<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>gardenia02 님의 블로그</title>
    <link>https://gardenia02.tistory.com/</link>
    <description>gardenia02 님의 블로그 입니다.</description>
    <language>ko</language>
    <pubDate>Sat, 16 May 2026 04:00:51 +0900</pubDate>
    <generator>TISTORY</generator>
    <ttl>100</ttl>
    <managingEditor>gardenia02</managingEditor>
    <item>
      <title>Jumplist Explorer</title>
      <link>https://gardenia02.tistory.com/5</link>
      <description>&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;Jumplist&lt;/b&gt;&lt;/h4&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;jumplist란?&lt;/b&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;윈도우7부터 새롭게 추가된 아티펙트로, 사용자가 자주 사용하거나 최근에 사용한 문서 또는 프로그램을 관리하는 링크 파일이다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;저장 경로 &lt;/b&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;i&gt;%UserProfile%\AppData\Roaming\Microsoft\Windows\Recent\&lt;br /&gt;&lt;/i&gt;&lt;/p&gt;
&lt;ul style=&quot;list-style-type: disc;&quot; data-ke-list-type=&quot;disc&quot;&gt;
&lt;li&gt;AutomaticDestinations : &lt;span style=&quot;background-color: #ffffff; color: #222222; text-align: start;&quot;&gt;운영체제가 자동으로 남기며, 최근 사용목록 및 자주 사용되는 항목을 알 수 있다.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;CustomDestinations : &lt;span style=&quot;background-color: #ffffff; color: #222222; text-align: start;&quot;&gt;응용프로그램이 자체적으로 남기며, 작업목록 항목을 알 수 있다.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-filename=&quot;blob&quot; data-origin-width=&quot;1075&quot; data-origin-height=&quot;449&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/doRxEh/btsKvfZSXbX/YFffoLnayc5pkX2nqkK0Kk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/doRxEh/btsKvfZSXbX/YFffoLnayc5pkX2nqkK0Kk/img.png&quot; data-alt=&quot;유형이 &amp;quot;바로 가기&amp;quot;임을 확인할 수 있다.&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/doRxEh/btsKvfZSXbX/YFffoLnayc5pkX2nqkK0Kk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FdoRxEh%2FbtsKvfZSXbX%2FYFffoLnayc5pkX2nqkK0Kk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;673&quot; height=&quot;281&quot; data-filename=&quot;blob&quot; data-origin-width=&quot;1075&quot; data-origin-height=&quot;449&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;유형이 &quot;바로 가기&quot;임을 확인할 수 있다.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;종류&lt;/b&gt;&lt;/p&gt;
&lt;ul style=&quot;list-style-type: disc;&quot; data-ke-list-type=&quot;disc&quot;&gt;
&lt;li&gt;recent(최근 항목)&lt;br /&gt;응용프로그램을 통해 최근 열람한 파일&amp;nbsp;&lt;/li&gt;
&lt;li&gt;frequent(자주 사용하는 항목)&lt;br /&gt;응용프로그램을 통해 자주 열람하는 파일&amp;nbsp; &lt;/li&gt;
&lt;li&gt;pinned(사용자 고정)&lt;br /&gt;응용프로그램의 사용이 종료되어도 사용자가 작업 표시줄에 아이콘을 남겨둔 파일&amp;nbsp;&lt;/li&gt;
&lt;li&gt;tasks(작업)&amp;nbsp;&lt;br /&gt;응용프로그램에서 지원하는 작업 목록&lt;/li&gt;
&lt;li&gt;other types&lt;br /&gt;최근 닫은 창, top sites 등&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;활용&lt;/b&gt;&lt;/p&gt;
&lt;ol style=&quot;list-style-type: decimal;&quot; data-ke-list-type=&quot;decimal&quot;&gt;
&lt;li&gt;문서/프로그램의 실행 유무를 판단할 수 있다.&lt;/li&gt;
&lt;li&gt;자주 사용하는 문서/프로그램의 정보를 확인할 수 있다.&lt;/li&gt;
&lt;li&gt;최근에 사용한 문서/프로그램의 정보를 확인할 수 있다.&lt;/li&gt;
&lt;li&gt;사용자의 행위를 파악할 수 있다.&lt;br /&gt;사용자가 직접 삭제하지 않는 이상 운영체제 설치 시점부터 지속적으로 로그가 저장된다.&lt;br /&gt;따라서 애플리케이션의 사용 패턴을 추적할 수 있다.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;외부 저장 장치에 접근한 기록을 확인할 수 있다.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;사용자가 방문했던 웹사이트 URL을 확인할 수 있다.&lt;/li&gt;
&lt;/ol&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;Jumplist Explorer 사용법&lt;/b&gt;&lt;/h4&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;먼저 kape를 사용해 관련 파일을 추출한다.&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1055&quot; data-origin-height=&quot;653&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bStXOl/btsKvIm26tj/CnK662usxAVLRxSJ1pX0k0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bStXOl/btsKvIm26tj/CnK662usxAVLRxSJ1pX0k0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bStXOl/btsKvIm26tj/CnK662usxAVLRxSJ1pX0k0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbStXOl%2FbtsKvIm26tj%2FCnK662usxAVLRxSJ1pX0k0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;689&quot; height=&quot;426&quot; data-origin-width=&quot;1055&quot; data-origin-height=&quot;653&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;jumplist explorer을 열어 추출한 파일을 load한다.&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1292&quot; data-origin-height=&quot;755&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/X1zoT/btsKwQxyIfT/KpklYO4g4yN5I3CuKD8nyK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/X1zoT/btsKwQxyIfT/KpklYO4g4yN5I3CuKD8nyK/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/X1zoT/btsKwQxyIfT/KpklYO4g4yN5I3CuKD8nyK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FX1zoT%2FbtsKwQxyIfT%2FKpklYO4g4yN5I3CuKD8nyK%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;742&quot; height=&quot;434&quot; data-origin-width=&quot;1292&quot; data-origin-height=&quot;755&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;다양한 정보를 확인할 수 있다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;참고 링크: &lt;a href=&quot;http://www.forensic-artifact.com/windows-forensics/jumplist&quot; target=&quot;_blank&quot; rel=&quot;noopener&amp;nbsp;noreferrer&quot;&gt;http://www.forensic-artifact.com/windows-forensics/jumplist&lt;/a&gt;&lt;/p&gt;
&lt;figure id=&quot;og_1730703346126&quot; contenteditable=&quot;false&quot; data-ke-type=&quot;opengraph&quot; data-ke-align=&quot;alignCenter&quot; data-og-type=&quot;website&quot; data-og-title=&quot;디지털 포렌식 아티팩트 &amp;amp; 증거 분석 기법 공유 | 인섹시큐리티&quot; data-og-description=&quot;[증거]테이블의 상단 칼럼 정보를 통해 앱ID, 앱ID에 따른 응용프로그램 이름, 경로, 마지막 접근 시간, MAC 주소 확인이 가능하고 우측 [세부 정보]테이블을 통해서도 확인 가능&quot; data-og-host=&quot;www.forensic-artifact.com&quot; data-og-source-url=&quot;http://www.forensic-artifact.com/windows-forensics/jumplist&quot; data-og-url=&quot;http://www.forensic-artifact.com/windows-forensics/jumplist&quot; data-og-image=&quot;https://scrap.kakaocdn.net/dn/beaWoO/hyXsUnfcUI/HfIK9gzZG2QGsRziBYNN3K/img.png?width=1131&amp;amp;height=639&amp;amp;face=0_0_1131_639,https://scrap.kakaocdn.net/dn/Dl7G1/hyXpuXEfy7/gypGqjmPOSYpnpcwF6w9dk/img.png?width=1027&amp;amp;height=652&amp;amp;face=0_0_1027_652,https://scrap.kakaocdn.net/dn/L330b/hyXsWFnTd0/c5z9jybA7kuatkbOAPaa5K/img.png?width=1027&amp;amp;height=652&amp;amp;face=0_0_1027_652&quot;&gt;&lt;a href=&quot;http://www.forensic-artifact.com/windows-forensics/jumplist&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; data-source-url=&quot;http://www.forensic-artifact.com/windows-forensics/jumplist&quot;&gt;
&lt;div class=&quot;og-image&quot; style=&quot;background-image: url('https://scrap.kakaocdn.net/dn/beaWoO/hyXsUnfcUI/HfIK9gzZG2QGsRziBYNN3K/img.png?width=1131&amp;amp;height=639&amp;amp;face=0_0_1131_639,https://scrap.kakaocdn.net/dn/Dl7G1/hyXpuXEfy7/gypGqjmPOSYpnpcwF6w9dk/img.png?width=1027&amp;amp;height=652&amp;amp;face=0_0_1027_652,https://scrap.kakaocdn.net/dn/L330b/hyXsWFnTd0/c5z9jybA7kuatkbOAPaa5K/img.png?width=1027&amp;amp;height=652&amp;amp;face=0_0_1027_652');&quot;&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;og-text&quot;&gt;
&lt;p class=&quot;og-title&quot; data-ke-size=&quot;size16&quot;&gt;디지털 포렌식 아티팩트 &amp;amp; 증거 분석 기법 공유 | 인섹시큐리티&lt;/p&gt;
&lt;p class=&quot;og-desc&quot; data-ke-size=&quot;size16&quot;&gt;[증거]테이블의 상단 칼럼 정보를 통해 앱ID, 앱ID에 따른 응용프로그램 이름, 경로, 마지막 접근 시간, MAC 주소 확인이 가능하고 우측 [세부 정보]테이블을 통해서도 확인 가능&lt;/p&gt;
&lt;p class=&quot;og-host&quot; data-ke-size=&quot;size16&quot;&gt;www.forensic-artifact.com&lt;/p&gt;
&lt;/div&gt;
&lt;/a&gt;&lt;/figure&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;</description>
