SANS FOR508 2016 |
||
Name |
DOWNLOAD Copy Link | |
Total Size |
98.6 GB |
|
Total Files |
779 |
|
Hash |
EF9EE1CE583E8049E7960AA6D68F43D9960ACE52 |
/ |
|
|
106.6 MB |
|
91.7 MB |
|
134.5 MB |
|
1.9 MB |
|
115.3 MB |
|
98.2 MB |
|
0.0 KB |
|
135.0 MB |
|
113.3 MB |
|
155.9 MB |
|
133.4 MB |
|
73.6 MB |
/FOR508-USB/ |
|
|
95.7 KB |
/FOR508-USB-B/ |
|
|
33.8 KB |
/FOR508-USB/documents/ |
|
|
3.7 MB |
|
560.7 KB |
|
1.9 MB |
|
137.9 KB |
|
9.9 MB |
|
3.6 MB |
Windows 7 and Windows Server 2008 R2 Security Event Descriptions.xls |
207.9 KB |
|
705.0 KB |
|
610.3 KB |
Detecting-security-incidents-windows-workstation-event-logs.pdf |
836.5 KB |
|
3.9 MB |
|
780.6 KB |
|
1.3 MB |
|
2.6 MB |
|
426.2 KB |
|
3.5 MB |
|
69.3 KB |
|
112.2 KB |
|
370.3 KB |
|
5.7 MB |
|
0.2 KB |
|
565.3 KB |
/.../SIFT-Lab-Install/ |
|
|
223.8 MB |
/.../example-memory-images/ |
|
|
715.0 MB |
|
74.0 MB |
|
35.6 MB |
|
93.8 MB |
|
175.9 MB |
|
39.8 MB |
|
41.7 MB |
|
128.0 MB |
|
71.8 MB |
|
93.3 MB |
|
53.9 MB |
|
295.3 MB |
|
29.5 MB |
|
174.8 MB |
|
73.5 MB |
|
37.8 MB |
|
244.3 MB |
|
177.4 MB |
|
42.4 MB |
/.../SIFT-Lab-Install/SIFT/ |
|
|
18.5 GB |
/.../SIFT-Lab-Install/7zip/ |
|
|
1.4 MB |
|
1.1 MB |
/.../xp-tdungan-10.3.58.7/ |
|
|
9.6 MB |
/.../SIFT-Lab-Install/VMware/ |
|
|
515.0 MB |
|
98.9 MB |
/.../SIFT-Lab-Install/Redline/ |
|
|
9.1 MB |
|
70.2 MB |
|
57.3 MB |
/.../win7-64-nfury-10.3.58.6/ |
|
|
12.9 MB |
/.../SIFT-Lab-Install/IOC Editor/ |
|
|
2.2 MB |
|
339.7 KB |
|
1.0 KB |
/.../SIFT-Lab-Install/Windows Tools/ |
|
|
303.2 KB |
|
767.9 KB |
|
82.7 KB |
|
3.3 KB |
|
33.3 KB |
|
1.5 MB |
|
1.3 MB |
|
696.3 KB |
|
17.7 MB |
|
4.5 MB |
|
242.9 MB |
|
871.4 KB |
|
158.8 KB |
|
411.0 KB |
|
293.7 KB |
|
12.3 MB |
|
5.6 KB |
|
6.4 KB |
|
5.6 KB |
|
57.3 KB |
/.../SIFT-Lab-Install/Redline/DOTNET/ |
|
|
50.4 MB |
|
70.0 MB |
/.../SIFT-Lab-Install/IOC Editor/DOTNET/ |
|
|
70.0 MB |
|
50.4 MB |
|
242.7 MB |
/.../SIFT-Lab-Install/Timeline Explorer/ |
|
|
20.9 KB |
|
28.4 MB |
|
7.9 KB |
/.../Event Log Explorer/ |
|
|
5.0 MB |
/.../SIFT-Lab-Install/Redline/APT1 - IOCS/ |
|
|
6.1 KB |
|
31.1 KB |
|
16.1 KB |
|
4.8 KB |
|
7.3 KB |
|
25.3 KB |
|
35.4 KB |
|
12.8 KB |
|
9.2 KB |
|
258.7 KB |
|
6.8 KB |
|
11.6 KB |
|
17.2 KB |
|
5.5 KB |
|
5.7 KB |
|
6.8 KB |
|
7.6 KB |
|
36.8 KB |
|
4.5 KB |
|
10.1 KB |
|
20.5 KB |
|
5.7 KB |
|
8.7 KB |
|
8.2 KB |
|
19.3 KB |
|
6.0 KB |
|
7.5 KB |
|
8.1 KB |
|
10.3 KB |
|
19.2 KB |
|
8.4 KB |
|
4.0 KB |
|
20.6 KB |
|
21.9 KB |
|
6.5 KB |
|
60.0 KB |
|
42.9 KB |
|
23.9 KB |
|
30.4 KB |
|
5.3 KB |
|
5.4 KB |
|
22.2 KB |
|
7.2 KB |
|
12.0 KB |
