windows 8 forensics - sans institute · quick thorough good if you trust the person you are giving...

69
WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

Upload: others

Post on 09-Jan-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

WINDOWS 8

RECOVERY FORENSICS Understanding the Three R’s

W. Kenneth Johnson (@patories)

SANS DFIR SUMMIT 2012

Page 2: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

INTRODUCTION

Who Am I?

MS Student at Iowa State University

IT Security Analyst with Principal Financial Group

Forensic and Malware Researcher

Why are we here?

To understand the forensic impacts of Windows 8 Recovery options

Page 3: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

ISSUES

New System Recovery options with new challenges.

1. Availability

2. Data Recovery

3. Additional Artifacts

Today we will cover the following topics:

1. Recovery options Available

2. Forensic Implications

Page 4: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

TESTING ENVIRONMENT

Windows 8 installed in multiple VM instances

VMWare Workstation 8

FTK Imager

FTK ToolKit

Impact with Bitlocker enabled not tested

Solid State Drives not tested

Page 5: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVERY OPTIONS

System Restore Points

System Refresh Points

System Reset

Page 6: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SYSTEM RESTORE POINTS

What are they?

Page 7: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SYSTEM RESTORE POINT

Relevant Files

Every 7 Days

SRSetRestorePoint API

Page 8: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SYSTEM RESTORE – NEW REG KEYS

HKLM\Software\MS\WindowsNT\CurrentVersion\SystemRestore

SystemRestorePointCreationFrequency

ScopeSnapshots

Page 9: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SYSTEM RESTORE – ISSUES

Dual Boot Systems

Data Retention

Page 10: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SYSTEM REFRESH POINTS

What are they?

Page 11: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SYSTEM REFRESH POINT - PROCESS

Page 12: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SYSTEM REFRESH POINT - DEFAULT

What is Retained What is not Retained

Wireless Network Connections

Mobile Broadband Connections

BitLocker Settings

BitLocker To GO settings

Drive Letter Assignments

Personalization Settings

Metro Style Application

File Type Associations

Display Settings

Windows Firewalls

Desktop Installed Applications

Volume Shadow Copies

Restore Points

Page 13: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SYSTEM REFRESH POINT - CUSTOM

Desktop Applications

Default Refresh Behavior

No Volume Shadow Copies

Page 14: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SYSTEM REFRESH POINT

Default Restore with Install

Multiple

One

Start at Boot Time

Page 15: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SYSTEM REFRESH POINT - CUSTOM

How is it done?

RecImg.exe

ReAgent.exe

Page 16: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

System Refresh Point -

RecImg

Creates Custom Refresh Image

Image Directory can be on a Local,

Removable or Remote Drive.

Set a new current Image

Remove current image and revert back

to default

Shows the current image

Page 17: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

System Refresh Point -

ReAgentC

Where the WinRE is located

Configures if machine will start the

Recovery process at start up

Sets the location of recovery image

Page 18: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SYSTEM RESET

What are they?

Page 19: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SYSTEM RESET - PROCESS

Page 20: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SYSTEM RESET – INITIAL COMMANDS

Page 21: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SYSTEM RESET – INITIAL COMMADS

Page 22: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SYSTEM RESET – DATA WIPE OPTIONS

Quick Thorough

Good if you trust the person

you are giving it to.

Good if you are going to give to

charity.

Both options are not recommended for

cleaning a drive if a multi-pass scrubbing

operation is required!

Page 23: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

DIGITAL FORENSICS

Artifacts and Implications

Page 24: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RESTORE POINT ARTIFACTS

Accessible through multiple options

May contain the following previous versions:

Registry Settings

Documents and files

Applications

FileHistory Configuration

System Events

Page 25: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RESTORE POINTS - GUI

Page 26: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RESTORE POINT - VSSADMIN

Page 27: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RESTORE POINT – SYMBOLIC LINK

Page 28: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RESTORE POINT CONCERNS

