Security Incident Investigation
|
|
|
- Ruby Ward
- 9 years ago
- Views:
Transcription
1 Security Incident Investigation Mingchao Ma STFC RAL, UK HEPSYSMAN Workshop 10 th June 2010
2 Overview Security incident handling lifecycle Based on NIST SP800-61rev1 recommendation Aim at first responder What and how to do? Tips and tricks on Evidence collection Basic forensic
3 It is a question of when incident will happen, not if
4 Incident Handling Lifecycle Preparation Identification Containment Forensic Analysis - Evidence acquisition - Log and Timeline analysis - Media (e.g. file system) analysis - String search - Data recovery - Artifact (malware) analysis - Reporting Eradication Recovery Lesson-learned
5 Be warned! No two incidents are identical NO one-for-all solution, tailor it for your OWN need! Many types of incidents DoS, Virus/Worm, Inappropriate usage, unauthorized access etc. Focus on hacking scenario But the principle remains the same!
6 Step 1 - Preparation Know existing policies, regulations and laws Authority of investigation Job description Incident handling procedure What information can be collected? Privacy and wiretapping issue Do not violate any existing security policies And do not break laws!
7 Preparation Security policy and incident handling procedure Policies & procedures, write them down on PAPER A simple and easy-to-follow procedure is very helpful Building a team Information about the team - "Organizational Models for Computer Security Incident Response Teams (CSIRTs) ( Contacts information and communication channels Name, telephone, , PGP keys etc. Incidents Prevention Risk assessment Patching, hardening, best practice, education etc. Be aware of your organization's security policy Known your systems before an incident Profile systems and network Know normal behaviours
8 Toolkit Live CDs Incident response toolkit Linux forensic live CDs Helix (no longer free ) - Live response, live/dead acquisition and analysis FCCU GNU/Linux Forensic Boot CD Belgian Federal Computer Crime Unit BackTrack 4 has an option to boot into forensic mode Many others Will not modify the target system harddisk Will not auto-mount devices on target system Will not use target system swap partition Build-in some well-known open source forensic tools
9 Toolkit - Forensic Any Linux system plus proper open source forensic tools US CERT forensic appliance (fedora) A fully functional Linux VM forensics appliance Linux Forensics Tools Repository (RPMs for fedora) SANS SIFT workstation (Ubuntu) VM forensic appliance Free, but registered first BackTrack Load of tools readily available
10 Toolkit - Forensic TSK + Autopsy (GUI-frontend) The Sleuth Kit and Autopsy browser Alternative PSK (GUI-frontend) The Coroner's Toolkit (TCT)
11 Toolkit Network forensic Wireshark/tshark Tcpdump Nmap Snort P0f (OS passive fingerprinting) Antivirus software AVG and avast! for Linux, free!
12 Toolkit Build in Trusted binaries - statically compiled binaries run from CD or USB ls, lsof, ps, netstat, w, grep, uname, date, find, file, ifconfig, arp Test before use different Linux distributions and kernels both 32 bit and 64 bit platform Will not modify A-time of system binaries; Be aware of limitation can be cheated as well Kernel mode rootkit
13 Incident Handling Lifecycle Preparation Identification Containment Eradication Recovery Lesson-learned
14 Step 2 - Identification Detect deviation from normal status Alerted by someone else; Host & network IDS alerts; antivirus/antispyware alerts; Rootkit detection tools; file integrity check; System logs; firewall logs; A trusted central logging facility is essential; Correlate all information available to minimise false alarm
15 Identification Declare an incident once confirmed Make sure that senior management is informed Notification who should be notified? EGEE CSIRTs: PROJECT-EGEE-SECURITY- Following incident handling procedures EGEE incident response procedure
16 Incident Handling Lifecycle Preparation Identification Containment Forensic Analysis - Evidence acquisition - Log and Timeline analysis - Media (e.g. file system) analysis - String search - Data recovery - Artifact (malware) analysis - Reporting Eradication Recovery Lesson-learned
17 Step 3 Containment & Forensic Analysis Prevent attackers from further damaging systems Questions to be answered! Online or Offline? Pull the network cable? Live or Dead system? Pull the plug?
18 Forensic Analysis Start up forensic analysis process once incident has been identified Aim to obtain forensic sound evidences Live system information Will lose once powered off Bit by bit disk image Logs analysis Timeline analysis Data/file recovery Collect volatile data FIRST, if possible!
