An Ontology for Digital Forensics in IT Security Incidents - OPUS

An Ontology for Digital Forensics in IT Security Incidents - OPUS An Ontology for Digital Forensics in IT Security Incidents - OPUS

opus.bibliothek.uni.augsburg.de
from opus.bibliothek.uni.augsburg.de More from this publisher
15.01.2014 Views

76 APPENDIX B. FORENSIC TOOLS OUTPUT LISTINGS $EA (224) Size : 0 -65536 Flags : $LOGGED_UTILITY_STREAM (256) Size : 0 -65536 Flags : Non - resident Listing B.1: Output of fsstat from the sleuth kit Virtual Physical Name ---------- ---------- ---- 0 xe18e7a38 0 x09433a38 \??\ C :\ Do .. en \ Benutzer1 \ Lok .. en \ Anw .. en \ Mi ..\ Wi ..\ UsrClass . dat 0 xe18e08d8 0 x091a38d8 \ Dev .. e1 \ Doku .. ellungen \ Benutzer1 \ NTUSER . DAT 0 xe156ab60 0 x068ceb60 \ Dev .. e1 \ Doku .. ngen \ Lo ..\ Lok .. en \ Anw .. en \ Mi ..\ Wi ..\ UsrClass . dat 0 xe1561ac8 0 x068b8ac8 \ Dev .. e1 \ Do .. en \ Lo ..\ NTUSER . DAT 0 xe153d9f0 0 x062a89f0 \ Dev .. e1 \ Do .. en \ Net ..\ Lok .. en \ Anw .. en \ Mi ..\ Wi ..\ UsrClass . dat 0 xe1534b60 0 x06213b60 \ Dev .. e1 \ Doku .. ellungen \ NetworkService \ NTUSER . DAT 0 xe1371218 0 x037da218 \ Device \ HarddiskVolume1 \ WINDOWS \ system32 \ config \ software 0 xe1378008 0 x04149008 \ Device \ HarddiskVolume1 \ WINDOWS \ system32 \ config \ SECURITY 0 xe1378758 0 x04149758 \ Device \ HarddiskVolume1 \ WINDOWS \ system32 \ config \ default 0 xe134ab30 0 x03003b30 \ Device \ HarddiskVolume1 \ WINDOWS \ system32 \ config \ SAM 0 xe1254130 0 x02269130 [ no name ] 0 xe1018258 0 x0202b258 \ Device \ HarddiskVolume1 \ WINDOWS \ system32 \ config \ system 0 xe1007260 0 x01feb260 [ no name ] 0 x8068f9bc 0 x0068f9bc [ no name ] Listing B.2: Output of the hivelist module of volatility(shortened)

Appendix C Screenshots Figure C.1: Neo4J web interface: Interactive graph explorer 77

Appendix C<br />

Screenshots<br />

Figure C.1: Neo4J web <strong>in</strong>terface: Interactive graph explorer<br />

77

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!