<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>vared - Blog</title>
    <link>https://var3d.tistory.com/</link>
    <description></description>
    <language>ko</language>
    <pubDate>Thu, 9 Apr 2026 22:01:08 +0900</pubDate>
    <generator>TISTORY</generator>
    <ttl>100</ttl>
    <managingEditor>vared</managingEditor>
    <image>
      <title>vared - Blog</title>
      <url>https://tistory1.daumcdn.net/tistory/3899450/attach/27def0fc3a6f48238a88f57d3a807d0b</url>
      <link>https://var3d.tistory.com</link>
    </image>
    <item>
      <title>[Upload] TRIM</title>
      <link>https://var3d.tistory.com/entry/Upload-TRIM</link>
      <description>&lt;p data-ke-size=&quot;size16&quot;&gt;TRIM에 대한 글이 업로드 되었습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;TRIM 기능은 SSD에서 주기적으로 삭제될 예정인 데이터를 처리하는 것으로 디지털 포렌식 관점에서 파일을 복원/카빙할 때 원본 수집 대상이 SSD인 경우 필수적으로 참고해야 하는 기능입니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;SSD의 TRIM 기능만을 살펴본 것이 아닌, 비활성화 되어 있는 경우 활성화 하는 방법과&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;RAID를 사용하거나 Windows 7 이전 운영체제를 사용하는 경우 TRIM 기능을 사용할 수 없다는 내용까지 알아보았습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://www.forensic-cheatsheet.com/etc/trim&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.forensic-cheatsheet.com/etc/trim&lt;/a&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;읽어보시고 궁금한 내용이나 수정해야하는 내용은&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;커뮤니티를 이용해 주시면 감사하겠습니다&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://discord.gg/CDtc5kWWA8&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://discord.gg/CDtc5kWWA8&lt;/a&gt;&lt;/p&gt;</description>
      <category>Digital Forensic</category>
      <category>forensic-cheatsheet</category>
      <category>ssd</category>
      <category>trim</category>
      <author>vared</author>
      <guid isPermaLink="true">https://var3d.tistory.com/191</guid>
      <comments>https://var3d.tistory.com/entry/Upload-TRIM#entry191comment</comments>
      <pubDate>Wed, 31 May 2023 21:38:16 +0900</pubDate>
    </item>
    <item>
      <title>[Upload] MFT Attribute (2)</title>
      <link>https://var3d.tistory.com/entry/Upload-MFT-Attribute-2</link>
      <description>&lt;p data-ke-size=&quot;size16&quot;&gt;Filesystem 게시판의 MFT Attribute(2)에 대한 글이 업로드 되었습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;MFT Attribute(2)에서는 이전 장에서 다루지 못했던 각각의 속성에 대해서 다루어 보았으며&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;소개한 속성들을 이해함을 통해 NTFS 파일시스템에서의 파일 저장에 대한 내용을 이해할 수 있었습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://www.forensic-cheatsheet.com/filesystem/mft-attribute-2&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.forensic-cheatsheet.com/filesystem/mft-attribute-2&lt;/a&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;읽어보시고 궁금한 내용이나 수정해야하는 내용은&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;커뮤니티를 이용해 주시면 감사하겠습니다&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://discord.gg/CDtc5kWWA8&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://discord.gg/CDtc5kWWA8&lt;/a&gt;&lt;/p&gt;</description>
      <category>Forensic-CheatSheet</category>
      <author>vared</author>
