[00:00.000 --> 00:04.700] Six million men and women are directly engaged in the defense of staff. [00:15.600 --> 00:17.040] Just a quick announcement. [00:17.400 --> 00:21.680] The amateur radio testing is still going on on the first floor. [00:21.860 --> 00:25.060] So if you're interested in getting an amateur radio license, you can... [00:25.480 --> 00:29.000] I don't know what the test is like, but maybe you can cheat. [00:30.860 --> 00:38.780] The next panel is Basics of Forensic Recovery with Cal Loper, who has a Ph.D., I found out last night. [00:46.290 --> 00:46.890] Thank you. [00:48.190 --> 00:48.790] Thank you. [00:51.450 --> 00:51.890] Hello? [00:52.230 --> 00:52.530] Okay. [00:53.010 --> 00:54.090] Yeah, they'll give a Ph.D. [00:54.170 --> 00:54.850] to anyone these days. [00:57.010 --> 01:03.410] Before I begin, I thought it would be nice to explain to you my motivations in putting this together the way I have. [01:04.230 --> 01:05.730] I'm going to make a couple distinctions. [01:06.710 --> 01:09.590] Maybe make you aware of a field that you hadn't heard of before. [01:11.790 --> 01:13.630] As I move closer to the mic. [01:14.030 --> 01:14.470] Okay. [01:17.690 --> 01:20.010] My thought is, this might be useful to you. [01:20.150 --> 01:21.010] I hope you find it so. [01:21.350 --> 01:25.930] I'm not claiming to be the definitive expert on any of the items I discuss. [01:25.930 --> 01:26.990] I know about them. [01:27.070 --> 01:27.710] I work with them. [01:27.750 --> 01:28.710] I've worked with them for years. [01:28.930 --> 01:31.910] I would be happy to answer questions in detail or explain. [01:32.230 --> 01:38.270] Yet, I teach entire master's degree courses in this, and I had to throw some material out. [01:38.270 --> 01:43.690] So, if you feel like I've oversimplified, put things together that maybe you didn't see them going together that way. [01:44.350 --> 01:45.170] Bear with me. [01:45.310 --> 01:45.890] Ask questions. [01:46.010 --> 01:46.850] I'd be happy to answer them. [01:51.340 --> 01:51.780] Okay. [01:52.160 --> 01:55.620] One of the things that I run into that's a problem is, I deal with two different camps. [01:55.820 --> 01:57.480] I'm a professor of criminal justice. [01:58.120 --> 02:09.900] My primary job is to teach people who want to become police officers, corporate security people, people who found physics wasn't a challenge for them, so they thought they'd go into criminal justice. [02:09.900 --> 02:10.860] You name it. [02:13.940 --> 02:14.420] Okay. [02:15.660 --> 02:21.720] That side of the house sees forensics as something very different than what the computer science side of the house sees it as. [02:21.850 --> 02:29.580] I also work with our computer science faculty, and I have been in this community for a while. [02:31.920 --> 02:33.520] Longer than I've been in that community. [02:34.220 --> 02:38.220] But the point is, we say the same word and we mean different things. [02:38.940 --> 02:51.940] Forensics to the computer science side of the house means incident recovery, it means remediation, it means investigating the incident, the post-mortem analysis on the logs, on the IDS, whatever it takes to figure out what happened. [02:52.680 --> 02:54.960] Forensics on the law side of the house... [02:56.040 --> 02:56.520] Okay. [03:00.710 --> 03:02.870] You don't get to see what it means on the other side of the house. [03:05.350 --> 03:05.830] Okay. [03:06.770 --> 03:08.470] See, examination of an incident. [03:08.610 --> 03:10.390] A quickie definition there, right? [03:10.390 --> 03:11.650] Just so we can move on. [03:12.950 --> 03:16.870] To the legal side, it means literally belonging to courts of justice. [03:17.010 --> 03:20.570] If you think about the forensics team in high school, they went out and argued. [03:20.810 --> 03:22.810] Forensics is pertaining to argument. [03:23.350 --> 03:25.770] Argument in this context occurs in courts. [03:25.930 --> 03:29.150] I'm talking about the law side definition of forensics. [03:29.330 --> 03:32.670] Some people used to call it static forensics as opposed to network forensics. [03:32.770 --> 03:38.170] That term is lost currency because our model is shifting to a more dynamic recovery of data model. [03:38.390 --> 03:39.670] So it's no longer static. [03:39.850 --> 03:42.070] Frankly, because the systems are too complex. [03:42.350 --> 03:42.590] If you're... [03:42.590 --> 03:53.130] Anybody who's tried to take down an AD system of any size, Active Directory for those of you who despise Microsoft, you understand it's really hard to do that with the static model. [03:53.130 --> 03:56.230] I mean, if the clients will pay for that, do it. [03:56.490 --> 04:03.410] But very few people are willing to put up with that kind of expense while you piddle around with bringing up a pet or a toy AD system. [04:04.250 --> 04:08.030] So what I'm going to be talking about is legal forensics under that definition. [04:08.150 --> 04:11.590] I really apologize if you came to hear about the latest, greatest way to parse logs. [04:12.430 --> 04:13.690] That's just not what I'm doing today. [04:15.170 --> 04:17.670] I put this thing here and then... [04:18.490 --> 04:19.970] Whoa, that's cool, isn't it? [04:21.050 --> 04:21.950] I hate PowerPoint. [04:22.570 --> 04:25.330] Anyway, this is probably more pertinent. [04:25.590 --> 04:26.970] It's another legal