Showing posts with label Magnet Forensics. Show all posts
Showing posts with label Magnet Forensics. Show all posts

Friday, February 13, 2026

How to detect encryption disk

How to detect encryption disk.

Detecting disk encryption is one of the most critical steps in Digital Forensics. If an investigator shuts down a machine  without realizing the disk is encrypted, they risk losing access to the data permanently if the recovery key is unknown.

Based on industry-standard forensic guidelines and the provided evidence, here is the step-by-step process for detecting encryption.

How to detect encryption disk

Step 1: Visual Inspection (Live System)

The first step is to check for obvious UI indicators while the system is still running.

  • File Explorer: Look for a lock icon on the drive letters in "This PC."

    • Gold Lock: The drive is encrypted and currently locked (requires a key).

    • Silver/Open Lock: The drive is encrypted but currently unlocked (accessible).

  • System Tray: Look for icons related to encryption software like VeraCrypt, PGP, or Check Point.

How to detect encryption disk

Under BitLocker Drive Encryption - Hard Disk Drives, if you see the following text: Windows (H:) On, then your hard drive is encrypted.

How to detect encryption disk

Step 2: Native Command Line Verification

Using built-in OS tools is a "low-footprint" way to confirm encryption status without installing new software.

For Windows (BitLocker)

  1. Open Command Prompt or PowerShell as an Administrator.

  2. Run the command: manage-bde -status

  3. Analysis:

    • Conversion Status: Look for "Fully Encrypted" vs. "Fully Decrypted."

    • Percentage Encrypted: Shows if an encryption process is currently in progress.

    • Encryption Method: Identifies the algorithm (e.g., AES 128 or XTS-AES 256).

    • Lock Status: Confirms if the volume is Locked or Unlocked.

How to detect encryption disk

How to detect encryption disk


How to detect encryption disk
Photo by magnetforensics[.]com

Magnet Encrypted Disk Detector (v3.10 released June 19th, 2022) is a command-line tool that can quickly and non-intrusively check for encrypted volumes on a computer system during incident response. The decision can then be made to investigate further and determine whether a live acquisition needs to be made in order to secure and preserve the evidence that would otherwise be lost if the plug was pulled .

How to detect encryption disk

Step 3: Forensic Scanning Tools (Magnet EDD)

Standard OS commands may miss third-party encryption (like TrueCrypt or VeraCrypt). Forensic investigators use specialized, non-intrusive tools like Magnet Encrypted Disk Detector (EDD).

  1. Execution: Run EDDv310.exe from a forensic USB drive to avoid altering the host's registry.

  2. Physical Drive Scan: The tool scans physical disk signatures (MBR/GPT) for encryption headers.

  3. Logical Volume Scan: It checks every mounted volume for BitLocker, TrueCrypt, PGP, or VeraCrypt.

  4. Results: If the tool detects encryption, it will red highlight the specific drive and the type of encryption found in red highlight, as seen in your provided screenshots.


Critical Forensic Guidelines (Post-Detection)

If encryption is detected, DO NOT SHUT DOWN THE COMPUTER until you have performed the following:

  1. RAM Capture: Use a tool (like FTK Imager) to capture the volatile memory. Encryption keys are often stored in plain text within the RAM while the drive is mounted.

  2. Search for Recovery Keys: Look for BitLocker Recovery Key.txt files on the desktop, in the user's Microsoft Account, or printed physical documents.

  3. Live Imaging: If the disk is "Unlocked," perform a "Live Image" of the logical volume. This captures the data in its unencrypted state.

  4. Hash Validation: Always calculate the Hash Value (MD5/SHA-256) of your captured image to ensure its integrity for use in court.


