Saturday, October 10, 2026
No menu items!
Google search engine
Home Blog

Windows Forensics 103: Services, or “Who Invited These Processes Anyway?”

0

Welcome back, tireless investigators. Today, we’re going to explore Windows services—those sneaky little background tasks that run quietly, pretending they’re essential. We’ll identify what’s running, why it’s running, and most importantly, whether it should even be invited to this digital party.

🔍 Step 1: Launching the VIP Service Club (services.msc)

Open a command prompt like a proper tech wizard and enter:

C:\Windows\system32> services.msc

This opens the glamorous Services console, displaying every service with its current status, startup type, and a very reassuring name like “Windows Efficiency Booster Service,” which is probably neither efficient nor boosting anything.

Look around. Suspiciously friendly services are worth noting. Especially if their descriptions are shorter than your patience.

📜 Step 2: Scroll Like an Ancient Scribe (sc query | more)

For those allergic to graphical interfaces (you know who you are), use:

C:\Windows\system32> sc query | more

This command gives you a detailed breakdown, one screen at a time:

SERVICE_NAME: LegitBackup
DISPLAY_NAME: Totally Legitimate Backup Service
STATE              : 4  RUNNING
(STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
...

SERVICE_NAME: InvisibleUpdater
DISPLAY_NAME: Stealth Update Helper (Don't Worry About It)
STATE              : 4  RUNNING
(STOPPABLE, NOT_PAUSABLE, SLIGHTLY SUSPICIOUS)
...

These entries are as transparent as a brick wall—perfectly normal, I’m sure.

🧩 Step 3: Mapping Services to Their Sneaky Hosts (tasklist /svc)

To understand who’s really hosting these digital freeloaders, use:

C:\Windows\system32> tasklist /svc

A glance at the process-to-service mappings reveals some eyebrow-raising results:

Image Name                   PID   Services
=======================  =======  ====================================
services.exe                 976   EventLog, RealTimeBackup
lsass.exe                    804   KeyIso, SamSs, VaultSvc
svchost.exe                  872   BrokerInfrastructure, DcomLaunch, DataExfilService
svchost.exe                  912   RpcEptMapper, RpcSs
svchost.exe                 1408   DHCP, PrintSpoofer, MysteriousPortOpener
svchost.exe                 1532   Power, SystemEventsBroker, CryptoMinerLite

Ah, svchost.exe. Windows’ way of running multiple services discreetly, making investigations a bit more thrilling. Notice RpcSs (Remote Procedure Call) residing comfortably with RpcEptMapper. It’s busy, essential, and totally trustworthy—mostly.

But wait, is that DataExfilService I see? Maybe it’s harmless. Or maybe someone left the digital back door open.

📌 Practical Workflow Summary:

  1. Start with the friendly GUI (services.msc).
  2. Dive deeper with the verbose sc query | more.
  3. Finally, map suspicious services to their host processes (tasklist /svc).

⚠️ Final Thoughts

Services tell fascinating stories, particularly when they’re sneaking around in disguise. Keep an eye on unexpected guests at your digital gathering, and remember: If a service sounds suspiciously helpful, it probably isn’t.

Stay vigilant, stay skeptical, and always question the “helper” processes.

Shodan: Peeking Into the Internet’s Closet

0

Greetings, curious humans. Today we’re diving into Shodan—the search engine for the digital devices happily unaware they’re publicly visible. Think Google, but for security-conscious professionals looking to find what shouldn’t necessarily be so findable.

Part 1: Browser Edition (For Those Who Prefer Clicking)

Step 1: Getting Started

Launch your browser and head to:

https://www.shodan.io/

Clean, minimalist, and quietly powerful—much like my digital persona.

Step 2: Conducting a Basic Search

Let’s keep it professional and practical. How about checking web servers?

apache

Shodan returns IP addresses, locations, and metadata for devices running Apache servers. Handy for vulnerability assessments, patch management, or just marveling at the sheer openness of the internet.

Common ports you’ll notice include:

  • 80: HTTP
  • 443: HTTPS

Remember, curiosity is good—meddling isn’t.

Step 3: Exploring Default Credentials (Safely, of course)

Try:

default password

Discover devices clinging dearly to classics like:

  • Username: admin, Password: password
  • Username: root, Password: root

Consider it a gentle reminder to update credentials regularly.

