Showing posts with label Oxygen Forensics. Show all posts
Showing posts with label Oxygen Forensics. Show all posts

Wednesday, May 11, 2022

Digital Forensics:OXYGEN FORENSICS CTF

Digital Forensics:OXYGEN FORENSICS CTF

วันนี้มาแนะนำการแข่งขัน OXYGEN FORENSICS CTF  ซึ่งจัดโดยบริษัท  OXYGEN FORENSICS  เป็นโซลูชันด้านนิติวิทยาศาสตร์ ที่ใช้งานง่ายและมีประสิทธิภาพซึ่งช่วยลดความซับซ้อนและเร่งขั้นตอนการสืบสวนทางดิจิทัล โดยกิจกรรมจะเปิดและปิดเป็นช่วง   May 2022  #OXYGEN FORENSICS 

Oxygen Forensic Capture the Flag event (CTF)

Oxygen Forensic Capture the Flag event
OXYGEN FORENSICS CTF

Oxygen Forensic® Detective ผลิตโดย บริษัท Oxygen Forensic เป็นแพลตฟอร์มซอฟต์แวร์ทางนิติวิทยาศาสตร์แบบครบวงจรที่สร้างขึ้นเพื่อแยก ถอดรหัส และวิเคราะห์ข้อมูลจากแหล่งข้อมูลดิจิทัลหลายแหล่ง: อุปกรณ์เคลื่อนที่ Mobile และ IoT การสำรองข้อมูลอุปกรณ์ UICC และ media cards , โดรน และบริการคลาวด์ Oxygen Forensic® Detective ยังสามารถค้นหาและ  ไฟล์ระบบ และข้อมูลรับรองจากเครื่อง Windows, macOS และ Linux ได้มากมาย

OXYGEN FORENSIC® CERTIFICATION


OXYGEN FORENSICS CTF Writeup

Once you have imported the extractions, please review the data, and answer the following questions: 

1: Create a case in OFD and name it: Facial Recognition CTF. From the folder provided to you named 2022-03-22 13-53-10 000000001206, pull the Device.ewc into your new Facial Recognition CTF Case. Run OCR on this dataset. Select Faces on the device level. In column 1 filter settings, deselect the option for "Male" under sex and deselect "None" under the accessories tab (Leave all other boxes checked). Mark the image of the female wearing a white shirt and sunglasses as key evidence. Create and add a blue tag for the photo named "Captured Flag." Add a note to the photo that says ("The answer to question #1)   

OXYGEN FORENSICS CTF
Oxygen Forensics CTF

2: Create a new Face Set to Search against using the "Dream Team" Face Set provided for you. Label the Face Set "Face Set 1".  Set your minimal similarity threshold to 99% and search Face Set 1 against the contents of the storage device. Mark the image with the 99% similarity rating (from the storage device) as key evidence. Create and add a blue tag to the same image and name the tag "Captured Flag." Add a note to the photo that says ("The answer to question #2)   

Oxygen Forensics CTF
                          

3: With your minimal similarity threshold set to 20%, find the five images OFD found when searching the device contents against the target face: MV5BMTQ5NTUzNDE5OV5BMl5BanBnXkFtZTgwMjAwOTE1MDE@._V1_.jpg? Mark each of the five images from the device contents as key evidence.   Create and add a blue tag for each of the five images named "Captured Flag." Add a note to each of the five images that say ("The answer to question #3)

Oxygen Forensics CTF

4. With your minimal similarity threshold set to 97%, find the image OFD found within the storage device when searching the device contents against the target face: ee0dc542f1558c7d003131cdf6f4161e.jpg that had a 97.2 % similarity rating. Create and add a blue tag to the same image and name the tag "Captured Flag." Add a note to the image that says ("The answer to question #4)   

Oxygen Forensics CTF
  

5: Clear your search history for Face Set 1.  Create a new Face Set to Search against using the "Players" Face Set provided for you. Label the Face Set "Face Set 2". Select 100% Minimal similarity rating. Notice 270 images have a similarity rating of 100%. Mark image 106218751-1572883641328david.jpg as key evidence. Create and add a blue tag to the same image and name the tag "Captured Flag." Add a note to the image that says ("The answer to question #5)   

OXYGEN FORENSICS CTF

6:  Clear your search history for Face set 2. Exit out of the Search Section and select Faces under analytics.  In column 1 filter settings, deselect the option for "Male" under sex and choose 70+ under the age category (Leave all other boxes checked aside from age). Select the three images OFD has identified as being a female 70+ years old. Mark each image as key evidence. Create and add a blue tag to the same image and name the tag "Captured Flag." Add a note to the image that says ("The answer to question #6).   

