Windows 痕迹与事件日志取证
面向 Windows 主机痕迹分析,主要使用 Eric Zimmerman 系列工具处理 Prefetch、Shimcache、Amcache、MFT、USN Journal、注册表、Shellbags、LNK、Jump Lists、SRUM、浏览器数据库和 EVTX 日志,并结合 Autoruns/ASEP 对服务、驱动、计划任务和自启动项进行持久化排查。适合判断程序执行、文件变化、用户活动、登录认证及攻击链行为,并通过多类痕迹相互印证提高结论可靠性。
在 AI 中使用此 Skill将本页链接复制给 AI,即可让 AI 获取完整 Skill 内容并按此执行
安全提示: 本站 Skill 均经 ChatGPT 最新模型扫描,未发现恶意脚本及危险指令、未检出已知恶意行为特征,但不保证绝对安全,使用即表示接受此风险
Skill 文件
版本 20260324 · 7b336fd6a06d2297863ce1339c33e7e1
SKILL.md
--- name: windows-artifacts description: Analyze Windows forensic artifacts on SANS SIFT with Eric Zimmerman tools, Autoruns data, registry hives, MFT and USN Journal, Prefetch, Amcache, Shimcache, Shellbags, LNK/Jump Lists, SRUM, browser databases, and Windows event logs. --- # Windows Artifact Analysis Use this skill for host-based Windows artifact analysis on SANS SIFT. It focuses on execution evidence, persistence, account activity, filesystem changes, user interaction and event-log correlation. Keep exported evidence read-only and use UTC for cross-source timeline work. ## Eric Zimmerman tools on SIFT The command-line EZ Tools are commonly installed under `/opt/zimmermantools/` and invoked through the .NET runtime. Use the installed `.dll` on Linux rather than the Windows `.exe` counterpart. Typical tools include: - `PECmd` — Prefetch - `AppCompatCacheParser` — Shimcache/AppCompatCache - `AmcacheParser` — Amcache - `MFTECmd` — `$MFT` and `$UsnJrnl:$J` - `RECmd` — registry parsing and batch queries - `SBECmd` — Shellbags - `JLECmd` — Jump Lists - `LECmd` — LNK files - `SrumECmd` — SRUM - `EvtxECmd` — Windows event logs - `SQLECmd` — supported SQLite application artifacts - `RBCmd` — Recycle Bin GUI-only tools should be handled on a compatible Windows analysis system or under a supported compatibility layer; do not assume every EZ utility runs natively on Linux. ## Execution evidence ### Prefetch ```bash dotnet /opt/zimmermantools/PECmd.dll -d ./exports/prefetch/ --csv ./exports/prefetch/ --csvf prefetch_parsed.csv ``` Prefetch can corroborate program execution and provide run timestamps and referenced files. Absence is not proof of non-execution, especially on systems where Prefetch is disabled. ### Shimcache / AppCompatCache ```bash dotnet /opt/zimmermantools/AppCompatCacheParser.dll -f ./exports/registry/SYSTEM --csv ./exports/shimcache/ ``` On modern Windows, Shimcache is best treated as evidence that a file was present or observed, not as standalone proof that it executed. ### Amcache ```bash dotnet /opt/zimmermantools/AmcacheParser.dll -f ./exports/registry/Amcache.hve --csv ./exports/amcache/ ``` Use file paths, hashes and application metadata as pivots and corroborate timestamps with other artifacts. ## MFT and USN Journal Parse the MFT with all relevant timestamp fields: ```bash dotnet /opt/zimmermantools/MFTECmd.dll -f ./exports/mft/\$MFT --at --csv ./exports/mft/ --csvf mft.csv ``` Parse the NTFS change journal: ```bash dotnet /opt/zimmermantools/MFTECmd.dll -f ./exports/mft/\$J --csv ./exports/mft/ --csvf usnjrnl.csv ``` Use MFT metadata for current and deleted file records; use the USN Journal for create, modify, delete and rename activity. Correlate the two before drawing conclusions about a file's lifecycle. ## Registry analysis Use `RECmd` batch mode for broad triage when the shipped batch files match the question: ```bash dotnet /opt/zimmermantools/RECmd/RECmd.dll \ -d ./exports/registry/ \ --bn /opt/zimmermantools/RECmd/BatchExamples/Kroll_Batch.reb \ --csv ./exports/registry/ \ --csvf registry_batch.csv ``` High-value registry areas include: - Run/RunOnce and service keys for persistence - UserAssist and MRU families for user activity - USB/USBSTOR and MountedDevices for removable-media history - BAM/DAM for execution-related traces - timezone, computer-name and shutdown metadata for context ## Shellbags, Jump Lists and LNK ```bash dotnet /opt/zimmermantools/SBECmd.dll -d ./exports/registry/ --tz UTC --csv ./exports/shellbags/ dotnet /opt/zimmermantools/JLECmd.dll -d ./exports/jumplists/ --csv ./exports/jumplists/ dotnet /opt/zimmermantools/LECmd.dll -d ./exports/lnk/ --csv ./exports/lnk/ ``` These artifacts can reveal folders, local/removable/network targets, volume identifiers and access history even after the target object disappears. ## SRUM and activity databases ```bash dotnet /opt/zimmermantools/SrumECmd.dll -f ./exports/srum/SRUDB.dat -r ./exports/registry/SOFTWARE --csv ./exports/srum/ ``` Use SRUM to correlate application resource and network usage. For Windows activity history databases, parse them with the installed compatible tool and retain the original database for repeatability. ## Browser artifacts Use `SQLECmd` where supported, or work from forensic copies of browser SQLite databases. Preserve `History`, `Cookies`, `Downloads`, `Web Data` and related databases as separate evidence files. If WAL/SHM sidecars exist, copy them with the database before parsing. ## Persistence / ASEP review Autoruns/Autorunsc collections are valuable for services, drivers, scheduled tasks, Run keys, shell extensions, WMI and other auto-start extensibility points. Triage for: - enabled unsigned or unverifiable entries - binaries in user-writable or temporary locations - suspicious or missing image paths - drivers absent from a trusted baseline - scheduled tasks or services launching interpreters or script hosts unexpectedly Do not classify an entry as malicious from signature status alone; validate path, publisher, hash, creation time and related event logs. ## Windows event logs Parse a directory of EVTX files with mapping files when available: ```bash dotnet /opt/zimmermantools/EvtxeCmd/EvtxECmd.dll \ -d ./exports/evtx/ \ --csv ./exports/evtx/parsed/ \ --maps /opt/zimmermantools/EvtxeCmd/Maps/ ``` Useful event families include: - 4624/4625 — successful/failed logon - 4648 — explicit credentials - 4672 — privileged logon - 4688 — process creation - 4698/4702 — scheduled task creation/update - 4720/4726 — account creation/deletion - 4768/4769/4771/4776 — Kerberos/NTLM authentication - 4103/4104 — PowerShell module/script-block logging - 1149 — RDP authentication - 1116/1117 — Defender detection/action - 7045 — service installation Interpret event IDs in context: log source, audit policy, host role, logon type, account, source IP and surrounding events matter. ## Correlation method 1. Establish host timezone and collection window. 2. Parse MFT/USN and core registry hives. 3. Add Prefetch, Amcache and Shimcache execution evidence. 4. Add user-interaction artifacts such as Shellbags, LNK and Jump Lists. 5. Parse Security, PowerShell, RDP, Defender, System and Task Scheduler logs. 6. Correlate timestamps, paths, hashes, users, PIDs and source addresses across artifacts. 7. Preserve raw CSV exports separately from filtered analyst views. A high-confidence conclusion should normally be supported by more than one independent artifact class.
此文件不提供内嵌文本预览
请使用左侧文件行末尾的外链图标打开原始文件。