|
31.6 KB |
|
29.3 KB |
|
16.6 KB |
/.../Threat Intelligence Reports/ |
|
|
3.0 MB |
|
4.9 MB |
|
288.0 KB |
|
4.2 MB |
|
2.5 MB |
|
2.9 MB |
|
2.0 MB |
2015-Project2049-Stokes_PLA_General_Staff_Department_Unit_61398.pdf |
1.6 MB |
|
1.9 MB |
|
3.6 MB |
|
6.1 MB |
|
1.5 MB |
|
6.8 MB |
|
3.4 MB |
|
2.3 MB |
|
6.8 MB |
|
1.7 MB |
|
3.1 MB |
2011-Project2049-PLA third department_sigint cyber stokes lin hsiao.pdf |
1.5 MB |
|
76.6 KB |
/.../SIFT-Lab-Install/F-Response-Enterprise/ |
|
|
16.1 MB |
|
633.1 KB |
/.../SIFT-Lab-Install/IOC Editor/APT1 - IOCS/ |
|
|
4.5 KB |
|
10.1 KB |
|
8.2 KB |
|
36.8 KB |
|
20.6 KB |
|
6.0 KB |
|
19.3 KB |
|
20.5 KB |
|
7.6 KB |
|
30.4 KB |
|
6.8 KB |
|
4.0 KB |
|
8.4 KB |
|
8.7 KB |
|
5.7 KB |
|
7.2 KB |
|
21.9 KB |
|
5.3 KB |
|
23.9 KB |
|
31.1 KB |
|
35.4 KB |
|
5.7 KB |
|
5.4 KB |
|
31.6 KB |
|
25.3 KB |
|
7.3 KB |
|
42.9 KB |
|
9.2 KB |
|
12.8 KB |
|
12.0 KB |
|
29.3 KB |
|
17.2 KB |
|
16.1 KB |
|
11.6 KB |
|
4.8 KB |
|
258.7 KB |
|
16.6 KB |
|
22.2 KB |
|
6.8 KB |
|
6.5 KB |
|
7.5 KB |
|
8.1 KB |
|
6.1 KB |
|
19.2 KB |
|
60.0 KB |
|
10.3 KB |
|
5.5 KB |
/.../Cyber Threat Intelligence IOCs/ |
|
|
209.2 KB |
|
627.9 KB |
|
1.2 MB |
/.../xp-tdungan-memory/ |
|
|
1.3 KB |
|
2.1 GB |
|
93.8 MB |
/.../xp-tdungan-c-drive/ |
|
|
1.8 KB |
|
7.0 GB |
/.../SIFT-Lab-Install/IOC Editor/DOTNET/DOTNET/ |
|
|
70.0 MB |
|
50.4 MB |
/.../SIFT-Lab-Install/IOC Editor/Additional IOCs/ |
|
|
7.1 KB |
|
40.8 KB |
|
10.8 KB |
|
24.7 KB |
|
2.0 KB |
|
7.9 KB |
|
6.4 KB |
|
9.1 KB |
|
6.1 KB |
|
4.4 KB |
|
16.0 KB |
|
2.1 KB |
|
3.5 KB |
|
60.5 KB |
|
3.7 KB |
|
48.9 KB |
|
9.6 KB |
|
75.3 KB |
|
16.1 KB |
|
69.1 KB |
|
0.2 KB |
|
11.4 KB |
|
23.2 KB |
|
7.5 KB |
|
1.3 KB |
|
3.4 KB |
|
4.3 KB |
|
22.6 KB |
|
40.7 KB |
iocbucket_031920b99a51bae014d6f882c48fa594ccf99d61_apt 28 russia cyber espionage oldbait.ioc |
1.9 KB |
iocbucket_eb666b9fdb964500f9a67f45935c8ccee3d99a3a_duqu kaspersky.ioc |
6.6 KB |
|
3.7 KB |
|
6.8 KB |
iocbucket_dcda86771553fa54820b22099277599cb479f702_mattulm.yara |
0.4 KB |
iocbucket_ce405547a0e213f1c53b55f05e5592617297df37_operation windigo.ioc |
59.3 KB |
iocbucket_13e5d0358dcecb0fc1fbb8b236990c0ae9572ec3_webc2-qbp (family).ioc |
10.1 KB |
iocbucket_4610c2e6f08fa7f2a29d219e8b3fdcaa5279168e_deep panda chinese apt.ioc |
10.4 KB |
iocbucket_4f8622cf3eaa9056fb5fc841b5e1297329b944ee_kronos banking trojan.ioc |
6.1 KB |
iocbucket_cdf7e4a7735d2505bd5c75ca5c23b50f57664ec2_ramnit rootkit.ioc |
16.1 KB |
|
2.1 KB |
|
1.7 KB |
|
3.7 KB |
|
4.5 KB |
|
10.0 KB |
|
3.2 KB |
|
60.6 KB |
