Digital Forensics Module 4 CS 996
Hard Drive Forensics Acquisition Bit for bit copy Write protect the evidence media EnCase for DOS Safeback (NTI: www.forensics-intl.com) Analysis EnCase FTK (www.accessdata.com) WinHex Forensic Edition 2/23/2005 Module 4 2
Acquisition Steps With EnCase Create EnCase boot disk DOS boot disk Network boot disk Start subject computer with boot disk Acquire data to storage computer Network acquisition Drive to drive acquisition Parallel cable acquisition Windows acquisition 2/23/2005 Module 4 3
EnCase Resources Academic CD Instructor Notes User Manual excerpts on analysis Training Manual www.guidancesoftware.com Online videos 2/23/2005 Module 4 4
EnCase Acquisition Geometry Network cable acquisition NETWORK CROSSOVER CABLE SUBJECT COMPUTER STORAGE COMPUTER 2/23/2005 Module 4 5
EnCase Acquisition Geometry, cont. Drive to Drive acquisition IDE CABLE STORAGE COMPUTER SUBJECT HARD DRIVE 2/23/2005 Module 4 6
Analysis With EnCase Basic navigation String searches (key words, GREP, etc.) Signature match Registry analysis (compound file) Email analysis (compound file) File viewers (third party viewers) 2/23/2005 Module 4 7
EnCase Image File Contains more than raw dd sector image Case information header CRC for each 32KB of data MD5 checksum for entire image Image verification Does CRC match for each 32KB block 2/23/2005 Module 4 8
Analysis With EnCase Install software Initialize case Drag and drop evidence file into EnCase Bookmarks: reporting Need to keep track of key findings 2/23/2005 Module 4 9
Initialize Case: EnCase Scripts Allow custom forensic analysis Program in C++ like API Pre-made scripts Initialize Case Download from www.guidancesoftware.com Install in: c:\program files\encase\scripts\examples Running scripts: View Scripts Select Script Run View report => Bookmarks 2/23/2005 Module 4 10
Using EnCase Scripts Image filtering for porn investigation Find victims; find all images Need to look through 10,000+ images Aspect ratio theory Select images with 33-40% aspect ratio Reject images that are square (+/- 2 pixels) Reference: www.armordata.com 2/23/2005 Module 4 11
Using Bookmarks Save important data for report View Bookmarks: Create New Folder Text Images 2/23/2005 Module 4 12
2/23/2005 Module 4 13
2/23/2005 Module 4 14
Navigating Case View Table Signature analysis (in Search function) Hash analysis Gallery Timeline Report Disk 2/23/2005 Module 4 15
2/23/2005 Module 4 16
2/23/2005 Module 4 17
2/23/2005 Module 4 18
2/23/2005 Module 4 19
Finding Evidence Sorting columns in table view Filters, queries and scripts Recovering folders Keyword search 2/23/2005 Module 4 20
2/23/2005 Module 4 21
Filters, Queries and Scripts Filters Use built-in capabilities Create queries when filter is run Queries Combine more than one filter in semi-custom query Scripts Create your own search function using C++ like language 2/23/2005 Module 4 22
2/23/2005 Module 4 23
2/23/2005 Module 4 24
2/23/2005 Module 4 25
String Search Adding keywords Choose files/folders to be searched Configure search 2/23/2005 Module 4 26
EnCase Search Method First does logical search Next does sector by sector Compound files like.pst and.dat need to be mounted separately CLUSTER N PHONE TAP CLUSTER N+1 2/23/2005 Module 4 27
2/23/2005 Module 4 28
2/23/2005 Module 4 29
2/23/2005 Module 4 30
2/23/2005 Module 4 31
2/23/2005 Module 4 32
File Signatures Stated extension on evidence file Header information in the file itself Matches? Reference for file signatures: www.garykessler.net 2/23/2005 Module 4 33
2/23/2005 Module 4 34
2/23/2005 Module 4 35
Compound File Analysis Registry Email Files that are composed of multiple layers 2/23/2005 Module 4 36
Access Registry 2/23/2005 Module 4 37
Win98: user.dat 2/23/2005 Module 4 38
View Email Folder Compound file Locate.dbx or.pst files View file structure 2/23/2005 Module 4 39
2/23/2005 Module 4 40
2/23/2005 Module 4 41
File Viewers Look at file outside Encase Add: View => File Viewers Create association: View => File Types Double click on file: copies and opens with viewer QuickView Plus www.avantstar.com 200+ different file formats Eliminates problems with trojans, viruses, etc. 2/23/2005 Module 4 42
Add File Viewer 2/23/2005 Module 4 43
Create Association (View Filetypes) 2/23/2005 Module 4 44
Next Lab Assignment Familiarize yourself with EnCase Complete the posted lab assignment 2/23/2005 Module 4 45