Beruflich Dokumente
Kultur Dokumente
7:
Current
Events
in
the
World
of
Windows
Forensics
OS Artifacts
File Systems
NTFS, FAT32, ExFAT
Fvevol.sys
Mount, Partition & Volume
Managers
• Thanks
to
Eoghan
Casey.
“Disk”
OS Artifacts
File Systems
NTFS, FAT32, ExFAT
Fvevol.sys
Mount, Partition & Volume
Managers
“Disk”
Note
disk
signature:
2E140032
0x1b8-‐1bb
Note
disk
signature:
2E140032
0x1b8-‐1bb
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\STORAGE\Volume\
1&19f7e59c&0&Signature2E140032Offset100000Length114FD00000
OS Artifacts
File Systems
NTFS, FAT32, ExFAT
Fvevol.sys
Mount, Partition & Volume
Managers
“Disk”
OS Artifacts
File Systems
NTFS, FAT32, ExFAT
Fvevol.sys
Mount, Partition & Volume
Managers
“Disk”
• Physical
level
view
of
the
header
of
the
boot
sector
of
the
second
parXXon,
the
BitLocker
protected
volume:
– 0xEB
52
90
2D
46
56
45
2D
46
53
2D
– ëR-‐FVE-‐FS-‐
• Physical
level
view
of
the
header
of
the
boot
sector
of
the
second
parXXon,
the
BitLocker
protected
volume:
– 0xEB
58
90
2D
46
56
45
2D
46
53
2D
– ëX-‐FVE-‐FS-‐
Application
User
Mode
Kernel
Mode
Fvevol.sys
Volume Manager
BitLocker
Drive
EncrypXon
Recovery
Key
The
recovery
key
is
used
to
recover
the
data
on
a
BitLocker
protected
drive.
To
verify
that
this
is
the
correct
recovery
key
compare
the
idenXficaXon
with
what
is
presented
on
the
recovery
screen.
OS Artifacts
File Systems
NTFS, FAT32, ExFAT
Fvevol.sys
Mount, Partition & Volume
Managers
“Disk”
hfp://msdn.microsoi.com/en-‐us/library/aa914353.aspx
OS Artifacts
File Systems
NTFS, FAT32, ExFAT
Fvevol.sys
Mount, Partition & Volume
Managers
“Disk”
\\localhost\C$\@GMT-‐2009.07.17-‐08.45.26\
Every
shadow
copy
data
set
should
approximate
the
size
of
the
original
volume.
Amount
of
case
data=(number
of
shadow
copies)
x
(size
of
the
volume)+(size
of
the
volume).