Saturday, November 17, 2018

DIGITAL FORENSICS:Data Leakage Case

DIGITAL FORENSICS:Data Leakage Case

The CFReDS Project


Scenario Overview

‘Iaman Informant’ was working as a manager of the technology development division at a famous international company OOO that developed state-of-the-art technologies and gadgets.

One day, at a place which ‘Mr. Informant’ visited on business, he received an offer from ‘Spy Conspirator’ to leak of sensitive information related to the newest technology. Actually, ‘Mr. Conspirator’ was an employee of a rival company, and ‘Mr. Informant’ decided to accept the offer for large amounts of money, and began establishing a detailed leakage plan.

‘Mr. Informant’ made a deliberate effort to hide the leakage plan. He discussed it with ‘Mr. Conspirator’ using an e-mail service like a business relationship. He also sent samples of confidential information though personal cloud storage.

After receiving the sample data, ‘Mr. Conspirator’ asked for the direct delivery of storage devices that stored the remaining (large amounts of) data. Eventually, ‘Mr. Informant’ tried to take his storage devices away, but he and his devices were detected at the security checkpoint of the company. And he was suspected of leaking the company data.

At the security checkpoint, although his devices (a USB memory stick and a CD) were briefly checked (protected with portable write blockers), there was no evidence of any leakage. And then, they were immediately transferred to the digital forensics laboratory for further analysis.

The information security policies in the company include the following:

  1. Confidential electronic files should be stored and kept in the authorized external storage devices and the secured network drives.

  2. Confidential paper documents and electronic files can be accessed only within the allowed time range from 10:00 AM to 16:00 PM with the appropriate permissions.

  3. Non-authorized electronic devices such as laptops, portable storages, and smart devices cannot be carried onto the company.

  4. All employees are required to pass through the ‘Security Checkpoint’ system.

  5. All storage devices such as HDD, SSD, USB memory stick, and CD/DVD are forbidden under the ‘Security Checkpoint’ rules.

In addition, although the company managed separate internal and external networks and used DRM (Digital Rights Management) / DLP (Data Loss Prevention) solutions for their information security, ‘Mr. Informant’ had sufficient authority to bypass them. He was also very interested in IT (Information Technology), and had a slight knowledge of digital forensics.

In this scenario, find any evidence of the data leakage, and any data that might have been generated from the suspect’s electronic devices.

[Please note: If you have any issues clicking on the links to download the files, please "right click" and choose to "save as".]


Target Systems and Devices

TargetDetailed Information
Personal Computer
(PC)
TypeVirtual System
CPU1 Processer (2 Core)
RAM2,048 MB
HDD Size20 GB
File SystemNTFS
IP Address10.11.11.129
Operating SystemMicrosoft Windows 7 Ultimate (SP1)
Removable Media #1
(RM#1)*
TypeUSB removable storage device
Serial No.4C530012450531101593
Size4 GB
File SystemexFAT
Removable Media #2
(RM#2)
TypeUSB removable storage device
Serial No.4C530012550531106501
Size4 GB
File SystemFAT32
Removable Media #3
(RM#3)
TypeCD-R
Size700 MB
File SystemUDF

* Authorized USB memory stick for managing confidential electronic files of the company.


Acquired Data Information

Personal Computer (PC) – 'DD' Image

Download Linkspc.7z.001pc.7z.002pc.7z.003 (total 5.05 GB compressed by 7zip) - hash
Imaging S/WFTK Imager 3.4.0.1
Image Formatconverted from VMDK

Personal Computer (PC) – 'EnCase' Image

Download Linkspc.E01pc.E02pc.E03pc.E04 (total 7.28 GB compressed by EnCase) - hash
Imaging S/WEnCase Imager 7.10.00.103
Image FormatE01 (Expert Witness Compression Format) converted from VMDK

Removable Media #1 (RM#1) – 'EnCase' Image

Download Linksrm#1.E01 (total 74.5 MB compressed by EnCase) - hash
Imaging S/WFTK Imager 3.3.0.5 (write-blocked by Tableau USB Bridge T8-R2)
Image FormatE01 (Expert Witness Compression Format)

* The RM#1 is not required to

Removable Media #2 (RM#2) – 'DD' Image

Download Linksrm#2.7z (total 219 MB compressed by 7zip) - hash
Imaging S/WFTK Imager 3.3.0.5 (write-blocked by Tableau USB Bridge T8-R2)
Image FormatDD

Removable Media #2 (RM#2) – 'EnCase' Image

Download Linksrm#2.E01 (total 243 MB compressed by EnCase) - hash
Imaging S/WEnCase Imager 7.09.00.111 (write-blocked by Tableau USB Bridge T8-R2)
Image FormatE01 (Expert Witness Compression Format)

Removable Media #3 (RM#3) – 'Raw / CUE' Image

Download Linksrm#3-type1.7z (total 92.8 MB compressed by 7zip) - hash
Imaging S/WFTK Imager 3.3.0.5
Image FormatRAW ISO / CUE (sometimes BIN / CUE)*

* The RAW ISO file is a raw sector-by-sector binary copy of tracks in the original disk, and the CUE file is a plain-text file which stores the information of disk and tracks.

