National Institute of Standards and Technology (NIST) provides DFIR challenges to help people learn about various types of challenges and the techniques that can be used to solve them. This challenge provides the following scenario. This challenge requires we analyze a drive disk image made available to us, to "Find any hacking software, evidence of their use, and any data that might have been generated".
Artifact: Computer Name.
Artifact: Computer Name same above in Time Description table.
Artifact: Last Shutdown.
Artifact: Profile List.
Artifact: User Accounts.
Steps to Solve:
1. Go to file category.
2. Go to program file/Look@LAN folder.
3. Double click on irunin.ini file to see the content.
Artifact: Internet Explorer Main History.
Artifact: Internet Explorer Main History.
Answer: ShowLetter.
Artifact: Recycle Bin.