Showing posts with label Cloud Forensics. Show all posts
Showing posts with label Cloud Forensics. Show all posts

Saturday, May 8, 2021

Cloud Forensics:Google Drive

Cloud Forensics:Google Drive

 วันนี้มาทดสอบการตรวจหาร่องรอยจาก GOOGLE DRIVE จากเครื่องคอมพิวเตอร์โดยพิจารณาจากอะไรบ้าง

ขั้นแรกทำการใช้โปรแกรม FTK Imager ทำสำเนาหลักฐานจากเครื่องคอมพิวเตอร์เป้าหมาย  ได้เป็น Forensic Image file ชื่อ CF009.E01 

Acquiring Disk Image with FTK Imager


Run Autopsy 4.15 and select New Case.
Provide the Case Name and the directory to store the case file. Click on Next.
  • Choose the required data source type, in this case Disk Image and click on Next.
  • Give path of the data source and click on Next.
  • You reach here once all the modules have been ingested. You can begin begin investigating but i recommend waiting until analysis and integrity check is complete.

Google Drive Forensic Artifatcs 

Directories created when Google Drive is installed

<SYSTEMROOT>\Program Files\Google\Drive

In this folder you will find the executable file of the application

<SYSTEMROOT>\Program Files (x86)\Google\Drive

Here you will find information about the updates of the application

<SYSTEMROOT>\Users\<username>\GoogleDrive

This is the default folder used for synchronizing the user’s files with Google Drive cloud service

<SYSTEMROOT>\Users\<username>\AppData\Local\Google\Drive

Here you will find all the native app’s files that store information about the app and the user’s data


Registry 

The installation of Google drive creates various keys and values inside the Registry. View the registry hives listed below in the forensic image of the suspect's hard disk.


    SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders

    SOFTWARE\Google\Drive

    NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Run\GoogleDriveSync




 From the Registry we can obtain the installed version and the user folder.

Let’s check the Registry to see if the sync process starts automatically with the user’s login. The right key to view here is NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Run

 

Event Log

Path

<SYSTEMROOT>\Windows\System32\winevt\Logs\Application.evtx

Event ID

1033

Event Description Summary

Windows installer installed the product

Provider Name

MsInstaller

Event Data

Among others “<EventData> <Data> Backup and Sync From Google3.43.2448.907110330Google,Inc.(NULL)</Data>”



Prefetch

Windows stores Prefetch files at <SYSTEMROOT>\Windows\Prefetch.
WinPrefetchView



LNK (Shortcut) Files

  • <SYSTEMROOT>\Users\<username>\Desktop\Google Drive.lnk
  •  <SYSTEMROOT>\Users\<username>\Links\Google Drive.lnk
  • <SYSTEMROOT>\ProgramData\Microsoft\Windows\Start Menu\Programs\Google \Drive\Google Drive.lnk
You can parse each of these lnk files with Eric Zimmerman's LECmd for detailed information. A truncated output is shown below.

Web-browsing history
You can find an SQLite database with browsing history under C:\Users\%username%\AppData\Local\Google\Chrome\User Data\Default.

The Log File

You can obtain information about the client sync session from the sync_log.log file located at <SYSTEMROOT>\Users\<username>\AppData\Local\Google\Drive\user_default. 
Database Artifacts

Database Artifacts

  • <SYSTEMROOT>\Users\<username>\AppData\Local\ Google\Drive\user_default\snapshot.db
  • <SYSTEMROOT>\Users\<username>\AppData\Local\Google\Drive\user_default\sync_config.db
  •  <SYSTEMROOT>\Users\<username>\AppData\Local\Google\Drive\cloud_graph\cloud_graph.db
  •  <SYSTEMROOT>Users\<username>\AppData\Local\Google\Drive\global.db
  •  snapshot.db

     Sync_config.db

    • Client version installed
    • Local sync root path
    • User email

                      cloud forensics google drive 

    #WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD 


    หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

    * หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง ADMIN เพื่อแก้ไขต่อไป
    ขอบคุณครับ

