Showing posts with label Computer Forensics Exercises. Show all posts
Showing posts with label Computer Forensics Exercises. Show all posts

Friday, July 4, 2025

Digital Forensics:How to Detect AI Generated Images

Digital Forensics:How to Detect AI Generated Images

เมตาดาตาในบริบทของ ChatGPT หมายถึงข้อมูลเกี่ยวกับข้อมูลที่สร้างขึ้นโดย AI ซึ่งอาจรวมถึงรายละเอียดเกี่ยวกับการสร้าง วัตถุประสงค์ และบริบท เมตาดาตานี้สามารถใช้เพื่อทำความเข้าใจลักษณะของเนื้อหา ซึ่งอาจช่วยในงานต่างๆ เช่น การตรวจสอบเนื้อหา การติดตามประสิทธิภาพ และแม้กระทั่งช่วยปรับแต่งการตอบสนองในอนาคต

Photo By: AI ChatGPT

ตรวจสอบโดยใช้ exiftool(-k) Tools  ChatGPT Image


Photo By: AI ChatGPT

วิเคราะห์ข้อมูลจาก Metadata

1. แหล่งกำเนิดและเครื่องมือสร้างภาพ

  • สร้างโดย AI: Software Agent: GPT-4o, OpenAI API

  • เครื่องมือสร้าง: Claim Generator: ChatGPT

  • ประเภทเนื้อหา: Digital Source Type: trainedAlgorithmicMedia (สื่อที่สร้างโดยอัลกอริทึม)

  • มาตรฐานเนื้อหา: ใช้มาตรฐาน C2PA (Coalition for Content Provenance and Authenticity) สำหรับติดตามที่มาของเนื้อหา C2PA signature เป็นเทคโนโลยีที่ใช้ในการลงนามและยืนยันความถูกต้องของเนื้อหาดิจิทัล เช่น รูปภาพและวิดีโอ โดยใช้มาตรฐานของ Content Authenticity Initiative (C2PA) เพื่อให้แน่ใจว่าเนื้อหานั้นไม่ได้ถูกแก้ไขหรือปลอมแปลง 

  • การวิเคราะห์ข้อมูลเมตาสำหรับการตรวจสอบ ผู้เชี่ยวชาญด้านนิติวิทยาศาสตร์ใช้ข้อมูลเมตาเพื่อระบุความไม่สอดคล้องกัน (เช่น รุ่นกล้องที่ถ่าย และ เวลาที่ถ่ายภาพ) ซึ่งภาพที่สร้างโดย AI ไม่มีข้อมูลดังกล่าว อาจบ่งชี้ว่าเป็นภาพปลอมหรือถูกสร้างขึ้น (Missing camera information (e.g., no camera model, lens details).

  • การระบุภาพที่สร้างโดย AI:

    ซึ่งมักเกี่ยวข้องกับการมองหาความไม่สอดคล้องเล็กๆ น้อยๆ ในรายละเอียด พื้นผิว แสง พื้นหลัง และลักษณะใบหน้าที่ AI ไม่สามารถจำลองได้อย่างสมบูรณ์แบบ

  • ตรวจสอบวันที่สร้างหรือข้อมูลซอฟต์แวร์ไม่สอดคล้องกัน

2. ข้อมูลการสร้างและแก้ไข

  • เวลาสร้างจริง02:48:48 AM (จากชื่อไฟล์) vs 02:49:53 UTC (เวลาบันทึกไฟล์) - มีความคลาดเคลื่อน 1 นาที 5 วินาที

  • การกระทำสำคัญ:

    • c2pa.created: การสร้างเนื้อหาเริ่มต้น

    • c2pa.converted: การแปลงรูปแบบไฟล์

3. ลายเซ็นดิจิทัลและความสมบูรณ์

  • ลายเซ็นดิจิทัลSelf-signed JUMBF manifest

  • อัลกอริทึมแฮชSHA-256 (ใช้ในการตรวจสอบความสมบูรณ์)

  • ผลการตรวจสอบ:

    • claimSignature.validated - ลายเซ็นถูกต้อง

    • assertion.dataHash.match - ข้อมูลไม่ถูกแก้ไขหลังสร้าง

4. ข้อมูลสำคัญที่ซ่อนอยู่ (Forensic Artifacts)