definition. [04:27.150 --> 04:27.870] Forensic engineering. [04:28.090 --> 04:31.250] You can stretch it a little bit and figure out this is really what we're talking about. [04:31.870 --> 04:45.170] Practice by legally qualified professional engineers slash professional anything else, charlatans who attended a course on the web, call themselves forensic experts, you name it, who are experts in their field, both by education and experience. [04:45.430 --> 04:51.710] Very important they're in courts and what I'm talking about is legally related so you've got to understand the court perspective. [04:51.870 --> 04:53.030] You don't have to agree with it. [04:53.330 --> 04:58.070] But I think it's really important to understand the reality you're dealing with whether you agree with it or not. [04:58.350 --> 05:04.330] In fact, you're more effective working against it, with it, whatever, if you understand it in the terms other people do. [05:04.510 --> 05:05.850] And this is what I'm presenting. [05:06.870 --> 05:08.790] And don't worry, I will get to the technical stuff. [05:11.750 --> 05:14.530] All right, this is the basic model. [05:14.670 --> 05:20.490] This is culled from about six different PowerPoint presentations that I've got, you know, that I give during the course of a year. [05:21.190 --> 05:25.970] But right now, current practice is that static model that I was talking about. [05:26.110 --> 05:33.070] You go out, you seize a drive, you take it home, you analyze it, you fill out lots of paperwork so everybody knows what's going on, where it comes from. [05:34.030 --> 05:39.170] To the degree that the courts are willing to trust, you do the things necessary to obtain that trust. [05:39.890 --> 05:50.970] And unlike, you know, the kind of cryptographic solutions we're talking about here in other panels, this is really just the documentation that says you haven't screwed it up through mishap. [05:51.330 --> 05:51.590] Right? [05:51.710 --> 05:56.150] There is an assumption that people who testify in court will be telling the truth, especially the experts. [05:56.510 --> 06:04.490] That is part of why the education, the experience, the verifiable credentials that you bring to the forensic process are so important. [06:04.490 --> 06:08.570] What you're doing is putting your reputation up there on the stand as an expert witness. [06:09.030 --> 06:12.430] And if the court doesn't find you credible, you're useless. [06:13.170 --> 06:16.690] And after that point, if you don't know what you're talking about, you're useless. [06:17.370 --> 06:17.870] Right? [06:17.870 --> 06:19.030] You've got to have both. [06:19.710 --> 06:23.870] Somebody who has a PhD and knows nothing, and believe it or not, I know several. [06:24.570 --> 06:27.810] I may be one, but I contend otherwise in court. [06:28.290 --> 06:28.550] Right? [06:29.710 --> 06:34.030] Believe it or not, those people, you know, may get up on the stand. [06:34.030 --> 06:37.990] They have that initial... they get in the door, basically. [06:38.670 --> 06:43.330] I work with a guy who has been in this community for a long, long time. [06:43.670 --> 06:51.330] He is teaching me every day, and I'm learning, and I'm absolutely loving the fact that I'm picking up all these tricks from him in spite of the fact that I've been at this for years. [06:51.790 --> 06:52.130] Right? [06:52.130 --> 06:57.130] And he has established his credibility by being an expert witness a number of times. [06:57.530 --> 07:00.350] He finished his bachelor's degree, I want to say, a year ago. [07:01.170 --> 07:01.610] Right? [07:01.770 --> 07:04.830] He has been testifying as an expert witness based on his own merit. [07:05.090 --> 07:11.790] But the mistake many people make is, since you know that you know something, you believe everyone else should know that you know something. [07:12.470 --> 07:18.170] And here, you stand around, you talk about it, people go, oh, okay, you know what you're talking about, I'll listen to you. [07:18.170 --> 07:26.290] In court, you've got to build up a track record, or get through that initial gate with education or experience. [07:26.590 --> 07:27.030] Right? [07:27.250 --> 07:31.570] For that reason, this field of forensics is heavily dominated by former law enforcement. [07:31.890 --> 07:34.670] It is simply one of the best ways to get experience in court. [07:34.930 --> 07:48.710] If you go in as a police officer, as a federal agent, to court, testify, work a number of cases, present yourself with a, you know, a professional vitae, I've been to these trainings, I've been to court this many times, right? [07:48.850 --> 07:52.330] Other courts are willing to say, okay, fine, we're ready to go with you. [07:52.510 --> 07:56.530] It doesn't mean you know what you're talking about, but then again, it doesn't mean you don't know what you're talking about. [07:57.130 --> 08:04.130] Anybody who thinks that police who investigate computer crime are stupid, well, you know, you're living in a fantasy world. [08:04.230 --> 08:05.590] These people are highly skilled. [08:05.950 --> 08:10.370] And I'm not saying every cop you meet who looks at a computer is going to understand the inner workings of it. [08:11.010 --> 08:12.250] But don't kid yourself. [08:12.250 --> 08:18.650] There are people out there who are really intelligent and have applied themselves to this and have done