19 How to collect evidences Volatile data collection Hard disk image Where to store evidences? Attach a USB device Transfer data over network with netcat Evidence workstation ( ): #./nc l p 2222 > evidence.txt Compromised host: #./ lsof n nc
20 Volatile Data Collection Aim: Collect as much volatile data as possible But minimise footprint on the target system In the order of most volatile to least Memory Network status and connections Running processes Other system information Be warned: system status will be modified Document everything you have done Be aware of the concept of chain of custody Maintain a good record (a paper trail) of what you have done with evidence
21 Volatile Data Collection? System RAM Raw memory image with memdump Available at Hardware-based memory acquisition? Virtual Machine Take a snapshot Network Information open ports and connections lsof and netstats Nmap Process information Running processes with ps Process dumping with pcat Available at
22 Other volatile data System Information System uptime: uptime OS type and build: uname a Current date/time: date Partition map: fdisk -l Mount points: mount?
23 What to do with memory image? Linux memory dump Very limited option (at least with open source tools) Strings search for IP, or strange strings etc Can be used to cross check with evidence found in file system/logs Some ongoing researches in open source community
24 Collect Evidence Disk Image Bit by bit disk image Capture both allocated and unallocated space Do not use gzip/tar or normal backup tools Lose unallocated space Can t recover deleted files How to do it? Live system vs dead system image? Full disk vs Partition?
25 Disk Image Live system image vs Dead system image? Helix Live CD or FCCU Live CD Or USB Writeblocker?
26 Disk Image Full disk vs. Partition? Full disk if possible Get everything in one go Can copy host protection area - HPA (after reset) Might not be feasible RAID system: too big, RAID reconstruction? Image only partition OS partitions
27 Disk image Linux dd command Full disk dd if=/dev/sda of=/mnt/usb/sda.img bs=512 Partition dd if=/dev/sda1 of=/mnt/usb/sda1.img bs=512 Enhanced dd e.g. dc3dd or dcfldd dcfldd if=/dev/sourcedirve hash=md5 hashwindow=10m md5log=md5.txt bs=512 of=driveimage.dd dd_rescue
28 What to do with disk images? Mount disk image/partition to the loop device on a forensic workstation in READ ONLY mode mount -o loop, ro, offset=xxxx disk_image.dd /mnt/mount_point Partition information can be obtained sfdisk l disk_image.dd fdisk lu disk_image.dd mmls t type disk_image.dd In the TSK toolset Either work on the whole image Use the offset parameter Or, split the image to individual partitions and then mount them separately dd if=disk_image.dd bs= 512 skip=xxx count=xxx of=partition.dd
29 Evidence Collection Memory dump; Network status; Process dump; Other system information; Disk images; Forensic analysis done on the images NOT on the original disk;
30 After Evidence Collection Mount disk/partition images on a trusted system Timeline analysis with TSK What had happened? Media (e.g. file system) analysis with TSK What was modified/changed and or left? String search on both allocated and unallocated areas with strings Data recovery with TSK What was deleted? Artifact (malware) analysis To understand the function of the malware Sharing findings with relevant parties
31 Incident Handling Lifecycle Preparation Identification Containment Eradication Recovery Lesson-learned
32 Step 4 Eradiation Remove compromised accounts Revoke compromised credentials Remove malware/ artifact left over by the attackers Restore from most recent clean backup If root-compromised, rebuild system from scratch Harden, patch system to prevent it from reoccurrence
33 Incident Handling Lifecycle Preparation Identification Containment Eradication Recovery Lesson-learned
34 Recovery Put system back to production in a control manner Decision should be made by management Closely monitoring the system
35 Incident Handling Lifecycle Preparation Identification Containment Eradication Recovery Lesson-learned
36 Step 6 Lesson learned Know what went right and what went wrong Learning & improving A post-mortem meeting/discussion
37 Thanks 7/03/
38 DEMO How to detect rootkit in a live Linux system? 7/03/
39 The rootkit Captured in last year incident Kernel mode rootkit with sniffing backdoor Hide itself and relevant files from normal detection Can survive from system reboot Protected with password
40 DEMO 7/03/
41 EX2/EX3 file system premier Superblock Block size, number of blocks, number of Inodes, number of reserved blocks, number of blocks per group, number of Inodes per Group Block Groups All blocks belong to a Block Group Begins from block 0, after reserved blocks Each Block Group Superblock backup Group Descriptor Table Block Bitmap, Inode Bitmap Inode Table, Data Blocks
42 EX2/3 Meta Data structure
43 Directories Directory itself is a file A sequence of entries Inode number File name Size of file name Byte Offset Inode Number File Names init fstab passwd group
Unix/Linux Forensics 1
Unix/Linux Forensics 1 Simple Linux Commands date display the date ls list the files in the current directory more display files one screen at a time cat display the contents of a file wc displays lines,
Computer Forensics using Open Source Tools
Computer Forensics using Open Source Tools COMP 5350/6350 Digital Forensics Professor: Dr. Anthony Skjellum TA: Ananya Ravipati Presenter: Rodrigo Sardinas Overview Use case explanation Useful Linux Commands
Where is computer forensics used?
