorets operational log does log event id 131 when the rdp connection is first established this occurs prior to authentication like event id 1149 did previously and while there is no workstation name or user account associated with this log entry it does provide the connecting ip unfortunately this log channel does not exist in windows 7 i touched on network level authentication above when discussing the logon type field recorded in the security log nla requires the client to authenticate before connecting to the host an easy way to tell if nla is disabled is that when connecting to a host you see the login screen of that device before entering credentials this allows an attacker to see who is currently logged in other user accounts on the pc and the domain name nla really should be enabled on most devices but if it is not you can find an additional event in the terminalservices remoteconnectionmanager admin log event id 1158 will also display the source ip while this log is available in windows 7 i was not able to generate event id 1158 when connecting to a windows 7 pc without nla closing one final tip if you re doing any rdp testing and want to force your client to connect without nla you can do so by editing the rdp connection file to do so save the rdp file and open it in notepad or another text editior paste the following line anywhere in the file enablecredsspsupport i 0 if you ve got any feedback feel free to share i m still on the lookout for a good way to identify brute force rdp attempts on default windows 7 configurations so if you ve got any thoughts on that let me know mike cary uncategorized 1 comment february 15 2019 may 14 2019 4 minutes featured locked file access using esentutl exe i m currently working on a solution to collect files off a live system to be used during some ir processes i won t go into any great detail but i m limited to only using built in windows utilities i need access to browser history data and while chrome and firefox allow copying of the history files the webcachev01 dat file that ie and edge history are stored in is a locked file and cannot be copied using native copy commands cmdlets like xcopy copy item robocopy etc ese database files and esentutl exe the webcachev01 dat file is an ese extensible storage engine database file and there is a built in tool for performing maintenance operations on such files esentutl exe i started wondering if i could use this tool to export the database or at least dump the history running esentutl exe from a command prompt we see two interesting options m to dump a file and y to copy a file copying the file sounds great to me let s try esentutl exe y webcachev01 dat d c path to save webcachev01 dat strike 1 that gives us the same file is being used error that i received with other copy commands ok so taking another look at the copy options i see the vss and vssrec options a couple of important distinctions here i am running windows 10 build 1803 the vss and vssrec options are only available on win 10 and server 2016 or later the vss and vssrec options require you to be running as an admin the vss option copies a snapshot of the file does not replay the logs we ll talk a little more about the transaction logs later but let s go with the vss option for now ok that s much better if i open up the webcachev01 dat file in esedatabaseview or browsinghistoryview i see browsing history leading up to my testing initially i thought it was grabbing a copy of the file from a previous volume shadow copy vsc but that isn t the case esentutl exe is able to use the volume shadow copy service to make a backup of a locked file this can be done even if vscs are disabled on the system what about the vssrec option data is not written directly to the database file in simple terms data is instead written to ram and then to transaction logs before being flushed into the database file microsoft s documentation says the data can be written to the database file later possibly immediately potentially much later i did some testing with this and i m not sure under what scenarios this doesn t happen right away i opened up edge and navigated to a new page then immediately copied the webcachev01 dat file while edge was still open and it contained this new entry just keep in mind that when using the vss option only we have the potential to miss entries that have not been written to the database using the vssrec option will replay these transaction logs this is the syntax used esentutl exe y c path to webcachev01 dat vssrec v01 d c exports webcachev01 dat this can be a double edged sword though because you also have the potential to lose deleted records that have yet to be purged from the database once the logs are flushed if this is a concern you could go with both options and just save two copies of the file this article from sans provides more details on the ins and outs of ese databases and transaction logs https digital forensics sans org blog 2015 06 03 ese databases are dirty additional uses of esentutl exe so we know we can use esentutl exe to copy ese database files but what about other locked files well it turns out you can in this example i grab a copy of the ntuser dat file for the currently logged in account i really like this as an option for copying system files when doing investigations or even testing i m sure it has value to red teams as well as it allows you to grab other hives like the sam and other ese databases like ntds dit without introducing outside tools or using powershell blue teams can detect this type of activity by auditing process creation and looking for activity by esentutl exe particularly with the vss switch final thoughts i m still looking for a good way to get ie edge browser history on the versions of windows that do not have the vss switch so if you ve got any ideas there let me know mike cary uncategorized 6 comments december 6 2018 december 6 2018 3 minutes featured installing volatility on windows i recently had the need to run volatility from a windows operating system and ran into a couple issues when trying to analyze memory dumps from the more recent versions of windows 10 volatility uses profiles to handle differences in data structures between operating systems there are changes in these data structures between some builds of windows 10 that are significant enough to cause certain plugins to fail or return incomplete and unreadable results compiled versions of volatility are available on https www volatilityfoundation org releases these releases contain all the required dependencies and don t require any installation but they don t contain