  • Zone Identifier: บ่งชี้ว่าไฟล์นี้ถูกดาวน์โหลดจากอินเทอร์เน็ต

  • Thumbnail JPEG: มีภาพ thumbnail ขนาด 34.1 KB ฝังใน metadata

5. การตรวจสอบโดย The C2PA Verify tool 

มาตรฐาน C2PA คืออะไร และช่วยอะไรบ้าง?
C2PA เป็นมาตรฐานทางเทคนิคแบบเปิดที่อนุญาตให้ผู้เผยแพร่ บริษัท และบุคคลอื่นๆ ฝังเมตาดาตาลงในสื่อเพื่อยืนยันแหล่งที่มาและข้อมูลที่เกี่ยวข้อง C2PA ไม่ได้มีไว้สำหรับภาพที่สร้างโดย AI เท่านั้น แต่มาตรฐานเดียวกันนี้ยังถูกนำมาใช้โดยผู้ผลิตกล้อง องค์กรข่าว และบุคคลอื่นๆ เพื่อรับรองแหล่งที่มาและประวัติ (หรือที่มา) ของเนื้อหาสื่อ
Digital Forensics:How to Detect AI Generated Images
Photo by :https://opensource.contentauthenticity.org

Digital Forensics:How to Detect AI Generated Images
Photo By: AI ChatGPT


6. Hive Moderation:(เว็บไซต์ ตรวจสอบภาพด้วย AI 

Digital Forensics:How to Detect AI Generated Images
Photo by :sightengine.com

7. Forensically:(เว็บไซต์ ตรวจสอบภาพด้วย AI )


Digital Forensics:How to Detect AI Generated Images
Photo by :https://29a.ch/

Photo by: hackerfactor[.]com

How to Detect AI Generated Images
Question

1.What is the  file header in this image?
ANS:
hint:FTKImager,Hex Editor

2.When was this image created?
ANS:

3.What brand of camera was this photo taken with?
ANS:
4.This picture is generator by?
ANS:

5.Which information shows the details of the received content as true without modification?
ANS:
hint:C2PA

6.What is C2PA?
ANS:

7.Can you confirm that this image was created by AI?
ANS:
hint:contentcredentials


อ่านเพิ่มเติม
* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics
#digitalforensics #investigation #cybercrime #fraud

Friday, October 11, 2024

Digital Forensics:METADATA LAB II

Digital Forensics:METADATA LAB II

Analyzing EXIF data:

The ways to analyze the metadata in a PDF file is through a free application Exiftool. 

Let's take a look at File A's metadata with exiftool:

Digital Forensics:METADATA LAB II

USING THE EXIFTOOL FOR METADATA   


ExifTool is a platform-independent Perl library plus a command-line application for reading, writing and editing meta information

USING THE EXIFTOOL FOR METADATA   


Lab II. File1

1. What is the name of this file?

 Ans:

2. What is the type of this file?

 Ans:

3. What is the file type extension?

 Ans:

4. What is the size of it?

 Ans:

5. Who’s the creator of the file?

Ans:

6. What is the MAC date of this file?

Ans:

7.Find the md5 hash of this File1 pdf file.

Ans:


อ่านเพิ่มเติม:


* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics
#digitalforensics #investigation #cybercrime #fraud

Sunday, August 22, 2021

DIGITAL FORENSICS:OTTERCTF MEMORY FORENSICS

DIGITAL FORENSICS:otterctf Memory Forensics

วันนี้่จะมาแนะนำการฝึกทำ Digital Forensics & MEMORY FORENSICS ในเว็บ https://otterctf.com/  ของ Asaf Eitani มีโจทย์ CTF มาให้ลองเล่น เป็นโจทย์แนว MEMORY FORENSICS

ในความพยายามที่จะพัฒนาทักษะด้าน Digital Forensics  ใช้เวลาในการฝึกโดยการเล่น CTF ทาง Digital Forensics 

OtterCTF เริ่มตั้งแต่เดือนธันวาคม 2018 และรวมถึง,Misc,Reverse Engineering ,Network ,Steganography  และความท้าทายด้าน Forensics  บทความนี้ครอบคลุมเฉพาะส่วน ของMemory Forensics  คุณสามารถเข้าไปของเล่นได้ที่  OtterCTF 




1 - What the password?

you got a sample of rick's PC's memory. can you get his user password? format: CTF{...}
#vol.exe imageinfo -f J:\CTF\OtterCTF.vmem

#vol.exe vol.py -f J:\CTF\OtterCTF.vmem --profile="Win7SP1x
64" hashdump

J:\CTF\volatility_2.6>vol.exe vol.py -f J:\CTF\OtterCTF.vmem --profile="Win7SP1x

64" lsadump


CTF{MortyIsReallyAnOtter}

2 - General Info

Let's start easy - whats the PC's name and IP address?

volatility -f OtterCTF.vmem --profile Win7SP1x64 hivelist




volatility -f OtterCTF.vmem --profile Win7SP1x64 printkey -o 0xfffff8a000024010 -K "ControlSet001\Control\ComputerName\ComputerName"

CTF{192.168.202.131}
CTF{WIN-LO6FAF3DTFE}

3 - Play Time

Description: Rick just loves to play some good old videogames. can you tell which game is he playing? whats the IP address of the server?

volatility -f OtterCTF.vmem --profile Win7SP1x64 netscan


CTF{LunarMS}
CTF{77.102.199.102}


4 - Name Game

 We know that the account was logged in to a channel called Lunar-3. what is the account name?

