Notifications
Clear all

agent for shellbags

4 Posts
3 Users
0 Reactions
385 Views
 dega
(@dega)
Reputable Member
Joined: 11 years ago
Posts: 267
Topic starter  

dear all,
I need something to keep monitorated the shell bags. We need to analyze what happns in a USB.
Thanks all


   
Quote
nightworker
(@nightworker)
Estimable Member
Joined: 16 years ago
Posts: 134
 

you sould acquire remotely multiple registries and parse it with encase enterprise or ftk softwares

or silent runer maybe do this for you

or you can set up siem or full network packet capture infustructure


   
ReplyQuote
 dega
(@dega)
Reputable Member
Joined: 11 years ago
Posts: 267
Topic starter  

OK many thanks. What is siem?


   
ReplyQuote
EricZimmerman
(@ericzimmerman)
Estimable Member
Joined: 13 years ago
Posts: 222
 

encase or FTK? they dont do anything special for shell bags

shellbags explorer is by FAR the most capable software there is for looking at shell bag entries.

all you need is usrclass.dat or ntuser.dat (on older systems) and load them into shellbags explorer

get it and a ton more here

https://binaryforay.blogspot.com/


   
ReplyQuote
Share: