Showing posts with label Incident Response. Show all posts
Showing posts with label Incident Response. Show all posts

Friday, June 27, 2025

Digital Forensics:Incident Response Plan & Playbook

Digital Forensics:Incident Response Plan & Playbook

เนื่องด้วย แอดได้ข้อมูลจาก Meetup ประจำเดือนมิถุนายนของ 2600Thailand x OWASP ใน ปี 2025

เรื่อง Incident Response Plan & Playbook
โดยคุณ Setthawhut Saennam จาก MFEC Co., Ltd เมื่อวันศุกร์ ที่ 27 มิถุนายน 2568

Incident Response Plan & Playbook
Info by :Setthawhut Saennam 2600Thailand x OWASP

Info by :Setthawhut Saennam 



Digital Forensics:Incident Response Plan & Playbook
Info by :Setthawhut Saennam 


Digital Forensics:Incident Response Plan & Playbook
https://www.mdes.go.th/law/detail/5049
Info by :Setthawhut Saennam 

Digital Forensics:Incident Response Plan & Playbook
Info by :Setthawhut Saennam 

Digital Forensics:Incident Response Plan & Playbook
Info by :Setthawhut Saennam 

Digital Forensics:Incident Response Plan & Playbook
https://csrc.nist.gov/projects/incident-response
Info by :Setthawhut Saennam 


Digital Forensics:Incident Response Plan & Playbook
Info by :Setthawhut Saennam 

Detection and Response Roles Overview
Digital Forensics:Incident Response Plan & Playbook
Info by :Setthawhut Saennam 

Digital Forensics:Incident Response Plan & Playbook
https://www.mdes.go.th/law/detail/5049
Info by :Setthawhut Saennam 

DFIR Ransomware Cyber Extortion
Digital Forensics:Incident Response Plan & Playbook
https://www.sans.org/posters/ransomware-and-cyber-extortion/
Info by :Setthawhut Saennam  

Digital Forensics:Incident Response Plan & Playbook
https://www.cisa.gov/resources-tools/resources/federal-government-cybersecurity-incident-and-vulnerability-response-playbooks
Info by :Setthawhut Saennam

Incident Response vs Digital Forensics

  • Incident Response (IR)is immediateandaimed at stopping threats and reducing impact during an incident to resume normal business operations.
  • Digital Forensics (DF)is about precision—collecting, preserving, and analyzing evidence for legal or potential legal matters (civil or criminal).
Digital Forensics:Incident Response Plan & Playbook
https://brettshavers.com/brett-s-blog/entry/should-df-be-separated-from-ir-1
Info by :Setthawhut Saennam

Incident Response vs Digital Forensics

Aspect  Incident Response (IR)  Digital Forensics (DF)
Primary Objective 
(วัตถุประสงค์หลัก)
Manage and mitigate security incidents
(จัดการและบรรเทาเหตุการณ์ที่เกี่ยวข้องกับความปลอดภัย) 
Collect, preserve, and analyze digital evidence
End Goal Contain and recover from attacks quickly
(ควบคุมและกู้คืนจากการโจมตีอย่างรวดเร็ว )
Provide evidence for legal proceedings
(จัดเตรียมหลักฐานสำหรับกระบวนการทางกฎหมาย)
Role Focus Incident responder or analyst 
(ผู้ตอบสนองเหตุการณ์หรือผู้วิเคราะห์)
 Examiner or analyst
 (ผู้ตรวจสอบหรือผู้วิเคราะห์)
Evidence Handling 
(การจัดการหลักฐาน)
Focused on system recovery and containment
(เน้นการกู้คืนและควบคุมระบบ)
Strict chain of custody and preservation
(ห่วงโซ่การควบคุมและการเก็บรักษาที่เข้มงวด)
Legal Standards 
(มาตรฐานทางกฎหมาย)
 May not meet legal standards unless specified
(อาจไม่เป็นไปตามมาตรฐานทางกฎหมาย เว้นแต่จะระบุไว้)
Meets courtroom admissibility standards
 (เป็นไปตามมาตรฐานการรับฟังความคิดเห็นของศาล)
Time Sensitivity Highly time-sensitive for operational recovery
(มีความอ่อนไหวต่อเวลาสูงสำหรับการกู้คืนการดำเนินงาน)
Not as time-sensitive unless court deadlines
(ไม่อ่อนไหวต่อเวลามากนัก เว้นแต่จะถึงกำหนดเส้นตายของศาล)
Typical Context Cybersecurity incidents, breaches, and intrusions (เหตุการณ์ด้านความปลอดภัยทางไซเบอร์ การละเมิด และการบุกรุก) Criminal, civil, or regulatory investigations
(การสอบสวนทางอาญา ทางแพ่ง หรือทางกฎระเบียบ)
Use of Tools Uses similar tools for rapid analysis
(ใช้เครื่องมือที่คล้ายกันสำหรับการวิเคราะห์อย่างรวดเร็ว)
Uses forensic tools for evidence extraction
(ใช้เครื่องมือทางนิติเวชสำหรับการสกัดหลักฐาน)
Training Emphasis Emphasizes quick action and recovery
(เน้นการดำเนินการอย่างรวดเร็วและการฟื้นตัว)
Emphasizes legal procedures and evidence integrity (เน้นขั้นตอนทางกฎหมายและความสมบูรณ์ของหลักฐาน)
 Mindset  Operational and urgent
(ปฏิบัติการและเร่งด่วน)
 Legal and methodical
 (กฎหมายและระเบียบวิธี)
 Reporting Reports focus on recovery steps and impact for business
(รายงานเน้นที่ขั้นตอนการฟื้นฟูและผลกระทบต่อธุรกิจ)
Detailed and legally sound reports for legal proceedings (รายงานรายละเอียดและถูกต้องตามกฎหมายสำหรับการดำเนินคดีทางกฎหมาย)
https://brettshavers.com/brett-s-blog/entry/should-df-be-separated-from-ir-1

