SRUM db network usage
文章描述了一起涉嫌数据外泄的内部调查案件,涉及文件删除、关键文件下载及上传至OneDrive/SharePoint的情况。通过srubdb发现大量数据上传行为,但OneDriveExplorer显示空数据库。询问如何查找OneDrive删除的相关证据。 2025-9-11 03:56:28 Author: www.reddit.com(查看原文) 阅读量:3 收藏

Working internally on an alleged exfiltration case. Obvious deletions of files and file view history are noted, two key files were downloaded and the concern is upload. A decent amount of data was uploaded to OneDrive/sharepoint as seen in srubdb. OneDriveExplorer found empty dbs, how do I find artifacts of OneDrive deletion?


文章来源: https://www.reddit.com/r/computerforensics/comments/1ndyys6/srum_db_network_usage/
如有侵权请联系:admin#unsafe.sh