3 ms·
The more technical writeup [0] linked at the bottom of the article doesn't specifically mention it, but it sounds like they probably booted off the Live CD to g
by splonk 4y ago
The more technical writeup [0] linked at the bottom of the article doesn't specifically mention it, but it sounds like they probably booted off the Live CD to get access to the registry.
> You can’t analyze the registry live on a windows machine because it locks the NTUSER.dat files by the process id (PID) 104 known as Registry.exe. Any useful registry information will be found in that process, and we recommend getting a memory and VAD dump of the Registry.exe process as soon as possible. You can do this quite easily with the REKALL tool, which can perform live and dead memory analysis on Windows machines.
[0]: https://blog.unit221b.com/dont-read-this-blog/0xdead-zeppelin https://blog.unit221b.com/dont-read-this-blog/0xdead-zeppeli...
- Someone 4y agoReading between the lines, I get the impression the key is deleted from the registry, but not explicitly erased, allowing recovery if the disk space isn’t reused yet. “Since Zeppelin deletes the registry key store, we will have to extract unallocated cells from the registry to recover the Public Key section. […] We have had 100% success carving the public key from NTUser.dat for live Zeppelin samples in the field”