SRUM-DUMP Hands-on Labs¶
Choose the Interactive Lab to practise SRUM-DUMP and LibreOffice Calc without installation. Use the Full Lab to process an instructor-provided evidence set in an isolated Windows VM and preserve a reviewable case package.
Hands-on Windows resource usage forensics
Parse it. Focus it. Corroborate it.
Investigate an after-hours transfer lead, retain the parser context, examine network and application records, and state what the telemetry supports.
Interactive Lab¶
Full Lab¶
SRUM-DUMP Full Lab
Outcome-led, not screenshot-led
The lab uses checkpoints and expected evidence rather than requiring every interface to look identical. Record meaningful differences in tool, Windows, and LibreOffice versions.
Use isolated, authorised evidence
Use an instructor-provided synthetic set or evidence you are authorised to examine. Protect acquisition copies, analyse verified working copies, and keep parser and analyst output separate from the source.
Before you begin
You need an isolated Windows VM, SRUM-DUMP, LibreOffice Calc, a hashing utility,
case storage, and a matched SRUDB.dat and SOFTWARE training pair with known
expected records.
How to use this lab
Stop when a milestone is missing. Correct input identity, integrity, parser status, time context, or filter logic before drawing an investigative conclusion.
Recommended first
Beginner Core Lab¶
Parse one matched SRUM evidence pair, isolate an after-hours application cluster, correlate it across two workbook tables, and write a bounded finding.
Expected time: 70–110 minutes including setup.
Optional extension
Network corroboration¶
Compare the SRUM period with authorised firewall, proxy, DNS, or flow records and test whether independent telemetry supports a destination or transfer claim.
Expected time: 30–45 additional minutes.
- Session 1Prepare and parse
- Session 2Filter and correlate
- Session 3Report and review
Objective¶
You are supporting case SUSA-114. A monitoring alert indicates unusually high
outbound traffic from ENG-LT-07 between 2026-07-14 21:15 and 21:45 UTC.
The assigned user is CORP\mira. Determine whether SRUM contains application
resource records consistent with the alert, preserve the relevant rows, and
state what additional evidence is required before claiming data exfiltration.
The expected synthetic set contains normal background activity and a controlled
rclone.exe test pattern. This is a training lead, not a predetermined finding.
01
Activity 1: Establish the boundary¶
- Snapshot the isolated VM and create
E:\Cases\SUSA-114\{source,working,output,analysis,notes}. - Record authority, source host or image, acquisition method, original paths, acquisition time, host time zone, and examiner.
- Protect the source pair and create labelled working copies of
SRUDB.datandSOFTWARE. - Calculate SHA-256 for both source and working copies, then confirm each pair matches.
- Record the SRUM-DUMP and LibreOffice versions, sources, filenames, and hashes.
- Write the investigation question and the UTC alert window before opening the evidence.
Expected result Another analyst can identify the source, reproduce both working-copy hashes, and understand the exact question before parsing begins.
02
Activity 2: Parse and examine¶
- Start SRUM-DUMP with the verified working
SRUDB.dat, matchingSOFTWAREhive, and emptyoutputfolder. - Preserve the generated configuration before any optional edit. Record the parser engine, interface or command, options, start and finish times.
- On completion, retain the displayed total record count,
srum_dump.log, configuration, workbook or CSV outputs, warnings, errors, and SHA-256 values. - Create a labelled analysis copy of the workbook and open it in LibreOffice.
- Record all worksheet names and initial row counts. Locate the network usage table and preserve its exact displayed name.
- Filter the timestamp field to
2026-07-14 21:15through21:45 UTC, then filter application or process forrclone.exeand user forCORP\mira. - Record the criteria in order, remaining row count, displayed interfaces and profiles, and sent and received values with their units.
- Locate corresponding application timeline or resource usage records in the same bounded period. Preserve the exact table and fields used.
- Export the focused rows without replacing the complete parser workbook, then calculate their SHA-256.
Expected result Relevant rows remain linked to the database, workbook, worksheet, source field labels, UTC window, filter sequence, and hashes.
03
Activity 3: Corroborate and report¶
- Compare the bounded period with at least one independent endpoint source, such as Prefetch, Amcache, event logs, browser data, or file-system metadata.
- If authorised network telemetry is supplied, test the host, time, volume, application, and destination hypothesis against firewall, proxy, DNS, or flow records.
- Record negative and conflicting evidence. Do not convert missing telemetry into proof that an event did not occur.
- Write separate Observation, Interpretation, Confidence, Limitations, Alternative explanations, and Next step sections.
- Ask a peer to reconstruct the focused workbook view from the recorded filter log and compare the exported row hashes.
Answer these questions before completing the report:
- Which source database, hive, parser engine, workbook, and worksheet produced the relevant rows?
- What exact UTC field and filters defined the population?
- Which application, identity, interface, profile, and resource values were observed?
- Does independent evidence support execution, a destination, or file transfer?
- What remains unknown about person, intent, content, destination, and success?
Case: SUSA-114
Question and scope:
Source pair and SHA-256:
Tools, versions, engine, and settings:
Parser result and output SHA-256:
Worksheet and filter log:
Relevant rows and focused-export SHA-256:
Corroboration:
Observation:
Interpretation and confidence:
Limitations and alternative explanations:
Next step:
Expected result A peer can reproduce the workbook population and test each claim against the retained evidence package.
Extend the lab with a comparison engine
On a new verified working copy, process the same input with the alternate ESE engine. Preserve the second command, log, configuration, output, record count, and hashes. Compare only like tables and explain any row or value differences. Do not select a preferred result solely because it better supports the lead.
Full Lab evidence checklist¶
The checklist applies to the VM-based Full Lab. Interactive Lab learners can retain the downloadable simulation summary instead.
-
Core completion¶
Required for an attributable SRUM examination.
-
Good analyst practice¶
Records that strengthen reproducibility and review.
Troubleshooting¶
| Symptom | First check |
|---|---|
| Database will not parse | Verify the working-copy hash, input path, permissions, parser log, selected engine, and known issues. Preserve every failure. |
| Workbook has unresolved profiles | Confirm that the matching SOFTWARE hive was supplied and parsed; do not substitute another system's hive. |
| No rows remain after filtering | Clear filters, confirm the worksheet, initial population, exact UTC window, application spelling, and identity representation. |
| Byte totals differ from an alert | Confirm units, aggregation, filter boundaries, interfaces, parser engine, and whether the external alert measures the same traffic. |
| Application appears only in one table | Record the result. Different SRUM tables have different schemas, retention, and populations. |
| LibreOffice changed formatting or formulas | Return to the hashed parser workbook, create a fresh analysis copy, and record application version and import warnings. |
| Peer cannot reproduce the result | Compare workbook hash, worksheet, filter order, source fields, locale, time conversion, and focused-export rows. |
Clean up¶
Protect the evidence pair, parser log, configuration, complete workbook, focused exports, hashes, filter log, and report under lab policy. Remove disposable working copies only when authorised and revert the isolated VM snapshot.