Skip to content

Add a Background Intelligent Transfer Service database parser #1475

@william-billaud

Description

@william-billaud

Background Intelligent Transfer Service store some information in qmgr.db database located in the sysvol/ProgramData/Microsoft/Network/Downloader/ folder. This database is in ESE format, but with only two table (Files and Job). These column contains a "blob" of data that must be parsed.
This can be used as an evidence of file upload/download and to investigate persistence.
Before windows 10, database has an another format (qmgr.dat)

References related to this artefact

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions