Thursday, June 11, 2015

EnCase v7 and some indexing woes

EnCase v7 is deeply oriented to indexing as fundamental step in investigation and data analyses, but looks like bad luck which EnCase had in v6 with indexing continues also in v7. It turns out in first few sub-versions of v7 indexing was not implemented correctly and in real life of not much benefit, more horror source.

Things get better and in lastest version 7.9 and 7.10, Now  indexing is working more or less ok, but with still some peculiarities and not easy to digest features. I'll compile in this articles some notes, tips  which maybe can help.

One quite useful thing from indexed data is to get list of keywords, it can be very useful in password cracking and many other purposes. In version 6 it was possible ti dump this data trough enscript, but in version 7 now this is in passware tool interface. Even if you don't have passware kit, dump can be done, it will generate index.words.txt file which contains data from index file. Documentation is missing and no explanation what is what.But still from there it is possible to feed some dictionary attack tools etc, you'll need some regular expression tools to further extract useful data from it.

A huge issue is also lack of examples, per instance there are predefined patterns in indexing for finding email addresses, credit card numbers etc, but no examples.

There is no clue whatsoever how it works at all, Trying combinations you'll get no result or some confusing errors, there is only one small passus in support forum about but no details, results are erratic even in the latest version v7.10.5.

In ordinary indexing search it is possible to use wild  chars and patterns but again it can be quite erratic, I was positive there are some issues with our local language localisation, but never been able to reproduce it in satisfactory way.  Very confusing issue is globbing in indexing search and regexp search in raw search. Since it is possible to combine both of it t in same search,  using two different query syntax is often misleading.








Tuesday, June 2, 2015

ERA conference Riga June 2nd 2015

Today I've done presentation "Collecting and processing electronic evidence and the essential difference between evidence and “traditional” forms of evidence" on conference  "Planning and Justifying the Search and Seizure of Electronic Evidence"  . 

I think I pressed listeners to much since I've done two presentations in one, first setting the terms and definitions of digital evidence and digital forensics and second presenting trough slides how to use EnCase v7 in basic digital investigation.
Impression are good, almost same good feeling as after Bahrain last week, but still I can say that there is a lot of issues in relations among lawyers and computer science.
One exciting talk on the margin of conference, so interesting that I lost my way to hotel, 
was about data center data seizure. Extremely interesting question because of possible technical twists and volume of data. 

There was set of very interesting presentation, very advanced,  I was last one and going fast to keep schedule. 

Ian Walden:
  • Computer forensics and the presentation of electronic evidence in criminal cases and
  • Planning and justifying the search and seizure of electronic evidence in the Clouds


Stephen Mason:
  • Challenges of international investigations (search and seizure) and other trial considerations (methods of presentation, admissibility tests)


Federico Paesano:
  • Investigating money laundering with bitcoins and other virtual currencies: challenges and solutions


Thursday, May 28, 2015

CyberCrime training in Bahrain


I've just been one among trainers on the "Training Course on Combating CyberCrime", organised by Judicial and Legal Institute, Kingdom of Bahrain in cooperation with GPEN, Global Prosecutors E-Crime Network.  It was very interesting event, very successful and really high above usual, perfect organisation by our hosts, judges, prosecutors, police officers from all Arab gulf states, with immense interest and will to participate, 
Instead of pure "slide & lecture" scenario, it was full interaction, questions, answers, case comments with perfect simultaneous translation,  Language is always problem, not only pure mother tongue to mother tongue, but also more important in our situation technical language to legal language and tradition. 
I'm sure that training gets its purpose, interaction and cooperation among all participants was from start, that was the key goal, basically all definitions and answers were provided by participants, trainers were more moderators and ones who asked hard questions.
The discussion and events makes me think about terms we use and its meaning I think I should write one post on word Cyber which is often used this days

Sunday, May 10, 2015

Competition workshop

Recently I was involved in a digital forensic workshop for a competition agency.

It is an interesting issue because a great deal of work in competition enforcement agencies today is related to handling digital evidence. There are a lot of document on the international competition  network site which lively present the state of anti cartel practice. Each anti cartel agency has its own procedures and history but there is one common thing, introduction of digital evidence support. Some agencies are even completely moved to electronic documents while others are handling paper documents or being completely on the paper documentation. The process which leads to digitization and accepting digital evidence is not an easy one, it takes a lot of time and effort, and usually requires thinking about procedures and documentation workflow in the anti cartel agency. Such processes can take a long time and have a lot of mishaps.
I was involved in preparing a  raid simulation as the basic part of the workshop, very nice  operation with a lot of things to learn.  The result of workshop was a set of forms and blueprints which give the full planing capability for the agency. The idea was well tested from disaster recovery and business continuity practices. A simple approach where you create a set of procedures and documents which drive you through the whole event, it also gives a nice opportunity for role play approach and testing scenarios. I hope we did a good thing.
Later on DataFocus2015 Mr. Mislav Kršulović from Croatian Competition Agency did presentation about "Dawn raid in practice", To my great pleasure this state of art example from real life showed our workshop was very close to reality.

