log2timeline / plaso

Super timeline all the things
https://plaso.readthedocs.io
Apache License 2.0
1.73k stars 351 forks source link

Addtional Parser request for Microsoft BIT jobs #2404

Open 82d28a opened 5 years ago

82d28a commented 5 years ago

Background Intelligent Transfer Service (BITS) is used for persistence.

Two sources: Microsoft-Windows-Bits-Client/(Microsoft-Windows-Bits-Client/Operational.evtx AND qmgr[??].dat

REF: https://www.secureworks.com/blog/malware-lingers-with-bits

joachimmetz commented 5 years ago

if the evtx is regular Windows XML event log file it should be parsed any context on qmgr[??].dat ?

82d28a commented 5 years ago

https://mgreen27.github.io/posts/2018/02/18/Sharing_my_BITS.html

https://github.com/ANSSI-FR/bits_parser

Based on this it looks like ESE for Win 10