Showing posts with label Email Forensics Tools. Show all posts
Showing posts with label Email Forensics Tools. Show all posts

Friday, January 3, 2025

Email Header Analysis IP Tracker

 Email Header Analysis IP Tracker 

Email Header Analysis Tool

Sample I

Email Header Analysis tool  to trace the origin of an email and gain valuable insights into its journey. Simply paste the email header into the form below to uncover details like the sender’s IP address, mail servers, and email path. If you need help extracting the header, 

Email Header Analysis by  iptrackeronline 

1.Open the email message

Email Header Analysis Tools

2. Click Show Original.

IP Lookup Email (SPF)

3. Copy and paste the header information into the Email Header Analysis Engine, and click Submit header for analysis.

Photo by :iptrackeronline

Geographical Info

Email Header Analysis Tools

 

Email Header Info

Email Header Analysis Tools
Photo by :iptrackeronline
Information Gathering
Email Header Analysis Tools
Photo by :iptrackeronline


Sample II 

Email Header Analysis by  Header Analyzed

Email Header Analysis  IP Tracker
Photo by :mxtoolbox.com

Relay Information

Email Header Analysis  IP Tracker
Photo by :mxtoolbox.com

Headers Found

Email Header Analysis  IP Tracker
Photo by :mxtoolbox.com

Email Header Analysis  IP Tracker
Photo by :mxtoolbox.com

SPF and DKIM Information

Email Header Analysis  IP Tracker
Photo by :mxtoolbox.com


อ่านเพิ่มเติม: Email Forensics Tools

ทีมา :   iptrackeronline
หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูล  เผยแพร่ความรู้และให้โอกาสในการค้นคว้าหาข้อมูลเพื่อการศึกษา   บุคคลที่สนใจโดยทั่วไป รวมถึงนักเรียน นิสิต นักศึกษา  ในการเรียนรู้เท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD


Friday, January 8, 2021

Email Forensics: Metaspike CTF

Email Forensics: Metaspike CTF

วันนี้มาแนะนำการแข่งขัน Email Forensics CTF ซึ่งจัดโดยกลุ่ม Metaspike Community! กลุ่มเปิดให้ทุกคนพูดคุยเกี่ยวกับ digital forensics เข้าร่วมการสนทนาเพื่อแบ่งปันประสบการณ์คำแนะนำและเคล็ดลับและเรียนรู้จากผู้อื่น และมีจัดกิจกรรม Capture The Flag (CTF)  โดยกิจกรรมจะเปิดและปิดเป็นช่วง Jan- Feb 2021

Tools recommendations for the CTF

Text Editor

I strongly recommend using a capable text editor. My favorite is UltraEdit. Other good options are Sublime Text or Atom, possibly with some MIME syntax highlighters.

Conversions

I recommend using CyberChef for date and format conversions.

MAPI

When working with MSGs and PSTs, you can use MFCMAPI or OutlookSpy with Outlook.

General Metadata Extraction

You will likely need a general-purpose tool that can extract embedded files, file metadata, etc. Good candidates are X-Ways, Autopsy, or perhaps ExifTool or MetaDiver when you don’t feel like pulling out the big guns.

PDF Deep Dive

When you encounter PDFs, you will likely need a deep dive tool to look into them in detail. You can use PDF CanOpener (with Acrobat), PDF Stream Dumper, pdf-parser.py, etc.

ลองทำโจทย์ข้อ 1 Draft_Agreement.eml

(SHA-256: 42B6FD78DAF38C03E1A744ECA1A0CB44F6859AB892E0F32B01763EFD835B5648)

เป็นอีเมลปกติ ลงวันที่ 7 มีนาคม 2016 มีการสื่อสารระหว่าง Yahoo และ Gmail พร้อมไฟล์แนบ PDF
 ใช้ https://mxtoolbox.com ดู EML มีสองวิธีในการดูส่วนหัวของอีเมล  ทั้งในรูปแบบข้อความภายใต้“ ส่วนหัวของข้อความ” หรือแยกวิเคราะห์เป็นช่องภายใต้“ คุณสมบัติ” แต่เนื่องจากอีเมลอยู่ในรูปแบบ EML เราจึงสามารถดูได้ตามรูปที่แสดงผลลัพธ์ดังนี้
พบว่าในส่วนลายเซ็น DKIM   ซึ่งอาจจะไม่ถูกต้องก็ได้และ ใช้ในการตอบ 

ตอบ: F for Fack เป็นไปได้ว่าเป็นอีเมลที่ถูกปลอมขึ้น 


โจทย์ข้อที่ 2  ใช้ไฟล์จากโจทย์ข้อ 1  You will be examining the same email as in Part 1.