iocbucket_08441c5d5f339359e526d6705465c30777092bda_xtreme rat.ioc |
25.9 KB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/ |
|
|
0.1 KB |
|
49.6 KB |
|
2.3 KB |
|
1.3 KB |
|
3.4 KB |
|
3.2 KB |
|
11.3 KB |
/.../win7-64-nfury-memory/ |
|
|
108.7 MB |
|
2.1 GB |
|
1.3 KB |
/.../Redline-Older-Versions/ |
|
|
69.5 MB |
|
68.2 MB |
|
7.8 MB |
/.../win7-64-nfury-c-drive/ |
|
|
12.0 GB |
|
1.8 KB |
/.../SIFT-Lab-Install/IOC Editor/Additional IOCs/FIN4/ |
|
|
0.3 KB |
|
0.8 KB |
|
5.0 KB |
/.../SIFT-Lab-Install/IOC Editor/Additional IOCs/APT3/ |
|
|
0.6 KB |
|
9.8 KB |
|
3.6 KB |
/.../SIFT-Lab-Install/IOC Editor/Additional IOCs/APT28/ |
|
|
13.2 KB |
|
3.1 KB |
|
2.3 KB |
|
0.3 KB |
|
5.0 KB |
|
2.8 KB |
/.../SIFT-Lab-Install/IOC Editor/Additional IOCs/APT12/ |
|
|
0.4 KB |
|
8.7 KB |
/.../SIFT-Lab-Install/IOC Editor/Additional IOCs/APT17/ |
|
|
8.1 KB |
|
0.4 KB |
/.../SIFT-Lab-Install/IOC Editor/Additional IOCs/APT18/ |
|
|
0.3 KB |
|
3.1 KB |
/.../SIFT-Lab-Install/IOC Editor/Additional IOCs/APT30/ |
|
|
0.3 KB |
|
70.9 KB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Modules/ |
|
|
0.1 KB |
|
2.8 KB |
|
4.3 KB |
/.../xp-tdungan-incident-response/ |
|
|
232.7 KB |
/.../win7-32-nromanoff-memory/ |
|
|
1.5 KB |
|
2.1 GB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Analysis/ |
|
|
9.7 KB |
|
1.8 KB |
|
5.1 KB |
|
42.4 KB |
/.../SIFT-Lab-Install/IOC Editor/Additional IOCs/BlogPosts/ |
|
|
5.8 KB |
|
11.8 KB |
|
11.1 KB |
|
19.2 KB |
|
29.0 KB |
|
4.4 KB |
|
2.7 KB |
|
9.0 KB |
|
3.1 KB |
|
7.6 KB |
|
1.9 KB |
|
5.0 KB |
|
0.7 KB |
/.../SIFT-Lab-Install/Windows Tools/RegistryExplorer_RECmd/ |
|
|
40.7 MB |
|
4.7 MB |
/.../win7-32-nromanoff-c-drive/ |
|
|
9.7 GB |
/.../win7-32-nromanoff-memory/ |
|
|
2.1 GB |
|
1.5 KB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Modules/Log/ |
|
|
1.6 KB |
|
3.3 KB |
|
0.5 KB |
|
0.7 KB |
|
17.7 KB |
|
0.8 KB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Modules/Net/ |
|
|
1.2 KB |
|
1.3 KB |
|
4.6 KB |
|
4.1 KB |
|
0.2 KB |
|
0.2 KB |
|
0.3 KB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Modules/IOC/ |
|
|
2.0 KB |
/.../xp-tdungan-c-drive/precooked/mbr/ |
|
|
0.5 KB |
/.../win7-32-nromanoff-c-drive/ |
|
|
9.7 GB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Modules/bin/ |
|
|
369.8 KB |
|
2.4 MB |
|
591.5 KB |
|
629.4 KB |
|
489.0 KB |
|
536.3 KB |
|
0.1 KB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Analysis/Net/ |
|
|
1.6 KB |
|
1.0 KB |
|
1.7 KB |
|
0.6 KB |
|
0.7 KB |
|
0.8 KB |
|
0.8 KB |
|
1.6 KB |
|
1.7 KB |
|
1.6 KB |
|
1.5 KB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Analysis/log/ |
