r… r… - smarter forensics · database view android metadata (1) history sqlite sequence (1) su...

24
Bueller…Bueller… Smartphone Forensics Moves Pretty Fast. If you don’t Stay Current,You’ll Miss Evidence Hank Mahalik [email protected] Twitter: @HeatherMahalik http://smarterforensics.com 3

Upload: others

Post on 25-Jun-2020

7 views

Category:

Documents


0 download

TRANSCRIPT

Bueller…Bueller…SmartphoneForensics

MovesPrettyFast.Ifyoudon’tStayCurrent,You’ll

MissEvidence

HankMahalik

[email protected]

Twitter:@HeatherMahalik

http://smarterforensics.com

3

Aboutme…

•  EmployeeofOcean’sEdge,Inc.

•  SANSSeniorInstructor

•  InvolvedwithForensics/infosecfor13years

•  Co-authorFOR585andFOR518

•  Co-AuthorofPracticalMobileForensics

•  Availableonsocialmedia

Copyright@2015HeatherMahalik,AllRightsReserved

HowhaveOSupgradeschangedthegameofSmartphoneForensics?

Copyright@2015HeatherMahalik,AllRightsReserved

Whatdoesthismean?

•  YouneedtofullyunderstandtheOSonthedevice

•  Thestateofeverymobiledevicemayvary

•  Youwillneedmorethanonetool

•  Youwillneedtheskillstomanuallycarveforforensic

artifacts

•  Reality–Yourtoolmaymissrelevantdata!

Copyright@2015HeatherMahalik,AllRightsReserved

Upgrades

•  OperatingSystem

– AndroidL&M

–  iOS9

•  Applications

– All3rdPartyApplicationsonbothdevices

Copyright@2015HeatherMahalik,AllRightsReserved

Lollipop,Lollipop…•  Multipleuseraccounts

•  Factoryresetprotection–  Musthavepassword

•  Fulldiskencryption–  Userispromptedatfirststartup

•  SmartLock

–  DeviceautomaticallyunlockswhennearspecificBluetooth,

WiFiorNFCtags

Copyright@2015HeatherMahalik,AllRightsReserved

Marshmallow!!!!!

Copyright@2015HeatherMahalik,AllRightsReserved

Updatedfingerprintscan

VisualVoicemail

•  T-MobileandOrangeFrance

Rotatinghomescreen

RAMManager

NetworkSettingReset

OhEvidence,WhereareYou?

•  Thelocationoftheevidencehasn’treally

changed(yet)

•  Gettingtotheevidencemaybeharder

•  Acquisitionmaybemoredifficultandmore

expensive!

Copyright@2015HeatherMahalik,AllRightsReserved

UnderstandingtheEvidence(1)

•  Maps-com.google.android.apps.maps

•  Database:da_destination_history

Copyright@2015HeatherMahalik,AllRightsReserved

UnderstandingtheEvidence(2)

•  Maps-com.google.android.apps.maps

•  Database:search_history.db

Copyright@2015HeatherMahalik,AllRightsReserved

UnderstandingtheEvidence(3)•  Socialmediageo-tagging

–  Facebook

–  Google+

–  Twitter

–  Etc.

•  Considerwhattracesare

leftbehindwhentheuser

“checks-in”andtagsa

location

Copyright@2015HeatherMahalik,AllRightsReserved

iOS9

•  Addedfunctionality

•  “Remembers”thingsforyou

•  Let’syou“undelete”pictures/videos

•  Changedseveraldatalocations…

Copyright@2015HeatherMahalik,AllRightsReserved

YourPastMayHauntYou!•  iOS8&9“Recall”

Feature

–  Scarythatyouthought

itwasgone…

–  Butguesswhat?

Copyright@2015HeatherMahalik,AllRightsReserved

ManualExam:SMSAttachments

CantheTooldoThat?

Copyright@2015HeatherMahalik,AllRightsReserved

OhEvidence,WhereareYou?

•  CallLogs

–  Library/CallHistory/call_history.db

–  Library/CallHistory/callhistory.storedata(iOS8&9)

•  GoogleMaps

–  Library/Maps/History.mapsdata

–  Library/Maps/GeoHistory.mapsdata(iOS8&9)

Copyright@2015HeatherMahalik,AllRightsReserved

What’sGoingonHere…

Copyright@2015HeatherMahalik,AllRightsReserved

3rdPartyApplicationUpgrades

•  EncodingandEncryptionchanges

•  Changesthefilenamecontainingthedata

•  Createsanewfilefordatastorage

•  Makesaccessingthedatamoredifficult

– Sometimes…

Copyright@2015HeatherMahalik,AllRightsReserved

Example:Cyberdust(1)•  Claimstoremovealluserdataupontransmission/

receipt

– Nevertrustclaimsoryourtool

– ManuallyreviewAppfilesforuseractivity

Copyright@2015HeatherMahalik,AllRightsReserved

Example:Cyberdust(2)

•  MessagesareencodedtwiceusingBase64

Copyright@2015HeatherMahalik,AllRightsReserved

Essentialskilldevelopment•  LearnhowdataisstoredonAndroidandiOSdevices

•  LearnhowtoidentifytracesofOSupgrades

•  Learndecodingandmanualcarvingtechniques

•  Findwaystooutsmartyourtools

•  TakeFOR585tomakesureyoubuildthenecessary

skillstoeffectivelyexaminethenextsmartphoneyou

see(andyouwillseeone…)

Copyright@2015HeatherMahalik,AllRightsReserved

•  FOR585 Advanced Smartphone Forensics

•  Practical Mobile Forensics

•  http://smarterforensics.com

•  https://andriller.com/

•  http://az4n6.blogspot.com/p/downloads.html

•  http://cheeky4n6monkey.blogspot.com/

References, Sources and Suggested Reading

FOR585AdvancedSmartphoneForensicsCourseAvailableAt:

Chantilly,VAw/HeatherMahalik–Dec10timesin2016!

OnDemand–Anytimeyouwant!

*FOR408–vLive–LearninyourPJswithabeer!

UpcomingCourses

Questions?

HeatherMahalik

[email protected]

Twitter:@HeatherMahalik

www.smarterforensics.com

[email protected]

Copyright@2015HeatherMahalik,AllRightsReserved