Advanced Digital Forensics Techniques
Advanced Digital Forensics Techniques
2
Internal
Advanced
Managing Forensic Data Digital Forensics
• Disk Duplicators
• Write Blockers
• Forensic Tools
• Faraday’s Bags
• Cables
Internal
Advanced
Managing Forensic Data Digital Forensics
Chain of Custody
Internal
Internal
Advanced
Digital Forensic tool functions Digital Forensics
6
Internal
Advanced
Digital Forensic tool functions Digital Forensics
7
Internal
Advanced
Data Acquisition Digital Forensics
Forensic imaging
Hardware
Software 8
Internal
Advanced
Digital Forensics
Data Acquisition
Internal
Advanced
Digital Forensics
Data Acquisition
Internal
Advanced
Digital Forensics
Data Acquisition
Internal
Advanced
Digital Forensics
Data Acquisition
Internal
Advanced
Digital Forensics
Data Acquisition
Internal
Advanced
Digital Forensics
Data Acquisition
Internal
Advanced
Write Blockers Digital Forensics
15
Internal
Advanced
Write Blockers Digital Forensics
16
Internal
Advanced
Digital Forensics
Data Acquisition
Internal
Advanced
Digital Forensics
Data Acquisition
Internal
Advanced
Digital Forensics
Data Acquisition
Internal
Advanced
Digital Forensics
Data Acquisition
Internal
Advanced
Digital Forensics
Data Acquisition
Internal
Advanced
Forensic Imaging - Tableau TD2U Digital Forensics
22
Internal
Advanced
Forensic Imaging - Tableau TD2U Digital Forensics
23
Internal
Advanced
Forensic Imaging - Tableau TD2U Digital Forensics
24
Internal
Advanced
Forensic Imaging - Tableau TD2U Digital Forensics
• Forensic Wiping
• Write-Block (default)
• Hard disk drive / USB drive:
o Disk Cloning
o Disk Imaging
• Hashing (MD5 and SHA1)
• Multiple copies (2)
25
Internal
Advanced
Digital Forensics Digital Forensics
3) Multimedia or not.
a) Sensor-based system and indeterminate, or finite
system and determinate)
26
Internal
Advanced
Digital Forensics Digital Forensics
27
Internal
Advanced
Viewing Forensic Data Digital Forensics
• Using EnCase’s search tool, you can view or search for keywords
anywhere on the physical drive.
• You can search the entire case (all devices in the case) at once or
any subset of data within the case, down to a single file.
• Using FTK Imager tool, you can view the suspected drive image
and extract the questioned file or data for forensic analysis.
• Using F-RAT tool, you can view the registry values of the
suspected computer.
28
Internal
Advanced
Viewing Forensic Data Digital Forensics
29
Internal
Advanced
Viewing Forensic Data Digital Forensics
30
Internal
Advanced
Viewing Forensic Data Digital Forensics
Internal
Advanced
Managing Forensic Data Digital Forensics
32
Internal
Advanced
Managing Forensic Data Digital Forensics
33
Internal
Advanced
Managing Forensic Data Digital Forensics
34
Internal
Advanced
Managing Forensic Data Digital Forensics
36
Internal
Advanced
Managing Forensic Data Digital Forensics
• Evidence collection
Evidence collection
38
Internal
Advanced
Managing Forensic Data Digital Forensics
Chain of Custody:
39
Internal
Advanced
Managing Forensic Data Digital Forensics
Personnel:
41
Internal
Advanced
Viewing Forensic Data Digital Forensics
42
Internal
Advanced
Converting Forensic Data Digital Forensics
• Data compression
• Data encryption
43
Internal
Advanced
Converting Forensic Data Digital Forensics
Data compression
44
Internal
Advanced
Converting Forensic Data Digital Forensics
Data compression
45
Internal
Advanced
Converting Forensic Data Digital Forensics
Data compression
46
Internal
Advanced
Converting Forensic Data Digital Forensics
Data compression
47
Internal
Advanced
Converting Forensic Data Digital Forensics
Data encryption
Data encryption
49
Internal
Advanced
Converting Forensic Data Digital Forensics
Data encryption
51
Internal
Advanced
Cryptographic Hashing Digital Forensics
MD5
52
Internal
Advanced
Cryptographic Hashing Digital Forensics
SHA1
53
Internal
Advanced
Cryptographic Hashing Digital Forensics
SHA1
54
Internal
Advanced
Cryptographic Hashing Digital Forensics
55
Internal
Advanced
Cryptographic Hashing Digital Forensics
56
Internal
Open Source analysis tools Advanced
Digital Forensics
and their use
• Encase Imager
• FTK Imager
• ProDiscover Basic
• Bulk Extractor
• WinHex
57
Internal
Advanced
Risks - Challenges Digital Forensics
• Encryption
• Anonymity
• Volatility
• Anti-Forensic Programs
58
Internal
Advanced
Challenges - Encryption Digital Forensics
59
Internal
Advanced
Challenges - Encryption Digital Forensics
• These include:
61
Internal
Advanced
Challenges - Encryption Digital Forensics
65
Internal
Advanced
Challenges - Volatility Digital Forensics
66
Internal
Advanced
Challenges - Volatility Digital Forensics
• registers, cache
• routing table, ...[address resolution protocol or ARP] cache,
process table, kernel statistics, memory
• temporary file systems
• disk
• remote logging and monitoring data that is relevant to the
system in question
• physical configuration, network topology
• archival media
67
Internal
Advanced
Challenges – Anti-Forensic programs Digital Forensics
69
Internal
Advanced
Challenges – Anti-Forensic programs Digital Forensics
70
Internal
Advanced
Challenges – Anti-Forensic programs Digital Forensics
1. Encryption
• One of the widespread anti-forensic techniques is
encryption, which is the art of embedding confidential and
sensitive information into ciphertext (garbled text). Modern-
day encryption algorithms are used to prevent unwanted
eyes from accessing the concealed text, image, or code.
Attackers make use of full-volume encryption and a key file to
hide their malicious codes or campaigns. A secret key is used
to seal the information, which is then decrypted —
deciphering ciphertext back to plain text at the destination
point.
• Forensic analysts are unable to decrypt malicious files
without an authenticated secret key. Malicious files which
are encrypted are not detected in many security screening
techniques and tools. 71
Internal
Advanced
Challenges – Anti-Forensic programs Digital Forensics
2. Program Packers
3. Overwriting data
74
Internal
Advanced
Challenges – Anti-Forensic programs Digital Forensics
4. Onion Routing
75
Internal
Advanced
Challenges – Anti-Forensic programs Digital Forensics
76
Internal
Advanced
Challenges – Anti-Forensic programs Digital Forensics
5. Steganography
77
Internal
Advanced
Challenges – Anti-Forensic programs Digital Forensics
78
Internal
Advanced
Challenges – Anti-Forensic programs Digital Forensics
6. Changing Timestamps
79
Internal
Advanced
Challenges – Anti-Forensic programs Digital Forensics
80
Internal
Advanced
Challenges – Anti-Forensic programs Digital Forensics
81
Internal
Challenges – Advanced
Digital Forensics
Operating System dependency
• Some forensic tools will work effectively on certain version of
Operating system.
82
Internal
Advanced
Q&A Digital Forensics