|
|
0.8 KB |
|
0.7 KB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Modules/ASEP/ |
|
|
1.8 KB |
|
6.6 KB |
|
0.6 KB |
|
3.3 KB |
|
0.3 KB |
|
0.5 KB |
|
1.8 KB |
|
2.1 KB |
|
0.5 KB |
|
0.3 KB |
|
0.6 KB |
|
4.3 KB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Modules/Disk/ |
|
|
10.5 KB |
|
10.0 KB |
|
10.3 KB |
|
1.7 KB |
|
3.7 KB |
|
3.6 KB |
|
0.5 KB |
|
46.7 KB |
|
2.9 KB |
|
0.5 KB |
/.../xp-tdungan-memory/baseline-memory/ |
|
|
2.1 GB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Analysis/asep/ |
|
|
0.9 KB |
|
1.1 KB |
|
0.8 KB |
|
1.2 KB |
|
0.9 KB |
|
0.3 KB |
|
0.9 KB |
|
1.0 KB |
|
0.9 KB |
|
0.9 KB |
|
0.8 KB |
|
0.9 KB |
|
1.2 KB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Analysis/meta/ |
|
|
1.6 KB |
|
0.6 KB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Analysis/disk/ |
|
|
4.3 KB |
/.../win7-64-nfury-incident-response/ |
|
|
374.5 KB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Modules/Config/ |
|
|
0.6 KB |
|
0.3 KB |
|
2.1 KB |
|
0.3 KB |
|
1.0 KB |
|
0.4 KB |
|
0.5 KB |
|
1.4 KB |
|
0.6 KB |
|
0.9 KB |
|
0.7 KB |
|
2.4 KB |
/.../xp-tdungan-c-drive/precooked/hashes/ |
|
|
1.1 MB |
/.../xp-tdungan-c-drive/precooked/redline/ |
|
|
57.3 MB |
|
91.3 MB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Modules/Process/ |
|
|
0.8 KB |
|
2.9 KB |
|
2.7 KB |
|
9.9 KB |
|
1.2 KB |
|
0.6 KB |
|
1.3 KB |
|
3.4 KB |
|
2.9 KB |
|
2.6 KB |
|
0.5 KB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Analysis/config/ |
|
|
0.7 KB |
|
1.4 KB |
|
2.6 KB |
/.../SIFT-Lab-Install/Windows Tools/RegistryExplorer_RECmd/RECmd/ |
|
|
0.8 KB |
|
1.1 MB |
/.../xp-tdungan-c-drive/precooked/timeline/ |
|
|
5.6 MB |
|
3.0 MB |
|
1.2 MB |
|
0.2 KB |
|
32.5 MB |
|
100.7 MB |
|
2.5 KB |
|
0.1 KB |
|
1.1 MB |
|
26.1 MB |
|
4.0 KB |
/.../win2008R2-controller-memory/ |
|
|
454.8 MB |
|
2.7 GB |
|
1.4 KB |
/.../SIFT-Lab-Install/Windows Tools/Kansa-master/Analysis/process/ |
|
|
0.6 KB |
|
0.7 KB |
|
1.0 KB |
|
0.6 KB |
|
0.6 KB |
|
0.8 KB |
|
0.7 KB |
|
0.7 KB |
|
0.4 KB |
|
0.7 KB |
/.../SIFT-Lab-Install/Windows Tools/RegistryExplorer_RECmd/Plugins/ |
|
|
8.2 KB |
|
12.8 KB |
|
8.7 KB |
|
9.7 KB |
|
9.7 KB |
|
9.7 KB |
|
8.7 KB |
|
11.3 KB |
|
9.2 KB |
|
8.7 KB |
|
10.2 KB |
|
43.5 KB |
|
11.3 KB |
|
9.7 KB |
|
43.5 KB |
/.../win2008R2-controller-c-drive/ |
|
|
1.9 KB |
|
14.4 GB |
/.../xp-tdungan-c-drive/precooked/volatility/ |
|
|
5.1 KB |
|
383.0 KB |
|
1.1 MB |
/.../SIFT-Lab-Install/Windows Tools/RegistryExplorer_RECmd/Settings/ |
|
|
0.2 KB |
/.../win7-32-nromanoff-incident-response/ |
|
|
311.5 KB |