อ่านเพิ่มเติม


ขออนุญาติแชร์บางส่วนครับ

แอดขอขอบคุณ Setthawhut Saennam(คุณต้า)จาก MFEC Co., Ltd. ผู้ให้ข้อมูลดีๆและมีประโยชน์ต่อชาว Security  เสมอมาครับ 

Download Incident Response Plan & Playbook

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD

Tuesday, March 21, 2023

DIGITAL FORENSICS:Magnet RESPONSE Free Tools

DIGITAL FORENSICS:Magnet RESPONSE Free Tools

    วันนี้แอดจะมาแนะนำโปรแกรม Magnet RESPONSE เครื่องมือฟรี ของบริษํท MAGNET FORENSICS สำหรับรวบรวมและเก็บรักษาข้อมูล ในเครื่องคอมพิวเตอร์อย่างรวดเร็วก่อนที่จะถูกแก้ไขหรือสูญหาย สามารถกำหนดเป้าหมายไฟล์และข้อมูลที่ครอบคลุมซึ่งเกี่ยวข้องกับการตรวจสอบการตอบสนองต่อเหตุการณ์ รวมถึง RAM

Download Magnet RESPONSE here.

DIGITAL FORENSICS:Magnet RESPONSE Free Tools

Magnet Response Configuration
DIGITAL FORENSICS:Magnet RESPONSE Free Tools

DIGITAL FORENSICS:Magnet RESPONSE Free Tools

Key Benefits & Features
  • Easy To Use: ใช้งานง่าย  ผู้ใช้ที่ไม่มีความรู้ทางด้านเทคนิค ก็สามารถใช้เครื่องมือได้
  • Portable:พกพาได้: ไฟล์เรียกทำงานเพียงไฟล์เดียว (น้อยกว่า 1MB)  สามารถดาวน์โหลดได้ง่าย และสามารถจัดเก็บและเรียกใช้จาก  USB Drive
  • Outputเอาต์พุตถูกรวมและบันทึกเป็นไฟล์ .zip เพื่อการส่งที่ง่าย หรือสำหรับการประมวลผลและการวิเคราะห์ใน Magnet AXIOM & Magnet AXIOM Cyber
  • Data Integrity:มีการระบุค่าแฮชที่ฝังไว้เพื่อตรวจสอบความสมบูรณ์ของข้อมูล

Output: Log.txt
              Ramdump.dmp
              .zip file
DIGITAL FORENSICS:Magnet RESPONSE Free Tools

ท่านสามารถนำไฟ์ล์ที่ได้ มาเปิดด้วย โปรแกรม   Magnet AXIOM & Magnet AXIOM Cyber (Commercial software)  และวิเคราะห์หาหลักฐานเพิ่มเติม ดังตัวอย่าง

ใช้โปรแกรม Magnet AXIOM Process 5.0
DIGITAL FORENSICS:Magnet RESPONSE Free Tools
Analyze Evidence > Ramdump.dmp

Analyze Evidence > 2023.03.20_10.56.17.zip 
DIGITAL FORENSICS:Magnet RESPONSE Free Tools

DIGITAL FORENSICS:Magnet RESPONSE Free Tools

DIGITAL FORENSICS:Magnet RESPONSE Free Tools
DIGITAL FORENSICS:Magnet RESPONSE Free Tools

DIGITAL FORENSICS:Magnet RESPONSE Free Tools


ท่านสามารถนำไฟล์ Ramdump.dmp  ไปวิเคราะห์ด้วยโปรแกรม Volatility framework และ PassMark Volatility Workbench ,MemProcFS

ท่านสามารถดูวิธีการใช้งานโปรแกรม Magnet RESPONSE 


อ้างอิง  magnetforensics 

อ่านเพิ่มเติม Magnet Forensics


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud #MagnetForensic

Friday, November 25, 2022

Digital Forensics:Incident Handling Cycle

Digital Forensics:Incident Handling Cycle

Digital Forensics:Incident Handling Cycle
Computer Security Incident Handling Guide NIST SP 800-61