Abuse

Page 29: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

REFRESH & RESET ARTIFACTS - OVERVIEW

Similar Artifacts found on the Boot System Volume

Different Artifacts found on the Operating System Volume

Different Artifacts based on type of Reset used

Page 30: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

REFRESH & RESET ARTIFACTS

Before Refresh/Reset After Refresh/Reset

Page 31: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

REFRESH & RESET ARTIFACTS

Before Refresh/Reset After Refresh/Restore

Page 32: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

REFRESH & RESET ARTIFACTS

Page 33: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

REFRESH & RESET – REAGENT.XML

ReAgentC

RecImg

Page 34: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

CUSTOM REFRESH – REAGENT.XML

Page 35: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

REFRESH & RESET – RELOAD.XML

Page 36: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

CUSTOM REFRESH – RELOAD.XML

Page 37: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

REFRESH ARTIFACTS

Boot System OS System

Reagent.xml

Reload.xml

Logs Directory

Unallocated Data

$SysReset

Windows.old

User files will be migrated over

FileHistory (if enabled)

Logs of migrated files

Logs of uninstalled applications

Logs of Migrated OS Updates

Page 38: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

PARTITION 2 ARTIFACTS - REFRESH

Before Refresh, or After Reset After Refresh Only

Page 39: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

REFRESH ARTIFACTS - $SYSRESET

Page 40: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

REFRESH ARTIFACTS – WINDOWS.OLD

Page 41: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

REFRESH ARTIFACTS – USERS DIRECTORY

Page 42: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

REFRESH ARTIFACTS – USERS DIRECTORY

Page 43: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVER ARTIFACTS - REFRESH

Page 44: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVER ARTIFACTS - REFRESH

Page 45: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVER ARTIFACTS - REFRESH

Page 46: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVERY ARTIFACTS - REFRESH

Page 47: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVERY ARTIFACTS – REFRESH

FILEHISTORY

Page 48: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVERY ARTIFACTS – REFRESH

FILEHISTORY

Page 49: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVERY ARTIFACTS – REFRESH

FILEHISTORY

Page 50: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

QUICK RESET ARTIFACTS

Boot System OS System

Reagent.xml

Reload.xml

Logs Directory

Unallocated Data

Must be Carved

Page 51: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVERY ARTIFACTS

Test Data

Page 52: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVER ARTIFACTS – QUICK RESET

Page 53: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVER ARTIFACTS – QUICK RESET

Page 54: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVER ARTIFACTS – QUICK RESET

Page 55: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVER ARTIFACTS – QUICK RESET

Page 56: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVER ARTIFACTS – QUICK RESET

Page 57: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVER ARTIFACTS – QUICK RESET

Page 58: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVER ARTIFACTS – QUICK RESET

Other Data Recoverable

Page 59: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

THOROUGH RESET ARTIFACTS

Boot System OS System

Reagent.xml

Reload.xml

Logs Directory

Unallocated Data

Difficult to be carved

Page 60: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVERY ARTIFACTS –

THOROUGH RESET

Page 61: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVERY ARTIFACTS –

THOROUGH RESET

Page 62: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVERY ARTIFACTS –

THOROUGH RESET

Page 63: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

RECOVERY ARTIFACTS –

THOROUGH RESET

Page 64: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SUMMARY

Review, Resources and links

Page 65: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

SUMMARY

Each Recovery option will leave unique Artifacts behind

System Restore Points are accessible using current technology

Refresh and Reset will leave similar artifacts in the Boot System

Refresh and Reset will destroy all System Restore Points on machine

Users Settings will persist over Refresh and Restore Point

Refresh will have a copy of the Registry file prior to refresh in

Windows.old

The thorough reset option does the best job of destroying the evidence

Page 66: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

WINDOWS 8 FORENSICS

Questions?

Page 68: Windows 8 Forensics - SANS Institute · Quick Thorough Good if you trust the person you are giving it to. Good if you are going to give to charity. Both options are not recommended

WINDOWS 8 RESOURCES

http://www.verboon.info/index.php/2012/01/the-windows-8-refresh-

your-pc-feature/

http://blogs.msdn.com/b/b8/archive/2012/01/04/refresh-and-reset-your-

pc.aspx