      <category>디지털포렌식</category>
      <category>jumplist</category>
      <category>jumplist explorer</category>
      <category>점프리스트</category>
      <author>gardenia02</author>
      <guid isPermaLink="true">https://gardenia02.tistory.com/5</guid>
      <comments>https://gardenia02.tistory.com/5#entry5comment</comments>
      <pubDate>Mon, 4 Nov 2024 16:09:48 +0900</pubDate>
    </item>
    <item>
      <title>Thumbnail cache와 Icon cache, Thumbcache Viewer 사용법</title>
      <link>https://gardenia02.tistory.com/4</link>
      <description>&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;Thumbnail cache&lt;/b&gt;&lt;/h4&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;thumbnail cache란?&lt;/b&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;background-color: #ffffff; color: #000000; text-align: start;&quot;&gt;썸네일은 어떤 파일에 대한 미리보기를 나타내주는 것이다. 그래픽 이미지를 축소하였기 때문에 많은 양의 이미지를 빠르게 탐색할 수 있다.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;background-color: #ffffff; color: #000000; text-align: start;&quot;&gt;윈도우는 자체적으로 파일의 썸네일을 생성하여 데이터베이스 형식으로 보관한다. &lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;background-color: #ffffff; color: #000000; text-align: start;&quot;&gt;미리보기를 한 번이라도 했다면 썸네일이 데이터베이스에 저장되는데, 원본 파일이 삭제되더라도 썸네일은 삭제되지 않는다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;thumbnail cache 저장경로&lt;/b&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;i&gt; %UserProfile%\AppData\Local\Microsoft\Windows\Explorer\thumbcache_*.db &lt;/i&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;각 파일은 bmp, png, jpg 파일을 여러 개 가지고 있다.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-filename=&quot;blob&quot; data-origin-width=&quot;1151&quot; data-origin-height=&quot;789&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/cp1aSN/btsKvMv0HKP/L4InlzVy1SFWOu2Ks7YVS0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/cp1aSN/btsKvMv0HKP/L4InlzVy1SFWOu2Ks7YVS0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/cp1aSN/btsKvMv0HKP/L4InlzVy1SFWOu2Ks7YVS0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fcp1aSN%2FbtsKvMv0HKP%2FL4InlzVy1SFWOu2Ks7YVS0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;614&quot; height=&quot;421&quot; data-filename=&quot;blob&quot; data-origin-width=&quot;1151&quot; data-origin-height=&quot;789&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;thumbnail cache의 활용 &lt;/b&gt;&lt;/p&gt;
&lt;ol style=&quot;list-style-type: decimal;&quot; data-ke-list-type=&quot;decimal&quot;&gt;
&lt;li&gt;그래픽이나 동영상, 문서 등의 파일의 과거 존재 여부를 파악할 수 있다.&lt;/li&gt;
&lt;li&gt;파일의 내용을 식별할 수 있다.&lt;br /&gt;멀티미디어 파일의 경우, 파일 내의 임의의 프레임이 썸네일로 캐시된다.&lt;br /&gt;문서 파일의 경우, 첫 번째 페이지가 썸네일로 캐시된다.&lt;/li&gt;
&lt;/ol&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;Icon cache&lt;/b&gt;&lt;/h4&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;icon cache란?&lt;/b&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;background-color: #ffffff; color: #333333; text-align: left;&quot;&gt;windows 아이콘을 보여주기 위해서 가지고 있는 캐시이다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;background-color: #ffffff; color: #333333; text-align: justify;&quot;&gt;아이콘 캐시는 사용자 컴퓨터 및 외부 저장매체에서 열람/실행한 응용프로그램들의 아이콘 캐시 정보를 저장하고 있다. &lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;background-color: #ffffff; color: #333333; text-align: justify;&quot;&gt;기록된 응용프로그램의 아이콘 캐시 정보는 삭제되지 않는다. &lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;background-color: #ffffff; color: #333333; text-align: justify;&quot;&gt;아이콘 캐시는 재방문 시 속도향상을 위해 사용된다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;icon cache 저장 경로&lt;/b&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;i&gt;%UserProfile%\AppData\Local\Microsoft\Windows\Explorer\iconcache_*.db &lt;/i&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;각 파일은 bmp, png, jpg 파일을 여러 개 가지고 있다.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-filename=&quot;blob&quot; data-origin-width=&quot;1112&quot; data-origin-height=&quot;795&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/rlMkC/btsKv5B7t78/kgDmwJY1qchBfTTYkgTZtk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/rlMkC/btsKv5B7t78/kgDmwJY1qchBfTTYkgTZtk/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/rlMkC/btsKv5B7t78/kgDmwJY1qchBfTTYkgTZtk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FrlMkC%2FbtsKv5B7t78%2FkgDmwJY1qchBfTTYkgTZtk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;629&quot; height=&quot;450&quot; data-filename=&quot;blob&quot; data-origin-width=&quot;1112&quot; data-origin-height=&quot;795&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;icon cache의 활용&lt;/b&gt;&lt;/p&gt;
&lt;ol style=&quot;list-style-type: decimal;&quot; data-ke-list-type=&quot;decimal&quot;&gt;
&lt;li&gt;아이콘을 보유하고 있는 악성코드 흔적 확인이 가능하다. 그러나 애드웨어류를 제외하고는 대부분의 악성코드가 아이콘을 보유하고 있지 않다. 동시에 악성 프로그램 설치 경로를 확인할 수 있다.&lt;/li&gt;
&lt;li&gt;대부분의 안티포렌식 도구는 아이콘을 가지고 있는 프로그램이다. 따라서 사용자가 이와 같은 도구를 사용했는지 확인할 수 있다.&lt;/li&gt;
&lt;li&gt;광학드라이브 사용 흔적을 확인 가능하다. 캐시된 아이콘 경로의 드라이브 문자를 확인해 광학드라이브에서의 프로그램 실행 여부를 알 수 있다.&lt;/li&gt;
&lt;li&gt;일반 프로그램 사용 흔적을 확인 가능하다.&lt;/li&gt;
&lt;li&gt;외부저장매체 사용 흔적을 확인 가능하다. 로컬 시스템에 외부저장매체를 연결하면 해당 아이콘이 로컬에 캐시된다.&lt;/li&gt;
&lt;/ol&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;Thumbcache Viewer 사용법&lt;/b&gt;&lt;/h4&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;thumbcache viewer 프로그램을 실행하고, 원하는 thumbnail cache나 icon cache를 드래그한다.&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;참고로 thumbnail cache 파일은 kape를 통해 수집할 수 있다.&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1615&quot; data-origin-height=&quot;692&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/s1WlD/btsKwNgqNWB/SvmfKPrSfI8k34oKdXPI1K/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/s1WlD/btsKwNgqNWB/SvmfKPrSfI8k34oKdXPI1K/img.png&quot; data-alt=&quot;thumbnail cache&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/s1WlD/btsKwNgqNWB/SvmfKPrSfI8k34oKdXPI1K/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fs1WlD%2FbtsKwNgqNWB%2FSvmfKPrSfI8k34oKdXPI1K%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;664&quot; height=&quot;285&quot; data-origin-width=&quot;1615&quot; data-origin-height=&quot;692&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;thumbnail cache&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-filename=&quot;blob&quot; data-origin-width=&quot;1617&quot; data-origin-height=&quot;694&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bwmGSO/btsKwMu2tbo/wF4sN85or0VQYkPXuakrn0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bwmGSO/btsKwMu2tbo/wF4sN85or0VQYkPXuakrn0/img.png&quot; data-alt=&quot;icon cache&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bwmGSO/btsKwMu2tbo/wF4sN85or0VQYkPXuakrn0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbwmGSO%2FbtsKwMu2tbo%2FwF4sN85or0VQYkPXuakrn0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;720&quot; height=&quot;309&quot; data-filename=&quot;blob&quot; data-origin-width=&quot;1617&quot; data-origin-height=&quot;694&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;icon cache&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;아래와 같은 다양한 정보를 확인할 수 있다.&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1629&quot; data-origin-height=&quot;100&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/cz2Kyq/btsKwk0fQou/CgibNZBLlMKydKc0vpGqdk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/cz2Kyq/btsKwk0fQou/CgibNZBLlMKydKc0vpGqdk/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/cz2Kyq/btsKwk0fQou/CgibNZBLlMKydKc0vpGqdk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fcz2Kyq%2FbtsKwk0fQou%2FCgibNZBLlMKydKc0vpGqdk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;1629&quot; height=&quot;100&quot; data-origin-width=&quot;1629&quot; data-origin-height=&quot;100&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;참고 링크: &lt;a href=&quot;http://forensic-proof.com/archives/2092&quot; target=&quot;_blank&quot; rel=&quot;noopener&amp;nbsp;noreferrer&quot;&gt;http://forensic-proof.com/archives/2092&lt;/a&gt;&lt;/p&gt;