Ref:  magnetforensics[.]com


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น ช่วยเตือนความจำ


* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Tuesday, March 21, 2023

DIGITAL FORENSICS:Magnet RESPONSE Free Tools

DIGITAL FORENSICS:Magnet RESPONSE Free Tools

    วันนี้แอดจะมาแนะนำโปรแกรม Magnet RESPONSE เครื่องมือฟรี ของบริษํท MAGNET FORENSICS สำหรับรวบรวมและเก็บรักษาข้อมูล ในเครื่องคอมพิวเตอร์อย่างรวดเร็วก่อนที่จะถูกแก้ไขหรือสูญหาย สามารถกำหนดเป้าหมายไฟล์และข้อมูลที่ครอบคลุมซึ่งเกี่ยวข้องกับการตรวจสอบการตอบสนองต่อเหตุการณ์ รวมถึง RAM

Download Magnet RESPONSE here.

DIGITAL FORENSICS:Magnet RESPONSE Free Tools

Magnet Response Configuration
DIGITAL FORENSICS:Magnet RESPONSE Free Tools

DIGITAL FORENSICS:Magnet RESPONSE Free Tools

Key Benefits & Features
  • Easy To Use: ใช้งานง่าย  ผู้ใช้ที่ไม่มีความรู้ทางด้านเทคนิค ก็สามารถใช้เครื่องมือได้
  • Portable:พกพาได้: ไฟล์เรียกทำงานเพียงไฟล์เดียว (น้อยกว่า 1MB)  สามารถดาวน์โหลดได้ง่าย และสามารถจัดเก็บและเรียกใช้จาก  USB Drive
  • Outputเอาต์พุตถูกรวมและบันทึกเป็นไฟล์ .zip เพื่อการส่งที่ง่าย หรือสำหรับการประมวลผลและการวิเคราะห์ใน Magnet AXIOM & Magnet AXIOM Cyber
  • Data Integrity:มีการระบุค่าแฮชที่ฝังไว้เพื่อตรวจสอบความสมบูรณ์ของข้อมูล

Output: Log.txt
              Ramdump.dmp
              .zip file
DIGITAL FORENSICS:Magnet RESPONSE Free Tools

ท่านสามารถนำไฟ์ล์ที่ได้ มาเปิดด้วย โปรแกรม   Magnet AXIOM & Magnet AXIOM Cyber (Commercial software)  และวิเคราะห์หาหลักฐานเพิ่มเติม ดังตัวอย่าง

ใช้โปรแกรม Magnet AXIOM Process 5.0
DIGITAL FORENSICS:Magnet RESPONSE Free Tools
Analyze Evidence > Ramdump.dmp

Analyze Evidence > 2023.03.20_10.56.17.zip 
DIGITAL FORENSICS:Magnet RESPONSE Free Tools

DIGITAL FORENSICS:Magnet RESPONSE Free Tools

DIGITAL FORENSICS:Magnet RESPONSE Free Tools
DIGITAL FORENSICS:Magnet RESPONSE Free Tools

DIGITAL FORENSICS:Magnet RESPONSE Free Tools


ท่านสามารถนำไฟล์ Ramdump.dmp  ไปวิเคราะห์ด้วยโปรแกรม Volatility framework และ PassMark Volatility Workbench ,MemProcFS

ท่านสามารถดูวิธีการใช้งานโปรแกรม Magnet RESPONSE 


อ้างอิง  magnetforensics 

อ่านเพิ่มเติม Magnet Forensics


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud #MagnetForensic

Thursday, March 2, 2023

Digital Forensics:Magnet Virtual Summit Capture The Flag (CTF)2023

Digital Forensics:Magnet Virtual Summit Capture The Flag (CTF) 2023
MVS 2023 CTF Writeups

CTFs นี้เป็นโอกาสในการเรียนรู้แบบเกมเพื่อทดสอบทักษะของคุณด้วยความท้าทายด้านนิติวิทยาศาสตร์ดิจิทัล Forensic images ของหลักฐานหลายข้อ มีให้ผู้เข้าแข่งขัน พร้อมกับคำถามท้าทายต่างๆ ตามชุดข้อมูล  ผู้เข้าแข่งขัน สามารถใช้เครื่องมือใด ๆ ที่พวกเขาต้องการเพื่อตอบคำถามต่าง ๆ หาFlag  ซึ่งมีค่าคะแนนขึ้นอยู่กับระดับความยาก
 
MVS 2023 CTF Writeups


MVS 2023 CTF Writeups

MVS 2023 CTF Writeups


MVS 2023 CTF Writeups

ตัวอย่างหมวด  Cipher

#Time to practice our CW.