Removable Media #3 (RM#3) – 'DD' Image

Download Linksrm#3-type2.7z (total 78.6 MB compressed by 7zip) - hash
Imaging S/WFTK Imager 3.3.0.5 + bchunk (http://he.fi/bchunk)
Image FormatDD converted from ‘RAW ISO + CUE’

Removable Media #3 (RM#3) – 'EnCase' Image

Download Linksrm#3-type3.E01 (total 90.2 MB compressed by EnCase) - hash
Imaging S/WEnCase Imager 7.09.00.111
Image FormatE01 (Expert Witness Compression Format)


Additional Data Information

Seed Files

Download Linksseed-files.7z (total 150 MB compressed by 7zip) - hash
File Information- Seed files stored in RM#1 and a shared network drive
- Base files for creating seed files were randomly selected from Govdocs1
- The first page of each seed file was manually added
Seed file list and hash values


Digital Forensic Practice Points

The followings are the summary of detailed practice points related to above images.

Practice PointDescription
Understanding
Types of Data Leakage
- Storage devices
      > HDD (Hard DiskDrive), SSD (Solid State Drive)
      > USB flash drive, Flash memory cards
      > CD/DVD (with Optical Disk Drive)
- Network Transmission
      > File sharing, Remote Desktop Connection
      > E-mail, SNS (Social Network Service)
      > Cloud services, Messenger
Windows Forensics- Windows event logs
- Opened files and directories
- Application (executable) usage history
- CD/DVD burning records
- External devices attached to PC
- Network drive connection traces
- System Caches
- Windows Search databases
- Volume Shadow Copy
File System Forensics- FAT, NTFS, UDF
- Metadata (NTFS MFT, FAT Directory entry)
- Timestamps
- Transaction logs (NTFS)
Web Browser Forensics- History, Cache, Cookie
- Internet usage history (URLs, Search Keywords…)
E-mail Forensics- MS Outlook file examination
- E-mails and attachments
Database Forensics- MS Extensible Storage Engine (ESE) Database
- SQLite Database
Deleted Data Recovery- Metadata based recovery
- Signature & Content based recovery (aka Carving)
- Recycle Bin of Windows
- Unused area examination
User Behavior Analysis- Constructing a forensic timeline of events
- Visualizing the timeline


