Showing posts with label GUYMAGER. Show all posts
Showing posts with label GUYMAGER. Show all posts

Friday, September 11, 2020

Digital Forensics: How to Forensics image with CAINE Live USB/DVD Linux bootable

Digital Forensics: How to Forensics image  with CAINE Live USB/DVD


CAINE (Computer Aided Investigative Environment) is an Italian GNU/Linux live distribution created as a Digital Forensics project.

CAINE 11 - GNU/Linux Live Distribution For Digital Forensics Project, Windows Side Forensics And Incident Response 

CAINE 11.0 "Wormhole" 64bit - Official CAINE GNU/Linux distro latest release. 

The important news is that CAINE 11.0, 10.0, 9.0, 8.0 and 7.0 block all the block devices (e.g. /dev/sda), in Read-Only mode. You can use a tool with a GUI named UnBlock present on Caine's Desktop.

This new write-blocking method assures all disks are really preserved from accidentally writing operations, because they are locked in Read-Only mode.

By: https://www.caine-live.net


Tools

- CAINE 11 Live USB/DVD

-Kingston data Traveler_3.0  15.5 GB  (Evidence)

-Laptop Workstation 


After CAINE boots, choose the "Boot Live system". If all goes well, the following desktop should appear:

หลังจาก Boot ด้วย CAINE

CAINE  can boot on Uefi/Uefi+secure boot/Legacy Bios/Bios.

CAINE  can boot to RAM




CAINE has a utility called Mounter, which is located in the task bar. It's the tiny icon circled above. Double clicking this icon brings up a dialog box that shows which block devices are currently mounted:

From the CAINE website documentation:

This new write-blocking method assures all disks are really preserved from accidentally writing operations, because they are locked in Read-Only mode.
If you need to write a disk, you can unlock it with BlockOn/Off or using "Mounter" changing the policy in writable mode. 

1. เราจะทำ Forensic image  /dev/sdb1  evidence  สถานะ Read-only

   sdb Read-Only disk

การเขียนข้อมูลลง External HDD ที่เป็นระบบ NTFS ต้องทำการเขียนคำสั่ง - #sudo ntfs-3g -o rw /dev/sda4 /media/sda4

2.จะทำการ สร้าง Folder CF010 และเก็บไฟล์ CF010.e01 ไว้ที่ /dev/sda4  สถานะ Writable  /Media/sda4/CF010

3 Check Timezone and Date time Setting

4.ตั้งชื่อ Case Number ,Evidence number   CF010.e01

5.เปิดโปรแกรม Guymager เลือก  Forensic image  /dev/sdb  Kingston data Traveler_3.0  15.5 GB 

just start GuyMager (which is the imaging software we will use). A link to Guymager is on the main desktop.

The guymager main screen shows four disks. In our case disk WDC_WDS500G2B0A is the internal HDD (/dev/sda) and the Kingston data Traveler_3.0  is the Flash Drive. The third drive (linux loop) is the memory space CAINE uses to run the live USB/DVD.
Guymager supports two formats: Linux dd raw image and Expert Witness Format. Newer version of guymager also support the advanced forensic image format (AFF). Only DD and EWF support splitting the image onto subfile. This is recommended, as handling files larger than 4GB can be difficult on some filesystems (FAT). In this case we use EWF that support built-in metadata. EWF is a well supported format in most forensic packages (EnCase, Autopsy…etc).
this should be the location where the external hard drive is available. This is typically /media/root/<DISKNAME>. In this particular case, image verification is selected (which will make sure no errors have taken place during the capture).Select start 

6.เมื่อเสร็จ จะได้   CF010.e01

7.นำ Forensic image file  CF010.e01 ทำการวิเคราะห์ไฟล์โดยใช้ Autopsy 

A new page will open. Enter the details in ‘Case Name’ and ‘Base Directory’ . Then click on next to proceed to next step. 

Here in next step you have to enter the case number and Examiner details and click on finish to proceed to next step.
A new window will open .It will ask for add data source in Step 1. Select source type to add & browse the file Path (Disk Image and click on NEXT Option to proceed further.
In Step .  Configure ingest Modules I have chosen all the modules as I am looking for complete information on evidence device or disk or system  etc. and click next to proceed further.
After Process completion, it will show Forensic Investigation Report.


