Friday, January 6, 2023

Digital Forensics:How to Aquire vmdk to dd using FTK Imager

Digital Forensics:How to Aquire vmdk to dd using FTK Imager

วันนี้จะมาแนะนำการทำ Image file จาก vmdk  ให้เป็นไฟล์ DD โดยใช้ FTK Imager


How to Aquire vmdk to dd using FTK Imager

VMDK (short for Virtual Machine Disk) is a file format that describes containers for virtual hard disk drives to be used in virtual machines like VMware Workstation or VirtualBox.

Initially developed by VMware for its proprietary[1] virtual appliance products, VMDK became an open format[2] with revision 5.0 in 2011, and is one of the disk formats used inside the Open Virtualization Format for virtual appliances.

Refer: https://en.wikipedia.org/wiki/VMDK

Requisites

Steps to create forensic image (vmdk ) using FTK Imager

Step 1: Download and extract FTK Imager lite version on Forensics Workstation 

Install FTK Imager on Forensics Workstation 

In this step we download FTK Imager lite version from their official website and extract the downloaded zip file on our Forensics Workstation . The lite version contains the only necessary files to run FTK Imager tool from the Forensics Workstation .

Install FTK Imager on USB drive  In this step we download FTK Imager lite version from their official website and extract the downloaded zip file on our USB drive. The lite version contains the only necessary files to run FTK Imager tool from the USB drive.

Step 2: Running FTK Imager exe from Forensics Workstation 



Step 3: Running FTK Imager for forensic image acquisition

To create a forensic image 1. Do one of the following:   Click File > Create Disk Image.   Click the Create Disk Image button on the Toolbar


Step 4: Selecting the Source to acquire image

In the Select Source dialog box, select the source you want to make an image of

How to Aquire vmdk to dd using FTK Imager
Select File *.Vmdk

Step 5: Setting the acquired image destination and image file type

Step 6: Filling in the evidence item information

Step 7: Selecting image destination


Step 8:After the images are successfully created, the Drive/Image Verify Results box shows detailed image information, including MD5 and SHA1 check sums, and bad sectors. 
The Image Summary also includes the data you entered in the Evidence Item Information 




Refer:Booting a forensic image in VirtualBox with FTK Imager

Mount Disk Images (VDMK) With OSFMount



หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD #คดีอาชญากรรมคอมพิวเตอร์ #พยานหลักฐานดิจิทัล

DIGITAL FORENSICSP:How to Scan Multiple URLs from Command Line using VirusTotal?

How to Scan Multiple URLs from Command Line using VirusTotal?

VT-Domain-Scanner

Takes an input file with domains or IPs on each line and passes them to the VT API then writes the following items to a CSV. IPs that are put through this scanner is effectively doing a HTTP/HTTPS check to see if a direct IP connection is malicious.

  • Most recent scan date/time
  • Sanitized domain
  • Count of non-clean detections
  • Total AV scans
  • Link to scan results
How to Scan Multiple URLs from Command Line using VirusTotal?
API Key

How to Scan Multiple URLs from Command Line using VirusTotal?
Daily quota 500 lookups / day
URL List
How to Scan Multiple URLs from Command Line using VirusTotal?

VT_Domain_Scanner_py3.exe
How to Scan Multiple URLs from Command Line using VirusTotal?

Step 1 #VT_Domain_Scanner_py3.exe
Step 2 #API Key
Step 3 #public
Step 4#URL_List.txt
Results.csv
How to Scan Multiple URLs from Command Line using VirusTotal?


How to Scan Multiple URLs from Command Line using VirusTotal?
Step 5:URL double check 




อ่านเพิ่ม :FILE HASH CHECK WITH VIRUSTOTAL
                vtlookup


Referent:
VirusTotal-Tools



หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud #MagnetForensic

Sunday, January 1, 2023

Digital Forensics: Challenge #2 - User Policy Violation Case

 Digital Forensics: Challenge #2 - User Policy Violation Case

  • Challenge #2 - User Policy Violation Case

  • This is another digital forensics image that was prepared to cover a full Windows Forensics course.