      <guid isPermaLink="true">https://var3d.tistory.com/190</guid>
      <comments>https://var3d.tistory.com/entry/Upload-MFT-Attribute-2#entry190comment</comments>
      <pubDate>Wed, 31 May 2023 19:42:41 +0900</pubDate>
    </item>
    <item>
      <title>[Upload] Alternative Data Stream(ADS)</title>
      <link>https://var3d.tistory.com/entry/Upload-Alternative-Data-StreamADS</link>
      <description>&lt;p data-ke-size=&quot;size16&quot;&gt;artifacts 게시판에 Alternative Data Stream(ADS)에 대한 글이 업로드 되었습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;ADS는 MFT Entry 내의 속성 중 $DATA 속성이 여러개 있는 파일에 대한 내용입니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;데이터 은닉과 악성코드 삽입 등 여러 방면에서 사용될 수 있으며 특정 파일에 대해서는 파일의 유입 경로까지 파악할 수 있습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://www.forensic-cheatsheet.com/artifacts/ads&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.forensic-cheatsheet.com/artifacts/ads&lt;/a&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;읽어보시고 궁금한 내용이나 수정해야하는 내용은&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;커뮤니티를 이용해 주시면 감사하겠습니다&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://discord.gg/CDtc5kWWA8&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://discord.gg/CDtc5kWWA8&lt;/a&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;</description>
      <author>vared</author>
      <guid isPermaLink="true">https://var3d.tistory.com/189</guid>
      <comments>https://var3d.tistory.com/entry/Upload-Alternative-Data-StreamADS#entry189comment</comments>
      <pubDate>Tue, 9 May 2023 16:00:03 +0900</pubDate>
    </item>
    <item>
      <title>[Upload] MFT Attribute (1)</title>
      <link>https://var3d.tistory.com/entry/Upload-MFT-Attribute-1</link>
      <description>&lt;p data-ke-size=&quot;size16&quot;&gt;Filesystem 게시판의 MFT Attribute에 대한 글이 업로드 되었습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;NTFS 파일시스템에서 파일을 저장하는 방식을 이해하기 위해선 MFT의 Attribute에 대한 온전한 이해가 필요합니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;이번 게시글에서는 어떤 종류의 데이터가 저장되는지와 더불어 어떤 방식으로 시스템이 파일시스템의 공간을 활용하여 데이터를 저장하는지 알아보았습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://www.forensic-cheatsheet.com/filesystem/mft-attribute-1&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.forensic-cheatsheet.com/filesystem/mft-attribute-1&lt;/a&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;읽어보시고 궁금한 내용이나 수정해야하는 내용은&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;커뮤니티를 이용해 주시면 감사하겠습니다&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://discord.gg/CDtc5kWWA8&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://discord.gg/CDtc5kWWA8&lt;/a&gt;&lt;/p&gt;</description>
      <category>Forensic-CheatSheet</category>
      <author>vared</author>
      <guid isPermaLink="true">https://var3d.tistory.com/188</guid>
      <comments>https://var3d.tistory.com/entry/Upload-MFT-Attribute-1#entry188comment</comments>
      <pubDate>Tue, 2 May 2023 23:44:27 +0900</pubDate>
    </item>
    <item>
      <title>[Upload] iconcache/thumbcache 아티팩트</title>
      <link>https://var3d.tistory.com/entry/Upload-iconcachethumbcache-%EC%95%84%ED%8B%B0%ED%8C%A9%ED%8A%B8</link>
