Escolar Documentos
Profissional Documentos
Cultura Documentos
Computacional no
Sistema Operacional
RicardoKlberMartinsGalvo
www.ricardokleber.com
ricardokleber@ricardokleber.com
@ricardokleber
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
A nova cara do sistema Desktop da Microsoft
Motivao:
- Alm da esttica o que mudou
(estruturalmente)?
- Tcnicas e ferramentas convencionais
so suficientes para uma percia
(anlise forense computacional)?
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Novidades do Windows 8
Por que isso importante?
http://www.blogmicrosoftbrasil.com.br/windows-8-aos-seis-meses-uma-sessao-de-perguntas-e-respostas-com-tami-reller/
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Novidades do Windows 8
Por que isso importante?
http://www.w3schools.com/browsers/browsers_os.asp
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Forense Computacional
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
- User Interface
- Artifacts
- Registry
- Event Logs
- Recycle Bin
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: User Interface
- User Interface
- Artifacts
- Registry
- Event Logs
- Recycle Bin
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: User Interface
- User Interface
- Artifacts
- Registry
- Event Logs
- Recycle Bin
????
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Artifacts
- User Interface
Local Folder
- Artifacts
- Registry
Metro Apps
Internet Explorer 10
Communication App
- Event Logs
- Recycle Bin
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Artifacts
- User Interface
Local Folder:
- Artifacts
- Registry
- Event Logs
- Recycle Bin
%Root%\Users\%User%\AppData\Local\
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Artifacts
- User Interface
- Artifacts
- Registry
- Event Logs
- Recycle Bin
Microsoft\Windows\Recent\AutomaticDestinations
Microsoft\Windows\Recent\CustomDestinations
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Artifacts
- User Interface
Metro Apps:
- Artifacts
- Registry
- Event Logs
- Recycle Bin
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Artifacts
- User Interface
Metro Apps:
- Artifacts
- Registry
- Event Logs
- Recycle Bin
%Root%\Users\%User%\AppData\Local\Packages\%MetroAppName%\AC\INetCache
%Root%\Users\%User%\AppData\Local\Packages\%MetroAppName%\AC\INetCookies
%Root%\Users\%User%\AppData\Local\Packages\%MetroAppName%\AC\INetHistory
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Artifacts
- User Interface
- Artifacts
- Registry
- Event Logs
- Recycle Bin
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Artifacts
- User Interface
Communication App:
- Artifacts
- Registry
- Event Logs
- Recycle Bin
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Artifacts
- User Interface
Communication App:
- Artifacts
- Registry
- Event Logs
- Recycle Bin
%Root%\Users\%User%\AppData\Local\Packages\
microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache
%Root%\Users\%User%\AppData\Local\Packages\
microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCookies
%Root%\Users\%User%\AppData\Local\Packages\
microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetHistory
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Artifacts
- User Interface
- Artifacts
- Registry
- Event Logs
- Recycle Bin
microsoft.windowscommunicationsapps_8wekyb3d8bbwe\
LocalState\LiveComm\%Rtulo do Endereo WindowsLive do Usurio%\
%Verso do Appn%\DBStore\LogFiles\
edb.log
edb00002.log
edb###.log
edbtmp.log
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Registry
- User Interface
SAM
- Artifacts
- Registry
SYSTEM
- Event Logs
- Recycle Bin
SOFTWARE
SECURITY
COMPONENTS
DRIVERS
Novidade !!!
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Registry
- User Interface
- Artifacts
- Registry
- Event Logs
- Recycle Bin
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Registry
- User Interface
Identificador de UserTile
%System Root%\Windows\System32\Config\SAM
Domains\Account\Users\UserTile
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
- Artifacts
- Registry
- Event Logs
- Recycle Bin
Microsoft Windows 8
Anlise Estrutural :: Registry
- User Interface
- Artifacts
- Registry
- Event Logs
- Recycle Bin
ControlSet001\Control\ComputerName\ComputerName
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Registry
- User Interface
- Artifacts
- Registry
- Event Logs
- Recycle Bin
Impressoras
ControlSet001\Enum\SWD\PRINTENUM\%Id_Impressora%\FriendlyName
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Registry
- User Interface
CurrentBuild
CurrentVersion
EditionID
InstallDate
ProductName
Registered (empresa)
RegisteredOwner (usurio)
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
- Artifacts
- Registry
- Event Logs
- Recycle Bin
Microsoft Windows 8
Anlise Estrutural :: Registry
- User Interface
- Artifacts
- Registry
- Event Logs
- Recycle Bin
%System Root%\Windows\System32\Config\SOFTWARE
Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Registry
- User Interface
- Artifacts
- Registry
- Event Logs
- Recycle Bin
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Outras Estruturas (Registro/Hives) para Anlise
%System Root%\Windows\System32\Config\BBI
- Registry
- Event Logs
- Recycle Bin
{07637a49-713b-4114-8776-585cb1d48193}
(...)
