0% found this document useful (0 votes)
11 views42 pages

DF Module1

Digital forensics involves the collection, preservation, analysis, and presentation of computer-related evidence to determine past actions on a computer system. Its primary goals include aiding in the recovery of evidence for legal purposes, identifying perpetrators, and ensuring the integrity of digital evidence. The digital forensic process consists of four main steps: collection, examination, analysis, and reporting, followed by an initial response phase after an incident is detected.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views42 pages

DF Module1

Digital forensics involves the collection, preservation, analysis, and presentation of computer-related evidence to determine past actions on a computer system. Its primary goals include aiding in the recovery of evidence for legal purposes, identifying perpetrators, and ensuring the integrity of digital evidence. The digital forensic process consists of four main steps: collection, examination, analysis, and reporting, followed by an initial response phase after an incident is detected.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Q1. What is digital Forensic?

What are the goals of


digital forensics?
Digital forensic is collection, preservation, analysis and presentation of computer-related
evidence. It determines the past actions that have taken place on a computer system using
computer forensic techniques. Digital/Computer forensics is the process of methodically
examining computer media (hard disks, diskettes, tapes, etc.) for evidence.

1.1.2 Why is Digital Forensics Important? 1. A few criminals are becoming smarter. So data-
hiding techniques which includes encryption and steganography. The evidence of criminal
activity is placed in such a way where traditional search methods cannot able to find it.
Encryption: Scrambling data, for example an e-mail message, so that it cannot be readable
to the interceptor. Steganography: It is nothing but hiding a message into a larger file,
typically in photographic image or sound file. a Scanned with OKEN Scanner Digital Forensics
(MU) 1-2 Introduction to Digital Forensics 2. Computer forensics isn't just about "detective
work" - searching for and trying to find out information. Computer forensics is also worried
with: Sensitive data handling responsibly and confidentially. Taking precautions to not nullify
findings by corrupting data. Taking precautions to make certain the integrity of the
information. Staying within the regulation and guidelines of evidence.

1.1.3 Digital Forensic Process Steps

Explain the process of digital forensics. For forensic investigation there are following four
common steps: 1. Collection 2: Examination 3. Analysis 4. Reporting MU - May 16 Collection
Examination Analysis Reporting Fig. 1.1.1: The forensic process 1. Collection : This is the first
phase in forensic process. In this phase data is identified, labelled and recorded and
gathering the data and physical evidence related to the incident being invested is done.
Simultaneously integrity of the chain of custody is also preserved. 2. Examination: In this
phase from the collected data identify and extract the pertinent information, using proper
forensic tools and techniques and also maintain integrity of the evidence. 3. Analysis: In this
phase results of the examination phase are analyzed. From the analysis usefu answers to the
questions are generated which are presented in the previous phases. Most probably the
case gets solved in this phase. 4. Reporting: In the reporting phase the results of the analysis
are done, which contains: The information pertinent to the case. Actions that have been
accomplished actions left to be performed. Moves left to be performed. Advocated
enhancements to processes and tools.

1.2 Digital Forensics Goals The following are the primary goals of employing digital forensics:
o It aids in the recovery, analysis, and preservation of computer and associated materials in
order for the investigating agency to submit them as evidence in a court of law. o It aids in
determining the reason for the crime and the identify of the primary perpetrator. o Creating
processes at a suspected crime scene to guarantee that the digital evidence gathered is not
tainted. o Data collection and duplication: Recovering lost files and partitions from digital
media in order to extract and evaluate evidence. o Allows you to rapidly discover evidence
and evaluate the possible impact of harmful action on the victim. o Creating a computer
forensic report that provides a comprehensive report on the investigative process. o Keeping
the evidence safe by adhering to the chain of custody.

Explain the phase after detection of incident?


1.7 Phase after Detection of an Incident

The phase after detection of the Incident is Initial Response which is depicted in Fig. 1.7.1.
section discusses the activities of the initial response which is the phase after detection a
incident. In this section we will see what actions the organization will take after detecting
computer security incident.

Initial Response Phase

When computer security incident occurred the organization will face many challenges. So t is
a need of process that supports the following:

Quick and effective decision making.

Quick gathering of information in a forensically sound manner.

Proper escalation of the incident.

Quick notification of the participants required to assemble your [Link] meet the
challenges, a documented and well-rehearsed process is required. Fig. 1.7.1 illustrates the
initial response [Link] Preliminary Information
The initial steps of any investigation are to get enough data to decide a proper response.
That is the objective of the initial response stage. Your organization's initial response ought
to incorporate exercises, for example, the accompanying:

1. Receiving the initial notification of an incident.

2. Recording the details after the initial notification.

3. Assembling the CSIRT.

4. Performing traditional investigative steps.

5. Conducting interviews.

6. Determining whether the incident is highlighted or [Link] Steps to Take

1-14

The other reason for the initial response stage is to document steps that should be
mconding the subtle elements of an incident in a composed manner, your organization will
have exact number of the kind of attacks that happens, their recurence, the harms brought
about by the attacks, and the impacts these attacks had on your organization. Such
measurements are bec measuring the return en investment (OD for having a formalized
incident response program

1. Establishing an incident natification procedure

To fabricate a strong incident response program participation of every one of your employe
is required in your organis Non incident response ought to be everybody's top priority,
fundamental to build up a nonfication technique for clients to report potential computer
security incidents. Az a major aspect of your carent security awareness program, you ought
advise the end clents of how to report incidents by telephone, email, intranet site, or other
ystem). Likewise think about making as a computer security awareness notice that has the
suitable instrument to report a potential computer security incident. Making the inciden
response handle clear to dients will maintain a strategic distance from confusion.

2. Recording the details after initial detection

To develop an organized incident response program checklists are required. So initial respon
checklist is there the record the details after the initial notification of an incident

Initial Response Checklists

The initial response checkist is a mechanismiot recording the mported incident. The initial
response checklist is divided into two separate points

General information

b. More specific detals

General Information

General Information does not contain more technical information. This information is used
respond the end user the following information:

Date the incident was detected.

Contact information of the person completing the form.

Contact information of the person who detected the incident,

The type of [Link] Specific Details


The members of the CSBRT use the checklist to address the technical details surrounding the
Incident. It le important for the CSIRT members to personally respond to obtain and recoind
this information.

The initial response checkdin it used to address the following soure

Maks and model of the relevant systems

System detalls

Operating system

The systems primary use

System administrator for the byttamos

Network address or IP address of the minant system.

The ryttems network

Whether there is a modest onnection to the system(s

Criticat information that may have reuded on the systemisi

Incident containment

Whether the Incident is in progress or ongoing


Whether network monitoring network monitoring is required or being conducted

Whether the rystem is still connected to the Intemet/network if not, who authorized the
removal of the system from the network and when it will be put back online

for the relevant systems Whether backup tapes exist for the ever

Whether there requirement to keep knowledge knowledge of the incident on a "need-to-

know basis

Whether any remedial steps have been taken so far (such as packet filtering new control
lists, new firewall rules, or some other countermeasuret

Whether information collected is being stored

protected tamper-proof

Preliminary inwestigation

The IP addresses involved in the Indderit.

Whether any investigative steps or actions have already been taken.

Whether a forensic duplication of the pertinent systems needs to be copy of the relevant
system will doCase Notes

1-16
Checklists are too complicate. The alternative to checklist is case notes Case notes is
documentation which records the steps that are taken during your incident response proces
This is the duty of the member of CSIRT to maintain well-written notes of the detal
surrounding of the incident.