What is computer forensics? The preservation, recovery, analysis and reporting of digital artifacts including information stored on computers, storage media (such as a hard disk or CD-ROM), an electronic
2! Bit-stream copy. Acquisition and Tools. Planning Your Investigation. Understanding Bit-Stream Copies. Bit-stream Copies (contd.
Acquisition and Tools COMP 2555: Principles of Computer Forensics Autumn 2014 http://www.cs.du.edu/2555 1 Planning Your Investigation! A basic investigation plan should include the following activities:!
Computing forensics: a live analysis
April 18th, 2005 1 2 3 Objectives Evidence acquisition Recovery and examination of suspect digital evidence (think Warrick Brown on CSI) Hardware: servers, workstations, laptops, PDAs, mobiles, cameras
Forensics source: Edward Fjellskål, NorCERT, Nasjonal sikkerhetsmyndighet (NSM)
s Unix Definition of : Computer Coherent application of a methodical investigatory techniques to solve crime cases. Forensics source: Edward Fjellskål, NorCERT, Nasjonal sikkerhetsmyndighet (NSM) s Unix
Capturing a Forensic Image. By Justin C. Klein Keane <[email protected]> 12 February, 2013
Capturing a Forensic Image By Justin C. Klein Keane 12 February, 2013 Before you Begin The first step in capturing a forensic image is making an initial determination as to the
GNU/LINUX Forensic Case Study (ubuntu 10.04)
GNU/LINUX Forensic Case Study (ubuntu 10.04) Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Unported License [email protected] FCCU Federal Computer Crime Unit of Belgium Assistance house
DIGITAL FORENSIC INVESTIGATION, COLLECTION AND PRESERVATION OF DIGITAL EVIDENCE. Vahidin Đaltur, Kemal Hajdarević,
DIGITAL FORENSIC INVESTIGATION, COLLECTION AND PRESERVATION OF DIGITAL EVIDENCE Vahidin Đaltur, Kemal Hajdarević, Internacional Burch University, Faculty of Information Technlogy 71000 Sarajevo, Bosnia
INCIDENT RESPONSE & COMPUTER FORENSICS, SECOND EDITION
" - * INCIDENT RESPONSE & COMPUTER FORENSICS, SECOND EDITION CHRIS PROSISE KEVIN MANDIA McGraw-Hill /Osborne New York Chicago San Francisco Lisbon London Madrid Mexico City Milan New Delhi San Juan Seoul
Incident Response and Computer Forensics
Incident Response and Computer Forensics James L. Antonakos WhiteHat Forensics Incident Response Topics Why does an organization need a CSIRT? Who s on the team? Initial Steps Detailed Project Plan Incident
Linux System Administration on Red Hat
Linux System Administration on Red Hat Kenneth Ingham September 29, 2009 1 Course overview This class is for people who are familiar with Linux or Unix systems as a user (i.e., they know file manipulation,
Lecture outline. Computer Forensics and Digital Investigation. Defining the word forensic. Defining Computer forensics. The Digital Investigation
Computer Forensics and Digital Investigation Computer Security EDA263, lecture 14 Ulf Larson Lecture outline! Introduction to Computer Forensics! Digital investigation! Conducting a Digital Crime Scene
Incident Response. Six Best Practices for Managing Cyber Breaches. www.encase.com
Incident Response Six Best Practices for Managing Cyber Breaches www.encase.com What We ll Cover Your Challenges in Incident Response Six Best Practices for Managing a Cyber Breach In Depth: Best Practices
Open Source Security Tool Overview
Open Source Security Tool Overview Presented by Kitch Spicer & Douglas Couch Security Engineers for ITaP 1 Introduction Vulnerability Testing Network Security Passive Network Detection Firewalls Anti-virus/Anti-malware
Open Source and Incident Response
Open Source and Incident Response Joe Lofshult, CISSP, GCIH 1 Agenda Overview Open Source Tools FIRE Demonstration 2 Overview Incident Adverse event that threatens security in computing systems and networks.
UNIX Computer Forensics
Honeynet2_book.fm Page 347 Thursday, April 29, 2004 11:09 AM 12 UNIX Computer Forensics Brian Carrier In the last chapter, we discussed the basics of computer forensics. In this chapter, we discuss the
Computer Forensic Tools. Stefan Hager
Computer Forensic Tools Stefan Hager Overview Important policies for computer forensic tools Typical Workflow for analyzing evidence Categories of Tools Demo SS 2007 Advanced Computer Networks 2 Important
Defining Digital Forensic Examination and Analysis Tools Using Abstraction Layers
Defining Digital Forensic Examination and Analysis Tools Using Abstraction Layers Brian Carrier Research Scientist @stake Abstract This paper uses the theory of abstraction layers to describe the purpose
FORENSIC ANALYSIS OF USB MEDIA EVIDENCE. Jesús Alexander García. Luis Alejandro Franco. Juan David Urrea. Carlos Alfonso Torres
FORENSIC ANALYSIS OF USB MEDIA EVIDENCE Jesús Alexander García Luis Alejandro Franco Juan David Urrea Carlos Alfonso Torres Manuel Fernando Gutiérrez UPB 2012 Content INTRODUCTION... 3 OBJECTIVE 4 EVIDENCE
FALSE ALARM? Incident Management Case Study. Carlos Villalba [email protected]
FALSE ALARM? Incident Management Case Study Carlos Villalba [email protected] Initial Discovery The panic sets in: You think your company has been breached! So, what do you do? First steps First things
Digital Forensics Tutorials Acquiring an Image with Kali dcfldd
Digital Forensics Tutorials Acquiring an Image with Kali dcfldd Explanation Section Disk Imaging Definition Disk images are used to transfer a hard drive s contents for various reasons. A disk image can
Virtualization in Linux KVM + QEMU
CS695 Topics in Virtualization and Cloud Computing KVM + QEMU Senthil, Puru, Prateek and Shashank 1 Topics covered KVM and QEMU Architecture VTx support CPU virtualization in KMV Memory virtualization
USM IT Security Council Guide for Security Event Logging. Version 1.1
USM IT Security Council Guide for Security Event Logging Version 1.1 23 November 2010 1. General As outlined in the USM Security Guidelines, sections IV.3 and IV.4: IV.3. Institutions must maintain appropriate
IDS and Penetration Testing Lab ISA656 (Attacker)
IDS and Penetration Testing Lab ISA656 (Attacker) Ethics Statement Network Security Student Certification and Agreement I,, hereby certify that I read the following: University Policy Number 1301: Responsible
Introduction to The Sleuth Kit (TSK) By Chris Marko. Rev1 September, 2005. Introduction to The Sleuth Kit (TSK) 1
Introduction to The Sleuth Kit (TSK) By Chris Marko Rev1 September, 2005 Introduction to The Sleuth Kit (TSK) 1 This paper provides an introduction to The Sleuth Kit (referred to as TSK herein), from Brian
using memory dumps in digital forensics
SAM STOVER AND MATT DICKERSON using memory dumps in digital forensics Stover is an independent security researcher with experience in network- and host-based forensics. [email protected] Matt Dickerson
Forensic Acquisition and Analysis of VMware Virtual Hard Disks
Forensic Acquisition and Analysis of VMware Virtual Hard Disks Manish Hirwani, Yin Pan, Bill Stackpole and Daryl Johnson Networking, Security and Systems Administration Rochester Institute of Technology
