I just have to do a post about a benefit of using log2timeline, because this is entirely too cool.
On a recent investigation, one system had a Seagate FreeAgent Go (USB HD) attached at some point, and this showed up in USB history (from Woanware USB Device Forensics and RegRipper). However, I could not associate it with the user profile through MountPoints2 (MP2) because the USBSTOR didn't contain the Parent Prefix ID Prefix (PPID) for this device. The PPID is used in MountedDevices to identify the drive letter association and GUID; the GUID is then used in MP2 to identify the user (without the GUID you get nothing). Basically all I had was the Vendor, Product, and Version from USBSTOR, along with the connection date from DeviceClasses. As a side note, Enum\USB also did not provide the Volume ID (VID) or Product ID (PID).
At first I wasn't sure why the parsed MP2 didn't show the user association, so I went through the manual process (as detailed by SANS, Harlan Carvey, etc). This revealed what I've noted above regarding the PPID. Even though I did not necessarily need to, I also went through the setupapi.log just to confirm install date, and work the steps, as it were.
To quickly find the device in setupapi, I searched the file for "FreeAgent" using Notepad++. By clicking the "Find All in Current Document" button (as opposed to "Find Next"), I saw that there were hits in very different locations within the file. Looking more closely at these entries, I discovered that there had in fact been two Seagate FreeAgent Go drives attached to the system, more than a month apart. Well, well, well. The serial number for the second one (as logged in setupapi, which also showed the VID and PID) did show up in RegRipper's output for USBSTOR and DeviceClasses, but again that wasn't everything.
I must note at this point that until I started going through manually I hadn't spent a lot of time on RR's output, having focused on Woanware with its nicely organized text file and spreadsheet for ease of use as I had a lot of systems and not a lot of time. I had confirmed the first drive's existence, but hadn't looked to see if there were more like it. Good reminder to cross-check results, even though it may take significantly more time, depending on the amount of relevant data...
Anyway, all that said, here's the cool part with l2t. I loaded up my timeline (created by l2t's CSV output module) in Excel and went to the date/time of the initial setupapi.log entry. Sure enough, there were the install entries, just like expected. And immediately following the installation activity came the MountPoints2 key entry parsed from System Restore Point RPxxx, showing the user association. This was true for both drives in question. In addition, these historic MP2 entries showed the GUID, to help round out the analysis. Aaah, the sweet smell of forensication in the morning... ;-).
Call me a fanboy if you must, but I do like log2timeline. Thanks, Kristinn!
LM
Tips, tricks, problems, solutions, testing, and other 'cool' things from my forensic journey...
Showing posts with label regripper. Show all posts
Showing posts with label regripper. Show all posts
Thursday, April 28, 2011
Thursday, March 10, 2011
Timeline Registry Automation Script
I just couldn't keep from writing the script. Just couldn't. After going through the process yesterday, then posting about it, I just kept thinking about how I could streamline the process, so I took me a little bit of time and worked up the following. Ran through it a few times to make sure it worked and tweaked it a little.
Please keep in mind, I'm no scripting guru (aka, Hal Pomeranz et al) , so this may seem kludgy. But it does work. I could probably feed it a list of mount points and output files to fill in the variables and have it run through the whole of it, but that would probably take me more time to create and test (and fix) than it would for me to run this a handful of times.
So here it is, in all its (lack of) glory:
Here's hoping someone can use it.
Cheers!
LM
Please keep in mind, I'm no scripting guru (aka, Hal Pomeranz et al) , so this may seem kludgy. But it does work. I could probably feed it a list of mount points and output files to fill in the variables and have it run through the whole of it, but that would probably take me more time to create and test (and fix) than it would for me to run this a handful of times.
So here it is, in all its (lack of) glory:
_________________________________________________________________
#!/bin/sh
#
# Script to automate regripper in linux for timeline creation.
# This is designed to be run from your regripper directory.
# This version of rip.pl is brought over from the Windows download to run in Linux based on http://grey-corner.blogspot.com/2010/04/running-regripper-on-linux.html
#
# This will will automatically run through the 4 hives in a given mount point and write specified output file.
# By default, the 'all' module is run, rather than specific to hive type.
#
# $Src is the path (mount point) to be recursed for file in question
# $Dst is the path & file for regripper output (path must already exist)
# Order of operation should be ./rip.sh src dst
Src=$1
Dst=$2
#
#
# Check that the user provided all arguments required by this script.
if [ -z $1 ]; then
echo -e "USAGE: rip.sh SOURCEDIR OUTPUTFILE";
exit;
fi
if [ -z $2 ]; then
echo "USAGE: rip.sh sourcedir TARGETFILE";
exit;
fi
echo
echo
#
# Begin the job, updating the user along the way.
echo "Parsing user hive ... Please be patient."
echo
find $1 -iname ntuser.dat | while read d; do ./rip.pl -f all -r "$d" >> $2; done
echo
echo "Thank you for being patient."
echo
echo
echo "Parsing system hive ... This will only take a minute."
echo
find $1 -iname system | while read d; do ./rip.pl -f all -r "$d" >> $2; done
echo
echo "See, I told you it wouldn't take long."
echo
echo
echo "Parsing security hive ... Just a second, it's almost done."
echo
find $1 -iname sam | while read d; do ./rip.pl -f all -r "$d" >> $2; done
echo
echo "There! I can't believe you're so impatient."
echo
echo "Last one - the software hive ... Hold your horses, okay?"
echo
find $1 -iname software | while read d; do ./rip.pl -f all -r "$d" >> $2; done
echo
echo "Okay, we're done now. Stop complaining; I worked as fast as I could."
echo
echo
echo "If you want to run another system, please start over"
echo
echo "Thanks for playing; have a nice day."
echo
# end of script
#
_________________________________________________________________
Here's hoping someone can use it.
Cheers!
LM
Labels:
automation,
bash script,
log2timeline,
regripper,
regtime,
scripting,
timeline
Subscribe to:
Posts (Atom)