สรุป 

   1. การใช้ CAINE 11 จะป้องการเขียนข้อมูลลงหลักฐาน โดยจะใช้ Read-Only mode.   หากจะเขียนข้อมูลลง  Disk ต้องเปลี่ยน  writable mode ก่อน  (Unblock)

    2.  การเขียนข้อมูลลง External HDD ที่เป็นระบบ NTFS ต้องทำการเขียนคำสั่ง - #sudo ntfs-3g -o rw /dev/sda1 /media/sda1

If the user wants to mount and write on an NTFS media should instead use the "ntfs-3g" command (e.g., $ sudo ntfs-3g -o rw /dev/sda1 /media/sda1).

sudo ntfs-3g -o rw /device-path /your-mount-point

     3.ถ้าไม่สามารถ  boot USB ได้ให้ลองปิด  disable  UEFI (   If secureboot failed, try to disable it from UEFI.)

    4. สามารถใช้  guymager  ในการทำ Imager 

   5. ตรวจสอบ วันเวลา Time setting


Cerdit:

 https://www.caine-live.net

https://www.dfir.vn

http://az4n6.blogspot.com

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น


* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics

#digitalforensics #investigation 

Saturday, June 8, 2019

Digital Forensics : Acquisition in Kali Linux - Guymager

Digital Forensics : Acquisition in Kali Linux - Guymager


       เตรียม อุปกรณ์และ ทดสอบ Acquisition Tool On site step by step


1. Notebook Kingston 120 GB   (Evidence)
2. Kali Linux  USB Boot (SanDisk Extreme USB 3.0 32 GB
3. Guymager 0.8.8
4. Western SATA HDD 4 TB  (forensics Image)
5. External box  (Orico)
6. Clock & Camera


เตรียมติดตั้ง Kali Linux  บน Flash Drive  SanDisk Extreme USB 3.0  32 GB
SanDisk Extreme USB 3.0
กด Esc ทำการเข้า BIOS ทำการเลือก  Boot Option Menu   
F9 Boot Option
เลือก USB Hard Drive (UEFI)
USB Hard Drive (UEFI)
เลือก Kali Linux Forensics Mode  เพื่อป้องกันการเขียนทับข้อมูลบนหลักฐานดิจิทัล

Kali Linux Forensics Mode

Acquisition in Kali Linux 


เตรียม  HDD format  FAT32 ,exFAT  สำหรับเก็บ forensics Image file  รองรับ Linux  เพราะ Kali ทำงานบน Linux
HDD 4 TB
Mount Disk สำหรับเก็บสำเนาหลักฐาน
Mount Disk :  Forensics Image

ตรวจสอบ  Hard disk ที่เชื่อมต่อ แสดงครบหรือไม่ พร้อมจดรายละเอียด และถ่ายรูป

 เปิดโปรแกรม GUYMAGER เลือก  KINGSTON 120 GB   (EVIDENCE)  ใช้คำสั่ง  ACQUIRE IMAGE

เลือก path  ที่เก็บ forensics Image file   ตั้งชื่อที่เก็บ Forensics Image and Check box : Hash

ใช้คำสั่ง  ACQUIRE IMAGE


Forensics Image file Location


ก่อนทำให้ทำการ กำหนดค่า  Automatic Screen look >  Off
Automatic Screen look >  Off
Blank Screen > Never
Blank Screen > Never
  • Check Re-read source after acquisition for verification (Takes twice as long)
  • Verify image after acquisition (Takes twice as long)  
Source verification  on 
Image verification  on 

Start 

Finished-Verified OK

Complete 

 ตรวจสอบวันเวลา (Data Time ) เมื่อทำเสร็จ และ Path  จะปรากฎไฟล์ Forensic Image นามสกุล *.E01 
 ตรวจสอบ Forensic Image *.E01
 ตรวจสอบ Report .Info  แสดงรายละเอียด Forensic Image ,ค่า Hash MD5,SHA1    
 ทำแบบเดียวกันอีกครั้ง เพื่อดูว่าค่า Hash เปลี่ยนแปลงหรือไม่

 Forensics Report  *.Info  & Hash Compare
ทำการ Mount Image File เพื่อตรวจสอบว่าใช้งานได้หรือไม่  ก่อนเก็บหลักฐาน (seizure )

Digital Forensics with Kali Linux : Introduction to Forensic Imaging


Forensic Acquisition in Linux - Guymager



สรุป:Kali Linux ในการทำสำเนาหนักฐาน
  •  จำเป็นต้องตรวจสอบค่าวันเวลา
  • เตรียม  HDD format  FAT32 ,exFAT   ที่รองรับ Linux  สำหรับเก็บ Image file


