Source: Stories by Nasreddine Bencherchali on Medium
Author: Nasreddine Bencherchali
URL: https://nasbench.medium.com/the-ghost-in-the-logs-dfir-through-a-palimpsest-lens-b592ef733f4f
ONE SENTENCE SUMMARY:
Palimpsests in history and DFIR reveal how overwritten traces can be uncovered, aiding digital forensic investigations despite attack obfuscation.
MAIN POINTS:
- A palimpsest is a manuscript with overwritten traces beneath new text.
- The Archimedes Palimpsest was uncovered using advanced imaging techniques.
- Attackers hide traces by deleting logs and overwriting files in DFIR.
- Deleted or cleared logs and files still leave artifacts in systems.
- Tampering with tools and services can still be detected by anomalies.
- Absence of evidence often indicates a disruption or manipulation.
- Sophisticated attackers avoid common telemetry triggers.
- Investigators often face challenges due to lack of traditional logs.
- A “palimpsestic” mindset helps reveal hidden forensic evidence.
- Registry, $MFT, and other system artifacts hold valuable investigative data.
TAKEAWAYS:
- Palimpsests illustrate how overwritten information can be revealed.
- Forensic echoes linger despite attackers’ deletion efforts.
- A “palimpsestic” perspective aids detection of subtle traces.
- Advanced imaging uncovers hidden historical texts.
- Investigative success often depends on understanding system artifact persistence.