Saturday, August 8, 2020

DIGITAL FORENSICS:PALADIN and Autopsy ACQUISITION TOOL

DIGITAL FORENSICS:PALADIN and Autopsy ACQUISITION TOOL 

Forensic Data Collections with PALADIN

PALADIN Forensic  คือ ระบบปฏิบัติการลินุกซ์ Ubuntu ที่ถูกออกแบบและปรับแต่งเพื่อการทำงานด้านนิติวิทยาศาสตร์ดิจิตอล รองรับการทำสำเนาหลักฐานดิจิทัล ( forensics Image )

PALADIN Toolbox is the easiest way to image a device in a forensically sound manner.
All without the need of hardware write-blockers.
 

เตรียม อุปกรณ์และ ทดสอบก่อนไป Acquisition Tool On site step by step

1. Notebook HP 120 GB   (Evidence) 
2. PALADIN EDGE 64 (Version 8.01) USB boot
3. Autopsy 4.15 + Digital Forensics Laptop Workstation
4. External HDD WD SATA HDD 2 TB  (forensics Image)

Step 1  เข้าไป Download 
1.Navigate to www.sumuri.com. >. Sign into your account via the “My Account” menu. If you do not currently have an account you will need to register for a free account. and Download PALADIN ISO 
PALADIN EDGE 64
2. ทำการ create the PALADIN USB Boot and  you can use the ISO to make your own PALADIN USBs  > Rufus - https://rufus.akeo.ie   > 


Quick Summary to Boot PALADIN on a PC 
    3.1. Insert PALADIN DVD or USB. 
    3.2. Disable Secure Boot. 
    3.3. Set the boot order in the BIOS/UEFI Setup Menu to boot to PALADIN or choose to boot to PALADIN from the Boot Manager.


4. Booting PALADIN  USB on a Computer. >
       - Set the boot order in the BIOS/UEFI Setup
Forensic Mode
5. PALADIN Toolbox
      you can prepare the drive using the Disk Manager in the PALADIN Toolbox.

5.1 The default Time Zone in PALADIN is GMT. To change the time zone click on the Time and Date icon found at the bottom of the desktop to access its settings.  

Note: It may take a minute or two for the displayed system clock to update.
 
6. PALADIN Toolbox - Imaging a Drive
6.1 Logs in PALADIN Toolbox can be saved automatically to a destination drive of your choice.
Click the “Logs” icon in the upper right-hand corner of the PALADIN Toolbox Window.



  • Source = Select the physical or logical drive that you want to image.
  • Source =/dev/sda Kinston SUV400S37120G 111.79GB
  • Image Type = This is where you select the type of forensic image for the output or select “Device” to make a clone. 
  •  Image Type = EWF(E01)
  • EWF (Expert Witness Format or .E01)
  • Destination = This is the volume where you want your forensic image to go.
  • Destination =/dev/sdv1 WDC WD20NMVW-11AV353 E-2TB.4 1862.98GB ntfs  (read-Write)
  • Verify after creation = Select this if you want to hash the forensic image files after they have been created (SHA-1 and MD5).
  • Segment Size = Select this if you would like to divide your forensic image file into smaller segments or “chunks”. Due to Linux FAT32 limitations (VFAT), 2000 Mb is the largest size allowed
WD SATA HDD 2 TB(forensic image)
Start - Starts imaging once your parameters as set.
Image Details

  • check box Verify after creation  /Verify Button – The Verify Button will generate a MD5 and SHA1 hash for any device or forensic image selected.
  • Set Segment Size
  • Imaging to an Additional Drive or Creating Two Different Images PALADIN Toolbox supports imaging to two separate destinations or as a different format on a single destination drive as a different format by selecting the “Additional” box.
  • Start - Starts imaging once your parameters as set.
Process
Disk Manager
Imager Logs
 7. Navigate to the destination for the decrypted data, hashes and log reports
Log Report



8. Images made with PALADIN can immediately be processed with Autopsy (Digital Forensics Laptop Workstation)

After imaging with PALADIN start Autopsy and select “Create New Case”.
Enter a “Case Name” select your “Base Directory” (drive mounted read-write) for output.
9.Add a “Case Number” and “Examiner” name. 
10. Select “Image File” for your source and navigate to the forensic image file
11. Select and configure your “Ingest Modules”.  and Click “Finish” to begin the processing.
ingest modules utilized by autopsy
12.Autopsy provides an easy to use and intuitive interface that makes processing and finding data easy!
Operating System Information
Web Downloads
Shell Bags
Wireless Networks

