Yüksek LisansAçık Erişim

Collection of triage from machines with windows operating system in incident response

2021
0 görüntülenme
0 i̇ndirme
Danışman: Doç. Dr. Fatih Ertam

Özet (EN)

Cyber threat actors can spread rapidly over the environment by using the machines that they compromised. DFIR teams acquire physical or logical disk images of the disks belong to compromised machines to detect and track the traces of the attackers. It is important to collect digital evidence of the incidents in incident response and digital forensic processes. In any case, it takes a long effort to acquire disk image from infected machines and analyze it. In some cases, Incident Response Analysts have to collect and analyze data from some machines as quick as possible in order to keep track of the attackers. Disk image acquiring processes can be achieved by collecting several file systems records or log files from devices with Windows operating systems to detect the root cause of the cyber-attack. It will be sufficient for the Incident Response Analysts to collect important operating system files from a live system or a forensic disk image for quick analysis of the case. In this article, Evidence of Program Execution, Deleted File or File Knowledge, Account Usage records will be discussed within the scope of analysis process. In this paper studies about collecting important records on local or remote machines with Windows operating systems by triage methods will be explained. As part of this thesis, a software called PS-TRIAGE, developed in the PowerShell script, was encoded that allows you to remotely connect to devices located in the Windows Active Directory and collect file system and application records via devices. PS-TRIAGE software also provides pre-analysis on machine-collected triage records and provides output to the incident response analyst.

Yazar

Kaan Yeniyol

Bu Yayına Nasıl Atıf Yapılır

Kaan Yeniyol (Master Thesis). Collection of triage from machines with windows operating system in incident response, 2021, Fırat University.

Anahtar Kelimeler

Lisans

Tüm Hakları Saklıdır

Bu eser belirtilen lisans koşulları altında paylaşılmaktadır.

Fırat University tezlerinden daha fazlası