Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 6 additions & 2 deletions scripts/artifacts/chromiumSessions.py
Original file line number Diff line number Diff line change
Expand Up @@ -25,8 +25,12 @@
"current releases, and Current Session and Last Session in the profile folder of older "
"ones, as in lonewolf_win10's Chrome profile; Sessions_Encrypted/Session_<number> is "
"matched too. Browser, Profile and User come from the path: the browser from the user "
"data folder, the profile from the folder inside it, and the user from the home folder "
"that holds it; Source File names the file each row came from. Browser, Profile and User "
"data folder, the profile from the folder inside it, and the user from the home "
"folder that holds it; Source File names the file each row came from. Window ID "
"is read from each record, and Window ID, Browser, Profile and User do not "
"separate the session files of one profile, as lonewolf_win10's profile holds "
"both a Current Session and a Last Session, so "
"Source File is what names the file. Browser, Profile and User "
"each held one value on every row of lonewolf_win10, which carries one Chrome profile in "
"one home folder, and User held one value on every row of pc_mus_001_win11, whose Chrome "
"and Edge profiles sit in one home folder. Only the Windows Google Chrome and Microsoft "
Expand Down
8 changes: 5 additions & 3 deletions scripts/artifacts/macosTCC.py
Original file line number Diff line number Diff line change
Expand Up @@ -22,9 +22,11 @@
"requirements": "none",
"category": "App Permissions (macOS)",
"notes": "Every TCC.db found is parsed (the system store under "
"/Library/Application Support/com.apple.TCC/ and each user's "
"under ~/Library/Application Support/com.apple.TCC/), tagged by "
"Source File. Service is shown without its kTCCService prefix. "
"/Library/Application Support/com.apple.TCC/ and each user's under "
"~/Library/Application Support/com.apple.TCC/), tagged by Source File. No other "
"column names the store: Access and the rest are read from each row, so they do "
"not separate the system store from a user's, and Source File names the store "
"each row came from. Service is shown without its kTCCService prefix. "
"Client Type is decoded (0 Bundle ID, 1 Absolute path) and the "
"Client is a bundle identifier or an on-disk path accordingly. "
"Access is decoded from auth_value on modern schemas (0 Not "
Expand Down
8 changes: 5 additions & 3 deletions scripts/artifacts/windowsJumpLists.py
Original file line number Diff line number Diff line change
Expand Up @@ -50,9 +50,11 @@
"notes": "Rows from the shell links inside a user's jump list files, read "
"from the files named in Source File. Each row is one destination "
"shell link. List Type is Automatic for an .automaticDestinations-ms "
"file and Custom for a .customDestinations-ms file. App ID is the "
"jump list file name, an application identifier, as stored; it is not "
"resolved to an application name here. An automatic jump list is an "
"file and Custom for a .customDestinations-ms file. App ID is the jump list file "
"name, an application identifier, as stored; it is not resolved to an application"
" name here. App ID does not separate two users' jump lists for one application, "
"and no column here names the user, so Source File names the file each row came "
"from. An automatic jump list is an "
"OLE compound file whose numbered streams are each a shell link, "
"ordered here by its DestList stream. MRU Position is the entry's "
"place in the DestList's stored order, 1 first; on the tested images "
Expand Down
6 changes: 5 additions & 1 deletion scripts/artifacts/windowsPrefetch.py
Original file line number Diff line number Diff line change
Expand Up @@ -81,7 +81,11 @@
"with many loaded files produces many rows. Executable is the name "
"from the prefetch header and Loaded File is the referenced path as "
"stored, usually in \\VOLUME{...}\\ form naming the volume by its "
"GUID and serial. Prefetch File is the .pf file name. The list is "
"GUID and serial. "
"Prefetch File is the .pf file name. Prefetch File does not separate two copies "
"of one prefetch file, and the declared path also matches a Prefetch folder under"
" Windows.old, so Source File names the file each row came from."
" The list is "
"what the program referenced when it was prepared to run, which "
"includes its own image, its DLLs and data files it opened. A "
"prefetch file records that Windows prepared an executable to run. "
Expand Down
8 changes: 5 additions & 3 deletions scripts/artifacts/windowsThumbcache.py
Original file line number Diff line number Diff line change
Expand Up @@ -56,9 +56,11 @@
"not surfaced. Thumbnail is the cached image extracted from the "
"entry and shown inline; the entry data is sniffed and only a real "
"image (PNG, JPEG, BMP or GIF) is shown, with its format in Data "
"Format and byte count in Data Size. Cache Size is the thumbnail "
"size the file name encodes (for example 256 from thumbcache_256.db, "
"or sr, wide, exif, idx as stored). Cache Entry ID is the entry's "
"Format and byte count in Data Size. Cache Size is the thumbnail size the file "
"name encodes (for example 256 from thumbcache_256.db, or sr, wide, exif, idx as "
"stored). Cache Size does not separate two users' files of one size, and no "
"column here names the user, so Source File names the file each row came from. "
"Cache Entry ID is the entry's "
"64-bit ThumbnailCacheId as hex. Identifier is the entry's own "
"identifier string as stored, which is sometimes a file path, a "
"shell folder GUID or the entry id, and is not a reliable file name. "
Expand Down
Loading