&lt;figure id=&quot;og_1730700789101&quot; contenteditable=&quot;false&quot; data-ke-type=&quot;opengraph&quot; data-ke-align=&quot;alignCenter&quot; data-og-type=&quot;website&quot; data-og-title=&quot;썸네일 포렌식 분석 (Thumbnail Forensics) | FORENSIC-PROOF&quot; data-og-description=&quot;&quot; data-og-host=&quot;forensic-proof.com&quot; data-og-source-url=&quot;http://forensic-proof.com/archives/2092&quot; data-og-url=&quot;http://forensic-proof.com/archives/2092&quot; data-og-image=&quot;&quot;&gt;&lt;a href=&quot;http://forensic-proof.com/archives/2092&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; data-source-url=&quot;http://forensic-proof.com/archives/2092&quot;&gt;
&lt;div class=&quot;og-image&quot; style=&quot;background-image: url();&quot;&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;og-text&quot;&gt;
&lt;p class=&quot;og-title&quot; data-ke-size=&quot;size16&quot;&gt;썸네일 포렌식 분석 (Thumbnail Forensics) | FORENSIC-PROOF&lt;/p&gt;
&lt;p class=&quot;og-desc&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class=&quot;og-host&quot; data-ke-size=&quot;size16&quot;&gt;forensic-proof.com&lt;/p&gt;
&lt;/div&gt;
&lt;/a&gt;&lt;/figure&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;http://forensic-proof.com/archives/5168&quot; target=&quot;_blank&quot; rel=&quot;noopener&amp;nbsp;noreferrer&quot;&gt;http://forensic-proof.com/archives/5168&lt;/a&gt;&lt;/p&gt;
&lt;figure id=&quot;og_1730700795903&quot; contenteditable=&quot;false&quot; data-ke-type=&quot;opengraph&quot; data-ke-align=&quot;alignCenter&quot; data-og-type=&quot;website&quot; data-og-title=&quot;IconCache를 최대한 활용하자 (Make the Best of the IconCache) | FORENSIC-PROOF&quot; data-og-description=&quot;&quot; data-og-host=&quot;forensic-proof.com&quot; data-og-source-url=&quot;http://forensic-proof.com/archives/5168&quot; data-og-url=&quot;http://forensic-proof.com/archives/5168&quot; data-og-image=&quot;&quot;&gt;&lt;a href=&quot;http://forensic-proof.com/archives/5168&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; data-source-url=&quot;http://forensic-proof.com/archives/5168&quot;&gt;
&lt;div class=&quot;og-image&quot; style=&quot;background-image: url();&quot;&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;og-text&quot;&gt;
&lt;p class=&quot;og-title&quot; data-ke-size=&quot;size16&quot;&gt;IconCache를 최대한 활용하자 (Make the Best of the IconCache) | FORENSIC-PROOF&lt;/p&gt;
&lt;p class=&quot;og-desc&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class=&quot;og-host&quot; data-ke-size=&quot;size16&quot;&gt;forensic-proof.com&lt;/p&gt;
&lt;/div&gt;
&lt;/a&gt;&lt;/figure&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://brunch.co.kr/@bl4cksh33p/4&quot; target=&quot;_blank&quot; rel=&quot;noopener&amp;nbsp;noreferrer&quot;&gt;https://brunch.co.kr/@bl4cksh33p/4&lt;/a&gt;&lt;/p&gt;
&lt;figure id=&quot;og_1730701290336&quot; contenteditable=&quot;false&quot; data-ke-type=&quot;opengraph&quot; data-ke-align=&quot;alignCenter&quot; data-og-type=&quot;article&quot; data-og-title=&quot;IconCache 파일 포맷 분석&quot; data-og-description=&quot;IconCache 파일 구조와 포렌식적 의미를 알아보자 | 1.&amp;nbsp;아이콘 캐시 1.1 &amp;nbsp;&amp;nbsp;아이콘 캐시란? 아이콘 캐시는 사용자 컴퓨터 및 외부 저장매체에서 열람 및 실행한 응용프로그램들의 아이콘 캐시 정보&quot; data-og-host=&quot;brunch.co.kr&quot; data-og-source-url=&quot;https://brunch.co.kr/@bl4cksh33p/4&quot; data-og-url=&quot;https://brunch.co.kr/@bl4cksh33p/4&quot; data-og-image=&quot;https://scrap.kakaocdn.net/dn/1rgpC/hyXs3xGOuz/qJUOT3wGlW71j3EhYSDhL0/img.png?width=800&amp;amp;height=800&amp;amp;face=0_0_800_800,https://scrap.kakaocdn.net/dn/BNCjX/hyXsXYzA6i/146G6t4zG7IW82N5BaxxYK/img.png?width=500&amp;amp;height=500&amp;amp;face=0_0_500_500&quot;&gt;&lt;a href=&quot;https://brunch.co.kr/@bl4cksh33p/4&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; data-source-url=&quot;https://brunch.co.kr/@bl4cksh33p/4&quot;&gt;
&lt;div class=&quot;og-image&quot; style=&quot;background-image: url('https://scrap.kakaocdn.net/dn/1rgpC/hyXs3xGOuz/qJUOT3wGlW71j3EhYSDhL0/img.png?width=800&amp;amp;height=800&amp;amp;face=0_0_800_800,https://scrap.kakaocdn.net/dn/BNCjX/hyXsXYzA6i/146G6t4zG7IW82N5BaxxYK/img.png?width=500&amp;amp;height=500&amp;amp;face=0_0_500_500');&quot;&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;og-text&quot;&gt;
&lt;p class=&quot;og-title&quot; data-ke-size=&quot;size16&quot;&gt;IconCache 파일 포맷 분석&lt;/p&gt;
&lt;p class=&quot;og-desc&quot; data-ke-size=&quot;size16&quot;&gt;IconCache 파일 구조와 포렌식적 의미를 알아보자 | 1.&amp;nbsp;아이콘 캐시 1.1 &amp;nbsp;&amp;nbsp;아이콘 캐시란? 아이콘 캐시는 사용자 컴퓨터 및 외부 저장매체에서 열람 및 실행한 응용프로그램들의 아이콘 캐시 정보&lt;/p&gt;
&lt;p class=&quot;og-host&quot; data-ke-size=&quot;size16&quot;&gt;brunch.co.kr&lt;/p&gt;
&lt;/div&gt;
&lt;/a&gt;&lt;/figure&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;</description>
      <category>디지털포렌식</category>
      <category>thumbcache viewer</category>
      <category>디지털포렌식</category>
      <category>썸네일 캐시</category>
      <category>아이콘 캐시</category>
      <author>gardenia02</author>
      <guid isPermaLink="true">https://gardenia02.tistory.com/4</guid>
      <comments>https://gardenia02.tistory.com/4#entry4comment</comments>
      <pubDate>Mon, 4 Nov 2024 15:36:30 +0900</pubDate>
    </item>
    <item>
      <title>BrowsingHistoryView, Hindsight</title>
      <link>https://gardenia02.tistory.com/3</link>
      <description>&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;web artifact&lt;/b&gt;&lt;/h4&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;사용자로 인해 웹 어플리케이션과 웹 브라우저가 통신하며 생성된 흔적이다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;background-color: #ffffff; color: #000000; text-align: start;&quot;&gt;웹 브라우저 쿠키, 웹 브라우저 히스토리, 웹 브라우저 다운로드 목록, 웹 캐시 등을 통해 웹 사용 내역을 조사할 수 있다.&lt;/span&gt;&lt;/p&gt;
&lt;ul style=&quot;list-style-type: disc;&quot; data-ke-list-type=&quot;disc&quot;&gt;
&lt;li&gt;cookies&lt;br /&gt;쿠키는 웹 서버가 생성하여 웹 브라우저로 전송하는 작은 파일 정보이다.&lt;br /&gt;호스트 이름과 경로, 쿠키 수정시간, 쿠키 만료 시간, 값, 마지막 접근 시간&lt;span style=&quot;background-color: #ffffff; color: #333333; text-align: start;&quot;&gt;&amp;nbsp;등을 알 수 있다.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;tool: ChromeCookiesView&lt;br /&gt;경로: &lt;i&gt;&lt;span style=&quot;background-color: #f7f7f7; color: #333333; text-align: start;&quot;&gt;%USERPROFILE%\AppData\Local\google\chrome\user&amp;nbsp;data\default\Cookies&lt;/span&gt; &lt;/i&gt;&lt;/li&gt;
&lt;li&gt;download file list&lt;br /&gt;웹에서 다운로드 받은 파일의 안정적인 전송과 이력을 관리하기 위해 다운로드되는 파일의 목록을 관리&lt;span style=&quot;background-color: #ffffff; color: #333333; text-align: start;&quot;&gt;하고 있다.&lt;/span&gt; &lt;span style=&quot;background-color: #ffffff; color: #333333; text-align: start;&quot;&gt;&lt;br /&gt;파일 저장 경로, 다운로드 url, 파일 크기, 다운로드 시간 등을 알 수 있다.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;background-color: #ffffff; color: #333333; text-align: start;&quot;&gt;&lt;br /&gt;경로: &lt;i&gt;&lt;span style=&quot;background-color: #f7f7f7; color: #333333; text-align: start;&quot;&gt;%USERPROFILE%\AppData\Local\google\chrome\user data\default\history&lt;/span&gt; &lt;/i&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;caches&lt;br /&gt;캐시된 data란 웹사이트를 방문할 때 자동으로 저장되는 data를 의미한다.&lt;br /&gt;접속 URL, 캐시 파일 정보(저장 시간, 파일명, 타입, 크기, 경로)&lt;span style=&quot;background-color: #ffffff; color: #333333; text-align: start;&quot;&gt; 등을 알 수 있다.&amp;nbsp;&lt;br /&gt;&lt;/span&gt;cached data의 종류: HTML, XML, JavaScript, Icon, Font, Text, JSON, Image, Audio, Video 등&amp;nbsp;&lt;br /&gt;tool: ChromeCacheView&lt;/li&gt;
