Showing posts with label Forensic Acquisition. Show all posts
Showing posts with label Forensic Acquisition. Show all posts

Sunday, March 29, 2026

A step-by-step guide on how to perform a drive acquisition using dc3dd

A step-by-step guide on how to perform a drive acquisition using dc3dd


Photo by Gemini

Step 1: Identify the Target Drive

Before starting, you must identify the correct device path for the drive you wish to image. Using a command like fdisk helps ensure you don't accidentally image the wrong disk.

  • Command: sudo fdisk -l

  • a log file detailing the acquisition

  • Result: In the provided example, the target drive is identified as /dev/sdb, a 1.9 GiB device.

Step 2: Prevent Data Overwriting (Write-Blocking)

ISO/IEC 27037

Option A: Hardware Write-Blocker (Recommended)

ฮาร์ดแวร์คอมพิวเตอร์

Use a physical hardware write-blocker (like Tableau or WiebeTech) between the suspect drive and your workstation. This is the gold standard in forensics.

Option B: Software Write-Block (Forensics Mode) 

Step 3: Execute the Acquisition Command

Run the dc3dd command with the necessary flags for hashing and logging. This ensures the integrity of your forensic image.

Command: sudo dc3dd if=/dev/sdb of=Desktop/CF005.dd hash=sha256 log=CF005.log

Breaking down the flags:

  • if=/dev/sdb: The input file (source drive).
  • of=Desktop/CF005.dd: The output file (forensic image destination).
  • hash=sha256: Calculates the SHA256 hash during the imaging process.
  • log=CF005.log: Creates a log file detailing the acquisition.

Step 4: Monitor Progress

dc3dd provides a real-time progress bar, showing the percentage completed, the amount of data copied, and the current transfer speed.

  • Example: The image shows the process at 9% completion with a speed of 7.4 M/s.

    a drive acquisition using dc3dd

Step 5: Review Acquisition Results

Once completed, dc3dd will display the input and output results. This includes the total sectors processed and the final hash value.

  • Input Results: 3870720 sectors in.

  • SHA256 Hash: f2404d910f82fc1e7d5907e28cb511cfb1d8a7d61d2f965e17f9019200054184.

  • a drive acquisition using dc3dd

A log file detailing the acquisition
  • a drive acquisition using dc3dd

Step 5: Verify Integrity 

To ensure the image is a perfect bit-for-bit copy, you should manually verify the hashes of both the source drive and the resulting image file.

  1. Check Source Hash: sudo sha256sum /dev/sdb > source_CF005.txt

    a drive acquisition using dc3dd

  2. Check Image Hash: sudo sha256sum Desktop/CF005.dd > Image_CF005.txt

a drive acquisition using dc3dd

Pro Tip: If the hashes match (as seen in the example images), you have successfully maintained the chain of custody and proven that the data has not been altered during the process.


Forensic Imaging with DD command

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Friday, February 26, 2021

BitLocker for Digital Forensics – Part II

BitLocker for Digital Forensics – Part II

     วันนี้พบบทความน่าสนใจเรื่องการจัดการหลักฐานที่มีการเข้ารหัสด้วย  BitLocker   โดยในกรณีศึกษา เช่น เมื่อเราไปเก็บหลักฐานจากแล็ปท็อปและทำสำเนาหลักฐานดิจิทัล ( forensic Image ) แล้วพบว่า ในหลักฐานมีการเข้าBitLockerไว้ ไม่มี recovery Key  ก็มีคำแนะนำว่าให้ทำการ ทำสำเนาเก็บไว้ก่อนแล้ว ค่อยไปขอ key และ รหัสผ่านจากผู้ต้องสงสัยทีหลัง  หรือทำการกู้คืน forensic Image ลงบน  Harddisk SSD ใหม่แทน และสลับเปลี่ยน SSD ของแล็ปท็อปด้วยไดรฟ์โคลน แล้วนำรหัสผ่าน Windows และรหัสBitLocker  ที่ได้จากผู้ต้องสงสัย Login แล็ปท็อป จากนั้นทำการ Export recovery Key ออกมา แล้วนำ Key  ที่ได้ไปใส่ในเครื่อง  Forensic workstation ที่กำลังวิเคราะห์หลักฐานและถอดรหัสได้อย่างสมบูรณ์

