Ethical Hacking Training at InfoSec Institute Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Tracking moved files? |
|---|---|
| Date: | Thu, 11 May 2006 09:42:18 -0700 |
LNK file analysis will do the trick, but you need to use a forensic method to extract and analyze them. There are embedded dates within these LNK files that you can use, also looking through the registry under the USBSTOR for thumb drives, matching to drive letters might provide some clues. Jim Jim Butterworth, EnCE, GCIA Manager, Professional Services, Southwest *** Sent while Mobile *** -----Original Message----- From: Bart Somers <zon4jou@gmail.com> To: Serge Jorgensen <filbanks@gmail.com> CC: forensics@securityfocus.com <forensics@securityfocus.com> Sent: Tue May 09 02:52:00 2006 Subject: Re: Tracking moved files? Besides the installation info, all files copied or moved to the removable storage should have been accessed (to read) or modified (remove). So i think analyzing the access-times from your source-filesystem should show you accessed and removed files. This is off course not water-tight, as i can plugin an USB-device, work on a lot of files (without doing something with the USB-device) and remoce the device, but at least it's a start. Best regards, Bart Somers. On 5/4/06, Serge Jorgensen <filbanks@gmail.com> wrote:
Hello! I'm try to show that files were copied and/or moved off a W2K drive onto a USB stick. Obviously the registry and setupapi files show the USB installation info - but I can't find the log file (or other method?) that Windows must use to track files being moved and copied. I don't have the USB device - which would make this a whole lot easier. Any ideas would be great. Thanks. George
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Recovering files from RAID 0 set, pentesticle |
|---|---|
| Next by Date: | RE: cmd.exe hack, Wim Remes |
| Previous by Thread: | RE: Tracking moved files?, Ricardo Landrau |
| Next by Thread: | Re: Tracking moved files?, Bill Wittmer |
| Indexes: | [Date] [Thread] [Top] [All Lists] |