Forensic Lab: Artifact Deep Dives
The Forensic Lab is the technical core of the Hermes Codex. Here, we dissect the traces left by OS operations, user activities, and threat actors to build undeniable evidence timelines.
🐧 Linux Forensics & Incident Response
Section titled “🐧 Linux Forensics & Incident Response”Deep dives into Unix-like artifacts for tracking intrusions, persistence, and lateral movement.
Authentication Logs Tracking SSH intrusions and sudo privilege escalation (auth.log, secure).
Connection Logs Analyzing wtmp, btmp, and lastlog for successful/failed logins and log wiping.
Account & Privileges Auditing passwd, shadow, and group to detect backdoor accounts (UID 0).
Sudoers Analysis Detecting unauthorized NOPASSWD access and LPE via GTFOBins.
Shell History Extracting post-compromise activity from .bash_history and memory buffers.
Text Editor Artifacts Extracting data from .viminfo, .nano_history, and .swp files.
SSH Artifacts Investigating authorized_keys, known_hosts, and stolen private keys.
Legacy Persistence Hunting for stealthy persistence in init.d, rc.local, and profile.d.
Systemd Persistence Analyzing malicious Unit files, Timers, and Drop-in modifications.
Advanced Persistence (Rootkits) Detecting LD_PRELOAD, Kernel Modules, and eBPF backdoors.
Filesystem & MAC Times Decoding POSIX MAC times, Inodes, and detecting timestomping.
Package Managers Verifying system binary integrity (APT/DPKG, DNF/RPM).
Process & Memory (Live) Hunting fileless malware via /proc and RAM acquisition.
Exfiltration & Staging Detecting LOLBAS abuse (curl, wget, tar) and cloud sync tools.
🪟 Windows: Event Logs & Telemetry
Section titled “🪟 Windows: Event Logs & Telemetry”Core OS logging mechanisms to trace attacker movement and configuration changes.
Event 4624/4625 (Logons) Decoding Logon Types, Pass-the-Hash, and Password Spraying.
Event 4688 (Process Creation) Reconstructing process trees and hunting for LOLBAS execution.
Event 4663/5145 (Object Access) Hunting Ransomware, Honeytokens, and SMB access via SACLs.
Event 7045/4698 (Modifications) Detecting malicious services and rogue scheduled tasks.
Sysmon (System Monitor) Detailed telemetry, ProcessGuid correlation, and threat hunting.
Process Lineage Analysis Core behavioral concepts for detecting advanced intrusions.
🪟 Windows: Execution Artifacts
Section titled “🪟 Windows: Execution Artifacts”Artifacts used to prove that a specific binary executed on a system.
Prefetch (.pf) Proving binary execution and timing.
Amcache & RecentFileCache Identifying binary identity and SHA1 hashes.
Shimcache (AppCompatCache) Tracking long-term executable metadata.
SRUM Tracking historical network activity and data exfiltration.
BAM (Background Activity) Linking binary execution definitively to a specific user SID.
WER (Error Reporting) Uncovering historical execution of unstable malware and crashes.
🗂️ Windows: File System & User Activity
Section titled “🗂️ Windows: File System & User Activity”Artifacts that reconstruct user navigation, intent, and data staging.
MFT ($MFT) Deep dive into the Master File Table and Timestomping detection.
USN Journal ($UsnJrnl) Tracking file creation, modification, and deletion timelines.
LNK Files (Shortcuts) Tracking interaction with deleted payloads and lateral movement.
UserAssist & MUIcache Tracking GUI-based program execution and run counts.
Shellbags Reconstructing folder navigation history and enumeration.
Jumplists Analyzing application-specific user interactions and opened files.
MRU Lists Following direct user interaction with the run dialog and file system.
Alternate Data Streams (ADS) Tracking the Mark of the Web (MoTW) and hidden malicious payloads.
⚔️ Windows: Evasion & Lateral Movement
Section titled “⚔️ Windows: Evasion & Lateral Movement”Tracking how attackers abuse native mechanisms to move and hide in memory.
PsExec & Lateral Movement Investigating service-based execution and network footprint.
WMI (Management Inst.) Detecting fileless persistence via WMI Event Subscriptions.
BITS (Transfer Service) Detecting LOLBAS payload staging and data exfiltration.
Named Pipes (IPC) Analyzing C2 beaconing, SMB encapsulation, and LPE.
DLL Hijacking & Sideloading Detecting Search Order Hijacking and phantom DLL loads.
Process Injection (Basics) Understanding the classic injection API chain and RWX memory.
Advanced Injection (Evasion) Hunting Module Stomping, Memory Mirroring, and Thread Hijacking.
🌐 Network & Edge Appliances (Ivanti)
Section titled “🌐 Network & Edge Appliances (Ivanti)”Forensic triage for proprietary perimeter devices.
Architecture & Versioning Navigating the dual-partition architecture and OS versioning.
Ivanti Log Analysis Parsing cryptic formats to hunt for zero-day web exploitation.
Artifact & Webshell Hunting Hunting webshells, analyzing ICT logs, and detecting trojanized files.