files converted int...
 
Notifications
Clear all

files converted into .pdf artifacts

3 Posts
3 Users
0 Reactions
812 Views
tibbs66
(@tibbs66)
Eminent Member
Joined: 16 years ago
Posts: 38
Topic starter  

Hi all,

Are there artifacts on a machine showing documents have been converted into .pdf's? If yes, what and where are those?

Thanks for any help!

Libby


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

There may be some…for example, the PDF metadata may show that the document originated as an MS Word document.

Depending upon how the file is converted to PDF, you may find the launch of that application by the user.

Another approach would be to try a conversion method, and image/analyze the system.


   
ReplyQuote
Bunnysniper
(@bunnysniper)
Reputable Member
Joined: 13 years ago
Posts: 259
 

Hi all,

Are there artifacts on a machine showing documents have been converted into .pdf's? If yes, what and where are those?

Check when the PDF was born (internal metadata versus file stamp versus $MFT) and correlate this date/ time with the typical execution artifacts like prefetch, shimcache and userassist. And check Event ID 7035/7036 if the spooler service was started for the printing process.


   
ReplyQuote
Share: