digital forensics and the most famous egg how did humpty dumpty fall?

26
Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Upload: rhoda-johnson

Post on 25-Dec-2015

214 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Digital Forensics and the Most Famous Egg

How did Humpty Dumpty fall?

Page 2: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Humpty Dumpty sat on a wall,Humpty Dumpty had a great fall.

All the king's horses and all the king's menCouldn't put Humpty together again

Page 3: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Reasons for Humpty’s Fall

• He was pushed• He jumped• He was inebriated• The wall was structurally unsound• He faked his own demise

Page 4: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Agenda

• Chain of Custody• Data Sources & Imaging• Data Types• Types of Cases• What to Look For in Forensic Provider

Page 5: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Chain of Custody

Page 6: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Data Sources

• Memory• Hard Drives– Rotational v. SSD– RAID– Encryption

• Mobile• Removable Media• Cloud

Page 7: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Memory

• What was going through Humpty’s mind?

Page 8: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Hard Drives

Page 9: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Mobile

Page 10: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Removable Media

Page 11: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Cloud

Page 12: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

What Do We Know?

• Largest egg producer• We don’t have RAM• We have his computer• No encryption or RAID• Always carried his smartphone• Used a tablet at home and on the road• Never seen using removable media• Might have had cloud accounts

Page 13: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Data Types

• Actual Files• Deleted Files• Email• Operating System Files

Page 14: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Actual Files

• DOCX, XLSX, PPTX, PDF, JPG– Content – Metadata• File System• File

• LNK– Metadata

• CLUE: Keyword search for “poached” turns up 2 hits.

Page 15: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Deleted Files

• Can be found anywhere• Due to both user and system activity• Mass deletions in short timeframe = RED FLAG• Greater chance of recovery IF– Less time from file deletion– Less activity on the disk

• CLUE: Found deleted JPG.

Page 16: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Recovered Photo

Page 17: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Email Files

• Outlook• Lotus Notes• Windows Mail• Mozilla Thunderbird• Webmail

• CLUE: No email files, but webmail URL’s found in Internet History.

Page 18: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Windows Operating System Files

• Registry• Event Logs• Browser• LNK• Prefetch• MFT and USN Journal

Page 19: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Registry Analysis

• C:\Windows\System32\Config• C:\Users\<user_name>\NTUSER.dat• MRU & Jump Lists• Shellbags• USB History• CLUE: New USB drive plugged in

7 days prior to Humpty’s death. Last plugged into the PC the morning of Humpty’s death. 2nd USB drive plugged in same day.

Page 20: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Browser Artifacts

• Depends upon the browser• IE, Firefox and Chrome• All very different & rapidly changing• Index.dat, SQLite, JSON

• CLUE: Carve for webmail content, but no meaningful fragments, BUT we find a new email address and domain that looks interesting.

Page 21: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Mobile Artifacts

• Device Encryption & Passcodes• Volatile Data• ~2M app’s between Android & iPhone• Most rely on plist or SQLite structure• Common ones are handled by mobile

forensics suites

• CLUE: Words With Friends has a chat feature.

Page 22: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Removable Media

• Write-block it• Physical image best, unless encrypted• PC USB• PC USB

• CLUE: Term sheet between Humpty Dumpty Eggs and Chicken Little Enterprises found.

Page 23: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

What Do We Know?

• Pam’s recipe for Eggs Benedict from the Internet saved to the desktop.

• Deleted JPG originating from Humpty’s phone puts him at Chicken Little’s house when the thumb drive is inserted.

• Internet history reveals new email address. Subpoena shows communication with the baker about expansion plan.

• Words With Friends shows chat log with “Ace”• 1st USB drive contains term sheet between Humpty Dumpty

Eggs and Chicken Little Enterprises• 2nd USB drive is unknown

Page 24: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

HD & CL Hatch a Plan to Corner the Egg Market

• Humpty Dumpty and Chicken Little conspire to establish an egg cartel and expand.

• Part of the egg-spansion is into other food goods, like hollandaise.

• Humpty pretexts the baker with a phony email address to get his recipe. (Turns out it’s really PAM’s)

• Baker finds out about Humpty’s plans.• Baker pushes Humpty and copies the recipe.– Butcher & Candlestick maker both have alibies.

Page 25: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Push Button Forensics

Page 26: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Forensic Analysis

QUESTIONS?

Mike LombardiVertigrate

[email protected](602) 283-1212