windows 8 recovery forensics - digital forensics - sans · windows 8 recovery forensics...

69
WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

Upload: nguyenkhanh

Post on 10-Apr-2018

231 views

Category:

Documents


5 download

TRANSCRIPT

Page 1: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

WINDOWS 8

RECOVERY FORENSICS Understanding the Three R’s

W. Kenneth Johnson (@patories)

SANS DFIR SUMMIT 2012

Page 2: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

INTRODUCTION

Who Am I?

MS Student at Iowa State University

IT Security Analyst with Principal Financial Group

Forensic and Malware Researcher

Why are we here?

To understand the forensic impacts of Windows 8 Recovery options

Page 3: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

ISSUES

New System Recovery options with new challenges.

1. Availability

2. Data Recovery

3. Additional Artifacts

Today we will cover the following topics:

1. Recovery options Available

2. Forensic Implications

Page 4: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

TESTING ENVIRONMENT

Windows 8 installed in multiple VM instances

VMWare Workstation 8

FTK Imager

FTK ToolKit

Impact with Bitlocker enabled not tested

Solid State Drives not tested

Page 5: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVERY OPTIONS

System Restore Points

System Refresh Points

System Reset

Page 6: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SYSTEM RESTORE POINTS

What are they?

Page 7: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SYSTEM RESTORE POINT

Relevant Files

Every 7 Days

SRSetRestorePoint API

Page 8: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SYSTEM RESTORE – NEW REG KEYS

HKLM\Software\MS\WindowsNT\CurrentVersion\SystemRestore

SystemRestorePointCreationFrequency

ScopeSnapshots

Page 9: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SYSTEM RESTORE – ISSUES

Dual Boot Systems

Data Retention

Page 10: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SYSTEM REFRESH POINTS

What are they?

Page 11: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SYSTEM REFRESH POINT - PROCESS

Page 12: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SYSTEM REFRESH POINT - DEFAULT

What is Retained What is not Retained

Wireless Network Connections

Mobile Broadband Connections

BitLocker Settings

BitLocker To GO settings

Drive Letter Assignments

Personalization Settings

Metro Style Application

File Type Associations

Display Settings

Windows Firewalls

Desktop Installed Applications

Volume Shadow Copies

Restore Points

Page 13: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SYSTEM REFRESH POINT - CUSTOM

Desktop Applications

Default Refresh Behavior

No Volume Shadow Copies

Page 14: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SYSTEM REFRESH POINT

Default Restore with Install

Multiple

One

Start at Boot Time

Page 15: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SYSTEM REFRESH POINT - CUSTOM

How is it done?

RecImg.exe

ReAgent.exe

Page 16: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

System Refresh Point -

RecImg

Creates Custom Refresh Image

Image Directory can be on a Local,

Removable or Remote Drive.

Set a new current Image

Remove current image and revert back

to default

Shows the current image

Page 17: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

System Refresh Point -

ReAgentC

Where the WinRE is located

Configures if machine will start the

Recovery process at start up

Sets the location of recovery image

Page 18: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SYSTEM RESET

What are they?

Page 19: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SYSTEM RESET - PROCESS

Page 20: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SYSTEM RESET – INITIAL COMMANDS

Page 21: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SYSTEM RESET – INITIAL COMMADS

Page 22: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SYSTEM RESET – DATA WIPE OPTIONS

Quick Thorough

Good if you trust the person

you are giving it to.

Good if you are going to give to

charity.

Both options are not recommended for

cleaning a drive if a multi-pass scrubbing

operation is required!

Page 23: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

DIGITAL FORENSICS

Artifacts and Implications

Page 24: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RESTORE POINT ARTIFACTS

Accessible through multiple options

May contain the following previous versions:

Registry Settings

Documents and files

Applications

FileHistory Configuration

System Events

Page 25: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RESTORE POINTS - GUI

Page 26: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RESTORE POINT - VSSADMIN

Page 27: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RESTORE POINT – SYMBOLIC LINK

Page 28: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RESTORE POINT CONCERNS

