Showing posts with label Tableau Forensic Duplicator. Show all posts
Showing posts with label Tableau Forensic Duplicator. Show all posts

Tuesday, July 12, 2022

DIGITAL FORENSICS:CCTV Forensics Disk-to-Disk (clone) duplication

DIGITAL FORENSICS:CCTV Forensics  Disk-to-Disk (clone) duplication

·         Dissembling HD from CCTV machine and Duplicate to the Blank HD by TD2 

CCTV Forensics  Disk-to-Disk (clone) duplication


Tableau Forensic Duplicator Disk-to-Disk (clone)

CCTV Forensics  Disk-to-Disk (clone) duplication



Disk-to-Disk (clone) save log


·      Save Log for Hash and none errors confirmation. 


--- The scenario shows that we can use this method to clone the source and then acquire the hash log for integrity purposes. -- --- Hence, following the practice above, we can extract the video content from CCTV evidence. However, it is essential to gain requirements from the client because it helps to shorten the process. -- --- If we can bring the CCTV machine along with the evidence source, we can produce a potential result. --

CCTV Forensics  Disk-to-Disk (clone) duplication

·         Put the Blank HD into CCTV machine and check, the result has shown that it can replay and record accordingly.

CCTV Forensics  Disk-to-Disk (clone) duplication

CCTV Forensics  Disk-to-Disk (clone) duplication

--- The scenario shows that we can use this method to clone the source and then acquire the hash log for integrity purposes. --


--- Hence, following the practice above, we can extract the video content from CCTV evidence. However, it is essential to gain requirements from the client because it helps to shorten the process. --
--- If we can bring the CCTV machine along with the evidence source, we can produce a potential result. --


อ่านเพิ่มเติม  Tableau Forensic Duplicator.

Credit: Examiner Opal (Digital Forensic Technician)

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น ช่วยเตือนความจำ

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD 

Wednesday, June 13, 2018

DIGITAL FORENSICS: เครื่องทำสำเนาข้อมูลดิจิทัล Forensic Imager

DIGITAL FORENSICS: เครื่องทำสำเนาข้อมูลดิจิทัล (Forensic Imager)


อุปกรณ์ในการเก็บหลักฐานดิจิทัล

สำหรับใช้เชื่อมต่อวัตถุพยานประเภทสื่อบันทึกข้อมูลดิจิทัล เช่น ฮาร์ดดิสก์ และหน่วยความจำแฟลช เพื่อทำสำเนาข้อมูล มีคุณสมบัติป้องกันการเปลี่ยนแปลง หรือเขียนทับข้อมูลดิจิทัลต้นฉบับ

Forensic data acquisition หมายถึง

การสำเนาข้อมูลจากหลักฐานดิจิทัล  โดยทั่วไปจะมีการคำนวณค่าแฮชยืนยันความถูกต้องครบถ้วนของสำเนาข้อมูลได้

เครื่องทำสำเนาข้อมูลดิจิทัล คือ

เป็นอุปกรณ์ใช้ทำสำเนาข้อมูลจากวัตถุพยานประเภท ฮาร์ดิสก์ และหน่วยความจำแฟลช สามารถทำสำเนาข้อมูลจากสื่อบันทึกดิจิทัลต้นฉบับไปยังสื่อบันทึกข้อมูลดิจิทัลปลายทาง มีความสามารถบีบอัดข้อมูลสำหรับการตรวจพิสูจน์หลักฐาน และยืนยันความถูกต้องของข้อมูล

คุณลักษณะ 

- เป็นอุปกรณ์ที่มีคุณสมบัติทำสำเนาข้อมูลแบบการตรวจพิสูจน์หลักฐาน (Forensic) หรือมีการป้องกันการเปลี่ยนแปลง หรือเขียนทับข้อมูลดิจิทัลต้นฉบับ (write-Protected)
- สามารถรองรับการเชื่อมต่อ (interface)แบบ SATA/SAS ,USB 3.0 ,PCie ,Fire Wire, Ethernet ,IDE
- สามารถทำสำเนาข้อมูลเป็น disk to disk , bit for bit และทำสำเนาข้อมูลเป็น image แบบ DD และ E01
- สามารถจัดเตรียมพื้นที่การทำสำเนาข้อมูล หรือล้างข้อมูลโดยวิธีการ Wipe
- มีกระบวนการตรวจสอบความถูกต้องของข้อมูลโดยวิธีการ Hash ,MD5 ,SHA-1

