Hottest Free Downloads - DownloadPipe.com Over 197,000 downloads! Bookmark Now!
DownloadPipe.com - New Downloads Every Minute
 SEARCH:
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Sniffing pagefile and such......

 
   Windows (Home) -> Security Admin RSS
Next:  Security log full, why?  
Author Message
jim

External


Since: Aug 01, 2007
Posts: 49



(Msg. 1) Posted: Sun Oct 14, 2007 2:45 pm
Post subject: Sniffing pagefile and such......
Archived from groups: microsoft>public>windowsxp>security_admin (more info?)

Is there software available that enables you to (1) see where XP tracks for
IE and Windows itself are written and (2) to scan those files for filenames,
readable text and links?

I am doing some minor forensics on an XP PC and I want to know all that I
can about when and where it was last used and what was the last things done
on or by the PC.

Thanks!
Back to top
Login to vote
Steven L Umbach

External


Since: Nov 02, 2005
Posts: 89



(Msg. 2) Posted: Sun Oct 14, 2007 2:45 pm
Post subject: Re: Sniffing pagefile and such...... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Yes there are tools such as from Foundstone at the link below.

http://www.foundstone.com/us/resources-free-tools.asp --- Founstone
forensic tools

Regseeker can also display contents of user index.dat files showing internet
activity.

http://www.hoverdesk.net/freeware.htm --- Regseeker

http://en.wikipedia.org/wiki/Index.dat --- about index.dat

The link below from Microsoft Antivirus Defense-In-Depth shows steps of how
to analyze a computer that is still running for evidence of what has
happened/current state though it is written for a hack attack but much of
the same applies.

http://www.microsoft.com/technet/security/guidance/serversecurity/avdind_4.mspx

You can also use the built in search in XP and search for files
created/modified within a date range and sort the results being sure to
select for hidden files and folders.

Having said that you have to be very careful in doing forensics if for any
legal reason or for proof and follow best practices for "chain of custody"
and no one should do it for legal/proof reasons unless they are highly
trained at it and can take a grilling in court from computer security
experts for the defense. When doing forensics the original hard drive is
typically cloned and then the original hard drive is saved as evidence and
the cloned drive is examined. There is much much more to it than that but
that is a start.

Steve


"jim" <jim DeleteThis @home.net> wrote in message
news:XstQi.3687$m8.3111@bignews8.bellsouth.net...
> Is there software available that enables you to (1) see where XP tracks
> for IE and Windows itself are written and (2) to scan those files for
> filenames, readable text and links?
>
> I am doing some minor forensics on an XP PC and I want to know all that I
> can about when and where it was last used and what was the last things
> done on or by the PC.
>
> Thanks!
>
Back to top
Login to vote
Display posts from previous:   
Related Topics:
pagefile size - looking at http://www.petri.co.il/pagefile_optimization.htm and http://support.microsoft.com/kb/q197379/#appliesto I thought maybe I would increase my pagefile size. However, I saw it was set to Custom and not System Managed. I never did this. Is not..

PageFile.sys - What is that for? It has a very huge in size, more than a GB.

pagefile.sys - Just to confirm, my pagefile.sys file is located at c:\ Can we just delete this file? Thanks

XP pagefile monitor - Doug Knox??? ....doesn't work on my machine. It always behaves like it's running the first time, ie. asking for where to put icons and how to display results.. System is: Asus A8N-VM m/b (BIOS 0506) , Athlon64 3200+ cooled by Thermaltake TR2-M14, ..

XP pagefile & fragmentation - Hello everyone, I had two questions about XP If I manually set the pagefile on c:\ will it lead to less fragmentation than system managed or will it not matter ? and does the pagefile cause fragmenation on the whole volume it's on or just to itself...
       Windows (Home) -> Security Admin All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You can edit your posts in this forum
You can delete your posts in this forum
You can vote in polls in this forum
Categories:
  Windows Forums
 Game Forums
 Linux Forums
 Mac Forums
 PDA Forums
 Mobile Forums
  Top  |  Store  |  RSS Feeds RSS  |  Data Feeds  |  Advertise  |  Submit  |  Bookmark  |  Newsletter  |  Contact