ขั้นตอนที่ 1: การเตรียมการและป้องกันการเกิดภัยคุกคามทำงไซเบอร์

การดำเนินมาตรการเพื่อเตรียมการและป้องกันการเกิดภัยคุกคามทางไซเบอร์ (preparation)

เป็นสิ่งที่จะต้องทาในระยะเริ่มต้น เพื่อเตรียมความพร้อมเมื่อต้องเผชิญเหตุ ได้แก่ การจัดเตรียมข้อมูลให้พร้อมการจัดตั้งและฝึกอบรมบุคลากรหรือทีมงาน การจัดหาเครื่องมือและทรัพยากรต่าง ๆ ที่จ าเป็น การตั้งค่าระบบต่าง ๆให้ปลอดภัย การจัดทานโยบาย แผนงาน และกระบวนการที่เกี่ยวข้อง รวมถึงการสร้างเครือข่ายความร่วมมือ


ขั้นตอนที่ 2: กำรตรวจจับและวิเครำะห์ภัยคุกคำมทำงไซเบอร์

แม้ว่าหน่วยงานจะจัดให้มีมาตรการต่าง ๆ เพื่อป้องกันหรือควบคุมมิให้เกิดภัยคุกคามทางไซเบอร์

ขึ้นแล้วก็ตาม แต่หน่วยงานก็ยังคงต้องเตรียมความพร้อมอยู่เสมอเพื่อรับมือกับสถานการณ์ภัยคุกคามทางไซเบอร์ที่ไม่อาจหลีกเลี่ยงได้ การดาเนินมาตรการในการตรวจจับและวิเคราะห์ภัยคุกคามทางไซเบอร์

(detection and analysis) จึงเป็นสิ่งจำเป็นที่จะช่วยให้หน่วยงานสามารถบรรเทาความเสี่ยงที่ยังคงเหลืออยู่

และสามารถแจ้งเตือนได้อย่างทันท่วงทีเมื่อมีภัยคุกคามทางไซเบอร์เกิดขึ้น 


ขั้นตอนที่ 3: การระงับภัยคุกคามทำงไซเบอร์

1 ปราบปรำมภัยคุกคามทางไซเบอร์ 2 และการฟื้นฟูระบบงาน

ที่ได้รับผลกระทบเมื่อมีภัยคุกคามทางไซเบอร์เกิดขึ้นหรือเมื่อหน่วยงานได้รับแจ้งเตือนการเกิดภัยคุกคามทางไซเบอร์หน่วยงานควรกาหนดแนวทางการดาเนินมาตรการเพื่อระงับภัยคุกคามทางไซเบอร์ การปราบปรามภัยคุกคามทางไซเบอร์ และการฟื้นฟูระบบงานที่ได้รับผลกระทบ (containment, eradication, and recovery) โดยการดำเนินการดังกล่าว ควรกาหนดให้สอดคล้องกับความรุนแรงและระดับของภัยคุกคามทางไซเบอร์แต่ละระดับจนกระทั่งสามารถกู้คืนทรัพย์สินสาคัญทางสารสนเทศให้กลับมาดาเนินงานหรือให้บริการได้ตามปกติ การตรวจจับและวิเคราะห์ภัยคุกคามทางไซเบอร์ที่อาจมีการลุกลามหรือทวีความรุนแรงมากขึ้นเพื่อให้การระงับและการปราบปรามภัยคุกคามทางไซเบอร์ ตลอดจนการฟื้นฟูระบบงานที่ได้รับผลกระทบจากการเกิดภัยคุกคามทางไซเบอร์ สอดคล้องกับสถานการณ์ที่เปลี่ยนแปลงไป

ขั้นตอนที่ 4: กำรดำเนินการภายหลังกำรแก้ปัญหาภัยคุกคามทางไซเบอร์

การดำเนินกิจกรรมที่เกี่ยวข้องภายหลังการแก้ปัญหาภัยคุกคามทางไซเบอร์ (post-incident activity)นั้น หน่วยงานควรกำหนดขั้นตอน วิธีปฏิบัติ หรือกำหนดนโยบายภายในที่เกี่ยวข้องเพื่อให้มีแนวทางที่ชัดเจน  ซึ่งการปฏิบัติตามมาตรการดังกล่าว จะช่วยให้หน่วยงานสามารถเรียนรู้จากเหตุภัยคุกคามทางไซเบอร์ที่ผ่านมา และสามารถหาแนวทางเพื่อแก้ไขจุดบกพร่องและพัฒนาแนวทางรับมือกับภัยคุกคามทางไซเบอร์ต่อไปในอนาคต นอกจากนี้หน่วยงานต้องเก็บรักษาข้อมูลและพยานหลักฐานที่จำเป็น เพื่อใช้ในกระบวนการทางนิติวิทยาศาสตร์ หรือใช้ในกรณี

