Company/wifi networ...
 
Notifications
Clear all

Company/wifi networks accessed for specific date range

6 Posts
2 Users
0 Reactions
448 Views
(@djarmellino)
New Member
Joined: 13 years ago
Posts: 3
Topic starter  

I am using EnCase Forensic v6.18 and am trying to determine exactly how many times a custodian accessed their company network as well as any wifi networks during a specific date range…Can anyone point me in the right direction as to how to obtain this information or if it is even possible to determine?


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

What are you examining? Logs from a WAP or a system? If you're analyzing a system, which OS and version are you examining?


   
ReplyQuote
(@djarmellino)
New Member
Joined: 13 years ago
Posts: 3
Topic starter  

I am examining a system w/ Microsoft Windows XP service pack 3.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

RegRipper has a plugin named "ssid.pl" that will extract this information for you; however, it will only tell you the last time that the device was connected to the WAP. You'll have to extract the System hives from the various Restore Points to get historical information.


   
ReplyQuote
(@djarmellino)
New Member
Joined: 13 years ago
Posts: 3
Topic starter  

I actually have already used RegRipper to parse the registry files and was only able to see what networks he accessed. I need to be able to see the amount of times each network was accessed between a specific date range. When you say "you'll have to extract the System hives from the various Restore Points to get historical information" do you mean simply exporting the "system" files and parsing it in RegRipper?


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

I actually have already used RegRipper to parse the registry files and was only able to see what networks he accessed. I need to be able to see the amount of times each network was accessed between a specific date range.

Sorry, to the best of my knowledge, WinXP doesn't maintain that information.

When you say "you'll have to extract the System hives from the various Restore Points to get historical information" do you mean simply exporting the "system" files and parsing it in RegRipper?

Yes.


   
ReplyQuote
Share: