Saturday, July 25, 2020

Digital Forensics:Android Forensics Challenge

Digital Forensics:Android Forensics Challenge

 

 

Download files: 

LINK: data1

LINK: data2


For evidence in the data1 folder, perform analysis and answer the following questions: 

  1. When was the usagestats file created? 
  2. On that same day, when and for how long was a messaging app used? 
  3. True or false: Twitter application has been used on the device between Apr 6th 2020, 03:51 AM, GMT and Apr 7th
    2020, 03:51AM GMT.
  4. True or false: User has logged into an active Twitter account on this device.

 

For evidence in the data2 folder, perform analysis and answer the following questions: 

  1. One application has the debuggable flag set to 1. What is its APPID? 
  2. Where is the data of that app stored? 
  3. Does it have any supplementary GIDs, and if yes, what are they? 
  4. Which three packages share the user ID 1001

 

 Credit:eforensicsmag

 

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

 

Digital Forensics: CelleBrite Physical Analyzer AKSFRIDGE.SYS Blue Screen Error

Digital Forensics:  CelleBrite Physical Analyzer AKSFRIDGE.SYS Blue Screen Error


CelleBrite Physical Analyzer AKSFRIDGE.SYS Blue Screen Error

The Cellebrite UFED Physical Analyzer  


Cellebrite - BSoD When Installing or Upgrading Win10


The  old HASP driver can cause Blue Screens in the following cases. The message is:

Stop code: PAGE_FAULT_IN_NONPAGED_AREA

What failed: aksfridge.sys

Case #1 - When installing Cellebrite on a Windows 10 Version 2004 OS.

Case #2 - When upgrading to Windows 10 Version 2004 (the latest as of May, 2020) when Cellebrite is already installed.

Resolution - The old HASP driver needs to be upgraded before you can proceed. Download and install the updated HASP driver from https://digitalintelligence.com/files/HASPUserSetup.exe before installing Cellebrite or upgrading Windows to version 2004.


How to troubleshoot and fix Windows 10 blue screen errors


Refer:

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD

Tuesday, July 21, 2020

Digital Forensics:Windows prefetch part II

Digital Forensics:Windows prefetch part II


  วันนี้มาลองทดสอบ Windows prefetch  โดยใช้เครื่องมือ WinPrefetchView
สำหรับผู้ใช้งาน Windows ถ้าสังเกตจะพบโฟลเดอร์ ใน C:\Windows\Prefetch ไม่ทราบว่าใช้ทำอะไร มีประโยชน์อะไรบางหรือเปล่า แล้วทำไมมีไฟล์อยู่เต็มไปหมด

Windows Prefetch คืออะไร

เป็นเทคนิคของ Windows ที่ใช้สำหรับการเก็บข้อมูลโปรแกรมที่เราเรียกใช้งานบ่อยๆ โดยจะเก็บเป็นไฟล์ข้อมูลเล็กๆ นามสกุล .pf  ใช้สำหรับการเก็บข้อมูลโปรแกรมที่เราเรียกใช้งานบ่อยๆ ในครั้งต่อไปที่เราเรียกใช้โปรแกรม  จะทำให้เรียกใช้โปรแกรมต่างๆ ได้เร็วขึ้น

Windows Prefetch จึงมีความสำคัญต่อการสืบสวนนิติดิจิตอล 
สำหรับผู้ตรวจสอบทางนิติวิทยาศาสตร์ สามารถใช้ Windows Prefetch  เป็นหลักฐานการใช้งานโปรแกรม   พวกเขาสามารถพิสูจน์ได้ว่าผู้ต้องสงสัยที่รันโปรแกรมเช่น CCleaner เพื่อปกปิดการกระทำผิดที่อาจเกิดขึ้น หากโปรแกรมถูกลบไปตั้งแต่นั้นไฟล์ prefetch อาจยังคงมีอยู่ในระบบเพื่อแสดงหลักฐาน การใช้ไฟล์ prefetch 
ประโยชน์อีกอย่างหนึ่งคือ ใช้ Windows Prefetch ในการตรวจสอบมัลแวร์ซึ่งสามารถช่วยผู้ตรวจสอบในการกำหนดว่าเมื่อใดจะมีการเรียกใช้โปรแกรมที่เป็นอันตราย เมื่อรวมสิ่งนี้เข้ากับการวิเคราะห์ Timeline  ผู้ตรวจสอบสามารถระบุไฟล์ที่เป็นอันตรายเพิ่มเติม จำนวนครั้งที่โปรแกรม run หรือ execute จากการดาวน์โหลดหรือสร้างขึ้นในระบบและช่วยระบุสาเหตุที่แท้จริงของเหตุการณ์ได้  


WinPrefetchView เป็นฟรีโปรแกรมที่ใช้ดูประวัติรายละเอียดต่าง ๆ ของ Prefetch

ซึ่งสามารถแสดงรายละเอียดได้ดีกว่าดูจากโฟลเดอร์ของ Prefetch และแสดงผลในรูปแบบที่เข้าใจได้ง่าย


prefetch files are found in the directory C:\Windows\Prefetch. Prefetch files have a .pf extension
Prefetch files contain the following metadata:
  • The name of the corresponding executable
  • The number of times the executable has been run
  • The size of the prefetch file
  • The files and directories that were referenced during the application startup (this is what Windows wants to trace)
  • Information related to the volume that the executable is on, including the volume path and serial number.


