Friday, October 22, 2010

Windows Persistence

I wrote up a post on the SANS Digital Forensics blog titled Digital Forensics: Persistence Registry keys where I gave a couple of links to text files containing Registry keys for Windows XP SP3 system that I'd run Autoruns on to gather a list of Registry keys that could (possibly) be used as persistence vector's for malware.

I have collected similar lists for Windows Vista and Windows 7. The files are available at trustedsignal.com/IR.

Grand Canyon: Rim-to-Rim 1 of n

I hadn't intended to drive for 16 hours. It's around midnight and my friend and I are about two hours away from Bright Angel Lodge a...