 


 ณ จุดนี้เนื่องจากคุณมีสำเนาหลักฐานดิจิทัล forensic Image  file อยู่แล้วคุณจึงไม่ต้องยุ่งกับหลักฐานต้นฉบับบน SSD ของแล็ปท็อปเว้นแต่ว่าจำเป็นจริงๆ คุณสามารถรับ BitLocker PIN และรหัสผ่าน Windows จากผู้ต้องสงสัยของคุณได้ ขั้นตอนการทำงานของคุณดังต่อไปนี้:

1. การกู้คืนอิมเมจทางนิติวิทยาศาสตร์ใส่ในฮาร์ดดิสก์ SSD ใหม่ ("ไดรฟ์โคลน")

2. การเปลี่ยน SSD ของแล็ปท็อปด้วยไดรฟ์โคลน


3. การบูตแล็ปท็อปป้อน PIN และรหัสผ่าน Windows

4. การแยกคีย์การกู้คืน BitLocker

5. การลบ BitLocker ออกจากภาพทางนิติวิทยาศาสตร์บนเวิร์กสเตชันทางนิติวิทยาศาสตร์

6. เริ่มต้นการวิเคราะห์ของคุณจากภาพทางนิติวิทยาศาสตร์ที่ถอดรหัสอย่างสมบูรณ์

(1) นอกจากนี้ยังมีความเป็นไปได้ซึ่งรวมถึงคีย์การกู้คืน BitLocker ที่ผู้ใช้จัดเก็บไว้ในอุปกรณ์จัดเก็บข้อมูลแบบถอดได้หรือสำเนาหลักฐานดิจิทัล ( forensic Image ) หรือจัดเก็บไว้ในบัญชีออนไลน์ของ Microsoft

เปรียบเทียบค่า hash ของ Disk Image  ที่เข้ารหัสโดย BitLocker

Credit:bitlocker-for-dfir-part-iii

           How to Enable BitLocker

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics #digitalforensics #investigation #cybercrime #fraud

 

Friday, September 11, 2020

Digital Forensics: How to Forensics image with CAINE Live USB/DVD Linux bootable

Digital Forensics: How to Forensics image  with CAINE Live USB/DVD


CAINE (Computer Aided Investigative Environment) is an Italian GNU/Linux live distribution created as a Digital Forensics project.

CAINE 11 - GNU/Linux Live Distribution For Digital Forensics Project, Windows Side Forensics And Incident Response 

CAINE 11.0 "Wormhole" 64bit - Official CAINE GNU/Linux distro latest release. 

The important news is that CAINE 11.0, 10.0, 9.0, 8.0 and 7.0 block all the block devices (e.g. /dev/sda), in Read-Only mode. You can use a tool with a GUI named UnBlock present on Caine's Desktop.

This new write-blocking method assures all disks are really preserved from accidentally writing operations, because they are locked in Read-Only mode.

By: https://www.caine-live.net


Tools

- CAINE 11 Live USB/DVD

-Kingston data Traveler_3.0  15.5 GB  (Evidence)

-Laptop Workstation 


After CAINE boots, choose the "Boot Live system". If all goes well, the following desktop should appear:

หลังจาก Boot ด้วย CAINE

CAINE  can boot on Uefi/Uefi+secure boot/Legacy Bios/Bios.

CAINE  can boot to RAM




CAINE has a utility called Mounter, which is located in the task bar. It's the tiny icon circled above. Double clicking this icon brings up a dialog box that shows which block devices are currently mounted:

From the CAINE website documentation:

This new write-blocking method assures all disks are really preserved from accidentally writing operations, because they are locked in Read-Only mode.
If you need to write a disk, you can unlock it with BlockOn/Off or using "Mounter" changing the policy in writable mode. 

