I was recently taken down by an almost almighty flu. Among numerous cups of tea and aspirins there was time to catch-up with reading and visit old web locations. It was refreshing to visit V. Venema porcupine.org site and read book and classroom slides in detail. There is my favorite definition of forensic computing and probably the earliest scholar writing on digital forensic, still very much worth of reading. When I'm lecturing digital forensics on uni, I'm always referencing to this site and its ideas. With the time understanding of UNIX like OS diminished among students, but still is is something what IT expert have to read if wants to in IT security. Unfortunately this site of often only referenced in digital forensics curriculums, what is a great shame. Brian Carrier book on file system forensic build on knowledge you can get from porcupine,
Wednesday, March 8, 2017
Thursday, February 23, 2017
windows 10 unix power tools and forensic tools
Since win 10 has ability to use UNIX power tools in native environment it gives a nice field to experiment. In theory tools like bash, awk, sed, grep, ed, vi ... and many more can be integrated into forensic process with standard commercial tools like encase or ftk or whatever can run on windows 10 platform.
It was possible even earlier trough cygwin or othet similar tools but with more or less trouble, converting data with iconv etc ..
There is great potential, but I'm skeptical since even existing ordinary windows script like tools were not much used. There is no reason to change this just because of UNIX power tools.
In the other hand it will provide much simpler environment around tools like volatility, I always dread way how volatility was handled in some training materials I've seen for commercial digital forensic software. The script command will now be natural and all IO will be processed much more consistent way :) :) I suppose the "expect" will be also able to run on windows 10.
I'll try it a bit and post results, this is nice extension possibility for current trend of using python in forensics
Some time ago I was writing about using cmd line grep from cygwin to filter out result of sweep operation, it was not integrated but still shows the basic idea. Perl is here very mature solution, but tow drawback exists, knowledge and unicode handling. Lack of knowledge is definitely the biggest problem especially current attitude to "exotic" knowledge, as we've seen in problems with swift attacks.
It was possible even earlier trough cygwin or othet similar tools but with more or less trouble, converting data with iconv etc ..
There is great potential, but I'm skeptical since even existing ordinary windows script like tools were not much used. There is no reason to change this just because of UNIX power tools.
In the other hand it will provide much simpler environment around tools like volatility, I always dread way how volatility was handled in some training materials I've seen for commercial digital forensic software. The script command will now be natural and all IO will be processed much more consistent way :) :) I suppose the "expect" will be also able to run on windows 10.
I'll try it a bit and post results, this is nice extension possibility for current trend of using python in forensics
Some time ago I was writing about using cmd line grep from cygwin to filter out result of sweep operation, it was not integrated but still shows the basic idea. Perl is here very mature solution, but tow drawback exists, knowledge and unicode handling. Lack of knowledge is definitely the biggest problem especially current attitude to "exotic" knowledge, as we've seen in problems with swift attacks.
Wednesday, February 1, 2017
EnCase training changes
Looks like GuidanceSoftware or now GUID decided to close down its network of international training partners (ATP). There were also some internal reduction since Chicago training center was closed in 2016. Now 90 day closing period is on , by end of April 2017 it all should be closed.
I suppose that will be harsh option for police forces of smaller no-english speaking countries, Training will probably has translators service involved ...
I suppose that will be harsh option for police forces of smaller no-english speaking countries, Training will probably has translators service involved ...
Sunday, November 13, 2016
Graduation exams at VSITE
Last week I've been on a few final graduation exams. One of the candidates Antonio Zekić did perfectly. His thesis "Forenzička analiza malicioznih programa" was under done my mentorship, I had hardy anything to do, just to enjoy reading
Here is summary and keywords of the thesis:
"This thesis briefly describes the process of identifying, documenting and collecting data which is subject to forensic analysis. Techniques described include the process of proactive data collection, forensic hard drive duplication and collection of other key evidence.
It was done from the real life everyday work practice, we are thinking of extending our lab exercises based on this paper because our current materials are bit old, The problem we have with RFOR curriculum at Vsite is cronical lack of trained people so materials and equipment stays unchanged for a long time.
Here is summary and keywords of the thesis:
"This thesis briefly describes the process of identifying, documenting and collecting data which is subject to forensic analysis. Techniques described include the process of proactive data collection, forensic hard drive duplication and collection of other key evidence.
The thesis also presents
methods used in forensic analysis of collected data and key evidence which includes
analysis of the file system, memory image, Registry database, Prefetch files, scheduled
tasks and Event log entries. Most commonly used malware persistence mechanisms are
described along with dynamic and static analysis of malicious software.
