Académique Documents
Professionnel Documents
Culture Documents
Essential Training
Sherif Eldeeb
https://eldeeb.net
Acknowledgment
The Computer Evidence sample we shall use
is TDurden evidence file, which Guidance
Software provides for free; get it from:
http://media.johnwiley.com.au/product_ancillary
/63/04709010/DOWNLOAD/tdurdenex01.html
https://www.4shared.com/file/aa3BYubz/TDurde
n.htm
EnCase v7 new UI
Sherif Eldeeb
https://eldeeb.net
Evidence
Acquisition
Sherif Eldeeb
https://eldeeb.net
FastBloc SE
FastBloc SE is the first
commercial software
write-blocking solution
that allows EnCase to take
full control of IDE, SATA
and SCSI channels on
particular PCI controller
cards, as well as the
FireWire and USB ports
from Windows, permitting
a forensically sound
acquisition without the
use of hardware writeblocking devices.
Tools -> `FastBloc SE`
Sherif Eldeeb
https://eldeeb.net
FastBloc SE modes
All modes protect the evidence from actual
modifications.
Write Protected: Operating system will not
allow any modifications (copy to / delete /
modify) and will throw an error. Use this
mode for imaging!
Sherif Eldeeb
https://eldeeb.net
FastBloc SE modes
Write Blocked: OS will act as if the device is
not write blocked at all, and will allow
changing security permissions of files use
this mode for casual `browsing` where
sometimes access is not permitted due to
security permissions. (if you unplugged and
plugged device again, it will lose all
modifications).
Sherif Eldeeb
https://eldeeb.net
Sherif Eldeeb
https://eldeeb.net
Sherif Eldeeb
https://eldeeb.net
10
Sherif Eldeeb
https://eldeeb.net
11
Add Evidence
Sherif Eldeeb
https://eldeeb.net
12
Add Evidence
Since the evidence is attached as a USB
device, we pick `Add local device`.
we will explore the other options later,
God willing.
Sherif Eldeeb
https://eldeeb.net
13
Sherif Eldeeb
https://eldeeb.net
14
Sherif Eldeeb
https://eldeeb.net
15
Sherif Eldeeb
https://eldeeb.net
16
Sherif Eldeeb
https://eldeeb.net
17
Acquiring evidence
Right click on evidence name -> Acquire ->
Acquire
Sherif Eldeeb
https://eldeeb.net
18
Sherif Eldeeb
https://eldeeb.net
19
Format
`Current` format is NOT compatible with v6!!
Sherif Eldeeb
https://eldeeb.net
20
21
Stopping FastBloc SE
The USB device(s) will remain write-blocked
till FastBloc SE is stopped Clear All
Sherif Eldeeb
https://eldeeb.net
22
Adding Evidence
Files
Sherif Eldeeb
https://eldeeb.net
23
Sherif Eldeeb
https://eldeeb.net
24
Sherif Eldeeb
https://eldeeb.net
25
Sherif Eldeeb
https://eldeeb.net
26
Adding Raw
image files `DD`
Sherif Eldeeb
https://eldeeb.net
27
Sherif Eldeeb
https://eldeeb.net
28
Sherif Eldeeb
https://eldeeb.net
29
Sherif Eldeeb
https://eldeeb.net
30
Acquiring Mobile
Phones
PRE-REQUISITES AND IMPORTANT
CONSIDERATIONS
Sherif Eldeeb
https://eldeeb.net
31
32
Sherif Eldeeb
https://eldeeb.net
33
34
IMPORTANT!!!
35
Sherif Eldeeb
https://eldeeb.net
36
Install drivers
For EnCase to be able to acquire evidence
from mobile devices, appropriate drivers
needs to be installed the computer needs to
recognize them correctly first.
This means installing
iTunes for apple devices,
Sherif Eldeeb
https://eldeeb.net
37
Android:
Prerequisites
Sherif Eldeeb
https://eldeeb.net
38
Requirements
As per Encase, we need to do the following
ON THE PHONE before acquiring evidence
(dont forget to document your actions):
39
Sherif Eldeeb
https://eldeeb.net
Settings might
change slightly
40
Sherif Eldeeb
https://eldeeb.net
41
Sherif Eldeeb
https://eldeeb.net
42
43
Android:
Acquisition Demo
Sherif Eldeeb
https://eldeeb.net
44
Sherif Eldeeb
https://eldeeb.net
45
Sherif Eldeeb
https://eldeeb.net
46
Sherif Eldeeb
https://eldeeb.net
47
Sherif Eldeeb
https://eldeeb.net
48
Acquisition done!