Here’s a sample of some prefetch files from my test host:

C:\Digital Forensics Tools.exe    = DIGITAL FORENSICS TOOLS.EXE-52542CA8.pf


\127.0.0.1\C$\Digital Forensics Tools.exe  = DIGITAL FORENSICS TOOLS.EXE-95205518.pf

C$Digital Forensics Tools.exe


H:\Digital Forensics Tools.exe  = DIGITA~1.EXE-7EC97B47.pf

F:\Digital Forensics Tools.exe  = DIGITAL FORENSICS TOOLS.EXE-1C722632.pf

  • z:\Digital Forensics Tools.exe is executed
  • it is mapped to its UNC path 
  • \\Localhost\Z\Digital Forensics Tools.exe = DIGITAL FORENSICS TOOLS.EXE-7DE46524.pf



Note that I’ve got several applications with the same name, but a different location. That is evidence by the somewhat-similar hashes, and in many application’s cases, is likely indicative of folder structure change.

สรุปจากทดสอบ
    1 เมื่อUser.เปิดไฟล์ Digital Forensics Tools.exe ใน Drive ที่แตกต่างกัน ค่า prefetch files ที่ได้จึงมีแตกต่างกันตาม 
ทีมา :  

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD

Saturday, July 18, 2020

DIGITAL FORENSICS:MAGNET AXIOM MEMORY ANALYSIS

DIGITAL FORENSICS:Magnet AXIOM  Memory Analysis


    วันนี้ลองมาใช้เครื่องมือสำหรับวิเคราะห์ memory ที่ไม่ฟรีบ้างครับ ว่าทำงานอะไรบ้าง 
Magnet AXIOM เป็นซอฟต์แวร์สำหรับตรวจพิสูจน์หลักฐานดิจิทัล พัฒนาโดยบริษัท Magnet Forensics ช่วยในการตรวจพิสูจน์ข้อมูลดิจิทัล เพื่อสืบค้นและวิเคราะห์ข้อมูล ที่บันทึกอยู่ในสื่อบันทึกข้อมูลดิจิทัลต่าง ๆ อีกทั้งยังสามารถสืบค้นและวิเคราะห์ข้อมูล  memory ,windows usb,ระบบโซเลียลเน็ตเวิร์ค ข้อมูลร่องรอยการใช้งานระบบโซเลียลเน็ตเวิร์คได้อีกด้วย  ซอฟต์แวร์นี้ต้องซื้อ license ครับ

Tools 
-  Magnet AXIOM
- Windows  workstation

ทำการสร้างเคส Create New case และใส่รายละเอียด
เลือก Evidence Source  > เลือก Computer

เลือก Memory 
WIN-TTUMF6EI3O3-20140203-123134.raw

 ทำการเลือก Profile >windows WIN7SP1x86
เริ่มทำการ analyze evidence

Search in Process

Operating System

เลือกหัวข้อ Malware Finder เพื่อดู Process ที่น่าสงสัย
 สังเกตุ Process 1524   สังเกต Details
เลือก ดูในส่วน Connections > Matching >Process 1524
runddl32.exe
*MSDCSC is a common path utilized by DarkComet. Most likely a default path in the builder.
Export > Process 1524   ที่สงสัยแล้วเอาไป scan virus
 พบว่า Process 1524 ที่ export ออกมามีมัลแวร์น่าสงสัย ทำการ Up ไฟล์ ไปที่ virustotal


 ทำการ Upload ไฟล์ไปที่ sandbox analysis
Backdoor DarkKomet


Magnet AXIOM 2.0 — Memory Analysis



สรุป ผลการใช้งานเบื้องต้นโปรแกม Magnet AXIOM ในการวิเคราะห์ memory  เนื่องด้วยในการทดสอบนี้เป็นการวิเคราะห์Static analysis เบื้องต้นเท่านั้นเพื่อไม่ได้ลงลึก  ครับขออภัยมาณที่นี้ด้วยครับ