Students and Image Forensics

After a long wait, I finally have a candidate from Vsite who is interested in image forensics, a perfect challenge. There are a lot of talks about tools, applications and methods on how to use image forensics in our law enforcement community.

Digital image forensics is a big field running at a very fast pace. Our position is more towards practical application and tools for handling and comparing images rather than basic scientific work. Most of the practical problems in our local community are in the classification and recognition of  images extracted from mobiles devices, computers etc. It boils down to handling hashes and effectively working with a huge number of files. I believe we will have to tackle this part of the situation in order to propose or implement a solution which can automate such tasks. 

We will all have to discuss the possibilities in order to combine the fresh inquisitive mind of the students with the tools and realities of law enforcement, while at the same time getting some practical results.  My idea is to shape a practical part for a graduation thesis into practical tools or systems which have to be used in real life and also to be a proof of concepts for further work and expansion,

I really hope for some nice student work, useful tools and a few published articles.

I'll post about how events will go, can be interesting and inspiring too.



Wednesday, April 29, 2015

Articles for Mipro 2015 conference

Mipro is nice technical conference in Opatija, our mother company IN2 is a sponsor so we put set of articles about digital forensics and security. There are very strict reviewers but we managed to get trough. I wrote about experience in mobile forensics  professional training since 2012 under posh title "Concepts and methodology in mobile devices digital forensics education and training". It is about relating our experience with issues mentioned in Stephen Pearson and Richard Watson book : “DigitalTriage Forensics”, Syngress ,July 13, 2010,  ISBN-13: 978-1-59749-596-7, and  Gary C. Kessler presentation :“Is Mobile Device ForensicsReally "Forensics"?”,  NIST Mobile Forensics Workshop, Gaithersburg, MD, June 2014. Paper get a rough recension, a lot of requests for clarifying,  I suppose the subject was interesting. I'll add article when it will available trough official conference site.
 "Digital Triage Forensics" is my old favorite, I loved since I read it.  Book  address practical issues in putting whole organization into motion, not only mobile  forensics issues. Unfortunately tools used are outdated, plenty of new versions and changes come since 2010,  but everything else is still extremely useful, especially if you are working with military or police. 

Sunday, April 12, 2015

DataFoucs 2015 - 31 March 2015 - Zagreb, Croatia

I've been forgetting to put a few lines about DataFocus 2015 in Zagreb from the 31st March 2015.  It's the fourth and got the best reviews.  As far as I was concerned, I was to remain only on the margins of the conference and on the lunch actively trying to avoid any responsibilities and enjoy good food and interesting lectures. However, this was not meant to be. There were a lot of interesting talks and a lot of interesting tools, NUIX, Belkasoft, FTK, EnCase, Oxygen. At the end there were a lot of happy winners with the lotttery, especially among our Police Accademy students. 


Workshops were fully attended with people popping in at the last minute. My own small contribution was an unusual one. For such events with international lecturers something can go wrong, Murphy's law is always somewhere around, and there is always a backup plan for emergencies, This time, lecturers for first lecture at legal track "Legal and Investigative Aspects of Bitcoin" were unable to get to Zagreb on time, the day before DataFocus.  Since the subject was extremely interesting it was decided not to replace the lecture with the scheduled backup, but to replace the lecturer with apologies and hopefully some add-on value. As the task landed on me, I had to do my best in preparing for that lecture in one day. To make things worse my knowledge about Bitcon, at the time, was twopence worth. In short it was a long 24 hours, I even decline attending the VIP dinner the night before the conference because I was studying :) :)

The original material by Vaciago Giuseppe and Dal Checco Paolo was very good and concise but, to me, a lot of details seemed missing. So I used resources from the excellent online book "Mastering Bitcoin By: Andreas M. Antonopoulos".  The further I went through the book the more impressed and intrigued I got. The author of Bitcoin was really a genius in more than one field.  The lecture went well, my friend Blerim Krasniqi has taken some pictures of lecture, it all went well.