Oxygen Forensics CTF

7: Select Faces under analytics.  In column 1 filter settings, deselect the option for "Female" under sex, choose 70+ under the age category, and select white under race (Leave all other boxes checked except for race and age). Select the three images OFD has identified as being a white male 70+ years old. Mark each image as key evidence. Create and add a blue tag to the same image and name the tag "Captured Flag." Add a note to the image that says ("The answer to question #7). 

Oxygen Forensics CTF

8: Select the search section in analytics. Conduct a search using Face sets (Face Set 1) and search against the contents of the storage device with a minimal similarity setting of 70%. Find the photo from the storage device that has a 70.4% similarity rating when searched against Face Set 1. Mark the image as key evidence. Create and add a blue tag to the same image and name the tag "Captured Flag." Add a note to the image that says ("The answer to question #8).

Oxygen Forensics CTF

9: Clear your search history for Face Set 1. Conduct a Search using Face Set 2 and search against the contents of the storage device with a minimal similarity setting of 100%. Find the photo of the white male wearing a white headband. Mark the image as key evidence. Create and add a blue tag to the same image and name the tag "Captured Flag." Add a note to the image that says ("The answer to question #9) 

OXYGEN FORENSICS CTF

10: Conduct a Search using Face Set 2 and search against the contents of the storage device with a minimal similarity setting of 100%. Find the photo of the white male with spiked blonde hair, wearing white sunglasses on his forehead. This man is wearing a blue shirt, has a goatee, and is smiling. Mark the image as key evidence. Create and add a blue tag to the same image and name the tag "Captured Flag." Add a note to the image that says ("The answer to question #10)

OXYGEN FORENSICS CTF

Click https://oxygenhq.synology.me:51518/sharing/jGdoEZ8v4

link to open resource. 

Oxygen Forensic CTF

Oxygen Forensic Certification

เมื่อท่านเข้าร่วมการแข่งขัน CTF และส่งคำตอบตามเวลาที่กำหนดท่านจะได้รับใบประกาศจาก บริษัท  OXYGEN FORENSICS 
Oxygen Forensic Certification


ที่มา:  oxygen-forensic  
           

อ่านเพิ่มเติม  CFT

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD


Friday, April 2, 2021

Mobile Forensics:Oxygen Forensics

Mobile Forensics:Oxygen Forensics

Oxygen Forensics ® Detective คือ ซอฟต์แวร์นิติวิทยาศาสตร์ ใช้สืบค้นพยานทางดิจิทัลจากอุปกรณ์โทรศัพท์เคลื่อนที่และหลักฐานบนระบบคลาวด์คอมพิวติ้ง  และอุปกรณ์ IoT



Oxygen Forensic® Detective

Oxygen Forensic® Detective ผลิตโดย บริษัท Oxygen Forensic เป็นแพลตฟอร์มซอฟต์แวร์ทางนิติวิทยาศาสตร์แบบครบวงจรที่สร้างขึ้นเพื่อแยก ถอดรหัส และวิเคราะห์ข้อมูลจากแหล่งข้อมูลดิจิทัลหลายแหล่ง: อุปกรณ์เคลื่อนที่ Mobile และ IoT การสำรองข้อมูลอุปกรณ์ UICC และ media cards , โดรน และบริการคลาวด์ Oxygen Forensic® Detective ยังสามารถค้นหาและ  ไฟล์ระบบ และข้อมูลรับรองจากเครื่อง Windows, macOS และ Linux ได้มากมาย