FORENSIC IMAGER

 #เครื่องทำสำเนาหลักฐาน

Forensic Duplicator

#เครื่องทำสำเนาข้อมูลดิจิทัล

สามารถทำสำเนาข้อมูลจากต้นทางจำนวน 1 ตัว ไปยังปลายทางจำนวนไม่น้อยกว่า  2 ตัว แบบพร้อมกัน

Forensic Duplicator


* การตรวจพยานหลักฐานอิเล็กทรอนิกส์ในคอมพิวเตอร์จำเป็นต้องมีการทำสำเนาข้อมูลทั้งหมด

Forensic Imager
ใช้ในการสำเนาหลักฐานในรูปแบบของ Disk to File (Image) เป็นการเก็บหลักฐานโดยทำการสำเนาจาก Disk ต้นทาง ไปเป็นไฟล์ Disk Image (Raw, E01,..) ลงบนปลายทาง

Forensic Imager 

รูปจำลองทางการตรวจพิสูจน์หลักฐาน (Forensic image) หรือสำเนาของสื่อต้นฉบับ

ใช้ในการสำเนาหลักฐานในรูปแบบของ Disk to disk เป็นการเก็บหลักฐานโดยทำการสำเนาจาก Disk ต้นทาง ไปยัง Disk ปลายทาง

Disk to Disk

Tableau Forensic Duplicator TD2u


Forensic Imager Introduction




Forensic Duplicator TD3 Download



ที่มา:
กลุ่มงานตรวจพิสูจน์อาชญากรรมคอมพิวเตอร์ กองพิสูจน์หลักฐานกลาง
tableau
Guidance Software

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics #digitalforensics #investigation #cybercrime #fraud

Saturday, September 23, 2017

Digital Forensics:WIPE Part II

Digital Forensics:WIPE Part 2

 เทคนิคการเตรียม hard disk ไว้สำหรับเตรียมเก็บข้อมูลหรือทำสำเนาข้อมูล  คือการ Wipe  ซึ่งเราจะใช้อุปกรณ์ Tableau Forensic Duplicator (TD2)  ในการทดสอบครั้งนี้  เพื่อให้แน่ใจว่า hard disk ที่จะนำไปใช้สำหรับทำสำเนาข้อมูลไม่มีข้อมูลปนเปื้อนหรือสิ่งอื่นใดหลงเหลืออยู่ Hard disk 
Forensic Duplicator TD2
Standard operations:
  • Disk-to-Disk (clone) duplication
  • Disk-to-File (image) duplication
  • Format
  • Wipe
  • Hash (MD5 or SHA-1)


1. Hard disk ที่จะทำการ Wipe   ให้บันทึกรายละเอียด  Model: WDC WD5000AAKX-00ERMA0
                                              S/N: WD-WMC2E3267484 


2. ทำการเชือมต่อ Hard disk กับอุปกรณ์  Tableau Forensic Duplicator (TD2)

Forensic Duplicator TD2

3. ทำการเลือกคำสั่ง Wipe Disk


TD2 Duplicator

4. รอจนเครื่องทำงานเสร็จ  ทำการ export log file ออกมา เพื่อทำรายงาน

TD2 Duplicator

5. ตัวอย่าง Log file

Task: Wipe
Status: Ok
Created: 2018-08-10 14:39
Closed : 2018-08-10 18:26
User: Dforensic Examiner

Duplicator serial num: 01d21065
Duplicator firmware timestamp: Mar 27 2012 19:49:00
Duplicator firmware revision: 3.15
Duplicator log ID num: 121

--------------------------Wipe Options--------------------------

Wipe method: Multi-pass Write
# of sectors: 976,773,168 (500.1 GB)

--------------------------Dest-1 Disk---------------------------

Model: WDC WD5000AAKX-00ERMA0
S/N: WD-WMC2E3267484
Firmware Revision: 15.01H15
Capacity in sectors reported Pwr-ON: 976,773,168 (500.1 GB)
Capacity in sectors reported by HPA: 976,773,168 (500.1 GB)
Capacity in sectors reported by DCO: 976,773,168 (500.1 GB)
HPA in use: No
DCO in use: No
ATA Security in use: No
Cable/Interface type: SATA
ATA PIO mode: PIO 4
ATA DMA mode: UDMA 6

6. นำ Harddsik ที่ผ่านการ Wipe แล้ว แยกเก็บไว้ในตู้  เพื่อใช้ในเคสต่อไป


 หมายเหตุ ท่านสามารถศึกษาเครื่องมือ Tableau Forensic Duplicator (TD2) เพิ่มเติมได้ที่ website ด้านล่าง

Referent
https://www.guidancesoftware.com/tableau/hardware/td2u

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


#wipe #secureerase #diskwiping #Sanitization #Computer Forensics #DigitalForensics

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...