Questions

  1. What are the hash values (MD5 & SHA-1) of all images?
    Does the acquisition and verification hash value match?
  2. Identify the partition information of PC image.
  3. Explain installed OS information in detail.
    (OS name, install date, registered owner…)
  4. What is the timezone setting?
  5. What is the computer name?
  6. List all accounts in OS except the system accounts: Administrator, Guest, systemprofile, LocalService, NetworkService. (Account name, login count, last logon date…)
  7. Who was the last user to logon into PC?
  8. When was the last recorded shutdown date/time?
  9. Explain the information of network interface(s) with an IP address assigned by DHCP.
  10. What applications were installed by the suspect after installing OS?
  11. List application execution logs.
    (Executable path, execution time, execution count...)
  12. List all traces about the system on/off and the user logon/logoff.
    (It should be considered only during a time range between 09:00 and 18:00 in the timezone from Question 4.)
  13. What web browsers were used?
  14. Identify directory/file paths related to the web browser history.
  15. What websites were the suspect accessing? (Timestamp, URL...)
  16. List all search keywords using web browsers. (Timestamp, URL, keyword...)
  17. List all user keywords at the search bar in Windows Explorer. (Timestamp, Keyword)
  18. What application was used for e-mail communication?
  19. Where is the e-mail file located?
  20. What was the e-mail account used by the suspect?
  21. List all e-mails of the suspect. If possible, identify deleted e-mails.
    (You can identify the following items: Timestamp, From, To, Subject, Body, and Attachment)
    [Hint: just examine the OST file only.]
  22. List external storage devices attached to PC.
  23. Identify all traces related to ‘renaming’ of files in Windows Desktop.
    (It should be considered only during a date range between 2015-03-23 and 2015-03-24.)
    [Hint: the parent directories of renamed files were deleted and their MFT entries were also overwritten. Therefore, you may not be able to find their full paths.]
  24. What is the IP address of company’s shared network drive?
  25. List all directories that were traversed in ‘RM#2’.
  26. List all files that were opened in 'RM#2’.
  27. List all directories that were traversed in the company’s network drive.
  28. List all files that were opened in the company’s network drive.
  29. Find traces related to cloud services on PC.
    (Service name, log files...)
  30. What files were deleted from Google Drive?
    Find the filename and modified timestamp of the file.
    [Hint: Find a transaction log file of Google Drive.]
  31. Identify account information for synchronizing Google Drive.
  32. What a method (or software) was used for burning CD-R?
  33. When did the suspect burn CD-R?
    [Hint: It may be one or more times.]
  34. What files were copied from PC to CD-R?
    [Hint: Just use PC image only. You can examine transaction logs of the file system for this task.]
  35. What files were opened from CD-R?
  36. Identify all timestamps related to a resignation file in Windows Desktop.
    [Hint: the resignation file is a DOCX file in NTFS file system.]
  37. How and when did the suspect print a resignation file?
  38. Where are ‘Thumbcache’ files located?
  39. Identify traces related to confidential files stored in Thumbcache.
    (Include ‘256’ only)
  40. Where are Sticky Note files located?
  41. Identify notes stored in the Sticky Note file.
  42. Was the ‘Windows Search and Indexing’ function enabled? How can you identify it?
    If it was enabled, what is a file path of the ‘Windows Search’ index database?
  43. What kinds of data were stored in Windows Search database?
  44. Find traces of Internet Explorer usage stored in Windows Search database.
    (It should be considered only during a date range between 2015-03-22 and 2015-03-23.)
  45. List the e-mail communication stored in Windows Search database.
    (It should be considered only during a date range between 2015-03-23 and 2015-03-24.)
  46. List files and directories related to Windows Desktop stored in Windows Search database.
    (Windows Desktop directory: \Users\informant\Desktop\)
  47. Where are Volume Shadow Copies stored? When were they created?
  48. Find traces related to Google Drive service in Volume Shadow Copy.
    What are the differences between the current system image (of Question 29 ~ 31) and its VSC?
  49. What files were deleted from Google Drive?
    Find deleted records of cloud_entry table inside snapshot.db from VSC.
    (Just examine the SQLite database only. Let us suppose that a text based log file was wiped.)
    [Hint: DDL of cloud_entry table is as follows.]

            CREATE TABLE cloud_entry
            (doc_id TEXT, filename TEXT, modified INTEGER, created INTEGER, acl_role INTEGER,
            doc_type INTEGER, removed INTEGER, size INTEGER, checksum TEXT, shared INTEGER,
            resource_type TEXT, PRIMARY KEY (doc_id));
  50. Why can’t we find Outlook’s e-mail data in Volume Shadow Copy?
  51. Examine ‘Recycle Bin’ data in PC.
  52. What actions were performed for anti-forensics on PC at the last day '2015-03-25'?
  53. Recover deleted files from USB drive ‘RM#2’.
  54. What actions were performed for anti-forensics on USB drive ‘RM#2’?
    [Hint: this can be inferred from the results of Question 53.]
  55. What files were copied from PC to USB drive ‘RM#2’?
  56. Recover hidden files from the CD-R ‘RM#3’.
    How to determine proper filenames of the original files prior to renaming tasks?
  57. What actions were performed for anti-forensics on CD-R ‘RM#3’?
  58. Create a detailed timeline of data leakage processes.
  59. List and explain methodologies of data leakage performed by the suspect.
  60. Create a visual diagram for a summary of results.

Answers

Look at the answers [PDF



หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Friday, November 16, 2018

Digital Forensics: CYBER FORENSICS ASSOCIATE (CFA)

Digital Forensics: CYBER FORENSICS ASSOCIATE (CFA)

Digital Forensics Certifications

The Cyber Forensics Associate(C|FA)  certification demonstrates an individual’s knowledge on how to detect hacking attacks and properly extract evidences to report the crime and conduct audits to prevent future attacks. Individuals who learn the principles of digital forensics can become invaluable members of incident handling and incident response teams.

