Monday, July 2, 2012
DFIR SUMMIT 2012: A Look Back
Last week was the SANS Digital Forensics and Incident Response Summit in Austin, Texas. I have to say the summit was probably my favorite conference experience I have had thus far. It was a great mix of networking and content. Your days are filled with spectacular information and you are still provided with a lot of opportunity to meet new people and discuss. Plus, if you're active in the #DFIR twitter space, then it was an excellent opportunity to actually meet many of the people who use it. I would highly suggest that, if you the ability to attend the summit. I hope to be back in the coming years.
As I mentioned, days at the summit are filled with a lot of great content from the speakers at the conference. I have to say my favorite presentation, personally, was When Macs Get Hacked from Sarah Edwards. This was simply because it was something I have yet to really see or research and provided a great baseline of knowledge where to look for information and various tools to utilize. This presentation went very well with Andrew Cases's talk on Mac Memory Analysis with Volatility.
Nick Harbour gave an EXCELLENT talk on Anti-Incident Response, that I really enjoyed a lot. His talk was pretty technical and provided a lot of insight into the mind of an attacker. Jeff Hamm's presentation on Carve for Records Not Files provided a lot of good information that should be considered in an investigation. Event records very well may be much easier to carve for than an entire event log file. Where a file is likely to miss all the information, carving for a fragment of that information is a lot simpler and may be just as useful.
Cindy Murphy, this years Forensic 4Cast Examiner of the Year, gave an amazing keynote to open the summit. I thought it was very interesting and insightful. If nothing else, I think a lot of people left the talk inspired and proud to be a part of this community. Mike Viscuso's ending talk on Security Cameras - The Corporate DFIR Tool of the Future was also very interesting and, at least personally, gave a lot to think about the future of investigations and what that brings with big data.
This is just a small sample of what the Summit offered, after all there were two tracks going the whole time (I couldn't make it to everything). The presentations are posted already on SANS website here: http://computer-forensics.sans.org/community/summits. I highly recommend that you go through and take a look for yourself. I really enjoyed the Summit, meeting everyone was awesome and it was nice to be around people that share the same passion (it's reinvigorating).
Labels:
Conferences,
DFIR,
InfoSec,
SANS,
SUMMIT
Friday, April 27, 2012
My Education in Digital Forensics
I have been in school awhile now, and was lucky enough to have a few classes with Mark McKinnon. Mark, was kind enough to share his passion for the digital forensics field with not only me, but the hundreds of students who've attended his courses at Davenport University here in West Michigan over the last few years. In many ways my many thanks go to him and everything he's been willing to share, and much of this post will kind of stem from his knowledge and suggestions he provided me with progressing into this field. This will be a recap of how I went about learning about digital forensics, mostly pertaining to analysis of Microsoft Windows computers and, eventually, was lucky enough to get certified. Also, I'm writing towards the digital forensic interested people, not those in the field (although I would love to hear comments or suggestions for alterations to my following suggestions in the comments).
Disclaimer:
First, there is a lot of great material available on digital forensics but you have to realize reading this books do not make you an expert. That being said, I highly recommend getting as much hands on experience as you possibly can. Many of the books I will be suggesting contain a list of tools they use or show output from tools. It's highly advantageous to download these tools and execute the same commands to analyze more practically what you're reading about. Be prepared to get hands on with a lot of different software, and be prepared for mistakes and know that making a mistake is OK as it's all a learning experience. Also, I'm not an expert! Take my advice with a grain of salt. I am just beginning in this field and want to share what I can.
Mentors and Involved Community
That being said, let me get into it. As I mentioned, I started my interest in digital forensics (DF) in seat at Davenport University in their IAAS 421 course, taught by Mark McKinnon. This was an invaluable introduction to a lot of topics involved in DF from file systems, to registry and memory analysis. If you are unsure about DF as a possible career, I highly recommend trying to find an intro course. After taking the course I went from thinking as forensics as an interest to I wanted it to be my career. Another reason I suggest taking a course is with the right teacher you can use them as a springboard into the field. I quickly found Mark as a forensic guru who could point me in the right direction, and if he didn't know an answer he probably knew someone who he could get it from. Too me, I think finding people you can bounce ideas off of is a great way to advance in this field. I quickly got involved on twitter and started following people in the industry and began to frequent #DFIR searches. This was a great way to figure out what was happening in the community and proved to link to a lot of great resources and blogs that I could reference for other things.
Books
I started diving deep into forensics books, and per suggestion, I started with Brian Carrier's File System Forensic Analysis. As you may have guessed this book is pretty much regarded as the holy grail of forensic analysis of file systems. This book is highly technical, and for me at the time, was somewhat dry. However, this book provides knowledge that will be called upon by almost every other book I'll suggest (most in fact reference it). Therefore, I suggest you start here as it's an essential forensic knowledge foundation.
