Section 5: Anti-Forensics & Advanced Recovery

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/9

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:51 PM on 6/16/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

10 Terms

1
New cards

What is the purpose of VSS (Volume Shadow Copy Service) in forensics?

It creates automatic snapshots of the disk, allowing analysts to recover older versions of files or deleted evidence.

2
New cards

What tool from the Shadow Brokers leak can surgically remove event log entries?

DanderSpritz (via its eventlogedit feature).

3
New cards

What are the two primary NTFS journaling files?

$LogFile (records metadata changes for resiliency) and $UsnJrnl (records a high-level log of all file and directory changes).

4
New cards

What does an Alternate Data Stream (ADS) with a Zone.Identifier of 3 indicate?

The file was downloaded from the Internet.

5
New cards

What defensive countermeasure is highly recommended for the USN Journal?

Increase its default size (e.g., from 32MB to 256MB) to extend the historical runway of file system activity it retains.

6
New cards

Why can SSDs be harder for forensic data recovery than HDDs?

Wear-leveling and TRIM features actively clear deleted data blocks, reducing the chance of recovering deleted files.

7
New cards

What is MFT Carving?

Extracting deleted NTFS records from raw space when the standard file system metadata is missing or damaged.

8
New cards

Name common tools used by attackers for file wiping (anti-forensics).

SDelete, BCWipe, Eraser, and cipher.exe.

9
New cards

What is the core purpose of the Stark Research Labs capstone scenario?

To apply all course skills to reconstruct a multi-stage intrusion end-to-end using MITRE ATT&CK.

10
New cards