Recipe Difficulty: Hard
Python Version: 2.7
Operating System: Linux
With the major release of popular operating systems, everyone in the cyber community gets excited (or worried) about the potential new artifacts and changes to existing artifacts. With the advent of Windows 10, we saw a few changes (such as the MAM compression of prefetch files) and new artifacts as well. One of these artifacts is the System Resource Usage Monitor (SRUM), which can retain execution and network activity for applications. This includes information such as when a connection was established by a given application and how many bytes were sent and received by this application. Obviously, this can be very useful in a number of different scenarios. Imagine having this information on hand with a disgruntled employee who uploads many gigabytes of data on their last day using...