ที่ต้องการร้องทุกข์หรือดาเนินคดี เนื่องจากภัยคุกคามทางไซเบอร์ที่เกิดขึ้นนั้น อาจเข้าลักษณะเป็นความผิดตามประมวลกฎหมายอาญา หรือพระราชบัญญัติว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ พ.ศ. ๒๕๖๐และที่แก้ไขเพิ่มเติม (ถ้ามี) หรือกฎหมายอื่น ๆ ที่เกี่ยวข้อง (โดยการเก็บข้อมูลบางประเภทนั้นอาจจำเป็นต้องดาเนินการตั้งแต่เมื่อมีการตรวจพบว่ามีภัยคุกคามทางไซเบอร์เกิดขึ้น เนื่องจากข้อมูลดังกล่าวอาจสูญหายไปในระหว่างที่ต้องระงับเหตุภัยคุกคามทางไซเบอร์นั้น หรืออาจถูกลบหรือทำลายโดยผู้โจมตี)เมื่อมีการเก็บรวบรวมข้อมูลและหลักฐานที่จำเป็นตามวรรคหนึ่งแล้ว หน่วยงานควรนำข้อมูลและหลักฐานที่รวบรวมได้มาใช้ในการจัดทำบันทึกข้อมูลสถิติภัยคุกคามทางไซเบอร์ โดยอาจจัดทำเป็นรายสัปดาห์หรือรายเดือน เพื่อเสนอต่อผู้ที่มีหน้าที่ดูแลและรับผิดชอบภายในหน่วยงาน และกาหนดขั้นตอนที่หน่วยงานควรดำเนินการ เพื่อป้องกันไม่ให้เกิดภัยคุกคามทางไซเบอร์ในลักษณะดังกล่าวขึ้นอีกในอนาคต


นิยามศัพท์

การวางแผนบริหารความต่อเนื่อง (Business Continuity Planning : BCP) หมายถึง

กระบวนการในการสร้างระบบการทํางานเพื่อการป้องกันและฟื้นฟู จากภาวะคุกคามต่าง ๆ ที่ส่ง

ผลกระทบต่อธุรกิจ โดยการวางแผนนั้นต้องมั่นใจว่าบุคลากรรวมไปถึงทรัพยากรและสินทรัพย์ต่าง ๆ

จะได้รับการปกป้องเป็นอย่างดี และพร้อมใช้งานได้อย่างดีในทุก ๆ สถานการณ์


การจัดการภาวะวิกฤติ (Crisis Management) หมายถึง การจัดการในลักษณะที่

ลดความเสียหายให้น้อยที่สุดและช่วยให้องค์กรที่ได้รับผลกระทบสามารถฟื้นตัวได้อย่างรวดเร็ว

Traffi c Light Protocol (TLP) หมายถึง การจัดระดับชั้นความลับและความละเอียดอ่อนของ

ข่าวสารที่ใช้แบ่งปัน โดยมักแบ่งตามลําดับชั้นของสี


Web Defacement หมายถึง การโจมตีเว็บไซต์ที่เปลี่ยนรูปลักษณ์ของเว็บไซต์หรือหน้าเว็บ

ซึ่งเจาะเข้าไปในเว็บเซิร์ฟเวอร์และแทนที่เว็บไซต์ที่โฮสต์ด้วยเว็บไซต์ของตนเอง


อ้างอิงจาก


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD

Monday, November 21, 2022

Collecting Volatile OS Data

Collecting Volatile OS Data

คำแนะนำเกี่ยวกับการนำเทคนิคทางนิติวิทยาศาสตร์ดิจิทัลมาประยุกต์ใช้ในการตอบสนองต่อเหตุการณ์ภัยคุกคาม (SP 800-86)

Collecting Volatile OS Data

การเก็บรวบรวมข้อมูลระบบปฏิบัติการประเภทผันผวน (Collecting Volatile OS Data)

ข้อมูลระบบปฏิบัติการแบบผันผวน (Volatile OS Data) ที่เกี่ยวข้องกับเหตุการณ์ความไม่ปลอดภัย สามารถเก็บรวบรวมได้จากระบบที่กำลังเปิดใช้งานอยู่ (Live System) ซึ่งยังไม่เคยผ่านการรีบูตหรือปิดเครื่องนับตั้งแต่เกิดเหตุการณ์ขึ้นเท่านั้น

ทุกๆ การกระทำที่เกิดขึ้นบนระบบ ไม่ว่าจะเริ่มต้นโดยมนุษย์หรือตัวระบบปฏิบัติการเอง เกือบจะแน่นอนว่าจะสร้างความเปลี่ยนแปลงให้แก่ข้อมูลประเภทผันผวนนี้ไม่ทางใดก็ทางหนึ่ง ดังนั้น ผู้ซักถามหรือนักวิเคราะห์ (Analysts) จึงควรตัดสินใจให้เร็วที่สุดเท่าที่จะเป็นไปได้ว่าสมควรจะรักษาข้อมูลระบบปฏิบัติการแบบผันผวนนี้ไว้หรือไม่