ทำการใช้คำสั่ง  dump รายละเอียด ที่ถูกเรียกใช้ โดย Process ID 708 ไปที่Folder ที่เราสร้างไว้
#volatility -f j:\CTF\OtterCTF.vmem --profile Win7SP1x64 memdu
mp -p 708 -D J:\CTF\volatility_2.6\Dump

strings Desktop/Dump/708.dmp | grep -a Lunar\-3 -C 4 

CTF{0tt3r8r33z3}


6 - Silly Rick

Description: Silly rick always forgets his email's password, so he uses a Stored Password Services online to store his password. He always copy and paste the password so he will not get it wrong. whats rick's email password?

#vol.py -f j:\CTF\OtterCTF.vmem --profile Win7SP1x64 clipboard

CTF{M@il_Pr0vid0rs}

7 - Hide And Seek


The reason that we took rick's PC memory dump is because there was a malware infection. Please find the malware process name (including the extension)
#vol.py -f OtterCTF.vmem --profile="Win7SP1x64" pstree

#vol.py -f j:\CTF\OtterCTF.vmem --profile Win7SP1x64 cmdli
ne -p 3820,3720
Name: VapeHacksLoader.exe

CTF{vmware-tray.exe}

8 - Path To Glory

How did the malware got to rick's PC? It must be one of rick old illegal habits...
vol.py -f OtterCTF.vmem --profile="Win7SP1x64" filescan | grep -i "rick and morty"


vol.py -f OtterCTF.vmem --profile="Win7SP1x64" dumpfiles -Q 0x000000007d8813c0 -D
cat file.None.0xfffffa801af10010.dat

root@kali:~# volatility -f Desktop/OtterCTF.vmem --profile="Win7SP1x64" dumpfiles -Q 0x000000007dae9350 -D .

root@kali:~# strings file.None.0xfffffa801b42c9e0.dat

CTF{M3an_T0rren7_4_R!ck}


10 - Bit 4 Bit

We've found out that the malware is a ransomware. Find the attacker's bitcoin address.

#volatility -f Desktop/OtterCTF.vmem --profile="Win7SP1x64" filescan | grep "Desktop"


#vol.py -f OtterCTF.vmem --profile="Win7SP1x64" memdump -p 3720 -D .


#strings -e l 3720.dmp | grep -i -A 5 "ransom"


CTF{1MmpEmebJkqXG8nQv4cjJSmxZQFVmFo63M}






อ่าน เพิ่ม Memory Forensics



หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD







Friday, June 5, 2020

NIST Scientific Foundation Study for Digital Examiners

DIGITAL FORENSICS:NIST Scientific Foundation Study for Digital Examiners


NIST to Digital Forensics Experts: Show Us What You Got

First large-scale “black box” study will test the accuracy of computer and mobile phone forensics.

 “We want to understand the state of the practice. Can experts produce accurate and reliable information when extracting data from a digital device?” —Barbara Guttman, leader of NIST’s digital forensics research program
For the NIST black box study, participants will download simulated evidence from the NIST website in the form of one virtual mobile phone and one virtual computer. Such virtual devices, called “forensic images,” are commonly used in digital forensics, and study participants will be able to connect to them using the same software tools they use when working on real cases.
The forensic images created for this study simulate imagined but realistic scenarios involving a potential homicide and a potential theft of intellectual property. Study participants will download the images, examine them using whatever forensic software tools they choose, and answer a series of questions. For instance:
  • What software program was used to discuss a potentially illegal transaction? 
  • What was the VIN number of the vehicle that connected to the phone via Bluetooth?  
  • What location information can be gleaned from the photo of a black Labrador found on this device?

Welcome to NIST Scientific Foundation Study for Digital Examiners

You have chosen to take the offline simulated case study for the hard drive test.

Your will need to download the material for the offline simulated case study.
These files include the image file download for the hard drive test study, as well as the testing worksheet.
We estimate the test to take approximately 2 hours to complete after downloading the simulated case material.
Complete the case study offline then return your worksheet answers to NIST using the 'Test Survey' link listed below.

