E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

27
E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group www.edecision4u.com

Transcript of E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Page 1: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

E-Detective Decoding Centre (EDDC)Offline Decoding & Reconstruction Solution

Decision Groupwww.edecision4u.com

Page 2: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

2

EDDC Application Diagram (1)

Page 3: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

EDDC Application Diagram (2)

Offline Raw Data Decoding and Reconstruction system.Comes with User and Case Management functions.

Investigator 1Case 1

Investigator 2Case 2

Case 1 Results

Case 2 Results

Collect,Import

Raw Data For Case 1 Case 1

Case 2Collect,Import

Raw Data For Case 2

Reconstruct various Internet Protocols

Page 4: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

EDDC Home Page Dashboard Reports

Top-Down View Report

Page 5: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

IM/Chat(Yahoo,

MSN, ICQ,QQ, IRC,

Google TalkEtc.)

EmailWebmail

HTTP(Link, Content,Reconstruct,

UploadDownload)

File TransferFTP, P2P

OthersOnline Games

Telnet etc.

Internet Protocols Supported

Support more than 140 protocols

Page 6: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sample Reconstruction: Email (POP3)

Page 7: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sample Reconstruction: Email (SMTP)

Company Logo

Page 8: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sample Reconstruction: Webmail (Read)

Supports various Webmail Type such as Yahoo Mail, Gmail,

Hotmail etc.

Page 9: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sample Reconstruction: Webmail (Sent)

Page 10: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sample Reconstruction: IM – MSN

Page 11: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sample Reconstruction: IM - YAHOO

Page 12: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sample Reconstruction: IM - QQ

QQ messages are encrypted. QQ cracking tool is provided.

Page 13: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sample Reconstruction: File Transfer (FTP)

Page 14: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sample : File Transfer (P2P File Sharing Log)

Bittorent, eMule/eDonkey, FastTrack, Gnutella

Page 15: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sample : HTTP Web Link Content Reconstruct

Company Logo

Page 16: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sample : HTTP (Download/Upload)

Page 17: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sample: HTTP Video Streaming (FLV)

Youtube, Google Video, Metacafe etc.

Page 18: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sample: Telnet (with play back)

Page 19: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sample: VoIP Reconstruction (Playback)

Codecs:G.711a-lawG.711µ-law

G.729ILBC

Page 20: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sample: HTTPS/SSL Decryption

SSL Private Key must be known

Page 21: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

EDDC User Management

Admin create multiple users that can have

access to authority to use this system.

Page 22: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

EDDC Case Management

User can create own case based on their

authority assigned by Administrator.

Page 23: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Import Analysis (Manual Import Raw Data)

User import raw data files to be parsed and analyzed (reconstructed)

Page 24: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Reconstructed Data Export/Backup

Page 25: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Sniffer Mode (Raw Data Retention)

System can be connected to the network. Raw data can be captured and reserved through mirror mode. Only when administrator require to see the content of traffic at specific period (date-time), these raw data files can be

imported, parsed and analyzed.

Page 26: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

References – Implementation Sites and Customers

Criminal Investigation Bureau The Bureau of Investigation Ministry of Justice National Security Agency (Bureau) in various countries Intelligence Agency in various countries Ministry of Defense in various countries Counter/Anti Terrorism Department National Police, Royal Police in various countries Government Ministries in various countries Federal Investigation Bureau in various countries Telco/Internet Service Provider in various countries Banking and Finance organizations in various countries Others

Notes: Due to confidentiality of this information, the exact name and countries of the various organizations cannot be revealed.

Page 27: E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution Decision Group .

Decision Groupwww.edecision4u.com