Sherif Eldeeb
https://eldeeb.net
49
Note!
For some reason, photos taken by camera
(the ones usually in DCIM) were not included
in the evidence file when we acquired it
We didnt check why, but you may copy the
files from the phone storage directly and
take appropriate notes (MD5 hashes etc.)
Or make a logical evidence file which includes the
images.
Sherif Eldeeb
https://eldeeb.net
50
iTunes Backup
Files
Sherif Eldeeb
https://eldeeb.net
51
Sherif Eldeeb
https://eldeeb.net
52
Point to `Manifest.plist`
Sherif Eldeeb
https://eldeeb.net
53
Browsing and
Viewing Evidence
Sherif Eldeeb
https://eldeeb.net
54
Sherif Eldeeb
https://eldeeb.net
55
Sherif Eldeeb
https://eldeeb.net
56
Sherif Eldeeb
https://eldeeb.net
57
Sherif Eldeeb
https://eldeeb.net
58
Timeline
Tick from the left, display on the right
Easier focusing on finding what happened in
a specified time range
Sherif Eldeeb
https://eldeeb.net
59
Sherif Eldeeb
https://eldeeb.net
60
Sherif Eldeeb
https://eldeeb.net
61
Mounting
Evidence
Sherif Eldeeb
https://eldeeb.net
62
Mounting evidence
Evidence could be mounted as local, or
network mounted drives.
This will enable casually browsing the
evidence, or perform a virus scan.
Virtual Machines could be created from
evidence if mounted as local drive.
63
Sherif Eldeeb
https://eldeeb.net
64
Sherif Eldeeb
https://eldeeb.net
65
Sherif Eldeeb
https://eldeeb.net
66
67
3
4
Sherif Eldeeb
https://eldeeb.net
68
Sherif Eldeeb
https://eldeeb.net
69
Sherif Eldeeb
https://eldeeb.net
70
Running evidence
as a Virtual
Machine
Sherif Eldeeb
https://eldeeb.net
71
Running evidence as a VM
Once mounted using PDE, we can create a
virtual machine which boots as the evidence.
Sherif Eldeeb
https://eldeeb.net
72
Running evidence as a VM
Create a new VM, custom (advanced)
Sherif Eldeeb
https://eldeeb.net
73
Sherif Eldeeb
https://eldeeb.net
74
No network!!
Or else bad things might happen then
continue clicking through.
Sherif Eldeeb
https://eldeeb.net
75
Sherif Eldeeb
https://eldeeb.net
76
Sherif Eldeeb
https://eldeeb.net
77
Or not
Most probably
windows wont
start without
manual fix
YMMV.
Sherif Eldeeb
https://eldeeb.net
78
Processing
Evidence
. WHERE THE FUN BEGINS
Sherif Eldeeb
https://eldeeb.net
79
Sherif Eldeeb
https://eldeeb.net
80
Evidence Processing
Some tasks take very, very very long time.
It is recommended that you pick what you
are looking for only.
Sherif Eldeeb
https://eldeeb.net
81
Sherif Eldeeb
https://eldeeb.net
82
83
Sherif Eldeeb
https://eldeeb.net
84
Sherif Eldeeb
https://eldeeb.net
85
Sherif Eldeeb
https://eldeeb.net
86
Sherif Eldeeb
https://eldeeb.net
87
Sherif Eldeeb
https://eldeeb.net
88
Processing
Evidence
CONTD.
Sherif Eldeeb
https://eldeeb.net
89
Sherif Eldeeb
https://eldeeb.net
90
Process
Right click on Evidence -> Process Evidence > Process
Sherif Eldeeb
https://eldeeb.net
91
Processor Options
Sherif Eldeeb
https://eldeeb.net
92
Processor Options
Process all evidence files? Or just current?
Sherif Eldeeb
https://eldeeb.net
93
Processor Options
If it is blue, its a hyperlink and it has more
options.
Sherif Eldeeb
https://eldeeb.net
94
Prioritization
What to process first?
To process only the types of selected items,
Check Process only prioritized items
Sherif Eldeeb
https://eldeeb.net
95
Recover Folders
Try to recover deleted files and folders
When you turn on the Recover folder
structure of NTFS 3.0 files option, recovery
will take longer, but will reconstruct (folder
tree); if you left that unchecked, all found
folders will be grouped together without
tree structure.
