Daily Blog #716: Sunday Funday 1/12/25
2025-1-13 01:10:0 Author: www.hecfblog.com(查看原文) 阅读量:5 收藏

By January 12, 2025

 

Hello Reader,

It's Sunday! That means it's time for another challenge. This week are going back to our roots with some digital forensics artifact testing. SRUM is collected, parsed and relied on by multiple types of investigations but how many of us have ever validated the metrics it presents?

The Prize:


$100 Amazon Giftcard

The Rules:

  1. You must post your answer before Friday 1/17/25 7PM CST (GMT -5)
  2. The most complete answer wins
  3. You are allowed to edit your answer after posting
  4. If two answers are too similar for one to win, the one with the earlier posting time wins
  5. Be specific and be thoughtful
  6. Anonymous entries are allowed, please email them to [email protected]. Please state in your email if you would like to be anonymous or not if you win.
  7. In order for an anonymous winner to receive a prize they must give their name to me, but i will not release it in a blog post
  8. AI assistance is welcomed but if a post is deemed to be entirely AI written it will not qualify for a prize. 

The Challenge:

With so many of us relying on SRUM for so many different uses its time to do some validation on the counters so many people cite. For this challenge you will test and validate the following SRUM collected metrics and document if they accurately capture the data or if there is a skew present. 

Use cases to test and validate on Windows 11 or Windows 10 but you must document which:

1. Copying data between two drives using copy and paste (look for disk read and write activity )

2. Uploading data to an online service of your choice (look for process network traffic)

3. Wiping files (look for disk read and write activity)

bonus points for attempting different popular utilities/functions. 


文章来源: https://www.hecfblog.com/2025/01/daily-blog-716-sunday-funday-11225.html
如有侵权请联系:admin#unsafe.sh