๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
  • Tried. Failed. Logged.
728x90

๐Ÿ”’์ •๋ณด๋ณด์•ˆ/๋””์ง€ํ„ธ ํฌ๋ Œ์‹16

๋””์ง€ํ„ธ ํฌ๋ Œ์‹ - ์ด๋ฏธ์ง€์™€ ์••์ถ• ํŒŒ์ผ(zip)์„ ๊ฒฐํ•ฉํ•˜๋Š” ๊ฐ„๋‹จํ•œ ์Šคํ…Œ๊ฐ€๋…ธ๊ทธ๋ž˜ํ”ผ ์‚ฌ์ „ ์ค€๋น„ ์ƒ๋Œ€๋ฐฉ์„ ์†์ผ ์ด๋ฏธ์ง€์™€ ์ˆจ๊ธฐ๊ณ  ์‹ถ์€ ํŒŒ์ผ์„ ์••์ถ•ํ•œ zip์„ ์ค€๋น„ํ•œ๋‹ค. cmd ์ฐฝ์„ ์—ด์–ด "copy /B ์ด๋ฏธ์ง€+์••์ถ•ํŒŒ์ผ ์ถœ๋ ฅ์ด๋ฆ„"์„ ์ž…๋ ฅํ•œ๋‹ค. (/B๋Š” ์ด์ง„ ํŒŒ์ผ ์˜ต์…˜์ด๋‹ค.) ์ถœ๋ ฅ๋œ ๊ฒฐ๊ณผ(output.zip)๋Š” ์ผ๋ฐ˜ ์ด๋ฏธ์ง€์™€ ๋˜‘๊ฐ™์•„ ๋ณด์ธ๋‹ค. ๋”๋ธ” ํด๋ฆญ์„ ํ•˜๋ฉด ์ด๋ฏธ์ง€ ๋ทฐ๋„ ์ •์ƒ์ ์œผ๋กœ ๋ถˆ๋Ÿฌ์˜จ๋‹ค. ํ•˜์ง€๋งŒ ์›๋ณธ๊ณผ ๋น„๊ตํ•˜๋ฉด ์šฉ๋Ÿ‰์ด ํ›จ์”ฌ ์ฆ๊ฐ€ํ•œ ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. ์—ฌ๊ธฐ์„œ ์ž ๊น ํ™•์žฅ์ž๋ฅผ .zip์œผ๋กœ ๋ณ€๊ฒฝํ•˜๋ฉด ํŒŒ์ผ ์•„์ด์ฝ˜์ด ๊นจ์ ธ ๋ณด์ด์ง€๋งŒ ๋”๋ธ” ํด๋ฆญ์„ ํ•˜๋ฉด ์••์ถ• ํ”„๋กœ๊ทธ๋žจ์ด ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ ์ •์ƒ์ ์œผ๋กœ ์—ด๋ฆฐ๋‹ค. ํ’€๊ธฐ๋„ ๊ฐ€๋Šฅํ•˜๊ณ  ํŒŒ์ผ ์ฝ˜ํ…์ธ ๋„ ๊ทธ๋Œ€๋กœ ์••์ถ• ํ•ด์ œ๊ฐ€ ๊ฐ€๋Šฅํ•˜๋‹ค. ๋‹ค์Œ์€ image.jpg์™€ output.zip์˜ ์‹œ์ž‘๊ณผ ์ค‘๊ฐ„ ์ชฝ์˜ ๋ฐ”์ด๋„ˆ๋ฆฌ๊ฐ€ ์ผ์น˜ํ•˜๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด๋ฏธ์ง€ ๋ทฐ์–ด ํ”„๋กœ๊ทธ๋žจ์€ ์ด๋ ‡๊ฒŒ ํŒŒ์ผ์˜ ์‹œ.. 2023. 8. 10.
๋””์ง€ํ„ธ ํฌ๋ Œ์‹ - PowerShell ๋ช…๋ น์–ด ๊ธฐ๋ก ์ €์žฅ ๊ฒฝ๋กœ(ConsoleHost_history.txt) ๋กœ๊ทธ ํŒŒ์ผ ๊ฒฝ๋กœ $env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt ์ฐธ๊ณ ๋กœ powershell -c ๋ช…๋ น์–ด ๊ฐ™์€ ๋ผ์ธ ์‹คํ–‰ ๋ช…๋ น์–ด๋Š” ๊ธฐ๋ก์ด ์•ˆ ๋˜๋Š” ๊ฒƒ์œผ๋กœ ๋ณด์ธ๋‹ค. ์ถœ์ฒ˜: https://www.reddit.com/r/computerforensics/comments/gqjhhw/does_windows_log_the_cmd_history/ r/computerforensics on Reddit: Does windows log the cmd histo.. 2023. 5. 12.