&lt;li&gt;login credentials&lt;br /&gt;로그인 시 사용되는 아이디, 비밀번호와 같은 정보이다.&lt;br /&gt;경로:&amp;nbsp; &lt;i&gt;&lt;span style=&quot;background-color: #f7f7f7; color: #333333; text-align: start;&quot;&gt;%USERPROFILE%\AppData\Local\google\chrome\user data\{profile}/Login Data&lt;br /&gt;%UserProfile%\AppData\Roaming\Microsoft\Protect\{SID}\{GUID}\&lt;/span&gt;&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;history&lt;br /&gt;url, 페이지 title, 접속 시간, 접속 횟수 등을 알 수 있다.&lt;br /&gt;특히 url을 통해서 user ID, 검색 키워드, timestamp의 정보를 얻을 수 있다.&amp;nbsp;&lt;br /&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1615&quot; data-origin-height=&quot;137&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/sKHIQ/btsKqMCy2ji/ZM4zCbLj2Ipom4oizZbc8k/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/sKHIQ/btsKqMCy2ji/ZM4zCbLj2Ipom4oizZbc8k/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/sKHIQ/btsKqMCy2ji/ZM4zCbLj2Ipom4oizZbc8k/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FsKHIQ%2FbtsKqMCy2ji%2FZM4zCbLj2Ipom4oizZbc8k%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;1615&quot; height=&quot;137&quot; data-origin-width=&quot;1615&quot; data-origin-height=&quot;137&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
tool: BrowsingHistoryView&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;BrowsingHistoryView&lt;/b&gt;&lt;/h4&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;여러 웹 브라우저의 방문 데이터를 읽고 모든 방문기록을 하나의 테이블에 표시하는 프로그램이다.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;734&quot; data-origin-height=&quot;982&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/cHJWGw/btsKqCfNwxO/E3RHAZTR6D0Yz3HzYf4Bl0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/cHJWGw/btsKqCfNwxO/E3RHAZTR6D0Yz3HzYf4Bl0/img.png&quot; data-alt=&quot;방문기록을 가져올 기준과 웹브라우저 종류를 설정할 수 있다.&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/cHJWGw/btsKqCfNwxO/E3RHAZTR6D0Yz3HzYf4Bl0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FcHJWGw%2FbtsKqCfNwxO%2FE3RHAZTR6D0Yz3HzYf4Bl0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;386&quot; height=&quot;516&quot; data-origin-width=&quot;734&quot; data-origin-height=&quot;982&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;방문기록을 가져올 기준과 웹브라우저 종류를 설정할 수 있다.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1428&quot; data-origin-height=&quot;797&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/6Q91q/btsKqv185e2/SD227K2Aiz5zKlu92SLih0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/6Q91q/btsKqv185e2/SD227K2Aiz5zKlu92SLih0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/6Q91q/btsKqv185e2/SD227K2Aiz5zKlu92SLih0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2F6Q91q%2FbtsKqv185e2%2FSD227K2Aiz5zKlu92SLih0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;634&quot; height=&quot;354&quot; data-origin-width=&quot;1428&quot; data-origin-height=&quot;797&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1103&quot; data-origin-height=&quot;605&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/cj281C/btsKpPmB13S/yaUmlk7n02qTOQdUMWIUU0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/cj281C/btsKpPmB13S/yaUmlk7n02qTOQdUMWIUU0/img.png&quot; data-alt=&quot;url, 페이지 title, 방문 시각과 횟수 등 자세한 정보를 확인할 수 있다.&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/cj281C/btsKpPmB13S/yaUmlk7n02qTOQdUMWIUU0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fcj281C%2FbtsKpPmB13S%2FyaUmlk7n02qTOQdUMWIUU0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;543&quot; height=&quot;298&quot; data-origin-width=&quot;1103&quot; data-origin-height=&quot;605&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;url, 페이지 title, 방문 시각과 횟수 등 자세한 정보를 확인할 수 있다.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4 style=&quot;color: #000000; text-align: start;&quot; data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;Hindsight&lt;/b&gt;&lt;/h4&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;hindsight_gui.exe를 실행시키면 아래와 같은 창이 뜬다.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1574&quot; data-origin-height=&quot;851&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bx2kfn/btsKpSqfGg9/h8yIJ5bZUBXrPkKb9VEcXK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bx2kfn/btsKpSqfGg9/h8yIJ5bZUBXrPkKb9VEcXK/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bx2kfn/btsKpSqfGg9/h8yIJ5bZUBXrPkKb9VEcXK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fbx2kfn%2FbtsKpSqfGg9%2Fh8yIJ5bZUBXrPkKb9VEcXK%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;647&quot; height=&quot;350&quot; data-origin-width=&quot;1574&quot; data-origin-height=&quot;851&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;http://localhost:8080/으로 접속해보자.&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1873&quot; data-origin-height=&quot;905&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bEg9ev/btsKqv2o4aT/lY2xFklT0KnKAGSdE0h9a1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bEg9ev/btsKqv2o4aT/lY2xFklT0KnKAGSdE0h9a1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bEg9ev/btsKqv2o4aT/lY2xFklT0KnKAGSdE0h9a1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbEg9ev%2FbtsKqv2o4aT%2FlY2xFklT0KnKAGSdE0h9a1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;674&quot; height=&quot;326&quot; data-origin-width=&quot;1873&quot; data-origin-height=&quot;905&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;위의 Profile Path 부분에 autopsy등에서 extract한 &lt;span style=&quot;color: #333333; text-align: start;&quot;&gt;파일 경로를 넣는다&lt;/span&gt;.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;이 때 timezone은 우리나라에 맞춰 설정해준다.&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1048&quot; data-origin-height=&quot;469&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/b7aQSw/btsKrdGJM2I/TzmhfjpVS29Ne5cupvenTK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/b7aQSw/btsKrdGJM2I/TzmhfjpVS29Ne5cupvenTK/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/b7aQSw/btsKrdGJM2I/TzmhfjpVS29Ne5cupvenTK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fb7aQSw%2FbtsKrdGJM2I%2FTzmhfjpVS29Ne5cupvenTK%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;643&quot; height=&quot;288&quot; data-origin-width=&quot;1048&quot; data-origin-height=&quot;469&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;run을 누르면 아래와 같이 뜨는데, save xlsx를 누르면 엑셀 파일을 다운받을 수 있다.&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;915&quot; data-origin-height=&quot;524&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bTj8Q6/btsKrx53meF/KP2EUCpHIpkUOh93IoqLrk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bTj8Q6/btsKrx53meF/KP2EUCpHIpkUOh93IoqLrk/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bTj8Q6/btsKrx53meF/KP2EUCpHIpkUOh93IoqLrk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbTj8Q6%2FbtsKrx53meF%2FKP2EUCpHIpkUOh93IoqLrk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;603&quot; height=&quot;345&quot; data-origin-width=&quot;915&quot; data-origin-height=&quot;524&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;다음은 다운 받은 엑셀 파일이다.&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1362&quot; data-origin-height=&quot;788&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/VdXkc/btsKrQEgNZE/G2XkEOORiOe5LqUYdmMzf1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/VdXkc/btsKrQEgNZE/G2XkEOORiOe5LqUYdmMzf1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/VdXkc/btsKrQEgNZE/G2XkEOORiOe5LqUYdmMzf1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FVdXkc%2FbtsKrQEgNZE%2FG2XkEOORiOe5LqUYdmMzf1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;781&quot; height=&quot;452&quot; data-origin-width=&quot;1362&quot; data-origin-height=&quot;788&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;timestamp, url, titile, visit count 등의 다양한 정보를 얻을 수 있다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;참고링크: &lt;a href=&quot;https://biny-j.tistory.com/40&quot; target=&quot;_blank&quot; rel=&quot;noopener&amp;nbsp;noreferrer&quot;&gt;https://biny-j.tistory.com/40&lt;/a&gt;&lt;/p&gt;
