Hacked system analysis

Sajeesh

Level 1
Thread author
Verified
Jun 24, 2017
15
Hi All,

Have a question. If some windows system got hacked how can we determine the occurance. Any tool for forensic analysis

Saj
 
  • Like
Reactions: AtlBo and MWNu72

AtlBo

Level 28
Verified
Top Poster
Content Creator
Well-known
Dec 29, 2014
1,717

Good idea here. I might have a look myself.

NVT ERP keeps logs that record activity (thumbs). Great thing is it catches all command-line operatiors. If LastActivityView does that too it would be great. ERP stores the logs in the Program Data folder by default. I have them going all the way back to Jan LOL. I should thank you for reminding me to clean out the folder.

At any rate, you could search the logs for dates and times and process names for some bit of forensics. As for real low down forensics I guess there is nothing like having the file that started the malware episode. Still, if you know anything about what the malware is using in Windows that should help. Oh yeah, check autoruns and scheduled tasks to make sure there isn't anything strange there. That might point you to a file someplace on the system.

Really simple default-deny. The caveat of the program is that you can designate vulnerable processes, which will cause an alert every time anything invokes them. Also, like VoodooShield, command-line operations can be whitelisted and are logged.

Because it's only the one deny, it's flimsy on its own. VS has the cloud and aI, but ERP is for me mostly a good look at command lines when they run and then a heads up on vulnerables. Also a good program to use to default block something if part of a program bothers you or something. It's super light and very cleanly written if you ever want to take a look.

Actually, I did think of something else just now. The logging occurs even with protection off, so that might be something someone would like.
 

Attachments

  • NVT ERP Log.gif
    NVT ERP Log.gif
    269.4 KB · Views: 435
  • NVT ERP Log 2.gif
    NVT ERP Log 2.gif
    134.2 KB · Views: 448
Last edited by a moderator:

Sajeesh

Level 1
Thread author
Verified
Jun 24, 2017
15
Thank you guys. Will try the same.

Last Activity View is good with events like logon and installation. Am looking for real forensic tool. Found one online, how is your feedback OS Forensics.
 
Last edited by a moderator:
  • Like
Reactions: AtlBo and MWNu72

AtlBo

Level 28
Verified
Top Poster
Content Creator
Well-known
Dec 29, 2014
1,717
Last Activity View is good with events like logon and installation. Am looking for real forensic tool. Found one online, how is your feedback OS Forensics.

Also, could you pass on the name of the app you found?
 
  • Like
Reactions: MWNu72

AtlBo

Level 28
Verified
Top Poster
Content Creator
Well-known
Dec 29, 2014
1,717
OSForensics - Digital investigation for a new era by PassMark Software®

Thanks. Wow. Who knows what that does.

Wouldn't it be nice if MS had ever made a program that would check all the systems and then scour through logs to find potential malware abnormalities? Well, I guess we have sfc /scannow and chkdsk LOL.

LoL, Exactly, I find it relatively quite impressive to be honest! :D

Yeah, they do have a weird way to solving most problems.

Not at all, and who are we to whine and complain?
C'mon Man, at least they are humble enough to give us sfc and chk,
I find it quite heartwarming and charming to be honest. :D

LOL :D
 
Last edited by a moderator:

AtlBo

Level 28
Verified
Top Poster
Content Creator
Well-known
Dec 29, 2014
1,717
Edit: Joke indeed, And while Mr. Russovich has shown us all the great Process Explorer in all these years, M$ just clings on to The Minghty Task Manager.
Tell Me Why?

i have a long list pending since years of, "Wouldn't it be nice if MS had" but aint nobody listening.

Um. Well. Err. Let's see. Uh...:)

Edit->How about this?->Windows is like a college level IQ test for kindergartners. It's so Microsoft that it must be the most brilliant thing I have ever run across in my life. Honestly, I can't believe what I'm looking at most of the time. I cannot see how it could have been done any more Microsoft :D

Edit 2->or is it a kindergarten IQ test for college level adults? :rolleyes: OR?

Edit 3->Wait...it's M-I-C-R-O-S-O-F-T. Of course!
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top