โดย ideal แล้ว (ตามหลักการที่สมบูรณ์แบบ) เกณฑ์ที่ใช้ในการตัดสินใจเรื่องนี้ควรถูกจัดทำเป็นเอกสารไว้ล่วงหน้า เพื่อให้นักวิเคราะห์สามารถตัดสินใจได้อย่างดีที่สุดทันที ความสำคัญของการตัดสินใจนี้เป็นเรื่องที่ไม่สามารถมองข้ามได้เลย เนื่องจากกระบวนการปิดเครื่อง หรือแม้กระทั่งการตัดเชื่อมต่อออกจากระบบเครือข่าย อาจทำลายโอกาสในการเก็บรวบรวมข้อมูลที่อาจมีความสำคัญอย่างยิ่ง ตัวอย่างเช่น หากผู้ใช้เพิ่งจะรันเครื่องมือเข้ารหัสเพื่อรักษาความปลอดภัยของข้อมูลไปเมื่อเร็วๆ นี้ Memory (RAM) ของคอมพิวเตอร์ก็อาจจะยังคงมีค่า Password Hashes ซึ่งสามารถนำไปใช้สืบหาตัวรหัสผ่านได้

ในทางกลับกัน การเก็บรวบรวมข้อมูลระบบปฏิบัติการแบบผันผวนจากคอมพิวเตอร์ที่กำลังทำงานอยู่ก็มีความเสี่ยงในตัวเองเช่นเดียวกัน ตัวอย่างเช่น มีความเป็นไปได้เสมอที่ไฟล์บนคอมพิวเตอร์อาจจะเปลี่ยนแปลงไป และข้อมูลผันผวนอื่นๆ ก็อาจถูกแก้ไข ยิ่งไปกว่านั้น ผู้ไม่หวังดีอาจมีการติดตั้ง Rootkits ที่ถูกออกแบบมาเพื่อส่งคืนข้อมูลเท็จ ลบไฟล์ หรือทำการโจมตีที่เป็นอันตรายอื่นๆ ไว้

ในการตัดสินใจว่าจะเก็บรวบรวมข้อมูลผันผวนหรือไม่นั้น ความเสี่ยงที่เกี่ยวข้องกับการเก็บรวบรวมดังกล่าว ควรถูกนำมาชั่งน้ำหนักเปรียบเทียบกับโอกาสที่จะกู้คืนข้อมูลสำคัญกลับคืนมา ตามที่ระบุไว้ในส่วนที่ 3.2 หากคาดว่าจำเป็นต้องใช้พยานหลักฐาน นักวิเคราะห์ควรถ่ายภาพหรือบันทึกสิ่งที่ปรากฏบนหน้าจออย่างครบถ้วนก่อนที่จะเริ่มแตะต้องระบบ

หากระบบที่เปิดใช้งานอยู่นั้นอยู่ในโหมดสลีป (Sleep Mode) หรือมีระบบป้องกันด้วยรหัสผ่านปรากฏอยู่ นักวิเคราะห์ต้องตัดสินใจด้วยว่า จะทำการเปลี่ยนสถานะของระบบโดยการปลุกเครื่องให้ตื่นจากโหมดสลีป หรือพยายามแกะรหัสผ่าน/ข้ามการป้องกันรหัสผ่าน เพื่อให้สามารถเข้าไปเก็บรวบรวมข้อมูลผันผวนได้หรือไม่ แต่หากความพยายามที่ต้องใช้ในการเก็บข้อมูลผันผวนนั้นดูไม่คุ้มค่า นักวิเคราะห์อาจตัดสินใจใช้วิธีการปิดเครื่อง (Shutdown) แทน ตามที่อธิบายไว้ในส่วนที่ 5.2.2

ส่วนที่ 5.2.1.1 จะอธิบายถึงวิธีการเตรียมและเครื่องมือทางนิติวิทยาศาสตร์ (Forensic Tools) เพื่อเตรียมพร้อมสำหรับการเก็บรวบรวมข้อมูลผันผวน ถัดมาในส่วนที่ 5.2.1.2 จะอภิปรายถึงประเภทของข้อมูลต่างๆ พร้อมทั้งกล่าวถึงหมวดหมู่ของเครื่องมือ หรือเครื่องมือเฉพาะทางของระบบปฏิบัติการที่มีประสิทธิภาพในการเก็บรวบรวมข้อมูลแต่ละประเภท และสุดท้าย ส่วนที่ 5.2.1.3 จะอธิบายถึงความจำเป็นในการระบุประเภทของข้อมูลผันผวนที่มีแนวโน้มจะมีคุณค่ามากที่สุดในสถานการณ์นั้นๆ แล้วจึงจัดลำดับความสำคัญในการเก็บรวบรวมข้อมูล โดยอิงตามความสำคัญและระดับความผันผวนของข้อมูล (Relative Volatility) (Guide to Integrating Forensic Techniques into Incident Response  NIST SP 800-86)

อ่านเพิ่มเติม:


ที่มา:  SP 800-86 (Guide to Integrating Forensic Techniques into Incident Response).