Contents. vii. Preface. P ART I THE HONEYNET 1 Chapter 1 The Beginning 3. Chapter 2 Honeypots 17. xix
Honeynet2_bookTOC.fm Page vii Monday, May 3, 2004 12:00 PM Contents Preface Foreword xix xxvii P ART I THE HONEYNET 1 Chapter 1 The Beginning 3 The Honeynet Project 3 The Information Security Environment
Incident Response and Forensics
Incident Response and Forensics Yiman Jiang, President and Principle Consultant Sumus Technology Ltd. James Crooks, Manager - Advisory Services PricewaterhouseCoopers LLP UBC 2007-04-12 Outline Computer
USB 2.0 Flash Drive User Manual
USB 2.0 Flash Drive User Manual 1 INDEX Table of Contents Page 1. IMPORTANT NOTICES...3 2. PRODUCT INTRODUCTION...4 3. PRODUCT FEATURES...5 4. DRIVER INSTALLATION GUIDE...6 4.1 WINDOWS 98 / 98 SE... 6
Lukas Limacher Department of Computer Science, ETH. Computer Forensics. September 25, 2014
Lukas Limacher Department of Computer Science, ETH Zürich Computer Forensics September 25, 2014 Contents 9 Computer Forensics 1 91 Objectives 1 92 Introduction 2 921 Incident Response 2 922 Computer Forensics
Rootkit: Analysis, Detection and Protection
Rootkit: Analysis, Detection and Protection Igor Neri Sicurezza Informatica Prof. Bistarelli 1/34 Definition of Rootkit A rootkit is malware which consists of a set of programs designed to hide or obscure
Digital Forensic. A newsletter for IT Professionals. I. Background of Digital Forensic. Definition of Digital Forensic
I Digital Forensic A newsletter for IT Professionals Education Sector Updates Issue 10 I. Background of Digital Forensic Definition of Digital Forensic Digital forensic involves the collection and analysis
Digital Forensics For Unix. The SANS Institute
Digital Forensics For Unix The SANS Institute John Green [email protected] Hal Pomeranz [email protected] 1 1 Forensics in a Nutshell Evidence seizure Investigation and analysis Reporting results
Computer Forensics Basics, First Responder, Collection of Evidence
May 7, 2008 1 Computer Forensics Basics, First Responder, Collection of Evidence Omveer Singh Joint Director / Scientist D [email protected] Indian Computer Emergency Response Team (CERT-In) Department
BackTrack Hard Drive Installation
BackTrack Hard Drive Installation BackTrack Development Team jabra [at] remote-exploit [dot] org Installing Backtrack to a USB Stick or Hard Drive 1 Table of Contents BackTrack Hard Drive Installation...3
information security and its Describe what drives the need for information security.
Computer Information Systems (Forensics Classes) Objectives for Course Challenges CIS 200 Intro to Info Security: Includes managerial and Describe information security and its critical role in business.
Information Technology Audit & Forensic Techniques. CMA Amit Kumar
Information Technology Audit & Forensic Techniques CMA Amit Kumar 1 Amit Kumar & Co. (Cost Accountants) A perfect blend of Tax, Audit & Advisory services Information Technology Audit & Forensic Techniques
EC-Council Ethical Hacking and Countermeasures
EC-Council Ethical Hacking and Countermeasures Description This class will immerse the students into an interactive environment where they will be shown how to scan, test, hack and secure their own systems.