1. เราจะทำ Forensic image  /dev/sdb1  evidence  สถานะ Read-only

   sdb Read-Only disk

การเขียนข้อมูลลง External HDD ที่เป็นระบบ NTFS ต้องทำการเขียนคำสั่ง - #sudo ntfs-3g -o rw /dev/sda4 /media/sda4

2.จะทำการ สร้าง Folder CF010 และเก็บไฟล์ CF010.e01 ไว้ที่ /dev/sda4  สถานะ Writable  /Media/sda4/CF010

3 Check Timezone and Date time Setting

4.ตั้งชื่อ Case Number ,Evidence number   CF010.e01

5.เปิดโปรแกรม Guymager เลือก  Forensic image  /dev/sdb  Kingston data Traveler_3.0  15.5 GB 

just start GuyMager (which is the imaging software we will use). A link to Guymager is on the main desktop.

The guymager main screen shows four disks. In our case disk WDC_WDS500G2B0A is the internal HDD (/dev/sda) and the Kingston data Traveler_3.0  is the Flash Drive. The third drive (linux loop) is the memory space CAINE uses to run the live USB/DVD.
Guymager supports two formats: Linux dd raw image and Expert Witness Format. Newer version of guymager also support the advanced forensic image format (AFF). Only DD and EWF support splitting the image onto subfile. This is recommended, as handling files larger than 4GB can be difficult on some filesystems (FAT). In this case we use EWF that support built-in metadata. EWF is a well supported format in most forensic packages (EnCase, Autopsy…etc).
this should be the location where the external hard drive is available. This is typically /media/root/<DISKNAME>. In this particular case, image verification is selected (which will make sure no errors have taken place during the capture).Select start 

6.เมื่อเสร็จ จะได้   CF010.e01

7.นำ Forensic image file  CF010.e01 ทำการวิเคราะห์ไฟล์โดยใช้ Autopsy 

A new page will open. Enter the details in ‘Case Name’ and ‘Base Directory’ . Then click on next to proceed to next step. 

Here in next step you have to enter the case number and Examiner details and click on finish to proceed to next step.
A new window will open .It will ask for add data source in Step 1. Select source type to add & browse the file Path (Disk Image and click on NEXT Option to proceed further.
In Step .  Configure ingest Modules I have chosen all the modules as I am looking for complete information on evidence device or disk or system  etc. and click next to proceed further.
After Process completion, it will show Forensic Investigation Report.


สรุป 

   1. การใช้ CAINE 11 จะป้องการเขียนข้อมูลลงหลักฐาน โดยจะใช้ Read-Only mode.   หากจะเขียนข้อมูลลง  Disk ต้องเปลี่ยน  writable mode ก่อน  (Unblock)

    2.  การเขียนข้อมูลลง External HDD ที่เป็นระบบ NTFS ต้องทำการเขียนคำสั่ง - #sudo ntfs-3g -o rw /dev/sda1 /media/sda1

If the user wants to mount and write on an NTFS media should instead use the "ntfs-3g" command (e.g., $ sudo ntfs-3g -o rw /dev/sda1 /media/sda1).

sudo ntfs-3g -o rw /device-path /your-mount-point

     3.ถ้าไม่สามารถ  boot USB ได้ให้ลองปิด  disable  UEFI (   If secureboot failed, try to disable it from UEFI.)

    4. สามารถใช้  guymager  ในการทำ Imager 

   5. ตรวจสอบ วันเวลา Time setting


Cerdit:

 https://www.caine-live.net

https://www.dfir.vn

http://az4n6.blogspot.com

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น


* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics

#digitalforensics #investigation 

Monday, August 31, 2020

Digital Forensics:Case study Forensic Acquisition

Digital Forensics:Case Study Forensic Acquisition 


วันนี้ได้ทำการทดสอบ กระบวนการได้มาซึ่งหลักฐานดิจิทัล  ในการเตรียมอุปกรณ์สำหรับการสำเนาหลักฐานอุปกรณ์เก็บข้อมูลแบบ SSD PCIe  ในเครื่อง Notebook รุ่นใหม่
(เนื่องจากบทความนี้ทำพอสังเขป และใช้ภาพจาก Internet เป็นตัวอย่างประกอบ อาจจะข้ามขั้นตอนบางส่วนไป จึงขออภัยมา ณ ที่นี้ด้วย)

การเก็บหลักฐานเป็นไฟล์ Disk Image (Image Acquisition)

