Skip to content

Series

BAM/DAM in practice

3 posts in this series. Read them in order or jump to any one.

  1. How to Analyze BAM and DAM Registry Keys, Step by Step

    A practical workflow to parse BAM/DAM from a SYSTEM hive: collect, parse in the browser, scope by user and control set, triage flags, corroborate and export.

  2. BAM SID to Username: Attributing Execution to a User

    How BAM ties programs to accounts: reading the SID, resolving it via ProfileList, SAM or the domain, well-known SIDs like SYSTEM and DWM, and traps to avoid.

  3. BAM Evidence of Execution: A Lateral Movement Case

    A fictional investigation on FIN-WKS-07 read through BAM: phishing, a hijacked service account, scanning, PsExec, RDP and rclone — and what BAM could not show.

All posts in this series