Next, I picked up a copy of Handbook of Digital Forensics and Investigation. This would be the first of Eoghan Casey's books that I read. This book was recommended to me by Eric Huber on Twitter. This book was a great reference and was a lot broader than Carrier's book, but it allows you better insight as to how the field is and what sort of artifacts to look for throughout an investigation.
This is not how I read the following, but how I would now recommend reading these books as it will flow much better. After finishing Casey's book, Mark McKinnon introduced me to the writing styles of one Harlan Carvey. I started with Windows Forensic Analysis Second Edition (WFA2E) which is a great resource on Windows forensic artifacts. I would then suggest reading Windows Registry Forensics as it'll delve deeper into the registry, where WFA2E will act as a great precursor for. You'll learn more about the Windows registry than you probably think may be possible. The next book I suggest is Windows Forensic Analysis Third Edition, as this will progress even further your understanding of Windows operating systems and will move into the more modern Windows versions, including Windows 7. However, I will say before reading those three texts. Start by reading Digital Forensics with Open Source Tools authored by Cory Altheide and Harlan Carvey. I say this because it goes over a lot of artifacts for every system, but I suggest it more so because it goes over how to set up a lab machine and provides a great list of tools to utilize and install on your system that will allow you to do analysis without purchasing the more expensive software.
I next chose to read Digital Evidence and Computer Crime, Third Edition: Forensic Science, Computers, and the Internet again by Eoghan Casey. I chose this book for one distinct reason, as all of the other books were valuable in learning about the forensic artifacts available in an environment, as is this text, but Casey provides two chapters on the legal side of forensics. These chapters provide a lot of great information on legal side of forensics in both the United States and European nations. Another interesting aspect of the text is more of the psychological end of how a criminal acts when using digital devices.
Challenges
Hopefully, while you're reading those texts you're following along with them and performing a bit of hands on work with each book. Getting familiar with all of the different tools and how they work is one of the more fun things you get to do in forensic investigations. Also, application testing and verification is a big part of the industry, so it's a good idea to get used to it from the beginning. Two of the best things I have found to play with tools are the SIFT forensic workstation, this was made available from SANS and DEFT which are both free live Linux distributions which include tons of tools to play with and get familiar with.
Once you've gotten used to your tools and read a bit, I suggest looking for forensic challenges. You can find them from several area's, i started out with a few of my mates from college and we did the DC3 Cyber Crime Challenge, which is an annual competition put on by the Department of Defense. Even if you don't want to submit challenges this is a great way to get some hand-on work done, as you're often given an artifact to analyze and you have to give information regarding that artifact. Challenges vary and can take a lot of time, but they are well worth it I feel if you're new to the field.
Back to being involved with the community, there are many forums and mailing lists you can become a part of. I suggest going out and once you have your feet wet with forensics a bit and become involved with them. You can quickly learn the types of issues you can face on a daily basis within the forensic community. Sometimes you'll find a challenge presented there, I was lucky enough to win a SANS Lethal Forensicator Coin this way.
Development
When I started my capstone for my bachelors degree, I was having a tough time to come up with what I wanted to do. If you're not familiar a capstone, it is essentially a big project (150+) where you come up with some sort of product (paper/software/whatever) and then present that topic to a group. Once again I leaned on Mark McKinnon, and he basically convinced me to make my own forensic analysis machine and software for quick triage of system. Seemed like a lot of work and a big challenge, and it was; but it was worth it.
Creating my own machine and triage script forced me to recall everything I had learned. I had to know what tools to use and then validate those tools. For the triage script, I had to know what artifacts are more relevant to an investigation and can provide actionable intel through quick analysis. It also, got me into the world of computer programming, something I had never attempted before. After my capstone project I turned the triage script into a pretty neat tool that I released as open-source, it's still in it's infancy but it's progressing nicely.
Stay Involved
The biggest suggestion I can make? Get involved and join the conversation! It doesn't take a lot to get out and provide feedback or commentary. If you look at my blog I post about once a month and probably on average about 5 times a week on twitter, something that takes maybe 3 hours of my time a month. If you're out testing tools, provide feedback (things you like, didn't work or things you'd like to see). They may not be seen by many but providing back to the community is a great way to stay involved and keeps you dedicated. A great reason to stay involved, also, is because this industry especially evolves quickly with new applications that could produce a relevant artifact released almost daily. Staying up-to-date on that stuff can mean a lot to an investigation, so it's important to at least keep a rough idea of what's going on in the wild; you shouldn't just stop your education.
Also, if you're researching something interesting and come across an interesting artifact take a quick minute to share it. Start a blog or something and share experiences! If you look at my blog, I don't think I have put up a lot of stuff, but I like to think it's valuable at least to someone. If you can share your failures along with your successes, as we can all learn together.