โดยทั่วไปการได้มาของไฟล์ Disk Image จะดำเนินการในห้องปฏิบัติการทางนิติดิจิทัลโดยผู้เชี่ยวชาญที่ผ่านการฝึกอบรมและได้รับการรับรองว่าได้รับไฟล์ Disk Imageจากอุปกรณ์คอมพิวเตอร์บางประเภท (เช่นโทรศัพท์มือถือแล็ปท็อปหรือแท็บเล็ต)

สมมติว่าในขณะที่คอมพิวเตอร์ปิดอยู่ผู้ตรวจสอบควรเริ่มต้นด้วยขั้นตอนดังนี้:

•ตรวจสอบหลักฐานทางกายภาพ(physical evidence)และเบิกออกจากที่เก็บหลักฐานตามขั้นเอกสารหลักฐาน (chain of custody)
•เมื่อเอาซีลที่วางอยู่บนช่องเปิดของเคสคอมพิวเตอร์ สิ่งนี้ควรได้รับการบันทึกไว้ในสมุดบันทึกของผู้ตรวจสอบ
•ถอดอุปกรณ์จัดเก็บข้อมูล จากนั้นอุปกรณ์จัดเก็บข้อมูลสามารถเชื่อมต่อกับคอมพิวเตอร์นิติดิจิทัล (forensic workstation)โดยเฉพาะโดยมีตัวบล็อกการเขียน(write blocker)ติดอยู่กับดิสก์  ในหลาย ๆ กรณีอาจทำได้โดยไม่ต้องรีสตาร์ทคอมพิวเตอร์
•การสร้างภาพดิสก์ (Image Acquisition) จะอาศัยซอฟต์แวร์ที่ติดตั้งบนคอมพิวเตอร์  (forensic workstation)หรือผู้ตรวจสอบสามารถติดตั้งตัวบล็อกการเขียน(write blocker) และที่เก็บข้อมูลเพิ่มเติมที่จะเก็บภาพไว้ล่วงหน้า
•บูตคอมพิวเตอร์ด้วยดิสก์สำหรับบูตทางนิติดิจิทัล Bootable Live USB forensics tools

สิ่งที่ต้องเตรียมการสำเนาหลักฐานดิจิทัล

  1. ศึกษารายละเอียดของ Notebook Model แต่ละรุ่น https://support.lenovo.com และวิธีการถอดอุปกรณ์
  2. เตรียมอุปกรณ์สำหรับรองรับการเชื่อมต่อ Harddisk ssd M.2 ,PCle 
  3. ชุดเครื่องมืออุปกรณ์ 
  4. กล้องดิจิทัลและตั้งค่าเวลาเป็นปัจจุบน
  5. กล่องหรือพลาสติกกันกระแทก สำหรับบรรจุหลักฐาน
  6. ถุงพลาสติกสำหรับใส่หลักฐาน 
  7. Label สำหรับเขียนรายละเอียดหลักฐาน

ชุดเครื่องมือ(Hardware Tools) 

ขั้นตอนการเตรียมการสำเนาหลักฐานดิจิทัล

Check list
1. Evidence คือเครื่อง Notebook  (Notebook Lenovo )  เปิดเครื่องและกด Enter Setup เพื่อเข้า Bios >Power (ควรจดรายละเอียด ของหลักฐานเช่นรอยแตก รอยขีดข่วน สถานะเครื่องก่อนตรวจสอบ และถ่ายรูปไว้)
ควรดูคู่มือวิธีการกดปุ่มเข้า Bios ทุกครั้ง ก่อนเปิดเครื่อง
2. ทำการถ่ายรูป BIOS version , System Date &Time and Disk Storage  ตรวจสอบกล้องถ่ายรูปว่ามีการตั้งค่าเวลาเป็นปัจจุบัน


3. ทำการ Disable Battery เพื่อป้องกันการเสียหายจากกระแสไฟขณะที่ถอด HDD  

 
Disable Battery
3.1  Disconnect Battery ถอดขั้วต่อแบตเตอรี่ออกจากแผงวงจรหลักโดยดึงขั้วต่อเข้าหาแบตเตอรี่  หากไม่ได้ปิดใน Bios ภาพตัวอย่าง