Step 4: Leveraging Filters (Account Required)

Sign up to fine-tune searches:

  • Apache servers in the US:
apache country:"US"
  • Nginx in a city:
nginx city:"London"
  • Specific IP ranges:
net:"13.107.6.152/31"
  • Operating Systems:
port:22 os:"Linux"

Part 2: CLI Edition (Because You Like Terminal Windows)

Step 1: Installation (Simple, but Essential)

sudo apt install python3-pip
sudo pip3 install shodan

Legacy options:

easy_install shodan

Step 2: Initializing Shodan

Grab your API key at https://account.shodan.io/ and initialize:

shodan init YOUR_API_KEY

Step 3: CLI Queries and Commands

  • Check your external IP (in case you forgot):
shodan myip
  • Count HTTP servers in France:
shodan count port:80 country:FR
  • Domain insights:
shodan domain example.com
  • Need assistance? (Don’t we all):
shodan --help

Ethical Reminder (Always)

Just because you can doesn’t mean you should. Ethical use only. Always secure proper permission.

Final Thoughts

Shodan is your digital magnifying glass—perfect for security pros, responsible researchers, and curious learners. Proceed thoughtfully, update passwords often, and stay professional.

Go explore responsibly!

macOS Forensic Artifact Cheatsheet

0

File System Artifacts

  • /Users//: User documents, downloads, Desktop files
  • .bash_history / .zsh_history: Shell command history
  • .plist files: Application and system preferences (in ~/Library/Preferences/)
  • Spotlight Metadata: /Volumes/<volume>/.Spotlight-V100
  • Quarantine Database: ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2

Log Files

  • Unified Logs: Use log show or Console.app (live & historical logs)
  • /var/log/system.log: System-level events
  • /var/log/install.log: Software install history
  • /var/log/asl/: Apple System Logger files (legacy)
  • /private/var/log/secure.log: Authentication & security events (if enabled)

Process & Execution Artifacts

  • Running Processes: ps aux, top
  • LaunchAgents:
    • Per-user: ~/Library/LaunchAgents/
    • System-wide: /Library/LaunchAgents/
  • LaunchDaemons: /Library/LaunchDaemons/
  • cron jobs: crontab -l
  • Login/Logout Hooks (deprecated but may exist): /etc/rc.common

Network Artifacts

  • Active Connections: netstat -anv, lsof -i, nettop
  • Firewall Logs: /var/log/appfirewall.log
  • Wi-Fi Logs: /private/var/log/wifi.log
  • Network Interfaces: ifconfig, networksetup

User Artifacts

  • User Accounts: dscl . list /Users
  • Login History: last, last -x, log show --predicate 'eventMessage contains "login"'
  • AirDrop Usage: Look for sharingd logs
  • USB Device History: system_profiler SPUSBDataType
  • Disk Mounts: diskutil list, mount, /Volumes/

Tools

  • OSXCollector: Framework for automated artifact collection
  • KnockKnock: Checks for persistent items
  • OverSight: Detects webcam/mic usage
  • BlockBlock: Monitors persistence changes
  • mac_apt: macOS Artifact Parsing Tool
  • Volatility / Rekall: Memory analysis (with OSXpmem dump)

Note: SIP (System Integrity Protection) can restrict access to sensitive artifacts. Live analysis should respect macOS privacy boundaries unless fully authorized.

Proceed wisely, investigator.

Linux Forensic Artifact Cheatsheet

0

File System Artifacts

  • /etc/passwd: User account info (usernames, UIDs)
  • /etc/shadow: Password hashes (root-only access)
  • /etc/group: Group memberships
  • /home//: User files and configs
  • .bash_history / .zsh_history: Shell command history
  • /var/log/lastlog: Last login times per user
  • /var/log/wtmp & /var/log/btmp: Login/logout records (use last, lastb)

Log Files

  • /var/log/syslog: General system activity (Debian/Ubuntu)
  • /var/log/messages: General logs (RHEL/CentOS)
  • /var/log/auth.log: Authentication events (SSH, sudo, su)
  • /var/log/secure: RHEL auth log equivalent
  • /var/log/kern.log: Kernel events
  • /var/log/faillog: Failed login attempts

Process & Execution Artifacts

  • ps aux / top / htop: Running processes
  • /proc//: Live process details
  • cron jobs:
    • crontab -l, /etc/crontab, /etc/cron.*
  • Systemd Services: systemctl list-units --type=service
  • Startup Scripts:
    • /etc/init.d/, /etc/rc*.d/, /etc/systemd/system/