Conferences are a great way to stay involved as well. You can also meet a lot of great people this way. I have only had the opportunity to sit in at a few conferences, but they've always been a blast. Sometimes they can be expensive; however, you can think of them as an investment often times as networking within the industry is a great way of possibly getting jobs. In my job now, I'm more likely to look at someone for an internship or whatever if I know they're keeping up and possibly have seen them at conferences or meetings I attend. Often time you can find meetings for cheap, I am lucky enough to have several free meetings around me locally, even though they're not dedicated to forensics it's in the general realm of information security. And if nothing else, you can sign on once a month and check out Mike Wilkinson's awesome idea of a monthly forensic meetup online known as DFIRonline.
How I Used This All
From the time I sat in my first digital forensics course to today it's been about 18 months. It was a long and a very fun process of learning all of this stuff. During that time, while pursuing my bachelors degree I was lucky enough to get an internship in an information security office and then able to turn that opportunity into an analyst position where PART of my duties include forensics. But, I was able to get sent to Florida for SANS 2012 where I took Forensics 408 or Computer Forensic Investigations - Windows In-Depth with Ovie Carroll and Lee Whitfield. This opportunity was amazing! The course covers in 6 days what I learned over the course of a year and a half and then some. After reading all those texts and keeping up with events, I had learned a foundation to where everything was familiar. However, the course will put it into context for you on how you'll use the information you used put it into an investigation and then report it properly. If you get the opportunity, I highly suggest taking it. After taking the course, I went over the text material they provide to you for a couple of weeks and took the exam weeks after the course. After 18 months I went from an interested party to now a GIAC Certified Forensic Examiner. It took a lot of time and dedication, but it has been a lot of fun and I can't wait to continue (NEXT is SANS FOR 508 and the GCFA! since they re-wrote it). Also, I want to thank all the people who helped me get where I'm at, including all the previously mentioned authors, the great people on the #DFIR twitter realm, the people at SANS and especially Mark McKinnon.
That's about all I have to say and share on the subject. I hope you enjoyed reading, and I would love to hear other people's takes on this topic about what they did to get where they're at, as I'm not done with my journey and would like to learn from someone smarter than me. :)
Disclaimer:
First, there is a lot of great material available on digital forensics but you have to realize reading this books do not make you an expert. That being said, I highly recommend getting as much hands on experience as you possibly can. Many of the books I will be suggesting contain a list of tools they use or show output from tools. It's highly advantageous to download these tools and execute the same commands to analyze more practically what you're reading about. Be prepared to get hands on with a lot of different software, and be prepared for mistakes and know that making a mistake is OK as it's all a learning experience. Also, I'm not an expert! Take my advice with a grain of salt. I am just beginning in this field and want to share what I can.
Mentors and Involved Community
That being said, let me get into it. As I mentioned, I started my interest in digital forensics (DF) in seat at Davenport University in their IAAS 421 course, taught by Mark McKinnon. This was an invaluable introduction to a lot of topics involved in DF from file systems, to registry and memory analysis. If you are unsure about DF as a possible career, I highly recommend trying to find an intro course. After taking the course I went from thinking as forensics as an interest to I wanted it to be my career. Another reason I suggest taking a course is with the right teacher you can use them as a springboard into the field. I quickly found Mark as a forensic guru who could point me in the right direction, and if he didn't know an answer he probably knew someone who he could get it from. Too me, I think finding people you can bounce ideas off of is a great way to advance in this field. I quickly got involved on twitter and started following people in the industry and began to frequent #DFIR searches. This was a great way to figure out what was happening in the community and proved to link to a lot of great resources and blogs that I could reference for other things.
Books
I started diving deep into forensics books, and per suggestion, I started with Brian Carrier's File System Forensic Analysis. As you may have guessed this book is pretty much regarded as the holy grail of forensic analysis of file systems. This book is highly technical, and for me at the time, was somewhat dry. However, this book provides knowledge that will be called upon by almost every other book I'll suggest (most in fact reference it). Therefore, I suggest you start here as it's an essential forensic knowledge foundation.
Next, I picked up a copy of Handbook of Digital Forensics and Investigation. This would be the first of Eoghan Casey's books that I read. This book was recommended to me by Eric Huber on Twitter. This book was a great reference and was a lot broader than Carrier's book, but it allows you better insight as to how the field is and what sort of artifacts to look for throughout an investigation.