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูล  เผยแพร่ความรู้และให้โอกาสในการค้นคว้าหาข้อมูลเพื่อการศึกษา   บุคคลที่สนใจโดยทั่วไป รวมถึงนักเรียน นิสิต นักศึกษา  ในการเรียนรู้เท่านั้น


* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


#DataBreachCheck #คิดก่อนPrompt #AISecurity #NCSA2026

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD

Friday, November 19, 2021

DIGITAL FORENSICS:Automate Live Response

 DIGITAL FORENSICS:Automate Live Response

 Live Response Collection – Cedarpelta Build  – Automated tool that collects volatile data from Windows, OSX/macOS, and *nix based operating systems

1.Go to the Windows Live Response directory.


2. Double click on the “Windows Live Response Collection.exe” file.


3. A window will appear, similar to the one below:

4.Now, just to do a quick test, let’s use the third option titled “Secure-Triage” and
then click the “Run Selected Windows Live Response Script.”


5. It will take some time to complete and then you will be presented with a “Press any
key to continue.” Before you press the Enter key; make sure you have recorded the
key to open the encrypted 7zip archive. Without this key you won’t be able to open
the final archive; you have been warned.


 6. I recommend that you open the archive and check its contents.

Event Log

Network INfo.





Re. :brimorlabs

        

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics #digitalforensics #investigation #cybercrime #fraud

 

Tuesday, May 19, 2020

DIGITAL FORENSICS:INCIDENT-RESPONSE-CHALLENGE

DIGITAL FORENSICS:incident-response-challenge


วันนี้่จะมาแนะนำการฝึกทำ Digital Forensics & Incident Response ในเว็บ incident-response-challenge.com/  ของ Cynet  มีโจทย์ CTF มาให้ลองเล่น เป็นโจทย์แนว forensics
:INCIDENT-RESPONSE-CHALLENGE
Cynet  คือ แพลตฟอร์มทางเลือกสำหรับ Incident Response

แพลตฟอร์ม Cynet 360 ช่วยให้ผู้รับมือ Incident Response ด้วยการมองเห็น process execution, network traffic and user activity. ปริมาณการใช้เครือข่ายและกิจกรรมของผู้ใช้ สภาพแวดล้อมทั้งหมด ช่วยให้ผู้เชี่ยวชาญด้าน IR สามารถมองเห็นได้ทันที  ใช้ในการสืบสวน  ช่วยในเรื่องขั้นตอนการตรวจสอบเบื้องต้นเพื่อให้เข้าใจถึงขอบเขตของเหตุการณ์ โดยไม่ต้องเสียเวลา


Hall of Fame  ลำดับสุดยอด  คนที่ทำคะแนนได้สูงและเร็ว แต่ละประเทศ จะเห็นได้ว่ามีคนไทยเก่งๆหลายคน และอาจารย์ที่ผมรู้จักด้วย
:INCIDENT-RESPONSE-CHALLENGE

:INCIDENT-RESPONSE-CHALLENGE

ก่อนเล่นให้ ทำการสมัครสมาชิก
:INCIDENT-RESPONSE-CHALLENGE
Challenges เริ่มทำ โดยมีการจับเวลา
:INCIDENT-RESPONSE-CHALLENGE
เมื่อทำการ Download File เวลาจะเริ่มเดิน และ เมื่อทำเสร็จให้กด Submit 
:INCIDENT-RESPONSE-CHALLENGE
ใช้เครื่องมือต่างๆและความรู้ทางด้าน  Digital Forensics & Incident Response
ตัวอย่าง ข้อ Basic ก็ถือว่ายากสำหรับคนที่ไม่มีพื้นฐานด้านนี้ แต่คนที่มีพื้นฐานก็จะสนุกกลับมัน

JumpList Explorer
:INCIDENT-RESPONSE-CHALLENGE
 Volatility Workbench
:INCIDENT-RESPONSE-CHALLENGE
 MFTDump
:INCIDENT-RESPONSE-CHALLENGE
Windows prefetch
:INCIDENT-RESPONSE-CHALLENGE

:INCIDENT-RESPONSE-CHALLENGE
 Registry Viewer
:INCIDENT-RESPONSE-CHALLENGE


และเป็นอีกครั้งที่ผมทำ LAB ไม่เสร็จ ขอค้างไว้แค่นี้ก่อนแล้วค่อยทยอย ทำเรื่อยๆครับ

Challenge-Answers

หมายเหตุ : เหมาะสำหรับการฝึกฝน Digital Forensics & Incident Response และทำให้ใช้เครื่องมือต่างๆ ได้คล่อง


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud #ฝึกทำLab

Saturday, December 23, 2017

Digital Forensics:Incident Response & Computer Forensics

Digital Forensics:Incident Response & Computer Forensics

Incident Response & Computer Forensics, Third Edition

Online   Digital Forensics Course

Textbook

Incident Response & Computer Forensics, Third Edition by by Jason Luttgens, Matthew Pepe, and Kevin Mandia
Publisher: McGraw-Hill Education; 3 edition (August 1, 2014)
Sold by: Amazon Digital Services, LLC
ASIN: B00JFG7152
Kindle edition: $36, Paper edition: $16 (prices I saw on 4-10-16 at Amazon)
Buy from Amazon ($15 - $40)

Catalog Description

Forensics tools, methods and procedures for investigating computers. Data recovery techniques and evidence collection, protection of evidence, expert witness skills and computer crime investigation techniques. Analysis of various file systems and specialized diagnostic software to retrieve data. Prepares in part for CompTIA Security+ and maps to Computer Investigation Specialists exam. CSU Examine computer media to discover evidence.