&lt;figure id=&quot;og_1730339823578&quot; contenteditable=&quot;false&quot; data-ke-type=&quot;opengraph&quot; data-ke-align=&quot;alignCenter&quot; data-og-type=&quot;article&quot; data-og-title=&quot;웹 아티팩트의 종류별 특징 &amp;amp; 분석방법 파악&quot; data-og-description=&quot;웹 아티팩트(Web Artifcact)? 사용자 행위로 인해 웹 어플리케이션과 웹 브로우저가 통신하면서 생성되는 흔적이다. 웹 브라우저 쿠키, 웹 브라우저 히스토리, 웹 브라우저 다운로드 목록, 웹 캐시 &quot; data-og-host=&quot;biny-j.tistory.com&quot; data-og-source-url=&quot;https://biny-j.tistory.com/40&quot; data-og-url=&quot;https://biny-j.tistory.com/40&quot; data-og-image=&quot;https://scrap.kakaocdn.net/dn/dJ5SJ1/hyXpBvhezX/zkruFrSHSJ4aJRPkU7RlYK/img.png?width=600&amp;amp;height=450&amp;amp;face=0_0_600_450,https://scrap.kakaocdn.net/dn/b7OHLF/hyXpsyjYgt/TJacwtocqYz1pCetSXsQB1/img.png?width=600&amp;amp;height=450&amp;amp;face=0_0_600_450,https://scrap.kakaocdn.net/dn/ch6WV0/hyXs4o0Wr4/lEbvndpJRhZpGbz05a8KJ0/img.jpg?width=1024&amp;amp;height=1024&amp;amp;face=0_0_1024_1024&quot;&gt;&lt;a href=&quot;https://biny-j.tistory.com/40&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; data-source-url=&quot;https://biny-j.tistory.com/40&quot;&gt;
&lt;div class=&quot;og-image&quot; style=&quot;background-image: url('https://scrap.kakaocdn.net/dn/dJ5SJ1/hyXpBvhezX/zkruFrSHSJ4aJRPkU7RlYK/img.png?width=600&amp;amp;height=450&amp;amp;face=0_0_600_450,https://scrap.kakaocdn.net/dn/b7OHLF/hyXpsyjYgt/TJacwtocqYz1pCetSXsQB1/img.png?width=600&amp;amp;height=450&amp;amp;face=0_0_600_450,https://scrap.kakaocdn.net/dn/ch6WV0/hyXs4o0Wr4/lEbvndpJRhZpGbz05a8KJ0/img.jpg?width=1024&amp;amp;height=1024&amp;amp;face=0_0_1024_1024');&quot;&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;og-text&quot;&gt;
&lt;p class=&quot;og-title&quot; data-ke-size=&quot;size16&quot;&gt;웹 아티팩트의 종류별 특징 &amp;amp; 분석방법 파악&lt;/p&gt;
&lt;p class=&quot;og-desc&quot; data-ke-size=&quot;size16&quot;&gt;웹 아티팩트(Web Artifcact)? 사용자 행위로 인해 웹 어플리케이션과 웹 브로우저가 통신하면서 생성되는 흔적이다. 웹 브라우저 쿠키, 웹 브라우저 히스토리, 웹 브라우저 다운로드 목록, 웹 캐시&lt;/p&gt;
&lt;p class=&quot;og-host&quot; data-ke-size=&quot;size16&quot;&gt;biny-j.tistory.com&lt;/p&gt;
&lt;/div&gt;
&lt;/a&gt;&lt;/figure&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://secuworld.tistory.com/34&quot; target=&quot;_blank&quot; rel=&quot;noopener&amp;nbsp;noreferrer&quot;&gt;https://secuworld.tistory.com/34&lt;/a&gt;&lt;/p&gt;
&lt;figure id=&quot;og_1730339830649&quot; contenteditable=&quot;false&quot; data-ke-type=&quot;opengraph&quot; data-ke-align=&quot;alignCenter&quot; data-og-type=&quot;article&quot; data-og-title=&quot;웹 분석-Chrome&quot; data-og-description=&quot;웹 분석-Chrome 아티팩트 저장 경로 Cache %USERPROFILE%\AppData\Local\google\chrome\user data\default\cache 폴더 History %USERPROFILE%\AppData\Local\google\chrome\user data\default\history 파일 History파일에는 사용자가 방문한 URL &quot; data-og-host=&quot;secuworld.tistory.com&quot; data-og-source-url=&quot;https://secuworld.tistory.com/34&quot; data-og-url=&quot;https://secuworld.tistory.com/34&quot; data-og-image=&quot;https://scrap.kakaocdn.net/dn/c5fNOV/hyXs4WQ2xp/KIY0I0pfzaztldX9BtkkJ1/img.png?width=800&amp;amp;height=371&amp;amp;face=0_0_800_371,https://scrap.kakaocdn.net/dn/B9G7F/hyXs2krcGR/SJ0bMQFjanj5DCRHYGmB1K/img.png?width=800&amp;amp;height=371&amp;amp;face=0_0_800_371,https://scrap.kakaocdn.net/dn/Rr1iB/hyXpAJWHe1/tU9FLtN8H5FBrppbK22GH0/img.png?width=1920&amp;amp;height=1020&amp;amp;face=0_0_1920_1020&quot;&gt;&lt;a href=&quot;https://secuworld.tistory.com/34&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; data-source-url=&quot;https://secuworld.tistory.com/34&quot;&gt;
&lt;div class=&quot;og-image&quot; style=&quot;background-image: url('https://scrap.kakaocdn.net/dn/c5fNOV/hyXs4WQ2xp/KIY0I0pfzaztldX9BtkkJ1/img.png?width=800&amp;amp;height=371&amp;amp;face=0_0_800_371,https://scrap.kakaocdn.net/dn/B9G7F/hyXs2krcGR/SJ0bMQFjanj5DCRHYGmB1K/img.png?width=800&amp;amp;height=371&amp;amp;face=0_0_800_371,https://scrap.kakaocdn.net/dn/Rr1iB/hyXpAJWHe1/tU9FLtN8H5FBrppbK22GH0/img.png?width=1920&amp;amp;height=1020&amp;amp;face=0_0_1920_1020');&quot;&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;og-text&quot;&gt;
&lt;p class=&quot;og-title&quot; data-ke-size=&quot;size16&quot;&gt;웹 분석-Chrome&lt;/p&gt;
&lt;p class=&quot;og-desc&quot; data-ke-size=&quot;size16&quot;&gt;웹 분석-Chrome 아티팩트 저장 경로 Cache %USERPROFILE%\AppData\Local\google\chrome\user data\default\cache 폴더 History %USERPROFILE%\AppData\Local\google\chrome\user data\default\history 파일 History파일에는 사용자가 방문한 URL&lt;/p&gt;
&lt;p class=&quot;og-host&quot; data-ke-size=&quot;size16&quot;&gt;secuworld.tistory.com&lt;/p&gt;
&lt;/div&gt;
&lt;/a&gt;&lt;/figure&gt;</description>
      <category>디지털포렌식</category>
      <category>BrowsingHistoryView</category>
      <category>hindsight</category>
      <category>디지털포렌식</category>
      <category>웹아티팩트</category>
      <author>gardenia02</author>
      <guid isPermaLink="true">https://gardenia02.tistory.com/3</guid>
      <comments>https://gardenia02.tistory.com/3#entry3comment</comments>
      <pubDate>Thu, 31 Oct 2024 13:22:38 +0900</pubDate>
    </item>
    <item>
      <title>프리패치(Prefetch), PECmd와 WinPrefetchView 사용법</title>
      <link>https://gardenia02.tistory.com/2</link>
      <description>&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;Prefetch&lt;/b&gt;&lt;/h4&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;윈도우 XP 이후 운영체제에서 제공하는 메모리 관리 정책이다. 이 파일은 특정 프로그램이 실행될 때 필요한 파일과 데이터를 미리 기록하여, 다음 실행 시 프로그램 로딩 시간을 줄이는 역할을 한다.&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;prefetch 파일의 주요 가능은 다음과 같다.&lt;/p&gt;
&lt;ol style=&quot;list-style-type: decimal;&quot; data-ke-list-type=&quot;decimal&quot;&gt;
&lt;li&gt;프로그램 실행 속도 향상: 프로그램 실행 시 필요한 파일과 데이터를 미리 로드하여 빠르게 실행할 수 있게 해준다.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;사용자 경험 최적화: 자주 실행되는 프로그램들의 정보를 미리 캐싱해 둠으로써, 시스템 성능을 최적화한다.&lt;/li&gt;
&lt;li&gt;진단 및 포렌식 자료: Prefetch 파일은 프로그램 실행 기록을 저장하기 때문에 시스템 진단이나 디지털 포렌식에서 유용한 정보를 제공한다.&lt;/li&gt;
&lt;/ol&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;prefetch 파일명은 *.pf이고, &lt;span style=&quot;color: #222222; text-align: start;&quot;&gt;C:\Windows\Prefetch에 저장된다.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;color: #222222; text-align: start;&quot;&gt;또한 prefetch 파일의 naming rule은 다음과 같다. 여기서 pf을 제외한 모든 문자는 대문자여야 한다.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;pre id=&quot;code_1727841135572&quot; class=&quot;bash&quot; data-ke-language=&quot;bash&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;[executable filename]-[Prefetch-hash(filepath)].pf&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;781&quot; data-origin-height=&quot;297&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bCXGm1/btsJTER9QJ9/7lywQoUmH18HnZR6en4lGK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bCXGm1/btsJTER9QJ9/7lywQoUmH18HnZR6en4lGK/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bCXGm1/btsJTER9QJ9/7lywQoUmH18HnZR6en4lGK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbCXGm1%2FbtsJTER9QJ9%2F7lywQoUmH18HnZR6en4lGK%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;621&quot; height=&quot;236&quot; data-origin-width=&quot;781&quot; data-origin-height=&quot;297&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;color: #222222; text-align: start;&quot;&gt;prefetch 파일을 HxD로 열어보면 MAM 시그니처가 보인다.