/.../win7-32-nromanoff-incident-response/ |
|
|
311.5 KB |
/.../xp-tdungan-c-drive/precooked/PEid-Signatues/ |
|
|
490.6 KB |
/.../xp-tdungan-c-drive/precooked/bulk-extractor/ |
|
|
315.2 MB |
/.../win7-32-nromanoff-memory/baseline-memory/ |
|
|
2.1 GB |
/.../SIFT-Lab-Install/Windows Tools/RegistryExplorer_RECmd/Bookmarks/Common/ |
|
Program execution_NtUser_MUICache_a51a8919-ffdd-4135-91fa-affac7f65bb5 |
0.3 KB |
Program execution_NtUser_RunMRU_524957bc-0c7e-490c-a8cf-f6bce2e1e1b5 |
0.3 KB |
Operating system_System_FilesNotToSnapshot_af3e091f-8598-43e1-9e19-39c1352a72ea |
0.4 KB |
User configuration_Software_StartMenuInternet_dc7c443e-51be-41c6-bd71-851c9d108ad6 |
0.3 KB |
User configuration_NtUser_PrinterPorts_fe1bbde9-e2bc-4764-9948-3c3b8d8c2112 |
0.3 KB |
User general_NtUser_CCleaner_ec48ddd3-4f09-4431-b388-7f5d18eaab43 |
0.2 KB |
Program execution_NtUser_Sysinternals_a801be22-7473-4c4c-9a57-9dbc90bcbf7c |
0.3 KB |
Operating system_System_EventLog_e99f1b87-9f35-4876-a5c5-3c99b92e4bfd |
0.3 KB |
User configuration_Software_command_0054aabe-ed43-4485-b3ce-bc6490cfe81e |
0.3 KB |
Operating system_System_FileSystem_b20a0736-0d62-4a26-9539-a53ded5f152b |
0.3 KB |
Operating system_System_RDP-Tcp_6e9f18d0-7173-424c-b695-e8c2894ee110 |
0.3 KB |
Operating system_System_VSS_7afab042-09fb-4f0f-ae3e-b3c58c93f83c |
0.2 KB |
Operating system_System_USB_d9ecec7b-e4c6-4c8d-9f65-2b971efbb4c4 |
0.2 KB |
Program execution_NtUser_FileExts_03427bd9-675f-4564-9d7b-058e797a7cb6 |
0.3 KB |
Operating system_System_{6bdd1fc6-810f-11d0-bec7-08002be2092f}_80aafc9b-f28d-41a8-929c-6c016c4b5bc0 |
0.4 KB |
Operating system_System_Windows_d73fc227-8ea3-45e8-ac69-041a06a6c629 |
0.6 KB |
Operating system_System_{53f56307-b6bf-11d0-94f2-00a0c91efb8b}_18c3eafb-034d-49b6-9558-45b92416bf33 |
0.3 KB |
Operating system_System_TimeZoneInformation_e16fbaa9-172c-4501-a55d-0cb4adb02cac |
0.5 KB |
User files and folders_UsrClass_BagMRU_237fdb41-7713-485d-94ab-f07f4c157356 |
0.3 KB |
Operating system_System_Windows_29e05135-bc83-4332-a11b-ea3c357e4de5 |
0.2 KB |
Operating system_System_PrefetchParameters_0f9651f6-3aa8-4bac-89aa-e57a73744ee2 |
0.4 KB |
Operating system_System_SafeBoot_1da3ee50-90bf-49ed-9aa6-b97ba9948eee |
0.3 KB |
Operating system_System_Services_9a4c3785-ec1c-4248-8b0a-cc32a3578d67 |
0.3 KB |
Operating system_System_Terminal Server_bc0da746-e8c5-465a-a70f-2779e7c914de |
0.8 KB |
Program execution_NtUser_FirstFolder_a640410c-d053-4966-ace5-36bc4b977c9a |
0.3 KB |
Operating system_System_Memory Management_15dc67bb-bf95-46ef-87db-e4e34e387125 |
0.3 KB |