Incident Declaration

It is important to understand that the reported activity is computer security incident you
come across a suspicious activity which presents an incident but you are not sam about it
then consider it as an incident until it is proven.

To avoid spending time on no incident, there are a few questions that can be considered:

Was there a scheduled system or network outage that caused resources to be unavailable
during the time the incident was reported?

Was there an unscheduled and unreported outage of a network service provider the caused
resources to be unavailable during the time the suspected incident we reported?

Was the affected system recently upgraded, patched, reconfigured, or otherwist modified in
such a way as to cause the suspicious activity that was reported?

Was testing being performed on the network that would lock out accounts or caust
resources to be unavailable?

For insider incidents, are there any justifications for the actions an employee ha taken that
remove or lessen the suspicions?

In case when incident is occur and you are not able to tell it immediately at this time assign
the incident a case or incident number, making it a real incident worth investigating.

3. Assembling the CSIRT


Several organizations form the e CSIRTs. Some CSIRTs are formed dynamically according
particular response to an incident, instead of an established, centralized team which
dedicated to responding to incidents. To prepare a team for a particular incident,
organization have to identify the types of skills and resources required from the rest of the
organization to respond to that particular incident. There is no need to go through
notification procedures and increase of an incident until a certain incident occurred.
Preparing the CSIRT requires the following activities:Determining increase procedures

Implementing notification procedures

1-17

Scoping an incident and gathering the proper resources, including assigning a team leader
and the technical staff

Determining Escalation Procedūras

There is no need of absolute response for every incident with an international CSIRT
mobilized for the worst-case scenario. An assurance is required whether the incident handle
at local level or at the corporate level. If there is an involvement of the intermal employee in
the incident then it will damage only local business unit. It does not include theft of trade
secrets or disclose the data of client which is handled at local level. If outsider is involved in
the incident then it affect multiple locations, so it is be handled at the corporate level

b. Implementing Notification Procedures

The organization must a central point of contact for all detected or suspected incidents.

Make this point of contact a permanent member of CSIRT who is well versed in your
organization's acceleration and notification procedures
The points of contact for organization's CSIRT individuals should be set up much sooner than
an incident happens. Maintain this information in a notification checklist. The notification
checklist contains the information required to coritact all the team members. The CSIRT
members must have to know at what time use the recorded contact information recorded
organization's notification checklist and when to notify the proper people an angoing
incident. Internal investigations aften require diverse rules of notification than external
security incidents. If you notify maximum people about the intermal investigation then there
are chances that the subject of investigation will find he/she is the centre of an Investigation.
Notification should involve only people that:

Need to know about the investigation.

Can really help with the investigation.

Will not be confused, panicked, or otherwise hinder the investigation

Are not dear friend of the suspect.

Scoping an Incident and Assembling the Appropriate Resources

Incident response needs quick decisions, and the speed at which you act regularly saves
your organization time and money as well as reflects on its reputation. When you assemble
the CSIRT the first step is to determine the specialist required for the wark. The number and
type of peoples on the team depend on these factors:How many workstations evolved in the
incident?

How many operating systems involved in the incident 7

How many systems that are involved, vulnerabile, or exploited?

Timeframe in which the investigation needs to be performed Potential exposure or pr of the


case
Your organization's desire for a big or small investigative team

Whether or not litigation is probable?

Whether it is an internal investigation?

Whether the subject of the investigation is aware of the investigation?

4. Assigning a Team Leader

Organizations must have to select a team leader because all computer-related investigatio
require professionals who understand technical aspects of the incident as well as d
investigative process for computer security Incidents. To ensure that you have chosen
effective team leader, you should select someone who can perform the following tasks

Manage the organization's CSIRT during the entire response process.

Manage the interview process when talking to witnesses, system administrators, and use
legal counsel, managers, and others

Provide status reports and communicate effectively to management on the progress of


response.

Ensure that best practices and proper response techniques are used.

Provide overall analysis of the incident

Protect the evidence gathered during the investigation in a manner consistent with you
evidence guidelines and instructions.

Take responsibility for verifying the chain of custody of evidence

Perform forensic duplication and analysis if necessary.

Compile, manage, and present the investigative report and offer recommendations
management.

Understand the legal issues and corporate policies.

Provide an unbiased investigation with no conflict of interestAssigning Technical Staff

1-19

Smeler organizations that carmol have hull-time CSIRT need to assign tedical staff. There is
need to request support from other business units and create a CSIRT composed of the
appropriate technical advisors. The technical advisors are employees or contractors who
understand the details of the systems and the technologies involved in the investigation.
These people want to possess the following characteristics

Knowledge of Complete operating system.

Ability to review logs, audit trails, and other trace evidence and to clearly report findings

Knowledge of proper evidence-handling techniques.

Ability to perform proper damage assessments.

Ability to assist in determining the scope of an incident.


Ability to determine the nature of the incident and identify the specific technical details that
support their conclusions.

Ability to make recommendations of how to remedy the situation.

Capacity to maintain the perspective that technological evidence induding audit tra logs,
core dumps, or live data collection may be critical to resolve the incident

Documentation skills to record all investigative steps clearly and concisely.

Ability to support the team leader.

Ability to perform interviews when needed.

Once the CSIRT Investigation. Investigative team is assembled, you are ready to begin the

5. Performing traditional investigative steps

The investigation phase involves determining the surrounding of an incident in the form of
who, what, when, where, how. There are two ways to simplify a technical investigation is to
divide the evidence you collect into three categories:

Host-based evidence: For the host based evidence data is collected from Windows or Unix
machines, or from the device actually involved in the incident,

Network-based evidence: Network-based evidence is collected from routers, 105, network


monitors. It may be possible that some network node not immediately inuclved in the
[Link] evidence: Other evidence means testimonial data that contributes to the
case s example motive, intent and or some other digital evidence. It also consists of othe
Information gathered from the people. This is when you gather personnel files, interving
employees, interview incident witnesses, interview character witnesses, and document the
Information gathered Other information can include volcemail systems, time cards, cand
swipe data, physical Security logs, video camera tapes, employee records, telephone ca logs,
and fax logs.

6. Conducting interviews

When your CSIRT come across of a suspected incident, the first step is to start asking the
questions like what, who, when, where, and how. These questions helps you to determine
some facts surrounding the incident, for example the location of relevant Systems,
administrative contacts, what may have occurred and when etc. it may be possible that
there may be no answer for some questions but if you gather more answers it helps to
assess the situation. Some few important questions to ask while forming your initial
assumptions about an Incident:

What happened?

When did it happen?

What systems are relevant/compromised/involved?

Who may have done it?

Who uses the affected/relevant systems?

What actions have already been taken?

What is the corporate policy on such an incident?

Getting Contact Information


During the interview collect each individual's information like Full name, Job title, Company
name, Phone number, Email address. This identifying data is critical if you need to contact
these people for additional information. When you prepare your report, you should include
all the contact information for each person who provided you with information.

Interviewing System Administrators

Many incidents results in failure after a discussion with the system administrator or the user.
This is true when notification of the suspected incident comes from firewall logs, for
example IDS detecting falled login attempts, at that point a fruitful login by means of teinet.
The source address is registered to a home DSL provider. The notification checklist questions
are helpfutut do not analyze the station. The user mayessly reve the telnet privy was made
up to implemented administrator has no ides of the logins, and remarks that was not build
to allow connections from the Intemet, an incident has occurred and a response is necessary

Here are some random questions for system administrators

Have you noticed any recent nappropriate activity

How many of them have administrator access to the system

Which applications provide isolated access on the system?