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1092&quot; data-origin-height=&quot;232&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/cF09RS/btsJTKELwZc/OiQMxvWHjEAc60RLKfM8z1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/cF09RS/btsJTKELwZc/OiQMxvWHjEAc60RLKfM8z1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/cF09RS/btsJTKELwZc/OiQMxvWHjEAc60RLKfM8z1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FcF09RS%2FbtsJTKELwZc%2FOiQMxvWHjEAc60RLKfM8z1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;620&quot; height=&quot;132&quot; data-origin-width=&quot;1092&quot; data-origin-height=&quot;232&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;color: #222222; text-align: start;&quot;&gt;이는 압축된 상태의 파일로, decompress을 해야 파일 분석이 가능하다. decompress 하는 코드는 다음 링크를 참고해라.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;color: #222222; text-align: start;&quot;&gt;&lt;a href=&quot;https://kali-km.tistory.com/entry/XPRESS-Decompress-by-Python&quot; target=&quot;_blank&quot; rel=&quot;noopener&amp;nbsp;noreferrer&quot;&gt;https://kali-km.tistory.com/entry/XPRESS-Decompress-by-Python&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;figure id=&quot;og_1727842221927&quot; contenteditable=&quot;false&quot; data-ke-type=&quot;opengraph&quot; data-ke-align=&quot;alignCenter&quot; data-og-type=&quot;article&quot; data-og-title=&quot;XPRESS Decompress by Python&quot; data-og-description=&quot; &quot; data-og-host=&quot;kali-km.tistory.com&quot; data-og-source-url=&quot;https://kali-km.tistory.com/entry/XPRESS-Decompress-by-Python&quot; data-og-url=&quot;https://kali-km.tistory.com/entry/XPRESS-Decompress-by-Python&quot; data-og-image=&quot;https://scrap.kakaocdn.net/dn/tclTF/hyXaC161TS/OSHeVIM4p6Zn6dhaNxKnQk/img.png?width=800&amp;amp;height=800&amp;amp;face=0_0_800_800,https://scrap.kakaocdn.net/dn/wg04b/hyXau32h91/8LVrrLgwGUFEBRnsTm39CK/img.png?width=800&amp;amp;height=800&amp;amp;face=0_0_800_800,https://scrap.kakaocdn.net/dn/sGCAi/hyXazEftH8/MKP8Ece3K3NzIrFskvDD11/img.jpg?width=709&amp;amp;height=403&amp;amp;face=0_0_709_403&quot;&gt;&lt;a href=&quot;https://kali-km.tistory.com/entry/XPRESS-Decompress-by-Python&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; data-source-url=&quot;https://kali-km.tistory.com/entry/XPRESS-Decompress-by-Python&quot;&gt;
&lt;div class=&quot;og-image&quot; style=&quot;background-image: url('https://scrap.kakaocdn.net/dn/tclTF/hyXaC161TS/OSHeVIM4p6Zn6dhaNxKnQk/img.png?width=800&amp;amp;height=800&amp;amp;face=0_0_800_800,https://scrap.kakaocdn.net/dn/wg04b/hyXau32h91/8LVrrLgwGUFEBRnsTm39CK/img.png?width=800&amp;amp;height=800&amp;amp;face=0_0_800_800,https://scrap.kakaocdn.net/dn/sGCAi/hyXazEftH8/MKP8Ece3K3NzIrFskvDD11/img.jpg?width=709&amp;amp;height=403&amp;amp;face=0_0_709_403');&quot;&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;og-text&quot;&gt;
&lt;p class=&quot;og-title&quot; data-ke-size=&quot;size16&quot;&gt;XPRESS Decompress by Python&lt;/p&gt;
&lt;p class=&quot;og-desc&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class=&quot;og-host&quot; data-ke-size=&quot;size16&quot;&gt;kali-km.tistory.com&lt;/p&gt;
&lt;/div&gt;
&lt;/a&gt;&lt;/figure&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;압축 해제를 완료하면 다음과 같이 SCCA 시그니처가 보인다.&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1084&quot; data-origin-height=&quot;230&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/boSHPz/btsJTo28dLH/kfpDDKH9hkknt7XJmqV9N1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/boSHPz/btsJTo28dLH/kfpDDKH9hkknt7XJmqV9N1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/boSHPz/btsJTo28dLH/kfpDDKH9hkknt7XJmqV9N1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FboSHPz%2FbtsJTo28dLH%2FkfpDDKH9hkknt7XJmqV9N1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;633&quot; height=&quot;134&quot; data-origin-width=&quot;1084&quot; data-origin-height=&quot;230&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;color: #222222; text-align: start;&quot;&gt;파일 포멧은 다음과 같다.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1299&quot; data-origin-height=&quot;602&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/REOkv/btsJSH95T37/t361kaUBSRdYKU2JOa9Ad0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/REOkv/btsJSH95T37/t361kaUBSRdYKU2JOa9Ad0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/REOkv/btsJSH95T37/t361kaUBSRdYKU2JOa9Ad0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FREOkv%2FbtsJSH95T37%2Ft361kaUBSRdYKU2JOa9Ad0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;746&quot; height=&quot;346&quot; data-origin-width=&quot;1299&quot; data-origin-height=&quot;602&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #222222; text-align: start;&quot;&gt;포렌식에서의 Prefetch 활용&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;color: #222222; text-align: start;&quot;&gt;prefetch 파일을 통해 알 수 있는 정보는 다음과 같다. &lt;/span&gt;&lt;/p&gt;
&lt;ul style=&quot;list-style-type: disc;&quot; data-ke-list-type=&quot;disc&quot;&gt;
&lt;li&gt;실행 파일의 이름과 전체 경로&lt;/li&gt;
&lt;li&gt;실행 횟수&lt;/li&gt;
&lt;li&gt;마지막 실행 시간&lt;/li&gt;
&lt;li&gt;볼륨 관련 정보: 볼륨 장치 경로, 볼륨 일련 번호, 볼륨 생성 시간 등&lt;/li&gt;
&lt;li&gt;참조된 리소스 목록: 실행에 필요한 DLL 파일들&lt;/li&gt;
&lt;li&gt;참조된 파일 목록(최근에 사용된 파일들) &lt;br /&gt;ex) Microsoft Word, Excel, PowerPoint, 7z, Bandizip, Notepad++, Visual Studio Code&lt;/li&gt;
&lt;li&gt;생성 시간 (Created time)&lt;br /&gt;prefetch 파일이 생성된 시각은 exe 파일이 처음 실행된 시각과 같다.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;수정 시간 (Modified time)&lt;/li&gt;
&lt;li&gt;접근 시간 (Access time)&lt;/li&gt;
&lt;li&gt;마지막 실행 시간 (Last execution times)&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;Prefetch 파일 분석 도구: PECmd&lt;/b&gt;&lt;/h4&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;먼저 PECmd.exe가 존재하는 경로로 들어간 후 아래의 명령어를 입력한다.&amp;nbsp;&lt;/p&gt;
&lt;pre id=&quot;code_1727849010850&quot; class=&quot;bash&quot; data-ke-language=&quot;bash&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;./PECmd -f [*.pf 파일 경로]&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1693&quot; data-origin-height=&quot;763&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/p8dVk/btsJStknfps/hHyISCf62eRZEdjmqXgUx1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/p8dVk/btsJStknfps/hHyISCf62eRZEdjmqXgUx1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/p8dVk/btsJStknfps/hHyISCf62eRZEdjmqXgUx1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fp8dVk%2FbtsJStknfps%2FhHyISCf62eRZEdjmqXgUx1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;1693&quot; height=&quot;763&quot; data-origin-width=&quot;1693&quot; data-origin-height=&quot;763&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;created time, modified time, last accessed time, last run time 등을 확인할 수 있다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;주의할 점은 이 시간들이 모두 영국 시간 기준(UTF+00:00)이기 때문에 한국 시간 (UTC+09:00)으로 변환해줘야 한다.&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4 style=&quot;color: #000000; text-align: start;&quot; data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;Prefetch 파일 분석 도구: WinPrefetchView&lt;/b&gt;&lt;/h4&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;WinPrefetchView.exe를 실행시키면 다음과 같은 화면이 뜬다.&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1635&quot; data-origin-height=&quot;970&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/dspLor/btsJSMcSfoo/yMBi70nlFAhwg1A4vSwjAK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/dspLor/btsJSMcSfoo/yMBi70nlFAhwg1A4vSwjAK/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/dspLor/btsJSMcSfoo/yMBi70nlFAhwg1A4vSwjAK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FdspLor%2FbtsJSMcSfoo%2FyMBi70nlFAhwg1A4vSwjAK%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;776&quot; height=&quot;460&quot; data-origin-width=&quot;1635&quot; data-origin-height=&quot;970&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;아이콘, 경로, 실행시각을 알 수 있고, 분석하고 싶은 파일을 더블 클릭하면 더 자세한 정보들이 나온다.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;720&quot; data-origin-height=&quot;417&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/zXjzN/btsJT4p0Nof/1cPMdS4n8KT9OfV1QhDVfk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/zXjzN/btsJT4p0Nof/1cPMdS4n8KT9OfV1QhDVfk/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/zXjzN/btsJT4p0Nof/1cPMdS4n8KT9OfV1QhDVfk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FzXjzN%2FbtsJT4p0Nof%2F1cPMdS4n8KT9OfV1QhDVfk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;455&quot; height=&quot;264&quot; data-origin-width=&quot;720&quot; data-origin-height=&quot;417&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;</description>