This is not how I read the following, but how I would now recommend reading these books as it will flow much better. After finishing Casey's book, Mark McKinnon introduced me to the writing styles of one Harlan Carvey. I started with Windows Forensic Analysis Second Edition (WFA2E) which is a great resource on Windows forensic artifacts. I would then suggest reading Windows Registry Forensics as it'll delve deeper into the registry, where WFA2E will act as a great precursor for. You'll learn more about the Windows registry than you probably think may be possible. The next book I suggest is Windows Forensic Analysis Third Edition, as this will progress even further your understanding of Windows operating systems and will move into the more modern Windows versions, including Windows 7. However, I will say before reading those three texts. Start by reading Digital Forensics with Open Source Tools authored by Cory Altheide and Harlan Carvey. I say this because it goes over a lot of artifacts for every system, but I suggest it more so because it goes over how to set up a lab machine and provides a great list of tools to utilize and install on your system that will allow you to do analysis without purchasing the more expensive software.
I next chose to read Digital Evidence and Computer Crime, Third Edition: Forensic Science, Computers, and the Internet again by Eoghan Casey. I chose this book for one distinct reason, as all of the other books were valuable in learning about the forensic artifacts available in an environment, as is this text, but Casey provides two chapters on the legal side of forensics. These chapters provide a lot of great information on legal side of forensics in both the United States and European nations. Another interesting aspect of the text is more of the psychological end of how a criminal acts when using digital devices.
Challenges
Hopefully, while you're reading those texts you're following along with them and performing a bit of hands on work with each book. Getting familiar with all of the different tools and how they work is one of the more fun things you get to do in forensic investigations. Also, application testing and verification is a big part of the industry, so it's a good idea to get used to it from the beginning. Two of the best things I have found to play with tools are the SIFT forensic workstation, this was made available from SANS and DEFT which are both free live Linux distributions which include tons of tools to play with and get familiar with.
Once you've gotten used to your tools and read a bit, I suggest looking for forensic challenges. You can find them from several area's, i started out with a few of my mates from college and we did the DC3 Cyber Crime Challenge, which is an annual competition put on by the Department of Defense. Even if you don't want to submit challenges this is a great way to get some hand-on work done, as you're often given an artifact to analyze and you have to give information regarding that artifact. Challenges vary and can take a lot of time, but they are well worth it I feel if you're new to the field.
Back to being involved with the community, there are many forums and mailing lists you can become a part of. I suggest going out and once you have your feet wet with forensics a bit and become involved with them. You can quickly learn the types of issues you can face on a daily basis within the forensic community. Sometimes you'll find a challenge presented there, I was lucky enough to win a SANS Lethal Forensicator Coin this way.
Development
When I started my capstone for my bachelors degree, I was having a tough time to come up with what I wanted to do. If you're not familiar a capstone, it is essentially a big project (150+) where you come up with some sort of product (paper/software/whatever) and then present that topic to a group. Once again I leaned on Mark McKinnon, and he basically convinced me to make my own forensic analysis machine and software for quick triage of system. Seemed like a lot of work and a big challenge, and it was; but it was worth it.
Creating my own machine and triage script forced me to recall everything I had learned. I had to know what tools to use and then validate those tools. For the triage script, I had to know what artifacts are more relevant to an investigation and can provide actionable intel through quick analysis. It also, got me into the world of computer programming, something I had never attempted before. After my capstone project I turned the triage script into a pretty neat tool that I released as open-source, it's still in it's infancy but it's progressing nicely.
Stay Involved
The biggest suggestion I can make? Get involved and join the conversation! It doesn't take a lot to get out and provide feedback or commentary. If you look at my blog I post about once a month and probably on average about 5 times a week on twitter, something that takes maybe 3 hours of my time a month. If you're out testing tools, provide feedback (things you like, didn't work or things you'd like to see). They may not be seen by many but providing back to the community is a great way to stay involved and keeps you dedicated. A great reason to stay involved, also, is because this industry especially evolves quickly with new applications that could produce a relevant artifact released almost daily. Staying up-to-date on that stuff can mean a lot to an investigation, so it's important to at least keep a rough idea of what's going on in the wild; you shouldn't just stop your education.
Also, if you're researching something interesting and come across an interesting artifact take a quick minute to share it. Start a blog or something and share experiences! If you look at my blog, I don't think I have put up a lot of stuff, but I like to think it's valuable at least to someone. If you can share your failures along with your successes, as we can all learn together.
Conferences are a great way to stay involved as well. You can also meet a lot of great people this way. I have only had the opportunity to sit in at a few conferences, but they've always been a blast. Sometimes they can be expensive; however, you can think of them as an investment often times as networking within the industry is a great way of possibly getting jobs. In my job now, I'm more likely to look at someone for an internship or whatever if I know they're keeping up and possibly have seen them at conferences or meetings I attend. Often time you can find meetings for cheap, I am lucky enough to have several free meetings around me locally, even though they're not dedicated to forensics it's in the general realm of information security. And if nothing else, you can sign on once a month and check out Mike Wilkinson's awesome idea of a monthly forensic meetup online known as DFIRonline.