      <description>&lt;p data-ke-size=&quot;size16&quot;&gt;Artifacts&amp;nbsp;게시판의&amp;nbsp;iconcache/thumbcache가&amp;nbsp;업로드&amp;nbsp;되었습니다.&amp;nbsp;&lt;br /&gt;&lt;br /&gt;IconCache와&amp;nbsp;ThumbCache는&amp;nbsp;주로&amp;nbsp;파일&amp;nbsp;실행/&amp;nbsp;미디어&amp;nbsp;열람에&amp;nbsp;대한&amp;nbsp;흔적을&amp;nbsp;확인해볼&amp;nbsp;수&amp;nbsp;있는&amp;nbsp;아티팩트입니다.&lt;br /&gt;직접적으로&amp;nbsp;아티팩트&amp;nbsp;안에&amp;nbsp;실행된&amp;nbsp;흔적을&amp;nbsp;찾아보는것은&amp;nbsp;아니고,&amp;nbsp;실행에&amp;nbsp;따라&amp;nbsp;이미지가&amp;nbsp;캐시되는데&amp;nbsp;이를&amp;nbsp;간접적인&amp;nbsp;요소로&amp;nbsp;하여&amp;nbsp;사용하게&amp;nbsp;됩니다.&amp;nbsp;시스템에서&amp;nbsp;활용하는&amp;nbsp;영역이기때문에&amp;nbsp;삭제가&amp;nbsp;쉽지&amp;nbsp;않아&amp;nbsp;안티&amp;nbsp;포렌식이&amp;nbsp;적용된&amp;nbsp;분석&amp;nbsp;대상에&amp;nbsp;있어&amp;nbsp;요긴하게&amp;nbsp;활용될&amp;nbsp;수&amp;nbsp;있는&amp;nbsp;아티팩트입니다.&lt;br /&gt;&lt;br /&gt;이번&amp;nbsp;글에서는&amp;nbsp;언제&amp;nbsp;iconcache와&amp;nbsp;thumbcache의&amp;nbsp;차이점을&amp;nbsp;알아보며,&amp;nbsp;내부적으로는&amp;nbsp;어떤&amp;nbsp;데이터가&amp;nbsp;포함되어&amp;nbsp;있는지&amp;nbsp;알아보았습니다.&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://www.forensic-cheatsheet.com/artifacts/caches&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.forensic-cheatsheet.com/artifacts/caches&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;읽어보시고 궁금한 내용이나 수정해야하는 내용은&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;커뮤니티를 이용해 주시면 감사하겠습니다&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://discord.gg/CDtc5kWWA8&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://discord.gg/CDtc5kWWA8&lt;/a&gt;&lt;/p&gt;</description>
      <category>Forensic-CheatSheet</category>
      <category>Artifacts</category>
      <category>digital-forensics</category>
      <category>forensic-cheatsheet</category>
      <category>iconcahce</category>
      <category>Thumbcache</category>
      <author>vared</author>
      <guid isPermaLink="true">https://var3d.tistory.com/187</guid>
      <comments>https://var3d.tistory.com/entry/Upload-iconcachethumbcache-%EC%95%84%ED%8B%B0%ED%8C%A9%ED%8A%B8#entry187comment</comments>
      <pubDate>Thu, 6 Apr 2023 12:23:06 +0900</pubDate>
    </item>
    <item>
      <title>[Upload] Jumplist</title>
      <link>https://var3d.tistory.com/entry/Upload-Jumplist</link>
      <description>&lt;p data-ke-size=&quot;size16&quot;&gt;Jumplist 에 대한 글이 업로드 되었습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;Jumplist&amp;nbsp;역시&amp;nbsp;다른&amp;nbsp;아티팩트와&amp;nbsp;마찬가지로&amp;nbsp;사용자&amp;nbsp;행위와&amp;nbsp;파일&amp;nbsp;실행에&amp;nbsp;대한&amp;nbsp;흔적을&amp;nbsp;찾아볼&amp;nbsp;수&amp;nbsp;있는&amp;nbsp;아티팩트입니다.&amp;nbsp;관련하여&amp;nbsp;구조체가&amp;nbsp;아직&amp;nbsp;많이&amp;nbsp;분석되어&amp;nbsp;있지&amp;nbsp;않은&amp;nbsp;실정이지만,&amp;nbsp;특정&amp;nbsp;파일에&amp;nbsp;대한&amp;nbsp;실행&amp;nbsp;여부를&amp;nbsp;확인한&amp;nbsp;것만으로도&amp;nbsp;큰&amp;nbsp;의미를&amp;nbsp;가지는&amp;nbsp;아티팩트라고&amp;nbsp;생각됩니다.&amp;nbsp;이번&amp;nbsp;글에서는&amp;nbsp;언제&amp;nbsp;Jumplist&amp;nbsp;파일이&amp;nbsp;생성되며,&amp;nbsp;내부적으로는&amp;nbsp;어떤&amp;nbsp;데이터가&amp;nbsp;포함되어&amp;nbsp;있는지&amp;nbsp;알아보았습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://www.forensic-cheatsheet.com/artifacts/jumplist&quot;&gt;https://www.forensic-cheatsheet.com/artifacts/jumplist&lt;/a&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;읽어보시고 궁금한 내용이나 수정해야하는 내용은&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;커뮤니티를 통해 문의해 주시길 바랍니다 :)&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://discord.gg/CDtc5kWWA8&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://discord.gg/CDtc5kWWA8&lt;/a&gt;&lt;/p&gt;</description>
