SRUM (System Resource Usage Monitor)
Also called SRUDB.dat, system resource usage monitor, network data usage forensics.
- PLATFORM
- Windows
- CATEGORY
- Network and Remote Activity
- INDEX
- 32 of 36
- PROVES
- 4 findings
- CANNOT PROVE
- 6 limits
- QUESTIONS
- 3 answered
A Windows database attributing network bytes sent and received, and application foreground time, to individual programs and user accounts in hourly buckets.
Where it lives
C:\Windows\System32\sru\SRUDB.dat
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of srum (system resource usage monitor)” is neither.
What it records
The resource usage monitor keeps per-provider tables recording, for each application and user SID, the bytes sent and received over each network interface in an interval, along with application resource usage such as processor time and foreground duration, and network connectivity periods. Data is accumulated in memory and flushed to the database periodically, so the most recent interval may be missing from a database read from a dead image.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That a named application transmitted a specific quantity of data during a recorded interval, attributed to a user SID — a byte count, which almost no other endpoint artifact supplies
- Which network the machine was connected to during a period, and for how long
- Foreground application time, corroborating other application-usage artifacts
- Anomalous transfer volume: a browser or sync client sending gigabytes on an evening, which is a materially harder record to explain than a bare device connection
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- Where the data went. SRUM records volume per application, not destinations — no address, no hostname, no service
- What the data was. There are no filenames, no content and no indication of whether the bytes were documents, video, telemetry or an operating-system update
- That a transfer was an exfiltration. A cloud backup, a large software update delivered through a browser-based installer, and a video call all produce large counts
- Anything outside the retention window, which is a rolling period commonly measured in weeks and varies with configuration and activity
- Sub-hourly timing. Counts are bucketed by interval, so a transfer cannot be placed more precisely than the bucket holding it
- Complete coverage on a live acquisition, since the most recent interval may still be in memory and absent from the file
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Offering an innocent high-volume explanation the examiner did not exclude — updates, backups, streaming, conferencing
- Pointing out that no destination appears anywhere in the artifact, so the transfer cannot be tied to a personal account or an external party
- Establishing the rolling retention window and showing the relevant period aged out
- Noting that a live acquisition may have missed the final interval, which is often the interval of interest
What survives, and for how long
The database keeps a rolling window commonly measured in weeks rather than months, which makes it one of the artifacts that most rewards immediate preservation. It survives reboots, and a shadow copy sometimes holds an older version of the database covering a period the live one no longer does.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
Can SRUM show how much data was uploaded from a computer?
Yes, per application and per user account, in hourly buckets — bytes sent and received. That makes it one of the very few endpoint artifacts that supplies a quantity rather than an inference, and a browser or sync client transmitting several gigabytes on a Sunday evening is a harder record to explain than a bare USB connection. It records no destination and no content.
Does SRUM show where data was sent?
No. The database attributes byte counts to an application and a user, and to a network interface and connectivity period. There is no destination address, no hostname and no service name anywhere in it. Establishing where the data went requires network-side records — proxy, firewall, or endpoint data-loss-prevention logs — which are usually held by the employer and purged on short cycles.
How far back does SRUM data go?
A rolling window commonly measured in weeks, varying with configuration and system activity. That is short relative to the age of most disputes, so SRUM is frequently the artifact that would have decided the question and no longer covers it. A volume shadow copy sometimes preserves an older version of the database covering a period the live one has dropped.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
Browser History, Cache and Downloads
Per-profile databases recording pages visited with timestamps and transition types, files downloaded with their source URLs and target paths, and cached copies of retrieved content.
Prefetch
Files Windows writes to speed up program launches, recording that an executable ran, when it last ran, how many times, and which files it loaded on startup.
BAM and DAM
A registry record, organised by user SID, of the last execution time of individual executables — the rare Windows artifact that attributes execution to an account directly.
Volume Shadow Copies
Point-in-time block-level snapshots of a volume, often holding an earlier version of a file that has since been altered or deleted — sometimes the only copy of a document as it originally stood.
Whether the srum (system resource usage monitor)evidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.