Plainbit에서 작성한 Artifact 관련 문서가 있어 이를 정리하려고 합니다. 글의 전체 내용은 문서를 근거로 작성되었습니다.
IE는 ~ 9 와 10 ~ 이후로 각각의 정보들을 관리하는 경로와 방법이 차이가 난다. 10버전부터 index.dat이 아닌 WebcacheV01.dat (기존 index.dat 구성과 달리ESE Database를 기반으로 구성, 하나의 파일로 통합관리)로 관리한다.
Cache에 관한 정보 (~ IE9)
Website URI / Access Time / Cahce File name / Cache Path
%UserProfile%\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
History에 관한 정보 (~ IE9)
Website URI / Access Time / Visit Count / Web Page title / HTTP Header
%UserProfile%\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
Cookie에 관한 정보 (~ IE9)
Website Domain / Access Time / Cookie Name/Value /Cookie Expire Time / Cookie Created Tim
%UserProfile%\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
Download에 관한 정보 (~ IE9)
Download URI / Download Filename / Download File Local Full Path / Download File Size
%UserProfile%\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\index.dat
Cache / History / Cookie / Download 에 관한 정보 (IE10 ~)
%UserProfile%\AppData\Local\Microsoft\Windows\WebCache\
WebCacheV(01|16|24).dat
Cache에 관한 정보
URI / First Access time / Last Access time / Visit count / Cache [Filename, Path, expire time], HTTP Response Header
%UserProfile%\AppData\Local\Google\Chrome\User Data\Default\Cache
\data_[0-4]
History에 관한 정보
URI / First Access time / Last Access time / Web page title / Visit count / Visit duration time / search keyword
%UserProfile%\AppData\Local\Google\Chrome\User Data\Default\History
Cookie에 관한 정보
URI / Cookie [name,value,last access time] / Secure cookie flag / Httponly Flag / expire flag
%UserProfile%\AppData\Local\Google\Chrome\User Data\Default\Cookies
Download에 관한 정보
Download[URI,Start time, End time, Filename, Path, size]
%UserProfile%\AppData\Local\Google\Chrome\User Data\Default\History
Cache에 관한 정보
URI / Last Access time / Last Modified time / Visit count / Cache [File name,Path,Expire time]
%UserProfile%\AppData\Local\Mozilla\Firefox\Profiles\\cache2\index
History에 관한 정보
URI / Last Access time / Web page title / Visit count / Search keyword
%UserProfile%\AppData\Roaming\Mozilla\Firefox\Profiles\\places.sqlite
Cookie에 관한 정보
URI / Cookie[Name, Create time, Expire time, Last Access time]
%UserProfile%\AppData\Roaming\Mozilla\Firefox\Profiles\\cookies.sqlite
Download에 관한 정보
URI / Download[Start time, End time, Path, File size, Complete flag, File last modified-time at loacl filesystem]
%UserProfile%\AppData\Roaming\Mozilla\Firefox\Profiles\\places.sqlite
종류 : lnk, jumplist, prefetch, recentfilecache, event log, registry, timeline(activity log)
execution time, target volume label, target volume serial number, target file size, target file full path, target drive type, local mac address
Recent: %AppData%\Microsoft\Windows\Recent*.lnk
execution time, execution application, target volume label, target volume serial number, target file size, target file full path, target drive type, local mac address
execution time, open file list, volume serial number
%SystemRoot%\Prefetch*.pf
execution file full path
%SystemRoot%\AppCompat\Programs\RecentFileCache.bcf
Malware full path, Malware Threat name, Malware Detection time
%SystemRoot%\system32\winevt\Logs\MicrosoftWindows-WindowsDefender%4Operational.evtx
Process ID, Process image file full path, parent of current process, process execution time, process permission
%SystemRoot%\system32\winevt\Logs\MicrosoftWindows-Sysmon%4Operational.evt
Service name, Service start/stop time
%SystemRoot%\system32\winevt\Logs\System.evtx
Execution file full path, execution time, execution user name, execution host domain
%SystemRoot%\system32\winevt\Logs\Security.evtx
Execution File full path, execution count, execution time
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist{}\Count
Execution file name, Execution order
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
lnk file name, execution order
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
해당 자료는 plainbit에서 작성한 PDF를 근거로 작성되었습니다.