Sherif Eldeeb
https://eldeeb.net
96
Sherif Eldeeb
https://eldeeb.net
97
Sherif Eldeeb
https://eldeeb.net
98
Thumbnail creation
Will create thumbnails for all images to be
viewed in the Gallery upfront.
Sherif Eldeeb
https://eldeeb.net
99
Hash Analysis
Calculate hash value for all files.
Is required for more advanced analysis.
Entropy -> high value indicates
compression or encryption.
Takes time, if not required, unselect.
Sherif Eldeeb
https://eldeeb.net
100
Sherif Eldeeb
https://eldeeb.net
101
Find Email
Will extract messages (and attachments)
from email archives (e.g. PST).
Sherif Eldeeb
https://eldeeb.net
102
Sherif Eldeeb
https://eldeeb.net
103
Sherif Eldeeb
https://eldeeb.net
104
Sherif Eldeeb
https://eldeeb.net
105
Creating an Index
An `index` is a list of all text in an evidence;
create it once, search through it very quickly.
Will enable searching
across all types of
information and view
results in email, files,
smartphones,
and
any other processed
data in one search
results view.
Sherif Eldeeb
https://eldeeb.net
Personal Information
Credit cards, Phone numbers, Email
addresses & USA Social security numbers
Sherif Eldeeb
https://eldeeb.net
107
Personal Information
Information about the Qatari ID number, and
how to configure EnCase to look for them
could be found at the following site:
https://eldeeb.net/wrdprs/?p=330
Sherif Eldeeb
https://eldeeb.net
108
Sherif Eldeeb
https://eldeeb.net
109
IM Parser
Scans for AOL, MSN and Yahoo chat artifacts
Who is using those anyways :/ not very
useful unless youre investigating an
evidence acquired long, long time ago.
Sherif Eldeeb
https://eldeeb.net
110
File Carver
File carving is the process of reassembling
files from fragments in the absence of
filesystem metadata.
e.g. there will be no file names or created time
only file data.
111
File Carver
Sherif Eldeeb
https://eldeeb.net
112
File Carver
Sherif Eldeeb
https://eldeeb.net
113
Sherif Eldeeb
https://eldeeb.net
114
Sherif Eldeeb
https://eldeeb.net
115
Sherif Eldeeb
https://eldeeb.net
116
Unix Login
This module parses files with the names
wtmp and utmp
Those files keep track of all logins and logouts to
the system.
Sherif Eldeeb
https://eldeeb.net
117
Sherif Eldeeb
https://eldeeb.net
118
119
Processing
Evidence
RESULT SETS: LIMITING THE CASE PROCESSING
SCOPE
Sherif Eldeeb
https://eldeeb.net
120
Sherif Eldeeb
https://eldeeb.net
121
Sherif Eldeeb
https://eldeeb.net
122
Result Sets
To view the Result Set, click view -> Results
Sherif Eldeeb
https://eldeeb.net
123
124
Viewing Case
Processor Results
Sherif Eldeeb
https://eldeeb.net
125
Sherif Eldeeb
https://eldeeb.net
126
Sherif Eldeeb
https://eldeeb.net
127
General Useful
Tricks
Sherif Eldeeb
https://eldeeb.net
128
Sherif Eldeeb
https://eldeeb.net
129
Sherif Eldeeb
https://eldeeb.net
130
Sherif Eldeeb
https://eldeeb.net
131
Smartphone
Reports
Sherif Eldeeb
https://eldeeb.net
132
Smartphone Reports
Creating reports for smartphone information
using EnCase couldnt be easier
Tools Smartphone Report
Sherif Eldeeb
https://eldeeb.net
133
Smartphone Reports
`Tags` are explained in Chapter 12 in user
manual (and will be explained in next course,
God willing)
`OK` and it
will work
for a while.
Sherif Eldeeb
https://eldeeb.net
134
Smartphone Reports
Reports could be Short or detailed
You can pick what to be included
Sherif Eldeeb
https://eldeeb.net
135
Smartphone Reports
Sherif Eldeeb
https://eldeeb.net
136
Sherif Eldeeb
https://eldeeb.net
137
Sherif Eldeeb
https://eldeeb.net
138
Sherif Eldeeb
https://eldeeb.net
139
Export to CSV
Data could be exported as CSV for further
dissemination using other tools
Sherif Eldeeb
https://eldeeb.net
140
The forensic
challenge
Sherif Eldeeb
https://eldeeb.net
141
Sherif Eldeeb
https://eldeeb.net
@SheriefEldeeb
Sherif Eldeeb
https://eldeeb.net