      <category>디지털포렌식</category>
      <category>pecmd</category>
      <category>prefetch</category>
      <category>winprefetchview</category>
      <category>디지털포렌식</category>
      <category>프리패치</category>
      <author>gardenia02</author>
      <guid isPermaLink="true">https://gardenia02.tistory.com/2</guid>
      <comments>https://gardenia02.tistory.com/2#entry2comment</comments>
      <pubDate>Wed, 2 Oct 2024 15:17:25 +0900</pubDate>
    </item>
    <item>
      <title>이벤트 로그, EvtxECmd 사용법</title>
      <link>https://gardenia02.tistory.com/1</link>
      <description>&lt;p data-ke-size=&quot;size18&quot;&gt;&lt;b&gt;이벤트 로그&lt;/b&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;컴퓨터 시스템에서 이벤트 로그는 하드웨어와 소프트웨어 이벤트에 대한 정보를 기록한다.&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;이 중에서 특히 windows 이벤트 로그는 일반적으로 세 가지 범주 중 하나로 분류된다.&lt;/p&gt;
&lt;ol style=&quot;list-style-type: decimal;&quot; data-ke-list-type=&quot;decimal&quot;&gt;
&lt;li&gt;시스템 관련 이벤트(System.evtx)&lt;br /&gt;운영 체제 자체에서 발생하는 이벤트&lt;/li&gt;
&lt;li&gt;보안 이벤트(Security.evtx)&lt;br /&gt;로그인/로그아웃 이벤트&lt;/li&gt;
&lt;li&gt;애플리케이션 이벤트(Application.evtx)&lt;br /&gt;Windows에서 실행 중인 애플리케이션이 기록한 이벤트&lt;/li&gt;
&lt;/ol&gt;
&lt;p style=&quot;color: #333333; text-align: start;&quot; data-ke-size=&quot;size18&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;color: #333333; text-align: start;&quot; data-ke-size=&quot;size18&quot;&gt;&lt;b&gt;이벤트 로그 분석 도구: EvtxECmd&lt;/b&gt;&lt;/p&gt;
&lt;p style=&quot;color: #333333; text-align: start;&quot; data-ke-size=&quot;size16&quot;&gt;이벤트 로그를 분석하는 도구 중 대표적인 것이 EvtxECmd이다. 이 툴의 사용법을 알아보자.&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;color: #333333; text-align: start;&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;color: #333333; text-align: start;&quot; data-ke-size=&quot;size16&quot;&gt;Security 로그 파일을 파싱해보자.&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;color: #333333; text-align: start;&quot; data-ke-size=&quot;size16&quot;&gt;여기서 주의할 점은 powershell을 관리자 권한으로 실행시켜야 한다는 점이다.&lt;/p&gt;
&lt;p style=&quot;color: #333333; text-align: start;&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;color: #333333; text-align: start;&quot; data-ke-size=&quot;size16&quot;&gt;이벤트 로그의 경로는 다음과 같다.&lt;/p&gt;
&lt;p style=&quot;color: #333333; text-align: start;&quot; data-ke-size=&quot;size16&quot;&gt;&lt;i&gt;&lt;u&gt;C:\Windows\System32\winevt\Logs&lt;/u&gt;&lt;/i&gt;&lt;/p&gt;
&lt;pre id=&quot;code_1726107250597&quot; class=&quot;bash&quot; data-ke-language=&quot;bash&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;./EvtxECmd -f &quot;이벤트 로그 파일 경로&quot; --csvf [파일이름]&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1920&quot; data-origin-height=&quot;1200&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/LM5TV/btsJzHI46xH/z6Cac9CqAomiBbKsGZmIl1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/LM5TV/btsJzHI46xH/z6Cac9CqAomiBbKsGZmIl1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/LM5TV/btsJzHI46xH/z6Cac9CqAomiBbKsGZmIl1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FLM5TV%2FbtsJzHI46xH%2Fz6Cac9CqAomiBbKsGZmIl1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;1920&quot; height=&quot;1200&quot; data-origin-width=&quot;1920&quot; data-origin-height=&quot;1200&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;결과로 출력된 Event ID 각각의 의미는 다음과 같다:&lt;/p&gt;
&lt;ul style=&quot;list-style-type: disc;&quot; data-ke-list-type=&quot;disc&quot;&gt;
&lt;li&gt;4616: 시스템 시간 변경&lt;/li&gt;
&lt;li&gt;4624: 성공적인 로그인 이벤트&lt;br /&gt;누가 언제 로그인했는지를 추적하는 데 사용됨&amp;nbsp;&lt;/li&gt;
&lt;li&gt;4634: 사용자 로그오프 이벤트&lt;/li&gt;
&lt;li&gt;4648: 명시적인 인증을 사용한 로그온 시도&amp;nbsp;&lt;/li&gt;
&lt;li&gt;4672: 특권 계정으로 로그온할 때 발생&amp;nbsp;&lt;br /&gt;관리자는 특권을 가진 계정으로 로그인할 때 추가 권한을 부여받는다. 이 이벤트는 특권이 필요한 작업을 수행할 수 있는 계정이 시스템에 로그인할 때 기록된다.&amp;nbsp;&lt;br /&gt;*특권&lt;br /&gt;&lt;b&gt;- &lt;/b&gt;SeSecurityPrivilege: 보안 로그 관리&lt;br /&gt;- SeBackupPrivilege: 백업 파일 및 디렉터리&lt;br /&gt;- SeRestorePrivilege: 파일 및 디렉터리 복원&lt;br /&gt;- SeTakeOwnershipPrivilege: 파일이나 다른 리소스 소유권 획득&lt;/li&gt;
&lt;li&gt;4673: 특권 서비스 요청 이벤트 &lt;br /&gt;사용자가 고급 권한을 요구하는 작업을 실행할 때 기록된다. 이는 관리자 권한이 필요한 작업을 수행하려는 시도를 나타낸다.&lt;/li&gt;
&lt;li&gt;4797: 그룹 정책을 통해 원격 서비스 로그온이 발생함&lt;/li&gt;
&lt;li&gt;4798: 로컬 그룹 멤버 자격을 쿼리하는 이벤트 &lt;br /&gt;누군가 시스템의 로컬 그룹 멤버십을 조회할 때 발생한다. 이는 시스템 권한 또는 계정 정보에 접근하려는 시도를 모니터링하는 데 중요하다.&lt;/li&gt;
&lt;li&gt;4799: 로컬 그룹 멤버 자격을 쿼리한 결과를 나타냄&lt;br /&gt;로컬 그룹 멤버십 쿼리에 대한 응답으로 발생하는 이벤트로, 조회된 그룹 멤버십 정보가 반환되었음을 의미한다.&lt;/li&gt;
&lt;li&gt;5061: 암호화된 키가 사용된 이벤트&lt;/li&gt;
&lt;li&gt;5379: 파일 무결성 확인을 위한 인증서 서비스 요청&lt;/li&gt;
&lt;li&gt;5382: Cryptographic 모듈에서 키 삭제 작업이 발생했을 때 기록됨&lt;/li&gt;
&lt;/ul&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;추가로, 다음은 보안과 관련된 몇 가지 Event ID이다.&lt;/p&gt;
&lt;ul style=&quot;list-style-type: disc;&quot; data-ke-list-type=&quot;disc&quot;&gt;
&lt;li&gt;4735, 4737, 4739: 그룹 변경&lt;br /&gt;보안 그룹의 변경은 권한을 상승시키거나 액세스 제어를 수정하려는 시도&lt;/li&gt;
&lt;li&gt;4907: 감사 정책 변경&lt;br /&gt;감사 설정이 반복적으로 변경되었음을 의미, 악의적인 활동을 숨기기 위해 변경되었을 가능성이 있음&lt;/li&gt;
&lt;li&gt;5379: 자격 증명 관리자의 자격 증명 읽기&lt;br /&gt;자격 증명을 탈취하려는 시도를 나타낼 수 있음&lt;/li&gt;
&lt;/ul&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;추가로, 위의 결과를 json 형태로 저장하고 싶으면 아래와 같이 입력하면 된다.&lt;/p&gt;
&lt;pre id=&quot;code_1726108677389&quot; class=&quot;bash&quot; data-ke-language=&quot;bash&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;./EvtxECmd -f &quot;이벤트 로그 파일 경로&quot; --json &quot;파일을 저장할 경로&quot;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1920&quot; data-origin-height=&quot;1200&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/Xil6S/btsJzUH10EO/guRM9YoiCxrPFS4myT9e90/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/Xil6S/btsJzUH10EO/guRM9YoiCxrPFS4myT9e90/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/Xil6S/btsJzUH10EO/guRM9YoiCxrPFS4myT9e90/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FXil6S%2FbtsJzUH10EO%2FguRM9YoiCxrPFS4myT9e90%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;1920&quot; height=&quot;1200&quot; data-origin-width=&quot;1920&quot; data-origin-height=&quot;1200&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;사용 가능한 기타 옵션은 다음 사진과 링크를 참고해라.&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1819&quot; data-origin-height=&quot;562&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/uZQ2k/btsJIOIi5Zs/vkoY3EFoQa2QZCyC5DvYI1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/uZQ2k/btsJIOIi5Zs/vkoY3EFoQa2QZCyC5DvYI1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/uZQ2k/btsJIOIi5Zs/vkoY3EFoQa2QZCyC5DvYI1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FuZQ2k%2FbtsJIOIi5Zs%2FvkoY3EFoQa2QZCyC5DvYI1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;1819&quot; height=&quot;562&quot; data-origin-width=&quot;1819&quot; data-origin-height=&quot;562&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://binaryforay.blogspot.com/2019/04/introducing-evtxecmd.html&quot; target=&quot;_blank&quot; rel=&quot;noopener&amp;nbsp;noreferrer&quot;&gt;https://binaryforay.blogspot.com/2019/04/introducing-evtxecmd.html&lt;/a&gt;&lt;/p&gt;
