15.01.2014 Views

An Ontology for Digital Forensics in IT Security Incidents - OPUS

An Ontology for Digital Forensics in IT Security Incidents - OPUS

An Ontology for Digital Forensics in IT Security Incidents - OPUS

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

76 APPENDIX B. FORENSIC TOOLS OUTPUT LISTINGS<br />

$EA (224) Size : 0 -65536 Flags :<br />

$LOGGED_UTIL<strong>IT</strong>Y_STREAM (256) Size : 0 -65536 Flags : Non - resident<br />

List<strong>in</strong>g B.1: Output of fsstat from the sleuth kit<br />

Virtual Physical Name<br />

---------- ---------- ----<br />

0 xe18e7a38 0 x09433a38 \??\ C :\ Do .. en \ Benutzer1 \ Lok .. en \ <strong>An</strong>w .. en \ Mi ..\ Wi ..\ UsrClass . dat<br />

0 xe18e08d8 0 x091a38d8 \ Dev .. e1 \ Doku .. ellungen \ Benutzer1 \ NTUSER . DAT<br />

0 xe156ab60 0 x068ceb60 \ Dev .. e1 \ Doku .. ngen \ Lo ..\ Lok .. en \ <strong>An</strong>w .. en \ Mi ..\ Wi ..\ UsrClass . dat<br />

0 xe1561ac8 0 x068b8ac8 \ Dev .. e1 \ Do .. en \ Lo ..\ NTUSER . DAT<br />

0 xe153d9f0 0 x062a89f0 \ Dev .. e1 \ Do .. en \ Net ..\ Lok .. en \ <strong>An</strong>w .. en \ Mi ..\ Wi ..\ UsrClass . dat<br />

0 xe1534b60 0 x06213b60 \ Dev .. e1 \ Doku .. ellungen \ NetworkService \ NTUSER . DAT<br />

0 xe1371218 0 x037da218 \ Device \ HarddiskVolume1 \ WINDOWS \ system32 \ config \ software<br />

0 xe1378008 0 x04149008 \ Device \ HarddiskVolume1 \ WINDOWS \ system32 \ config \ SECUR<strong>IT</strong>Y<br />

0 xe1378758 0 x04149758 \ Device \ HarddiskVolume1 \ WINDOWS \ system32 \ config \ default<br />

0 xe134ab30 0 x03003b30 \ Device \ HarddiskVolume1 \ WINDOWS \ system32 \ config \ SAM<br />

0 xe1254130 0 x02269130 [ no name ]<br />

0 xe1018258 0 x0202b258 \ Device \ HarddiskVolume1 \ WINDOWS \ system32 \ config \ system<br />

0 xe1007260 0 x01feb260 [ no name ]<br />

0 x8068f9bc 0 x0068f9bc [ no name ]<br />

List<strong>in</strong>g B.2: Output of the hivelist module of volatility(shortened)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!