Scollr summary
What this paper is about
This paper investigates which forensically relevant information remains extractable from encrypted SMB traffic, and introduces operation signatures, rule-based descriptions of expected packet sequences defined over payload sizes and communication directions, that reconstruct file operations without decryption.
Full abstract
Read the full abstract
The Server Message Block (SMB) protocol is the foundation for file sharing in Windows environments. Captured SMB traffic enables the reconstruction of transferred files and file operations, providing valuable forensic evidence. With SMB version 3, optional protocol-level encryption renders existing plaintext-dependent analysis methods inapplicable. This paper investigates which forensically relevant information remains extractable from encrypted SMB traffic. We first examine the prerequisites for decryption and contribute Volatility 3 plugins that automate the recovery of session keys from memory images. When decryption is not feasible, three sources remain. First, the unencrypted session establishment reveals the authenticated user, the target server, the session timeframe, and connection parameters. Second, we extend an existing approach for fingerprinting SMB clients from two to seven features, enabling reliable identification of client implementations and finer version differentiation. Third, we introduce operation signatures, rule-based descriptions of expected packet sequences defined over payload sizes and communication directions, that reconstruct file operations without decryption. We develop an automated framework that generates datasets with reliable ground truth for evaluation. On over 18,000 operations, the signatures reconstruct 99.62 % of operations for smbclient and 96.11 % for PowerShell, including parameters such as file name lengths and transferred data volumes.
Direct answer
What can I do from this paper page?
Use this page to scan "Forensic Analysis of Encrypted SMB Traffic: Decryption, Client Identification and Event Reconstruction" quickly: start with the summary and abstract, then check the authors, source, topics, and related papers. From here, open Scollr to follow Digital and Cyber Forensics research, save the paper, or map adjacent work.
Research areas
Follow related topics
Citation
BibTeX
@article{Gadde2026Forensic,
title = {Forensic Analysis of Encrypted SMB Traffic: Decryption, Client Identification and Event Reconstruction},
author = {Carl Gadde and Jan-Niclas Hilgert},
journal = {Digital Threats Research and Practice},
year = {2026},
doi = {10.1145/3848131},
url = {https://doi.org/10.1145/3848131}
}
FAQ
Using this paper in a discovery workflow
How do I find related work for this paper?
Use the related papers and topic links on this page as starting points. In Scollr, you can also open the paper and build a literature map around its references, citing papers, and related work.
How can I keep up with new Digital and Cyber Forensics research papers?
Follow Digital and Cyber Forensics research in Scollr. New papers from the topic flow into a personalized feed, and you can save useful studies to revisit later.
Can I cite this paper from this page?
This page includes a static BibTeX block for Forensic Analysis of Encrypted SMB Traffic: Decryption, Client Identification and Event Reconstruction. Always verify the DOI, source, and publication details against the publisher record before submitting a manuscript.
Follow this research in Scollr
Follow the topics and authors behind this paper, save useful studies, and build a literature map when you are ready to go deeper.
Get the app