[ << ALL_FEED ]

Recovering EVTX records: carving methods

More in General

Recovering EVTX records: carving methods 🧩

When investigating incidents where attackers encrypt virtual machine images, a situation often arises in which the file system is damaged to such an extent that standard mounting becomes impossible.

Restoring it manually is theoretically possible, but it takes a lot of time and is accompanied by data loss. In such cases, carving is used — a byte-by-byte search for signatures directly in the raw image, bypassing the file system.

❗️ The PT ESC IR team prioritizes automating the parsing of artifacts for subsequent detection of malicious activity — this speeds up reconstructing the picture of the incident.

Our pipeline is predominantly implemented in Go, so we developed our own library in the same language. It parses ready-made EVTX files even when checksums do not match or the file is damaged, and also performs carving of events from bitwise copies, memory dumps, and virtual disk images.

For more on what can be recovered and why some approaches yield the full record structure while others yield only individual fields, read our article on Habr 🫲

#ir #dfir #tip
@ptescalator

More from oUth0R

More from oUth0R

More in General