    Thursday, March 11, 2021

    Cloud Forensics:How To Extract Credential Data Using KeyScout

    Cloud Forensics:How To Extract Credential Data Using KeyScout

    Forensic Imaging & DATA Extraction

    Credit Photo by:  blog.oxygen-forensic 

    KeyScout is a utility built into Oxygen Forensic® Detective which uncovers and extracts user data, tokens and passwords from apps and web browsers as well as Wi-Fi hotspot passwords, iTunes backups, and operating system data on PCs running Windows.

    OxyKeyScout.Windows.exe  

    1. Run KeyScout on the target  computer

    Forensic Imaging & DATA Extraction
    The KeyScout application is one of the tools available in the tool suite concept of the Forensic Detective product. KeyScout is a standalone application that can be run locally. 
    Forensic Imaging & DATA Extraction
    2. Start search
    Forensic Imaging & DATA Extraction
    3. Save collected data to an inserted removable drive (this collection will contain both an ocpk file and odb file).
    Save resulted 
    Forensic Imaging & DATA Extraction
    Export Finished 
    Forensic Imaging & DATA Extraction
    2 passwords and 3 tokens. That’s bad all by itself. Out of 8 different applications, 5.67GB. of data – we’ll have a look. 
    Forensic Imaging & DATA Extraction
    Or, as you’ll see inside Detective when you finally pull extracted data into a case, the accounts and passwords section is the same information that would be contained in an OCPK file. You’ll see a button in the tool called ‘Export to OCPK.’ We’ll talk about the way you’d do that and what that means. But this is the literal ability to grab the account data to feed the Cloud Extractor.
    Forensic Imaging & DATA Extraction

    Well, let’s look here: Passwords and tokens. 
    Forensic Imaging & DATA Extraction
     Who knows what you’re doing? Select it all.
    Forensic Imaging & DATA Extraction

    Forensic Imaging & DATA Extraction
    4. Investigators can import the ocpk file to Oxygen Forensic® Cloud Extractor and the odb file to JetEngine.

    “Import credentials file generated by Oxygen Forensic Detective, which we just saw, or KeyScout, which we just saw. If you click that, it’s looking for that OCPK file.

    Forensic Imaging & DATA Extraction
    Forensic Imaging & DATA Extraction
    Forensic Imaging & DATA Extraction
    Forensic Imaging & DATA Extraction
    Forensic Imaging & DATA Extraction
    Forensic Imaging & DATA Extraction
    Forensic Imaging & DATA Extraction
    Forensic Imaging & DATA Extraction
    Forensic Imaging & DATA Extraction

    Forensic Imaging & DATA Extraction



    สรุป

    Oxygen Forensics เป็นผู้พัฒนาเครื่องมือประเภท digital forensics เพื่อช่วยในการสืบสวน ตัวเครื่องมือมีความสามารถในการวิเคราะห์ข้อมูลทั้งจากคอมพิวเตอร์ ,โทรศัทพ์มือถือและเก็บข้อมูลบนคลาวด์ หนึ่งในความสามารถที่ถูกเพิ่มเข้ามาในเวอร์ชันหลังๆ คือการดึงข้อมูลของ Credential Data จาก  application มาวิเคราะห์ได้

    KeyScout เป็นเครื่องมือสำหรับดึง Credential Data  , User password ,Wi-Fi hotspot passwords และ Tokens ของเครื่องเป้าหมาย ไฟล์ที่ได้เป็น .OCPK เพื่อนำไปวิเคราะห์ต่อไป โดยใช้โปรแกรม Oxygen Forensics เหมาะสำหรับงาน Cloud Forensics ,Mobile Forensics เช่น ข้อมูลจาก Dropbox ,Google Drive


    Credit by:


    หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

    * หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
    ขอบคุณครับ

    #WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD



    Sunday, January 31, 2021

    Cloud Forensics คือ

    Cloud Forensics คือ

    ในโลกที่เราอาศัยอยู่ทุกวันนี้:

    •ข้อมูลที่มีค่าส่วนใหญ่ของโลกถูกจัดเก็บแบบดิจิทัลในระบบคอมพิวเตอร์

    •อินเทอร์เน็ตที่มีการพัฒนาตลอดเวลาได้สร้างการเชื่อมต่อระดับสูงในโลกสมัยใหม่

    •คอมพิวเตอร์ส่วนใหญ่ที่จัดเก็บข้อมูลที่มีค่านี้เชื่อมต่อทางอิเล็กทรอนิกส์กับอินเทอร์เน็ตและระบบอื่น ๆ รวมถึงระบบในคลาวด์

    การรวมกันของข้อเท็จจริงเหล่านี้นำไปสู่ความต้องการเทคนิคการสืบสวนใหม่ ๆ ที่ใช้โดยนักนิติวิทยาศาสตร์ดิจิทัลเพื่อต่อสู้กับข้อมูลดิจิทัลที่สร้างขึ้นทั่วโลกที่เพิ่มขึ้นเรื่อย ๆ

    Cloud Forensics  การตรวจพิสูจน์พยานหลักฐานอิเล็กทรอนิกส์บนระบบคลาวน์ คือ ส่วนหนึ่งใน Network Forensics และ Digital Forensics เป็นการประยุกต์ใช้หลักการทางนิติวิทยาศาสตร์ดิจิทัล  แนวทางปฏิบัติในการสืบสวนสอบสวนเพื่อหาหลักฐานการประมวลผลบนคลาวด์และวิธีการการเก็บรักษา การตรวจสอบเหตุการณ์ การตีตวาม และการจัดทำรายงาน สามารถใช้เป็นพยานหลักฐานในศาลได้

    Cloud Computing คือบริการที่ครอบคลุมถึงการให้ใช้กำลังประมวลผล หน่วยจัดเก็บข้อมูล และระบบออนไลน์ต่างๆจากผู้ให้บริการ เพื่อลดความยุ่งยากในการติดตั้ง ดูแลระบบ ช่วยประหยัดเวลา และลดต้นทุนในการสร้างระบบคอมพิวเตอร์และเครือข่ายเอง ซึ่งก็มีทั้งแบบบริการฟรีและแบบเก็บเงิน

    ประเภทของบริการ คลาวด์คอมพิวติ้ง  (Cloud Service Models)

    บริการ Cloud Computing มีหลากหลายรูปแบบ หลักๆ 3 แบบได้แก่

    Software as a Service (SaaS)

    เป็นการที่ใช้หรือเช่าใช้บริการซอฟต์แวร์หรือแอพพลิเคชั่น ผ่านอินเทอร์เน็ต โดยประมวลผลบนระบบของผู้ให้บริการ ทำให้ไม่ต้องลงทุนในการสร้างระบบคอมพิวเตอร์ ฮาร์ดแวร์ ซอฟต์แวร์เอง ไม่ต้องพะวงเรื่องค่าใช้จ่ายในการดูแลระบบ เพราะซอฟต์แวร์จะถูกเรียกใช้งานผ่าน Cloud จากที่ไหนก็ได้