User files and folders_NtUser_MountPoints2_28014255-7733-4398-a859-dd76642a19c7 |
0.4 KB |
User configuration_NtUser_CurrentVersion_b8239cb1-3e84-41ae-a156-ebabfadea7d1 |
0.3 KB |
User configuration_NtUser_CurrentVersion_9fef0ee2-99c9-4131-bd77-3f28fad9f8c7 |
0.3 KB |
Storage_System_{10497b1b-ba51-44e5-8318-a65c837b6661}_9fe29ea5-44f1-4d92-82a0-d6b1fb84ee34 |
0.5 KB |
User configuration_NtUser_Internet Settings_57563b19-0d7b-4f61-a76a-5ec5dfecb7c4 |
0.3 KB |
User network_NtUser_TeamViewer_6aa0d3cd-9926-4f23-bf9b-f675636944f0 |
0.2 KB |
Program execution_NtUser_UserAssist_660a4ade-592f-4c64-bd85-8241378d0839 |
0.4 KB |
User network_NtUser_FTP_013baa05-0d47-4db7-9dbd-d4cb6231dc90 |
0.2 KB |
|
0.3 KB |
Storage_System_MountedDevices_0d010e87-8b14-4ce1-b084-e99b5ab9748c |
0.3 KB |
User files and folders_NtUser_ComDlg32_44d580cf-ef19-4749-b833-f787ac1b0220 |
0.3 KB |
User files and folders_NtUser_Compression_d0e9ff87-f6be-47ec-888d-164cb58f19f3 |
0.3 KB |
Software_Software_Internet Explorer_140f36ce-6571-4966-b6e4-641c30a9b9b1 |
0.3 KB |
Software_Software_Products_a3ce0f6a-434d-4c2d-ba8f-16ce24209fe4 |
0.3 KB |
Software_Software_Products_c6b061c4-df1d-477f-bcde-4846ec328c31 |
0.3 KB |
User files and folders_NtUser_7-Zip_af7dfd06-6a98-4c8b-a795-bfb9f5ae407d |
0.2 KB |
Program execution_System_AppCompatCache_f1adf410-8700-4a83-bc2e-f53cededc03d |
0.4 KB |
User general_NtUser_WordWheelQuery_89ca3fef-d045-4ff2-8891-4c61cf6c30ea |
0.3 KB |
User files and folders_NtUser_User MRU_41e2c5c4-4da2-4b96-99ae-a4fb532f93d4 |
0.3 KB |
User files and folders_NtUser_Shell Folders_feec11a9-1482-4629-a083-0caf2df99873 |
0.3 KB |
User files and folders_NtUser_User MRU_6bbf4038-b3c6-4ba5-a4e1-d04d3166e675 |
0.3 KB |
User files and folders_NtUser_User MRU_83fcbc4b-a0d4-40d2-b414-91ffa96d778c |
0.3 KB |
User files and folders_NtUser_WinRAR_204cf564-85f5-42b9-983f-d94a970e7374 |
0.2 KB |
User files and folders_NtUser_RecentDocs_51af122a-734f-4b9b-8138-4633f67e0cad |
0.3 KB |
User network_NtUser_Ares_fe9bac6b-b1fd-4710-8579-80b31f4fe288 |
0.2 KB |
User network_System_Shares_7794e865-4630-4703-ac0f-76e650314b01 |
0.2 KB |
Web browsing_NtUser_TypedURLs_24aec1e0-f92a-49db-8ec0-8443a7bbd130 |
0.3 KB |
User network_System_FirewallPolicy_6701136a-ccfb-476e-af28-d58543636ba4 |
0.3 KB |
User files and folders_NtUser_FileHistory_2895d67d-8601-45df-9758-f72958482822 |
0.3 KB |
User network_NtUser_Default_617e9fc6-565a-4986-a3fa-7e517fcbf6a3 |
0.3 KB |
User files and folders_NtUser_Map Network Drive MRU_df6ed689-944a-46b1-a806-f5f78830429a |
0.3 KB |
Operating system_System_Environment_7044cf87-168f-4588-bae0-426632d08330 |
