A look inside ESE

More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
Looking inside ESE 🫣
During incident investigations, we at PT ESC IR regularly encounter the need to analyze databases in the ESE (Extensible Storage Engine) format, since such artifacts can contain a lot of interesting information.
To work with such files more efficiently, it is important to understand how this format is structured internally. Therefore, based on the results of our research, we have prepared a detailed breakdown of the internal structure of ESE (also known as Jet Blue) — Microsoft’s built-in DBMS, which is used in many of the company’s products.
In the article, we explain how data storage is organized at a low level, how pages and records are structured, and also examine implementation details of the engine that may be useful when analyzing database contents and developing your own parsers for working with such files.
🫱 Details — on Habr.
#ir #dfir #win #tip
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…