    ซึ่งบริการ Software as a Service ที่ใกล้ตัวเรามากทื่สุดก็คือ GMail นั่นเอง นอกจากนั้นก็เช่น Google Docs หรือ Google Apps ที่เป็นรูปแบบของการใช้งานซอฟต์แวร์ผ่านเว็บบราวเซอร์ สามารถใช้งานเอกสาร คำนวณ และสร้าง Presentation โดยไม่ต้องติดตั้งซอฟต์แวร์บนเครื่องเลย แถมใช้งานบนเครื่องไหนก็ได้ ที่ไหนก็ได้ แชร์งานร่วมกันกับผู้อื่นก็สะดวก ซึ่งการประมวลผลจะทำบน Server ของ Google ทำให้เราไม่ต้องการเครื่องที่มีกำลังประมวลผลสูงหรือพื้นที่เก็บข้อมูลมากๆในการทำงาน Chromebook ราคาประหยัดซักเครื่องก็ทำงานได้แล้ว มหาวิทยาลัยทั้งในไทยและต่างประเทศหลายแห่งในปัจจุบัน ก็ยกเลิกการตั้ง Mail Server สำหรับใช้งาน e-mail ของบุคลากร และนักศึกษาในมหาวิทยลัยกันเองแล้ว แต่หันมาใช้บริการอย่าง Google Apps แทน เป็นการลดต้นทุน, ภาระในการดูแล, และความยุ่งยากไปได้มาก

    Platform as a Service (PaaS)

    สำหรับการพัฒนาแอพพลิเคชั่นนั้น หากเราต้องการพัฒนาเวบแอพพลิเคชั่นที่ค่อนข้างซับซ้อน ซึ่งรันบนเซิร์ฟเวอร์ หรือ Mobile application ที่มีการประมวลผลทำงานอยู่บนเซิร์ฟเวอร์ เราก็ต้องตั้งเซิร์ฟเวอร์ เชื่อมต่อระบบเครือข่าย และสร้างสภาพแวดล้อม เพื่อทดสอบและรันซอฟต์แวร์และแอพพลิเคชั่น เช่น ติดตั้งระบบฐานข้อมูล, Web server, Runtime, Software Library, Frameworks ต่างๆ เป็นต้น จากนั้นก็อาจยังต้องเขียนโค้ดอีกจำนวนมาก

    แต่ถ้าเราใช้บริการ PaaS  ผู้ให้บริการจะเตรียมพื้นฐานต่างๆ เหล่านี้ไว้ให้เราต่อยอดได้เลย  พื้นฐานทั้ง Hardware, Software, และชุดคำสั่ง ที่ผู้ให้บริการเตรียมไว้ให้เราต่อยอดนี้เรียกว่า Platform ซึ่งก็จะทำให้ลดต้นทุนและเวลาที่ใช้ในการพัฒนาซอฟท์แวร์อย่างมาก ตัวอย่าง เช่น Google App Engine, Microsoft Azure ที่หลายๆบริษัทนำมาใช้เพื่อลดต้นทุนและเป็นตัวช่วยในการทำงาน

    Application ดังๆหลายตัวเช่น Snapchat ก็เลือกเช่าใช้บริการ PaaS อย่าง Google App Engine ทำให้สามารถพัฒนาแอพที่ให้บริการคนจำนวนมหาศาลได้ โดยใช้เวลาพัฒนาไม่นานด้วยทีมงานแค่ไม่กี่คน

    Infrastructure as a Service (IaaS)

    เป็นบริการให้ใช้โครงสร้างพื้นฐานทางคอมพิวเตอร์อย่าง หน่วยประมวลผล ระบบจัดเก็บข้อมูล ระบบเครือข่าย ในรูปแบบระบบเสมือน (Virtualization) ข้อดีคือองค์กรไม่ต้องลงทุนสิ่งเหล่านี้เอง, ยืดหยุ่นในการปรับเปลี่ยนโครงสร้างระบบไอทีขององค์กรในทุกรูปแบบ, สามารถขยายได้ง่าย ขยายได้ทีละนิดตามความเติบโตขององค์กรก็ได้ และที่สำคัญ ลดความยุ่งยากในการดูแล เพราะหน้าที่ในการดูแล จะอยู่ที่ผู้ให้บริการ

    ตัวอย่างบริการอื่นๆในกลุ่มนี้ก็เช่น Google Compute Engine, Amazon Web Services, Microsoft Azure

    Photo credit: lucidchart

     