0.3 KB |
Autoruns_UsrClass_VirtualStore_bac80d4f-92ed-41a6-bb70-9749bf17736e |
0.2 KB |
Network_Software_NetworkCards_3cfa462c-31d1-4ad6-8b47-98f281c50728 |
0.3 KB |
Network_System_{4d36e972-e325-11ce-bfc1-08002be10318}_54796294-d279-4552-bda5-fe672b4ea675 |
0.3 KB |
Operating system_NtUser_CD Burning_0f0005c8-7a16-4223-8a73-87dc0d307849 |
0.3 KB |
Operating system_Sam_Users_58f6066e-53f0-43a7-823c-5679da0e4cd9 |
0.3 KB |
Communication_NtUser_UnreadMail_d6d419d3-bc7c-4e6c-b73d-e1235c3a2943 |
0.3 KB |
Communication_NtUser_TeamViewer_d32c0647-339c-4d4f-8282-daf26b927699 |
0.2 KB |
Operating system_System_CrashControl_a4d38e6e-fa6e-4ceb-8a1f-b7b2f25bf573 |
0.4 KB |
|
0.3 KB |
|
0.3 KB |
Operating system_Software_Channels_8ab43ae7-05ce-4c41-9c70-f77df5317e67 |
0.4 KB |
Network_Software_LastConnect_1516cac4-ff62-4d2e-a9f5-a20815853b3e |
0.3 KB |
Operating system_Software_Image File Execution Options_59ddbb92-609a-44e8-9bb7-e1f5b797e397 |
0.7 KB |
Operating system_Software_Winlogon_129b227e-57cd-400b-b370-4ef3d08f9627 |
0.3 KB |
Operating system_System_ComputerName_f5259882-9906-413f-b845-b2bbca09ffeb |
0.3 KB |
Operating system_Software_Control Panel_7e993a1a-b5af-4247-8b34-6bbe13eb7f3c |
0.4 KB |
Operating system_Software_EMDMgmt_5c905164-7055-4422-a141-f8539d5ef4fe |
0.4 KB |
Operating system_Software_Windows Portable Devices_39661eda-1373-493a-b333-583c51c9e74b |
0.3 KB |
Operating system_Software_CurrentVersion_3d9483dc-d89c-423a-ae83-a57405d6a752 |
0.4 KB |
Operating system_Software_Devices_121a3617-c512-4b5f-a770-11b1cdb19983 |
0.3 KB |
Operating system_Software_CurrentVersion_0a017e3d-c0fe-40c9-84fb-8bcd45c96a7e |
0.3 KB |
/.../win7-32-nromanoff-memory/baseline-memory/ |
|
|
2.1 GB |
/.../xp-tdungan-c-drive/precooked/redline/APT1 - IOCS/ |
|
|
25.3 KB |
|
7.3 KB |
|
35.4 KB |
|
5.7 KB |
|
12.8 KB |
|
258.7 KB |
|
6.8 KB |
|
42.9 KB |
|
11.6 KB |
|
9.2 KB |
|
7.2 KB |
|
30.4 KB |
|
5.3 KB |
|
17.2 KB |
|
23.9 KB |
|
22.2 KB |
|
31.6 KB |
|
12.0 KB |
|
29.3 KB |
|
16.6 KB |
|
5.4 KB |
|
4.8 KB |
|
4.0 KB |
|
8.4 KB |
|
6.8 KB |
|
8.7 KB |
|
5.7 KB |
|
7.5 KB |
|
8.1 KB |
|
16.1 KB |
|
6.1 KB |
|
19.2 KB |
|
10.3 KB |
|
5.5 KB |
|
20.5 KB |
|
60.0 KB |
|
20.6 KB |
|
6.5 KB |
|
31.1 KB |
|
8.2 KB |
|
6.0 KB |
|
21.9 KB |
|
19.3 KB |
|
4.5 KB |
|
7.6 KB |
|
10.1 KB |
|
36.8 KB |
/.../win2008R2-controller-incident-response/ |
|
|
322.5 KB |
/.../win7-32-nromanoff-c-drive/precooked/redline/ |
|
|
57.3 MB |
|
244.3 MB |
/.../win7-32-nromanoff-c-drive/precooked/timeline/ |
|
|
31.5 MB |
|
64.9 MB |
|
2.1 MB |