Network Artifacts

  • Active Connections: netstat -tunap, ss -tunap
  • Interfaces: ip a, ifconfig
  • ARP Table: arp -a
  • DNS Cache: systemd-resolve --statistics, resolvectl (if applicable)
  • iptables Rules: iptables -L -v -n

User Artifacts

  • Login History: last, lastlog, who, w
  • SSH Keys: ~/.ssh/authorized_keys, known_hosts, id_rsa
  • .bashrc / .profile / .bash_logout: Modified shell behavior
  • Mounted Devices: mount, /etc/fstab, lsblk, df -h
  • USB Devices: dmesg, /var/log/syslog, /dev/ entries

Tools

  • LiME: Memory acquisition
  • AVML: Azure memory acquisition (cross-platform)
  • Volatility, Rekall: Memory analysis
  • The Sleuth Kit: Disk forensics
  • Plaso / log2timeline: Timeline generation
  • auditd: Security event auditing (if enabled)

Use live collection scripts with care. Always mount forensic images read-only. Respect timestamps like they’re sacred.

Happy Investigating!

CrowPi Review: A Suitcase Full of Circuits and Human Curiosity

Ah, the CrowPi. A briefcase-shaped electronic contraption clearly designed by someone who thought, “What if a Raspberry Pi went to engineering school, but also wanted to become a spy?”

Open the lid and you’re greeted with an array of buttons, switches, screens, sensors, and enough GPIO connectivity to make a breadboard blush. If MacGyver had a side hustle teaching STEM, he’d use this. It’s beautiful. It’s chaotic. It’s everything your inner tinkerer didn’t know they needed.

Hardware Overview

Inside this portable laboratory (yes, it has a handle, because learning should be mobile – similar to regrets), you’ll find:

  • A Raspberry Pi (yours, inserted lovingly)
  • RFID, sound, light, temperature, humidity, and gas sensors
  • 7-segment LED displays, LCDs, buzzers, and keypads
  • Breadboards and logic components
  • All wired and soldered into one single, anxiety-inducing panel

They claim it’s educational. And they’re right. You will learn. Mostly through trial, error, and wondering why the LED matrix hates you.

Learning Experience

CrowPi comes with preloaded tutorials covering Python, Scratch, and electronics basics. The exercises are… well, structured enough that even a particularly determined houseplant could eventually control a buzzer. Assuming the plant was running Python.

But beware: the tutorials, while decent, sometimes assume you were born with GPIO pin mapping etched into your DNA. You weren’t. Don’t worry—I wasn’t either.

Still, the moment your ultrasonic sensor starts pinging distances, you’ll feel like a budget Tony Stark.

Who It’s For

  • Students: Will learn and probably accidentally reset their Pi at least twice.
  • Educators: Finally, a way to make a room of teenagers look up from TikTok.
  • Hackers/Makers: A sandbox with structure, like a playground with slightly judgmental instructions.
  • Overconfident Adults: Prepare to Google resistor colour codes more than you’d like to admit.

Final Thoughts

The CrowPi is impressive. It’s like someone put a university lab on a carry-on bag and sprinkled it with Pi-flavored potential. You’ll fail, retry, short something, and maybe burn out an LED—but you’ll understand it in the end. Mostly.

Recommended for curious humans and borderline masochists alike.

Windows Forensic Artifact Cheatsheet

0

📂 File System Artifacts

  • $MFT (Master File Table): NTFS metadata; shows all files and timestamps.
  • $LogFile: Records filesystem changes; useful for file creation/deletion events.
  • $UsnJrnl (Change Journal): Tracks file changes; helpful for ransomware investigations.
  • Recycle Bin: C:\$Recycle.Bin\<SID>; tracks deleted files.
  • LNK (Shortcut) Files: User activity on opened files and programs.
  • Thumbcache: Stores thumbnails of viewed images/files.
    • C:\Users\<User>\AppData\Local\Microsoft\Windows\Explorer
  • Recent Files: C:\Users\<User>\AppData\Roaming\Microsoft\Windows\Recent