How I Used This All
From the time I sat in my first digital forensics course to today it's been about 18 months. It was a long and a very fun process of learning all of this stuff. During that time, while pursuing my bachelors degree I was lucky enough to get an internship in an information security office and then able to turn that opportunity into an analyst position where PART of my duties include forensics. But, I was able to get sent to Florida for SANS 2012 where I took Forensics 408 or Computer Forensic Investigations - Windows In-Depth with Ovie Carroll and Lee Whitfield. This opportunity was amazing! The course covers in 6 days what I learned over the course of a year and a half and then some. After reading all those texts and keeping up with events, I had learned a foundation to where everything was familiar. However, the course will put it into context for you on how you'll use the information you used put it into an investigation and then report it properly. If you get the opportunity, I highly suggest taking it. After taking the course, I went over the text material they provide to you for a couple of weeks and took the exam weeks after the course. After 18 months I went from an interested party to now a GIAC Certified Forensic Examiner. It took a lot of time and dedication, but it has been a lot of fun and I can't wait to continue (NEXT is SANS FOR 508 and the GCFA! since they re-wrote it). Also, I want to thank all the people who helped me get where I'm at, including all the previously mentioned authors, the great people on the #DFIR twitter realm, the people at SANS and especially Mark McKinnon.
That's about all I have to say and share on the subject. I hope you enjoyed reading, and I would love to hear other people's takes on this topic about what they did to get where they're at, as I'm not done with my journey and would like to learn from someone smarter than me. :)
Tuesday, April 10, 2012
Review of Windows Forensic Analysis and Windows Registry Forensics
Both "Windows Forensic Analysis (Third Edition)" and "Windows Registry Forensics" are authored by Harlan Carvey and he is the author of a few other books regarding digital forensics. This will be a short review of both books. I really enjoyed both of these books. If you've ever read anything from Harlan, his writing style is very easy to follow and understand. Each book is laid out in a manner that makes sense as far as being applied practically.
Windows Forensic Analysis is the third installment to Harlan's Windows forensics books; however, as he says in the intro you should think of it as a companion to the second edition rather than a re-write replacement. This book includes all the latest and greatest information from the latest Windows 7 release. Things like volume shadow copies, application analysis, and a summary of registry analysis provide great insight on Windows Artifacts. Chapters on malware detection and timeline analysis are especially exceptionable.
Windows Registry Forensics, I like to think of it, is an extension to Windows Forensic Analysis books. The Windows registry is a treasure trove of evidence for analysis. Registry forensics does an excellent job of not only outlining most of the artifacts that are known about, but gives you a background on available tools that can be used to analyze these artifacts. The case studies are especially helpful in relating the discussed artifacts to practical experience.
Both books are fantastic, and I would highly suggest adding them to your digital forensics library and put them next to at least the second edition of Windows Forensic Analysis. Honestly, I feel like all three books should be considered one big compendium on Windows digital forensics. I would also say that, at this point, there isn't a better collection of material on the subject of Windows analysis. If possible, I would recommend setting up a lab with various Windows machines so you can test and play with all of the artifacts you will learn about. Also, that will give you a chance to install the various tools mentioned in the text and test them out for yourself.
Thursday, March 1, 2012
File Tags and Digital Forensics
So I was bored one day and decided that with school and work,
I just wasn’t busy enough and I needed a new project. I wanted to do some research, preferably in
the realm of digital forensics. I
started talking to my buddy Rob Marmo (@robmarmo) and the idea of looking how
Windows utilizes the tag properties within certain files came up. Eventually, after some thought and
consideration we decided that it would make for an extremely fun project that
would make for a great booster for our experience. As it ends up it was a great learning
experience in doing research and developing a way to utilize the information.
Background
If you are not familiar, Windows
introduced the ability to “tag” files in Windows Vista. This feature allows the user to add a desired
keyword to certain file types so they could easily be categorized and searched
within the Search function they included within Vista as well. Here is an example of how you can tag your
files:
Your other option for tagging your file is via the file properties
option for the file. If the file format
supports tagging you will see the option available within the “Details” tab,
like so:
These file tags are a great way to organize information in a
user customized way. To me, that is why
file tags are quite interesting from a forensic point of view, as these tags
are inputted manually via the user’s input.
So it’s quite possible to say that if a file is tagged with a certain
keyword it may provide that file with an added value of interest to an investigation.
How It Works
After a lot of looking and failed
avenues, I was finally able to get a handle on how Windows implements the
ability to File Tag. First, you may have
noticed that I said only certain file types can be tagged. I don’t deliberately state the files that are
tagged because it is a variable. When
you begin the tagging process, simply put, the tags are inserted into an XML
that is then inserted into the file. How
this is handled varies on the file type.