Hands-On How-To Computer Forensics Training
j8fm6pmlnqq3ghdgoucsm/ach5zvkzett7guroaqtgzbz8+t+8d2w538ke3c7t 02jjdklhaMFCQHihQAECwMCAQIZAQAKCRDafWsAOnHzRmAeAJ9yABw8v2fGxaq skeu29sdxrpb25zidxpbmznogtheories...ofhilz9e1xthvqxbb0gknrc1ng OKLbRXF/j5jJQPxXaNUu/It1TQHSiyEumrHNsnn65aUMPnrbVOVJ8hV8NQvsUE
How To Install Acronis Backup & Recovery 11.5 On A Linux Computer
Acronis Backup & Recovery 11.5 Server for Linux Update 2 Installation Guide Copyright Statement Copyright Acronis International GmbH, 2002-2013. All rights reserved. Acronis and Acronis Secure Zone are
Open Source Data Recovery
Open Source Data Recovery Options and Techniques CALUG MEETING October 2008 !! Disclaimer!! This presentation is not sponsored by any organization of the US Government I am here representing only myself
Do it Yourself System Administration
Do it Yourself System Administration Due to a heavy call volume, we are unable to answer your call at this time. Please remain on the line as calls will be answered in the order they were received. We
ITU Session Four: Device Imaging And Analysis. Mounir Kamal Q-CERT
ITU Session Four: Device Imaging And Analysis Mounir Kamal Q-CERT 2 Applying Forensic Science to Computer Systems Like a Detective, the archaeologist searches for clues in order to discover and reconstruct
MSc Computer Security and Forensics. Examinations for 2009-2010 / Semester 1
MSc Computer Security and Forensics Cohort: MCSF/09B/PT Examinations for 2009-2010 / Semester 1 MODULE: COMPUTER FORENSICS & CYBERCRIME MODULE CODE: SECU5101 Duration: 2 Hours Instructions to Candidates:
Acronis Backup & Recovery 10 Server for Linux. Update 5. Installation Guide
Acronis Backup & Recovery 10 Server for Linux Update 5 Installation Guide Table of contents 1 Before installation...3 1.1 Acronis Backup & Recovery 10 components... 3 1.1.1 Agent for Linux... 3 1.1.2 Management
Chapter 14 Analyzing Network Traffic. Ed Crowley
Chapter 14 Analyzing Network Traffic Ed Crowley 10 Topics Finding Network Based Evidence Network Analysis Tools Ethereal Reassembling Sessions Using Wireshark Network Monitoring Intro Once full content
Guide to Computer Forensics and Investigations, Second Edition
Guide to Computer Forensics and Investigations, Second Edition Chapter 12 Network Forensics Objectives Understand Internet fundamentals Understand network basics Acquire data on a Linux computer Guide
Detecting Malware With Memory Forensics. Hal Pomeranz SANS Institute
Detecting Malware With Memory Forensics Hal Pomeranz SANS Institute Why Memory Forensics? Everything in the OS traverses RAM Processes and threads Malware (including rootkit technologies) Network sockets,
EC-Council Certified Incident Handler
Page 1 Certified Incident Handler Page 2 TM E CIH Certified Incident Handler Course Description The Certified Incident Handler program is designed to provide the fundamental skills to handle and respond
Red Hat Linux Administration II Installation, Configuration, Software and Troubleshooting
Course ID RHL200 Red Hat Linux Administration II Installation, Configuration, Software and Troubleshooting Course Description Students will experience added understanding of configuration issues of disks,
Navigating the Rescue Mode for Linux
Navigating the Rescue Mode for Linux SUPPORT GUIDE DEDICATED SERVERS ABOUT THIS GUIDE This document will take you through the process of booting your Linux server into rescue mode to identify and fix the
What s Wrong with Information Security Today? You are looking in the wrong places for the wrong things.
What s Wrong with Information Security Today? You are looking in the wrong places for the wrong things. AGENDA Current State of Information Security Data Breach Statics Data Breach Case Studies Why current
How To Image A Single Vm For Forensic Analysis On Vmwarehouse.Com
MCP+I, MCSE, CCSA, CCSE, CISSP-ISSAP, CISM, CISA, CIFI, CCE, ACE, GCFE, GCFA, GSEC, VCP4/5, vexpert Senior SANS Instructor - [email protected] 1 A Lot To Cover In ½ An Hour We simply can not cover all cloud
Pen Test Tips 2. Shell vs. Terminal
Pen Test Tips 2 Shell vs. Terminal Once you have successfully exploited a target machine you may be faced with a common dilemma that many penetration testers have, do I have shell access or terminal access?
