AXREL: Automated Extracting Registry and Event Logs for Windows Forensics

dc.contributor.authorVisoottiviseth V.
dc.contributor.authorNoonkhan A.
dc.contributor.authorPhonpanit R.
dc.contributor.authorWanichayagosol P.
dc.contributor.authorJitpukdebodin S.
dc.contributor.correspondenceVisoottiviseth V.
dc.contributor.otherMahidol University
dc.date.accessioned2024-02-09T18:17:54Z
dc.date.available2024-02-09T18:17:54Z
dc.date.issued2023-01-01
dc.description.abstractWhen a cyber incident occurs, digital forensic is then essential for investigating how hackers compromised the system or how malware functioned. In this paper, we focus on Windows forensics which is one important branch of digital forensics. Windows forensics can be performed using some existing investigation tools that are expensive and require training before using them, while the current number of well-trained staffs in the cybersecurity field is limited. Moreover, in the step of evidence analysis, Windows forensic investigators need to manually extract certain files such as Windows registry and Windows event logs, which is a repetitive and time-consuming task. Therefore, we propose AXREL as an automated Windows evidence extracting application to facilitate new Windows forensic investigators by providing a user-friendly GUI. Our application is developed by Python 3 on the Windows platform. It can automatically extract Windows registry and event logs, which are the primary sources of evidence for Windows forensics.
dc.identifier.citation27th International Computer Science and Engineering Conference 2023, ICSEC 2023 (2023) , 74-78
dc.identifier.doi10.1109/ICSEC59635.2023.10329743
dc.identifier.scopus2-s2.0-85180152126
dc.identifier.urihttps://repository.li.mahidol.ac.th/handle/20.500.14594/96340
dc.rights.holderSCOPUS
dc.subjectMathematics
dc.subjectEnergy
dc.subjectComputer Science
dc.subjectDecision Sciences
dc.titleAXREL: Automated Extracting Registry and Event Logs for Windows Forensics
dc.typeConference Paper
mu.datasource.scopushttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85180152126&origin=inward
oaire.citation.endPage78
oaire.citation.startPage74
oaire.citation.title27th International Computer Science and Engineering Conference 2023, ICSEC 2023
oairecerif.author.affiliationMahidol University
oairecerif.author.affiliationLtd

Files

Collections