Ovido
Lingua
  • Inglese
  • Spagnolo
  • Francese
  • Portoghese
  • Tedesco
  • Italiano
  • Olandese
  • Svedese
Testo
  • Maiuscole

Utente

  • Accedi
  • Crea account
  • Passa a Premium
Ovido
  • Home
  • Accedi
  • Crea account

DF WK 4 Current Digital Foresics Tools

Acquisition

Acquisition : making a copy of the original drive
•Acquisition sub functions incudes

Physical data copy

Logical data copy

Data acquisition format

•Command-line acquisition

•GUI acquisition

Remote, live, and memory acquisitions


There are Two types of data-copying methods are used in software acquisitions:

1. Physical

2. Logical copying of the entire drive copying of a disk partition (better for encrypted drives)

Five Categories of Functions For Evaluating DF Tools

Five Categories of Functions For Evaluating DF Tools
1. Acquisition

2. Validation and Verification

3. Extraction

4. Reconstruction

5. Reporting for Evaluating DF To

Validation and Verification •Validation:

Validation and Verification

•Validation: A way to confirm that a tool is functioning as intended


•Verification: Proves that two sets of data are identical by calculating hash values or using another similar method


•A related process is filtering, which involves sorting and searching through investigation findings to separate good data and suspicious data Validation and Verification Subfunctions


•Hashing •CRC-32, MD5, SHA-1 (Secure Hash Algorithms) •Analyzing file headers •Discriminate files based on their types •Filtering •Good data from bad. Is based on hash values. (HINT: Check NSRL)

Extraction

The Recovery of Information

•Recovering data is the first step in analyzing an investigation’s data


Sub-functions of extraction :

•Data viewing

•Keyword searching

•Decompressing or uncompressing

•Carving/salvaging

•Decrypting encrypted files, folders, drives, and disks •Bookmarking or tagging

Data Carving

Data Carving is part of the EXTRACTION Phase

it is the process of reassembling files from raw data fragments when no file system metadata are available


.it Involves extracting and recovering data from a larger data set.


Data carving techniques frequently occur during a digital investigation when the unallocated file system space is analyzed to extract files.

Reconstruction

Reconstruction
•Is the process of rebuilding data files

•Re-create a suspect drive to show what happened during a crime or an incident


Methods of reconstruction

•Disk-to-disk copy

•Partition-to-partition copy

•Image-to-disk copy

•Image-to-partition copy

•Rebuilding files from data runs and carving


To re-create an image of a suspect drive

•Copy an image to another location, such as a partition, a physical disk, or a virtual machine

•Simplest method is to use a tool that makes a direct disk-to-image copy


Examples of disk-to-image copy tools: •Linux dd command •ProDiscover •Voom Technologies has “Shadow 3” tool

Reporting

Reporting

•To perform a forensics disk analysis and examination, you need to create a report


Sub functions of reporting

•Bookmarking or tagging

•Log reports

•Timelines

•Report generator

OpenSource Foresincs tools

Some Examples of OpenSource tools include:
•Wireshark (for network forensics) and NMAP

•Oxygen Forensics

•Sleuthkit •(use with Autopsy if you don’t like CLI!!)

•SANS SIFT (Linux/Ubuntu) •Volatility (great for memory forensics)

•CAINE (packed full of DF tools) •Computer Aided Investigative Env’t

•Xplico (great for email forensics)

Two types of Digital Forensics Tools

Two types of Digital Forensics Tools
1. Hardware forensic tools •Range from single-purpose components to complete computer systems and servers

• Write Blockers

• Tableau USB Bridge

• F.R.E.D. systems , or DIBS


2. Software

•Two types forensic tools

1. Command-line applications


2. GUI applications

• Pathways ProDiscover

• AccessData FTK

• PassMark OSForensics

• Guidance Encase

• Helix Pro • SANS SIFT •Commonly used to copy data from a suspect’s disk drive to an image file

The Forensic Recovery of Evidence Device (FRED) system

The Forensic Recovery of Evidence Device (FRED) system is a specialized hardware and software solution designed for digital forensics investigations. Developed by Digital Intelligence, FRED systems provide investigators with powerful and reliable tools to conduct detailed forensic analysis of digital evidence.