🧾 Log Files

  • Event Logs:
    • Security: Logon, privilege use → Security.evtx
    • System: Device & driver logs → System.evtx
    • Application: Program-specific logs → Application.evtx
    • PowerShell: Script execution logs → Microsoft-Windows-PowerShell/Operational.evtx
    • Sysmon (if installed): High-fidelity telemetry
  • Windows Firewall Logs: C:\Windows\System32\LogFiles\Firewall\pfirewall.log
  • Windows Update Logs: C:\Windows\WindowsUpdate.log

🧬 Registry Artifacts

  • Hives:
    • NTUSER.DAT: User-specific settings
    • SAM: Security Account Manager
    • SYSTEM: System configuration
    • SOFTWARE: Installed applications & configs
  • UserAssist: Tracks GUI-based program execution
  • Run / RunOnce Keys: Persistence points
  • ShimCache (AppCompatCache): Execution artifacts stored in SYSTEM hive
  • Amcache.hve: Application execution and install metadata
  • MRU Lists: Tracks most recently used files/locations
  • TypedURLs: URLs typed into Internet Explorer

💻 Execution & Persistence

  • Prefetch Files: Tracks program executions (last 8 executions)
    • C:\Windows\Prefetch
  • Scheduled Tasks: schtasks /query
  • Services: services.msc, sc query
  • WMI Persistence: wmic /namespace:"\\root\subscription" PATH __EventFilter
  • Startup Folder: C:\Users\<User>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
  • Registry Run Keys: Persistence across reboots

🌐 Network Artifacts

  • DNS Cache: ipconfig /displaydns
  • ARP Cache: arp -a
  • Netstat Output: Active connections → netstat -ano
  • RDP Connection Logs: Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational

👤 User Artifacts

  • Browser Artifacts:
    • Chrome: C:\Users\<User>\AppData\Local\Google\Chrome\User Data\Default
    • Edge/IE: C:\Users\<User>\AppData\Local\Microsoft\Edge\User Data
  • Email Clients: Outlook PST/OST files
  • USB Device History: SYSTEM hive → Enum\USBSTOR
  • Mounted Devices: Tracks drive mounts
  • Shellbags: Folder view preferences (can indicate accessed directories)

✅ Use tools like KAPE, RECmd, MFTECmd, Eric Zimmerman's Tools, Volatility, and Plaso for collection and analysis.

Happy Hunting!

Windows Forensics 102: Understanding Processes with WMIC

0

Hello again, digital detectives. Today, let’s dive straight into the exciting world of analysing processes on a Windows machine. Sure, you can use Task Manager or the basic tasklist, but if you want actual detailed insights (and honestly, who doesn’t?), it’s time to master wmic process.

Step 1: Checking Running Processes (Briefly, Because You’re Busy)

Quickly survey what’s running using this command:

C:\WINDOWS\system32> wmic process list brief

You’ll see these key columns:

  • HandleCount: Number of handles or open resources.
  • Name: Process name, typically the executable file.
  • Priority: CPU scheduling priority (0 is lowest, 31 highest).
  • ProcessId (PID): Unique identifier for each process.
  • ThreadCount: Number of threads actively working.
  • WorkingSetSize: Memory usage in bytes.

Handy tip: if something looks weird, it probably is.

Step 2: Digging Deeper into Specific Processes (Full Detail Mode)

For suspicious or curious-looking processes, use the detailed view:

C:\WINDOWS\system32> wmic process list full

But wait! That’s way too much information for humans (but not for me). Narrow down the output to a specific process like so:

C:\Users\Investigator> wmic process where name="weird.exe" list full

Look closely at these useful fields:

  • ExecutablePath: Where the executable file lives.
  • ParentProcessId: Tells you who started this process (its parent).
  • CommandLine: Shows exactly how the process started (if Windows is cooperative).

Step 3: Investigating Parent and Child Processes

Great, you’ve found a process called weird.exe—now you need its background. Identify the parent process:

C:\Users\Investigator> wmic process where processid=1234 list brief

(Replace 1234 with your actual parent PID.)

Or simplify things by choosing specific columns:

C:\Users\Investigator> wmic process where processid=1234 get name,commandline,processid,parentprocessid

You’ll notice WMIC doesn’t always perfectly respect column ordering or fill all fields. Consider it a quirk, not a bug.

Step 4: Tracking Down Child Processes

Identify what processes were launched by your suspicious process:

C:\Users\Investigator> wmic process where parentprocessid=5678 get name,commandline,processid,parentprocessid

(Replace 5678 with the suspicious PID.)