This determination is handled by reading the registry. If you look at
HKEY_CLASSES_ROOT\SystemFileAssociations in the registry, you will find a list
of various file types registered within the operating system. Each file type has two keys of interest for
our purposes the “FullDetails” and the “PreviewDetails”. Within these keys are several values, and the
one for file tags is “System.Keywords”.
This value says there is a way for Windows to store the tags within the
file. The actual injection of the XML is
done via a property handler that is based on the file type, often done via a
DLL.
There is
another part the file tagging system, beyond simply adding the keywords to a
file. As you recall, I mention that this
implementation was intended to allow for quick searching of files by these
keywords via the Windows Search function.
This plays an interesting point with the file tagging system. As you enter in these keywords this creates
an interaction with the Windows Search Index.
I created a quick animation GIF to show how the Search Index works as I
understand it:
As you can see, the search index works with a data
store. Those data stores work with the
Search function and filters, as well as a notification system. If certain parameters are met they are then
gathered and sent to the System Index, which is actually a database locally
stored on the system at:
C:\ProgramData\Microsoft\Search\Data\Application\Windows\Windows.edb *
*It should be noted that this location can be altered via the Index Options
in the Advanced options.
This is a interesting database and seems to be proprietary to
the Microsoft Operating System and is utilized by a few of their
applications. If you’re interested in
taking a look at the database, I was able to by doing the following:
- Turn off Windows Search Service (This essentially unlocks the DB so you can use it)
- Navigate to the Index location
- Make a copy of the index EDB file
- You can turn back on Windows Search Service
- Download and install an EDB Viewer (I suggest EseDB Viewer from Woanware)
- Open your copied EDB file in the viewer
Viewing the Search Index provides an interesting look at all
the information that your Windows systems can analyze in a short amount of
time. As best as I can tell the Search
Index database is utilized by the tagging system for the preview
generation. While you’re inputting a
tag, often time you will find that upon entry once you type in a letter you
will be given option of tags. These are
tags that have previously been applied to files, and from what I can tell these
are pulled from the Search Index database.
The “PreviewDetail” key discussed earlier is how the registry knows you
can get these tags via preview and then the property handler works with the
index.
Interest in Recovery
Again, each file type handles tag in
a different way; it is dependent upon the property handler assigned to it. How these handlers deal with the data and
inject it into the files is different, and through my testing of various files
types and how they dealt with the file tags I came across an interesting
discovery. Some of file types store tag
data not only within the file XML but also in various parts throughout the
file. In testing I was able to see when
tags were added or modified, and even if the file tags have been deleted (or
not viewable by the OS as Windows will only read tags from the XML), they are
still located within the file and viewable within the hex. Now, this only occurs in certain file types
with, dare I say, inefficient property handlers. Looking at the new Office formats like .docx
it handles XML with a higher proficiency it writes most all its properties to
XML and then archives it and then is read via Word or whatever. To me that makes for much more efficient way
to deal with files. However, when we
look at something like a .jpeg, it writes the tags to the file in different
locations based upon the interaction.
Forensically, this provides an investigator with an added way to look at
a file. My thought was if you have a
file that has a MAC timestamp of all the same times exactly, but you see that
within the file that it has indications that tags were added or modified it may
indicate that the file timestamps may have been altered.
Future
I am still in the research phase with
this information, but this is everything I have gathered thus far. I have developed a proof of concept
application that is working and pulling files that have been tagged and
readable by the OS. It’s still in
development, and I plan and getting it out to the community eventually once I
have it optimized and have added all the features I wish to include. Also, you may be wondering how I came to
acquire this information, so I am planning on posting a research and
implementation article as well that will describe the research I did in a fair
amount of detail with pertinent examples and such. It may also include how I learned to program
the tool I am developing as well. I
think explaining the thought process behind research and development may be
beneficial to the community and hopefully inspire others to do the same by
providing some background and basic thought process.
Hope you enjoyed this, and if you have any thoughts on the implications of file tags and how they can be utilized in an investigation I would love to hear them. Leave a comment or e-mail me at: michael.ahrendt@gmail.com
Labels:
DFIR,
File Tags,
Recovery,
Research,
Search Index
Wednesday, February 15, 2012
Review of Digital Evidence and Computer Crime
Just finished “Digital Evidence and Computer Crime: Forensic Science, Computers and the Internet”
by Eoghan Casey and featuring other contributing authors, and it’s quite
good. I bought this book because I
wanted an all-encompassing book that provided insight on the various aspects of
an investigation, especially the legal portion.
And in this aspect the book does an excellent job, and is in-depth in
area’s I have yet to see in other books.
