Please enable JavaScript.
Coggle requires JavaScript to display documents.
Anti-Forensic - Coggle Diagram
Anti-Forensic
Timestomping
Techniques
Tools
Detection
$SI "M" time prior to Shimcache timestamp
$SI times prior to executable's compile time
Fractional second values all zeros
$SI times prior to $130 slack entries
$SI "B" time prior to $FN "B" time
MFT entry number out of sequence
Registry Key/Value Deletion/Wiping
Detection
Unallocated Space
Recovery
Keys
Value
Timestamps
Tools
Registry Explorer
marked deleted (X)
File Delete/Wiping
Techniques
BCWipe
Eraser
SDelete
Cipher
Recovery
Metadata
Tools
icat - extact individually
tsk_recover - all files
Carving
Files Types
Files
PhotoRec - file signatures
VSS Snapshot
System Volume Information - vss_carver.py
Event Log and File System
Bulk Extractor - stream-based carving
Strings
indexed search
bit-by-bit
Filess Malware
Techniques
Powershell Base64 bit
Tools
Registry Explorer
Use "Find" features
Data Encryption
Hiding Data in Registry
Event Log Tampering