fantastically well at it, right? [08:18.730 --> 08:22.150] I have a lot of respect for those people just like I have a lot of respect for people here in the crowd today. [08:22.510 --> 08:24.990] You know, some of you I should have respect for, I just don't know you yet. [08:25.910 --> 08:31.770] But have that same respect for the police officers who are doing this training and are conducting that business. [08:32.790 --> 08:34.350] You may end up working with them someday. [08:34.650 --> 08:36.590] And frankly, I think you'll find that they're not that bad. [08:38.750 --> 08:39.770] You're not buying that, are you? [08:46.150 --> 08:48.350] He just mentioned ShmooCon, for those of you who didn't hear it. [08:49.030 --> 08:49.210] Okay. [08:50.170 --> 08:50.530] Absolutely. [08:51.010 --> 08:51.750] Get to know people. [08:52.450 --> 08:53.730] Invite them to your 2600 meetings. [08:54.950 --> 08:55.030] Right? [08:56.250 --> 08:58.730] Watch everybody get real quiet and act like they have the plague. [08:58.850 --> 08:59.150] It's fun. [09:02.590 --> 09:03.050] All right. [09:04.050 --> 09:08.130] Analysis is performed on an image, you know, if it helps, think about it as a DD. [09:08.130 --> 09:14.910] We use other formats, too, with varying degrees of crap thrown on for proprietary interest so they can sell things to you. [09:15.010 --> 09:18.730] But basically, a bitstream copy is the standard. [09:19.330 --> 09:21.370] A DD will work if you can verify it. [09:23.250 --> 09:27.170] It's important to note that evidence exists on the media that you take. [09:27.350 --> 09:28.930] And I'm talking about civil recovery here. [09:28.990 --> 09:31.250] I'm not explaining law enforcement recovery because I don't do that. [09:31.990 --> 09:37.470] But in civil recovery, a case I just did, went into an office after 6 PM. [09:37.470 --> 09:38.450] Everybody was gone. [09:38.930 --> 09:41.310] Human resources thought somebody was up to something bad. [09:41.610 --> 09:45.530] And I'm not talking about porn or something stupid like that because that's really at the shallow end of the pool. [09:46.870 --> 09:50.170] We went in, imaged the machine, and then went looking for it. [09:50.310 --> 09:53.450] And yeah, sure enough, there were intrusion tools on it. [09:53.630 --> 09:58.110] There were copies of other people's files they shouldn't have had access to. [09:58.110 --> 10:02.450] And, you know, we were able to give the client what they wanted to know. [10:02.630 --> 10:04.270] And then they decided where to go from there. [10:07.390 --> 10:15.710] The report that I did, which is getting back to this third bullet point here, the report that I did served as a map to where that information could be found in the evidence. [10:16.090 --> 10:17.470] My report is never evidence. [10:17.790 --> 10:19.630] It's simply an index to it. [10:20.050 --> 10:23.990] And, you know, if you're working a case where images are important, you can make copies of the images. [10:24.130 --> 10:25.190] But you still have to go back. [10:25.410 --> 10:29.170] And, you know, there have been times when people said, I want to know the hex offset, where that begins. [10:29.350 --> 10:31.230] And you're like, okay, fine. [10:31.830 --> 10:32.710] More billable hours. [10:32.810 --> 10:33.330] I'm good with that. [10:34.410 --> 10:35.510] Thank you, defense expert. [10:37.350 --> 10:40.370] Other times they want to know if you actually used a DOS disk to boot the computer. [10:40.610 --> 10:43.770] And, like, not in many years. [10:43.970 --> 10:45.470] But do you think it's important? [10:45.670 --> 10:46.230] We can do it. [10:50.140 --> 10:50.680] All right. [10:50.900 --> 10:58.780] And finally, the examiner and the quality and the trust in the court system that examiner brings is key to getting that index accepted. [10:59.660 --> 11:03.680] And oh, I just thought of a demo I want to show you. [11:03.940 --> 11:05.400] This is one of the tools that we use. [11:07.480 --> 11:08.360] I hope... [11:09.480 --> 11:10.500] No, I didn't put it there. [11:10.620 --> 11:11.260] That was clever of me. [11:15.090 --> 11:15.530] Okay. [11:15.590 --> 11:17.610] Pretend like you're not seeing my directory structure. [11:18.390 --> 11:21.430] I want to point out that I'm not a security expert. [11:22.270 --> 11:26.170] And you could easily obtain access to this machine. [11:27.210 --> 11:28.430] This was written by a friend of mine. [11:30.910 --> 11:34.590] So you have the source drive that you want to access. [11:35.010 --> 11:38.030] You decide you want the person to be guilty. [11:39.230 --> 11:40.070] Select porn. [11:46.100 --> 11:46.860] And there you go. [11:48.300 --> 11:49.600] Do you want to see it for ID theft? [11:51.940 --> 11:52.980] Oh, look, it worked, too. [11:53.560 --> 11:53.620] No. [11:55.860 --> 11:58.800] We were talking about an automated tool that anybody could use in this. [11:58.940 --> 12:00.120] You know, we're sitting in this presentation. [12:00.260 --> 12:04.040] This guy's, you know, just doing a quick little VB interface there. [12:04.240 --> 12:06.740] And, you know, we start distributing it by the end of the conference. [12:06.740 --> 12:09.300] Everybody had it and we're all, yeah, this is what we need. [12:14.540 --> 12:15.100] There we go. [12:15.680 --> 12:15.760] All right. [12:16.080 --> 12:18.960] One of the tools that we use, and you may