The user downloaded what they thought was the SysInternals tool suite, double-clicked it, but the tools did not open and were not accessible. Since that time, the user has noticed that the system has « slowed down » and become less and less responsive. Goal is to determine what happened, and when. Files can be downloaded HERE…
BSides Amman 2021 2nd Edition
Windows Forensics Workshop CASE OVERVIEW: You have been given a system that has been used for some illegal activity were the user accessed confidential files that the user was not supposed to access. The system has two user accounts which are the main suspects involved in this case (« joker » and « IEUser »). You are required to…