Compromised Windows System Live Data Gathering Checklist
Compromised Windows System Live Data Gathering Checklist
OR
Create and save memory dump
Command: LastActivityView.exe
Compute MD5 and SHA256 hashes of executable files in
%WINDIR%\System32, %SystemDrive%\Temp\, and all files in
%TEMP%
Command: PrcView/pv.exe –e
Command: chcp
Directory listing
Command: whoami
Windows Version
Command: ver
Command: systeminfo
Command: tasklist /V
Command: tasklist /M
List ARP
Command: arp –a
Find the Default Gateway MAC address
List users
Command: nbtstat -c
Command: nbtstat –S
Command: cports.exe
Command: sysinternals\autorunsc.exe
Command: sysinternals\psfile.exe
Command: sysinternals\pslist.exe
Command: sysinternals\PsLoggedon.exe
Command: sysinternals\psloglist.exe
Command: sysinternals\Tcpvcon.exe –a
Command: sysinternals\streams.exe –a
Run WinAudit
Command: WinAudit.exe
/r=gsoPxuTUeERNtnzDaIbMpmdcSArCHGBLJF
THEN
List Mounted Drives
DATE: ______________________________________________________________________________