hear about this, is a hardware tool. [12:19.460 --> 12:23.980] You know, going back to that, where forensics has been for the last few years is the static model. [12:24.220 --> 12:28.120] We go, we get the screwdrivers out, we remove the drive from the system. [12:28.240 --> 12:31.760] And I'll tell you a story later if we have time about why we don't necessarily do that anymore. [12:32.080 --> 12:32.960] But here's the model. [12:32.960 --> 12:36.340] Well, you take the hard drive out, you plug it into a hardware write blocker. [12:36.840 --> 12:38.820] I've spent way too much money on these damn things. [12:39.300 --> 12:43.720] But I've got one for SATA, I've got one for SCSI, I've got one for IDE, I've even got one for USB. [12:44.060 --> 12:47.920] I didn't bring it because my suitcase was full of black t-shirts that I could wear around here. [12:50.080 --> 12:57.980] This allows you to take that bitstream copy of the evidence and guarantee that you do not write back to that evidence. [12:58.160 --> 13:00.720] Because tainting the evidence is just bad. [13:00.720 --> 13:02.680] It's not something you want to do. [13:03.140 --> 13:04.100] Sometimes it happens. [13:04.540 --> 13:07.400] When it does, it doesn't mean you have to run around in circles and scream. [13:07.920 --> 13:11.700] You note what happened, you note why it happened, and you're honest about it. [13:11.920 --> 13:12.960] And that is the key. [13:13.080 --> 13:22.500] If you lie on the stand, if you stretch evidence, somebody smarter than you is going to point it out and then you've got to go be a college professor because nobody trusts you anymore. [13:24.220 --> 13:24.940] You did that? [13:25.140 --> 13:25.220] No. [13:32.660 --> 13:34.180] This is an excellent question. [13:34.320 --> 13:38.140] He said, what is the security that guarantees you cannot modify the data on an IDE device? [13:38.980 --> 13:40.820] These things are tested and validated. [13:41.000 --> 13:47.480] If you don't test them yourself, you're a very poor forensic practitioner or you're really busy and you're making enough money, you don't have to do that. [13:47.480 --> 13:53.040] But NIST, the National Institute of Standards, also does that, and they have reports available. [13:53.200 --> 13:53.900] They're on the web. [13:54.060 --> 13:55.580] Just go to Department of Justice. [13:55.840 --> 13:56.140] No. [13:57.320 --> 13:58.060] What are they under? [13:58.200 --> 13:58.500] Commerce? [13:59.260 --> 14:00.080] Because they're standards? [14:00.880 --> 14:01.320] Okay. [14:01.980 --> 14:09.720] And there are also reports available through the National Institute of Justice, NIJ, which is the oversight branch for research within Department of Justice. [14:10.020 --> 14:12.500] They have copies of all that where they've gone out and tested these. [14:12.500 --> 14:27.080] You can also go to any of the forensic hackers, you know, people who were at DEFCON back, you know, when it was cool, and now are out doing forensics because, frankly, they just want to get paid and do something useful. [14:27.820 --> 14:29.380] They go out and do this individual testing. [14:29.560 --> 14:30.040] I've done it. [14:30.240 --> 14:34.300] Frankly, what I do is I hook mine up to a target drive while I MD5 it. [14:34.540 --> 14:35.400] I know what's on it. [14:36.020 --> 14:36.860] I hook it up. [14:37.320 --> 14:38.180] I image it. [14:38.280 --> 14:39.340] I see if it's changed. [14:40.000 --> 14:40.360] Right? [14:40.560 --> 14:46.180] And I can guarantee that when I boot with a Windows system on this thing and it's connected through a USB cable to my system, nothing has changed. [14:46.560 --> 14:51.640] I do that under a bunch of different conditions, eventually I feel satisfied or I get a job and I go get paid to do something useful. [14:52.540 --> 14:55.800] Otherwise I just publish it and get, you know, closer to tenure. [14:58.460 --> 14:58.820] Right? [14:59.080 --> 15:00.800] The basic steps, I'm going to... [15:01.320 --> 15:04.440] I never go fast enough, but I'm going to try and go a little faster because I do want to entertain your questions. [15:05.420 --> 15:07.700] The basic steps, the things... [15:09.260 --> 15:10.300] Just checking the time here. [15:10.380 --> 15:11.280] I'm really not taking calls. [15:12.220 --> 15:16.220] The basic steps you want to go through is acquiring the data, authenticating the data, interpreting... [15:16.220 --> 15:18.760] And bear with me, these terms are loose. [15:19.940 --> 15:20.740] Interpreting the data. [15:21.180 --> 15:26.420] And that's so important because if you don't know what that file format means and you can't read it, you're not doing a whole lot of good. [15:26.660 --> 15:32.440] You can search it for strings and stuff like that, but generally speaking, you want to be able to interpret that data. [15:32.440 --> 15:33.960] So file viewers are very important. [15:34.200 --> 15:42.220] You want to get a tool that can get those all put together for you so you don't have to use 30 or 40 different programs to do an analysis because that takes time. [15:43.240 --> 15:46.460] You want to be able to report the results because that's why you're there. [15:47.060 --> 15:48.200] It's fun to do forensics. [15:48.340 --> 15:49.400] It's more fun to get paid. [15:50.460 --> 15:50.820] Wow. [15:51.360 --> 15:51.460] Yeah. [15:53.860 --> 15:58.060] And