Skip to content

SRUM-DUMP Hands-on Labs

Choose the Interactive Lab to practise SRUM-DUMP and LibreOffice Calc without installation. Use the Full Lab to process an instructor-provided evidence set in an isolated Windows VM and preserve a reviewable case package.

Hands-on Windows resource usage forensics

Parse it. Focus it. Corroborate it.

Investigate an after-hours transfer lead, retain the parser context, examine network and application records, and state what the telemetry supports.

⏱ Setup: 20–30 min · Exercise: 50–80 min◆ Guided beginner✓ Evidence required

Interactive Lab

Full Lab

Isolated Windows VM · Setup: 20–30 min · Exercise: 50–80 min

SRUM-DUMP Full Lab

Authorised SRUM evidence set required

Outcome-led, not screenshot-led

The lab uses checkpoints and expected evidence rather than requiring every interface to look identical. Record meaningful differences in tool, Windows, and LibreOffice versions.

Use isolated, authorised evidence

Use an instructor-provided synthetic set or evidence you are authorised to examine. Protect acquisition copies, analyse verified working copies, and keep parser and analyst output separate from the source.

Before you begin

You need an isolated Windows VM, SRUM-DUMP, LibreOffice Calc, a hashing utility, case storage, and a matched SRUDB.dat and SOFTWARE training pair with known expected records.

How to use this lab

Stop when a milestone is missing. Correct input identity, integrity, parser status, time context, or filter logic before drawing an investigative conclusion.

Optional extension

Network corroboration

Compare the SRUM period with authorised firewall, proxy, DNS, or flow records and test whether independent telemetry supports a destination or transfer claim.

Expected time: 30–45 additional minutes.

  1. Session 1Prepare and parse
  2. Session 2Filter and correlate
  3. Session 3Report and review

Objective

You are supporting case SUSA-114. A monitoring alert indicates unusually high outbound traffic from ENG-LT-07 between 2026-07-14 21:15 and 21:45 UTC. The assigned user is CORP\mira. Determine whether SRUM contains application resource records consistent with the alert, preserve the relevant rows, and state what additional evidence is required before claiming data exfiltration.

The expected synthetic set contains normal background activity and a controlled rclone.exe test pattern. This is a training lead, not a predetermined finding.

01

Activity 1: Establish the boundary

  1. Snapshot the isolated VM and create E:\Cases\SUSA-114\{source,working,output,analysis,notes}.
  2. Record authority, source host or image, acquisition method, original paths, acquisition time, host time zone, and examiner.
  3. Protect the source pair and create labelled working copies of SRUDB.dat and SOFTWARE.
  4. Calculate SHA-256 for both source and working copies, then confirm each pair matches.
  5. Record the SRUM-DUMP and LibreOffice versions, sources, filenames, and hashes.
  6. Write the investigation question and the UTC alert window before opening the evidence.
Milestone 1Inputs attributableThe matched evidence pair and tools are verified, the alert window is fixed, and output locations are separate.

Expected result Another analyst can identify the source, reproduce both working-copy hashes, and understand the exact question before parsing begins.

02

Activity 2: Parse and examine

  1. Start SRUM-DUMP with the verified working SRUDB.dat, matching SOFTWARE hive, and empty output folder.
  2. Preserve the generated configuration before any optional edit. Record the parser engine, interface or command, options, start and finish times.
  3. On completion, retain the displayed total record count, srum_dump.log, configuration, workbook or CSV outputs, warnings, errors, and SHA-256 values.
  4. Create a labelled analysis copy of the workbook and open it in LibreOffice.
  5. Record all worksheet names and initial row counts. Locate the network usage table and preserve its exact displayed name.
  6. Filter the timestamp field to 2026-07-14 21:15 through 21:45 UTC, then filter application or process for rclone.exe and user for CORP\mira.
  7. Record the criteria in order, remaining row count, displayed interfaces and profiles, and sent and received values with their units.
  8. Locate corresponding application timeline or resource usage records in the same bounded period. Preserve the exact table and fields used.
  9. Export the focused rows without replacing the complete parser workbook, then calculate their SHA-256.
Milestone 2Observation reproducibleThe parser run is documented and a second analyst can rebuild the same SRUM filter and focused export.

Expected result Relevant rows remain linked to the database, workbook, worksheet, source field labels, UTC window, filter sequence, and hashes.

03

Activity 3: Corroborate and report

  1. Compare the bounded period with at least one independent endpoint source, such as Prefetch, Amcache, event logs, browser data, or file-system metadata.
  2. If authorised network telemetry is supplied, test the host, time, volume, application, and destination hypothesis against firewall, proxy, DNS, or flow records.
  3. Record negative and conflicting evidence. Do not convert missing telemetry into proof that an event did not occur.
  4. Write separate Observation, Interpretation, Confidence, Limitations, Alternative explanations, and Next step sections.
  5. Ask a peer to reconstruct the focused workbook view from the recorded filter log and compare the exported row hashes.

Answer these questions before completing the report:

  • Which source database, hive, parser engine, workbook, and worksheet produced the relevant rows?
  • What exact UTC field and filters defined the population?
  • Which application, identity, interface, profile, and resource values were observed?
  • Does independent evidence support execution, a destination, or file transfer?
  • What remains unknown about person, intent, content, destination, and success?
Case: SUSA-114
Question and scope:
Source pair and SHA-256:
Tools, versions, engine, and settings:
Parser result and output SHA-256:
Worksheet and filter log:
Relevant rows and focused-export SHA-256:
Corroboration:
Observation:
Interpretation and confidence:
Limitations and alternative explanations:
Next step:
Milestone 3Finding reviewableThe report describes recorded resource usage without claiming a destination, transfer success, intent, or exact execution event unless independent evidence supports it.

Expected result A peer can reproduce the workbook population and test each claim against the retained evidence package.

Extend the lab with a comparison engine

On a new verified working copy, process the same input with the alternate ESE engine. Preserve the second command, log, configuration, output, record count, and hashes. Compare only like tables and explain any row or value differences. Do not select a preferred result solely because it better supports the lead.

Full Lab evidence checklist

The checklist applies to the VM-based Full Lab. Interactive Lab learners can retain the downloadable simulation summary instead.

  • Core completion

    Required for an attributable SRUM examination.

  • Good analyst practice

    Records that strengthen reproducibility and review.

0 of 9 recorded Mark each item when you have saved the evidence.

Troubleshooting

Symptom First check
Database will not parse Verify the working-copy hash, input path, permissions, parser log, selected engine, and known issues. Preserve every failure.
Workbook has unresolved profiles Confirm that the matching SOFTWARE hive was supplied and parsed; do not substitute another system's hive.
No rows remain after filtering Clear filters, confirm the worksheet, initial population, exact UTC window, application spelling, and identity representation.
Byte totals differ from an alert Confirm units, aggregation, filter boundaries, interfaces, parser engine, and whether the external alert measures the same traffic.
Application appears only in one table Record the result. Different SRUM tables have different schemas, retention, and populations.
LibreOffice changed formatting or formulas Return to the hashed parser workbook, create a fresh analysis copy, and record application version and import warnings.
Peer cannot reproduce the result Compare workbook hash, worksheet, filter order, source fields, locale, time conversion, and focused-export rows.

Clean up

Protect the evidence pair, parser log, configuration, complete workbook, focused exports, hashes, filter log, and report under lab policy. Remove disposable working copies only when authorised and revert the isolated VM snapshot.