      <category>Forensic-CheatSheet</category>
      <author>vared</author>
      <guid isPermaLink="true">https://var3d.tistory.com/186</guid>
      <comments>https://var3d.tistory.com/entry/Upload-Jumplist#entry186comment</comments>
      <pubDate>Sat, 18 Mar 2023 01:36:21 +0900</pubDate>
    </item>
    <item>
      <title>[Upload] Shellbag 아티팩트</title>
      <link>https://var3d.tistory.com/entry/Upload-Shellbag-%EC%95%84%ED%8B%B0%ED%8C%A9%ED%8A%B8</link>
      <description>&lt;p data-ke-size=&quot;size16&quot;&gt;Shellbag 아티팩트에 대한 글이 업로드 되었습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;사용자가 특정 디렉토리에 접근한 흔적을 남기는 아티팩트로 주로 알려져 있으며 이외에도 다양한 정보를 담고 있습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;이번 글에서는 어떤 상황에서 Shellbag 아티팩트가 생성되는지와, 경로와 수정/생성일자와 같은 주요 데이터가 어떤 형태로 저장되는지를 주로 다루어 보았습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://www.forensic-cheatsheet.com/artifacts/shellbag&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.forensic-cheatsheet.com/artifacts/shellbag&lt;/a&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;읽어보시고 궁금한 내용이나 수정해야하는 내용은&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;본 게시글에&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;u&gt;&lt;b&gt;공개&lt;/b&gt;&lt;b&gt;댓글&lt;/b&gt;&lt;/u&gt;로 남겨주시면 감사하겠습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;</description>
      <category>Forensic-CheatSheet</category>
      <category>Digital Forensic</category>
      <category>forensic artifacts</category>
      <category>shellbag</category>
      <category>shellbag forensics</category>
      <author>vared</author>
      <guid isPermaLink="true">https://var3d.tistory.com/185</guid>
      <comments>https://var3d.tistory.com/entry/Upload-Shellbag-%EC%95%84%ED%8B%B0%ED%8C%A9%ED%8A%B8#entry185comment</comments>
      <pubDate>Wed, 1 Mar 2023 14:33:50 +0900</pubDate>
    </item>
    <item>
      <title>[Upload] Recycle Bin 아티팩트</title>
      <link>https://var3d.tistory.com/entry/Upload-Recycle-Bin-%EC%95%84%ED%8B%B0%ED%8C%A9%ED%8A%B8</link>
      <description>&lt;p data-ke-size=&quot;size16&quot;&gt;Recycle Bin 아티팩트에 대한 글이 업로드 되었습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;휴지통에 있는 파일들을 분석하는 방법에 대해 자세히 알아본 글입니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;휴지통에서 파일을 복구하는 데 도움이 될 것으로 예상됩니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://www.forensic-cheatsheet.com/artifacts/recyclebin&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.forensic-cheatsheet.com/artifacts/recyclebin&lt;/a&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;읽어보시고 궁금한 내용이나 수정해야하는 내용은&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;본 게시글에&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;u&gt;&lt;b&gt;공개&lt;/b&gt;&lt;b&gt;댓글&lt;/b&gt;&lt;/u&gt;로 남겨주시면 감사하겠습니다.&lt;/p&gt;</description>