Type Message Description Probable Cause Suggested Action. Fan in the system is not functioning or room temperature
Table of Content Error Messages List... 2 Troubleshooting the Storage System... 3 I can t access the Manager... 3 I forgot the password for logging in to the Manager... 3 The users can t access the shared
ServerPronto Cloud User Guide
ServerPronto Cloud User Guide Virtual machines Virtual machines are based on templates and are deployed on hypervisors. Hypervisors give them access to CPU, disk and network resources. The ServerPronto
Cleartext Passwords in Linux Memory
Cleartext Passwords in Linux Memory Sherri Davidoff [email protected] July 26, 2008 Abstract Upon examination, the memory of a popular Linux distribution contained many cleartext passwords, including login,
Professional Xen Visualization
Professional Xen Visualization William von Hagen WILEY Wiley Publishing, Inc. Acknowledgments Introduction ix xix Chapter 1: Overview of Virtualization : 1 What Is Virtualization? 2 Application Virtualization
Israel Aladejebi Computer Forensics Century College Information Technology Department
Israel Aladejebi Computer Forensics Century College Information Technology Department Being able to break security doesn t make you a hacker anymore than being able to hotwire cars makes you an automotive
Impact of Digital Forensics Training on Computer Incident Response Techniques
Impact of Digital Forensics Training on Computer Incident Response Techniques Valorie J. King, PhD Collegiate Associate Professor University of Maryland University College Presentation to AFCEA June 25,
Kevin Cardwell. Toolkits: All-in-One Approach to Security
Kevin Cardwell Kevin Cardwell spent 22 years in the U.S. Navy, starting off in Sound Navigation and Ranging (SONAR). He began programming in 1987. He was fortunate enough to get on the Testing Team and
Getting Physical with the Digital Investigation Process
Getting Physical with the Digital Investigation Process Brian Carrier Eugene H. Spafford Center for Education and Research in Information Assurance and Security CERIAS Purdue University Abstract In this
Backup & Disaster Recovery Appliance User Guide
Built on the Intel Hybrid Cloud Platform Backup & Disaster Recovery Appliance User Guide Order Number: G68664-001 Rev 1.0 June 22, 2012 Contents Registering the BDR Appliance... 4 Step 1: Register the
Recovering Deleted Files in Linux
Recovering Deleted Files in Linux Brian Buckeye and Kevin Liston Most systems administrators have experienced a situation where a vital file has accidentally been deleted without a recent backup. In this
Linux Overview. The Senator Patrick Leahy Center for Digital Investigation. Champlain College. Written by: Josh Lowery
Linux Overview Written by: Josh Lowery The Senator Patrick Leahy Center for Digital Investigation Champlain College October 29, 2012 Disclaimer: This document contains information based on research that
The BackTrack Successor
SCENARIOS Kali Linux The BackTrack Successor On March 13, Kali, a complete rebuild of BackTrack Linux, has been released. It has been constructed on Debian and is FHS (Filesystem Hierarchy Standard) complaint.
How to Restore a Linux Server Using Bare Metal Restore
How to Restore a Linux Server Using Bare Metal Restore This article refers to firmware version 5.4 and higher, and the Barracuda Linux Backup Agent 5.4 and higher. Use the steps in this article to restore
Network Forensics: Log Analysis
Network Forensics: Analysis Richard Baskerville Agenda P Terms & -based Tracing P Application Layer Analysis P Lower Layer Analysis Georgia State University 1 2 Two Important Terms PPromiscuous Mode
Advanced Linux System Administration on Red Hat
Advanced Linux System Administration on Red Hat Kenneth Ingham September 29, 2009 1 Course overview This class is for people who are familiar with basic Linux administration (i.e., they know users, packages,
Reboot the ExtraHop System and Test Hardware with the Rescue USB Flash Drive
Reboot the ExtraHop System and Test Hardware with the Rescue USB Flash Drive This guide explains how to create and use a Rescue USB flash drive to reinstall and recover the ExtraHop system. When booting
System Compatibility. Enhancements. Email Security. SonicWALL Email Security 7.3.2 Appliance Release Notes
Email Security SonicWALL Email Security 7.3.2 Appliance Release Notes System Compatibility SonicWALL Email Security 7.3.2 is supported on the following SonicWALL Email Security appliances: SonicWALL Email
Incident Response. Six Best Practices for Managing Cyber Breaches. Nick Pollard, Senior Director Professional Services EMEA / APAC, Guidance Software