The book is divided into five portions digital forensics, digital
investigations, apprehending offenders, computers and network forensics. For me the book was worth it for the first
three portions; however, the computers and network portions, while a good start,
there are more in-depth books that provide better insight.
Part I: Digital Forensics, was one of my favorite parts
of the book. It provides the reader with
a good background on where digital forensics comes from and how it has
evolved. It details the role of the
investigator in a case and the complications with digital evidence (the portion
applying to levels of certainty was very enlightening). I really enjoyed the portions of the book
relating to both US and European law.
This was an aspect I was looking to learn more about and the book
provides a great overview while outlining the specific important parts of
popular cyber law.
Part II: Digital
Investigions, is all about the process. Casey
does a good job of applying the tradition scientific method to the digital forefront. Applying it in this way it provides an easy
to apply method to the investigative process.
Not focusing on the specifics but more the outline of the thought
process, which allows you to go beyond knowing the specifics. Methods for conducting investigations,
handling crime scenes and reconstruction are discussed, as well as, going into
motives.
Part III:
Apprehending Offenders, was rather unexpected when I looked through the
table of contents and even more so when I read the chapters. However, in this case unexpected was
excellent. Various scenarios of need of
investigation are discussed like cyber stalking and computer intrusions, and
then delve into the victimology of the scenarios. This was really interesting to me, as it
provides a psychological aspect to the investigative process; something I then
realized can really help with an investigation.
Part IV and V:
Computers and Networking are pretty much what I expected. The computer portion really does give a great
foundation of knowledge, and if this is one of your beginning journeys it’s a
great place to start. It does go over
the background of important artifact information like file system structure,
basics of file recovery, browser artifacts, and the registry. It also provides good info on Unix and Mac
systems. The network portion is quite detailed
describing the various layers of the network topology. There is a lot of great
information in these chapters that was a great review of knowledge.
Overall, the book was enjoyable from start to finish and
I would recommend it to anyone looking for a great overview of digital forensic
investigation process from start to finish.
I am happy to add this book to my growing reference library.
Coming Up:
So, I have a lot going on. I have the following books to read (expect reviews):
- Windows Forensic Analysis 3rd Edition
- Practical Malware Analysis
- Digital Triage Forensics
- Windows Internals 6th Edition
I also have some research that I wish to share regarding File Tagging, with maybe a tool to follow eventually. So look for that as well.
Labels:
Book,
Digital Forensics,
Review
Monday, January 16, 2012
Automated Triage Utility
A New Utility
Well, it has been awhile since my last post. I have been busy finishing up Capstone course work at Davenport University. For my Capstone project I selected to focus on digital forensics and created a workstation for evidence examination with a Windows 7 host. On top of that, I elected to create a script that would perform basic triage functions with known commands and utilities. I developed the script with the AutoIt language based on a recommendation from a friend. The course allowed me to develop a proof-of-concept application that did quite a bit, but it did it very poorly. So a few long nights later, I re-did it all and made it work a bit better and do a few more interesting things, discussed later. After reading Corey Harrell's recent blog post about his new script, I decided I would share my tool as well since it's a small way I can contribute to the community I love.
I've posted the project on Google Code here: http://code.google.com/p/triage-ir/
The Requirements
As I mentioned previously, the script I created utilizes other applications to function. First off, it utilizes your standard 'cmd.exe' from the Windows system (found at C:\Windows\System32). Eventually, I hope to make it so it doesn't need a copy of the command prompt in the folder but the syntax in the script does not seem to be working properly at this point.So the application folder will look something like this:
You will notice that there is also a tools folder. This, obviously, will be where I have the tools required for the script stored. Unfortunately for licensing reasons, I do not include the tools needed. The tools are free, so you can download them as follows:
- Sysinternals Suite - Mark Russinovich
- DumpIt - MoonSols
- MD5DEEP & SHA1DEEP - Jesse Kornblum
The Function
The script is designed to perform basic triage commands, as well as acquire evidence automatically on the system. I designed the script to be ran from a flash drive, but you can really run it from anywhere. All reports and evidence will be collected in the script directory under a Incident folder with a time stamp ("mm-dd-yy Incident"). The tool should perform the following functions:
- Gather Information on
- System Information
- Running Processes
- Services Information
- NTFS Information
- Mounted Disks
- Directory Structure
- Scheduled Tasks
- AutoRun
- Account Settings
- Logged in Users
- IP Configuration
- Routes
- Active Connections
- ARP
- DNS
- NETBIOS
- Network Shares
- Shared Files
- Connected Sessions
- Workgroup PCs
- Capture Evidence
- Prefetch
- Recent Folder
- Jump Lists (Windows 7)
- SYSTEM hive
- SECURITY hive
- SAM hive
- SOFTWARE hive
- Current User NTUSER.DAT
- All user's NTUSER.DAT
- Random Access Memory
- Preserve Data
- MD5 Hashing
- SHA1 Hashing
All of this contained in a simplified graphical user interface. Many of the commands are modular so you can choose what commands and what items you wish to run or capture, with a simple check box. When you run the script you should get to see something like this:
The Results
Once you've selected your choice of modules you simply hit run and then you will see a new folder created in the script folder named "mm-dd-yy Incident". This folder if you run everything you will see something like this:
You'll get a lot of information regarding the PC you run the tool on. All of it sectional going to its own report. This was the easiest way for me to setup reporting. My hope is to someday create a centralized html file for easy access to all of the information in an easily navigated web page. The evidence folder is where you'll find all of your stored data. It will look a little like this:
You should find copies (used robocopy to retain metadata settings, I hope) of the Recent Folder, Prefetch Folder, and Jump List folders if you are in Windows 7. You will also notice it can rip all of your registry hives for quick analysis with your favorite tool. Considering adding a Reg Ripper module so you can get quicker reports from extracted registry data.