    - ทำงานได้รวดเร็ว ขึ้นอยู่กับ spec เครื่อง workstation 
    - ยังรองรับเฉพาะ windows memory  เท่าที่เห็นในส่วน Profile
    - ใช้งานง่าย มี GUI ไม่ต้องใช้ commandline สามารถศึกษาคู่มือและวิดิโอจากเว็บไซต์ได้
    - หากต้องใช้งานสำหรับ malware analysis อาจต้องมีเครื่องมืออื่นเพิ่มเติมสำหรับงานโดยเฉพาะ
    
     
Ref:

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Friday, July 17, 2020

Digital Forensics:SANS Community CTF 2020

Digital Forensics:SANS Community CTF 2020


The all-new (and FREE) SANS Community #CTF You can register at http://tomahawque.com
ซึ่ง SANS มีจัดกิจกรรม Capture The Flag (CTF) แบบนี้เป็นประจำทุกปี โดยกิจกรรมจะเปิดและปิดเป็นช่วงงต้องติดตามในตารางของแต่ละช่วง  Event  คุณสามารถเข้าไปลงทะเบียนรอบต่อไปได้ที่ http://tomahawque.com

Event info & Code of Conduct
 CHALLENGES










ที่มา:

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD #ฝึกทำLAB #CTF

Saturday, July 11, 2020

DIGITAL FORENSICS:RETRIEVE THE HOSTNAME FROM A MEMORY DUMP

DIGITAL FORENSICS:Retrieve the hostname from a memory dump

วันนี้เรามาหา  Computer name จาก memory dump มี lab ให้ทดลองทำครับ

This tutorial explains how to retrieve the hostname of the machine from which the memory dump has been taken.

Memory Forensics Lab
- Download Memory
-Volatility Framework 2.6.1


First, we want to get the profile:

 .\volatility.exe --plugins="C:\Users\AAA\Downloads\VolatilityWorkbench-v2.1\profiles" --filename="F:\18 Computer Forensics\CTF\Hackfest.tn\Q1\MEM\lab.raw" imageinfo


Then, we dump the hives to get the offset of the ones where we will find the hostname:

.\volatility.exe --plugins="C:\Users\AAA\Downloads\VolatilityWorkbench-v2.1\profiles" --filename="F:\18 Computer Forensics\CTF\Hackfest.tn\Q1\MEM\lab.raw" --profile=Win7SP1x64_23418 --kdbg=0xf80002846070 hivelist


Now, let's dump the registry key where the hostname will be revealed:

 .\volatility.exe --plugins="C:\Users\AAA\Downloads\VolatilityWorkbench-v2.1\profiles" --filename="F:\18 Computer Forensics\CTF\Hackfest.tn\Q1\MEM\lab.raw" --profile=Win7SP1x64_23418 --kdbg=0xf80002846070 printkey -o 0xfffff8a000024010 -K 'ControlSet001\Control\ComputerName\ComputerName'


Ref:

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น


* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD

Tuesday, July 7, 2020

DIGITAL FORENSICS:CyberArk Trustee certification

DIGITAL FORENSICS:CyberArk Trustee certification

Free online cybersecurity courses

CyberArk เป็นผู้ให้บริการ Privileged Access Security ชั้นนำสำหรับปกป้อง Privileged Account ที่ใช้ในการเข้าถึงระบบสำคัญขององค์กร ไม่ว่าจะเป็นเซิร์ฟเวอร์ ฐานข้อมูล หรือแอปพลิเคชัน


หลักสูตรนี้ 
Introduction to CyberArk Privileged Access Security

ผู้ที่ได้ใบรับรองนี้ได้พิสูจน์ความรู้พื้นฐาน เกี่ยวกับ  Privileged Access Security ในโลกไซเบอร์ ของค่าย CyberArk

Summary

The course Introduction to CyberArk Privileged Access Security is designed for anyone who is interested in learning about privileged account security. It is highly recommended for any professional who will be part of a CyberArk project.
The course is a free on-line course. This free, entry-level certification course enables a participant to:
Explain the importance of Privileged Access Security.

Computer Requirements: Speakers or headphones are required in order to watch and listen to the multimedia course presentation slides and the videos provided as part of the case study assessment.
Duration: The duration of the course is approximately two hours.
Relevant Certification: Trustee (Level 1) Details
Outline:
Introduction to Privileged Access Security
Business Risk – Insider Threat
Business Risk – Targeted Attacks and the "attack life-cycle"
Business Risk – Ransomware The CyberArk Solutions
CyberArk Blueprint for PAS Success
Introduction to DevOps and Secrets Management
[OPTIONAL] CyberArk and the CyberArk Solution


Duration

2 hours 
DIGITAL FORENSICS CyberArk Trustee certification

ref:

https://training.cyberark.com/

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud #CPE #cpe free credits #FREE CPE


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น
* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...