    Cloud Computing and Forensics
    ปัญหาทางนิติวิทยาศาสตร์ที่มีลักษณะเฉพาะสำหรับการประมวลผลแบบคลาวด์ ได้แก่ เขตอำนาจศาลการครอบครองหลายพื้นที่และการพึ่งพา cloud service provide Cloud Forensics เป็นขั้นตอนของการพิสูจน์หลักฐานดิจิทัลโดยอาศัยวิธีการเฉพาะในการตรวจสอบสภาพแวดล้อมระบบคลาวด์ cloud service provide มีเซิร์ฟเวอร์ทั่วโลกให้บริการโฮสต์เก็บข้อมูลลูกค้า เมื่อเกิดเหตุการณ์ทางไซเบอร์ขึ้นเขตอำนาจศาลทางกฎหมายและกฎหมายที่ควบคุมภูมิภาคจะนำเสนอความท้าทายที่ไม่เหมือนใคร คำสั่งศาลที่ออกในเขตอำนาจศาลที่ศูนย์ข้อมูลตั้งอยู่มีแนวโน้มว่าจะใช้ไม่ได้กับเขตอำนาจศาลสำหรับโฮสต์ในต่างประเทศนั้น ในสภาพแวดล้อม cloud service provide สมัยใหม่ลูกค้าสามารถเลือกภูมิภาคที่ข้อมูลจะอยู่ได้และควรเลือกอย่างรอบคอบ

    ข้อกังวลหลักสำหรับผู้ตรวจสอบคือการตรวจสอบให้แน่ใจว่าหลักฐานดิจิทัลไม่ได้รับการดัดแปลงโดยบุคคลที่สามดังนั้นจึงสามารถยอมรับได้ในศาล ในรูปแบบบริการ PaaS และ SaaS ลูกค้าต้องพึ่งพาผู้ให้บริการระบบคลาวด์ในการเข้าถึงบันทึก (access log) เนื่องจากไม่มีการควบคุมฮาร์ดแวร์ ในบางกรณี cloud service provide จะไม่เปิดเผยรายละเอียดของบันทึกจากลูกค้า ในกรณีอื่น ๆ cloud service provide  มีนโยบายที่จะไม่เสนอบริการเพื่อรวบรวมบันทึก

    ห่วงโซ่การคุ้มครองพยานหลักฐาน (Chain of custody )เป็นเรื่องที่ท้าทายมากในสภาพแวดล้อมแบบคลาวด์เมื่อเทียบกับสภาพแวดล้อมทางนิติดิจิทัลแบบเดิม ในสภาพแวดล้อมทางนิติดิจิทัลแบบเดิมทีมรักษาความปลอดภัยภายในสามารถควบคุมได้ว่าใครเป็นผู้ดำเนินการทางนิติวิทยาศาสตร์บนเครื่องในขณะที่ในการพิสูจน์หลักฐานบนคลาวด์ทีมรักษาความปลอดภัยไม่สามารถควบคุมได้ว่าใครเป็นผู้ที่ cloud service provide เลือกที่จะรวบรวมหลักฐาน หากพวกเขาไม่ได้รับการฝึกอบรมตามมาตรฐานทางนิติวิทยาศาสตร์และห่วงโซ่การคุ้มครองพยานหลักฐานจะไม่ถูกรับฟังในศาล  ส่วนหนึ่งของปัญหาเหล่านั้นคือเรื่องของกฎเกณฑ์และวิธีในการสืบสวนที่ใช้กับระบบคอมพิวเตอร์แบบเดิมไม่สามารถนำมาใช้ได้กับระบบคลาวด์คอมพิวติ้ง

     Cloud Forensics Course


    #การสืบสวนหลักฐานดิจิทัลบนระบบคลาวด์

    Credit:Forensics in the Cloud: What You Need to Know

              NIST Cloud Computing Forensic Science Challenges



    หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น ช่วยเตือนความจำ

    * หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
    ขอบคุณครับ

    #WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD #คดีอาชญากรรมคอมพิวเตอร์

     

     

    Volatility Lab

    Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...