Forensic Artifacts — Symantec EDR “localdatastore” Folder

Quick Overview

\ProgramData\Symantec\Symantec Endpoint Protection\[Version]\Data\EDR\localdatastore

Local Data Store

“.log” File

Example of SEDR Log
$fileSysWatcher = New-Object System.IO.FileSystemWatcher$fileSysWatcher.IncludeSubdirectories = $true$fileSysWatcher.Path = [Path to the localdatastore folder]$fileSysWatcher.EnableRaisingEvents = $true$action ={$path = $event.SourceEventArgs.FullPath$changetype = $event.SourceEventArgs.ChangeType$ext = [IO.Path]::GetExtension($path)if ($ext -eq ".log"){Copy-Item -Path $path -Destination [Path to new location]}}Register-ObjectEvent $fileSysWatcher 'Created' -Action $action

Conclusion

--

--

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store