Tuesday, June 23, 2015

Summer 2015 coming

It's 15C outside and heavy rain.. wonderful intro into glorious summer. I suppose it will be different summer, more in house and working one.

Since I'm feeling lazy and slow there is a set of unfinished posts here on the blog ...
"Problems with malware"  started 5/9/15
"Classification of digital forensic tools" started 5/1/15
"Tools and users woes" started  5/1/15
"Ransomware and some ideas" started  5/1/15
"Some post Riga conference thoughts" started  6/21/15
"Digital forensics and really big data" started  6/13/15
Hopefully this shameful list will force me to finish it ... to be honest I feel somehow restraint in writing. There are also some personal issues both with glorious 50th birthday coming 

Lecturing at Racunarstvo.hr slowly comes to end just two more lectures to go. I'm not satisfied this time, probably because I was not able to force myself to introduce new things into lecture. Somehow I feel I missed hearts & minds, probably to sleepy minds at lecture time 18:45 till 22:00.  I've introduced some points and discussions from ERA conferece as interesting live points in legal part.  The Bahrain training left some bouncing questions in my mind. It all remembers me on the old Science Fiction from Asimov and Stanislav Lem. The python lectures  was left out this time,  I was thinking to mix it up with practical command line linux issues like in B.J Grundy LinuxLeo guide.

NUIX is coming back to schedule to do preparations, actually to prepare it as part of our portfolio, but I feel I miss hardware for enough power to implement and test solutions.



Thursday, June 11, 2015

EnCase v7 and some indexing woes

EnCase v7 is deeply oriented to indexing as fundamental step in investigation and data analyses, but looks like bad luck which EnCase had in v6 with indexing continues also in v7. It turns out in first few sub-versions of v7 indexing was not implemented correctly and in real life of not much benefit, more horror source.

Things get better and in lastest version 7.9 and 7.10, Now  indexing is working more or less ok, but with still some peculiarities and not easy to digest features. I'll compile in this articles some notes, tips  which maybe can help.

One quite useful thing from indexed data is to get list of keywords, it can be very useful in password cracking and many other purposes. In version 6 it was possible ti dump this data trough enscript, but in version 7 now this is in passware tool interface. Even if you don't have passware kit, dump can be done, it will generate index.words.txt file which contains data from index file. Documentation is missing and no explanation what is what.But still from there it is possible to feed some dictionary attack tools etc, you'll need some regular expression tools to further extract useful data from it.

A huge issue is also lack of examples, per instance there are predefined patterns in indexing for finding email addresses, credit card numbers etc, but no examples.

There is no clue whatsoever how it works at all, Trying combinations you'll get no result or some confusing errors, there is only one small passus in support forum about but no details, results are erratic even in the latest version v7.10.5.

In ordinary indexing search it is possible to use wild  chars and patterns but again it can be quite erratic, I was positive there are some issues with our local language localisation, but never been able to reproduce it in satisfactory way.  Very confusing issue is globbing in indexing search and regexp search in raw search. Since it is possible to combine both of it t in same search,  using two different query syntax is often misleading.








Tuesday, June 2, 2015

ERA conference Riga June 2nd 2015

Today I've done presentation "Collecting and processing electronic evidence and the essential difference between evidence and “traditional” forms of evidence" on conference  "Planning and Justifying the Search and Seizure of Electronic Evidence"  . 

I think I pressed listeners to much since I've done two presentations in one, first setting the terms and definitions of digital evidence and digital forensics and second presenting trough slides how to use EnCase v7 in basic digital investigation.
Impression are good, almost same good feeling as after Bahrain last week, but still I can say that there is a lot of issues in relations among lawyers and computer science.
One exciting talk on the margin of conference, so interesting that I lost my way to hotel, 
was about data center data seizure. Extremely interesting question because of possible technical twists and volume of data. 

There was set of very interesting presentation, very advanced,  I was last one and going fast to keep schedule. 