WorkItems
{ff5cb789-f2e6-414c-a221-ac63d644c596}
- Artifacts
Events
- User Interface
(...)
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Outras Estruturas (Registro/Hives) para Anlise
- User Interface
COMPONENTS
- Artifacts
%System Root%\Windows\System32\Config\COMPONENTS
Canonical Data
Catalogs
Deploy
Configuration
Derived Data
Components
VersionedIndex
6.2.9200.16384 (win8_rtm.120725-1247)
Component Families
Installers
Shortcurt
Servicing Stack Versions
ccpinterface
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
- Registry
- Event Logs
- Recycle Bin
Microsoft Windows 8
Outras Estruturas (Registro/Hives) para Anlise
- User Interface
DRIVERS
- Artifacts
%System Root%\Windows\System32\Config\DRIVERS
Driver Database
Device Ids
Driver Files
Driver Inf Files
Driver Package
- Registry
- Event Logs
- Recycle Bin
%System Root%\Windows\System32\Config\ELAM
Windows Defender
Measured
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Event Logs
- User Interface
- Artifacts
%System Root%\Windows\System32\winevt\Logs
- Event Logs
- Recycle Bin
System.evtx
Setup.evtx
Security.evtx
Operational.evtx
- Registry
Application.evtx
HardwareEvents.evtx
*******.evtx
Mudou a localizao
Alterou a extenso (.evt p/ .evtx)
Diversificou
(cada App tem seu log especfico)
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
%System Root%\$Recycle.Bin\%USER_SID%
- Registry
- Event Logs
- Recycle Bin
- Artifacts
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Iso Automount
Suporte a USB3
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Forense Computacional
Estudo de Caso
Colocando a
mo na massa...
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Forense Computacional
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Forense Computacional
R$ 359,00
http://windows.microsoft.com/pt-BR/windows/buy
http://msdn.microsoft.com/windows/apps/br229516/
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Forense Computacional
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Forense Computacional
http://msdn.microsoft.com/pt-br/evalcenter/jj554510.aspx
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Forense Computacional
(thanks DealExtreme)
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Forense Computacional
Processador:
1.66 GHz
Memria RAM: 1 GB
Espao em Disco: 10 GB
350MB
9,5GB
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Forense Computacional
http://www.kali.org
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
# mkdir /media/win8
# mount /imagens/win8_part02.dd /media/win8 -o ro,loop
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Artifacts
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Artifacts
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Artifacts
# hexdump -C 26bfbdac8c66cb7d.automaticDestinations-ms
*
00000d90
00 00 0b 00 00 00 00 00
00 00 00 00 80 3f 13 36
|.............?.6|
00000da0
5c 19 7c 55 ce 01 ff ff
ff ff 14 00 44 00 3a 00
|\.|U........D.:.|
00000db0
5c 00 66 00 6f 00 74 00
6f 00 73 00 5c 00 72 00
|\.f.o.t.o.s.\.r.|
00000dc0
6b 00 5f 00 30 00 30 00
31 00 31 00 2e 00 70 00
|k._.0.0.1.1...p.|
00000dd0
6e 00 67 00 fb 10 c1 4a
8c 3e 1f cc 00 00 00 00
|n.g....J.>......|
00000de0
00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00
|................|
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Artifacts
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Estrutural :: Artifacts
# galleta F3YY0HQJ.txt
Cookie File: F3YY0HQJ.txt
SITE
VARIABLE
VALUE CREATION
TIME
EXPIRE
TIME
FLAGS
c.live.com/
MR
05/20/2013
14:33:32
06/19/2013
14:26:35
1024
c.live.com/
ANONCHK
05/20/2013
14:33:32
05/23/2013
14:26:35
1024
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
# mkdir /root/forense/win8
# cd /media/win8/Windows/System32/config
# cp SAM /root/forense/win8
# cp SYSTEM /root/forense/win8
# cp SOFTWARE /root/forense/win8
# cp SECURITY /root/forense/win8
# cd /media/win8/Users/RICARDO
# cp NTUSER.DAT /root/forense/win8
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
O que usar?
FRED (Forensic Registry EDitor) / FRED Reports
Chntpw
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Install path:
C:\Windows
Source path: n/a
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
RICARDO
RID: 1001 (0x000003E9)
Full name: RICARDO GALVAO
Last login time: n/a
Last pw change: 2013/05/20 17:34:27
Last failed login: n/a
Account expires: 1975/01/22 22:55:33
Total logins: 0
Failed logins: 0
Account flags: NoPwExpiry (528)
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
| ADMIN
| dis/lock |
| 01f5 | Convidado
| dis/lock |
| 03eb | HomeGroupUser$
| 03e9 | RICARDO
| ADMIN
| 03ec | teste_000
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
73 00 63 00 61 00 72 00 64 00 75 00 73 00 6B 00 s.c.a.r.d.u.s.k.