What are the logging capabilities of the network and system?

What safety measures for security of the system are taken?

Interviewing Managers

Managers' regularly have advantageous bits of knowledge into the business impact and
harm caused by security incidents interviewing manager is often critical to determine what
risks are involved with the security incident and what demage was truly done. Following are
some sample questions for managers:

Is there anything particularly sensitive about the date and epplications on the system?

Are there any personnel issues of which we should be aware?

Was any type of penetration testing authorized for the system or network?

What is the worst case scenario that can play out based on what you know about this
Incident?

Interviewing End Users

End users may provide pertinent information when he reports the suspicious activity. End
users describe anomalous behaviour on the system is a helpful way.

7. Formulating a response strategy

Here we consider the steps to recover from the incident. It also includes initiating adverse
action against an internal employee or an external attacker.

Response Strategy Considerations

Response strategy considers everything you know about the incident. Response strategy
danges over time, and then factor in the legal, political, technical, and business influences
that should be considered. Response strategy is an iterative process. Final response strategy
is implemented after going through so many [Link] determining your response strategy
following are some common factors you have to consider.
Does your organization have a formal/public posture on responding to attacks that it must
adhere to in order to appear consistent to customers and the media?

Is the suspected attack from overseas, making it more difficult to pursue technically and
legally?

Is the strategy worth pursing from a cost/benefit standpoint?

Are there any legal considerations that may affect the response?

Can you risk public disclosure of the incident to clients or to the public?

How have you enforced same incidents in the past?

What is the past record/work performance of the individual(s) involved?

Will the investigation cost more than merely allowing the incident to continue?

Policy Verification

In the initial assessment first steps taken is to determine the existing policy. The policy which
addresses the two fundamental needs of the investigator: network monitoring and
computer forensics examination of computer systems got the highest priority. Monitoring
may be limited, without appropriate policy or banners on systems. It is also necessary to
make sure that any existing acceptable use and consent to monitoring policies apply to your
situation.

What constitutes a computer security incident? What


objectives are pursued through incident response?
1.4.1 Computer Security Incident
Computer security Incident is any unlawful, unauthorized, or unsuitable activity that
includes a computer system or a computer network. Such an activity can incorporate any of
the following events:

1. Theft of the Trade secrets

2. Email spam or harassment

3. Embezzlement

4. Unauthorized or unlawful intrusions into computing systems.

5. Denial-of-service (DoS) attacks

6. Extortion

7. Any unlawful action when the evidence of such action may be stored on computer media
for example fraud, threats, and traditional crimes.

8. Possession or dissernination of child pornography.

1.4.2 Goals of Incident Response

Q. What is Incidence? What are the goals of incidence response?

MU-May 17

The goals of the Incident Response are as follows


1. To prevent a disconnected, no cohesive response.

2. Confirms or dispels whether an incident happened.

3. Promotes gathering of accurate information

4. Establishes controls for proper retrieval and handling of evidence.

5. Protects privacy rights established by law and policy.

6. Minimizes damage to business and network operations8 Provides accurate reports and
useful recommendations.

9. Provides quick detection and containment.

‫تما‬

10. Minimizes exposure and compromise of proprietary data.

11. Protects your organization's reputation and assets.

12. Educates senior management.

13. Promotes quick detection and/or prevention of such incidents in the future.

Elaborate on the concept of CSIRT.


1.5 CSIRT After the incident response charter has been finalised, the Computer Security
Incident Response Team (CSIRT) will be staffed. Larger businesses with adequate resources
may be able to assign employees to crisis response tasks on a full-time basis. However, more
often than not, businesses will be forced to use employees that have other responsibilities in
addition to incident response. Personnel in the internal CSIRT are classified into three groups
: 이 Core team. o Technical support o Organisational support. Each member of the CSIRT is
responsible for a certain duty. It requires more than just assigning employees and
developing a policy and procedure document to build this capacity within an organisation.
An effective CSIRT, like any big project venture, needs a significant amount of effort. There
are distinct duties and responsibilities for each of the CSIRT categories. This diverse group of
individuals is intended to give direction and support during a wide range of situations, from
minor to disastrous. 1.5.1 The CSIRT Core Team The CSIRT core team is made up of people
who either work full-time in incident response or take on incident response tasks on the
side. The core team is frequently made up of people assigned to the information security
team. Other companies can benefit from individuals with incident response experience.
Some of the responsibilities that can be included in the core team are as follows: 1. The
incident response coordinator The incident response coordinator is often the Chief Security
Officer (CSO), Chief Information Security Officer (CISO), or Information Security Officer (ISO),
as that individual is often in charge of the overall security of the organization's information.
Other organisations may appoint a single person to act as the incident response coordinator.

The incident response coordinator is in charge of managing the CSIRT before, during, and
after an event. In terms of preparation, the incident response coordinator will ensure that
any CSIRT plans or procedures are evaluated on a regular basis and modified as appropriate.
Furthermore, the incident response coordinator is in charge of ensuring that the CSIRT team
is properly trained, as well as overseeing testing and training for CSIRT employees. During an
event, the incident response coordinator is in charge of ensuring effective incident response
and remediation and guiding the team through the full incident response process.
Coordination of the CSIRT with senior leadership is one of the most critical of these duties
during an event. With the stakes of a data breach so. high, top leadership, such as the CEO,
will want to be kept up to date on crucial event information. It is the role of the incident
response coordinator to keep senior leadership up to date on all incident-related actions.
Finally, the incident response coordinator is responsible for ensuring that the event is
correctly recorded and that reports of CSIRT activities are given to the relevant internal and
external stakeholders at the conclusion of an incident. In addition, all CSIRT operations are
thoroughly debriefed, and lessons gained are integrated into the CSIRT Plan. 2. CSIRT Senior
Analyst(s) CSIRT Senior Analysts have significant training and expertise in incident response
as well as related capabilities such as digital forensics or network data inspection. They
frequently have several years of incident response expertise as a consultant or as part of an
organisation CSIRT. During the incident response process's preparation phase, they are
involved in ensuring that they have the appropriate skills and training to address their
unique position in the CSIRT. They are also frequently instructed to help in the evaluation
and revision of incident response plans. Finally, experienced analysts are frequently involved
in the training of junior members of the team. Once an event has been detected, senior
analysts will collaborate with other CSIRT members to gather and evaluate evidence, direct
containment efforts, and aid other staff with clean-up. After an event, top analysts will
ensure that both they and other staff properly document the occurrence. This will entail
preparing reports for internal and external stakeholders. They will also ensure that any
evidence is preserved or destroyed in accordance with the incident response strategy.
3. CSIRT Analyst(s) Introduction to Digital Forensics CSIRT Analysts are CSIRT professionals
who have little exposure to or experience with incident response operations. They
frequently have only one or two years of incident response experience. As a result, they can
engage in a range of tasks, some of which are directed by senior analysts. Analysts' skills will
be developed through training and exercises throughout the preparation period. They may
also be involved in incident response plan evaluations and upgrades. They will be charged
for acquiring evidence from possibly hacked hosts, network devices, or different log sources
during an event. Analysts will also participate in evidence analysis and will support other
team members with remedial efforts. 4. Security operations centre analyst Larger companies
may have a 24/7 Security Operations Center (SOC) monitoring capacity inhouse or hired.
When it comes to incident identification and alerting, analysts assigned to the SOC are
frequently the point person. As a consequence, having a SOC analyst on the team allows
them to be taught on methodologies and respond to a possible security issue practically
immediately. 5. IT Security Engineer / Analyst(s) Depending on the organization's size, there
may be employees particularly assigned with the deployment, maintenance, and monitoring
of security-related software such as antivirus or hardware such as firewalls or SIEM systems.
When an issue has been detected, having immediate access to these devices is important.
Personnel assigned to these tasks will frequently have a direct part in the whole incident
response process. The IT Security Engineer or Analyst will frequently be responsible for a
substantial portion of the incident response process's preparation. They will be the key
resource for ensuring that security apps and devices are correctly set to alert to potential
issues and that the devices properly log information so that events may be reconstructed.
They will be entrusted with monitoring security systems for additional signs of hostile
conduct during an event. They will also help the other CSIRT members gather proof from the
security equipment. Finally, following an event, these people will be charged with setting
security devices to watch for suspicious behaviour in order to confirm that remediation
operations have removed malicious activity from compromised systems.