&lt;figure id=&quot;og_1727074908627&quot; contenteditable=&quot;false&quot; data-ke-type=&quot;opengraph&quot; data-ke-align=&quot;alignCenter&quot; data-og-type=&quot;website&quot; data-og-title=&quot;Introducing EvtxECmd!!&quot; data-og-description=&quot;I am happy to announce the first beta version of my Windows Event Log (evtx) parser. We will be talking about the command line version today...&quot; data-og-host=&quot;binaryforay.blogspot.com&quot; data-og-source-url=&quot;https://binaryforay.blogspot.com/2019/04/introducing-evtxecmd.html&quot; data-og-url=&quot;https://binaryforay.blogspot.com/2019/04/introducing-evtxecmd.html&quot; data-og-image=&quot;https://scrap.kakaocdn.net/dn/bfdw1Z/hyW6FqAjC8/TDefumNzGSM68J6JdsTvkK/img.jpg?width=1200&amp;amp;height=630&amp;amp;face=0_0_1200_630&quot;&gt;&lt;a href=&quot;https://binaryforay.blogspot.com/2019/04/introducing-evtxecmd.html&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; data-source-url=&quot;https://binaryforay.blogspot.com/2019/04/introducing-evtxecmd.html&quot;&gt;
&lt;div class=&quot;og-image&quot; style=&quot;background-image: url('https://scrap.kakaocdn.net/dn/bfdw1Z/hyW6FqAjC8/TDefumNzGSM68J6JdsTvkK/img.jpg?width=1200&amp;amp;height=630&amp;amp;face=0_0_1200_630');&quot;&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;og-text&quot;&gt;
&lt;p class=&quot;og-title&quot; data-ke-size=&quot;size16&quot;&gt;Introducing EvtxECmd!!&lt;/p&gt;
&lt;p class=&quot;og-desc&quot; data-ke-size=&quot;size16&quot;&gt;I am happy to announce the first beta version of my Windows Event Log (evtx) parser. We will be talking about the command line version today...&lt;/p&gt;
&lt;p class=&quot;og-host&quot; data-ke-size=&quot;size16&quot;&gt;binaryforay.blogspot.com&lt;/p&gt;
&lt;/div&gt;
&lt;/a&gt;&lt;/figure&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;참고링크: &lt;a href=&quot;https://medium.com/@hammazahmed40/exploring-evtxecmd-a-beginners-guide-to-parsing-windows-event-logs-0f67115ac7cd&quot; target=&quot;_blank&quot; rel=&quot;noopener&amp;nbsp;noreferrer&quot;&gt;https://medium.com/@hammazahmed40/exploring-evtxecmd-a-beginners-guide-to-parsing-windows-event-logs-0f67115ac7cd&lt;/a&gt;&lt;/p&gt;
&lt;figure id=&quot;og_1727074021545&quot; contenteditable=&quot;false&quot; data-ke-type=&quot;opengraph&quot; data-ke-align=&quot;alignCenter&quot; data-og-type=&quot;article&quot; data-og-title=&quot;Exploring EvtxECmd: A Beginner&amp;rsquo;s Guide to Parsing Windows Event Logs&quot; data-og-description=&quot;Hey everyone! Today, we&amp;rsquo;re diving into a powerful command-line tool called EvtxECmd, part of Eric Zimmerman&amp;rsquo;s suite of forensic tools.&quot; data-og-host=&quot;medium.com&quot; data-og-source-url=&quot;https://medium.com/@hammazahmed40/exploring-evtxecmd-a-beginners-guide-to-parsing-windows-event-logs-0f67115ac7cd&quot; data-og-url=&quot;https://medium.com/@hammazahmed40/exploring-evtxecmd-a-beginners-guide-to-parsing-windows-event-logs-0f67115ac7cd&quot; data-og-image=&quot;https://scrap.kakaocdn.net/dn/vie6X/hyW6BuWC7t/1KOF8i5BxTfx6S6Its2KYK/img.png?width=841&amp;amp;height=466&amp;amp;face=0_0_841_466&quot;&gt;&lt;a href=&quot;https://medium.com/@hammazahmed40/exploring-evtxecmd-a-beginners-guide-to-parsing-windows-event-logs-0f67115ac7cd&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; data-source-url=&quot;https://medium.com/@hammazahmed40/exploring-evtxecmd-a-beginners-guide-to-parsing-windows-event-logs-0f67115ac7cd&quot;&gt;
&lt;div class=&quot;og-image&quot; style=&quot;background-image: url('https://scrap.kakaocdn.net/dn/vie6X/hyW6BuWC7t/1KOF8i5BxTfx6S6Its2KYK/img.png?width=841&amp;amp;height=466&amp;amp;face=0_0_841_466');&quot;&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;og-text&quot;&gt;
&lt;p class=&quot;og-title&quot; data-ke-size=&quot;size16&quot;&gt;Exploring EvtxECmd: A Beginner&amp;rsquo;s Guide to Parsing Windows Event Logs&lt;/p&gt;
&lt;p class=&quot;og-desc&quot; data-ke-size=&quot;size16&quot;&gt;Hey everyone! Today, we&amp;rsquo;re diving into a powerful command-line tool called EvtxECmd, part of Eric Zimmerman&amp;rsquo;s suite of forensic tools.&lt;/p&gt;
&lt;p class=&quot;og-host&quot; data-ke-size=&quot;size16&quot;&gt;medium.com&lt;/p&gt;
&lt;/div&gt;
&lt;/a&gt;&lt;/figure&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://www.crowdstrike.com/cybersecurity-101/observability/event-log/&quot; target=&quot;_blank&quot; rel=&quot;noopener&amp;nbsp;noreferrer&quot;&gt;https://www.crowdstrike.com/cybersecurity-101/observability/event-log/&lt;/a&gt;&lt;/p&gt;
&lt;figure id=&quot;og_1727074027986&quot; contenteditable=&quot;false&quot; data-ke-type=&quot;opengraph&quot; data-ke-align=&quot;alignCenter&quot; data-og-type=&quot;article&quot; data-og-title=&quot;What is an Event Log? Contents and Use - CrowdStrike&quot; data-og-description=&quot;An event is any significant action or occurence that's recognized by a software system and is then recorded in a special file called the event log.&quot; data-og-host=&quot;www.crowdstrike.com&quot; data-og-source-url=&quot;https://www.crowdstrike.com/cybersecurity-101/observability/event-log/&quot; data-og-url=&quot;https://www.crowdstrike.com/cybersecurity-101/observability/event-log/&quot; data-og-image=&quot;https://scrap.kakaocdn.net/dn/cHVks7/hyW6ySw9A5/DjoaVZI9cWcFxPhvaalBx0/img.png?width=421&amp;amp;height=260&amp;amp;face=0_0_421_260,https://scrap.kakaocdn.net/dn/dzCvSW/hyW6IOn60x/q8aEsNcnQ3wObqF6LvUAs1/img.png?width=500&amp;amp;height=300&amp;amp;face=0_0_500_300,https://scrap.kakaocdn.net/dn/bOJiBl/hyW6MpKvSB/xjxVRADvxiEKlyrHz0WkO1/img.png?width=421&amp;amp;height=260&amp;amp;face=0_0_421_260&quot;&gt;&lt;a href=&quot;https://www.crowdstrike.com/cybersecurity-101/observability/event-log/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; data-source-url=&quot;https://www.crowdstrike.com/cybersecurity-101/observability/event-log/&quot;&gt;
&lt;div class=&quot;og-image&quot; style=&quot;background-image: url('https://scrap.kakaocdn.net/dn/cHVks7/hyW6ySw9A5/DjoaVZI9cWcFxPhvaalBx0/img.png?width=421&amp;amp;height=260&amp;amp;face=0_0_421_260,https://scrap.kakaocdn.net/dn/dzCvSW/hyW6IOn60x/q8aEsNcnQ3wObqF6LvUAs1/img.png?width=500&amp;amp;height=300&amp;amp;face=0_0_500_300,https://scrap.kakaocdn.net/dn/bOJiBl/hyW6MpKvSB/xjxVRADvxiEKlyrHz0WkO1/img.png?width=421&amp;amp;height=260&amp;amp;face=0_0_421_260');&quot;&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;og-text&quot;&gt;
&lt;p class=&quot;og-title&quot; data-ke-size=&quot;size16&quot;&gt;What is an Event Log? Contents and Use - CrowdStrike&lt;/p&gt;
&lt;p class=&quot;og-desc&quot; data-ke-size=&quot;size16&quot;&gt;An event is any significant action or occurence that's recognized by a software system and is then recorded in a special file called the event log.&lt;/p&gt;
&lt;p class=&quot;og-host&quot; data-ke-size=&quot;size16&quot;&gt;www.crowdstrike.com&lt;/p&gt;
&lt;/div&gt;
&lt;/a&gt;&lt;/figure&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;</description>
      <category>디지털포렌식</category>
      <category>디지털포렌식</category>
      <category>이벤트로그</category>
      <author>gardenia02</author>
      <guid isPermaLink="true">https://gardenia02.tistory.com/1</guid>
      <comments>https://gardenia02.tistory.com/1#entry1comment</comments>
      <pubDate>Mon, 23 Sep 2024 16:02:13 +0900</pubDate>
    </item>
  </channel>
</rss>