The thesis concludes
with the practical work based on an the actual case in a which pre-prepared
computer is infected with malicious software. The process of forensic analysis
presented in the practical work includes analysis of memory image using the Volatility tool and its modules as well
as file system analysis which is carried out using the Autopsy tool. The thesis also describes the techniques of dynamic
and static analysis of malicious programs conducted in order to collect the information
about the malicious program itself, its functions and purpose."
Keywords:
Forensic analysis, malware, memory
analysis, hard disk analysis, static analysis, dynamic analysis, Volatility,
Autopsy
It was done from the real life everyday work practice, we are thinking of extending our lab exercises based on this paper because our current materials are bit old, The problem we have with RFOR curriculum at Vsite is cronical lack of trained people so materials and equipment stays unchanged for a long time.
Tuesday, November 1, 2016
Urgent Issue with Encase v8 and Windows 10
It was just announced with v8.02.01, there is a big problem with foreign languages (no plain English), indexing is not working correctly.
In the "EnCase Forensic Version 8.02.01 Release Notes October 25, 2016 Found in Version 8.02.01";
Quote: "FOR-5348: Foreign languages are not properly indexed when running EnCase Forensic on a Microsoft Windows 10 operating system."
To make things worse Microsoft stops selling windows 7 and 8, so all new sells installations are now in Limbo.
Work around is not using windows 10, or using virtualization on windows 10 if it is not possible to install windows 7 on your machine. Actually for any stronger machine more than 8 cores and more than 64 GB of RAM the good idea is virtualization, since most of forensic software can not utilize full resources.
6.11.2016
There wa also additional problem which is looks like solved now, Initial distribution of v8.02.01 was done without correct certificate for dongles, result was EnCase starting in acquisition mode, accessing and reading licence dongle correctly but being unable to register with it. Debug output from codemeter shows that straight. It was about two days to get correct certificates distributed. In mean time v7.14.01 get out too I have not even touch it yet.
I have a horrible wooden feeling of deja-vu on early days of v7 ..
The good news is that keyword / raw search in now how it was to be in v6, with even conditions and filters able to work on search results. Still there is no method of accessing code of default conditions, Copy feature is not yet implemented, you have to do like this How to edit or reuse system provided condition code in EnCase v8
19.12.2016
Since all this start we have v8.03 roll out, with programmable pathways, and still issues with indexing and keyword searches. I've noticed that keyword search can't be updated till at least one keyword search was successful, or at least it behaves in that way in my environment. I have not yet check indexing but there is a lot of yammer on forum about indexing troubles.
Programmable pathways looks a bit unfinished and rough, it all boils down to to create simple investigation workflow or a high level program ... I'm tired of pointing finger on such issue and concept well known from other area of computing science :) :)
Instead of using wizard to copy from one pane to another why not to write
open investigation "myinvestigation" by template "basic"
add evidece file x.ex01
do processing
do indexing
do find partiotins and mount findings
tag search by keyowrdlist "listone"
bookmark findings
end
20.12.2016
I forget to mention issues with new licence manager schema :) there are so many issues now that it is easy to forget about some of them. GuidanceSoftware did some licence technology change in version 8, probably with some good reason, but that caused a lot of problems (I've posted few lines about it and v8.02.01 and first roll out) . At the moment SAFE and NAS are separated into two distinctive services SAFE and LM (licence manager) we have a lot of problems in one university classroom with this "migration" process. There is hugely ovecomplicated procedure how to do migration from v7 safe/nas to v8 safe/lm but it does not correctly cover educational licences.. Here is the link to official procedure.
At the end after detailed testing and checkup it was working, but we get into one of the features :) The final LM issues was Tools->options ->Licence manger entry about IP address. It was a chain of events. Form documentation it is not clear that you have to put there not only IP address of LM but a TCP port too. Also looks like there is no validation on input values for that field. So we have first failure of putting only IP, support suggested to add port to, and here the second error fired, during copy paste somehow one blank before IP was copied into filed and that was enough to break it. so instead of "IP:PORT" it was "IP:PORT" invisible error and a lot of figuring out what is wrong...
This is how it should be, without any leading invisible chars ..
22.3.2017
Again almost a nightmare with classroom at one of our educational clients, with edu licencees now on the LM. It was renewed and forms for safe/lm arrived, actually a links to upload page. We followed procedure and get new safe/l m certificates. Everything works and looks magnificent but only one thing was bothering me, a expiration time visible trough help->about was same as before renewal, a possible quirk .. In fact it was not quirk, renewal failed, since Guid was unable to send to us a real dongle extension certificate. A lot of chatting with tech support to find out what was wrong, we got apologize but also a living fear about upgrades and new versions...