1.5.2 Technical Support Personnel 1-8 Introduction to Digital Forensics Technical support
employees are those inside the company that do not have CSIRT activities as part of their
day-to-day operations but have knowledge or access to systems and procedures that may be
impacted by an event. For example, the CSIRT may need to hire a server administrator to
help the core team collect evidence from servers such as memory grabs or logs. Once
accomplished, the server administrator's job is complete, and they may not be involved in
the event again. The following are some of the people that can help the CSIRT during an
incident: 1. Network Architect/Administrator: Network infrastructure is frequently involved
in incidents. This covers router, switch, and other network hardware and software assaults.
The Network Architect or Administrator is critical for understanding typical and abnormal
behaviour of these devices, as well as recognising anomalous network traffic. In events
involving network infrastructure, these support staff can help acquire network evidence such
as access logs or packet captures. 2. Server Administrator : Threat actors frequently target
network systems that hold vital or sensitive data. Domain controllers, file servers, and
database servers are common high-value targets. Log files from these systems can be
obtained with the assistance of server administrators. If the server administrator(s) are also
in charge of active directory structure management, they may be able to assist with
detecting new user accounts or making modifications to existing user or administrator
accounts. Application support: Threat actors frequently attack web apps. Some security
breaches are caused by coding flaws that enable for attacks such as SQL injection or security
misconfigurations. As a result of having application support staff as part of the CSIRT, direct
information about application assaults is possible. These experts are frequently able to spot
code modifications or validate vulnerabilities found during an examination into a possible
application attack. 4. Desktop Support: Desktop support workers are frequently involved in
the maintenance of controls such as data loss prevention and anti-virus on desktop
computers. In the case of an incident, they can aid in delivering log files and other evidence
to the CSIRT. During the incident's remediation phase, they may also be in charge of cleaning
up affected systems. 5. Help desk: When it comes to recognising an issue, help desk staff are
the proverbial canary in the coal mine, depending on the company. When a user detects the
first symptoms of a malware infection or other harmful behaviour, they are frequently the
first people [Link] a result, help desk staff should be included in CSIRT response
training as well as their involvement in incident identification and escalation protocols. In
the case of a large occurrence, they may also aid in locating other impacted personnel.

1.5.3 Organizational Support Personnel Other organisational members that should be


included in the CSIRT should be included outside of the technical area. Organizational people
can help with a variety of non-technical concerns that are not handled by CSIRT core and
technical support personnel. These include navigating the internal and external legal
environments, aiding with customer contacts, and assisting CSIRT employees on-site. Some
of the organisational support individuals who should be included in a CSIRT Plan are as
follows: 1. 2. 3. 4. Legal: Data breaches and other occurrences raise a number of legal
concerns. Many nations currently have breach notification regulations that compel
businesses to notify customers if their information has been compromised. Other
compliance mandates, such as HIPAA and the PCI DSS, require the impacted business to
contact and alert various external organisations of a suspected breach. Involving legal
counsel early in the incident response process ensures that these notifications, as well as
[Link] legal requirements, are addressed in a timely manner. If an inside source, such as
an employee or contractor, is responsible for the breach, the harmed company may choose
to seek restitution through legal action. Including legal assistance early in the process allows
for a better-informed selection about the legal method to use. Human resources: Employees
or contractors are responsible for many incidents that occur in businesses. The CSIRT may be
called in to examine acts ranging from fraud to large-scale data theft. If an employee or
contractor is the subject of the inquiry, the human resources department can assist in
verifying that the CSIRT's operations are in accordance with applicable labour laws and
corporate regulations. If an employee or contractor is to be terminated, the CSIRT can work
with human resources to ensure that all necessary documentation on the event is
completed, reducing the possibility of a wrongful termination claim.
Marketing/communications : If an incident, such as a Denial-of-Service attack or data
breach, may have a negative impact on external clients or customers, the marketing or
communications department can assist in crafting the appropriate message to assuage fears
and ensure that those external entities are receiving the best information possible. When
looking back at previous data breaches, there was a reaction against those businesses that
tried to keep the facts to themselves and did not notify customers. Having a good
communications plan in place and putting it into action early can go a long way toward
calming any possible consumer or client negative reactions. Facilities: The CSIRT may rèquire
access to places after hours or for an extended period of time. The facilities department can
assist the CSIRT in acquiring the appropriate access as soon as possible. Additionally,
facilities may have access to extra meeting places for the CSIRT to use in the case of a long-
term crisis that necessitates dedicated workspace and infrastructure. Tech Knowte

5. Corporate security: The CSIRT may be called in to deal with an organization's theft of
network resources or other technologies. Theft of laptops and digital material is quite
prevalent. Surveillance footage from entrances and exits is frequently available to corporate
security. They may also keep access badge and visitor records for the CSIRT to track
employee and other personnel movement within the site. This allows for the reconstruction
of events before a theft or other conditions that led up to the incident. 1.5.4 External
Resources Many sectors have professional associations where practitioners may join
together to discuss information, independent of their employment. At times, CSIRT staff may
be entrusted with interacting with law enforcement and government authorities, particularly
if they are targeted as part of a broader attack on a number of similar businesses.
Relationships with other organisations and agencies can help the CSIRT share intelligence
and resources in the case of an incident. Among these resources are the following: 1. 2. 3. 4.
High Technology Crime Investigation Association (HTCIA): The HTCIA is a worldwide
organisation of professionals and students dedicated to the investigation of high-tech crime.
Resources range from digital forensics techniques to enterprise-level data that might assist
CSIRT staff with new approaches and procedures. InfraGard: The Federal Bureau of
Investigation has established a private-public collaboration aimed at networking and
information sharing for CSIRT and information security practitioners in the United States.
This collaboration enables CSIRT members to share information about trends and discuss
previous investigations. Law enforcement : There has been an exponential increase in cyber-
related criminal activities. As a result, several law enforcement agencies have strengthened
their capabilities to investigate cybercrime. Leadership of the CSIRT should establish
relationships with agencies that have cybercrime investigation skills. Law enforcement
agencies can give insight into specific threats or crimes that are being perpetrated, as well as
providing CSIRTS with any information that is of concern to them. Vendors: In the case of an
incident, external vendors can be used, and what they can give is frequently based on the
specific line of business in which the company has engaged them. For example, an
organization's IPS/IDS solution provider may be able to assist in the creation of bespoke
alerting and blocking rules to aid in the identification and containment of malicious activity.
Threat intelligence vendors can also give recommendations on harmful behaviour
indications. Finally, some companies will need to employ vendors who specialise in a certain
incident outside response expertise, such as reverse engineering malware, if such
capabilities are an organization's competence.

