Windows SRUM Forensics

  Рет қаралды 21,932

13Cubed

13Cubed

Күн бұрын

Пікірлер
@user-good_day_
@user-good_day_ 6 жыл бұрын
Thank you for greate SRUM tutorial
@glassfrog3
@glassfrog3 7 жыл бұрын
Thanks Richard for another great video. This is an artefact I wasn't actually familiar with so your explanations are very helpful! I will definitely take your advice and do some further research, thanks for the links
@mdyousufuddin
@mdyousufuddin 3 жыл бұрын
It was very useful. Excellent. Any video on Windows Sandbox Forensics
@13Cubed
@13Cubed 3 жыл бұрын
Not yet - but that's on my suggestion list.
@jamiekomodo1751
@jamiekomodo1751 4 жыл бұрын
OK video for general procedure. I have to say, though, that I can't see what is being typed in those dark screens with small fonts, and I'm on a desktop too -- not mobile device. I know I can just review the tools command line, but if you're going to be making demo videos and you have a high resolution screen, you might want to zoom in or make cmd window large enough to see. Just a suggestion.
@13Cubed
@13Cubed 4 жыл бұрын
This is a very old episode. You'll find that the production quality has greatly increased for newer ones.
@CM-tw2oj
@CM-tw2oj 2 жыл бұрын
Change video res to HD and this issue is fixed.
@zelenko2064
@zelenko2064 4 жыл бұрын
how did you manage to put these files like "SAM" or "SYSTEM" please
@sean7949
@sean7949 3 жыл бұрын
FTK Imager
@samjohn1098
@samjohn1098 2 жыл бұрын
Nice one, quick question how do we identify to which IP or Domain name the nc.exe moved the data ?
@13Cubed
@13Cubed 2 жыл бұрын
You'd have to grab that information from netstat, and match up the PID of the nc.exe process (assuming it's active at the time). Or, you could potentially extract that information from a memory capture of the machine with a Volatility plugin like netscan.
@TheMindfulEdge1
@TheMindfulEdge1 2 жыл бұрын
How do you convert the BytesOutBound to more readable format. e.g. Mb, Gb ?
@13Cubed
@13Cubed 2 жыл бұрын
You could apply an Excel formula to divide the bytes by 1,048,576. This would convert it to MB, as that's the exact number of bytes in a megabyte.
@0Trance0
@0Trance0 Жыл бұрын
Any idea what foreground CPU time is in? Is that seconds ?!?
@13Cubed
@13Cubed Жыл бұрын
It's milliseconds (ms), as I recall.
@matteov.7072
@matteov.7072 6 жыл бұрын
Hi I use Windows 10, can you Explain to me why in all sheets my User SID are NONE?
@mouadzehari1724
@mouadzehari1724 Жыл бұрын
In my case i can simply copy paste the file (tested in Windows 10&11)
@robertboles7418
@robertboles7418 5 жыл бұрын
Nerd alert if you laughed out loud (1/2 point if you snorted,) at this spot. kzbin.info/www/bejne/i6ibn2eVpJJ4iq8 Ok. Ok. Guilty.
@cdielearn3710
@cdielearn3710 Жыл бұрын
its very bad quality and not handy for study
@13Cubed
@13Cubed Жыл бұрын
It's 2.5K QHD resolution with clear audio. Admittedly, the text isn't nearly big enough, but that was an earlier video and I was still learning the process. But, hey, thanks for the feedback!
@AlistairEwingforensic-services
@AlistairEwingforensic-services 7 ай бұрын
V Change the quality using the cog icon numbnuts; don't blame this guy for making free content.
@tunivol6626
@tunivol6626 2 жыл бұрын
i simply used ROBOCOPY to copy the file with the /B specified .
@13Cubed
@13Cubed 2 жыл бұрын
Interesting -- I had not tried that. Thanks for sharing!
Windows MACB Timestamps (NTFS Forensics)
28:09
13Cubed
Рет қаралды 28 М.
NTFS Journal Forensics
14:21
13Cubed
Рет қаралды 20 М.
Мен атып көрмегенмін ! | Qalam | 5 серия
25:41
Chain Game Strong ⛓️
00:21
Anwar Jibawi
Рет қаралды 41 МЛН
Quando eu quero Sushi (sem desperdiçar) 🍣
00:26
Los Wagners
Рет қаралды 15 МЛН
Introduction to Memory Forensics
23:24
13Cubed
Рет қаралды 78 М.
SANS How To's: SRUM-DUMP (System Resource Utilization Monitor) Tool
11:47
SANS Offensive Operations
Рет қаралды 2,4 М.
User Access Logging (UAL) Forensics
16:59
13Cubed
Рет қаралды 9 М.
Introduction to USB Detective
17:43
13Cubed
Рет қаралды 12 М.
Windows NTFS Index Attributes ($I30 Files)
13:14
13Cubed
Рет қаралды 21 М.
How to Crack Software (Reverse Engineering)
16:16
Eric Parker
Рет қаралды 824 М.
A File's Life - File Deletion and Recovery
30:26
13Cubed
Рет қаралды 7 М.
Linux File System/Structure Explained!
15:59
DorianDotSlash
Рет қаралды 4,3 МЛН
Introduction to Memory Forensics with Volatility 3
32:00
DFIRScience
Рет қаралды 71 М.
ShellBag Forensics
14:08
13Cubed
Рет қаралды 30 М.
Таким раствором работать одно удовольствие
1:00
Профессия созидатели
Рет қаралды 954 М.
Массаж головы пранк🤣
0:55
Kirya Kolesnikov
Рет қаралды 5 МЛН
DESAFIO DOS COPOS #shorts
0:38
Natan por Aí
Рет қаралды 34 МЛН