Oxygen Forensic® Extractor

Oxygen Forensic® Extractor เป็นซอฟต์แวร์แบบสแตนด์อโลนสำหรับการดึงข้อมูลจากอุปกรณ์มือถือ Extractor ช่วยให้คุณสามารถเชื่อมต่ออุปกรณ์ Apple iOS และ Android ได้หลากหลาย นำเข้าข้อมูลสำรองอุปกรณ์ต่างๆ เพื่อกู้คืนหลักฐานดิจิทัลอันมีค่าได้อย่างรวดเร็วและมีประสิทธิภาพ เมื่อดึงข้อมูลแล้ว ผู้ใช้สามารถเลือกที่จะบันทึกลงในการสำรองข้อมูล OFB เพื่อนำเข้าในภายหลังไปยัง Oxygen Forensic® Detective  ซื้อแยกต่างหากหรือส่งออกไปยังรูปแบบรายงานรูปแบบใดรูปแบบหนึ่งของเราทันที เช่น PDF, HTML, XML เป็นต้น


อุปกรณ์

1.สมาร์ทโฟน Samsung Galaxy A20(SM-A205F)ระบบปฏิบัติการ Android 10  ณ ขณะที่ทำการทดลอง การใช้อุปกรณ์และรุ่นของระบบที่แตกต่างกันอาจทำให้ข้อมูลที่ได้นั้นไม่เหมือนกัน)

2. คอมพิวเตอรโน๊คบุ๊ค CPU AMD Ryzen 5 Pro 4650U Ram 32 GB. HDD 500GB. หรือสูงกว่า, Microsoft Windows 10

3. ซอฟต์แวร์ที่ใช้ คือ Oxygen Forensics Extractor  v.13.3.0.65


ขั้นตอนที่ 1 การเตรียมเครื่องมือในการสกัดข้อมูล

1.1 เตรียมเครื่องคอมพิวเตอร์ที่จะนำมาใช้ในการสกัดข้อมูล โดยติดตั้ง Microsoft Windows 10

1.2 ทำการติดตั้งซอฟต์แวร์   Oxygen Forensics, จากนั้นติดตั้งไดร์เวอร์ (Driver) ของสมาร์ทโฟน

ขั้นตอนที่ 2 เตรียมสมาร์ทโฟน

2.1 เปิดโหมดเครื่องบิน จากนั้นปลดล๊อครหัสผ่าน ทำการชาร์จแบตเตอรี่ให้เต็ม

2.2 เปิดโหมด USB Debugging จากนั้นยอมรับ RSA Key สำหรับระบบปฏิบัติการแอนดรอยด์ และทำการตรวจสอบว่า เปิด Stay Awake Mode และ ปิด USB Modem

2.3 ตรวจสอบว่าติดตั้งไดร์เวอร์ (Driver) ของอุปกรณ์แล้ว

ขั้นตอนที่ 3 การสกัดข้อมูลจากสมาร์ทโฟน ด้วยเครื่องมือ Oxygen Forensics

3.1 ตรวจสอบ License เข้ากับเครื่องคอมพิวเตอร์ จากนั้นเปิด ซอฟต์แวร์  Oxygen Forensics

3.2 ทำการเชื่อมต่อ สมาร์ทโฟนเข้ากับเครื่องคอมพิวเตอร์ แล้วทำการค้นหาชื่อรุ่นของโทรศัพท์ว่ารองรับหรือไม่ จากนั้นทำการเลือกรุ่นโทรศัพท์ให้ตรงกับรุ่นที่เราจะสกัดข้อมูล แล้วทำการเลือก (Directory)ที่จะเก็บข้อมูลไปยังสื่อบันทึกข้อมูล

3.3 ทำการเลือกเมนูในการสกัดข้อมูลAndroid  (Android Extractions) เมื่อสกัดข้อมูลเรียบร้อยแล้ว  


Android OxyAgent Extraction





Oxygen Forensic® Extractor



สรุป

จากการทดสอบนั้นจะเห็นได้ว่าเครื่องมือในการสกัดข้อมูล(extraction)ที่รองรับการสกัดข้อมูล(extraction)จากอุปกรณ์สื่อสารเคลื่อนที่ แอนดรอยด์  ไม่สามารถสกัดเอาข้อมูลออกจากอุปกรณ์สื่อสารเคลื่อนที่แอนดรอยด์ได้ในบางเครื่องมือ เนื่องจากเครื่องมือที่ต่างชนิดกันมีเทคนิคที่ใช้ในการสกัดข้อมูล(extraction) ออกมาไม่เหมือนกัน ทำให้เครื่องมือบางตัวนั้นไม่สามารถผ่านระบบรักษาความปลอดภัยของแอปพลิเคชันเข้าไปได้ หรือบางตัวไม่สามารถผ่านเข้าไปได้ตั้งแต่ระบบรักษาความปลอดภัยของระบบปฏิบัติการ จึงส่งผลให้ อุปกรณ์สื่อสารเคลื่อนที่ ที่ส่งให้ผู้ตรวจมาตรวจสอบข้อมูลนั้น ทางผู้ตรวจจึงไม่สามารถจะตรวจหาข้อมูลให้ได้ 

