ShellBag Forensics

แชร์
ฝัง
  • เผยแพร่เมื่อ 10 พ.ย. 2024

ความคิดเห็น • 26

  • @scottsabo9070
    @scottsabo9070 6 ปีที่แล้ว +3

    I really enjoyed this video. Thanks for sharing. I wish I had more time in the day to watch all of your videos and develop my forensic skills.

  • @bernhardstosik4625
    @bernhardstosik4625 4 ปีที่แล้ว +2

    14:07 minutes full of learnings - thanks, great.

  • @moretwocome21
    @moretwocome21 6 ปีที่แล้ว +1

    @13Cubed the command line freak! Another great video sir! Thank you! Theae are helping me prepare for my interviews!

  • @johnnyguitar4391
    @johnnyguitar4391 ปีที่แล้ว

    great video introducing shell bags

  • @matthewgrady1579
    @matthewgrady1579 6 ปีที่แล้ว +4

    Great video! Good explanations and examples given. Keep it up. This is great content!

  • @davidmacfarlane8228
    @davidmacfarlane8228 4 ปีที่แล้ว +4

    I've been slowly working through the 13cubed archive and this is excellent!! I've read a couple of times (including on Magnet Forensics blog) that Shellbags are located within HKCR when clearly you are showing them within HKCU here... I'm confused!! 🤔

    • @13Cubed
      @13Cubed  4 ปีที่แล้ว

      This article will help: www.lifewire.com/hkey-classes-root-2625899
      Quoting from it: "However, because the HKEY_CLASSES_ROOT hive is actually combined data found in both the HKEY_LOCAL_MACHINE hive (HKEY_LOCAL_MACHINE\Software\Classes) and the HKEY_CURRENT_USER hive (HKEY_CURRENT_USER\Software\Classes), it also contains user-specific information as well. Even though that's the case, the HKEY_CLASSES_ROOT is still able to be browsed by any and all users."
      So, UsrClass.dat (one of the locations containing Shellbags [in addition to NTUSER.DAT]) plugs in to HKCU\Software\Classes, and HKCU\Software\Classes is part of HKCR.

    • @davidmacfarlane8228
      @davidmacfarlane8228 4 ปีที่แล้ว

      Thanks again, that's really helpful. One other thing I wanted to know was whether it was possible to use Shellbag Explorer to examine a disk image? I tried to load offline hives from artefacts extracted from FTK imager but with no success.

  • @JaKeizBrick33
    @JaKeizBrick33 4 ปีที่แล้ว +1

    Your channel is amazing.

  • @ellis6067
    @ellis6067 5 ปีที่แล้ว +2

    Well done! I sense some Rob Lee knowledge influence :)

  • @lollychan666
    @lollychan666 หลายเดือนก่อน

    how to disable shellbags recording logs?

  • @decimator8278
    @decimator8278 3 ปีที่แล้ว +1

    This vid was so helpful!

  • @ahmedmohsen3046
    @ahmedmohsen3046 2 ปีที่แล้ว +1

    What if I create new windows or upgrade current window version are shellbags will be exist for old windows

    • @13Cubed
      @13Cubed  2 ปีที่แล้ว +1

      They should still persist after the upgrade/feature update, but the timestamps may be affected. See this: df-stream.com/2019/10/shellbags-windows-10-feature-updates/

  • @othmanb4222
    @othmanb4222 3 ปีที่แล้ว

    Hello. I liked the content a lot however I'm not a native english speaker and I'm still looking for an exact definition of a shell bag. Is a shell bag:
    1 - a subkey.
    2 - The values stored in a subkey.
    3 - A subkey and its values.
    4 - A subkey, its values and its children keys?
    That would help me a lot.

  • @lucyboi3968
    @lucyboi3968 2 ปีที่แล้ว

    @13cubed Regarding the shellbag explorer demo, how long will the USB data be stored in that shellbag? Will it not be overwritten over time?

    • @13Cubed
      @13Cubed  2 ปีที่แล้ว

      They can be removed by privacy cleaners, or manually, but otherwise those bag entries are persistent and do not expire or become overwritten.

  • @arthifrox
    @arthifrox 4 ปีที่แล้ว +1

    please consider about font size of presentation.

    • @13Cubed
      @13Cubed  4 ปีที่แล้ว

      All later videos have much easier to read fonts. This was recorded quite a while ago.

  • @SecureTheWorld
    @SecureTheWorld 6 ปีที่แล้ว

    Excellent video. Thanks a lot.

  • @SecureTheWorld
    @SecureTheWorld 5 ปีที่แล้ว

    could you please share the software you use to prepare and edit your videos ! thanks a lot for the awesome tutorial as usual!

    • @13Cubed
      @13Cubed  5 ปีที่แล้ว

      Thanks - ScreenFlow and Final Cut Pro X

    • @SecureTheWorld
      @SecureTheWorld 5 ปีที่แล้ว +1

      13Cubed i really appreciate your efforts you do and making this knowledge easily accessible to others!

  • @thextomxriddlex
    @thextomxriddlex 3 หลายเดือนก่อน

    Lmao that introduction 😂

  • @quaidoralious4181
    @quaidoralious4181 หลายเดือนก่อน

    I know a few shellbags