29.3,2017
Correct dongle certificate arrived,with apologize, but now safe/lm is not working almost unbelievable situation. Looks like whole Guid certificate generation system was broken when we send request to Guidance. So back to support portal to get all this was Guidance messed up.
6.4.2017
Mess is finally over, with latest dongle extension certificate, for forensic v8, LM and SAFE can not be on the same machine, even if in SAFE a.03 installer there is an recommended configuration to use both SAFE and LM, but this is for Enterprise version. So we got instruction what to do, uninstall safe, enable LM and it is working.
11.4.2018
A year later, with licence upgrade same torture again ..opentextguidance send wrong certificate ..
In the "EnCase Forensic Version 8.02.01 Release Notes October 25, 2016 Found in Version 8.02.01";
Quote: "FOR-5348: Foreign languages are not properly indexed when running EnCase Forensic on a Microsoft Windows 10 operating system."
To make things worse Microsoft stops selling windows 7 and 8, so all new sells installations are now in Limbo.
Work around is not using windows 10, or using virtualization on windows 10 if it is not possible to install windows 7 on your machine. Actually for any stronger machine more than 8 cores and more than 64 GB of RAM the good idea is virtualization, since most of forensic software can not utilize full resources.
6.11.2016
There wa also additional problem which is looks like solved now, Initial distribution of v8.02.01 was done without correct certificate for dongles, result was EnCase starting in acquisition mode, accessing and reading licence dongle correctly but being unable to register with it. Debug output from codemeter shows that straight. It was about two days to get correct certificates distributed. In mean time v7.14.01 get out too I have not even touch it yet.
I have a horrible wooden feeling of deja-vu on early days of v7 ..
The good news is that keyword / raw search in now how it was to be in v6, with even conditions and filters able to work on search results. Still there is no method of accessing code of default conditions, Copy feature is not yet implemented, you have to do like this How to edit or reuse system provided condition code in EnCase v8
19.12.2016
Since all this start we have v8.03 roll out, with programmable pathways, and still issues with indexing and keyword searches. I've noticed that keyword search can't be updated till at least one keyword search was successful, or at least it behaves in that way in my environment. I have not yet check indexing but there is a lot of yammer on forum about indexing troubles.
Programmable pathways looks a bit unfinished and rough, it all boils down to to create simple investigation workflow or a high level program ... I'm tired of pointing finger on such issue and concept well known from other area of computing science :) :)
Instead of using wizard to copy from one pane to another why not to write
open investigation "myinvestigation" by template "basic"
add evidece file x.ex01
do processing
do indexing
do find partiotins and mount findings
tag search by keyowrdlist "listone"
bookmark findings
end
20.12.2016
I forget to mention issues with new licence manager schema :) there are so many issues now that it is easy to forget about some of them. GuidanceSoftware did some licence technology change in version 8, probably with some good reason, but that caused a lot of problems (I've posted few lines about it and v8.02.01 and first roll out) . At the moment SAFE and NAS are separated into two distinctive services SAFE and LM (licence manager) we have a lot of problems in one university classroom with this "migration" process. There is hugely ovecomplicated procedure how to do migration from v7 safe/nas to v8 safe/lm but it does not correctly cover educational licences.. Here is the link to official procedure.
At the end after detailed testing and checkup it was working, but we get into one of the features :) The final LM issues was Tools->options ->Licence manger entry about IP address. It was a chain of events. Form documentation it is not clear that you have to put there not only IP address of LM but a TCP port too. Also looks like there is no validation on input values for that field. So we have first failure of putting only IP, support suggested to add port to, and here the second error fired, during copy paste somehow one blank before IP was copied into filed and that was enough to break it. so instead of "IP:PORT" it was "
29.3,2017
Correct dongle certificate arrived,with apologize, but now safe/lm is not working almost unbelievable situation. Looks like whole Guid certificate generation system was broken when we send request to Guidance. So back to support portal to get all this was Guidance messed up.
6.4.2017
Mess is finally over, with latest dongle extension certificate, for forensic v8, LM and SAFE can not be on the same machine, even if in SAFE a.03 installer there is an recommended configuration to use both SAFE and LM, but this is for Enterprise version. So we got instruction what to do, uninstall safe, enable LM and it is working.
11.4.2018
A year later, with licence upgrade same torture again ..opentextguidance send wrong certificate ..
Tuesday, September 20, 2016
How to edit or reuse system provided condition code in EnCase v8
It is a bit strange combination since v8 EnCase returned back condition/enscript pane from v6, but with unexpected twist. Why to be simple if it can force you to hack your way.