MVS 2023 CTF Writeups
Step 1:  CyberChef > From Morse Code




#Time  to return to the bas(e)ics and eat a salad.
TFk6THBLeHFqdWJMcEt4cWp1Yq==
MVS 2023 CTF Writeups
Step 1: From base64 >>  LY:LpKxqjubLpKxqjub
MVS 2023 CTF Writeups

Step 2:https://www.dcode.fr/caesar-cipher 
IV:ImHungryImHungry
MVS 2023 CTF Writeups

#I can't remember that URL. I wish I could rewind my day and bookmark it!

MVS 2023 CTF Writeups
URL Encode Charecters

MVS 2023 CTF Writeups

URL Decode

MVS 2023 CTF Writeups

MVS 2023 CTF Writeups

MVS 2023 CTF Writeups

#BIN TO HEX keeps reminding (download file)

MVS 2023 CTF Writeups
Step 1:From Binary
Magnet Virtual Summit Capture The Flag (CTF)
Step 2: From Hex

MVS 2023 CTF Writeups

Flag: You must use the same email address on the CTF site as you used to register for the conference. Additional user accounts are prohibited, and any user found creating multiple accounts will be disqualified.


Magnet Virtual Summit Capture The Flag 2023 - Cipher


Magnet Virtual Summit Capture The Flag 2023  Writeups 

MVS 2023 CTF Writeups 


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud #CTF

Friday, February 10, 2023

Malware Forensics:Investigate Malware & Ransomware with Magnet forensics

Malware Forensics:Investigate Malware & Ransomware with Magnet forensics

                เนื่องด้วยบทความนี้เป็นการรีวิวพอสังเขป     โดยใช้เครื่องมือ Magnet AXIOM  จึงไม่ได้ลงรายละเอียดลึกมาก ขออภัยมา ณ ที่นี้ 


วัตถุประสงค์การทดสอบ

  •      ทำการเก็บรวบรวมพยานหลักฐาน ในหน่วยความจำ Memory
  •      ทำการค้นหาข้อมูลในหน่วยความจำ Memory
  •      ศึกษาเครื่องมือ Dump memory   
  •      ศึกษาเครื่องมือ   memory  analysis 
เครื่องมือที่ใช้

  • Magnet RAM Capture
  • FTK Imager 
  • Magnet AXIOM Examine 

  • Notebook workstation
  • Virus total  & Sandbox Online

Keyword 

  • WannaCry  (จากข้อมูลหลักฐานที่ได้ คือรูป หน้าจอโดน ransom ware ส่งมาที่ LAB)
  • WNCRY    (จากข้อมูลหลักฐานที่ได้ คือรูป หน้าจอโดน ransom ware ส่งมาที่ LAB)

Static analysis

Malware Forensics:Investigate Malware & Ransomware with Magnet forensics

Malware & Ransomware with Magnet forensics

ในส่วนนี้เราจะพูดถึงการตรวจสอบมัลแวร์   ซึ่่ง เราจะมาใช้เครื่องมือ AXIOM   ในการวิเคราะห์หน่วยความจำ มักจะมีร่องรอยสำคัญในการตรวจสอบมัลแวร์

เราได้ข้อมูล Memory Image  สำหรับใช้วิเคราะห์หลักฐานแล้ว 

  • ใช้เครื่องมือ FTK Imager  Dump memory    ไฟล์ชือ  "memdump.mem" 
  • ใช้เครื่องมือ Magnet RAM Capture    Dump memory   ไฟล์ชือ "Dump_CF-DF-MM01.raw"