:00010
6C 00 65 00 62 00 73 00 40 00 67 00 6D 00 61 00 l.e.b.s.@.g.m.a.
:00020
69 00 6C 00 2E 00 63 00 6F 00 6D 00
i.l...c.o.m.
tpw
52 00 49 00 43 00 41 00 52 00 44 00 4F 00
R.I.C.A.R.D.O.
47 00 41 00 4C 00 56 00 41 00 4F 00
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
G.A.L.V.A.O.
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Concluses
FRED (Forensic Registry EDitor) / FRED Reports
Chntpw
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
# mkdir /media/win8
# mount /imagens/win8_part02.dd /media/win8 -o ro,loop
# bkhive /media/win8/Windows/System32/config/SYSTEM syskey.txt
# samdump2 /media/win8/Windows/System32/config/SAM syskey.txt > hashes.txt
# john hashes.txt
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Forense Computacional
http://www.moonsols.com/windows-memory-toolkit/
E:\DumpIt.exe
rkwin8-20130420-175441.raw
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Forense Computacional
https://code.google.com/p/volatility
GNU / GPL v2
Python
Suporte a vrios SO's
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Forense Computacional
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Exemplo de Utilizao/Resultados:
Plugin: pslist
# ./vol.py -f rkwin8-20130420-175441.raw --profile=Win8SP0x86 pslist
The Volatility Memory Forensic Framework technology preview (3.0_tp2)
Offset(V)
Name
PID
PPID
Thds
Hnds
Time
232
0x836916c0 cmd.exe
1508
3488
0x83704d00 DumpIt.exe
3840
1508
0x83967040 smss.exe
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Exemplo de Utilizao/Resultados:
Plugin: userassist
# ./vol.py -f rkwin8-20130420-175441.raw --profile=Win8SP0x86 userassist
The Volatility Memory Forensic Framework technology preview (3.0_tp2)
REG_BINARY
%windir%\system32\cmd.exe :
Time Focused:
0:07:34.501000
Last updated:
2013-04-20 17:54:24
0x00000000
00 00 00 00 02 00 00 00 05 00 00 00 71 ed 06 00
............q...
0x00000010
00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf
................
0x00000020
00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf
................
0x00000030
00 00 80 bf 00 00 80 bf ff ff ff ff 50 0f 69 94
............P.i.
0x00000040
c0 73 cc 01 00 00 00 00
.s......
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Exemplo de Utilizao/Resultados:
Plugin: userassist
# ./vol.py -f rkwin8-20130420-175441.raw --profile=Win8SP0x86 userassist
The Volatility Memory Forensic Framework technology preview (3.0_tp2)
REG_BINARY
E:\DumpIt\DumpIt.exe :
Time Focused:
0:01:27.500000
Last updated:
2013-04-20 18:15:43
0x00000000
00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00
................
0x00000010
00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf
................
0x00000020
00 00 80 bf 00 00 80 bf 00 00 80 bf 00 00 80 bf
................
0x00000030
00 00 80 bf 00 00 80 bf ff ff ff ff 00 00 00 00
................
0x00000040
00 00 00 00 00 00 00 00
........
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
kdbgscan
pslist
pstree
psscan
dlllist
dlldump
pedump
handles
getsids
cmdscan
consoles
procinfo
memmap
procexedump
vadinfo
vadwalk
vadtree
vaddump
evtlogs
modules
modscan
moddump
driverscan
filescan
mutantscan
symlinkscan
thrdscan
connections
connscan
sockets
sockscan
netscan
hivescan
hivelist
printkey
hivedump
hashdump
lsadump
userassist
shimcache
getservicesids
crashinfo
hibinfo
imagecopy
raw2dmp
malfind
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
yarascan
svcscan
ldrmodules
impscan
apihooks
idt
gdt
threads
callbacks
driverirp
devicetree
psxview
timers
Microsoft Windows 8
Anlise Forense Computacional
WinPMEM
/usr/share/volatility-3.0-tp2/tools/windows/winpmem
Verso 1.1
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Parcialmente
As que fazem uso de plugins e templates esto em fase de atualizao
A coleta de todas as informaes disponveis necessrias j possvel
(com um pouco de esforo)
Esta apresentao no levou em considerao
solues/ferramentas comerciais e/ou baseadas
no sistema operacional
Microsoft Windows
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Perguntas
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
Microsoft Windows 8
Anlise Forense Computacional
Referncias / Agradecimentos:
NIC/BR / GTS
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber
AnliseForense
Computacionalno
SistemaOperacional
RicardoKlberMartinsGalvo
www.ricardokleber.com
ricardokleber@ricardokleber.com
@ricardokleber
GTS'21AnliseForenseComputacionalnoWindows8::RicardoKlber