๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
  • Tried. Failed. Logged.
๐Ÿ”’์ •๋ณด๋ณด์•ˆ/๋””์ง€ํ„ธ ํฌ๋ Œ์‹

๋””์ง€ํ„ธ ํฌ๋ Œ์‹ - Jumplist

by Janger 2024. 11. 6.
728x90

 

 

์ถœ์ฒ˜: 

 

https://shsh010914.tistory.com/66

 

Jumplist ๊ฐœ๋… ๋ฐ ์‹ค์Šต

[Jumplist] ์ตœ๊ทผ ์‚ฌ์šฉํ•œ ํŒŒ์ผ/ํด๋”์— ๋น ๋ฅด๊ฒŒ ์ ‘๊ทผํ•˜๊ธฐ ์œ„ํ•œ ๊ตฌ์กฐ๋ฅผ ๋งํ•œ๋‹ค. Jumplist์˜ ์ข…๋ฅ˜๋กœ๋Š” ์šด์˜์ฒด์ œ๊ฐ€ ์ž๋™์œผ๋กœ ๋‚จ๊ธฐ๋Š” ํ•ญ๋ชฉ์ธ Automatic๊ณผ ์‘์šฉํ”„๋กœ๊ทธ๋žจ์ด ์ž์ฒด์ ์œผ๋กœ ๊ด€๋ฆฌํ•˜๋Š” ํ•ญ๋ชฉ์ธ Custom์ด

shsh010914.tistory.com

 

[Jumplist]

 

์ตœ๊ทผ ์‚ฌ์šฉํ•œ ํŒŒ์ผ/ํด๋”์— ๋น ๋ฅด๊ฒŒ ์ ‘๊ทผํ•˜๊ธฐ ์œ„ํ•œ ๊ตฌ์กฐ๋ฅผ ๋งํ•œ๋‹ค. Jumplist์˜ ์ข…๋ฅ˜๋กœ๋Š” ์šด์˜์ฒด์ œ๊ฐ€ ์ž๋™์œผ๋กœ ๋‚จ๊ธฐ๋Š” ํ•ญ๋ชฉ์ธ Automatic๊ณผ ์‘์šฉํ”„๋กœ๊ทธ๋žจ์ด ์ž์ฒด์ ์œผ๋กœ ๊ด€๋ฆฌํ•˜๋Š” ํ•ญ๋ชฉ์ธ Custom์ด ์กด์žฌํ•œ๋‹ค.

 

๊ฒฝ๋กœ๋Š” ์•„๋ž˜์™€ ๊ฐ™๋‹ค.

%UserProfile%\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
%UserProfile%\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations

 

 

 

[Practice]

 

 

FTK Imager๋ฅผ ์—ด์–ด Add Evidence Item\Logical Drive\C ๋“œ๋ผ์ด๋ธŒ ๋“ฑ๋ก์„ ์‹คํ–‰ํ•œ ๋‹ค์Œ์— %UserProfile%\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations๊ณผ %UserProfile%\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations์„ ์ถ”์ถœํ•œ๋‹ค.

 

์ถ”์ถœํ•œ AutomaticDestinations๊ณผ CustomDestinations์„ ๋ณด๊ธฐ ์œ„ํ•ด JumpList Explorer๋ฅผ ๋‹ค์šด๋กœ๋“œํ•œ๋‹ค.

 

https://ericzimmerman.github.io/#!index.md

 

Eric Zimmerman's tools

 

ericzimmerman.github.io

 

 

์ถ”์ถœํ•œ AutomaticDestinations๊ณผ CustomDestinations์„ ์—ด๋ฉด App ID ๋ณ„๋กœ ํ™•์ธ์ด ๊ฐ€๋Šฅํ•˜๋‹ค. ์ด๋•Œ, ์•Œ๋ ค์ง€์ง€ ์•Š์€ App ID์˜ ๊ฒฝ์šฐ Unknown AppID๋กœ ๋‚˜ํƒ€๋‚œ๋‹ค.

 

 

์ƒ๋‹จ์˜ ์ •๋ณด๋ฅผ ํด๋ฆญํ•˜์—ฌ ํ•˜๋‹จ์˜ ์„ธ๋ถ€ ์ •๋ณด๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์™ผ์ชฝ ํ•˜๋‹จ์—๋Š” ๊ฐ๊ฐ์˜ LNK ํŒŒ์ผ๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ๊ณ , ์˜ค๋ฅธ์ชฝ ํ•˜๋‹จ์—๋Š” ๊ฐ LNK ํŒŒ์ผ์— ๋Œ€ํ•œ Target ์ •๋ณด๋ฅผ ๋ณด์—ฌ์ค€๋‹ค.

 

 

JumpList Explorer๋ฅผ ํ†ตํ•ด ํŒŒ์ผ ์ถ”์ถœ๋„ ๊ฐ€๋Šฅํ•˜๋‹ค. Windows Powershell์— ๋Œ€ํ•ด ์ถ”์ถœ์„ ์ง„ํ–‰ํ•œ๋‹ค.

 

 

์œ„์™€ ๊ฐ™์ด Windows Powershell์— ๋Œ€ํ•œ ํŒŒ์ผ ์ถ”์ถœ์ด ์™„๋ฃŒ๋˜์—ˆ๋‹ค.

 

 

Chrome์—์„œ ๋‚ด๊ฐ€ ๊ฒ€์ƒ‰ํ•œ ๊ธฐ๋ก๋“ค๋„ ํ™•์ธ์ด ๊ฐ€๋Šฅํ•˜๋‹ค.

 

728x90