\documentclass[10pt,a4paper]{article} % Packages \usepackage{fancyhdr} % For header and footer \usepackage{multicol} % Allows multicols in tables \usepackage{tabularx} % Intelligent column widths \usepackage{tabulary} % Used in header and footer \usepackage{hhline} % Border under tables \usepackage{graphicx} % For images \usepackage{xcolor} % For hex colours %\usepackage[utf8x]{inputenc} % For unicode character support \usepackage[T1]{fontenc} % Without this we get weird character replacements \usepackage{colortbl} % For coloured tables \usepackage{setspace} % For line height \usepackage{lastpage} % Needed for total page number \usepackage{seqsplit} % Splits long words. %\usepackage{opensans} % Can't make this work so far. Shame. Would be lovely. \usepackage[normalem]{ulem} % For underlining links % Most of the following are not required for the majority % of cheat sheets but are needed for some symbol support. \usepackage{amsmath} % Symbols \usepackage{MnSymbol} % Symbols \usepackage{wasysym} % Symbols %\usepackage[english,german,french,spanish,italian]{babel} % Languages % Document Info \author{koriley} \pdfinfo{ /Title (windows-ir-live-forensics.pdf) /Creator (Cheatography) /Author (koriley) /Subject (Windows IR Live Forensics Cheat Sheet) } % Lengths and widths \addtolength{\textwidth}{6cm} \addtolength{\textheight}{-1cm} \addtolength{\hoffset}{-3cm} \addtolength{\voffset}{-2cm} \setlength{\tabcolsep}{0.2cm} % Space between columns \setlength{\headsep}{-12pt} % Reduce space between header and content \setlength{\headheight}{85pt} % If less, LaTeX automatically increases it \renewcommand{\footrulewidth}{0pt} % Remove footer line \renewcommand{\headrulewidth}{0pt} % Remove header line \renewcommand{\seqinsert}{\ifmmode\allowbreak\else\-\fi} % Hyphens in seqsplit % This two commands together give roughly % the right line height in the tables \renewcommand{\arraystretch}{1.3} \onehalfspacing % Commands \newcommand{\SetRowColor}[1]{\noalign{\gdef\RowColorName{#1}}\rowcolor{\RowColorName}} % Shortcut for row colour \newcommand{\mymulticolumn}[3]{\multicolumn{#1}{>{\columncolor{\RowColorName}}#2}{#3}} % For coloured multi-cols \newcolumntype{x}[1]{>{\raggedright}p{#1}} % New column types for ragged-right paragraph columns \newcommand{\tn}{\tabularnewline} % Required as custom column type in use % Font and Colours \definecolor{HeadBackground}{HTML}{333333} \definecolor{FootBackground}{HTML}{666666} \definecolor{TextColor}{HTML}{333333} \definecolor{DarkBackground}{HTML}{034454} \definecolor{LightBackground}{HTML}{F7F9F9} \renewcommand{\familydefault}{\sfdefault} \color{TextColor} % Header and Footer \pagestyle{fancy} \fancyhead{} % Set header to blank \fancyfoot{} % Set footer to blank \fancyhead[L]{ \noindent \begin{multicols}{3} \begin{tabulary}{5.8cm}{C} \SetRowColor{DarkBackground} \vspace{-7pt} {\parbox{\dimexpr\textwidth-2\fboxsep\relax}{\noindent \hspace*{-6pt}\includegraphics[width=5.8cm]{/web/www.cheatography.com/public/images/cheatography_logo.pdf}} } \end{tabulary} \columnbreak \begin{tabulary}{11cm}{L} \vspace{-2pt}\large{\bf{\textcolor{DarkBackground}{\textrm{Windows IR Live Forensics Cheat Sheet}}}} \\ \normalsize{by \textcolor{DarkBackground}{koriley} via \textcolor{DarkBackground}{\uline{cheatography.com/12660/cs/11352/}}} \end{tabulary} \end{multicols}} \fancyfoot[L]{ \footnotesize \noindent \begin{multicols}{3} \begin{tabulary}{5.8cm}{LL} \SetRowColor{FootBackground} \mymulticolumn{2}{p{5.377cm}}{\bf\textcolor{white}{Cheatographer}} \\ \vspace{-2pt}koriley \\ \uline{cheatography.com/koriley} \\ \end{tabulary} \vfill \columnbreak \begin{tabulary}{5.8cm}{L} \SetRowColor{FootBackground} \mymulticolumn{1}{p{5.377cm}}{\bf\textcolor{white}{Cheat Sheet}} \\ \vspace{-2pt}Published 4th April, 2017.\\ Updated 5th April, 2017.\\ Page {\thepage} of \pageref{LastPage}. \end{tabulary} \vfill \columnbreak \begin{tabulary}{5.8cm}{L} \SetRowColor{FootBackground} \mymulticolumn{1}{p{5.377cm}}{\bf\textcolor{white}{Sponsor}} \\ \SetRowColor{white} \vspace{-5pt} %\includegraphics[width=48px,height=48px]{dave.jpeg} Measure your website readability!