เราคิดอยู่แล้วว่าอีเมลนั้นหลอกลวง และเราทราบดีว่าเนื่องจากไฟล์นั้นเป็นไฟล์ EML จึงสามารถแก้ไขทุกอย่างที่อยู่ภายในอีเมลได้ โดยเฉพาะอย่างยิ่งการประทับเวลาที่ระบุได้ง่าย

หากเราดูการประทับเวลาทุกครั้ง เราจะเห็นวันที่มาตรฐานที่หลากหลาย รวมถึงการประทับเวลาแบบยูนิกซ์ การถอดรหัสทั้งหมดนั้นค่อนข้างเป็นการประทับเวลาเดียวกันและก็ผิดด้วย  

Mon, 7 Mar 2016 14:38:34 -0800 (PST)
Mon, 07 Mar 2016 14:38:34 -0800 (PST)
Mon, 07 Mar 2016 14:38:34 -0800 (PST)
Mon, 7 Mar 2016 22:38:33 +0000
Mon, 7 Mar 2016 22:38:31 +0000 (UTC)



Mon, 7 Mar 2016 22:38 Incorrect 

Email Forensics Workshop

 where we solved the first five challenges in Metaspike's Email Forensics Capture The Flag (CTF) competition. We covered topics such as:

• Examining emails in MIME format
• Message headers
• Leveraging DKIM and ARC
• Working with MAPI
• Investigating IMAP servers
• Server metadata
• Q&A


Creadit:


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud


Saturday, August 15, 2015

DIGITAL FORENSICS: Email Forensics Tools

DIGITAL FORENSICS: Email Forensics Tools

1. Recover My Email For Microsoft Outlook

Recover My Email Software recovers deleted email messages and attachments in all versions of Microsoft Outlook and Outlook Express. It can also access corrupt Outlook .PST files and corrupt Outlook Express .DBX files, even if these programs are not installed on the computer.

 Source:http://www.recovermyemail.com

2.MailXaminer 

Designed from the ground up, as an Email Examination Tool. MailXaminer supports 20+ email file formats and 750+ MIME types. Thus, leveraging the examination of 80+ email clients

 Source:https://www.mailxaminer.com/


3.eMailTrackerPro


Trace email back to its source and stop spam

Over 97% of all email is spam. Spam can be harmless but annoying, it can contain viruses or it can try and trick someone into giving up personal details which in turn leads to identity fraud. EmailTrackerPro not only offers the ability to trace an email using the email header but it also comes with a spam filter (advanced edition), which scans each email as it arrives and warns the user if it's suspected spam. Essentially stopping spam email before it reaches its intended recipient.

Source:http://www.emailtrackerpro.com

4.Forensic Toolkit (FTK)® | AccessData

 FTK provides an intuitive interface for email analysis for forensic professionals. This includes having the ability to parse emails for certain words, header analysis for source IP address, etc. A central feature of FTK, file decryption is arguably the most common use of the software.

 

Source:https://accessdata.com/

5.Paraben E3:EMX 

 
E3:EMX was designed to be an affordable and comprehensive email examination tool for local email archives. Paraben has been processing email since 2002 and has a long history of understanding the issues that exist with email such as corruption and deleted data recovery. E3:EMX is the only tool that is priced to be affordable for everyone on a team processing for forensics or eDiscovery. E3:EMX provides support for over a dozen email archive types, all with easy-to-use options and automated deleted data recovery:

Source:https://paraben.com/email-forensics-emx/

6.Stellar Undelete Email for Outlook

Stellar Undelete Email for Outlook is an advanced deleted email recovery software that safely recovers lost or deleted emails from MS Outlook mailbox.'.


Source:https://www.stellarinfo.com

7. Kernel for Outlook PST Repair

Repair corrupted PST files and saves to PST, MBOX, Office 365 and Exchange server

Source:https://www.nucleustechnologies.com

 8.Wise Data Recovery

  Easily and quickly recover deleted photos, documents, videos, email, etc. Recover data from local drives, external drive, USB drive, SD card, mobile phone and other removable devices.

Source:https://www.wisecleaner.com/wise-data-recovery.html

9.EaseUS Email Recovery Wizard

 Easy email recovery software to recover your deleted or lost emails, email files, contacts, appointments and notes safely.

Source:https://www.easeus.com/emailrecoverywizard/

10.DiskInternals Updates Mail Recovery

 DiskInternals Mail Recovery allows everyone to recover and fix email databases used by Microsoft Outlook, Outlook Express, Windows Mail, Thunderbird and TheBat. The new version works fully automatically. The tool locates, recovers and repairs email databases automatically even if the disk is damaged or inaccessible.

Source:https://www.diskinternals.com/press/mail_recovery_15/

  11.Aid4Mail

 Aid4Mail is a fast, accurate, and easy-to-learn email forensics software solution. Over the years, it has become an essential tool for computer forensics and e-discovery professionals around the world.

Source:https://www.aid4mail.com/email-forensics

Email Header Analyzer Tools


 This tool will make email headers human readable by parsing them according to RFC 822.  Email headers are present on every email you receive via the Internet and can provide valuable diagnostic information like hop delays, anti-spam results and more. If you need help getting copies of your email headers

Source:https://mxtoolbox.com/EmailHeaders.aspx


13.Trace Email (Header Analyzer)

Analyze the email headers and trace the email sender IP location and IP Whois easily.
Source:https://dnschecker.org/email-header-analyzer.php

14.Analyze my mail header


15. EmailHeader

This plugin will parse .eml or .msg files for email message headers, including x-headers, and will also color IPv4 and IPv6 addresses for ease of readability. Note: requires Sublime Text build 3092 or higher.

Source: https://github.com/13Cubed/EmailHeader



16. G Suite Toolbox Messageheader analyzes 


Source:https://toolbox.googleapps.com/apps/messageheader/


17. Message Header Analyzer


Source: https://mha.azurewebsites.net/


18. iptrackeronline



Source: https://www.iptrackeronline.com/


19.Email Header Tracer


Source:https://www.ip2location.com/free/email-tracer



หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...