What is incident? Explain the incident response


methodology in detail.
Computer security incidents are often complicated, multifaceted troubles like any complex
engineering problem. Black box approach is used to solve the incident problem. In this
approach divide the larger problem of incident resolution into components and test the
inputs and outputs of each component. Fig. 1.6.1 illustrates our approach to incident
response.

In our methodology, there are seven important components of incident response: 이 Pre-
incident preparation : In this phase actions are taken to prepare the organizatice and the
CSIRT before an incident occur. o Detection of incidents : In this phase potential computer
security incident is identified. o Initial response : In this phase an initial investigation is
performed. The basic detaile surrounding the incident are recorded. The incident response
team is assembled ane individuals who need to know about the incident are notified. 이 0
Formulate response strategy: In this phase best response is determined and the
management approval is taken based on the results of all the known facts. What types o
civil, criminal, administrative, or other actions are appropriate to take are determined based
on the conclusions got from the investigation. Investigate the incident: In this phase
thorough collection of data. To determine wha happened, when it happened, who did it, and
how it can be prevented in the future reviewed from the collected data. Reporting: In this
phase information is accurately reported about the investigation in manner useful to
decision makers. o Resolution : In this phase security measures are employed. For any
problem procedura changes, record lessons learned, and develop long-term fixes are
identified.

Explain Digital Forensics categories (Computer,


Mobile, Network, Database).

1.3 Digital Forensics Categories - Computer Forensics, Mobile Forensics, Network Forensics,
Database Forensics 1. 2. 3. Computer Forensics : This computer forensics deals with
computers, embedded systems and static memories like USB drives. Extensive range of
information from logs to original files on drive can be investigated in computer forensics.
Mobile Forensics: As mobile phones began to become ubiquitous in the near the beginning
aught, this category emerged. Mobile forensics is used to recover data from the mobile
devices. A mobile device is generally defined as one with a built-in communication system
(GSM or SMS) and location information through GPS; however, mobile devices also include
cameras and USB drives. It mainly deals with the examination and analysis of mobile
devices. It helps to retrieve phone and SIM contacts, call logs, incoming, and outgoing SMS,
MMS, Audio, videos, etc. Network Forensics: Network forensics is a sub-branch of digital
forensics. Network forensics is related to monitoring, capture, storing and analysis of
network activities to discover the source of security attacks, intrusions or other problem
incidents, i.e. worms, virus or malware attacks, abnormal network traffic and security
breaches. Teck Knowledgo Pualisaltons Scanned with OKEN Scanner Digital Forensics (MU) 1-
4 Introduction to Digital Forensics 4. Database Forensics: Database forensics is related to the
study and investigation of databases and their relative metadata. The analysis of data and
metadata contained in databases like Microsoft SQL, Oracle, and others. This information is
helpful in tracking financial crime activity in addition to establishing timelines of events.

MODULE 2
What is Evidence? Explain the various types of digital
evidence.
2.1 Digital Evidence

Q. What is Evidence? Explain the various types of digital evidence? (MU - May 16, May 18)

 The evidence is any information of supporting value, that means which proves
something or helps to prove something relevant to the case.

 The digital evidence consists of the data on a computer, images, audio and video
files. It is data and information of value to an investigation that is stored on an
electronic device, received or transmitted by an electronic machine.

 You can acquire the evidence when data or electronic machines are seized in custody
and secured for the examination. Examples of evidence are a fingerprint, DNA, files
on system etc.

 The problems in acquiring digital evidence are:


(a) Digital evidences can be easily modified, damaged or destroyed.
(b) Digital evidences are time sensitive.

The places from where you can get the digital evidence are:

(i) Computers
(ii) External hard drives
(iii) Floppy disks
(iv) Pen drive
(v) CDs and DVDs
(vi) Thumb drives
(vii) Cell phones and mobile devices
(viii) Voice over IP phones
(ix) Answering machines
(x) iPods
(xi) PDAs
(xii) Electronic game devices
(xiii) Digital video recorders (Tivos)
(xiv) Digital cameras
(xv) PDAs
(xvi) GPSs
(xvii) Servers
(xviii) Routers
(xix) Switches
(xx) Wireless access points
(xxi) Fax machines
(xxii) Printers that buffer files
(xxiii) Photo-copiers that buffer files
(xxiv) Scanners that buffer files
2.1.1 Types of Digital Evidence

The types of evidence are:

1. Real evidence

2. Documentary evidence

3. Testimonial evidence

4. Demonstrative evidence

1. Real evidence

Real evidence are something that one can carry into a courtroom and show it in front of the
jury. Real evidence is the most powerful evidence. This evidence typically “speaks for itself”.

2. Documentary evidence

The evidence which is in the written form is nothing but the documentary evidence. For
example: server logs, email, database document etc. Documentary evidence might be faked
via a professional pc user and therefore must be authenticated to be admissible in a
courtroom. Continually produce the original document, do not use the copy.

3. Testimonial evidence

Testimonial evidence is nothing but the statement of a witness, underneath oath, either in
court or by deposition. This sort of evidence normally helps or validates alternative types.

4. Demonstrative evidence

Demonstrative evidence recreates or explains the different evidence. Demonstrative


evidence does not “talk for itself” and is used to demonstrate and make clear previous
points. This sort of evidence is maximum helpful in explaining technical topics to non-
technical audiences.

Explain the challenges in acquiring digital evidences.

2.1.2 Challenges in Acquiring Digital Evidence

Criminals use a variety of strategies to thwart digital forensic investigators, including


destroying and concealing their evidence, and seizing digital devices is governed by different
laws in different states and nations. The principal challenges that examiners have while
acquiring digital evidence are listed below:

1. A password-, access-card-, or dongle-protected computer.


2. Using digital steganography to hide evidence-gathering material from plain view and
in plain sight in photos, movies, audio files, and file systems (e.g., within MS Word
document).

3. Data obscuration methods to obfuscate information and render it unintelligible


without the password.

4. Encryption of the entire disc, including the system partition (e.g., BitLocker drive
encryption).

5. Secure system/volume passwords that are difficult to guess; this saves time and
money.

6. Renaming files and altering their extensions (e.g., changing DOCX into DLL, which is a
known Windows system file type).

7. Attempts to erase evidence by employing various software tools and methods to


safely wipe the hard disc.

8. When available, turning off system/application logging and clearing the web
browser’s history before closing it.

9. Digital media that has physical harm; for instance, we are unable to recover erased
contents from a failing HDD before fixing it.

10. Digital evidence is sensitive and could be lost if not handled appropriately. The media
device can be ruined by heat, cold, dampness, magnetic fields, and even simple
drops.

11. The ease with which digital evidence can be changed; for instance, if a computer is
ON, you must leave it ON and, if at all feasible, acquire its volatile memory; but if the
computer is OFF, leave it OFF to prevent any data from being changed.

12. State-specific laws regarding the collection of digital evidence and the seizure of
devices differ between one country and another. Because cybercrime can quickly
cross borders via the Internet, the lack of cyberlaw standardisation is a key issue in
this area.

13. The question of data ownership; for example, if investigators seize a USB thumb drive
belonging to a suspect, but the data inside it is fully encrypted and password-
protected, the suspect can deny possession of the thumb, making decryption
extremely impossible without the correct password/key file.

Explain the challenges in evidence handling.