๋””์ง€ํ„ธ ํฌ๋ Œ์‹ - ํœด๋Œ€ํฐ, ์ปดํ“จํ„ฐ ์ €์žฅ ์žฅ์น˜๋ฅผ ๋ณต๊ตฌ ๋ถˆ๊ฐ€๋Šฅํ•˜๊ฒŒ ๋งŒ๋“œ๋Š” ๋ฐฉ๋ฒ• ํœด๋Œ€ํฐ 1. ๊ณต์žฅ ์ดˆ๊ธฐํ™” 2. ์˜์–ด ๋Œ€์†Œ๋ฌธ์ž + ์ˆซ์ž + ํŠน์ˆ˜๋ฌธ์ž ๋น„๋ฐ€๋ฒˆํ˜ธ ์•”ํ˜ธํ™” 12์ž๋ฆฌ ์ด์ƒ 3. ํœด๋Œ€ํฐ ์žฌ๋ถ€ํŒ… ํ˜น์€ ์ข…๋ฃŒ - ํœด๋Œ€ํฐ์— ์‚ฝ์ž…ํ–ˆ๋˜ SD ์นด๋“œ๋Š” ๋ฐ‘์˜ ๋ฐฉ๋ฒ•์„ ๋”ฐ๋ฅธ๋‹ค. ์ปดํ“จํ„ฐ(HDD, SDD, SD ์นด๋“œ) 0. BitLocker ์•”ํ˜ธํ™” 1. ์œˆ๋„์šฐ ์ž์ฒด ๊ธฐ๋Šฅ์ธ "๋น ๋ฅธ ํฌ๋งท" ์‚ฌ์šฉ 2. ๋กœ์šฐ ํฌ๋งท 3๋ฒˆ ์ด์ƒ(ํ˜น์€ cipher ๋ช…๋ น์–ด ์‚ฌ์šฉ "cipher /w:๋“œ๋ผ์ด๋ธŒ๋ช…:" ) 3. ๊ฐ•์ž์„์œผ๋กœ ํ•˜๋“œ๋””์Šคํฌ์˜ ์ž์„ฑ์„ ๋ง๊ฐ€ํŠธ๋ฆฐ๋‹ค. 4. ๋“œ๋ฆด๋กœ ๋””์Šคํฌ๋ฅผ ๋ฌผ๋ฆฌ์ ์œผ๋กœ ํŒŒ๊ดด ์ฐธ๊ณ : https://syki66.github.io/blog/2020/08/10/make-disk-irrecoverable.html ์ €์žฅ์žฅ์น˜์—์„œ ํฌ๋ Œ์‹์œผ๋กœ๋„ ๋ณต๊ตฌ ๋ถˆ๊ฐ€๋Šฅํ•˜๊ฒŒ ํŒŒ์ผ ๋ฐ ํด๋” ์™„์ „ ์‚ญ์ œํ•˜๊ธฐ - syki66 blog ์ผ๋ฐ˜์ ์ธ .. 2022. 9. 16.
๋””์ง€ํ„ธ ํฌ๋ Œ์‹ - USB ์ ‘์† ๊ธฐ๋ก ํ™•์ธ ์žฅ์น˜ ๊ด€๋ฆฌ์ž ์žฅ์น˜ ๊ด€๋ฆฌ์ž - ๋ณด๊ธฐ(V) - ์ˆจ๊ฒจ์ง„ ์žฅ์น˜ ํ‘œ์‹œ(W) ๋””์Šคํฌ ๋“œ๋ผ์ด๋ธŒ - ์šฐํด๋ฆญ ์†์„ฑ(R) - ์ž์„ธํžˆ - ๋งˆ์ง€๋ง‰ ์ œ๊ฑฐ ๋‚ ์งœ   ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USBSTOR -ํ™•์ธ๊ฐ€๋Šฅ ์ •๋ณด : USB์˜ Unique Instance ๋ฐ USBSTOR์˜ Subkey๋ฅผ ๋ถ„์„ํ•  ๊ฒฝ์šฐ ์ด๋ฏธ ํ•ด๋‹น ์‹œ์Šคํ…œ์—์„œ ์‚ฌ์šฉํ•˜๊ฑฐ๋‚˜ ์‚ฌ์šฉํ–ˆ๋˜ USB ์žฅ์น˜๋ฅผ ํ™•์ธ   HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB -ํ™•์ธ๊ฐ€๋Šฅ ์ •๋ณด : USBSTOR์—์„œ ํ™•์ธํ•œ USB์˜ Unique Instance๋ฅผ ์ฐพ์œผ๋ฉด USB์˜ ์ œ์กฐ์‚ฌ ์•„์ด๋””(VID)์™€ ์ œํ’ˆID(PID) ํ™•์ธ ๊ฐ€๋Šฅ   HKEY_LOCAL_MACHINE\SOFTWARE\Mi.. 2022. 9. 12.
728x90