13.After tagging and bookmarking data click the “Generate Report” button and select your report type.
Autopsy Forensic Report

Download paladi manual





สรุป 
    1.  PALADIN EDGE เป็นเครื่องมือที่ใช้ทำสำเนาหลักฐานไช้งานง่าย
    2. สามารถนำไปใช้ทำสำเนาหลักฐานในงานภาคสนามและนอกสถานที่ได้ (Onsite)
    3. มีเครื่องมือ Convert Forensic Image file 

    4. เป็นอีกTools ทางเลือกสำหรับ Digital forensics investigator 
    5. มีคู่มือแล Update เสมอ
    6. ใน PALADIN V.6 มีเอกสารทดสอบจากหน่วยงาน The Department of Homeland Security
     7. ให้เลือก Verify after creation และกำหนด Segment Size  และบีบอัดไฟล์
ในกรณีที่ Source Harddisk (2TB) เท่ากับขนาดของ Destination Harddisk (2TB)หลักฐาน *แนะนำให้เอา HDD ที่มีขนาดใหญ่กว่าฮาร์ดิสก์ต้นฉบับ
     8. หากต้องการสำเนาหลักฐาน 2 ชุดให้เลือกคำสั่ง Additional Imager  และเลือกตำแหน่งเก็บ forensic Image (Create two forensic images or clones at the same time)

Ref:


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud



Wednesday, August 5, 2020

Digital Forensics: Computer Forensics Fundamentals

Digital Forensics: Computer Forensics Fundamentals  

    01 Foundational concepts about the computer forensics field Understanding of hexadecimal and hashing in relations to computer forensics An introductory understanding of what computer forensics is The process of collecting digital evidence How do create, mount and explore forensic digital images Considerations for first responders to a computer crime scene The course will consist of presentations to explain the concepts of computer forensics as well as demonstrations of proper collections of digital evidence.


    02 Understanding Hash and hexadecimal.

 Understanding of hexadecimal and hashing in relations to computer forensics An introductory understanding of what computer forensics is The process of collecting digital evidence How do create, mount and explore forensic digital images Considerations for first responders to a computer crime scene The course will consist of presentations to explain the concepts of computer forensics as well as demonstrations of proper collections of digital evidence.

    03 Understanding HW and filesytems
           001 Hardware Physical and Logical Copies.
           002 Hardware Devices, Files Systems and Operating Systems.

    04 Imaging software
             001 Creating a Forensic Disk Image.
             002 Add Evidience.
             003 Acquiring an Image.

    05 Image acquisition


    06 Mounting and Exploring an image file
              001 Mounting an Image.   
              002 Exploring the Image.

    07 First responder supplimental
             001 First Responders Guide to Collecting Evidence.

    08 Conclusion
            001 Conclusion and Wrap Up

Free Online   Digital Forensics

#digitalforensicsexaminer
#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Saturday, August 1, 2020

DIGITAL FORENSICS:ZIP PASSWORD BRUTEFORCE PART II

DIGITAL FORENSICS:ZIP PASSWORD BRUTEFORCE PART II


    วันนี้มาฝึก ทำ Lab โจทย์เราได้หลักฐานเป็นไฟล์ secret.zip  มา แต่โดนเข้ารหัสอยู่ ให้เราหารหัสผ่านของไฟล์  ZIP โหลดหลักฐานได้ที่ https://drive.google.com/file/d/10cDW00mnku9XU35erVvNUQrwp0m1IH4T/view?usp=sharing ชื่อไฟล์คือ secret.zip แต่ไฟล์นี้ถูกเข้ารหัสอยู่ ซึ่งเจ้าของข้อมูลก็ลืม password ในการเปิดไฟล์นั้นขึ้นมาอ่านแล้วด้วย  Hint: เจ้าของข้อมูลจำได้ว่า password มีขนาดไม่เกิน 4 ตัวอักษร เป็นภาษาอังกฤษตัวพิมพ์เล็ก และตัวเลข เท่านั้น *

1. ขั้นแรกให้ทำการใช้ เครื่องมือ
ZIP PASSWORD Crack คือ เครื่องมือที่เอาไว้ BRUTE FORCE รหัสผ่าน ของ ZIP FILE ที่ถูกเข้ารหัส