Testing Image Download:
Size mobile image, 5.2GB hard drive image 19GB


Image Download File Signatures:
mobile image SHAs =
MD5=c54a9c1659d931b14154c919929005b9 UFED_Samsung_GSM_SM-G920A_Galaxy_S6_2019_08_13_(001).zip
SHA1=43a7a27638020e2593d540186edc0e5f398a608b UFED_Samsung_GSM_SM-G920A_Galaxy_S6_2019_08_13_(001).zip
SHA256=04b2db3258ef30ebb1a3be47b9716455ef4fb1ede677a933470291eca82e9aff UFED_Samsung_GSM_SM-G920A_Galaxy_S6_2019_08_13_(001).zip

hard drive image SHAs
MD5=c1128ffc1c0582234d3a6fbb3a762d11 HardDrive-002.zip
SHA1= 795c2fd3632e5dc76cb4acfc9e42a948f73599a0 HardDrive-002.zip
SHA256= 8501aa9ba74fd4410489c8b2e1b120aa27c1bb8bac4c740f73ba708fff836445 HardDrive-002.zip

Testing Worksheet:



Testing Worksheet File Signatures:
mobile worksheet SHAs
nist_mobile_test_questions.pdf MD5=f821fb48dc5b6a7c8f63cd170bc514fd
nist_mobile_test_questions.pdf SHA1=c908963e6460205decd49be46696fd6f96573d6b
nist_mobile_test_questions.pdf SHA256=c8f5188538fc3187b374a332bb5de21817d3a1cea2f5e440ac9abf1faf5ece3a

hard drive worksheet SHAs
NIST_HD_TestQuestions.pdf MD5=a877e2d29e5e237592468d71c0c93158
NIST_HD_TestQuestions.pdf SHA1=377cd970c6828fa29b96fd0bf42a8019372ad3ab
NIST_HD_TestQuestions.pdf SHA256=662578cb175988cada78f00b6e5b7d53e157d23e362d9bd37fd75352291b4969


Expiration Date: 07/31/2022

NIST Blackbox Study for Digital Examiners


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

NIST black box study

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud #ฝึกทำLab

Tuesday, May 19, 2020

DIGITAL FORENSICS:INCIDENT-RESPONSE-CHALLENGE

DIGITAL FORENSICS:incident-response-challenge


วันนี้่จะมาแนะนำการฝึกทำ Digital Forensics & Incident Response ในเว็บ incident-response-challenge.com/  ของ Cynet  มีโจทย์ CTF มาให้ลองเล่น เป็นโจทย์แนว forensics
:INCIDENT-RESPONSE-CHALLENGE
Cynet  คือ แพลตฟอร์มทางเลือกสำหรับ Incident Response

แพลตฟอร์ม Cynet 360 ช่วยให้ผู้รับมือ Incident Response ด้วยการมองเห็น process execution, network traffic and user activity. ปริมาณการใช้เครือข่ายและกิจกรรมของผู้ใช้ สภาพแวดล้อมทั้งหมด ช่วยให้ผู้เชี่ยวชาญด้าน IR สามารถมองเห็นได้ทันที  ใช้ในการสืบสวน  ช่วยในเรื่องขั้นตอนการตรวจสอบเบื้องต้นเพื่อให้เข้าใจถึงขอบเขตของเหตุการณ์ โดยไม่ต้องเสียเวลา


Hall of Fame  ลำดับสุดยอด  คนที่ทำคะแนนได้สูงและเร็ว แต่ละประเทศ จะเห็นได้ว่ามีคนไทยเก่งๆหลายคน และอาจารย์ที่ผมรู้จักด้วย
:INCIDENT-RESPONSE-CHALLENGE

:INCIDENT-RESPONSE-CHALLENGE

ก่อนเล่นให้ ทำการสมัครสมาชิก
:INCIDENT-RESPONSE-CHALLENGE
Challenges เริ่มทำ โดยมีการจับเวลา
:INCIDENT-RESPONSE-CHALLENGE
เมื่อทำการ Download File เวลาจะเริ่มเดิน และ เมื่อทำเสร็จให้กด Submit 
:INCIDENT-RESPONSE-CHALLENGE
ใช้เครื่องมือต่างๆและความรู้ทางด้าน  Digital Forensics & Incident Response
ตัวอย่าง ข้อ Basic ก็ถือว่ายากสำหรับคนที่ไม่มีพื้นฐานด้านนี้ แต่คนที่มีพื้นฐานก็จะสนุกกลับมัน

JumpList Explorer
:INCIDENT-RESPONSE-CHALLENGE
 Volatility Workbench
:INCIDENT-RESPONSE-CHALLENGE
 MFTDump
:INCIDENT-RESPONSE-CHALLENGE
Windows prefetch
:INCIDENT-RESPONSE-CHALLENGE

:INCIDENT-RESPONSE-CHALLENGE
 Registry Viewer
:INCIDENT-RESPONSE-CHALLENGE


และเป็นอีกครั้งที่ผมทำ LAB ไม่เสร็จ ขอค้างไว้แค่นี้ก่อนแล้วค่อยทยอย ทำเรื่อยๆครับ

Challenge-Answers

หมายเหตุ : เหมาะสำหรับการฝึกฝน Digital Forensics & Incident Response และทำให้ใช้เครื่องมือต่างๆ ได้คล่อง


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud #ฝึกทำLab

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...