Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

26
Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Transcript of Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Page 1: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Digital Forensics and the Most Famous Egg

How did Humpty Dumpty fall?

Page 2: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Humpty Dumpty sat on a wall,Humpty Dumpty had a great fall.

All the king's horses and all the king's menCouldn't put Humpty together again

Page 3: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Reasons for Humpty’s Fall

• He was pushed• He jumped• He was inebriated• The wall was structurally unsound• He faked his own demise

Page 4: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Agenda

• Chain of Custody• Data Sources & Imaging• Data Types• Types of Cases• What to Look For in Forensic Provider

Page 5: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Chain of Custody

Page 6: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Data Sources

• Memory• Hard Drives– Rotational v. SSD– RAID– Encryption

• Mobile• Removable Media• Cloud

Page 7: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Memory

• What was going through Humpty’s mind?

Page 8: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Hard Drives

Page 9: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Mobile

Page 10: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Removable Media

Page 11: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Cloud

Page 12: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

What Do We Know?

• Largest egg producer• We don’t have RAM• We have his computer• No encryption or RAID• Always carried his smartphone• Used a tablet at home and on the road• Never seen using removable media• Might have had cloud accounts

Page 13: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Data Types

• Actual Files• Deleted Files• Email• Operating System Files

Page 14: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Actual Files

• DOCX, XLSX, PPTX, PDF, JPG– Content – Metadata• File System• File

• LNK– Metadata

• CLUE: Keyword search for “poached” turns up 2 hits.

Page 15: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Deleted Files

• Can be found anywhere• Due to both user and system activity• Mass deletions in short timeframe = RED FLAG• Greater chance of recovery IF– Less time from file deletion– Less activity on the disk

• CLUE: Found deleted JPG.

Page 16: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Recovered Photo

Page 17: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Email Files

• Outlook• Lotus Notes• Windows Mail• Mozilla Thunderbird• Webmail

• CLUE: No email files, but webmail URL’s found in Internet History.

Page 18: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Windows Operating System Files

• Registry• Event Logs• Browser• LNK• Prefetch• MFT and USN Journal

Page 19: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Registry Analysis

• C:\Windows\System32\Config• C:\Users\<user_name>\NTUSER.dat• MRU & Jump Lists• Shellbags• USB History• CLUE: New USB drive plugged in

7 days prior to Humpty’s death. Last plugged into the PC the morning of Humpty’s death. 2nd USB drive plugged in same day.

Page 20: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Browser Artifacts

• Depends upon the browser• IE, Firefox and Chrome• All very different & rapidly changing• Index.dat, SQLite, JSON

• CLUE: Carve for webmail content, but no meaningful fragments, BUT we find a new email address and domain that looks interesting.

Page 21: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Mobile Artifacts

• Device Encryption & Passcodes• Volatile Data• ~2M app’s between Android & iPhone• Most rely on plist or SQLite structure• Common ones are handled by mobile

forensics suites

• CLUE: Words With Friends has a chat feature.

Page 22: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Removable Media

• Write-block it• Physical image best, unless encrypted• PC USB• PC USB

• CLUE: Term sheet between Humpty Dumpty Eggs and Chicken Little Enterprises found.

Page 23: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

What Do We Know?

• Pam’s recipe for Eggs Benedict from the Internet saved to the desktop.

• Deleted JPG originating from Humpty’s phone puts him at Chicken Little’s house when the thumb drive is inserted.

• Internet history reveals new email address. Subpoena shows communication with the baker about expansion plan.

• Words With Friends shows chat log with “Ace”• 1st USB drive contains term sheet between Humpty Dumpty

Eggs and Chicken Little Enterprises• 2nd USB drive is unknown

Page 24: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

HD & CL Hatch a Plan to Corner the Egg Market

• Humpty Dumpty and Chicken Little conspire to establish an egg cartel and expand.

• Part of the egg-spansion is into other food goods, like hollandaise.

• Humpty pretexts the baker with a phony email address to get his recipe. (Turns out it’s really PAM’s)

• Baker finds out about Humpty’s plans.• Baker pushes Humpty and copies the recipe.– Butcher & Candlestick maker both have alibies.

Page 25: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Push Button Forensics

Page 26: Digital Forensics and the Most Famous Egg How did Humpty Dumpty fall?

Forensic Analysis

QUESTIONS?

Mike LombardiVertigrate

[email protected](602) 283-1212