I've done a short ppt on how direct servlet is created and used in EnCase. Recently we often have such questions so to simplify my work I've done small ppt which follows manual and put in on the Slideshare. It is easier to discuss with ppt than with going trough manual pages.
Wednesday, June 1, 2016
Monday, May 30, 2016
Managing digital forensic lab
For last few weeks I found myself in awkward situation, almost like echo from some previous jobs,
preparing materials for training titled "Managing digital forensic laboratory". This is almost accidental event, a first run of that training since we announced it few years ago.
The story behind course is strange by itself too, It all started as result of a failure. There was one nice big project about setting up digital forensic lab, for dual purpose forensics and education. Huge effort was put into project, especially in preparation for managing lab materials and intro course for that. Since project didn't realise we did logical move, reused prepared materials, and squeezed into 3 day trainng expandable to 5 days. Basic theory is based on excellent "Building a Digital Forensic.Laboratory: Establishing and Managing a Successful Facility"book by Andrew Jones and Craig Valli. I've decided to add additional things based of recent development for datacenters and open source tools for compatibility and certification based on "Sarbanes-Oxley IT Compliance Using Open Source Tools, 2nd Edition" where we can show how to inexpensively build a managing and control infrastructure even on knoppix. For lab case management I've decided to implement Foreman tool and mention comparation with other case management tools like FTK lab.
To cover datacenter approach and introduce good practice in managing a lot of computing power, what is always missing I've decided to use "Enterprise Data Center Design and Methodology"
By: Rob Snevely. There is a lot of other papers and web resources to mention and talk about ...
preparing materials for training titled "Managing digital forensic laboratory". This is almost accidental event, a first run of that training since we announced it few years ago.
The story behind course is strange by itself too, It all started as result of a failure. There was one nice big project about setting up digital forensic lab, for dual purpose forensics and education. Huge effort was put into project, especially in preparation for managing lab materials and intro course for that. Since project didn't realise we did logical move, reused prepared materials, and squeezed into 3 day trainng expandable to 5 days. Basic theory is based on excellent "Building a Digital Forensic.Laboratory: Establishing and Managing a Successful Facility"book by Andrew Jones and Craig Valli. I've decided to add additional things based of recent development for datacenters and open source tools for compatibility and certification based on "Sarbanes-Oxley IT Compliance Using Open Source Tools, 2nd Edition" where we can show how to inexpensively build a managing and control infrastructure even on knoppix. For lab case management I've decided to implement Foreman tool and mention comparation with other case management tools like FTK lab.
To cover datacenter approach and introduce good practice in managing a lot of computing power, what is always missing I've decided to use "Enterprise Data Center Design and Methodology"
By: Rob Snevely. There is a lot of other papers and web resources to mention and talk about ...
Thursday, May 19, 2016
FER lecture "Moć forenzičkih alata"
Yesterday I done small 60 minutes lecture on my old UNI, going there always brings nostalgia back, remebering and daydreaming. What always hits you is how many years have passed. Faces looks same, bright, young only difference are labtops and smartphones all around, when I saw myself in reflection I feel a pang of jealousy, Amstrad 6128 and ZX81 from my days will be helplesly lost among new thingies around. Even mighty VAX under ULTRIX too..
With such thoughts, new wrinkles on my face, and new glasess I've get into old lecture room, same where 20 years ago we were playing with Expect langugage scripts tailoring some Cisco ATM switches configuration for experimental live video streaming.
This time skill was needed only to find right presenter stick all other was working more or less as expected. My battred Dell labtop was working well, MS Powerpoint 2016 has frozen only once, probably just to show who is the boss. In the audience was few familiar faces, in first row left my young and gifted colleague Savina Gruicic.
On the FER lecture home page there are links to video capture and links to presentation.
Dr Pale did intro words and I've started. My plan was to do short as possible, skimming on top of digital forensic topics, badmouth a bit about current tools and practices, show brief run trough Encase v6,v7 Ufed, get people thinking about and asking, hardest of all forcing myself to keep in 60 minutes boundaries. People there are all from computer science community, I just need to show a topic, put a few words on context and let them think laudly :)
At the end we put in some new cyber-X words, Cyber-Hygiene and Cyber-illiteracy really it is fun to do Cyber words.