หลักสูตร Cyber Forensics Associate

Passed CYBER FORENSICS ASSOCIATE (CFA)


The purpose of the Cyber Forensics Associate credential is to validate the candidate's skills to identify an intruder's footprints and to properly gather the necessary evidence to prosecute in the court of law.
หลักสูตรการพิสูจน์หลักฐานไซเบอร์

CYBER FORENSICS ASSOCIATE

 CYBER FORENSICS ASSOCIATE EXAM OBJECTIVES

Analysis 

Analyze forensic images
Apply procedural concepts required to use forensic tools
Apply basic malware analysis using NIST accepted forensic techniques and tools
Identify anti-forensics techniques
Determine the important content of event logs in forensics
 

Discovery

Apply procedural concepts necessary to detect a hidden message inside a picture
Analyze a conversation between two endpoints from a PCAP file
Recognize that devices are kept in the same state as they were found
Determine how to gather evidence in a forensically sound manner
Apply procedural concepts required to discover evidence on different file systems
Apply procedural concepts required to gather evidence on different operating systems
Identify proper steps in network capture
Given a scenario, determine evidence of email crimes
 

Evidence 

Determine and report logon/logoff times for a specific user
Verify the authenticity of evidence (e.g., hash value)
Summarize the proper handling of evidence outlined the process for creating a forensically sound image
Apply evidence collection to the chain of custody
Discriminate between a live acquisition and static acquisition
 

Documentation and Reporting 

Apply forensic investigation methodology
Identify the steps necessary to validate an emergency contact list for incident response
Analyze a scene to determine what should be visually documented
Report findings from a malware analysis
Identify the elements of a complete forensic report
Communicate the results of an investigation to an internal team

Cyber Forensics Fundamentals

Identify different types of cyber crimes
Communicate incident handling and the response process
Distinguish between steganography and cryptography





Cyber Forensics Associate Exam outlines


  • Computer Forensics Fundamentals
  • Incident Response
  • Digital Evidence
  • Understanding File Systems
  • Windows Forensics
  • Network Forensics and Investigating Network Traffic
  • Stenography
  • Analyzing Logs
  • E-mail Crime and Computer Forensics
  • Writing Investigation Report

Successfully pass the CFA exam.

 Cyber Forensics Associate - 40 questions (50 minutes)

Cyber Forensics Associate References

paper :

National Initiative for CybersecurityEducation (NICE)Cybersecurity Workforce Framework

NIST Special Publication 800-181

Guide to Integrating ForensicTechniques into IncidentResponse  NIST  800-86

 

Review CYBER FORENSICS ASSOCIATE (CFA)

จุดประสงค์ ของใบประกาศตัวนี้ เน้นประเมินทักษะของของผู้สอบ  ที่มีเนื้อหาเกี่ยวกับการวิเคราะห์หาพยานหลักฐานทางดิจิทัล, กระบวนการวิเคราะห์พยานหลักฐาน หาร่องรอยผู้บุกรุก ตลอดจนเครื่องมือในการเก็บรวบรวมและวิเคราะห์พยานหลักฐานที่จำเป็นเพื่อดำเนินคดีในศาล

ความคิดเห็นส่วนตัว ผมเป็นคนหนึ่งที่ทำงานด้าน Digital Forensics  ลองทำข้อสอบแล้ว   ค่อนข้างเน้นทฤษฎี ที่เป็นเอกสารของทาง EC-Council CHFI และอื่นๆ และเวลาจำกัดมาก หากไม่เตรียมตัวสอบ โอกาสผ่านค่อนข้างยาก เนื่องจาก 

ลักษณะข้อสอบ > เรียงลำดับ Process  , multiple choice ตัวเลือกตอบ 2 และ 3 , ลากใส่ช่องให้ถูกต้อง,เลือก True ,False ,Drop down ,มีข้อคำนวน    หลายข้อแค่อ่านโจทย์ ก็หมดเวลาแล้ว 

เช่น คุณต้องเข้าใจ  Key Step in Forensic Investigations  และเรียงลำดับได้

Key Step in Forensic Investigations

ขั้นตอนและกฎหลักในการดำเนินการทางนิติวิทยาคอมพิวเตอร์ ประกอบด้วย

  1. การระบุอาชญากรรมทางคอมพิวเตอร์ที่เกิดขึ้น
  2. การรวบรวมหลักฐานเบื้องต้น
  3. การขอหมายศาลเพื่อยึดหลักฐานที่เกี่ยวข้อง
  4. การดำเนินการตอบสนองเบื้องต้น
  5. การยึดหลักฐานที่เกี่ยวข้องในที่เกิดเหตุ
  6. การนำส่งหลักฐานไปยังห้องปฏิบัติการทางนิติวิทยาศาสตร์อย่างปลอดภัย
  7. การสร้างสำเนาของหลักฐาน
  8. การสร้างข้อมูลการเข้ารหัส เช่น MD 5 เพื่อใช้ในการตรวจสอบความสมบูรณ์ของข้อมูลหลักฐาน
  9. การจัดเตรียมกระบวนการก็บรักษาหลักฐาน
  10. การป้องกันหลักฐานโดยจัดเก็บไว้ในที่ปลอดภัย
  11. การตรวจสอบสำเนาของหลักฐาน
  12. การจัดทำรายงาน
  13. การนาส่งรายงานให้ผู้ที่เกี่ยวข้อง
  14. การเข้าร่วมในการพิจารณาคดีความในชั้นศาล ในกรณีที่จำเป็น