if your package isn't validated and they don't provide training and support... [15:58.060 --> 15:59.220] The training and support... [15:59.220 --> 16:00.900] I mean, frankly, I still go to the vendor training. [16:00.900 --> 16:02.360] I host them at the university. [16:02.860 --> 16:06.060] And that's the only way I can afford to use them because they're really expensive. [16:08.280 --> 16:09.920] And I still go and listen in. [16:10.100 --> 16:12.040] And it's very rare that I don't pick something up. [16:12.040 --> 16:13.760] Usually because it's a colleague who's teaching it. [16:14.040 --> 16:16.040] And, you know, they just throw in a tidbit. [16:16.340 --> 16:19.460] And I'm like, wow, that would have been so useful six months ago. [16:23.040 --> 16:26.240] But this is the imaging program from one... [16:26.240 --> 16:29.600] I've sanitized it because I don't want to endorse any particular vendor. [16:30.220 --> 16:34.640] Which brings me to the point, if you are going to select tools, select a broad range of tools. [16:34.900 --> 16:37.400] I use three different packages on a regular basis. [16:37.740 --> 16:41.220] And what we found out is that in some cases, some of them miss stuff. [16:41.460 --> 16:42.480] And that's really bad. [16:42.900 --> 16:44.000] But they're working on it. [16:44.800 --> 16:44.920] Right? [16:45.060 --> 16:46.620] And that means we've got to go back and look. [16:46.780 --> 16:47.140] And we do. [16:47.980 --> 16:51.980] That's where the difference between some guy who shells out $1,200 for the training. [16:52.500 --> 16:54.000] Buys the software for something more. [16:54.320 --> 16:57.860] Puts out a shingle, you know, in front of his geek squad desk at Best Buy. [16:58.920 --> 17:01.920] And the difference between that and someone who's gone through this. [17:04.420 --> 17:05.700] Does anybody recognize this, by the way? [17:05.740 --> 17:06.160] Can you read it? [17:09.220 --> 17:09.740] Thank you. [17:13.330 --> 17:16.550] For those of you who don't know what that means, for those of you who do, great. [17:16.790 --> 17:21.050] That's the dongle that you have to use in case I want to do a demonstration later. [17:23.650 --> 17:26.630] This is the imaging tool again, but do you recognize what that's an image of? [17:29.690 --> 17:30.910] Somebody else did this in a presentation. [17:31.030 --> 17:32.650] It was a lot more fun for them because everybody answered. [17:32.850 --> 17:33.670] Maybe they could see it. [17:34.530 --> 17:34.610] All right. [17:34.970 --> 17:35.990] We're at offset zero. [17:36.230 --> 17:37.030] There's your first hint. [17:39.350 --> 17:39.870] Yeah. [17:40.130 --> 17:40.190] Okay. [17:40.310 --> 17:42.190] And no bootable partition found so you see the message there. [17:42.510 --> 17:43.010] Great. [17:44.110 --> 17:44.470] All right. [17:44.730 --> 17:47.870] This is the analysis tool because that demonstration wasn't real fun. [17:50.030 --> 17:54.470] And the beauty of these things, the tools, is not that they do the thinking for you. [17:55.030 --> 18:01.910] There is a gentleman in Austin who I admire greatly who has a forensics package built in Linux. [18:02.470 --> 18:04.110] If someone wants to yell out the name, you can. [18:04.270 --> 18:06.810] But again, I'm not going to endorse any particular product. [18:07.030 --> 18:07.650] I'm smart. [18:10.010 --> 18:11.990] And I love that thing. [18:12.170 --> 18:15.410] And I'm not even really a Linux user, as you may have guessed, because I'm using PowerPoint now. [18:16.310 --> 18:17.310] But it is nice. [18:18.150 --> 18:24.890] I also use this particular product, which is not the one I was mentioning, because it's convenient and it does a lot of the things I need to do in a convenient way. [18:24.890 --> 18:25.970] And here's the deal. [18:26.170 --> 18:30.910] If the package does the job, it does all those functions that I just listed, it's good. [18:31.190 --> 18:35.050] If it takes the tedious, repetitive work off of you, it's good. [18:35.250 --> 18:39.130] If it replaces your own mind in the equation, it's bad. [18:39.770 --> 18:47.630] And undertrained people or people who are a little insecure about their knowledge, like me, I'm a little insecure about it, don't do a good job. [18:47.930 --> 18:50.450] Because the tool presents information for you. [18:50.530 --> 18:51.470] It organizes it for you. [18:51.470 --> 18:54.390] It lets you run searches across multiple different images. [18:54.830 --> 18:57.550] But what it does not do is... [18:58.730 --> 19:00.290] Is that forensic planner still open? [19:00.470 --> 19:01.090] No, I guess not. [19:02.090 --> 19:02.430] Okay. [19:02.570 --> 19:04.730] What it doesn't do is develop the case for you. [19:04.730 --> 19:06.350] You've really got to know what it is you're looking for. [19:06.490 --> 19:08.290] And that's where the training and experience come in. [19:08.630 --> 19:11.190] That's where your knowledge that you already have come in. [19:11.350 --> 19:14.570] And if you haven't thought about it before, think about the things you would look for. [19:14.770 --> 19:15.130] Right? [19:15.330 --> 19:19.610] If you're looking to prove that someone has child pornography, what are you going to do? [19:20.910 --> 19:21.890] Look at pictures. [19:22.550 --> 19:22.950] Right? [19:23.270 --> 19:24.470] Immediately call law enforcement. [19:24.650 --> 