Ian Walden:
  • Computer forensics and the presentation of electronic evidence in criminal cases and
  • Planning and justifying the search and seizure of electronic evidence in the Clouds


Stephen Mason:
  • Challenges of international investigations (search and seizure) and other trial considerations (methods of presentation, admissibility tests)


Federico Paesano:
  • Investigating money laundering with bitcoins and other virtual currencies: challenges and solutions


Thursday, May 28, 2015

CyberCrime training in Bahrain


I've just been one among trainers on the "Training Course on Combating CyberCrime", organised by Judicial and Legal Institute, Kingdom of Bahrain in cooperation with GPEN, Global Prosecutors E-Crime Network.  It was very interesting event, very successful and really high above usual, perfect organisation by our hosts, judges, prosecutors, police officers from all Arab gulf states, with immense interest and will to participate, 
Instead of pure "slide & lecture" scenario, it was full interaction, questions, answers, case comments with perfect simultaneous translation,  Language is always problem, not only pure mother tongue to mother tongue, but also more important in our situation technical language to legal language and tradition. 
I'm sure that training gets its purpose, interaction and cooperation among all participants was from start, that was the key goal, basically all definitions and answers were provided by participants, trainers were more moderators and ones who asked hard questions.
The discussion and events makes me think about terms we use and its meaning I think I should write one post on word Cyber which is often used this days

Sunday, May 10, 2015

Competition workshop

Recently I was involved in a digital forensic workshop for a competition agency.

It is an interesting issue because a great deal of work in competition enforcement agencies today is related to handling digital evidence. There are a lot of document on the international competition  network site which lively present the state of anti cartel practice. Each anti cartel agency has its own procedures and history but there is one common thing, introduction of digital evidence support. Some agencies are even completely moved to electronic documents while others are handling paper documents or being completely on the paper documentation. The process which leads to digitization and accepting digital evidence is not an easy one, it takes a lot of time and effort, and usually requires thinking about procedures and documentation workflow in the anti cartel agency. Such processes can take a long time and have a lot of mishaps.
I was involved in preparing a  raid simulation as the basic part of the workshop, very nice  operation with a lot of things to learn.  The result of workshop was a set of forms and blueprints which give the full planing capability for the agency. The idea was well tested from disaster recovery and business continuity practices. A simple approach where you create a set of procedures and documents which drive you through the whole event, it also gives a nice opportunity for role play approach and testing scenarios. I hope we did a good thing.
Later on DataFocus2015 Mr. Mislav Kršulović from Croatian Competition Agency did presentation about "Dawn raid in practice", To my great pleasure this state of art example from real life showed our workshop was very close to reality.

Students and Image Forensics

After a long wait, I finally have a candidate from Vsite who is interested in image forensics, a perfect challenge. There are a lot of talks about tools, applications and methods on how to use image forensics in our law enforcement community.

Digital image forensics is a big field running at a very fast pace. Our position is more towards practical application and tools for handling and comparing images rather than basic scientific work. Most of the practical problems in our local community are in the classification and recognition of  images extracted from mobiles devices, computers etc. It boils down to handling hashes and effectively working with a huge number of files. I believe we will have to tackle this part of the situation in order to propose or implement a solution which can automate such tasks. 

We will all have to discuss the possibilities in order to combine the fresh inquisitive mind of the students with the tools and realities of law enforcement, while at the same time getting some practical results.  My idea is to shape a practical part for a graduation thesis into practical tools or systems which have to be used in real life and also to be a proof of concepts for further work and expansion,

I really hope for some nice student work, useful tools and a few published articles.

I'll post about how events will go, can be interesting and inspiring too.



Wednesday, April 29, 2015

Articles for Mipro 2015 conference

Mipro is nice technical conference in Opatija, our mother company IN2 is a sponsor so we put set of articles about digital forensics and security. There are very strict reviewers but we managed to get trough. I wrote about experience in mobile forensics  professional training since 2012 under posh title "Concepts and methodology in mobile devices digital forensics education and training". It is about relating our experience with issues mentioned in Stephen Pearson and Richard Watson book : “DigitalTriage Forensics”, Syngress ,July 13, 2010,  ISBN-13: 978-1-59749-596-7, and  Gary C. Kessler presentation :“Is Mobile Device ForensicsReally "Forensics"?”,  NIST Mobile Forensics Workshop, Gaithersburg, MD, June 2014. Paper get a rough recension, a lot of requests for clarifying,  I suppose the subject was interesting. I'll add article when it will available trough official conference site.
 "Digital Triage Forensics" is my old favorite, I loved since I read it.  Book  address practical issues in putting whole organization into motion, not only mobile  forensics issues. Unfortunately tools used are outdated, plenty of new versions and changes come since 2010,  but everything else is still extremely useful, especially if you are working with military or police.