    1. System Image: here
    2. Hashes & Password: here
    3. Other download URLs from (Archive.org) could be found here: here
Digital Forensics: Challenge


    You can use the image to learn the following:
    1. File Carving, Custom Carving, and Keyword Searching
    2. File System Forensics - NTFS
    3. Deep Windows Registry Forensics: System and User Hives
      • SYSTEM
      • SOFTWARE
      • SAM
      • NTUSER.DAT
      • USRCLASS.DAT
    4. Other Windows Files: LNK, Jump Lists, Libraries, etc

      1. Jump Lists

      2. Microsoft Windows Recent Items

      3. UserAssist  Applications launched via Explorer "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist"

        Digital Forensics: Challenge #2 - User Policy Violation Case
      4.  RegistryExplorer shows it has decrypted the ROT13 encryption
      5. Digital Forensics: Challenge #2 - User Policy Violation Case

    5. Application Compatibility Cache (ShimCache)

      1. Artifacts of Application Compatibility Cache

    6. Analyzing Windows Search (Search Charm)
    7. Analyzing Thumb Caches
    8. Analyzing Prefetch Files


      1. Winprefetchview , NirSoft
      2. Analyzing Prefetch Files
    9. Analyzing Recycle Bin(s)

      1. Analyzing Recycle Bin

    10. USB Forensics
    11. Events Analysis
    12. Email Forensics: Web and Outlook
    13. Browser Forensics: Internet Explorer and Google Chrome
    14. Skype Forensics  
TeamViewer log > C:\Program Files ( x86 )\TeamViewer\Connections_incoming.txt 
  • It was being operated remotely  2016/06/21 12:14:29.
Digital Forensics: Challenge #2 - User Policy Violation Case

      deleted file.
    This screenshot is from Autopsy and shows a forensic investigation of a deleted file.

    $I5Z6K8U : The highlighted ASCII text:  C:\Users\Hunter\Pictures\fakeporn

    $I1H3FM.7z is a Windows deleted-file artifact created by the Recycle Bin

    : The highlighted ASCII text:  C:\Users\Hunter\Pictures.7z


    This image covers most if not all of the recent system artifacts that you might encounter. Let me know if you need any help or if you are an instructor and want the answers to each part of the case. I will only send the answers to verified instructors.

    End of Case.


Extension Mismatch 
Extension Mismatch

Extension Mismatch



Refer:Ali Hadi

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD #คดีอาชญากรรมคอมพิวเตอร์ #พยานหลักฐานดิจิทัล

Sunday, December 25, 2022

Digital Forensics:Browser forensics

Digital Forensics:Browser forensics

Browsers keep a record of visited websites, which can reveal a user's search history and potential malicious activity.

Kroll Artifact Parser And Extractor (KAPE)

Kroll Artifact Parser And Extractor (KAPE) 

KAPE gives you access to targets and modules for the most common operations required in forensic exams, helping investigators gather a wider range of artifacts 

ChromeHistoryView

Description. ChromeHistoryView is a small utility that reads the history data file of Google Chrome Web browser, and displays the list of all visited Web pages 


Google Chrome’s browsing data is stored in the user’s AppData\\Local\\Google\\Chrome\\User Data\\Default directory.

Digital Forensics:Browser forensics

Browser forensics Lab

Digital Forensics:Browser forensics

Instruction

We found an attacker who compromised the machine and download malware . Please help find the URL which use by attacker.

Download History


Hint

Reveal download activity from Browser History.


Step 1.  KAPE Collecting Browser Artifacts

KAPE Collecting Browser Artifacts

Step 2. Chrome History provides analysts with the following information: 

Chrome History View is a free utility developed by NirSoft

To run it, navigate to where you downloaded and extracted the tool Chrome History View.exe and double click the file.


Chrome History View is a free utility
When it opens load the history from the users data folder  from the Advance Options menu.

Chrome History View
Then navigate to the path of the Users profiles from your Kape collection.
Click OK and it displays the Chrome history.

Chrome History

Step 3. SQLite Viewer Web App

SQLite Viewer Web is a free, web-based SQLite Explorer, inspired by DB Browser for SQLite and Airtable.

