How to Analyze BAM and DAM Registry Keys, Step by Step
A practical workflow to parse BAM/DAM from a SYSTEM hive: collect, parse in the browser, scope by user and control set, triage flags, corroborate and export.
Series
3 posts in this series. Read them in order or jump to any one.
A practical workflow to parse BAM/DAM from a SYSTEM hive: collect, parse in the browser, scope by user and control set, triage flags, corroborate and export.
How BAM ties programs to accounts: reading the SID, resolving it via ProfileList, SAM or the domain, well-known SIDs like SYSTEM and DWM, and traps to avoid.
A fictional investigation on FIN-WKS-07 read through BAM: phishing, a hijacked service account, scanning, PsExec, RDP and rclone — and what BAM could not show.
A practical workflow to parse BAM/DAM from a SYSTEM hive: collect, parse in the browser, scope by user and control set, triage flags, corroborate and export.
How BAM ties programs to accounts: reading the SID, resolving it via ProfileList, SAM or the domain, well-known SIDs like SYSTEM and DWM, and traps to avoid.
A fictional investigation on FIN-WKS-07 read through BAM: phishing, a hijacked service account, scanning, PsExec, RDP and rclone — and what BAM could not show.