\\ www.readability-score.com \end{tabulary} \end{multicols}} \begin{document} \raggedright \raggedcolumns % Set font size to small. Switch to any value % from this page to resize cheat sheet text: % www.emerson.emory.edu/services/latex/latex_169.html \footnotesize % Small font. \begin{multicols*}{2} \begin{tabularx}{8.4cm}{x{4.08 cm} x{3.92 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Unusual Network Usage}} \tn % Row 0 \SetRowColor{LightBackground} {\bf{Look at File Shares}} & `net view \textbackslash{}\textbackslash{}127.0.0.1` \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} {\bf{Open Sessions with Machine}} & `net session` \tn % Row Count 4 (+ 2) % Row 2 \SetRowColor{LightBackground} {\bf{Session This machine has Opened}} & `net use` \tn % Row Count 6 (+ 2) % Row 3 \SetRowColor{white} {\bf{NetBIOS over TCP/IP Activity}} & `nbtstat -S` \tn % Row Count 8 (+ 2) % Row 4 \SetRowColor{LightBackground} {\bf{List Listening TCP and UDP Ports}} & `netstat -na` \tn % Row Count 10 (+ 2) % Row 5 \SetRowColor{white} {\bf{5 - Continuous Scrolling every 5 seconds}} & `netstat -na 5` \tn % Row Count 13 (+ 3) % Row 6 \SetRowColor{LightBackground} {\bf{-o flag shows process ID -b flag shows executable}} & `netstat -naob` \tn % Row Count 16 (+ 3) % Row 7 \SetRowColor{white} {\bf{Inspect Firewall rules}} & `netsh advfirewall show currentprofile` \tn % Row Count 19 (+ 3) % Row 8 \SetRowColor{LightBackground} & `netsh firewall show config` \tn % Row Count 21 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{4.48 cm} x{3.52 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Unusual Accounts}} \tn % Row 0 \SetRowColor{LightBackground} {\bf{Unexpected Users in the Administrators Group}} & `lusrmgr.msc` \tn % Row Count 3 (+ 3) % Row 1 \SetRowColor{white} {\bf{List Users}} & `net user` \tn % Row Count 4 (+ 1) % Row 2 \SetRowColor{LightBackground} {\bf{List Members of Admin Group}} & `net localgroup administrators` \tn % Row Count 6 (+ 2) % Row 3 \SetRowColor{white} {\bf{List Domain Users}} & `net user /domain` \tn % Row Count 8 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}--} \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{{\bf{When looking at domain accounts, the command will be run on the domain controller. A large domain may take some time - redirect to a text file to analyze:}} \newline `net user /domain \textgreater{} domainUsers.txt`} \tn \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{2.64 cm} x{5.36 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Windows Security \& System Events To Look For}} \tn % Row 0 \SetRowColor{LightBackground} {\bf{Security 4720}} & User Account Created \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} {\bf{Security 4722}} & User Account Enabled \tn % Row Count 4 (+ 2) % Row 2 \SetRowColor{LightBackground} {\bf{Security 4724}} & Password Reset \tn % Row Count 6 (+ 2) % Row 3 \SetRowColor{white} {\bf{Security 4738}} & User Account Change \tn % Row Count 8 (+ 2) % Row 4 \SetRowColor{LightBackground} {\bf{Security 4732}} & Accout Added or Removed From Group \tn % Row Count 10 (+ 2) % Row 5 \SetRowColor{white} {\bf{Security 1102}} & Audit Log Cleared \tn % Row Count 12 (+ 2) % Row 6 \SetRowColor{LightBackground} {\bf{System 7030}} & Basic Service Operations \tn % Row Count 14 (+ 2) % Row 7 \SetRowColor{white} {\bf{System 7045}} & Service Was Installed \tn % Row Count 16 (+ 2) % Row 8 \SetRowColor{LightBackground} {\bf{System 1056}} & DHCP Server Oddities \tn % Row Count 18 (+ 2) % Row 9 \SetRowColor{white} {\bf{System 10000}} & COM Functionality \tn % Row Count 20 (+ 2) % Row 10 \SetRowColor{LightBackground} {\bf{System 20001}} & Device Driver Installation \tn % Row Count 22 (+ 2) % Row 11 \SetRowColor{white} {\bf{System 20002}} & Remote Access \tn % Row Count 24 (+ 2) % Row 12 \SetRowColor{LightBackground} {\bf{System 20003}} & Service Installation \tn % Row Count 26 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{3.92 cm} x{4.08 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Search for Other Startup Items}} \tn % Row 0 \SetRowColor{LightBackground} {\bf{Users' Autostart Folders}} & `dir /s /b "C:\textbackslash{}Documents and Settings\textbackslash{} {\emph{{[}user name{]}}}\textbackslash{}Start Menu\textbackslash{}"` \tn % Row Count 4 (+ 4) % Row 1 \SetRowColor{white} & `dir /s /b "C:\textbackslash{}Users\textbackslash{} {\emph{{[}user name{]}}}\textbackslash{}Start Menu\textbackslash{}"` \tn % Row Count 7 (+ 3) % Row 2 \SetRowColor{LightBackground} {\bf{Use WMIC To find Start Up Programs}} & `wmic startup list