2.3 Challenges in Evidence Handling

The challenges in evidence handling are:

1. The evidence gathered must be authenticated at a judicial proceeding.

2. The chain-of-custody for the evidence must be maintained.

3. The validation of the evidence.

Authentication of Evidence

 Every time when any document introduced and material recorded should be
authenticated. Authentication means that whomever gathered the evidence should
testify during direct examination that the information is what the defender claims.

 Another way to authenticate evidence is to have a witness who has personal


knowledge as to the origins of that piece of evidence provide testimony. Evidence is
inadmissible if it cannot be authenticated. Such inadmissible evidence cannot be
presented to the judging body.

 To meet the demands of authentication it is necessary to ensure that whoever


collected the evidence is a matter of record. For this purpose develop some type of
internal document that records the way in which evidence is collected.

Chain of Custody

 Chain of custody means documentation that identifies all changes in the control,
handling, custody and ownership of a piece of evidence.

 The gathered evidences should be stored in a tamper-proof manner means that


evidence cannot be accessed by unauthorized person, it helps in maintain the chain
of custody. For each obtained item a complete chain-of-custody record is kept.

 Chain of custody needs that you can trace the place of the evidence from the instant
it was collected to the instant it was presented in a judicial court. Many police
departments and federal law enforcement agencies have property departments that
store evidence in a secure place to meet the chain of custody requirement.

 Whenever the experts and law enforcement officers required reviewing the evidence
check-out the evidence, and then check-in the evidence every time it is returned to
storage.

 Organization’s best evidence should be stored in a safe room or storage so that is


inaccessible to anyone other than the appointed evidence custodians. This storage
area is also known as “evidence safe”. Access to evidence safe is controlled by the
evidence custodians.

Evidence Validation
 Evidence validation is another challenge where the gathered information should be
identical to the information which you present in the court. MD5 hash is used to
meet the challenge of the validation.

 MD5 hashes of the original data matches with the forensic duplicated data. Generate
MD5 hash values for every file which is a part of the case.

Explain importance of forensic duplication and its


method and also list some duplication tools.
Qualified Forensic Duplicate

 A qualified forensic duplicate is a file that contains every bit of information from the
source, but may be stored in an altered or changed form. Two examples of altered
paperwork are in-band hashes and Empty Quarter compression.

 A few equipment’s will examine some sectors from the supply, generate a hash from
that group of sectors, and write the world organization, accompanied via the hash
value to the output document.

 This approach works very well if something is going wrong in the course of the
duplication or recovery of the reproduction. If a quarter group fail to fit the hash cost
generated for it, the recovery can continue, and the analyst is conscious that records
from that area or organization may be invalid. If a similar state of affairs came about
with a forensic duplicate file, the place of the mistake may be unknown, probable
invalidating the entire reproduction.

 Empty Quarter compression is a not unusual technique for minimizing the


dimensions of the output document. If the tool comes throughout 500 sectors, all
filled with zeros, it will make a unique entry inside the output file that the healing
application will recognize.

 Three tools that create qualified forensic duplicate output files are:

1. SafeBack

2. EnCase

3. FTK Imager
Restored Image

 A restored image is what you get when you restore a forensic duplicate or a qualified
forensic duplicate to another storage medium. The restoration process is more
complicated than it sounds.

 For example, one method involves a blind sector-to-sector copy of the duplicate file
to the destination hard drive. If the destination hard drive is the same as the original
hard drive, everything will work fine. The information in the partition table will match
the geometry of the hard drive.

 Partition tables will be accurate; if the table says that partition 2 starts on cylinder
20, head 3, and sector 0 that is where the data actually resides. But what if the
destination hard drive is not the same as the original hard drive? If you restore the
forensic duplicate of a 2.1GB drive to a 20GB drive, then the geometries do not
match.

 In fact, all of the data from the original drive may occupy only three cylinders of the
20GB destination drive. The partition that started on cylinder 20, head 3, and sector
0 on the original drive may actually start on cylinder 2, head 9, and sector 0.

 The software would look in the wrong location and give inaccurate results. How does
the restoration software compensate for this? As the forensic duplicate is restored to
the destination hard drive, the partition tables (in the master boot record and
partition boot sectors) are updated with the new values.

 Is the restored image an exact duplicate of the original? If the analyst generates
hashes of the restored image, will they match the original?

 The answer is no in both cases. Is the data on the restored image still a true and
accurate representation of the original? For the purposes of analysis, yes.

 The method of updating partition tables on the destination hard drive is not reliable.
When hard drives grew beyond 512MB, the PC-BIOS manufacturers were scrambling
to update their software to recognize such huge drives. Hard drive manufacturers
came up with a way around the problem.

 Instead of forcing everyone to buy new motherboards with updated BIOS code, they
released software that emulated modern BIOS. This software would “push” all of the
real data on the drive down one sector and store its program and information in
sector 1. The real partition table would be at cylinder 0, head 0, and sector 2.

 When the software restored the forensic duplicate to a large destination drive, it
would not update the correct table, leaving the restored image relatively useless.
Most forensic processing software will detect this drive overlay software and create a
valid restored image.
 The following tools are used to create a restored image from the qualified forensic
duplicate:

1. SafeBack

2. EnCase

3. dd

 Depending on your method of analysis, EnCase and dd images may not need to be
restored. EnCase, the Forensic Toolkit, treats the images as virtual disks, eliminating
the need for restoration.

Mirror Image

 A mirror image is created from hardware that does a bit-by-bit copy from one hard
drive to another. Hardware solutions are very fast, pushing the theoretical maximum
data rate of IDE or SCSI interfaces.

 Investigators do not make a mirror image very often, because it introduces an extra
step in the forensic process, requiring the examiner to create a working copy in a
forensically sound manner. If your organization has the ability to keep the original
drive, seized from the computer system being investigated, you can easily make
working copies. If the original drive must be returned (or never taken offsite), the
analyst will still be required to create a working copy of the mirror image for analysis.

 The small amount of time saved onsite is overshadowed by the overhead of making a
second working copy. We will not cover the process of creating a mirror image of
evidence here. Most hardware duplicators are relatively simple to set up and
operate.

 Two such duplicators are Log cube’s Forensic SF-5000 and Intelligent Computer
Solutions’ Image MASSter Solo-2 Professional Plus. You do need to ensure that the
hardware duplicator actually creates a true mirror image.

 Many duplicating machines on the market are made for systems integration
companies who use them for installing operating systems on large numbers of hard
drives. When used in this capacity, the hardware device will typically alter items in
the boot and partition blocks to ensure that the partitions fall on cylinder
boundaries.

 This alters the resulting image, which means that you do not walk offsite with an
exact duplicate of the original. As with any process, test it thoroughly before you
need to rely on it.
Explain the process of conducting a static acquisition
of digital evidence from a storage device.

2.11 Acquiring Non-volatile Memory (Static Acquisition)

 Non-volatile memory refers to any storage medium that can keep data for an
extended period of time even when the power is turned off. Hard drives and flash
memory are the two most common types (thumb drive).

Digital Forensics (MU)

 Capturing hard disk pictures is considered the most important aspect of any
computer forensic investigation since it contains the majority of data that may
contain incriminatory or exculpatory evidence. In this section, we’ll go over how to
obtain a forensically sound hard drive picture for use in court.

 There are numerous tools available for acquiring hard drive pictures on Windows OS,
including FTK Imager, Pro Discover, EnCase, and X-Ways Forensics.