the latest profiles we can verify this if we download and run the compiled windows release with the info switch to display the available profiles those of you that are familiar with windows build numbers will note that we are missing the following builds 15063 16299 17134 and 17763 installation to get the latest profiles we need to install volatility using the source code files these utilize python and will also require some dependencies to be installed for all plugins to work also i d like to point out that while these instructions are for windows the same principle applies to installing on other operating systems for additional details i highly recommend you take a look at the installation page on the volatility github this provides links for all the dependencies and explains what functionality they provide download and install python 2 7 the volatility setup script doesn t currently support python 3 make sure to enable the option to add python to path during the installation as shown below download the volatility source code archive and extract files open a command prompt navigate to the location you extracted the volatility source to and run setup py install if we run vol py h at this point we will get an error indicating that several dependencies are not installed use the links and commands below to install the following dependencies distorm3 download from https github com gdabah distorm releases and run the executable to install pycrypto i had some issues with installing pycrypto the install link on the volatility github for the pycrypto binaries is the easiest install method but it stopped working shortly before this posting i ll leave it up in case it s a temporary issue if not we can use pip to install but will need to install the microsoft c compiler for python 2 7 prior to doing so download and install visual c compiler for python 2 7 from the command line type pip install pycrypto yara https www dropbox com sh umip8ndplytwzj1 aaddlrsrpjl1cm1vpvaxc5jza dl 0 lst i know the dropbox link seems sketchy but that s where the volatility github points to when selecting the option for binary installers there are several options on this page make sure to select one of the py2 7 exe options once downloaded run the executable to install openpyxl there are no compiled windows binaries so we will install by running pip install openpyxl from the command line ujson there is no compiled binary installer for this one either so we will use pip to install here too pip install ujson there is one other dependency listed for volatility which is the python imaging library pil this gives python the ability to process images an graphics i was unable to install this and it wasn t a capability i needed in volatility so i chose to leave it out so that s it now if we run vol py info we can see the newer profiles are listed we can get started with volatility by running vol py h from the command line to see the syntax the sans memory forensics cheat sheet is also a great resource if you need help getting started on memory forensics commands https digital forensics sans org media volatility memory forensics cheat sheet pdf finally i need to say thanks here to richard davis and his 13cubed youtube channel richard has a ton of great videos one of which covers this profile issue on sift workstation and kali linux i watched this several months ago and when i ran into the windows issue i knew the cause right away thanks to him here s the video if you are interested i hope this is helpful and if you have any questions or comments feel free to reach out mike cary uncategorized 4 comments october 29 2018 october 29 2018 3 minutes featured more automation get zimmermantools ps1 just wanted to provide an update on a recent addition to my github in my post last week i discussed the start imageparsing ps1 script which automates the use of various parsing tools against a forensic image one of the requirements in the script is that all of eric zimmerman s tools must be in the same directory i realized this download and extraction might be a pain for people that don t already have the tools so i put together this script to automate things it s also a good way to ensure that you always have the latest versions installed installation and execution download the script from my github and extract files https github com grayfold3d posh triage unblock the file and set the powershell execution policy this allows us to execute powershell scripts but prevents scripts that are either not local to your system or unsigned from running right click script select properties and then unblock file open powershell as administrator and type set executionpolicy executionpolicy remotesigned by default files are saved to c forensic program files zimmerman if you d like them to be saved to a different location you can specify this when executing from the powershell console using the outdir parameter or the script can be edited to set the location using these steps right click get zimmermantools ps1 and select edit change the area highlighted below to your desired folder and save changes right click get zimmermantools ps1 and select run with powershell the script will launch and begin downloading the files alternatively the script can also be launched from the powershell console by navigating to the directory it is saved to and entering get zimmermantools ps1 in this example we use the outdir parameter to specify an alternative location to save the files so that s it hopefully this will save you some headaches as always if you have any feedback or suggestions leave a comment or send me a message on twitter mike cary uncategorized leave a comment october 12 2018 october 12 2018 1 minute featured start imageparsing ps1 earlier this year i was able to take the sans for500 course i ve really never enjoyed any training more i took the ondemand course which i think allows you to soak up the material at a reasonable pace in addition to the course labs i found it very easy to apply the topics being covered to my daily work for most of the artifacts covered in the course sans tries to present one commercial tool and one open source tool that can be used to process the data the tools by eric zimmerman get a lot of coverage in this course if you aren t familiar with these you should definitely check out eric s blog there is a good mix of gui and command line applications which allow you to parse things like shell items registry hives the master file table mft and even mount volume shadow copies i plan to cover these in more detail and discuss how i use them in my workflow in a future blog post i r...
|