newly installed app...
 
Notifications
Clear all

newly installed application

2 Posts
2 Users
0 Reactions
1,248 Views
(@jolintan)
Trusted Member
Joined: 7 years ago
Posts: 32
Topic starter  

I got a image of one windows workstation, we are using encase and ftk.

is it possible to list the installed and uninstalled application for Apr.2020 to May 2020?

we find one application Simchar, from forensic software perspective, can we list the connected domain or ip when this application launched for the past three weeks?


   
Quote
Bunnysniper
(@bunnysniper)
Reputable Member
Joined: 13 years ago
Posts: 259
 

You can find the install dates in

Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

 

and any kind of comm protocols in your firewall/ proxy/ IDS/ IPS/ SIEM logs. 
With some luck, the local SRUM database has an IP address for you as well.

 

regards,
Robin

 


   
ReplyQuote
Share: