<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SRUM Parser — Blog</title>
    <link>https://www.srumparser.com/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Tue, 26 May 2026 18:41:41 GMT</lastBuildDate>
    <atom:link href="https://www.srumparser.com/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Detecting data exfiltration with SRUM network usage</title>
      <link>https://www.srumparser.com/en/blog/detect-data-exfiltration-srum</link>
      <guid isPermaLink="true">https://www.srumparser.com/en/blog/detect-data-exfiltration-srum</guid>
      <description>A focused method for spotting outbound data theft using SRUM&apos;s Network Data Usage table — per-process bytes, user attribution, and network profile.</description>
      <author>SRUM Parser</author>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to fix a dirty SRUDB.dat (ESE database recovery)</title>
      <link>https://www.srumparser.com/en/blog/recover-dirty-srudb-dat</link>
      <guid isPermaLink="true">https://www.srumparser.com/en/blog/recover-dirty-srudb-dat</guid>
      <description>Why a copied SRUDB.dat is often in a dirty state, and how to replay the transaction logs with esentutl so a parser can read every row.</description>
      <author>SRUM Parser</author>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How long does SRUM keep data? Retention and registry settings</title>
      <link>https://www.srumparser.com/en/blog/srum-data-retention</link>
      <guid isPermaLink="true">https://www.srumparser.com/en/blog/srum-data-retention</guid>
      <description>How far back SRUM history goes, what controls retention, and the registry keys that govern the short-term and long-term tables.</description>
      <author>SRUM Parser</author>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SRUM vs Prefetch vs Amcache: which execution artifact to use</title>
      <link>https://www.srumparser.com/en/blog/srum-vs-prefetch-amcache</link>
      <guid isPermaLink="true">https://www.srumparser.com/en/blog/srum-vs-prefetch-amcache</guid>
      <description>A practical comparison of the three main Windows program-execution artifacts — what each proves, their time resolution, and when SRUM wins.</description>
      <author>SRUM Parser</author>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The ESE database format that powers SRUDB.dat</title>
      <link>https://www.srumparser.com/en/blog/ese-database-format</link>
      <guid isPermaLink="true">https://www.srumparser.com/en/blog/ese-database-format</guid>
      <description>Understanding the Extensible Storage Engine — Windows&apos; embedded database used by SRUM, Active Directory, Exchange, the Edge browser cache, and more.</description>
      <author>SRUM Parser</author>
      <pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to parse SRUDB.dat without installing anything</title>
      <link>https://www.srumparser.com/en/blog/how-to-parse-srudb-dat</link>
      <guid isPermaLink="true">https://www.srumparser.com/en/blog/how-to-parse-srudb-dat</guid>
      <description>Three ways to extract data from a Windows SRUM database — pick the one that fits your time, environment, and skill level.</description>
      <author>SRUM Parser</author>
      <pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Using SRUM in a forensic investigation</title>
      <link>https://www.srumparser.com/en/blog/srum-forensics-investigation</link>
      <guid isPermaLink="true">https://www.srumparser.com/en/blog/srum-forensics-investigation</guid>
      <description>Real-world investigative questions that the SRUM database can answer — data exfiltration, malware activity, suspect timelines, insider threat.</description>
      <author>SRUM Parser</author>
      <pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SRUM tables explained: AppResource, Network, Energy, Push</title>
      <link>https://www.srumparser.com/en/blog/srum-tables-explained</link>
      <guid isPermaLink="true">https://www.srumparser.com/en/blog/srum-tables-explained</guid>
      <description>A reference guide to the well-known tables inside SRUDB.dat — their GUID names, columns, and what each one tells a forensic analyst.</description>
      <author>SRUM Parser</author>
      <pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Where is SRUDB.dat located on Windows?</title>
      <link>https://www.srumparser.com/en/blog/where-is-srudb-dat</link>
      <guid isPermaLink="true">https://www.srumparser.com/en/blog/where-is-srudb-dat</guid>
      <description>The exact filesystem path of the SRUM database on every supported Windows version, plus how to extract it safely from a live machine or forensic image.</description>
      <author>SRUM Parser</author>
      <pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is SRUM and why forensic analysts care</title>
      <link>https://www.srumparser.com/en/blog/what-is-srum</link>
      <guid isPermaLink="true">https://www.srumparser.com/en/blog/what-is-srum</guid>
      <description>Pillar guide to the Windows System Resource Usage Monitor: what it records, where to find it, and what investigators get from it.</description>
      <author>SRUM Parser</author>
      <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>