SQLite Viewer Web App
URL Table
SQLite Viewer Web App

Or  SQLite Browser 

SQLite Browser

Open SQLite Browser  and navigate to the Chrome database stored at C\Users\<User Name>\AppData\Local\Google\Chrome\User Data\Default.

SQLlite Browser


Digital Forensics:Browser forensics



Step 4. Check suspicious websites

Digital Forensics:Browser forensics

Step 5. Tracking Changes Over Time The Wayback Machine

Digital Forensics:Browser forensics

Q1. What sites have been visited in the last 
days ?
Ans:

Q2.How many times a site was visited (most frequency information) and what the page title by User visits  ?
Ans:

Q3.What is the name of the malicious file that was downloaded?
Ans:

Hint

Reveal download activity from Browser History.

Q4.What is the profile of the user who downloaded the malicious file? 
Ans:

Q5.The URL, page title, and referring website for visits used by the insider threat.
Ans:

อ่านเพิ่มเติม: How to analyze WebCacheV01.dat

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูล  เผยแพร่ความรู้และให้โอกาสในการค้นคว้าหาข้อมูลเพื่อการศึกษา   บุคคลที่สนใจโดยทั่วไป รวมถึงนักเรียน นิสิต นักศึกษา  ในการเรียนรู้เท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD

Friday, December 16, 2022

Digital Forensics:Meta Information

Digital Forensics:Meta Information

ข้อมูล EXIF ​​คืออะไร?

EXIF (Exchangeable Image File Format) คือมาตรฐานที่กำหนดข้อมูลเฉพาะที่เกี่ยวข้องกับภาพหรือสื่ออื่นๆ ที่ถ่ายด้วยกล้องดิจิทัล โดยสามารถจัดเก็บข้อมูลสำคัญต่างๆ เช่น การรับแสงของกล้อง วันที่/เวลาที่ถ่ายภาพ และแม้แต่ตำแหน่ง GPS

ExifTool is a platform-independent Perl library plus a command-line application for reading, writing and editing meta information

ExifTool ใช้ในการอ่านและเขียนข้อมูลเมตาในไฟล์ประเภทต่างๆ ดาวน์โหลดเครื่องมือ EXIF

File Types using Exiftool

Step 1. #CD C:\Users\ ...\Downloads\exiftool-12.51

E:\Software\exiftool-12.51

Step 2: # C:\Users\ ...\Downloads\exiftool-12.51>"exiftool(-k).exe" -filetype DSCN0010.jpg

Digital Forensics:Meta Information
The basic way of using the exiftool utility on Windows, is similar to the command used below:
#"exiftool(-k).exe" DSCN0010.jpg

Digital Forensics:Meta Information


Step 3: From the snapshot, we can gather the following useful information:
1. File Size: 162 KB
2. File Creation Date: 2022:11:30 15:28:23+07:00
3. File Type: JPG
4. File Name: DSCN0010.jpg
5.GPS Date/Time                   : 2008:10:23 14:27:07.24Z
6.GPS Latitude                    : 43 deg 28' 2.81" N
7.GPS Longitude                   : 11 deg 53' 6.46" E
8.Make                                   : NIKON
9.Camera Model Name          : COOLPIX P6000

ค้นหา “ละติจูด GPS” และ “ลองจิจูด GPS” ในหน้าต่างผลลัพธ์

Generate a single report for  photo.
#C:\Users\...\Downloads\exiftool-12.51>"exiftool(-k).exe" -a -u -g1 -w %f.txt DSCN0010.jpg

Digital Forensics:Meta Information

Digital Forensics:Meta Information

Step 4: generate a single report with all the information
# "exiftool(-k).exe" *.jpg -csv > report.csv

Digital Forensics:Meta Information


Digital Forensics:Meta Information

Step 5:Verify  pic2map 

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics
#digitalforensics #investigation #cybercrime #fraud

Data Breach Check

Data Breach Check Data Breach Check EP.4 “คิด ก่อน Prompt” AI อาจช่วยคุณทำงานได้เร็วขึ้น แต่บางครั้ง…ข้อมูลสำคัญก็อาจ “หลุดออกไป” โดยไม่รู้...