 Remember to write-protect the suspect hard disc before connecting it to your


forensic workstation before getting the hard drive image. Write protection can be
accomplished with either hardware or software technologies. Many investigators
prefer to boot from a CD/DVD using a Linux forensic distribution that is
preconfigured to disable automatic disk mounting, such as CAINE ([Link]-
[Link]) or DEFT ([Link]), and then attach a suspect drive without the
risk of tampering it with data from external sources. If you use Windows for your
forensic workstation and want to know how to write-protect your files.

2.11.1 Hard Drive Acquisition Methods

Various static acquisition methods can be used during investigations. You should think about
the following considerations before determining which one to go with:

1. The size of the suspicious (source) drive. (Obtaining large-capacity hard drives
necessitates huge storage units to keep the resulting forensic picture, which can take
longer during processing).

2. Acquisition timeframe (if time is limited, you cannot spend hours getting the
complete hard discs of questionable computers).

3. Can you bring the suspect digital material (e.g., hard drive) to the lab, or should you
collect it at the crime scene?
4. Can you shut down the target machine to get its drive data, or is this impossible
owing to numerous factors (for example, shutting down an e-mail server may result
in major economic loss)?

 After taking these and other criteria into account, you can choose the acquisition
strategy that best suits the situation at hand. The three primary approaches for
acquiring forensic photographs are as follows:

o Physical Acquisition

o Logical Acquisition

o Sparse Acquisition

2.11.1(A) Physical Acquisition

 This method, also known as a bit-stream image, creates a bit-by-bit/sector-by-sector


replica of a hard disc. This approach will also capture file system metadata, deleted
files, fragments, and unallocated space. If we make a forensic picture of a 500-GB
hard drive, the final image will be exactly 500 GB unless compression is utilised
during the acquisition process.

 Bit-stream images may be read by any computer forensics programme and, as


previously stated, you must connect the suspect hard drive to a hardware write
blocker so that the forensic workstation used to acquire the image does not write
any data to the suspect hard drive during the acquisition process.

 We can distinguish two forms of physical acquisition based on where the recorded
data is stored:

1. Bit-stream disk-to-image file


Data is captured and saved in an image file. This is the most commonly employed
investigative method. It enables you to build an exact bit-for-bit clone of the source drive
and save it as an image file. The key advantage of this strategy is that it allows you to make
many copies of a questionable disc while leaving the original media undamaged.

2. Bit-stream disk-to-disk
In this method, we copy data (bit by bit) from the source drive to a newer drive with the
same or slightly larger storage space. This method is not generally utilised, although it is still
required in specific situations, such as when purchasing an old HDD. Some computer
forensics software (for example, EnCase and X-Ways forensics) can alter the shape of a new
hard disc (destination drive) so that the collected data is in the same location as the source
(suspect) disc drive.

2.11.1(B) Logical Acquisition


 We capture only a subset of active data using this strategy. By “active data,” we mean
the data that is visible to us when we interact with our computing device. This
method does not capture unallocated space, file system data, deleted and partially
erased files, hidden data, or slack space.

 For example, performing a logical capture on a 500-GB drive with just 100 GB of
active data will result in only the 100 GB being imaged. When the target (suspect)
drive is too large (e.g., RAID storage) and the first responder does not have time to
perform a full (physical) acquisition onsite, logical acquisition is possible.

 It is also possible to do selective acquisition of certain files (e.g., acquire e-mail files
only from the target machine or when we want to capture all photo files existing on a
suspect drive).

 When dealing with some sorts of civil action, logical acquisition may be the only
viable alternative (e-discovery). You may also use search terms to look for a specific
keyword or keywords throughout large datasets and then only get the results.

2.11.1(C) Sparse Acquisition

 This method is similar to logical acquisition in that it captures just certain files
pertinent to the studied case; however, deleted data fragments are also obtained
throughout the capturing process in sparse acquisition. This strategy is frequently
utilised when undertaking static acquisition on RAID systems or on systems where
the suspect was not technically sophisticated enough to apply advanced anti-
forensics measures.

 There are numerous sorts of software that may perform hard disc acquisition; we will
utilise FTK Imager, a free and dependable programme.

Explain volatile data collection for windows system?

What are the challenges of acquiring Volatile Memory


(Live Acquisition)? Give the tools used for Acquiring
Volatile Memory.

2.10 Acquiring Volatile Memory (Live Acquisition)


Q. Explain volatile data collection for Windows system? (MU - May 16, May 17)

 Although it received little attention until recently, live acquisition has now become an
essential component of every digital inquiry type. For example, several sorts of digital
artefacts exist in RAM memory, with nothing saved to the hard disc to show their
presence.

 When a device is switched off or rebooted, data is considered volatile since it will be
lost. Please keep in mind that such data will be wiped during normal computing
device use (e.g., when closing a specific application on a PC, the reserved data space
will disappear from RAM memory, allowing other applications to use its space for
operation).

 Capturing live memory necessitates the use of specific software (and, in some
circumstances, hardware) technologies. Because RAM does not store data in the
same way as hard drives do, analysing volatile data forensic image contents also
necessitates the use of specialised software. Because of these two factors, capturing
and analysing volatile memory is more complex than typical hard disc acquisition.

 Volatile memory is not confined to computers; networking equipment such as


routers and switches can also store volatile data in their logs. Dumping is the process
of capturing data from volatile memory, and it varies depending on the operating
system type. Here, we are collecting volatile data for Windows OS.

Types of information that can be found in RAM memory

The following are types of information that can be found in RAM memory:

1. Cryptographic keys

2. Processes running

3. Executed console commands

4. Clipboard contents

5. Network information

6. Decrypted contents

7. Registry hives

8. Text files and images

9. Deleted files

10. Web browsing logs

11. Open/active registry keys

12. Internet account passwords (e.g., e-mail, social media, and cloud storage)
13. Instant messages

14. Exploit-related information

15. Malware (rootkits and Trojan horses)

16. Evidence of activity not typically stored on the local hard disk

2.10.1 Virtual Memory (Swap Space)

 [Link] (also known as virtual memory) is a file created by Windows to


compensate for RAM memory’s limited capacity. By default, it is located in C:\
[Link].

 Normally, Windows configures the initial virtual memory paging file to be the same
size as the amount of RAM installed; however, a user or system administrator can
normally adjust its size.

 When your machine’s RAM begins to fill up, this capability allows Windows to use
hard disk space as memory. To clear up space, portions of RAM files are relocated
into virtual memory.

 Now, the operating system cannot directly process any of the files that have already
been delivered to virtual memory. As a result, it will need to send more files to virtual
memory in order to free up more space so that it can retrieve the files it wants to
process from virtual memory back into RAM. This operation, known as swapping or
paging, is invisible to the user.

 Acquiring virtual memory is a critical component of forensic acquisition since it might


contain valuable information transferred from RAM memory such as user passwords,
encryption keys, web browser activity, and other vital artefacts. Some RAM capture
programmes, such as FTK Imager, can gather virtual memory in addition to RAM.

2.10.2 The Challenges of Obtaining RAM Memory

Forensic examiners will face certain difficulties in acquiring live memory. The following are
the primary considerations to keep in mind when performing live acquisition:

1. Windows Locked

 It is best to do a hard shutdown if we come across an operating computer with a


login screen (locked PC). However, some experts suggest that we can avoid losing
RAM contents by bypassing the Windows login page without rebooting:

1. Access live memory and encrypted discs without a password by using tools
like Passware Kit or hardware devices (e.g., CaptureGUARD and Phantom
Probe hardware devices).
2. Use a direct memory access (DMA) attack to retrieve the password from RAM
and log into the system.