Probably because in v6 users were able to modify system provided conditions and render it useless now it is impossible for user to see edit/open code of condition and use it as template for further development. You can only execute code and hope it is what you think it is since you can see what it is doing :)
Fortunately conditions and rest are still plain txt files somewhere on your disk and you can basically copy it from system provided path into your own user path and edit it. Plainly it is manipulation trough file system. Remember it is in internal format not easily readable by plain humans.
Conditions pane now contains two folders:
Default folder contains all system provide conditions, while User is for your development, to edit anything you have to be in User sub folders, since User is also system folder and no-editable for users.
So how to simply hack this this to see code and reuse it ?
1) open condition pane and in "User" sub folder add new sub folder, this is only place where you are allowed to make folder as user or add new condition. It is on right-click action on your mouse
2)find in the Default folder condition you like to edit/analyze and right-click "Browse" on it. This will open widows explorer in folder containing your chosen condition.
Select your chosen condition and copy it by CRTL-C or right-click copy option, than
close explorer window
3) In condition pane go to "User" folder, select you folder you created there in step (1) and right-clik browse on it. This will open windows explorer window where you can paste your chosen condition.
Close explorer window
4) Condition pane, on "User" folder right-click "refresh" that will show your condition in your sub folder,
5) choose your condition and right-clink "Edit" on it, you can edit and see how it works!!!!!
All this will be unneeded if copy function is still there in condition pane ...
Ages ago I've mentioned that it will be very good to force practice of standardized help or man page for each enscript or condition or filter but it will be never done.
PS: I'm quite sure this works for filters too
25.10.2016
To do things in more efficient way you can copy/paste whole condition tree from default folder to user folder, obviously conditions will be available only for user who does copy/paste.
The default condition are in installation folder in condition subfolder "C:\Program Files\EnCase8.01\Condition", so you just copy it content into your user condition folder: "C:\Users\\Documents\EnCase\Condition".
If Encase is running you'll have to restart Encase to see the change
Looks like in v8.02 or later we will have copy ability in condition interface in encase, so we will not have to do dumb things like this workaround
Probably because in v6 users were able to modify system provided conditions and render it useless now it is impossible for user to see edit/open code of condition and use it as template for further development. You can only execute code and hope it is what you think it is since you can see what it is doing :)
Fortunately conditions and rest are still plain txt files somewhere on your disk and you can basically copy it from system provided path into your own user path and edit it. Plainly it is manipulation trough file system. Remember it is in internal format not easily readable by plain humans.
Conditions pane now contains two folders:
- Default
- User
Default folder contains all system provide conditions, while User is for your development, to edit anything you have to be in User sub folders, since User is also system folder and no-editable for users.
So how to simply hack this this to see code and reuse it ?
2)find in the Default folder condition you like to edit/analyze and right-click "Browse" on it. This will open widows explorer in folder containing your chosen condition.
Select your chosen condition and copy it by CRTL-C
close explorer window
3) In condition pane go to "User" folder, select you folder you created there in step (1) and right-clik browse on it. This will open windows explorer window where you can paste your chosen condition.
Close explorer window
4) Condition pane, on "User" folder right-click "refresh" that will show your condition in your sub folder,
5) choose your condition and right-clink "Edit" on it, you can edit and see how it works!!!!!
All this will be unneeded if copy function is still there in condition pane ...
Ages ago I've mentioned that it will be very good to force practice of standardized help or man page for each enscript or condition or filter but it will be never done.
PS: I'm quite sure this works for filters too
25.10.2016
To do things in more efficient way you can copy/paste whole condition tree from default folder to user folder, obviously conditions will be available only for user who does copy/paste.
The default condition are in installation folder in condition subfolder "C:\Program Files\EnCase8.01\Condition", so you just copy it content into your user condition folder: "C:\Users\
If Encase is running you'll have to restart Encase to see the change
Looks like in v8.02 or later we will have copy ability in condition interface in encase, so we will not have to do dumb things like this workaround
Sunday, September 18, 2016
FSEC 2016
My mistake, I forget to put link to presentation for FSEC 2016, but somehow it goes with other developement. It was nice in Opera House in Varazdin, food was perfect, day was wonderful but in our track lectures were derailed because of sounds system failure. Than for second day we have to change our plans. To be honest it all started when our colleague who was supposed to go there went to Ireland, it was a change and we decided to put another lecture, this time about "Remote Digital Forensic" It was logical developement after I had serious discusion about enterprise network as part of forensic investigation
Subscribe to:
Posts (Atom)
