Track files and folders manipulation in Windows

Source: Internet
Author: User

The scenario is on business Secret and our client does worry about data leakage. They want to know whether Suspect copy those data to external hard drive or not. In fact it's not easy for forensic guys to answer this question. Of course if copy data from local drive to external drive and then access those files in external drive, there'll be Some LNK files created.

But if you are only copy files and folders from the local drive to external drive in Windows, you could not the find any "copy ARTIFAC TS "in log files or registry ... So how does we know if Suspect copy files and folders to external drive or not? as I know that the only-to-do-to-monitor and record files and folders manipulation, and you could take A look at logs-see-what ' s going on.

You could use commercial solutions like Ip-guard, etc.

It could also record copy operation to network drive.

There is a free solution called "Windows Explorer Tracker". As you could see that a external USB hard drive plug on at 15:31:15. Its driver is "G:" and the volume label was "HD-PNFU3". Then an Excel file "main service server password a list." XLS "created in" D: ", and we could say that this file could come from" G: ", the USB Externa L Hard drive.  And then some files created in "D:\ #1016" in a very short time, so we could say the those files also came from "G:". Let's see how happen to that xls file as below:

1. At 15:40:46 this XLS file being renamed to "123.xls".

2. At 15:40:59 a LNK file pointed to 123.xls created in "recent". That means Suspect double click on the that XLS file and took a look at its content.

3. At 15:45:58 Suspect deleted "123.xls" in "D:\".

By the-the-there is a file called "top-secret" created in "G:\" at 15:45:08. That means the This file is come from the local drives and being copied to the USB external hard drive "g:\".

Now we just need to find out where the USB external hard drive are, and search for file ' top-secret ' and other files as AB Ove. Then we could know if Suspect do copy folders and files from the local drives to external drives.

Track files and folders manipulation in Windows

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.