ให้วิเคราะห์เอกสาร Evidence Chain of Custody ว่ามีข้อผิดพลาดตรงไหน
Evidence chain of custody


สำหรับคนที่ทำงานด้านนี้ Digital Forensics ,Cyber Forensics ,Blue Team, CFA Cert ตัวนี้เป็นอีกตัวหนึ่งที่น่าสนใจ ควรมีไว้เป็นอย่างยิ่งและราคาไม่แรงมากครับ  

EC-Council Associate Series

หลักสูตรการพิสูจน์หลักฐานไซเบอร์

อบรม CYBER FORENSICS ASSOCIATE เนื้อหาการอบรม จำนวน 3 วัน

วันที่ 1
09:00 - 12:00 น.
• กระบวนการวิเคราะห์หลักฐานทางดิจิทัล
• เครื่องมือสำหรับวิเคราะห์หลักฐานทางดิจิทัล
• วิเคราะห์ภัยคุกคามประเภทมัลแวร์ด้วยเทคนิคและเครื่องที่ผ่านมาตรฐาน NIST
• เทคนิคการต่อต้านการวิเคราะห์พยานหลักฐานทางดิจิทัล
• เนื้อหาที่สำคัญของ event log ที่้ใช้ส าหรับวิเคราะห์หลักฐานทางดิจิทัล
• การตรวจจับข้อความที่ซ่อนอยู่ในรูปภาพ
• การวิเคราะห์ข้อความที่ส่งผ่านไฟล์ PCAP

13:00 - 16:00 น.
• การจัดการกับวัตถุพยาน
• การเก็บรวบรวมร่องรอยหลักฐานทางดิจิทัล
• ขั้นตอนการค้นหาร่องรอยหลักฐานทางดิจิทัลบนระบบไฟล์แต่ละแบบ
• ขั้นตอนการค้นหาร่องรอยหลักฐานทางดิจิทัลบนระบบปฏิบัติการ

วันที่ 2
09:00 - 12:00 น.
• ขั้นตอนการดักจับข้อมูลในระบบเครือข่าย
• ร่องรอยหลักฐานทางดิจิทัลจากการโจรกรรมทางอีเมล
• การตรวจสอบเวลาเข้าใช้และเลิกใช้ระบบของผู้ใช้แต่ละคน
• ตรวจสอบความถูกต้องของพยานหลักฐาน
• สรุปขั้นตอนการจัดการพยานหลักฐาน

13:00 - 16:00 น.
• กระบวนการในการสร้างอิมเมจของพยานหลักฐาน
• กระบวนการในการปฏิบัติงานกับพยานหลักฐานทางดิจิทัล
• แยกแยะระหว่างการรวบรวมพยานหลักฐานแบบ live acquisition กับแบบ static acquisition
• ระเบียบวิธีการสืบสวนหลักฐานทางดิจิทัล
• ระบุขั้นตอนที่จำเป็นในการตรวจสอบความถูกต้องสำหรับรายชื่อผู้ติดต่อในกรณีฉุกเฉินเมื่อเกิดเหตุการณ์
ผิดปกติ (Incident)
• วิเคราะห์เหตุการณ์เพื่อตัดสินใจเขียนสรุปรายงาน

วันที่ 3
09:00 - 12:00 น.
• รายการวิเคราะห์การค้นพบมัลแวร์
• ส่วนประกอบของรายงาน-ผลการตรวจพิสูจน์
• ติดต่อสื่อสารเกี่ยวกับผลลัพธ์ที่ได้จากการสืบสวนกับทีมงานภายใน

13:00 - 16:00 น.
• อธิบายความแตกต่างของประเภทอาชญกรรมทางคอมพิวเตอร์
• การจัดการกับเหตุการณ์ผิดปกติและขั้นตอนการตอบสนองต่อเหตุการณ์ดังกล่าว
• แยกความแตกต่างระหว่าง เทคนิคในการซ่อนข้อมูล (steganography) กับ วิทยาการเข้ารหัสลับ