เนื่องด้วยเครื่่องมือ Magnet AXIOM Examine V.6 เอาความสามารถของ volatility framework รวมเข้าด้วยกันใช้สำหรับวิเคราะห์ Memory 

volatility framework คือเครื่องมือที่ใช้วิเคราะห์ memory  


Analyze Evidence  ทำการ Load 

Malware & Ransomware with Magnet forensics

Malware & Ransomware with Magnet forensics

LNK Files  พบร่องรอยน่าสงสัยจาก LNK file  มีการกด link หรือเปิดไฟล์  @wanaDecryptor@.exe เวลา  16/2/2023 15:45  จาก USB หรือ อุปกรณ์ Volume Serial Number: E00FAB60   Volume Name :BSA  Drive :E  "E:\Sample Malware\@wanaDecryptor@.exe"

alware & Ransomware with Magnet forensics


Malware & Ransomware with Magnet forensics


เราพบว่ามีไฟล์ WannaCry.exe   น่าสงสัยคือ  Process Name : WannaCry.exe   Process ID: 728  

Ransomware with Magnet forensics

หลังจากนั้นมาทำการตรวจสอบ   Process ID: 728  WannaCry.exe   PPID:2696  พบว่ามีการเชื่อมโยงมาจาก "E:\Sample Malware\WannaCry.exe   และไปใช้งาน DLL file ต่างๆ

Malware & Ransomware with Magnet forensics

ทำการ Extract Process ID: 728 >  procedump , dlldump,  memdump  เพื่อมาตรวจสอบ

Ransomware with Magnet forensics

ได้ไฟล์ Executable.728.exe   และผลการ check virus total พบว่าเป็นมัลแวร์ 


Virus total Basic properties

ผลการ Scan ไฟล์ Executable.728.exe  โดย sandbox พบว่าเป็น ransomware

ทำการ Extract Process ID: 728  filedump   และไป scan  ใน Virus total 
file.728.0x869427a8.img

แต่เงื่อนไขสำคัญ คือ "ห้ามปิดหรือ restart เครื่องหลังจากติด WannaCry แล้วโดยเด็ดขาด" อีกทั้งห้ามปล่อยเวลาให้ผ่านนานเกินไป ไม่งั้น memory ส่วนที่เก็บค่าสำคัญนั้นอาจถูกลบหรือถูกเขียนทับโดย process อื่นไปแล้วก็เป็นได้ ข้อมูลในหน่วยความจำที่สามารถสูญหายได้เมื่อปิดอุปกรณ์ ก็จะทำให้หาร่อยรอยได้ยาก


ศึกษาเพิ่มเติม: Volatile Data.
                           Memory Forensics

ท่านสามารถใช้ WannaKiwi และยืนยันว่าสามารถปลดล็อก WannaCry บน Windows XP และ Windows 7 ได้เงื่อนไขเบื้องต้นในการปลดรหัสได้สำเร็จต้องมีอย่างน้อย 2 รายการเช่นเดียวกับ WannaKey คือ

  • คอมพิวเตอร์ที่ถูก WannaCry เข้ารหัส จะต้องยังไม่ถูกรีสตาร์ทไปเสียก่อน
  • พื้นที่บนๆ Memory ที่เกี่ยวข้องกับการกู้ข้อมูลกุญแจที่ใช้เข้ารหัสจะต้องยังไม่ถูก Reallocate หรือถูกลบไปโดยโปรเซสอื่นๆ   หากไม่ได้ถูกโปรแกรมอื่นใช้หน่วยความจำตำแหน่งเดียวกันแล้วเขียนข้อมูลทับไปเสียก่อน
  • ดาวน์โหลด WanaKiwi Decrypter ได้ผ่านทาง: https://github.com/gentilkiwi/wanakiwi/releases


ที่มา: https://www.techtalkthai.com/wanakiwi-decryptor-for-wannacry

         Investigate Malware & Ransomware with Speed and Efficiency


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics #digitalforensics #investigation #cybercrime #fraud

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...