Abuse

Page 29: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

REFRESH & RESET ARTIFACTS - OVERVIEW

Similar Artifacts found on the Boot System Volume

Different Artifacts found on the Operating System Volume

Different Artifacts based on type of Reset used

Page 30: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

REFRESH & RESET ARTIFACTS

Before Refresh/Reset After Refresh/Reset

Page 31: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

REFRESH & RESET ARTIFACTS

Before Refresh/Reset After Refresh/Restore

Page 32: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

REFRESH & RESET ARTIFACTS

Page 33: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

REFRESH & RESET – REAGENT.XML

ReAgentC

RecImg

Page 34: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

CUSTOM REFRESH – REAGENT.XML

Page 35: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

REFRESH & RESET – RELOAD.XML

Page 36: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

CUSTOM REFRESH – RELOAD.XML

Page 37: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

REFRESH ARTIFACTS

Boot System OS System

Reagent.xml

Reload.xml

Logs Directory

Unallocated Data

$SysReset

Windows.old

User files will be migrated over

FileHistory (if enabled)

Logs of migrated files

Logs of uninstalled applications

Logs of Migrated OS Updates

Page 38: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

PARTITION 2 ARTIFACTS - REFRESH

Before Refresh, or After Reset After Refresh Only

Page 39: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

REFRESH ARTIFACTS - $SYSRESET

Page 40: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

REFRESH ARTIFACTS – WINDOWS.OLD

Page 41: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

REFRESH ARTIFACTS – USERS DIRECTORY

Page 42: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

REFRESH ARTIFACTS – USERS DIRECTORY

Page 43: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVER ARTIFACTS - REFRESH

Page 44: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVER ARTIFACTS - REFRESH

Page 45: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVER ARTIFACTS - REFRESH

Page 46: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVERY ARTIFACTS - REFRESH

Page 47: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVERY ARTIFACTS – REFRESH

FILEHISTORY

Page 48: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVERY ARTIFACTS – REFRESH

FILEHISTORY

Page 49: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVERY ARTIFACTS – REFRESH

FILEHISTORY

Page 50: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

QUICK RESET ARTIFACTS

Boot System OS System

Reagent.xml

Reload.xml

Logs Directory

Unallocated Data

Must be Carved

Page 51: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVERY ARTIFACTS

Test Data

Page 52: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVER ARTIFACTS – QUICK RESET

Page 53: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVER ARTIFACTS – QUICK RESET

Page 54: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVER ARTIFACTS – QUICK RESET

Page 55: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVER ARTIFACTS – QUICK RESET

Page 56: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVER ARTIFACTS – QUICK RESET

Page 57: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVER ARTIFACTS – QUICK RESET

Page 58: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVER ARTIFACTS – QUICK RESET

Other Data Recoverable

Page 59: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

THOROUGH RESET ARTIFACTS

Boot System OS System

Reagent.xml

Reload.xml

Logs Directory

Unallocated Data

Difficult to be carved

Page 60: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVERY ARTIFACTS –

THOROUGH RESET

Page 61: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVERY ARTIFACTS –

THOROUGH RESET

Page 62: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVERY ARTIFACTS –

THOROUGH RESET

Page 63: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

RECOVERY ARTIFACTS –

THOROUGH RESET

Page 64: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SUMMARY

Review, Resources and links

Page 65: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

SUMMARY

Each Recovery option will leave unique Artifacts behind

System Restore Points are accessible using current technology

Refresh and Reset will leave similar artifacts in the Boot System

Refresh and Reset will destroy all System Restore Points on machine

Users Settings will persist over Refresh and Restore Point

Refresh will have a copy of the Registry file prior to refresh in

Windows.old

The thorough reset option does the best job of destroying the evidence

Page 66: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

WINDOWS 8 FORENSICS

Questions?

Page 68: Windows 8 Recovery Forensics - Digital Forensics - SANS · WINDOWS 8 RECOVERY FORENSICS Understanding the Three R’s W. Kenneth Johnson (@patories) SANS DFIR SUMMIT 2012

WINDOWS 8 RESOURCES

http://www.verboon.info/index.php/2012/01/the-windows-8-refresh-

your-pc-feature/

http://blogs.msdn.com/b/b8/archive/2012/01/04/refresh-and-reset-your-

pc.aspx