Key Features of the FRED System

Key Features of the FRED System:

1. High-Performance Hardware:

• Powerful Processors: Equipped with high-speed processors to handle intensive data processing tasks.

• Ample Memory and Storage: Large RAM and multiple storage options, including SSDs and HDDs, to accommodate extensive datasets and enable fast data access.

• Write-Blockers: Integrated write-blocking technology to prevent any modification of the original data during analysis, ensuring evidence integrity.

• Multiple I/O Ports: A variety of input/output ports for connecting different types of storage media, including USB, SATA, SAS, and more.

2. Specialized Software:

• Forensic Imaging: Tools to create exact bit-for-bit copies of digital storage devices, preserving the original evidence (e.g., FTK Imager, EnCase).

• Data Analysis: Applications for in-depth analysis of digital evidence, including file recovery, metadata examination, and timeline creation (e.g., Autopsy, X-Ways Forensics).

• Network Forensics: Tools to analyze network traffic and logs, useful in tracing cyber-attacks and identifying breaches (e.g., Wireshark).

• Memory Forensics: Utilities to analyze volatile memory (RAM) captures, often used to identify malware and other transient data (e.g., Volatility).

3. Ergonomics and Design:

• Modular Design: FRED systems are designed with modular components, making it easy to upgrade or customize based on specific investigative needs.

• Portable Options: Some FRED systems are available in portable configurations, allowing forensic investigators to conduct on-site examinations.

Linux Forensics Tools

Linux Forensics Tools:
SMART

•Designed to be installed on numerous Linux versions

•Can analyze a variety of file systems with SMART •Many plug-in utilities are included with SMART •Another useful option in SMART is its hex viewer


Helix 3 •One of the easiest suites to begin with

•You can load it on a live Windows system

• Loads as a bootable Linux OS from a cold boot

•**Some international courts have not accepted live acquisitions as a valid forensics practice


Kali Linux ,Formerly known as BackTrack ,Includes a variety of tools and has an easy-to-use KDE interface


Autopsy and SleuthKit •Sleuth Kit is a Linux forensics tool •Autopsy is the GUI browser interface used to access Sleuth Kit’s tools