19:25.350] Don't mess around with that stuff. [19:26.270 --> 19:27.670] It's just so toxic. [19:29.210 --> 19:32.670] But if you're looking for network intrusion, what are you looking for? [19:32.930 --> 19:34.010] You go for the logs. [19:34.190 --> 19:37.770] You look for evidence of tools on the machine of the person you think is doing it. [19:37.870 --> 19:39.110] Especially if you have access to it. [19:39.310 --> 19:42.170] And I'm not even getting into why and how you have access to it. [19:42.170 --> 19:45.510] Because the scope has to come down somewhere. [19:47.490 --> 19:49.010] This does nice things. [19:50.090 --> 19:50.990] If I can get a cursor. [19:51.470 --> 19:54.110] This line is labeled KFF alert files. [19:54.290 --> 19:55.290] That's known file filter. [19:55.650 --> 19:59.050] And what it does, which is so nice, is it takes a hash of a known file. [19:59.270 --> 20:00.870] It says this file. [20:01.010 --> 20:01.650] It hashes it. [20:01.730 --> 20:03.850] It goes, oh, that's just part of the Microsoft operating system. [20:03.990 --> 20:04.630] And it's unchanged. [20:05.210 --> 20:05.610] Ignores. [20:06.150 --> 20:07.150] And that's so nice. [20:07.290 --> 20:11.330] Because, you know, you've got 40, 50, 100,000 files on a system. [20:11.630 --> 20:13.690] And you really don't want to be jacking around with that. [20:13.930 --> 20:15.170] It takes a look at duplicates. [20:15.270 --> 20:16.630] It lets you filter them out conveniently. [20:16.850 --> 20:17.910] But it doesn't force you to. [20:18.350 --> 20:19.410] And that's one of the key things. [20:19.550 --> 20:21.130] Things that make decisions for you bad. [20:21.490 --> 20:23.410] Things that let you make decisions good. [20:23.690 --> 20:26.070] Be careful of the guy behind the keyboard at that point. [20:26.190 --> 20:29.230] Because he may not understand what decisions he's taking the default on. [20:29.350 --> 20:29.930] And what that means. [20:31.990 --> 20:32.710] Bad extension. [20:32.950 --> 20:34.570] This is one of the things I really like about this. [20:34.570 --> 20:38.930] There's another package out there with a company that I have a good relationship with and respect a lot. [20:39.130 --> 20:42.830] But it looks at the file extension to determine what type of file it is. [20:43.470 --> 20:44.870] And that's just a non-starter. [20:45.350 --> 20:45.630] Right? [20:45.710 --> 20:47.730] I can rename a text file .log. [20:48.070 --> 20:51.930] And, you know, you may be able to put that in there and say .log files are usually text. [20:52.630 --> 20:55.690] But changing a three-letter extension at the end of a file is real easy. [20:56.390 --> 20:56.790] Right? [20:58.130 --> 21:00.230] What this one does is takes a look at the header. [21:01.050 --> 21:04.470] It goes into the very beginning of the file and it matches it to that header. [21:04.570 --> 21:05.070] Signature. [21:05.250 --> 21:08.390] If you want to know more about that later, I have another presentation I can bring up like that. [21:08.550 --> 21:10.150] But let's get through this one. [21:11.910 --> 21:15.770] It lets you sort the types of files you want to look at. [21:15.930 --> 21:16.590] And that's handy. [21:16.690 --> 21:19.750] Because if you're not looking for graphics, you don't have to mess with graphics. [21:20.270 --> 21:21.210] You're looking at email. [21:21.370 --> 21:24.250] You want to know who released the company's trade secrets. [21:24.650 --> 21:25.010] Right? [21:25.270 --> 21:26.230] Is it going to be in a graphic? [21:26.230 --> 21:31.690] Well, you know, there might be indications there, but that's just a client with really deep pockets that wants you to look at graphics for that. [21:35.980 --> 21:36.700] The nice... [21:37.140 --> 21:38.220] And these slides are random. [21:38.340 --> 21:38.720] Forgive me. [21:39.600 --> 21:42.160] I'm going to connect this with the talk and then hit this case. [21:42.660 --> 21:44.960] There are penalties for people in the civil world. [21:45.080 --> 21:48.000] And again, remember, I'm talking about the civil world, not the criminal investigations. [21:48.600 --> 21:53.160] If you delete data, you can be subject to civil penalties. [21:53.480 --> 21:57.520] The type of case I'm typically working is an intellectual property case. [21:58.400 --> 22:03.080] Some admin left the company, took the passwords with them. [22:03.200 --> 22:06.580] The new admin is barely understanding how the system has been screwed up. [22:06.780 --> 22:08.820] I mean, set up over the last five, six years. [22:09.560 --> 22:11.880] Doesn't want to change the passwords on key accounts. [22:12.140 --> 22:13.080] You've seen it. [22:13.200 --> 22:15.580] If you haven't done it, you've seen people who did. [22:16.300 --> 22:23.800] And now the old admin is accessing, or should I say, the BlackBerry service is accessing the CEO's email. [22:24.060 --> 22:28.380] And for those of you who don't know, that service should not be reading anybody's email. [22:28.580 --> 22:31.400] And it shouldn't be exploring people's file directories and stuff like that. [22:31.960 --> 22:32.220] Right? [22:33.000 --> 22:35.080] What you do in that case is you have a client. [22:35.220 --> 22:35.800] You go in. [22:35.920 --> 22:37.820] You grab their information that you need. [22:37.940 --> 22:39.080] You take a look at their logs. [22:39.180 --> 22:40.300] You