Future
Full disclosure, this script is a work in progress at the moment. I can't promise it will work for everyone. I'm hoping some of you will be kind enough to test it out and send me your feedback and errors so I can hopefully ensure reliability of it. Also, if you have ideas that you would like to see implemented within the script just let me know and I will try to implement them properly. As of right now, I am simply continuing to work on getting the script to run without the copied command prompt and adjusting the tool to a better order of volatility when executing the commands. Also I need to add some sort of progress monitoring and clean up execution windows a bit. Any and all suggestions are welcomed! You may contact me at: michael.ahrendt@gmail.com
Again, you may download the script here. You can choose to just use the executable or, if you have AutoIt, you can run from the source code of the same name.
Hope you enjoy.
Saturday, October 1, 2011
Review of Metasploit: A Penetration Tester's Guide
Metaspoit: A Penetration Tester's Guide (MAPTG) from David Kennedy (@Dave_Rel1k), Jim O'Gorman (@_Elwood_), Devon Kearns (@dookie2000ca), and Mati Aharoni (@backtracklinux) is probably the foremost resource one can obtain for learning the basics of the Metasploit framework. The book is for those behind the curve a little bit and haven't used Metasploit yet. I feel like the book does a great job of delivering on what it promises, a foundation knowledge of the ins and outs of the great framework. By the time you finish the book you should understand how to use the framework; you most likely will not understand all of it, but it gives you great information on how you can figure it out really through utilizing the many utilities within the tool.
Let me start this review off by stating my personal opinion on how you should utilize this book: build a test penetration lab and follow the books instructions as you go along. Take advantage of the appendices! Appendix A will tell you how to setup your test environments, both your attack machines and your victim machines. Appendix B is your cheat sheet and quick reference for the numerous commands you'll be using. I suggest starting here and just familiarize yourself here before you begin. This is not what I did, but in retrospect I really wish I had.
The book doesn't waste time, after going into the basics of what will occur in a standard penetration test. The authors state that this book is not the best source for understanding all that can occur in a Pen Test and refer to the Penetration Test Execution Standard as a better source of gaining better insight on the subject if you're looking for it. Next the book cover's the basics of metasploit so you can get around the console with better familiarity, or options you have if you want more information. These chapters are small and cover the essentials of what you'll need to know to get through the book if you have no prior knowledge about the tool. The following chapters, which I will not cover in depth, go step-by-step through a basic Pen Test outline. They start and information gathering and go all the way into creating your own exploits to automating your process with scripts within the framework.
Every chapter covers it's subject very well. They're very concise and to the point, which I enjoy a whole lot. Also, most of the chapters include examples of how to run the tools, and what output should look like (which is why I suggest you set up a lab environment and run the commands as your read them). At times, I wish the chapters were a bit more in-depth, especially the creation of exploits chapter; however, that is probably a bit outside the scope of this particular book. I especially enjoyed the chapters on creating exploits and the power of the Social-Engineering Toolkit. The final chapter uniquely summarized what was learned in the book by explaining how to simulate a penetration test, and if completed properly will have you exploiting your vulnerable test lab in no time.
I highly would recommend this book to anyone who is looking to get into Metasploit a lot more. It gives you a great base to learn the tool, and if nothing else spawn even more of a desire to learn more (I know it did for me). I started this book with very base knowledge of the Metasploit framework, and after some testing and the guidance of this book I feel a lot more comfortable with using the amazing power behind Metasploit. You can pick this book up for about $28 dollars on Amazon, this is an amazing value! I would suggest if you even have an interest in penetration testing that you pick up this book and read it.
Labels:
Book,
Metasploit,
Review
Subscribe to:
Posts (Atom)

