data:image/s3,"s3://crabby-images/cfbd2/cfbd2b4ec70817a9993cb32c3b6acc10ba352f0d" alt="Osforensics mac"
data:image/s3,"s3://crabby-images/d8e69/d8e694a8cc9cad74f46a7b04149ec167031a715a" alt="osforensics mac osforensics mac"
Windows stores the MAC address in binary format, and in the version of RECmd that I was using Eric had programmed the tool to output the phrase “(Binary Data)” instead of the actual hex. I wrote out my little batch file that pulls out this value, and tested it out but alas it was not to be so.
data:image/s3,"s3://crabby-images/927f2/927f2e4eaed3c9c7f8a015c60c1de5d502eb1579" alt="osforensics mac osforensics mac"
They really allow you to process registry data at scale very quickly. For this, we need to use a batch file! If you haven’t looked at RECmd batch files I’d highly recommend it. Which led me to the following key/value in the SYSTEM hive : SYSTEM\ControlSet001\Control\NetworkSetup2\Interfaces\ with a wildcard and this isn’t supported in the –kn option. Searching for a known value is a good way for finding this kind of info, so using RECmd I searched my live registry for the MAC of my host. Also side note, you should support Eric’s tool-making.Įric was even kind enough to recently add an –sa option so that you can search across keys values data and slack in one query Who doesn’t love a bit of registry analysis, and of course Eric’s tools come to the rescue yet again for this kind of hunting.
data:image/s3,"s3://crabby-images/df3b8/df3b8867e112f93565c30b1cd9623bf6a63448d7" alt="osforensics mac osforensics mac"
I had a need to identify the MAC address of a computer from an image (actually a whole bunch of images) recently and went looking through the registry to try solve my problem.
data:image/s3,"s3://crabby-images/cfbd2/cfbd2b4ec70817a9993cb32c3b6acc10ba352f0d" alt="Osforensics mac"