(cryptography)
หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น


ที่มา:

Eccouncil-associate-programs-eha-cfa
Digital Forensics: CYBER FORENSICS ASSOCIATE (CFA)

Photo by : Certiport

  • Ec-Council Associate Ceertications From Certiport 

Photo by : Ec-Council

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD #MOBILEFORENSICS #สอบ Cyber Forensics Associate #การพิสูจน์หลักฐานไซเบอร์ #นิติวิทยาศาสตรไซเบอร์ 


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น
* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

Saturday, November 10, 2018

Digital Forensics:eLearnSecurity Certified Digital Forensics

Digital Forensics:eLearnSecurity Certified Digital Forensics Professional (eCDFP) – a friendly dive into digital forensics

เตรียมความพร้อมเพื่อสอบ Certified Digital Forensics

eLearnSecurity Certified Digital Forensics Professional

Through the ongoing war raged against the security community by big name companies who want to charge my kidneys for a certification I have found solace in eLearn’s platform. As such I will be taking multiple of their courses, though this is the first I have seen to the end (yes I got certified, woot). The course itself was very well done, having very straightforward material (sans multiple spelling/grammatical errors, if you are a Grammar Nazi this course may bug you a bit) and labs (though the test was a little iffy, which I’ll get into later). Another nice part about this course is that all of the tools used are open source/freeware, so you don’t need to buy some fancy product to do your job (though I will admit some of them can be nice). The course itself covers the following sections:

  1. Introduction to Digital Forensics
  2. Data Acquisition
  3. Data Representation & Files Examination
  4. Disks
  5. File Systems
  6. Windows Forensics
  7. Network Forensics
  8. Log Analysis
  9. Timeline Analysis
  10. Reporting (important but.. yawn)
 
The introduction modules was actually very important (sometimes I feel you can skip the intro sections for things). However, they covered some very key points that tie into forensics (especially digital) specifically. These points are:

  • The main goal of a digital investigation is to answer the 5 “W’s”, i.e. the What, Where, When, Who, and How related to a digital incident. This may seem kind of obvious, but it is extremely important to help out the client and build a strong case so you can charge a criminal if it goes to court or even just help them get their insurance claim (as is the case for a lot of ransomware cases). Those 5 “W’s” are a great guide to help start a forensics investigator throughout the investigation.
  • Digital forensics goes beyond just “finding out what the attacker did” and forensics investigators can work in a plethora of different fields, from law enforcement agencies, internal investigation teams, consulting, and even larger scope international investigative teams (whether through law enforcement or an international organization).
  • Digital forensics has a life cycle, and like most things it can be repeated over and over again. This life cycle is “Acquisition <> Analysis <> Presentation” and it is important to remember that each step could be revisited multiple times throughout an investigation as new pieces of evidence are brought to light or old ones need to be re-examined.
  • Forensics (in general) takes a scientific method approach, and if you remember from high school that means lots of note taking as a process should be able to be repeated to lead to the same result or conclusion. This is highly important and depending on the scope of the case or type of the case it may be extremely important to document everything that you do, so find a note taking method that works for you and stick with it.


The rest of the course is pretty straightforward and I won’t dive to deep into it here or go into exactly what each step is as I figure the module names are pretty descriptive of what they are all about. What I do think this course lacks is some more in depth experience with some of the artifacts that you come across. Like some of the labs could have been made (especially the Windows’ ones) a little bit longer and little bit less straightforward, more real life scenario. For example, MFT in NTFS file systems is a huge forensic artifact for seeing what was on disk and when. I’ve always used it to help build a timeline for cases irl, and though it is talked about in the course, it isn’t really explored in the labs or in the exam. Another thing that this course lacks is a look at linux forensics, though parts may be slightly covered (think log analysis) in some modules there is no talk about location, per say or meaning. Though in the wild, let’s be honest, you will definitely encounter some nix boxes (including mac), but you will most definitely encounter Windows, a lot of Windows boxes. That being said the course does do a good job of covering that, including older systems and going into detail about artifact differences between different versions.

Let’s talk about the exam. There are 30 questions total, all multiple choice, since I had to take it twice I can tell you that they are not the same each time. You get one 24 hour period to take it and the first 15 questions are completely theory; and if you have gone through the material they will be pretty straightforward to answer, though some you may have to look back at the material for. The last 15 are a little trickier as they require actual hands on forensics. There were a few questions that I complained about (like one question suggesting that “bad” images contain “kittens”, when really the only suspicious photos were of things from the tv series “Mr. Robot”, and there was no photos of kittens or options to select 0). Other than that though I’d suggest taking it slow, and thinking through each artifact. What is nice is that you don’t have to write up a report (I’m sure version 2 may change this), so get it while you can.