There was plenty of questions I can recall only a few, Like where you can get careere and trainign for digital forensic in Croatia, it was hard to answer since in 2 weeks I'll do some work in Daka, Bangladesh to eran my living :) ..
With such thoughts, new wrinkles on my face, and new glasess I've get into old lecture room, same where 20 years ago we were playing with Expect langugage scripts tailoring some Cisco ATM switches configuration for experimental live video streaming.
This time skill was needed only to find right presenter stick all other was working more or less as expected. My battred Dell labtop was working well, MS Powerpoint 2016 has frozen only once, probably just to show who is the boss. In the audience was few familiar faces, in first row left my young and gifted colleague Savina Gruicic.
On the FER lecture home page there are links to video capture and links to presentation.
Dr Pale did intro words and I've started. My plan was to do short as possible, skimming on top of digital forensic topics, badmouth a bit about current tools and practices, show brief run trough Encase v6,v7 Ufed, get people thinking about and asking, hardest of all forcing myself to keep in 60 minutes boundaries. People there are all from computer science community, I just need to show a topic, put a few words on context and let them think laudly :)
At the end we put in some new cyber-X words, Cyber-Hygiene and Cyber-illiteracy really it is fun to do Cyber words.
There was plenty of questions I can recall only a few, Like where you can get careere and trainign for digital forensic in Croatia, it was hard to answer since in 2 weeks I'll do some work in Daka, Bangladesh to eran my living :) ..
Thursday, May 5, 2016
Setting up EnCase classroom in Polytechnic of Zagreb
Just today we managed to setup EnCase classroom with 10 workplaces. It was pleasure and fun, relaxed work with everyone cooperating. Really relaxing action
20.5.2016 Still no official photos from classroom... I don't know if this is just laziness or hush-hush
Actually this is the first official classroom for digital forensic with state of art commercial software. around
20.5.2016 Still no official photos from classroom... I don't know if this is just laziness or hush-hush
Actually this is the first official classroom for digital forensic with state of art commercial software. around
Tuesday, May 3, 2016
Cyber attacks and energy dependecy
In the sense of recent
attacks on power providing infrastructure around the globe, I've remembered my
thoughts when I was last time in Gulf countries, Bahrain and Saudi Arabia. These
countries are even intuitively related to energy. If you think on oil and
petrol first association is usually oil and money reach gulf countries. If you
think more there is also a most modern technology there, since it can be easily
bought and requires minimal local workforce to deal with it. It is same for all
other aspects of life conclusion Is this combination is extremely vulnerable to
cyber threats. They are impossibly depend on energy and technology to live everyday
life, more than any the place on earth, only maybe the scientific base on Antarctica
is more dependent. Last incidents show can misconfiguration or lack of proactivity
can lead to disaster. What makes me thinking are recent fires in Dubai and some
other issue which show “quality” control problems, and such problems are important
in cyber attacks. It will be nice to have time and opportunity to work more,
looks like very good situation for preventive digital forensics, but because of
sheer size something vendor agnostic like Google GRR tool.
4th May 2016,
Nice article on "Procurement: Saudis In Search Of Their Lost Work Ethic" StrartegyPage.com, which talks about quality problem, wokrforce etc, things so important in cyber vulnerability.
4th May 2016,
Nice article on "Procurement: Saudis In Search Of Their Lost Work Ethic" StrartegyPage.com, which talks about quality problem, wokrforce etc, things so important in cyber vulnerability.
Friday, April 8, 2016
Some raw thoughts on current digital forensics, IT security and data science
Recently I’ve been
tasked with writing down some thoughts as discussion ideas and teasers on current
digital forensics, It security and data science. Some of this were floating
around for a long time more as reaction to events than real effort to do a
serious discussion.
At first glance digital forensics and data
science does not have much in common, especially when we are talking about how
digital forensics is approached and executed today. What is usually not taken
into the account is the fact that digital forensics is the
part of both computer and
forensic science, two very different science fields. At the moment digital
forensics is a new field getting incorporated into forensics, digital specifics
should be recognized and incorporated into traditional forensic environment.
