Please enable JavaScript.
Coggle requires JavaScript to display documents.
Nist Data Leakage - Coggle Diagram
Nist Data Leakage
1. Download dd images
md5sum
To verify the integrity of files
6. Window Registry
mmls
show unallocated spaces
impacket
Shimcache
files matadat
prefetch.py
preloads most frequently used software
samparse
stores account information
fsstat
partition details
2. Exam files in dd images
fdisk
show partition of an image
fls
List all deleted files
3. Extract key registry files
show
Display the content of the message
Partscan
Copy files
Print
Print a file directory
5. Install software
Windows prefetch
to analyze and record the startup behavior of applications
Regripper
To search string
Python-evtx
7. Window Event Log
Get a copy of security event log
val
Validate document
Sed
Text substitution
XML Parser
Write application
8. Email investigation
pffexport
To export items
libpff
Email extracting tool
hivexsh
Show mounted devices
9. File change history
USN journal
data of changed files
10. Network Evidence
JLECmd
Decode Information
Jumplist
Recently opened files
shellbag
Store used preferences
11. analysis of MFT and log file
12 Investigate Recycle bin
testdisk
recover recycle bin
Shimcache
Monitor Executed files
13. Data carving
Foremost
data carving
Sleuthkit
Recover Deleted files
Binwalk
Extracting tool
14. Crack window's password
rainbowcrack
To crack password