Recovering EVTX records: carving methods

More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
- Drama Rat: a malicious app that, once installed, really does make you sad
Recently, the Department for Comprehensive Response to Cyberthreats (PT ESC IR) received a number of samples…
Recovering EVTX records: carving methods 🧩
When investigating incidents where attackers encrypt virtual machine images, a situation often arises in which the file system is damaged to such an extent that standard mounting becomes impossible.
Restoring it manually is theoretically possible, but it takes a lot of time and is accompanied by data loss. In such cases, carving is used — a byte-by-byte search for signatures directly in the raw image, bypassing the file system.
❗️ The PT ESC IR team prioritizes automating the parsing of artifacts for subsequent detection of malicious activity — this speeds up reconstructing the picture of the incident.
Our pipeline is predominantly implemented in Go, so we developed our own library in the same language. It parses ready-made EVTX files even when checksums do not match or the file is damaged, and also performs carving of events from bitwise copies, memory dumps, and virtual disk images.
For more on what can be recovered and why some approaches yield the full record structure while others yield only individual fields, read our article on Habr 🫲
#ir #dfir #tip
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
- Drama Rat: a malicious app that, once installed, really does make you sad
Recently, the Department for Comprehensive Response to Cyberthreats (PT ESC IR) received a number of samples…