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud 

Saturday, May 18, 2019

Digital Forensics: GUYMAGER Acquisition Tool II

Digital Forensics: GUYMAGER Acquisition Tool II


       เตรียม อุปกรณ์และ ทดสอบก่อนไป Acquisition Tool On site step by step

1. Notebook Kingston 120 GB   (Evidence) 
2. Deft ZERO 2018 DVD Boot or USB Boot
3. Guymager 0.8.8
4. Western SATA HDD 4 TB  (forensics Image)
5. External box  (Orico)
6. Clock & Camera

ค้นหาว่า Notebook HP กดปุ่ม Esc + F9

กด Esc ทำการเข้า BIOS ทำการเลือก  Boot Option Menu   
DVD BOOT  DRIVE

ทำการ  Boot Deft ZERO  จาก DVD
Deft ZERO 2018
เลือก GUI Mode
DEFT GUI MODE

ตรวจสอบ  Hard disk ที่เชื่อมต่อ แสดงครบหรือไม่ พร้อมจดรายละเอียด และถ่ายรูป

Kingston 120 GB   (Evidence) 

 เปิดโปรแกรม GUYMAGER เลือก  Kingston 120 GB   (Evidence)  ใช้คำสั่ง  Acquire Image

ACQUIRE IMAGE Guymager 0.8.8

เลือก path  ที่เก็บ forensics Image file
 forensics Image file Location
เตรียม  HDD format  FAT32 ,exFAT  สำหรับเก็บ forensics Image file  รองรับ Linux  เพราะ Deft  ทำงานบน Linux
HDD 4 TB


 ตรวจสอบวันเวลา (Data Time ) เมื่อทำเสร็จ และ Path
Finished-Verified OK

ตรวจสอบ Forensic Image *.E01
Forensic Image File   *.E01 
 ตรวจสอบ Report .Info  แสดงรายละเอียด Forensic Image , Flash Drive ,ค่า Hash MD5,SHA1   ก่อนปิดเครื่อง 

GUYMAGER ACQUISITION INFO FILE
==============================

Guymager
========

Version              : 0.8.8-1                                                                       
Compilation timestamp: 2018-01-24-14.41.10                                                           
Compiled with        : gcc 4.9.2                                                                     
libewf version       : 20140608 (not used as Guymager is configured to use its own EWF module)       
libguytools version  : 2.1.0beta5                                                                    
Host name            : DeftZ                                                                         
Domain name          : (none)                                                                        

System               : Linux DeftZ 4.4.0-53-generic #74~14.04.1 SMP Tue Dec 20 14:33:58 CET 2016 i686

 Forensics Report  *.Info  
 GUYMAGER ACQUISITION INFO FILE
GUYMAGER ACQUISITION INFO FILE
ทำการ Mount Image File เพื่อตรวจสอบว่าใช้งานได้หรือไม่
Mount Image To Drive

 ทำแบบเดียวกันอีกครั้ง เพื่อดูว่าค่า Hash เปลี่ยนแปลงหรือไม่

Hash Compare

สิ่งที่ต้องตรวจสอบก่อนการทำสำเนาหลักฐาน
  - การเตรียมอุปกรณ์สำรองไฟ  UPS
  - ในกรณี เครื่องคอมพิวเตอร์ที่จะทำสำเนาหลักฐาน มีการต่อพ่วง Harddisk  หลายลูก ให้ตรวจสอบกำลัง power supply (PSU)  เพียงพอหรือไม่
  - ตรวจสอบลำดับ  boot  ถ้าMainboard ที่รองรับ UEFI  กรณี  USB boot หากไม่แน่ใจให้ถอด สายไฟเชื่อมต่อ HDD ออกก่อน จนแน่ใจว่าตั้งค่าถูกต้อง ค่อยเสียบสายเหมือนเดิม


https://bit.ly/2OHjY5i 

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud 

Tuesday, April 30, 2019

Digital Forensics:Forensic Data Carving using Foremost

Digital Forensics:Forensic Data Carving using Foremost

 วันนี้ทำการตรวจสอบและกู้ข้อมูล(Data Recovery)หลักฐานจากเครื่อง Notebook asus  พบ  Harddisk ชนิด mSATA SSD

