[{"id":92,"title":"Her SOC Analistinin Bilmesi Gereken Windows Dizinleri","content":"Bir SOC (G\u00fcvenlik Operasyon Merkezi) analisti olarak, Windows'un kritik g\u00fcvenlik bilgilerini nerede depolad\u0131\u011f\u0131n\u0131 anlamak, bir s\u0131zma giri\u015fimini erken tespit etmek veya tamamen ka\u00e7\u0131rmak aras\u0131ndaki fark\u0131 yaratabilir. Her g\u00fcvenlik profesyonelinin radar\u0131nda olmas\u0131 gereken temel Windows dizinlerini inceleyelim. <h2>Kimlik Bilgileri ve Eri\u015fim Kay\u0131tlar\u0131<\/h2> Kullan\u0131c\u0131 kimlik bilgilerinin g\u00fcvenli\u011fi, her g\u00fcvenlik duru\u015funun temelini olu\u015fturur. Bu konumlar hassas kimlik do\u011frulama verilerini depolar: <ul> <li><strong>C:\\Windows\\System32\\config\\SAM<\/strong>: Windows'un yerel parola hash'lerini depolad\u0131\u011f\u0131 yerdir ve bu da onu kimlik bilgisi toplama sald\u0131r\u0131lar\u0131 i\u00e7in \u00f6ncelikli bir hedef haline getirir. Bu dosyaya eri\u015fen sald\u0131rganlar, \u00e7evrimd\u0131\u015f\u0131 k\u0131rma i\u015flemleri i\u00e7in parola hash'lerini \u00e7\u0131karabilir.<\/li> <li><strong>C:\\Windows\\repair\\SAM<\/strong>: Kullan\u0131c\u0131 kimlik bilgilerinin bir yede\u011fini i\u00e7erir ve sald\u0131rganlar kimlik bilgisi h\u0131rs\u0131zl\u0131\u011f\u0131 i\u00e7in alternatif bir yol olarak hedefleyebilir.<\/li> <li><strong>C:\\Windows\\System32\\config\\SECURITY<\/strong>: Sisteminizin g\u00fcvenlik s\u0131n\u0131rlar\u0131n\u0131 tan\u0131mlayan g\u00fcvenlik politikalar\u0131n\u0131 ve eri\u015fim kontrol\u00fc ayarlar\u0131n\u0131 bar\u0131nd\u0131r\u0131r.<\/li> <\/ul> <h2>Sistem ve Olay Kay\u0131tlar\u0131<\/h2> Etkili g\u00fcvenlik izleme, kapsaml\u0131 g\u00fcnl\u00fck tutmaya ba\u011fl\u0131d\u0131r. Bu dizinler kritik g\u00fcnl\u00fck verilerini i\u00e7erir: <ul> <li><strong>C:\\Windows\\System32\\winevt<\/strong>: Windows Olay G\u00fcnl\u00fcklerini depolar, bu da SIEM korelasyonu ve g\u00fcvenlik izleme i\u00e7in \u00e7ok \u00f6nemlidir. Bu, potansiyel g\u00fcvenlik olaylar\u0131n\u0131 ara\u015ft\u0131r\u0131rken genellikle ilk dura\u011f\u0131n\u0131zd\u0131r.<\/li> <li><strong>C:\\Windows\\System32\\config\\SYSTEM<\/strong>: Yetkisiz de\u011fi\u015fiklikleri g\u00f6sterebilecek sistem genelindeki de\u011fi\u015fiklikleri ve yap\u0131land\u0131rmalar\u0131 izler.<\/li> <li><strong>C:\\Windows\\System32\\config\\SOFTWARE<\/strong>: Y\u00fckl\u00fc yaz\u0131l\u0131mlar ve de\u011fi\u015fiklikler hakk\u0131nda ayr\u0131nt\u0131lar i\u00e7eren kay\u0131t defteri bilgilerini i\u00e7erir, yetkisiz yaz\u0131l\u0131m kurulumlar\u0131n\u0131 belirlemenize yard\u0131mc\u0131 olur.<\/li> <\/ul> <h2>K\u00f6t\u00fc Ama\u00e7l\u0131 Yaz\u0131l\u0131m ve Tehdit Avlama G\u00f6stergeleri<\/h2> Tehditleri ararken, bu konumlar genellikle de\u011ferli adli kan\u0131tlar sa\u011flar: <ul> <li><strong>C:\\Windows\\Prefetch<\/strong>: Son zamanlarda \u00e7al\u0131\u015ft\u0131r\u0131lan programlar\u0131 izler, bu da bir soru\u015fturma s\u0131ras\u0131nda adli zaman \u00e7izelgeleri olu\u015fturmak i\u00e7in paha bi\u00e7ilmezdir.<\/li> <li><strong>C:\\Windows\\AppCompat\\Programs\\Amcache.hve<\/strong>: \u00c7al\u0131\u015ft\u0131r\u0131lan uygulamalar\u0131n ayr\u0131nt\u0131lar\u0131n\u0131 kaydeder, sald\u0131rganlar a\u011f\u0131n\u0131zda gezinirken yanal hareketi tespit etmek i\u00e7in m\u00fckemmeldir.<\/li> <li><strong>C:\\Users*\\NTUSER.dat<\/strong>: K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131n kal\u0131c\u0131l\u0131k i\u00e7in s\u0131kl\u0131kla istismar etti\u011fi kullan\u0131c\u0131ya \u00f6zg\u00fc kay\u0131t defteri ayarlar\u0131n\u0131 i\u00e7erir.<\/li> <\/ul> <h2>Kal\u0131c\u0131l\u0131k ve Ba\u015flang\u0131\u00e7 Ara\u015ft\u0131rmalar\u0131<\/h2> K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar genellikle sistem yeniden ba\u015flatmalar\u0131ndan sonra hayatta kalmak i\u00e7in kal\u0131c\u0131l\u0131k sa\u011flar. Bu konumlar s\u0131kl\u0131kla hedef al\u0131n\u0131r: <ul> <li><strong>C:\\Users*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup<\/strong>: Belirli bir kullan\u0131c\u0131 oturum a\u00e7t\u0131\u011f\u0131nda programlar\u0131 ba\u015flatan kullan\u0131c\u0131ya \u00f6zg\u00fc kal\u0131c\u0131l\u0131k mekanizmalar\u0131.<\/li> <li><strong>C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup<\/strong>: T\u00fcm kullan\u0131c\u0131lar\u0131 etkileyen k\u00fcresel ba\u015flang\u0131\u00e7 klas\u00f6r\u00fc, k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar taraf\u0131ndan yayg\u0131n olarak k\u00f6t\u00fcye kullan\u0131l\u0131r.<\/li> <\/ul> Bu kritik dizinleri d\u00fczenli olarak izleyerek, SOC analistleri yetkisiz eri\u015fimi, k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m kurulumunu ve kal\u0131c\u0131 tehditleri daha etkili bir \u015fekilde tespit edebilir. \u0130zleme stratejinize bu konumlar\u0131 dahil etmek, g\u00fcvenlik duru\u015funuzu ve olay m\u00fcdahale yeteneklerinizi \u00f6nemli \u00f6l\u00e7\u00fcde geli\u015ftirecektir. Sald\u0131rganlar\u0131n da bu konumlar\u0131n fark\u0131nda oldu\u011funu unutmay\u0131n, bu nedenle bu dizinler i\u00e7in uygun eri\u015fim kontrollerini ve izleme \u00e7\u00f6z\u00fcmlerini uygulamak, her g\u00fcvenlik ekibi i\u00e7in bir \u00f6ncelik olmal\u0131d\u0131r. EN: <h2>Key Windows Directories Every SOC Analyst Should Monitor<\/h2> As a SOC (Security Operations Center) analyst, understanding where Windows stores critical security information can make the difference between detecting an intrusion early or missing it completely. Let's explore the essential Windows directories that should be on every security professional's radar. <h2>Credential &amp; Access Logs<\/h2> The security of user credentials forms the foundation of any security posture. These locations store sensitive authentication data: <ul> <li><strong>C:\\Windows\\System32\\config\\SAM<\/strong>: This is where Windows stores local password hashes, making it a prime target for credential dumping attacks. Attackers who gain access to this file can potentially extract password hashes for offline cracking.<\/li> <li><strong>C:\\Windows\\repair\\SAM<\/strong>: Contains a backup of user credentials that attackers may target as an alternative path to credential theft.<\/li> <li><strong>C:\\Windows\\System32\\config\\SECURITY<\/strong>: Houses security policies and access control settings that define your system's security boundaries.<\/li> <\/ul> <h2>System &amp; Event Logs<\/h2> Effective security monitoring depends on comprehensive logging. These directories contain critical log data: <ul> <li><strong>C:\\Windows\\System32\\winevt<\/strong>: Stores Windows Event Logs, which are crucial for SIEM correlation and security monitoring. This is often your first stop when investigating potential security incidents.<\/li> <li><strong>C:\\Windows\\System32\\config\\SYSTEM<\/strong>: Tracks system-wide changes and configurations that may indicate unauthorized modifications.<\/li> <li><strong>C:\\Windows\\System32\\config\\SOFTWARE<\/strong>: Contains the registry hive with details on installed software and changes, helping you identify unauthorized software installations.<\/li> <\/ul> <h2>Malware &amp; Threat Hunting Indicators<\/h2> When hunting for threats, these locations often provide valuable forensic evidence: <ul> <li><strong>C:\\Windows\\Prefetch<\/strong>: Tracks recently executed programs, which is invaluable for building forensic timelines during an investigation.<\/li> <li><strong>C:\\Windows\\AppCompat\\Programs\\Amcache.hve<\/strong>: Logs details of executed applications, making it excellent for detecting lateral movement as attackers navigate through your network.<\/li> <li><strong>C:\\Users*\\NTUSER.dat<\/strong>: Contains user-specific registry settings that malware often abuses for persistence.<\/li> <\/ul> <h2>Persistence &amp; Startup Investigations<\/h2> Malware often establishes persistence to survive system reboots. These locations are frequently targeted: <ul> <li><strong>C:\\Users*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup<\/strong>: User-specific persistence mechanisms that launch programs when a specific user logs in.<\/li> <li><strong>C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup<\/strong>: Global startup folder affecting all users, commonly misused by malware.<\/li> <\/ul> By regularly monitoring these critical directories, SOC analysts can more effectively detect unauthorized access, malware installation, and persistent threats. Including these locations in your monitoring strategy will significantly enhance your security posture and incident response capabilities. Remember that attackers are well aware of these locations too, so implementing proper access controls and monitoring solutions for these directories should be a priority for any security team.","excerpt":"Bir SOC (G\u00fcvenlik Operasyon Merkezi) analisti olarak, Windows'un kritik g\u00fcvenlik bilgilerini nerede depolad\u0131\u011f\u0131n\u0131 anlamak, bir s\u0131zma...","created_at":"2025-04-21 11:06:28","updated_at":"2026-09-07 12:42:20","category_id":7,"view_count":684,"reading_time":6,"status":"published","editor_choice":0,"is_editor_choice":0,"published_at":"2025-04-21 11:06:28","featured_image":"resimyok.jpg","slug":"soc-analistinin-bilmesi-gereken-windows-dizinleri","category_name":"Cyber Security","category_slug":"cyber-security","category_color":"#10b981"}]