full` \tn % Row Count 9 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{3.6 cm} x{4.4 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Unusual Processes}} \tn % Row 0 \SetRowColor{LightBackground} {\bf{Task List}} & `tasklist` \tn % Row Count 1 (+ 1) % Row 1 \SetRowColor{white} & `wmic process list full' \tn % Row Count 3 (+ 2) % Row 2 \SetRowColor{LightBackground} Parend Process ID & `wmic process get name,parentprocessid, processid` \tn % Row Count 6 (+ 3) % Row 3 \SetRowColor{white} {\bf{Command-Line Options and DLLs}} & `tasklist /m /fi "pid eq {[}pid{]}"` \tn % Row Count 8 (+ 2) % Row 4 \SetRowColor{LightBackground} & `wmic process where processid={[}pid{]} get commandline` \tn % Row Count 11 (+ 3) \hhline{>{\arrayrulecolor{DarkBackground}}--} \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{{\bf{Run Task Manager: Start-\textgreater{}Run... and type}} `taskmgr.exe` \newline {\emph{- Look for unusual/unexpected processes}} \newline {\emph{- Focus on processes with username {\bf{SYSTEM}} or {\bf{ADMINISTRATOR}} or user in the {\bf{Local Administrator's}} group.}}} \tn \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{6.08 cm} x{1.92 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Unusual Scheduled Tasks}} \tn % Row 0 \SetRowColor{LightBackground} {\bf{List System Scheduled Tasks}} & \seqsplit{`schtasks`} \tn % Row Count 2 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}--} \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{You can also use the Task Scheduler GUI: \newline {\bf{Start-\textgreater{}Programs-\textgreater{}Accessories-\textgreater{}System Tools-\textgreater{}Scheduled Tasks}} \newline \newline Look for unusual Tasks run as a user of the Local Admin, SYSTEM, or blank username} \tn \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{8.4cm}}{\bf\textcolor{white}{Unusual Reg Key Entries}} \tn \SetRowColor{white} \mymulticolumn{1}{x{8.4cm}}{{\bf{Check the Registry Run keys for malware that has made an entry to launch itself.}} \newline % Row Count 2 (+ 2) \textasciicircum{}- HKLM\textbackslash{}Software\textbackslash{}Microsoft\textbackslash{}Windows\textbackslash{}CurrentVersion\textbackslash{}Run\textasciicircum{} \newline % Row Count 4 (+ 2) \textasciicircum{}- HKLM\textbackslash{}Software\textbackslash{}Microsoft\textbackslash{}Windows\textbackslash{}CurrentVersion\textbackslash{}Runonce\textasciicircum{} \newline % Row Count 6 (+ 2) \textasciicircum{}- HKLM\textbackslash{}Software\textbackslash{}Microsoft\textbackslash{}Windows\textbackslash{}CurrentVersion\textbackslash{}RunonceEx\textasciicircum{} \newline % Row Count 8 (+ 2) \textasciicircum{}- HKCU\textbackslash{}Software\textbackslash{}Microsoft\textbackslash{}Windows\textbackslash{}CurrentVersion\textbackslash{}Run\textasciicircum{} \newline % Row Count 10 (+ 2) \textasciicircum{}- HKCU\textbackslash{}Software\textbackslash{}Microsoft\textbackslash{}Windows\textbackslash{}CurrentVersion\textbackslash{}Runonce\textasciicircum{} \newline % Row Count 12 (+ 2) \textasciicircum{}- HKCU\textbackslash{}Software\textbackslash{}Microsoft\textbackslash{}Windows\textbackslash{}CurrentVersion\textbackslash{}RunonceEx\textasciicircum{} \newline % Row Count 14 (+ 2) `C:\textbackslash{}reg query hklm\textbackslash{}software\textbackslash{}microsoft\textbackslash{}windows\textbackslash{}currentversion\textbackslash{}run`% Row Count 16 (+ 2) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \SetRowColor{LightBackground} \mymulticolumn{1}{x{8.4cm}}{These can also be analyzed with `regedit.exe`. \newline `Autoruns.exe` from {\bf{SystInternals}} will pull all {\bf{Auto Start Entry Points}}.} \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{5.52 cm} x{2.48 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Unusual Services}} \tn % Row 0 \SetRowColor{LightBackground} {\bf{Services Control Panel}} & \seqsplit{`services.msc`} \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} {\bf{List Of Sevices Available}} & `nets start` \tn % Row Count 4 (+ 2) % Row 2 \SetRowColor{LightBackground} {\bf{Show Service Datail}} & `sc query | more` \tn % Row Count 6 (+ 2) % Row 3 \SetRowColor{white} {\bf{Map of Service from Which Process}} & `tasklist /svc` \tn % Row Count 8 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} % That's all folks \end{multicols*} \end{document}