Download ZIP PASSWORD Pro

Virus Total
หลักจากโหลดโปรแกรม ZIP PASSWORD CRACKมาให้ลอง check virus
เลือกไฟล์ที่จะถอดรหัส ไฟล์ secret.zip 

 2. เตรียม เลือกวิธีการ BRUTEFORCE สำหรับถอดรหัส LOWERCASE LETTERS & Numbers / DIGITS  เจ้าของข้อมูลจำได้ว่า password มีขนาดไม่เกิน 4 ตัวอักษร เป็นภาษาอังกฤษตัวพิมพ์เล็ก
Password Length Range

3.  ทำการเริ่มถอดรหัสผ่าน  Start ZIP Testing



The correct Zip file password is:
Success

สรุป 
   ปัจจัยสำคัญคือ ความยาวของรหัสผ่าน, ความซับซ้อนของรหัส  สำหรับ BRUTEFORCE


ที่มา:



#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD 

#ไฟล์ ZIP ติด PASSWORD  แก้อย่างไร


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง ADMIN เพื่อแก้ไขต่อไป
ขอบคุณครับ

Thursday, July 30, 2020

DIGITAL FORENSICS:ICSI Certified Network Security Specialist (CNSS)

DIGITAL FORENSICS:ICSI Certified Network Security Specialist (CNSS)

วันนี้แนะนำคอร์สออนไลน์ฟรีสำหรับ Network Security รีบลงทะเบียนก่อนหมดเวลา

Free online cybersecurity courses

Certified Network Security Specialist (CNSS)

Use coupon code #StaySafeHome during checkout to claim your free access. Offer is valid till 31/08/2020.
Course Overview

Course curriculum

Exam and Lab Information

ICSI Certified Network Security Specialist (CNSS)



 นอกจากนี้ยังมี Course อื่น ICSI | CDFE Certified Digital Forensics Examiner

CDFE Certified Digital Forensics Examiner
 

ref:

ICSI,UK (International CyberSecurity Institute

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud #CPE #cpe free credits #FREE CPE


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น
* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ



Saturday, July 25, 2020

Mobile Forensics:UFED Touch Clone SIM Card

Mobile Forensics:UFED Touch Clone SIM Card

   
  วันนี้มาลอง Clone SIM Card โดยใช้เครื่องมือ cellebrite  UFED (Universal Forensic Extraction Device'  สามารถทำสำเนาข้อมูลใน SIM CARD ( SIM Card Clone)

ชุดตรวจพิสูจน์โทรศัพท์เคลือนที่ Cellebrite  UFED คือ

อุปกรณ์ตรวจพิสูจน์ สืบค้นพยานทางดิจิทัลจากเครื่องโทรศัพท์มือถือ ใช้สำหรับใช้ตรวจพิสูจน์หลักฐานโทรศัพท์เคลื่อนที่ โทรศัพท์สมาร์ทโฟน และอุปกรณ์พกพา

Clone SIM ID The “Clone SIM ID” option allows an investigator to create an exact replica of the original SIM ID and extract phone data without allowing the cellular device to connect to the internet, which preserves the current call and SMS history and no Faraday Bag is needed. This option also allows an investigator to manually enter the ICCID or IMSI of the SIM, if the SIM card is missing, so that they can create a SIM card that mimics the original SIM card. This option also allows an investigator to clone and extract data from the original SIM card if it is locked by a PIN.

1. To clone a SIM card ID, if you have the original SIM card, click the “OK” 

button on “Clone SIM ID”.Click “OK”
 on “Clone an existing SIM card”.
Insert The SIM Card into the matching size slot

Select the partition to read, “USIM (3GPP)” or “SIM
(GSM)” and click “OK”. Remove the SIM card that you want to clone and then insert the Target SIM
ID Access Card into the SIM card slot and click the right arrow to continue. 
The SIM ID will be cloned  .
On process

Insert Target Card > Continue
 blank sim card
 blank sim card


Extraction in Progress
Extraction Summary  >Finish


UFED Touch Clone SIM Card


ที่มา:


Credit: ขอขอบคุณ ผู้เชี่ยวทางด้านโทรศัพท์เคลื่อนที่ ผู้แนะนำและสอนเทคนิคต่างๆ และเป็นผู้อยู่เบื้องหลัง Blog ของเรา  

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#อุปกรณ์ซิมการ์ดโคลน  #โคลนนิ่งSim #วิธีการโคลนSIM #WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD #MobileForensics # forensic_data_collections

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...