๋์งํธ ํฌ๋ ์ - ์ฆ๊ฑฐ ์์ง ํ์ผ ๋ฐ ๋ ์ง์คํธ๋ฆฌ ๊ฒฝ๋ก
๋ ์ง์คํธ๋ฆฌ ํ์ผ(SAM, SOFTWARE, SYSTEM, SECURITY, NTUSER) ๊ฒฝ๋ก
ํ์ผ ๊ฒฝ๋ก:
C:\Windows\System32\config
C:\users\{์ฌ์ฉ์๋ช
}\NTUSER.DAT
์ฐ๊ธฐ ๋ฐฉ์ง
๋ ์ง์คํธ๋ฆฌ ๊ฒฝ๋ก:
HKEY_LOCAL_MACHINE > SYSTEM > CurrentControlSet > Control > StorageDevicePolicies
WriteProtect ์์ฑ(REG_DWORD) > ๊ฐ์ 1๋ก ์ค์
์ฐ๊ฒฐ๋๋ USB์ ๋ณผ๋ฅจ๋ช , ์๋ฆฌ์ผ๋๋ฒ, ๋ณผ๋ฅจ GUID, ๋ง์ง๋ง ์ฐ๊ฒฐ ํด์ ์๊ฐ, ์ฌ์ฉ์ ๊ณ์ ์ ๋ณด ๋ฑ
ํ์ผ ๊ฒฝ๋ก:
Windows > inf > Setupapi.dev.log
USB Device Class ID(Vener Name + Product Name + Version)
๋ ์ง์คํธ๋ฆฌ ๊ฒฝ๋ก:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USBSTOR
-ํ์ธ๊ฐ๋ฅ ์ ๋ณด : USB์ Unique Instance ๋ฐ USBSTOR์ Subkey๋ฅผ ๋ถ์ํ ๊ฒฝ์ฐ ์ด๋ฏธ ํด๋น ์์คํ
์์ ์ฌ์ฉํ๊ฑฐ๋ ์ฌ์ฉํ๋ USB ์ฅ์น๋ฅผ ํ์ธ
๋ ์ง์คํธ๋ฆฌ ๊ฒฝ๋ก:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB
-ํ์ธ๊ฐ๋ฅ ์ ๋ณด : USBSTOR์์ ํ์ธํ USB์ Unique Instance๋ฅผ ์ฐพ์ผ๋ฉด USB์ ์ ์กฐ์ฌ ์์ด๋(VID)์ ์ ํID(PID) ํ์ธ ๊ฐ๋ฅ
์ฐ๊ฒฐํ๋ USB์ ๋ณผ๋ฅจ ์ด๋ฆ
๋ ์ง์คํธ๋ฆฌ ๊ฒฝ๋ก:
HKEy_LOCAL_MACHINE > SOFTWARE > Microsoft > Windows Portable Devices > Devices
๋คํธ์ํฌ ์นด๋(NIC) ์ ๋ณด
1) ๋ชจ๋ธ๋ช
๋ฐ GUID ํ์ธ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards\
2) DHCP IP Address ๋ฑ ํ์ธ(๋ ์ง์คํธ๋ฆฌ)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\
DhcpIPAddress : ์ปดํจํฐ ํ ๋น IP
DhcpNameServer : ISP ์ฃผ์ (e.g. 168.126.63.1 168.126.63.2)
DhcpServer : ๊ฒ์ดํธ์จ์ด ์ฃผ์
DhcpSubnetMask : ์๋ธ๋ท๋ง์คํฌ
LeaseObtainedTime : IP ์๋(ํ ๋น) ์ผ์
3) MAC Address ํ์ธ(๋ ์ง์คํธ๋ฆฌ)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\NetworkSetup2\Interfaces\{GUID}\Kernel\
๊ณต์ ๊ธฐ SSID & MAC Address ์ ๋ณด
1) ๋คํธ์ํฌ์นด๋ ์ ๋ณด ํ์ธ(๋ ์ง์คํธ๋ฆฌ)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\
2) MAC Address ํ์ธ(๋ ์ง์คํธ๋ฆฌ)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\
Jumplist (์ต๊ทผ ๋ฐ ์์ฃผ ์ฌ์ฉํ ๋ด์ญ ํ์ธ)
AutomaticDestinations:
%UserProfile%\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
CustomDestinations:
%UserProfile%\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
Thumbnail Cache & Icon Cache
ํ์ผ ๊ฒฝ๋ก:
%UserProfile%\AppData\Local\Microsoft\Windows\Explorer
Spool ํ์ผ(ํ๋ฆฐํฐ ์ ๋ณด)
ํ์ผ ๊ฒฝ๋ก:
C:\Windows\System32\spool\PRINTERS
ํ์ผ ์ญ์ , ์ด๋, ์์น ์ถ์ ($LogFile, $UsnJrnl:$J, $MFT For NTFS Log Tracker)
ํ์ผ ๊ฒฝ๋ก:
$UsnJrnl : C:\$Extend\$Usnjrnl:$J
$MFT : C:\$MFT
$LogFile : C:\$LogFile
Prefetch ์ ๋ณด(์คํ ํ์ผ ์ด๋ฆ ๊ฒฝ๋ก, ์คํ ํ์, ๋ง์ง๋ง ์คํ ์๊ฐ, ์ต์ด ์คํ ์๊ฐ)
ํ์ผ ๊ฒฝ๋ก:
%SystemRoot%\Prefetch
C:\WINDOWS\Prefetch
AmCache(๋ชจ๋ ์คํ ํ์ผ์ ์ด๋ฆ, ๊ฒฝ๋ก, ํฌ๊ธฐ, ํด์๊ฐ ํ์ธ)
ํ์ผ ๊ฒฝ๋ก:
%SystemDrive%\Windows\AppCompat\Programs\Amcache.hve