Prerequisite: Students should have taken CNIT 120 or have equivalent familiarity with the fundamentals of security.

After successful completion of this course, students will be able to:

Outcome 1: Define and describe computer forensics investigations.
Outcome 2: Compare and contrast the various operating systems and file systems.
Outcome 3: Evaluate and choose appropriate software, hardware, and tools to equip a Forensics Lab.
Outcome 4: Retrieve and analyze data from a suspect's computer.
Outcome 5: Create investigative reports and act as an expert witness.

Schedule

 1 Real-World Incidents 

2 IR Management Handbook

3 Pre-Incident Preparation

4 Getting the Investigation Started on the Right Foot
5 Initial Development of Leads 

6 Discovering the Scope of the Incident
7 Live Data Collection 

8 Forensic Duplication  

9 Network Evidence

 10 Enterprise Services

11 Analysis Methodology

12 Investigating Windows Systems (Part 1)
(Video for second half of class was lost)

 12 Investigating Windows Systems (Part 2)

12 Investigating Windows Systems (Part 3)
13 Investigating Mac OS X Systems
14 Investigating Applications
16 Report Writing  


17 Remediation Introduction

Speaker Biography

Conrad del Rosario Graduated law school in 1991 and have worked as a prosecutor for over 20 years. Worked in various criminal units at the SF DA's office including domestic violence, sexual assault, and narcotics before working identity theft and high technology crimes. Currently the managing attorney for the Economic Crimes Unit, part of our White Collar Division, where I oversee 5 attorneys including the high technology and identity theft teams. Currently assigned to the Rapid Enforcement Allied Computer Team (REACT) Task Force which is a consortium of local law enforcement agencies investigating high technology crimes based out of Silicon Valley, member of HTCIA, and currently a certified instructor for Peace Officer Standards and Training (POST) in the area of High Technology Investigations.

Links


Links for Chapter Lectures

Ch 1a: Deconstructing a Credit Card's Data
Ch 1b: Mitigating Fraud Risk Through Card Data Verification
Ch 1c: What data is stored on a payment card's magnetic stripe?
Ch 2a: The OpenIOC Framework

Ch 3a: Free Email Certificate | Secure SSL Certificate from Comodo
Ch 3b: Digitally Sign & Encrypt Emails
Ch 3c: 3 Alternatives to the Now-Defunct TrueCrypt for Your Encryption Needs
Ch 3d: VeraCrypt - Home
Ch 3e: Security Onion
Ch 3f: Network Security Toolkit (NST 24)
Ch 3g: Skynet Solutions : EasyIDS
Ch 3h: NIST Computer Forensic Tool Testing Program
Ch 3i: Evidence Tags and Chain of Custody Forms
Ch 3j: Searching and Seizing Computers and Obtaining Electronic Evidence in Criminal Investigations
Ch 3k: Federal Rules of Evidence
Ch 3l: Security Technical Implementation Guides (STIGs) for host hardening
Ch 3k: Securing Windows Service Accounts (Part 1)
Ch 3l: Download Splunk Enterprise for free
Ch 3m: GitHub - mcholste/elsa: Enterprise Log Search and Archive
Ch 3n: Snare SIEM Software Products
Ch 3o: SIEM, Security Information Event Management, ArcSight | Hewlett Packard Enterprise
Ch 3p: RSA enVision SIEM | EMC RSA
Ch 3q: Building a DNS Blackhole with FreeBSD
Ch 3r: Windows DNS Server Sinkhole Domains Tool | SANS Institute

Ch 5a: Report Crimes Against Children | Department of Justice

Ch 7a: Redline User Guide
Ch 7b: LINReS | Network Intelligence India Pvt. Ltd.(NII Consulting), Mumbai
Ch 7c: LiME – Linux Memory Extractor
Ch 7d: Memoryze for Mac
Ch 7e: Use the Mandiant Redline memory analysis tool for threat assessments

Ch 8a: Host protected area - Wikipedia
Ch 8b: Device configuration overlay - Wikipedia

Ch 9a: Basic Snort Rules Syntax and Usage
Ch 9b: Snort: Re: Rule for detecting ssh
Ch 9c: OptiView XG Network Analysis Tablet
Ch 9c: Network TAPs
Ch 9d: Security Onion
Ch 9e: Chapter 9 Scenario PCAPs - Incident Response and Computer Forensics, 3rd Edition
Ch 9f: Download NetWitness Investigator
Ch 9g: Old NetWitness Project