For start definitions should be stated. First
we can introduce forensics and digital forensics. Forensics is “The application
of scientific knowledge to legal problems" (Merriam-Webster), what
includes forensic medicine, physics, chemistry, dentistry, fingerprints, DNA,
firearm analysis, accounting all traditional sciences. In the other hand for
the digital forensics we have first idea of “Forensic Computing” by V. Venema,
D. Farmer late in 1990’s: „Gathering and analyzing data in a manner as free from
distortion or bias as possible to reconstruct data or what has happened in the
past on a system.”. When this definition of forensic computing is expanded with
digital evidence we get what is in current sense digital forensics. By
Wikipedia “Digital forensics and Computer forensics” is: defined as “Computer
forensics, sometimes known as computer forensic science is a branch of digital
forensic science pertaining to evidence found in computers and digital storage
media. The goal of computer forensics is to examine digital media in a
forensically sound manner with the aim of identifying, preserving, recovering,
analyzing and presenting facts and opinions about the digital information”. In
this context digital evidence or electronic evidence is defined
as “any probative information stored or transmitted in digital form
that a party to a court case may use at trial.”
To make things difficult digital evidence is the key element of digital forensics,
what makes it hard to accept in the traditional forensics and law
where sound physical evidence is golden standard. Also forensics science is not
dealing with big amount of data but with specific science scenarios and analysis
resulting in limited datasets, what causes different sensitivity and
understanding of the data and
computer science.
Even the basic Locard principle on which
forensic science is build up,
has its digital twist; Lockard’s Exchange Principle is "Every contact
leaves a trace" (Prof. Edmond Locard, c. 1910). It is perfectly correct,
log analysis was one of the first evolved branches of IT security and digital
forensics. .One of the key forensic principles is not to change evidence; when applied to digital forensics
means working with read only data copies with hash signatures providing proof
of data not being changed. Translating this to practical computing means
ability to do parallel processing limited only by media and processing bandwidth.
The core
problem of digital forensics today is the problem of processing huge volumes of
data. To be honest this is really a big unspoken obstacle
which is often overlooked, sometimes not understood by digital forensic
practitioners and even vendors. Disks size skyrocket from megabytes to tens of
terabytes; this sheer volume of data where relevant digital evidence is hidden
is a huge problem. Only to create a forensic copy of one terabyte disk you need
at least 3 hours and this is even before any analysis can be done. After that
step even more time consuming process of digital evidence finding and extraction
is started and it takes usually much longer - sometimes days are used in this
process. This step is analysis in digital forensics and is conceptually very
close to datamining process.
Current mainstream digital forensic tools are
not capable of efficient parallelism, automation or scripting and are limited
to Microsoft Windows platforms on Intel architecture, “general purpose PC
paradigm” which is not best choice for fast and efficient data processing.
Current problems and computing development makes
this issues practically unsolvable without using knowledge and experience form
other computing science fields, especially from data science. From data point
of view, we can separate digital forensics into two broad categories: classic
postmortem forensics and live forensic, in sense where we are dealing with
static data or dynamically changing data. In both situations we have to work
with raw data and transform it into meaningful digital evidence. This is even
more significant if we are talking about incident response in modern networked
systems. We can approach each end node involved in incident as data source
which has to be collected and analyzed; a situation where we have very
different types of data from raw binary disk and memory images to process structures,
elaborate log information or local agent database. At the moment all this data
is handled separately, not as a part of one picture. To address this issues in
efficient way data science knowledge should be used, to refine methods and
tools in digital forensics.
11.04.2016 link to draft presentation for this discussion
11.04.2016 link to draft presentation for this discussion
Wednesday, April 6, 2016
Datafocus 2016 and day after
Our small digital forensic conference finished yesterday, nice event a lot of people some interesting lectures and good food. Our colleague Steve Gregory caused a lot of interest, this year he was on MagnetForensic booth just across his former company booth. Steve was here since our first event becoming practically avatar for EnCase and GuidanceSoftware, this year he changed colors and caused a lot of "what are you doing on this boot and in this shirt" questions. On Guid booth was Mr.Jeff Hedlesky,
Forensic Evangelist from Guidance Software, answering questions about changes and events in GuiddanceSoftware. Looks like CEIC or EnFuse this year will be interesting probably dispersing some fears and providing some long expected news.
For me the most interesting lectures was by Steven Manson about intrepretation of electronic evidence.
Subscribe to:
Posts (Atom)