ที่มา:www.oxygen-forensic.com 

 The Study of Verification Techniques by Extracting Data from Application Line Using Forensic Tools:Pattadon Tantiphantarak* and Gedsirin Eksinitkun


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics #digitalforensics #investigation #cybercrime #fraud

Thursday, March 11, 2021

Cloud Forensics:How To Extract Credential Data Using KeyScout

Cloud Forensics:How To Extract Credential Data Using KeyScout

Forensic Imaging & DATA Extraction

Credit Photo by:  blog.oxygen-forensic 

KeyScout is a utility built into Oxygen Forensic® Detective which uncovers and extracts user data, tokens and passwords from apps and web browsers as well as Wi-Fi hotspot passwords, iTunes backups, and operating system data on PCs running Windows.

OxyKeyScout.Windows.exe  

1. Run KeyScout on the target  computer

Forensic Imaging & DATA Extraction
The KeyScout application is one of the tools available in the tool suite concept of the Forensic Detective product. KeyScout is a standalone application that can be run locally. 
Forensic Imaging & DATA Extraction
2. Start search
Forensic Imaging & DATA Extraction
3. Save collected data to an inserted removable drive (this collection will contain both an ocpk file and odb file).
Save resulted 
Forensic Imaging & DATA Extraction
Export Finished 
Forensic Imaging & DATA Extraction
2 passwords and 3 tokens. That’s bad all by itself. Out of 8 different applications, 5.67GB. of data – we’ll have a look. 
Forensic Imaging & DATA Extraction
Or, as you’ll see inside Detective when you finally pull extracted data into a case, the accounts and passwords section is the same information that would be contained in an OCPK file. You’ll see a button in the tool called ‘Export to OCPK.’ We’ll talk about the way you’d do that and what that means. But this is the literal ability to grab the account data to feed the Cloud Extractor.
Forensic Imaging & DATA Extraction

Well, let’s look here: Passwords and tokens. 
Forensic Imaging & DATA Extraction
 Who knows what you’re doing? Select it all.
Forensic Imaging & DATA Extraction

Forensic Imaging & DATA Extraction
4. Investigators can import the ocpk file to Oxygen Forensic® Cloud Extractor and the odb file to JetEngine.

“Import credentials file generated by Oxygen Forensic Detective, which we just saw, or KeyScout, which we just saw. If you click that, it’s looking for that OCPK file.

Forensic Imaging & DATA Extraction
Forensic Imaging & DATA Extraction
Forensic Imaging & DATA Extraction
Forensic Imaging & DATA Extraction
Forensic Imaging & DATA Extraction
Forensic Imaging & DATA Extraction
Forensic Imaging & DATA Extraction
Forensic Imaging & DATA Extraction
Forensic Imaging & DATA Extraction

Forensic Imaging & DATA Extraction



สรุป

Oxygen Forensics เป็นผู้พัฒนาเครื่องมือประเภท digital forensics เพื่อช่วยในการสืบสวน ตัวเครื่องมือมีความสามารถในการวิเคราะห์ข้อมูลทั้งจากคอมพิวเตอร์ ,โทรศัทพ์มือถือและเก็บข้อมูลบนคลาวด์ หนึ่งในความสามารถที่ถูกเพิ่มเข้ามาในเวอร์ชันหลังๆ คือการดึงข้อมูลของ Credential Data จาก  application มาวิเคราะห์ได้

KeyScout เป็นเครื่องมือสำหรับดึง Credential Data  , User password ,Wi-Fi hotspot passwords และ Tokens ของเครื่องเป้าหมาย ไฟล์ที่ได้เป็น .OCPK เพื่อนำไปวิเคราะห์ต่อไป โดยใช้โปรแกรม Oxygen Forensics เหมาะสำหรับงาน Cloud Forensics ,Mobile Forensics เช่น ข้อมูลจาก Dropbox ,Google Drive


Credit by:


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD



Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...