RDP Cache Forensics

Поделиться
HTML-код
  • Опубликовано: 28 дек 2024

Комментарии • 19

  • @AlexisBrignoni
    @AlexisBrignoni 6 лет назад +8

    Thanks for these series, they are excellent.

  • @migwe1019
    @migwe1019 2 года назад +3

    Great video, it really helped me a lot

  • @serhank9436
    @serhank9436 Год назад +1

    Thank you for the video

  • @MadGlitch
    @MadGlitch 4 года назад +2

    Great video, Helped me a ton! Keep it up !

  • @BobTheCat412
    @BobTheCat412 9 месяцев назад +1

    The issue here is that if an attacker uses an RDP connection to my host, I can't view this data because it's only available on their machine.

    • @13Cubed
      @13Cubed  9 месяцев назад

      Yes, but if an attacker moves laterally *within* your environment, the system from which the RDP connection was initiated would have the cache. This has proved useful for me on many occasions.

  • @shantanudeyanik8274
    @shantanudeyanik8274 3 года назад +2

    Thank you sir

  • @elmiklo5939
    @elmiklo5939 6 лет назад +1

    Very informative Sir

  • @emran5897
    @emran5897 6 лет назад +1

    Thanks For The Video...........

  • @learnwithrahulmishra
    @learnwithrahulmishra 3 года назад

    Can we find this cache files after imaging the system?

    • @13Cubed
      @13Cubed  3 года назад

      Not sure I understand your question?

    • @learnwithrahulmishra
      @learnwithrahulmishra 3 года назад

      @@13Cubed will this cache get erased after removing hdd?

    • @13Cubed
      @13Cubed  3 года назад +1

      @@learnwithrahulmishra If you delete the data on the hard drive after you pull it out, yes. Otherwise the data will remain intact on the drive. I'm still not sure I understand what you are asking.

  • @tommyboiret5723
    @tommyboiret5723 6 лет назад

    Hi, when execute the bmc script i've this error "unexpected bpp(0)..", you know what happening please ?

    • @13Cubed
      @13Cubed  6 лет назад

      Looking at the code, it appears as if the cache you are attempting to analyze is corrupt, or otherwise unable to be parsed by the utility (possibly of unexpected size). Can you try RDP cache from an alternate machine and see if you receive the same results?

    • @xZomBz7
      @xZomBz7 6 лет назад

      13Cubed the cache than i should analyse become from forensic challenge of root-me and i dont think it's corrupted. But i can on the wrong way you know which metod/tools i can used for detect corruption ? And i dont have another bmc file for test, i try found this later (it's 1am for me ^^ )

    • @xZomBz7
      @xZomBz7 6 лет назад

      And yes i've already check integrity and it's ok, my bmc file are 9mo. Excuse me i reply with wrong account.

    • @13Cubed
      @13Cubed  6 лет назад

      Interesting. I would suggest another tool, but there really isn't one to my knowledge (besides EnScripts). I haven't had any issues with the tool to this point, so unfortunately I'm afraid I can't be of much help.

    • @xZomBz7
      @xZomBz7 6 лет назад +1

      13Cubed no problem thank you for your answer, anyway your vidéo are really cool Good job.