สิ่งที่ต้องเตรียม

 -  mSATA SSD
 -  External Box
 -  Deft  boot DVD
 -  Guymager
 -  Foremost on Kali linux
 -  FTK Imager
  

mSATA SSD จะมีขนาดเล็กกว่าแบบ SATA  ส่วนมากจะนำมาใช้อัพเกรด Notebook ในNotebook หลายๆรุ่นจะมีช่องให้ติดตั้งเพิ่มได้ ทำให้น้ำหนักเครื่องเบาขึ้น ปัจจุบันความนิยมของ SSD มากขึ้น

Notebook Main board
Slot mSATA SSD
Slot mSATA SSD
ทำการต่อ mSATA กับ External Box  เพื่อทำสำเนาข้อมูล
mSATA SSD

 หลังจากนั้นทำการต่ออุปกรณ์กับ forensic machine และทำการใช้  Deft  boot DVD เพื่อป้องกันการเขียนทับข้อมูล
 Deft Zero
DEFT
 เลือก DEFT-Zero Linux Live  เพื่อทำการสำเนาข้อมูล
Deft
ใช้ Guymager ทำการทำ Forensic Image หลักฐานที่อยู่ใน mSATA
Guymager

Guymager

Guymager

FTK Imager

Image File Report
Forensic Image file +  .info ที่ได้
Forensic Image File
ทำการ Mount image file เพื่อดูว่าไฟล์สำเนาหลักฐานสมบูรณ์หรือไม่

ทำการ Mount Image File
Output Report 
data-carving เป็นเทคนิคการค้นหาไฟล์จาก image ต่างๆไม่ว่าจะเป็น image ของ harddisk, memory, หรือ USB storage โดยการค้นหาดังกล่าวนี้จะอาศัยการค้นหา header ของประเภทของไฟล์ที่ต้องการหา ไม่ว่าจะเป็นไฟล์รูปภาพ (.gif, .jpg, .png) ไฟล์เสียง (.mp3, .wav) หรือไฟล์วีดีโอต่างๆ (.avi) โดยหลังจากที่เจอ header ของไฟล์ดังกล่าวแล้ว ก็จะ extract ไฟล์ต่างๆออกมา

Foremost  คือ

 เป็นโปรแกรม command line บน linux เพื่อกู้คืนไฟล์ตามส่วนหัว header  ส่วนท้าย Footer และโครงสร้างภายในข้อมูล กระบวนการนี้มักเรียกกันว่าการ data carving สำคัญที่สุดสามารถทำงานกับ Forensic image files เช่นที่สร้างขึ้นโดย dd, Safeback, Encase ฯลฯ หรือโดยตรงบนไดรฟ์ ส่วนหัวและท้าย ของไฟล์ สามารถระบุได้โดย  กำหนดค่า Config หรือ คุณสามารถใช้ Command line เพื่อระบุประเภทไฟล์ได้  เพื่อให้การกู้ข้อมูลได้รวดเร็วยิ่งขึ้น

 เราทำการใช้โปรแกรม Foremost  เพื่อหาข้อมูลในหลักฐานที่ได้สำเนาไว้แล้ว
Foremost
#foremost -t Jpeg,png,zip.pdf,avi -i CFFFESSD1.E02




Output File
Evidence File

สรุป การทดสอบ

    การใช้เทคนิค data-carving เป็นเทคนิคการค้นหาไฟล์จาก (File  Signature ) ชนิดของไฟล์ข้อมูล โดย มีหลัก การทำงาน คือ การใช้การค้นหาข้อมูลที่เป็นเฮดเดอร์ (Header) และ ฟุตเตอร์   (Footer) ของไฟล์ชนิดต่างๆ ในการค้นหาตำแหน่งเริ่มต้นและสิ้นสุด ตลอดจนชนิดของไฟล์  ซึ่งก็จะทำให้สามารถกู้คืนข้อมูลในส่วนนี้คืนกลับมาได้ เหมาะกับ   ข้อมูลและ  Harddisk ที่ถูก Format  , MFT  ถูกทำลาย และถูกลบข้อมูล แต่ข้อมูลที่กู้มาได้จะไม่มีข้อมูลในส่วนของ Metadata และ Timestamp ของเดิมอยู่

ที่มา:
https://bit.ly/2GGz8lH
https://bit.ly/2I7wvdr
https://bit.ly/2CTp9GU
https://www.peerlyst.com/posts/how-to-perform-ssd-forensics-or-part-i-sudhendu?trk=search_page_search_result

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud #DataRecovery

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...