Ch 10a: Analyze Microsoft DHCP Server Log Files
Ch 10b: More About Microsoft DHCP Audit and Event Logging
Ch 10c: DHCP | Internet Systems Consortium
Ch 10d: Linux How To/Tutorial: Checking DHCP Logs
Ch 10e: using the ISC DHCP log function for debugging
Ch 10f: BIND | Internet Systems Consortium
Ch 10g: DNSCAP - DNS traffic capture utility | DNS-OARC
Ch 10h: IT Information Systems Management Software | LANDESK
Ch 10i: Parsing Landesk Registry Entries FTW
Ch 10k: LANDesk SoftMon Monitoring Information
Ch 10l: How to browse Software License Monitoring data ... |LANDESK User Community
Ch 10m: RegRipper
Ch 10n: GitHub - keydet89/RegRipper2.8
Ch 10o: GitHub - jprosco/registry-tools: Registry Forensics Tools
Ch 10p: Client Management Suite | Symantec
Ch 10q: Altiris Inventory Solutionâ„¢ 7.1 SP2 from Symantecâ„¢ User Guide
Ch 10r: Symantec Quarantined VBN file decoder
Ch 10s: John McAfee calls McAfee anti-virus "one of the worst products on the ... planet"
Ch 10t: Removing a PHP Redirector
Ch 10u: Understanding IIS 7 log files - Stack Overflow

Ch 11i: Filesystem Timestamps: What Makes Them Tick?
Ch 11j: File System Forensic Analysis: Brian Carrier
Ch 11k: Uuencoding - Wikipedia
Ch 11l: National Software Reference Library
Ch 11m: Nsrllookup
Ch 11n Security Firm Bit9 Hacked, Used to Spread Malware (2013)


Other Links

Yelp/osxcollector: A forensic evidence collection & analysis toolkit for OS X
ProcDump
SecureZeroMemory function (Windows)
Under My Thumbs -- Revisiting Windows thumbnail databases
Using Mandiant Redline to discover Meterpreter process injection - YouTube
Elcomsoft Advanced mobile forensics: iOS (iPhone and iPad), Windows Phone and BlackBerry 10
Aid4Mail Now (Free Trial)

New Unsorted Links

Ch 11a: Sawmill Web Log Analysis Sample - Dashboard
Ch 12a: File Times (Windows)
Ch 12b: SetMace: Manipulate timestamps on NTFS
Ch 12c: SANS Windows Artifact Analysis Poster
Ch 12d: Known Alternate Stream Names
Ch 12e: Bulk Removing Zone.Identifier Alternate Data Streams From Downloaded Windows Files
Ch 12f: Streams
Ch 12g: Manipulating Alternate Data Streams with PowerShell
Ch 12h: INDXParse: Tool suite for inspecting NTFS artifacts.
Ch 12i: Parse INDX
Ch 12j: Fsutil usn: the USN Change Journal
Ch 12k: Vssadmin
Ch 12l: View the content of Windows Prefetch (.pf) files
Ch 12k: FixEvt repairs corrupted Windows event logs
Ch 12n: Job File Parser
Ch 12o: SetRegTime
Ch 12p: Windows USER - Wikipedia
Ch 12q: Windows 7 Shellbags | SANS Institute
Ch 12r: MRU-Blaster
Ch 12s: Registry Decoder
Ch 12t: JLECmd: Automatic and Custom Destinations jump list parser with Windows 10 support
Ch 12u: Rifiuti2
Ch 12t: Hiberfil.sys - ForensicsWiki
Ch 12u: Zeus Malware Analysis using the Volatility Framework (Part I)
Installing Rekall on Windows
Download google/rekall � GitHub
RecuperaBit - A Tool For Forensic File System Reconstruction
Ch 12v: The VAD Tree: A Process-Eye View of Physical Memory
Ch 13a: iBored Disk Editor for Mac
Ch 13b: The MacPorts Project -- Download & Installation
Ch 13c: OS X 10.9: where are password hashes stored
Ch 13d: What type of hash are a Mac's password stored in?
Ch 13e: How to crack macbook admin password
Ch 13f: How to Convert plist Files to XML or Binary in Mac OS X
Ch 14a: BrowsingHistoryView - View browsing history of your Web browsers
Ch 14b: Extensible Storage Engine (ESE) Database File (EDB) format
Ch 14c: ESEDatabaseView - View/Open ESE Database Files (Jet Blue / .edb files)
Ch 14d: IECacheView - Internet Explorer Cache Viewer
Ch 14e: Freeware Web Browser Tools Package
Ch 14f: Google Chrome - ForensicsWiki
Ch 14g: Browser Popularity
Ch 14h: File:Browser usage share, 2009--2016, StatCounter.svg - Wikipedia
Ch 14i: How to Read and Analyze the Email Header Fields and Information about SPF, DKIM, SpamAssassin
Ch 14j: Inspect documents for hidden data and personal information
iOS Secure Boot 101 Slides from Axi0mX
Hibr2Bin: Comae Hibernation File Decompressor
A glimpse of iOS 10 from a smartphone forensic perspective
Mobile Forensics Monkey Wrench: iOS 10.2 and Encryption
iOS Forensics (7/25/17)
Evidence Acquisition and Analysis from iCloud



Ref.
Computer Forensics
121_F10

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น
* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...