Incident Response Six Best Practices for Managing Cyber Breaches Nick Pollard, Senior Director Professional Services EMEA / APAC, Guidance Software www.encase.com 2014 Guidance Software Inc., All Rights
Automating Linux Malware Analysis Using Limon Sandbox Monnappa K A [email protected]
Automating Linux Malware Analysis Using Limon Sandbox Monnappa K A [email protected] A number of devices are running Linux due to its flexibility and open source nature. This has made Linux platform
Lab III: Unix File Recovery Data Unit Level
New Mexico Tech Digital Forensics Fall 2006 Lab III: Unix File Recovery Data Unit Level Objectives - Review of unallocated space and extracting with dls - Interpret the file system information from the
CS197U: A Hands on Introduction to Unix
CS197U: A Hands on Introduction to Unix Lecture 4: My First Linux System J.D. DeVaughn-Brown University of Massachusetts Amherst Department of Computer Science [email protected] 1 Reminders After
Security Best Practice
Security Best Practice Presented by Muhibbul Muktadir Tanim [email protected] 1 Hardening Practice for Server Unix / Linux Windows Storage Cyber Awareness & take away Management Checklist 2 Hardening Server
Digital Forensics Lecture 3. Hard Disk Drive (HDD) Media Forensics
Digital Forensics Lecture 3 Hard Disk Drive (HDD) Media Forensics Current, Relevant Topics defendants should not use disk-cleaning utilities to wipe portions of their hard drives before turning them over
CERIAS Tech Report 2003-29 GETTING PHYSICAL WITH THE DIGITAL INVESTIGATION PROCESS. Brian Carrier & Eugene H. Spafford
CERIAS Tech Report 2003-29 GETTING PHYSICAL WITH THE DIGITAL INVESTIGATION PROCESS Brian Carrier & Eugene H. Spafford Center for Education and Research in Information Assurance and Security, Purdue University,
The Value of Physical Memory for Incident Response
The Value of Physical Memory for Incident Response MCSI 3604 Fair Oaks Blvd Suite 250 Sacramento, CA 95864 www.mcsi.mantech.com 2003-2015 ManTech Cyber Solutions International, All Rights Reserved. Physical
Acronis Disk Director 11 Advanced Server. Quick Start Guide
Acronis Disk Director 11 Advanced Server Quick Start Guide Copyright Acronis, Inc., 2000-2010. All rights reserved. Acronis and Acronis Secure Zone are registered trademarks of Acronis, Inc. "Acronis Compute
Workflow Templates Library
Workflow s Library Table of Contents Intro... 2 Active Directory... 3 Application... 5 Cisco... 7 Database... 8 Excel Automation... 9 Files and Folders... 10 FTP Tasks... 13 Incident Management... 14 Security
Course overview. CompTIA A+ Certification (Exam 220 902) Official Study Guide (G188eng verdraft)
Overview This 5-day course is intended for those wishing to qualify with. A+ is a foundation-level certification designed for IT professionals with around 1 year's experience whose job role is focused
Digital Forensics Tutorials Acquiring an Image with FTK Imager
Digital Forensics Tutorials Acquiring an Image with FTK Imager Explanation Section Digital Forensics Definition The use of scientifically derived and proven methods toward the preservation, collection,
Extreme Networks Security Upgrade Guide
Extreme Networks Security Upgrade Guide 9034868 Published July 2015 Copyright 2012 2015 All rights reserved. Legal Notice Extreme Networks, Inc. reserves the right to make changes in specifications and
Digital Forensic Techniques
Digital Forensic Techniques Namrata Choudhury, Sr. Principal Information Security Analyst, Symantec Corporation Professional Techniques T23 CRISC CGEIT CISM CISA AGENDA Computer Forensics vs. Digital Forensics
Recovering Data from Windows Systems by Using Linux
Recovering Data from Windows Systems by Using Linux Published by the Open Source Software Lab at Microsoft. November 2007. Special thanks to Chris Travers, Contributing Author to the Open Source Software
Session 334 Incident Management. Jeff Roth, CISA, CGEIT, CISSP
Session 334 Incident Management Jeff Roth, CISA, CGEIT, CISSP SPEAKER BIOGRAPHY Jeff Roth, CISA, CGEIT Jeff Roth has over 25 years experience in IT audit, security, risk management and IT Governance experience
Recovering Data from Windows Systems by Using Linux
Recovering Data from Windows Systems by Using Linux Published by the Open Source Software at Microsoft, May 27 Special thanks to Chris Travers, Contributing Author to the Open Source Software Lab Most
Design and Implementation of a Live-analysis Digital Forensic System
Design and Implementation of a Live-analysis Digital Forensic System Pei-Hua Yen Graduate Institute of Information and Computer Education, National Kaohsiung Normal University, Taiwan [email protected]