|
64.9 MB |
|
42.6 MB |
|
54.8 MB |
|
0.1 KB |
|
3.1 MB |
|
0.2 KB |
|
1.2 MB |
|
243.4 KB |
|
566.3 KB |
|
4.0 KB |
|
7.1 MB |
/.../win7-32-nromanoff-c-drive/precooked/redline/ |
|
|
244.3 MB |
|
57.3 MB |
/.../win7-32-nromanoff-c-drive/precooked/timeline/ |
|
|
7.1 MB |
|
4.0 KB |
|
1.2 MB |
|
243.4 KB |
|
3.1 MB |
|
0.2 KB |
|
566.3 KB |
|
2.1 MB |
|
0.1 KB |
|
54.8 MB |
|
42.6 MB |
|
31.5 MB |
|
64.9 MB |
|
64.9 MB |
/.../win7-32-nromanoff-c-drive/precooked/volatility/ |
|
|
383.0 KB |
/.../SIFT-Lab-Install/Windows Tools/RegistryExplorer_RECmd/Plugins/AppCompatCache/ |
|
|
9.7 KB |
|
16.4 KB |
/.../win7-32-nromanoff-c-drive/precooked/volatility/ |
|
|
383.0 KB |
/.../win7-32-nromanoff-c-drive/precooked/volume-shadow/ |
|
|
23.7 MB |
/.../win7-32-nromanoff-c-drive/precooked/PEid-Signatues/ |
|
|
490.6 KB |
/.../win7-32-nromanoff-c-drive/precooked/volume-shadow/ |
|
|
23.7 MB |
/.../win7-32-nromanoff-c-drive/precooked/PEid-Signatues/ |
|
|
490.6 KB |
/.../xp-tdungan-Redline-Live-Audit/ |
|
|
689.3 KB |
|
52.4 KB |
|
1.9 KB |
|
263.6 MB |
|
29.9 KB |
|
715.2 KB |
|
241.0 MB |
|
423.1 MB |
|
1.4 MB |
|
104.7 KB |
|
0.3 KB |
|
906.7 KB |
|
6.6 KB |
|
1.4 KB |
|
59.6 MB |
|
2.1 KB |
|
17.8 MB |
|
298.4 KB |
|
19.5 MB |
|
6.0 KB |
|
10.1 KB |
|
2.2 KB |
|
11.3 KB |
|
3.7 KB |
|
266.6 KB |
|
1.4 KB |
/.../win7-32-nromanoff-c-drive/precooked/redline/APT1 - IOCS/ |
|
|
7.5 KB |
|
8.4 KB |
|
6.8 KB |
|
4.0 KB |
|
5.5 KB |
|
16.1 KB |
|
8.7 KB |
|
10.3 KB |
|
8.1 KB |
|
4.5 KB |
|
21.9 KB |
|
20.6 KB |
|
6.5 KB |
|
31.1 KB |
|
19.2 KB |
|
6.0 KB |
|
19.3 KB |
|
8.2 KB |
|
20.5 KB |
|
10.1 KB |
|
7.6 KB |
|
36.8 KB |
|
5.7 KB |
|
31.6 KB |
|
16.6 KB |
|
29.3 KB |
|
12.0 KB |
|
5.4 KB |
|
22.2 KB |
|
23.9 KB |
|
17.2 KB |
|
5.3 KB |
|
30.4 KB |
|
7.2 KB |
|
5.7 KB |
|
35.4 KB |
|
6.8 KB |
|
258.7 KB |
|
4.8 KB |
|
6.1 KB |
|
42.9 KB |
|
11.6 KB |
|
25.3 KB |
|
7.3 KB |
|
12.8 KB |
|
9.2 KB |
|
60.0 KB |
/.../win7-32-nromanoff-c-drive/precooked/redline/APT1 - IOCS/ |
|
|
5.7 KB |
|
11.6 KB |
|
9.2 KB |
|
12.8 KB |
|
7.3 KB |
|
42.9 KB |
|
6.8 KB |
|
16.1 KB |
|
17.2 KB |
|
4.8 KB |
|
258.7 KB |
|
25.3 KB |
|
35.4 KB |
|
23.9 KB |
|
7.2 KB |
|
30.4 KB |
|
5.3 KB |
|
22.2 KB |
|
16.6 KB |
|
5.4 KB |
|
31.6 KB |
|
12.0 KB |
|
29.3 KB |
|
31.1 KB |
|
6.5 KB |
|
8.4 KB |
|
4.0 KB |
|
6.8 KB |
|
8.7 KB |
|
7.5 KB |
|
8.1 KB |
|
60.0 KB |
|
19.2 KB |
|
10.3 KB |
|
5.5 KB |
|
5.7 KB |
|
20.5 KB |
|
19.3 KB |
|
6.0 KB |
|
20.6 KB |
|
21.9 KB |
|
36.8 KB |
|
7.6 KB |
|
8.2 KB |
|
10.1 KB |
|
4.5 KB |
|
6.1 KB |
Total files 779 |
Copyright © 2024 FileMood.com