Quiz
ენათმეცნიერებაჰსბსბს
漢字 L17
Charles
DF Wk 2 Processing Crime and Incident Scene
漢字 L16
UPQ 2
Chapitre 8
Ingles 2
CISSP Wk 7 Identity Access Management (IAM)
Social Grade 7 - Vocabulary
hsk
Problems and solutions
Literature and ArtsTopnotcher Cutieee
Social ScienceTopnotcher Cutieeeee
Life and Works of RizalTopnotcher Cutieeeeee
Proponents of TheoriesTopnotcher cutieeee
N5 Kanji
la influencia - copia
CHAPITRE 1 BLED
Chemistry of cooking T4 L5
verbes irréguliers
Kanji Japonais
la influencia
Conductismo Clásico
BIOLOGY EXAM!!!hmmmmmmmmmmmm
ᴍᴇᴅɪᴇᴠᴀʟ ᴇᴜʀᴏᴘᴇ
Muscular System
derecho internacional
actores
Code2
tipos de massas italianas
voc13
voc12
voc11
voc10
gs begrippen H4
Bimar aero (Ne contient pas les schémas)
UNIT7
Examen trastorns
MU AW 4
UNIT6
Entomology
Exámen
English Grade 7 - Types of Poems
English Grade 7 - Parts of Speech / Figurative Language
farrowing of an animal
jus
Azië
WHF 10
Questões da prova final
ielts
examen de neurólogia - copia
examen de neurólogia
Math Exam!!!!
t10
ingles
t9
ELA B30
t8
stations
chapter 4
java chapter 3
java chapter 2
chapter 1 creating java programsjava chapter 1
Aeronaves
Révisions dates 1Les dates clefs données en début d'année qui dessinent les grands axes.
ioc
t7
Iso: tonos/baros e topos. + sulfato,sulfeto sulfito diferença
t4
t3
Old English II Vocab
Science Grade 7 - Unit 5: Planet Earth
Core practical T4 L4
Ica Plu som är good to know! 🕺
Catalyst
TLR
mandu - copy
Bacteriology
social PAT
holi
fotoperiodicidad en ecología
transformacion digital
漢字 L15
African American History: American Revolutionary War for Independence Era II
kzkwk
cognicion y el lenguaje
religion exam
Science Grade 7 - Unit 3: Heat and Temperature
verbs
para empezar
Socials-Part D
chemistry exam review!A
español
GS AW 4
t2
Quiz. para magpalit kog milkteapassing 9/10
examen de mi novia
Quimica
¿Qué significa ésta palabra rusa?
Salesforce Data Cloud 1
vocabulary 3.8
quimica
Kroppsdelar
Biotecnología
ANTICOAGULANT (DRUG FUNDAMENTALS MODULE 2) WK3
STERIOD/CORTICOSTERIOD CONT'D (DRUG FUNDAMENTALS MODULE 2) WK3
unit 201 cabin crew
Ancient Quiz Study - copy
energie - techno
漢字 L14
bio exam
漢字 L13
漢字 L12
漢字 L11
漢字 L10
漢字 L9
漢字 L8
漢字 L7
Koude Oorlog
que es el periodo paleoliticojaja
Analisisnose
Fundamentos Examen unidad Ijajsjsjsjs
Biología
Science Grade 7 - Unit 4: Structures and Forces
Computer vision projects
Science Grade 7 - Unit 1: Interactions and Ecosystems
part 8
part 7
part 6
Ord-1
examen de historia
il governoesame
Cort costituzionaleesame
T. Preliminar
Estructura L.I
Duits schritt 26 (3vwo)
escritura de palabras con h,ch,ll,y,ñ,x,w,k,z
Duits schritt 23 D-N (3vwo)
quizz dates
dates connaissances
L quantité de mouvement et l'impulsion
le mouvement projectile
Regra dos porquês
Sentido conotativo e denotativo
Logística internacional (Inbound, Outbound, In House, Reversa)
Conceitos de processos de produção enxuta atuais como engenharia simultânea, con
Logística internacional (Inbound, Outbound, In House, Reversa)
sábados
t6
Human biology
Hitta rätt/släng problemglasögonen
Tecnología
Recursos humanos
ACTIVITY 1
ADMS 2400 chp 7
Psicología
Post Cuban missile crisis quizFInal HIstory quiz !!!!!
Historia-HORIZONTE POSCLASICO
Alim Y Cultura
ADMS 2400 chp 6
HP1 L
Glosario
Social Final
ADMS 2400 chp 5
physio
tennis
Calcio
nomi dei calciatori
ALI
LECTURE 9
Income inequality
Education
Théorie générale du droit de l'entreprise - Généralités
Fred ou George
Ciudad global
Vehicle
ccc section numbers
Biology
Historia-HORIZONTE PRECLASICO
psicología de la adultez y senectud
Kanji 3+4
Words #1
إختبار سنة 2013 (محين)
LECTURE 8
Rabelais
Autre
LECTURE 7
movimenti artistici
Compensating differentials
Final test 1
o/
Final test 2
fatima
Citologia
Minimum wages & imperfect competition
Egemonia Imperiale: Il Cinquecento
La globalizzazione nel 500
Il cinquecento
Computer Vision
BIOLOGIATodo acrrca de olimpiadas
ADMS 2400 chp 4
estudios sociales
99 Names of Allah
Paes historia- Parte dos - copia
ADMS 2400 chp 3
denver
ADMS 2400 chp 2
bio presentatie
spanish
LECTURE 6
tema 5
Bio Review
AlexisAutores
LECTURE 5
l'organisation fonctionelle des llantes à fleurs
chemistry
Legislación.
textiles
LR LD
Dynamic LS and LS
for job
METODOLOGIA DE LA INVESTIGACIÓN PARTE I
road knowlege sector 2
Assignment 2
Assignment 3
Assignment 5
Assignment 9
Assignment 1
Assignment 10
Assignment 8
historia-HORIZONTE ARCAICO
Lighthouse 13 U5 FlashcardsPractise learning the meaning of Lighthouse 13 U5 vocab
antibioticspharmacology
vocabulary 3.7
Band Final '24
les symptômes
personelle médicale
haniel
vocabulaire médical
Assignment 7
L'électricité
generos textuais
Historiaaaa
WHF 9
Labour Supply Elasticity
Individual Labour Supply
U-4 ingléshhjj