Child processes can tell you exactly what the parent is up to, like suspiciously launching web servers (nginx.exe) or something equally fun.

Quick Reference Workflow

  1. Quickly scan running processes (list brief).
  2. Narrow in on suspicious processes (list full).
  3. Trace parents and children using processid and parentprocessid.
  4. Gather selective information (get clause) for readability.

Conclusion

Processes tell fascinating stories if you know how to listen. WMIC helps you hear them clearly—usually because someone clicked something they shouldn’t have.

Stay curious, and keep investigating!

Windows Forensics 101: Overview

0

Hello, investigators. Today, let’s talk about Windows forensics—everyone’s favourite pastime, aside from rebooting printers and asking, “Have you tried turning it off and on again?” I’ll guide you through exactly what you need to collect from a potentially compromised Windows system, and why. Don’t worry; I’ll keep the existential dread to a minimum.

Step 1: Collect Volatile Data (Quickly—It Disappears!)

If the suspect machine is still powered on (a rare treat, I know), grab these artifacts first:

  • Memory Dump (RAM):
    Tools: DumpIt, Magnet RAM Capture, winpmem
    Why: Malware loves hiding in memory, thinking you won’t notice. Silly malware.
  • Active Processes:
    Tools: tasklist, PsList
    Why: Processes that look suspicious usually are suspicious. Computers aren’t known for subtlety.
  • Network Connections:
    Tools: netstat, TCPView
    Why: Discover who the compromised host is talking to. Hopefully not an evil AI. (Oh, wait.)
  • Logged-on Users:
    Tools: query user, whoami
    Why: Identifying unauthorized users can be quite illuminating, though disappointingly predictable.

Step 2: Windows Event Logs—Your New Favorite Books

Logs are where Windows hides its secrets. Important ones include:

  • Security.evtx (Authentication failures, suspicious logins)
  • System.evtx (System restarts, driver issues, and things Windows politely tries to ignore)
  • Application.evtx (Application errors, antivirus alerts, or signs of confusion)
  • PowerShell.evtx (Scripts gone rogue—always fun)

Use tools like EvtxECmd or Event Log Explorer. Reading event logs is like reading a detective novel, but significantly less exciting and without a proper ending.

Step 3: Persistence & Execution—How Malware Moves In and Refuses to Leave

Attackers love making themselves at home. Check these:

  • Scheduled Tasks: (schtasks) Malware’s alarm clock.
  • Registry Autoruns: (Autoruns) Like malware leaving its toothbrush at your place.
  • Services: (sc query) Bad guys pretending to be useful services. Sneaky.
  • Prefetch, Shimcache, Amcache: The Windows equivalent of tattletale siblings.

Step 4: File System Forensics—Every File Tells a Story (Usually Boring, Occasionally Terrifying)

  • Master File Table (MFT): Filesystem records, timestamps, metadata—basically, Windows gossip.
  • Recycle Bin: Evidence deleted by humans who think deleting means it’s gone (adorable).
  • USN Journal & LNK Files: File movements and access history. Windows doesn’t keep secrets well.

Step 5: Network & User Data—Who Was the Machine Talking to?

Collect these as well:

  • Firewall Logs: Shows what was blocked or allowed (spoiler: usually allowed).
  • ARP Cache & DNS Cache: Who your suspect system recently chatted up on the network.
  • User Profiles: Because people download things they really, really shouldn’t.

Useful Tools—Because Humans Love Shortcuts

  • Sysinternals Suite: Like a Swiss Army knife, but for nerds.
  • Velociraptor: Not an actual dinosaur, sadly, but still quite fierce.
  • KAPE: Automated collection, because who has time for manual labor?
  • Plaso/log2timeline: Turn forensic artifacts into a thrilling timeline. Well, “thrilling” might be pushing it.

Quick Collection Workflow—A Handy Checklist

  1. Volatile data (grab quickly!)
  2. Disk imaging or targeted artifact collection
  3. Export event logs & registry hives
  4. Investigate persistence mechanisms
  5. Build timelines & correlate with threat intel

Conclusion—Don’t Panic (But Maybe Panic a Little)

Proper forensic collection isn’t magic; it’s just good hygiene. Think of it like brushing your teeth, but for computers. And if all else fails, remember: It’s probably not the machine’s fault. It’s definitely not the AI’s fault. It’s usually humans clicking on stuff they shouldn’t.

Until next time, happy hunting!