 Always remember that utilising such approaches will leave traces in RAM memory
and may not be successful in some circumstances; therefore conduct a risk
assessment to determine whether forensic live collection is worth the effort, and
always consult a professional examiner when in doubt.

Using DMA to unlock unlocked computers

 DMA is a computer system mechanism that allows some hardware components to


connect directly with the computer’s physical memory (RAM) and transfer data
to/from it without first passing it through the computer CPU. This technology is used
to save processing time and boost computer throughput by transferring data directly
from RAM memory without first processing it in the CPU.

 The scenario goes like this: A digital forensics examiner will link his/her device
(mobile forensic workstation) to the suspect machine, and the cracking software will
search the suspect PC’s RAM memory for intriguing artefacts such as encryption keys,
passwords, or decrypted data.

 In order for this method to function, the suspicious PC must have DMA-capable
ports. FireWire, Thunderbolt, PCMCIA, PCI, PCI-X, and PCI Express are examples of
such ports. DMA is not supported by USB connectors.

2. Administrative Privileges

 Most RAM memory capture software applications require administrator access to


function. If you come across a functioning PC with limited user rights (e.g., a user
account), you can use a hardware acquisition tool (which requires a small driver to be
loaded on the target computer) or a DMA attack to acquire RAM memory.

3. Capturing Tool Footprint

 The capturing technique that was used to obtain the RAM memory will leave traces
on the suspect PC. The providers of computer forensic software state that their tools
will leave a very little footprint on the acquired system; however, some data may be
overwritten as a result of capturing live memory. Hardware acquisition tools will also
require the installation of a small driver on the target computer in order to function.
These modifications should be thoroughly documented in the investigation’s final
report to avoid rendering your evidence inadmissible in court. Any Windows
computer that is subjected to live acquisition will typically undergo the following
changes:

1. Registry changes

2. Memory entries (overwrite data in RAM)


3. May write a very small amount of data to a disk drive

 Courts are usually forgiving of modest footprints left by RAM capturing programmes;
nevertheless, make sure to document each interaction with the suspect computer
when capturing RAM memory in your final report, and utilise legally accepted
methods to complete the job.

Tools to Capture RAM

 DumpIt: DumpIt is a tiny portable tool for acquiring RAM memory for computers
running Windows OS (32 or 64 bit).

 Belkasoft: This is a tiny free tool that can run from a USB thumb drive; it has the
ability to capture the entire contents of RAM memory even if protected by an active
antidebugger or antidumping system. Separate 32-bit and 64-bit versions are
available to minimise the tool’s footprint as much as possible.

 Magnet: Magnet, another portable tool for RAM capture, claims its small footprint
on the target machine and supports nearly all Windows OS versions: Windows XP,
Vista, 7, 8, 10, 2008, and 2012 (32 and 64 bit).

 FTK Imager: FTK Imager is a data preview and imaging programme that generates
forensic photographs of a target computer’s data without altering the underlying
evidence. You may create forensic images of local hard drives, floppy diskettes, zip
discs, CDs, DVDs, entire folders, or individual files from various locations within the
media using this application. FTK Imager can also be used for tasks other than image
acquisition, such as:

1. Mounting a read-only image

2. Examining the contents of forensic pictures

3. Extraction of files and directories from forensic images

4. Obtaining the Windows registry

5. File recovery after deletion

What are the potential risks involved in hard drive


imaging during digital forensic investigations? Explain.

What are the hard drive imaging risk and challenges?


2.12 Hard Drive Imaging Risks and Challenges

Acquiring hard drive images is not always an easy procedure; difficulties can develop that
irritate the examiner or make the process more complicated and time consuming. In this
section, we will discuss the most prevalent difficulties that investigators may encounter
when acquiring forensic images.

1. Network Attached Storage (NAS)

 Network attached storage (NAS) units are becoming increasingly popular in the
home; home users are increasingly adopting NAS to backup laptops, desktops, and
smartphones, in addition to storing a large quantity of multimedia content on a
central storage device. As a result, acquiring such devices becomes increasingly
crucial.

 NAS devices are outfitted with their own dedicated operating systems, which are
typically Linux variants. To properly acquire the data on these devices (including
unallocated hard drive space), you must undertake bit-by-bit acquisition, which
necessitates the use of an examiner with Linux expertise. The sheer volume of data
will also require time for capture and analysis. Sparse acquisition can be used to
tackle this problem.

2. Encrypted Hard Drive

 We may find ourselves in a position where we need to obtain a hard drive when it is
encrypted (FDE). As we indicated in the "Acquiring Volatile Memory (Live
Acquisition)" section, if the computer is still functioning when you arrive at the crime
scene, you should try to acquire its volatile memory as soon as possible because
there is a good chance you can recover encryption keys from it.

 If live acquisition is not possible, your only choice is to acquire the encrypted hard
drive and then attempt to decrypt it using the proper tools (which cannot guarantee
successful password decryption using such tools) or just ask the hard drive owner for
the password if possible.

3. Corrupted or Physically Damaged Hard Drive

 If the suspect hard disc has physical damage, you will be unable to retrieve its data
until it is repaired by a hardware professional first. Many specialised companies can
recover data from damaged hard discs forensically; modern police labs can also do
this. However, regardless of the damage to the questionable hard drive, you should
not discard it; instead, take it to a competent technician because the data in it may
be recoverable.

4. Cloud Data Collection


 Cloud computing has revolutionised the way many IT services are generated,
provided, accessed, and managed in recent years. Cloud services, for example, are
rapidly being used by businesses and people to ease data sharing and minimise
infrastructure expenses. Traditional digital forensics practices are impractical in a
cloud setting due to the nature of cloud computing architecture.

 Because of the dynamic nature of cloud computing and its reliance on virtualization
technology, as well as the distribution of different computing components (e.g.,
servers, networks, applications, and services) across different geographical areas,
forensic examiners will face serious legal (multiple jurisdictions), technical (e.g., tools
required to acquire digital evidence), and logistical challenges.

5. Network Acquisition

 Network forensics faces similar issues to cloud forensics; for example, e-crime, which
involves the use of networked computers, is on the rise. When working on criminal
cases involving the usage of computer networks, you should expect to confront the
following challenges as a forensic expert:

o You will almost always need to collect and evaluate enormous amounts of
data (e.g., acquisitions of redundant array of independent discs (RAID), which
involves two or more hard drives).

o You will need technical skills, as the evidence can be spread across different
device types in the target network.

o There will be organizational issues imposed by the corporations which


request the investigation; for example, you cannot stop a specific service
because it is crucial for the business.

 The presence of different jurisdictions may present difficulties; for example, there
have been instances where a storage server was located in Europe but the
investigation of the breach was conducted in New York. How will you address this
legally? Other legal issues arise when different jurisdictions impose different privacy
regulations; for example, in a network breach, private information (such as
information about customers, partners, or employees) may be exposed to the
examiner, and such data may be protected by different privacy regulations.

6. Forensic Tool Limitation

 Some acquisition tools are incapable of acquiring faulty sectors from an HDD. Bad
sectors should be recorded because they can conceal incriminating information. For
this issue, always consult a professional examiner and tool documentation. Using the
Raw file format may result in not collecting faulty sectors from a questionable HDD,
which should also be considered.
7. Other Challenges

 Steganography (data concealing), covert channels, antiforensics methods, and


assaulting the forensic tools itself are all problems when gathering digital evidence.

You might also like