4. ถอด Harddsik SSD adapter PCIe m.2 ,NVME
สังเกต Solid State Disk


* สังเกตว่ามี HDD .ในเครื่อง notebook  มี  1 หรือ  2 ตัว

ภาพตัวอย่าง เครื่อง notebook  มี  HDD 2 ตัว  
ภาพตัวอย่าง เครื่อง notebook  มี  HDD 2 ตัว  
ภาพตัวอย่าง เครื่อง notebook  มี  HDD 2 ตัว  


5. เตรียมออุปกรณ์ สำรองไฟ UPS  เพื่อใช้สำหรับต่อกับเครื่องทำ disk image
6.เตรียม  Hardware Write blocker  >Tableau PCIe M.2 SSD Adapter  เชื่อมต่อ SSD Harddsik 
Tableau PCIe M.2 SSD Adapter
* ใช้อุปกรณ์รองรับ SSD เชื่อมต่อกับอุปกรณ์ writer blocker
Check Status OK
- Hard disk storage (forensic Image file)
7. เริ่มทำ  Forensic Image - Forensics workstation install FTK Imager or Forensic acquisition tools
Create Image
7.1 หลังจากทำสำเนาหลักฐานเสร็จแล้วให้ทำการเปิด Forensic Image เพื่อตรวจสอบความครบถ้วนสมบูรณ์  เนื่องจากหาก Forensic Image  ไม่สมบูรณ์หรือเปิดไม่ได้ เราสามารถทำใหม่อีกครั้งได้ ก่อนเก็บหลักฐาน  ให้ทำการสำเนาหลักฐานไว้ 2 ชุดเพื่อป้องกันความเสียหาย

8.    ถ่ายรูป อุปกรณ์หลักฐาน และ Update Process
 Check list >Computer Bios Time ,Clock
- Chain of Custody Form


- Hardware Tools

- Label
9. เมื่อเสร็จเรียบร้อย ให้ทำการใส่อุปกรณ์ และประกอบ  Notebook ให้เหมือนเดิมและ  ทำการ Enable Battery เพื่อให้เครื่องทำงานตามปกติ  ตรวจสอบร่องรอยต่างๆ ว่ามีการแตกหักหรือชำรุดใดๆหรือไม่  และจดบันทึก  

 
Enable Battery
9.1 ถ่ายรูปหลักฐานอีกครั้งก่อนส่งคืน ไปห้องเก็บหลักฐาน



10.  ส่งหลักฐานไปห้องเก็บหลักฐาน เพื่อดำเนินการต่อไป
Evidence Room


ปัญหาที่พบ
 1. การกดเข้า Bios
     เช่น กด F1 , Del ,F11, F8 ,Enter แต่ละรุ่นไม่เหมือนกัน ควรศึกษาก่อนทำจากคู่มือก่อนทำ
 2. การปิด-เปิด แบตเตอรี่ใน Bios
Disable Battery
* เมื่อทำสำเนาเสร็จ ให้ทำการใส่ Hard Disk เข้าที่ Notebook และทำการ Enable Battery  ใน Bios
 3. ศึกษาการถอดประกอบเครื่อง Notebook จะได้ทราบตำแหน่งของอุปกรณ์ และ ชนิดของอุปกรณ์
 4.  หากไม่สามารถแกะหลักฐานออกมาได้ ให้ใช้วิธีการ boot ผ่าน อุปกรณ์ USB bootable forensic tools

ข้อควรปฎิบัติทั่วไปในการเก็บหลักฐาน 

   ไม่ควรทำให้เกิดการเปลี่ยนแปลงของหลักฐานในขั้นตอนการเก็บ เนื่องจากอาจทำให้กระทบต่อขั้นตอนการวิเคราะห์หลักฐานได้ 

 เพิ่มเติม:  ในกรณีที่ผิดพลาด ระบบ boot เข้า windows ให้ทำการบันทึก รายละเอียดและวันเวลาและสาเหตุที่เกิดผิดพลาด

ThinkPad - Solid State Drive Replacement


How to Turn off Lenovo ThinkPad T470 / T570 Internal Battery


Refer:


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud #DataRecovery

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...