Overall, it was an enjoyable experience and I think it would be beneficial for noobs and 1337s alike. I also found that if you are a red teamer this may be a good/cheaper way to get an inside scoop on the artifacts that forensic examiners look at, and their process, which may in turn help you cover your tracks when performing an exercise. That being said, if you do decide to take the course, glhf, and take it slow, really ingesting what each artifact is and how it affects the investigation will help in the long run outside of the course.


Digital Forensics Professional (DFP) — Launch Webinar



Some Tools Gone Over:
Autopsy https://www.sleuthkit.org/autopsy/
OSFMount https://www.osforensics.com/tools/mount-disk-images.html
FTK Imager http://accessdata.com/product-download/ftk-imager-version-3.4.3
dd https://linux.die.net/man/1/dd
DCode http://www.digital-detective.net/digital-forensic-software/free-tools/
Volatility http://www.volatilityfoundation.org/
HashCalc http://www.slavasoft.com/hashcalc/
Bambiraptor https://www.brimorlabs.com/tools/
ExifTool https://www.sno.phy.queensu.ca/~phil/exiftool/
ExifReader http://www.takenet.or.jp/~ryuuji/minisoft/exifread/english/
PhotoRec http://www.cgsecurity.org/wiki/PhotoRec
Active Disk Editor http://www.disk-editor.org/
WinHex https://www.x-ways.net/winhex/
bulk_extractor https://github.com/simsong/bulk_extractor
MFTCarver https://github.com/jschicht/MftCarver
SleuthKit http://www.sleuthkit.org/
PowerForensics https://github.com/Invoke-IR/PowerForensicshttps://github.com/Invoke-IR/PowerForensics
Immunity http://www.immunityinc.com/products-immdbg.shtml
WinDBG https://docs.microsoft.com/en-us/windows-hardware/drivers/download-the-wdk
Wireshark https://www.wireshark.org/

 reference:

https://inurdata.sh/elearnsecurity-certified-digital-forensics-professional-ecdfp-a-friendly-dive-into-digital-forensics/ 

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Saturday, November 3, 2018

Digital Forensics: case study กรณี การขโมยบัญชีธนาคารออนไลน์ด้วยการเปลี่ยนซิม

Digital Forensics: case study กรณี การขโมยบัญชีธนาคารออนไลน์ด้วยการเปลี่ยนซิม

พนักงานเจ้าหน้าที่จะรวบรวมพยานหลักฐานตาม พ.ร.บ. คอมพิวเตอร์


แนวทางการชั่งน้ำหนักพยานหลักฐาน (ม.๑๑)

จะลดความเสี่ยง และ เพิ่มความน่าเชื่อถือ ได้อย่างไร

พยานหลักฐานสำหรับความผิดเกี่ยวกับคอมพิวเตอร์

 


Digital Forensics: Case Study


ทีมา:
 บทบาทหน้าที่ของ กรรมการบริษัทในการกำกับดูแล เทคโนโลยีสารสนเทศตามกฎหมาย IT”วันอังคารที่ ๑๔ สิงหาคม ๒๕๖๑ โรงแรมสวิสโซเทล เลอ คองคอร์ด กรุงเทพฯ  ETDA

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

DIGITAL FORENSICS:Search And Seizure Requirements For Mobile Devices

DIGITAL FORENSICS:Search And Seizure Requirements For Mobile Devices

ข้อกำหนดในการค้นหาและยึดอุปกรณ์โทรศัพท์มือถือ

ข้อกำหนดในการค้นหาและยึดอุปกรณ์เคลื่อนที่  (Mobile Devices) เช่นเดียวกับคอมพิวเตอร์และข้อมูลดิจิทัลบนคลาวด์  เริ่มต้นด้วยหมายค้นหรือหมายเรียกที่ศาลออกให้ ใบสำคัญแสดงสิทธิจะระบุรายการอุปกรณ์หรือพื้นที่เฉพาะของโทรศัพท์มือถือหรืออุปกรณ์มือถือที่อาจตรวจสอบได้ เมื่อยึดอุปกรณ์มือถือได้ตามหมายค้นแล้วจะมีการปฏิบัติตามขั้นตอนมาตรฐานสำหรับการรวบรวมหลักฐานที่เกิดเหตุจากอุปกรณ์พกพามือถือ ขั้นตอนเหล่านี้ระบุไว้ด้านล่างเพื่อให้แน่ใจว่าคุณปฏิบัติตามขั้นตอนที่เป็นไปตามมาตรฐานการยอมรับในศาล


Is There Additional Evidence?

