Extracting Windows command line details from physical memory
Details
State: Public
Version: author
Serval ID
serval:BIB_1964BC5C15A3
Type
Article: article from journal or magazin.
Collection
Publications
Institution
Title
Extracting Windows command line details from physical memory
Journal
Digital Investigation
ISSN
1742-2876
Publication state
Published
Issued date
2010
Volume
7
Pages
S57 - S63
Language
english
Abstract
Current memory forensic tools concentrate mainly on system-related information like processes and sockets. There is a need for more memory forensic techniques to extract user-entered data retained in various Microsoft Windows applications such as the Windows command prompt. The command history is a prime source of evidence in many intrusions and other computer crimes, revealing important details about an offender’s activities on the subject system. This paper dissects the data structures of the command prompt history and gives forensic practitioners a tool for reconstructing the Windows command history from a Windows XP memory capture. At the same time, this paper demonstrates a methodology that can be generalized to extract user-entered data on other versions of Windows.
Publisher's website
Open Access
Yes
Create date
16/01/2019 21:48
Last modification date
20/08/2019 12:50