      <category>Forensic-CheatSheet</category>
      <author>vared</author>
      <guid isPermaLink="true">https://var3d.tistory.com/184</guid>
      <comments>https://var3d.tistory.com/entry/Upload-Recycle-Bin-%EC%95%84%ED%8B%B0%ED%8C%A9%ED%8A%B8#entry184comment</comments>
      <pubDate>Thu, 26 Jan 2023 15:49:49 +0900</pubDate>
    </item>
    <item>
      <title>[Upload] SRUM 아티팩트</title>
      <link>https://var3d.tistory.com/entry/Upload-SRUM-%EC%95%84%ED%8B%B0%ED%8C%A9%ED%8A%B8</link>
      <description>&lt;p data-ke-size=&quot;size16&quot;&gt;SRUM 에 대한 글이 업로드 되었습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;시스템 자원 사용량을 다루는 아티팩트로 파일 실행 흔적을 찾는데 사용되는 아티팩트입니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;흔하게들 비휘발성 데이터라고 생각하고 있지만, 실제로 SRUM 데이터는 휘발성 데이터라는 점이 인상깊게 봐야할 포인트입니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://www.forensic-cheatsheet.com/artifacts/srum&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.forensic-cheatsheet.com/artifacts/srum&lt;/a&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;읽어보시고 궁금한 내용이나 수정해야하는 내용은&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;본 게시글에&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;u&gt;&lt;b&gt;공개&lt;/b&gt;&lt;b&gt;댓글&lt;/b&gt;&lt;/u&gt;로 남겨주시면 감사하겠습니다.&lt;/p&gt;</description>
      <category>Forensic-CheatSheet</category>
      <author>vared</author>
      <guid isPermaLink="true">https://var3d.tistory.com/183</guid>
      <comments>https://var3d.tistory.com/entry/Upload-SRUM-%EC%95%84%ED%8B%B0%ED%8C%A9%ED%8A%B8#entry183comment</comments>
      <pubDate>Tue, 17 Jan 2023 16:21:10 +0900</pubDate>
    </item>
    <item>
      <title>[Upload] LNK File 아티팩트</title>
      <link>https://var3d.tistory.com/entry/Upload-LNK-File-%EC%95%84%ED%8B%B0%ED%8C%A9%ED%8A%B8</link>
      <description>&lt;p data-ke-size=&quot;size16&quot;&gt;LNK 파일 아티팩트에 대한 글이 업로드 되었습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;LNK 파일은 윈도우 시스템에서 파일의 실행 정보를 파악할 수 있는 주요 아티팩트입니다. 주로 LNK 파일의 구조와 어떤 데이터가 들어있는지 알아보았습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;a href=&quot;https://www.forensic-cheatsheet.com/artifacts/lnkfile&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.forensic-cheatsheet.com/artifacts/lnkfile&lt;/a&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;읽어보시고 궁금한 내용이나 수정해야하는 내용은&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;본 게시글에&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;u&gt;&lt;b&gt;공개&lt;/b&gt;&lt;b&gt;댓글&lt;/b&gt;&lt;/u&gt;로 남겨주시면 감사하겠습니다.&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;</description>
      <category>Forensic-CheatSheet</category>
      <category>Digital-Forensic</category>
      <category>File Execution</category>
      <category>LNK FIile</category>
      <category>Windows Artifact</category>
      <author>vared</author>
      <guid isPermaLink="true">https://var3d.tistory.com/182</guid>
      <comments>https://var3d.tistory.com/entry/Upload-LNK-File-%EC%95%84%ED%8B%B0%ED%8C%A9%ED%8A%B8#entry182comment</comments>
      <pubDate>Mon, 26 Dec 2022 11:32:57 +0900</pubDate>
    </item>
  </channel>
</rss>