มีหลักฐานเพิ่มเติมหรือไม่? 

ก่อนที่จะจัดการกับอุปกรณ์มือถือใด ๆ ให้ตัดสินใจว่าต้องการข้อมูลอื่นจากโทรศัพท์เช่น DNA หรือลายนิ้วมือ หากเป็นเช่นนั้นให้ปฏิบัติตามขั้นตอนการเก็บหลักฐานในสถานที่เกิดเหตุ  เพื่อรวบรวมดีเอ็นเอและเก็บรักษาหลักฐานนั้นก่อนดำเนินการใด ๆ จัดการกับหลักฐานดิจิทัลเพื่อรักษาความน่าเชื่อถือของพยานหลักฐาน


Turn Off The Device

 มีความเป็นไปได้สูงที่ข้อมูลจะสูญหายหากแบตเตอรี่หมดหรือมีสัญญาณเครือข่ายเกิดขึ้นทำให้บันทึกการโทร (call log) หรือข้อมูลอื่น ๆ ที่กู้คืนได้ถูกเขียนทับ อย่าลืมบันทึกไว้ในบันทึกว่าโทรศัพท์อยู่ในสถานะใดเมื่อคุณมาถึงที่เกิดเหตุ

Charge The Device

ชาร์จอุปกรณ์หากมีความจำเป็นต้องเปิดโทรศัพท์ไว้ควรชาร์จโทรศัพท์ไว้   จากนั้นควรปิดก่อนการขนส่ง

Transport The Devices

การขนส่งอุปกรณ์หลักฐานเพื่อปกป้องอุปกรณ์และป้องกันการใช้งานโดยไม่ได้ตั้งใจในระหว่างการขนส่งโทรศัพท์ควรบรรจุในภาชนะที่แข็งและปลอดภัย 

The Evidence Bag

ถุงเก็บหลักฐาน (evidence bag) ใช้สำหรับใส่หลักฐาน ที่ปิดสนิทเพื่อ จำกัดการเข้าถึงและขั้นตอนการติดฉลากสำหรับแสดงรายละเอียดของหลักฐานในแบบฟอร์ม ใส่โทรศัพท์มือถือ ไว้ในถุงฟาราเดย์(Faraday bag)แล้วใส่ในกระเป๋าเก็บหลักฐาน



หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น


* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD


Thursday, November 1, 2018

วิชาที่เกี่ยวข้องกับ Digital Forensics

วิชาที่เกี่ยวข้องกับ Digital Forensics

วิชาที่เกี่ยวข้องกับ Digital Forensics

รายวิชาในหลักสูตรที่เกี่ยวข้อง: การพิสูจน์หลักฐานจากทางดิจิทัล (

Digital Forensics)

อาชญากรรมทางอินเทอร์เน็ตและการป้องกัน (Internet Crime and Protection)

หลักพื้นฐานของระบบเครือข่ายคอมพิวเตอร์การรักษาความปลอดภัยของเทคโนโลยีสารสนเทศในระบบเครือข่าย อาชญากรรมทางอินเทอร์เน็ตและการป้องกัน กฎหมายที่เกี่ยวกับความปลอดภัยของเทคโนโลยีสารสนเทศ

Fundamentals of computer network systems. Security of information technology in

network systems. Internet crimes and protection. Laws related to information technology security.

นิติดิจิทัลและกฎหมายที่เกี่ยวข้อง  (Digital Forensics and Related Laws)

ระบบดิจิทัลและการสื่อสารเบื้องต้น ข้อมูลดิจิทัลและการจัดเก็บ ระบบเครือข่ายและความปลอดภัย ของเครือข่าย ระบบฐานข้อมูล การประมวลผลภาพดิจิทัล การสืบค้นข้อมูลส าหรับการสืบสวนอาชญากรรม ซอฟต์แวร์ที่ใช้ในการพิสูจน์หลักฐานทางนิติวิทยาศาสตร์เครือข่ายเชิงนิติวิทยาศาสตร์ จริยธรรมและกฎหมายที่เกี่ยวกับนิติดิจิทัล

Introduction to digital system and communication. Digital data and storing.

Network systems and security. Database system. Digital image processing. Information retrieval for

crime investigation. Software for forensic examination. Network forensics. Ethics and laws related

to digital forensics.

ที่มา :หลักสูตรวิทยาศาสตรมหาบัณฑิตสาขาวิชานิติวิทยาศาสตร์ มหาวิทยาลัยศิลปากร

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...