can just back those up to tape. [22:40.420 --> 22:41.140] Take them home with you. [22:41.380 --> 22:43.820] You look at key machines that you believe were involved. [22:43.820 --> 22:46.020] Image those and analyze them later. [22:46.920 --> 22:48.660] And then develop a case. [22:48.920 --> 22:50.120] They bring a lawsuit. [22:50.420 --> 22:51.640] Not talking about a criminal case. [22:51.720 --> 22:55.060] They bring a civil suit against the rival that's employed their old admin. [22:55.700 --> 22:56.140] Right? [22:56.500 --> 22:57.260] Take it to court. [22:57.360 --> 22:57.960] Get a subpoena. [22:58.920 --> 23:00.320] Go in and get their stuff. [23:00.540 --> 23:01.440] And then you take a look at it. [23:01.840 --> 23:04.700] Now, anybody in law enforcement is just aghast at this. [23:04.700 --> 23:08.660] And you've maybe noticed the hole in this, too, without any particular training. [23:08.840 --> 23:10.480] What if they delete the evidence? [23:11.120 --> 23:14.840] Well, you know, erasing programs leave tracks. [23:15.040 --> 23:17.920] I've got a couple instances of that here in the demo file. [23:18.200 --> 23:21.080] But I can tell generally where an eraser has been. [23:21.500 --> 23:23.000] I've got a hex profile. [23:23.280 --> 23:25.860] It makes a histogram of the bytes in hex. [23:25.860 --> 23:29.080] And it's really easy to tell when it's been overwritten with random characters. [23:29.260 --> 23:32.000] Because it's even more regular than encryption or compressed. [23:32.800 --> 23:33.000] Right? [23:33.380 --> 23:36.880] There's just a look that says I've been overwritten with random characters. [23:37.340 --> 23:39.980] And it's very compelling to a jury to see that histogram. [23:43.180 --> 23:45.680] I've got a lot of slides on the different certifications. [23:45.940 --> 23:49.220] Because I wasn't sure if any of you would be interested in moving into this area. [23:49.800 --> 23:55.560] One of the questions I tend to get a lot is what do I need to do to get that validation of my experience? [23:56.440 --> 24:00.440] Right now, everybody, I recommend the starting point is a CISSP. [24:01.440 --> 24:03.420] I always forget what those letters stand for. [24:03.520 --> 24:06.020] So I put them on the PowerPoint for me, as much as you. [24:07.040 --> 24:10.220] It's important to understand with certifications that any... [24:10.960 --> 24:14.140] Like, is anybody a Microsoft certified engineer? [24:15.580 --> 24:16.380] Yeah, okay. [24:16.660 --> 24:17.980] Well, you know what certifications are worth. [24:18.620 --> 24:20.060] The certifying authority... [24:21.260 --> 24:21.700] Sorry. [24:22.900 --> 24:26.160] The certifying authority has to have trust. [24:26.500 --> 24:26.900] Right? [24:27.040 --> 24:29.240] This is one of the organizations that's maintained its trust. [24:31.120 --> 24:32.380] Now, this is a fun one. [24:32.620 --> 24:35.700] The CFCE, you've got to be in law enforcement to take the training. [24:35.860 --> 24:37.620] I know the guy who's the president of that organization. [24:37.620 --> 24:40.340] And I'm still working on him to let me get in there. [24:41.500 --> 24:42.380] I just... [24:43.420 --> 24:45.560] He's maintaining that trust for his organization. [24:45.560 --> 24:46.400] He won't let me in. [24:46.400 --> 24:48.700] I can't take this training and get this certification. [24:49.540 --> 24:56.540] There are a number of certifications like that, which really helps former law enforcement officers who have acquired this knowledge and learned it hard. [24:56.800 --> 25:01.540] I mean, they worked for it to come in and move more easily into the forensics field. [25:01.660 --> 25:02.880] But there are other options. [25:05.960 --> 25:09.200] This certification is a good example of one that's losing its currency. [25:09.380 --> 25:11.460] It may be coming back several years ago. [25:11.500 --> 25:12.300] It was a good one. [25:12.300 --> 25:17.760] Now, the organization that gave it, it's doubtful if they exist anymore in a functional way. [25:18.400 --> 25:23.940] But, you know, a lot of the old guard have this credential and earned it back in the day and they still carry it. [25:25.300 --> 25:29.360] We have other things like from FLETC, the Federal Law Enforcement Training Center. [25:29.760 --> 25:30.940] They provide this. [25:31.040 --> 25:32.420] This is kind of the entry level. [25:33.800 --> 25:37.280] Hey, look, guys, I get to go to Georgia on vacation for a couple weeks. [25:37.280 --> 25:41.580] Can you cover my shifts for cops and federal agents and all that stuff? [25:42.480 --> 25:44.380] And again, this is a law enforcement only certification. [25:44.380 --> 25:47.120] But you can get the same training somewhere else. [25:49.440 --> 25:52.220] Unfortunately, there's a lot of money to be made in forensics. [25:52.560 --> 25:56.000] And the people who give the certifications know that and you pay for it. [25:56.680 --> 26:01.680] And so someone mentioned a product that used to be called Expert Witness. [26:03.180 --> 26:04.980] And if you don't know the story on that, just look it up. [26:04.980 --> 26:06.880] It's a great soap opera story. [26:07.500 --> 26:11.700] But there was a product that used to be called Expert Witness that is now being sold under a different brand. [26:11.880 --> 26:15.740] And it bears little resemblance to its ancient lineage. [26:16.000 --> 26:18.140] But it's a very popular package. [26:18.320 --> 26:20.460] It costs a heck of a lot of money. [26:20.500 --> 26:21.560] I can't afford it. [26:21.780 --> 26:23.780] So I work with companies that let me use it. [26:24.220 --> 26:26.360] You know, I have friends who have started their companies. [26:26.420 --> 26:28.540] I use their copy when I'm working on cases for them. [26:29.740 --> 26:32.120] They know that we're out there making money with the stuff. [26:32.280 --> 26:33.760] And they don't sell it cheap. [26:34.200 --> 26:35.500] Same thing with the certifications. [26:35.760 --> 26:37.620] They know that you're going to be out there making a lot of money. [26:37.820 --> 26:40.400] So breaking into this if you don't have a lot of money is hard. [26:40.720 --> 26:45.560] Which is why for years I've done my forensics with WinHex or, you know, some other Hex editor. [26:46.100 --> 26:50.060] Because I just couldn't get that on what they were paying a grad student. [26:50.520 --> 26:52.400] Or, you know, then a junior professor. [26:53.340 --> 26:59.900] But if you can get into it, if you can get to work with a company that will let you start going to those trainings and you want to do it, do it. [27:00.060 --> 27:02.500] And realize they're giving you an incredibly valuable skill. [27:02.760 --> 27:05.900] And maybe, you know, forgive them for the poor pay they're giving you at the moment. [27:06.480 --> 27:08.580] Because they are really setting you up for the future. [27:10.320 --> 27:11.040] More stuff. [27:11.380 --> 27:11.920] More stuff. [27:13.240 --> 27:14.800] There are tool certifications. [27:15.560 --> 27:17.960] And again, the certification doesn't make you better. [27:18.120 --> 27:19.560] The training behind it often does. [27:19.740 --> 27:23.900] But when you get into court, there are some assumptions that can be made if you've been certified. [27:24.220 --> 27:25.080] It's not a guarantee. [27:25.420 --> 27:28.520] Lawyers can argue about anything, including the color of the sky. [27:29.620 --> 27:35.280] But, you know, a clever lawyer will not argue the validity of these well-known industry standard certifications. [27:35.820 --> 27:36.920] That's why they're handy to have. [27:37.040 --> 27:39.500] They keep you from having to answer a few awkward questions. [27:40.160 --> 27:40.260] Right? [27:40.700 --> 27:41.480] You know you know it. [27:41.560 --> 27:42.480] Your friends know you know it. [27:42.740 --> 27:43.900] Does the court know you know it? [27:43.980 --> 27:45.400] Well, these letters behind your name help. [27:47.940 --> 27:49.100] And then there's other stuff. [27:50.540 --> 27:50.900] Right? [27:51.120 --> 27:55.300] There's some debate over whether these are valid or not, you know, for the forensic field. [27:56.560 --> 27:58.040] Frankly, why not have them? [27:58.200 --> 27:59.840] The entry cost on these is fairly low. [28:00.620 --> 28:02.320] If you're A plus, what does that mean? [28:02.320 --> 28:05.160] You can get hired at Best Buy and you don't have to stock. [28:05.380 --> 28:06.680] You can do the repairs. [28:07.820 --> 28:11.880] But it also proves that, you know, you've had some sort of validated training on the hardware. [28:12.100 --> 28:14.240] So you can remove a hard drive from a computer. [28:14.340 --> 28:15.860] Because we all know how difficult that can be. [28:17.900 --> 28:18.340] Right? [28:19.840 --> 28:21.360] I just have one side comment. [28:21.480 --> 28:26.420] Why do pedophiles always smoke a lot and not clean the inside of their computer ever? [28:30.400 --> 28:31.180] Well, you know. [28:31.960 --> 28:32.740] I'm just saying. [28:33.020 --> 28:33.960] I wear gloves. [28:39.290 --> 28:39.730] Okay. [28:40.070 --> 28:40.770] This, you want to read it? [28:41.610 --> 28:42.050] No. [28:43.410 --> 28:44.030] Thank you. [28:44.230 --> 28:44.710] Because I don't either. [28:48.250 --> 28:51.730] This deals, this is from the Electronic Communications Privacy Act. [28:51.850 --> 28:54.090] There's been a lot of law bandied about here. [28:55.210 --> 28:59.670] One of the things that you've got to be careful with is intercepting communication that's en route. [29:00.570 --> 29:01.950] Just because of the federal requirements. [29:02.190 --> 29:08.570] Generally in the civil side, as I've heard a couple of presentations here bring up, you're safe if your client owns the data. [29:09.250 --> 29:09.610] Right? [29:09.710 --> 29:12.130] If it's theirs, right? [29:12.290 --> 29:13.730] Generally speaking, you're covered. [29:13.890 --> 29:14.850] Now, I'm not a lawyer. [29:14.990 --> 29:16.170] I'm not giving you legal advice. [29:16.330 --> 29:20.610] I will not appear in court and say, yes, I said that at HOPE 6, so you should let this guy go. [29:20.750 --> 29:21.730] He didn't really commit a felony. [29:22.610 --> 29:31.770] But the fact of the matter is there are certain practices in the field, if you get experienced, if you get with people who know what they're doing and you learn from them, you're as safe as any member of the herd. [29:32.170 --> 29:36.630] If suddenly the courts decide the law really works a different way, there's not a lot any of us can do. [29:40.530 --> 29:40.890] Yes. [29:41.490 --> 29:43.030] That is the end of the slideshow. [29:43.150 --> 29:45.270] Now comes the interactive portion. [29:46.230 --> 29:48.750] I've got roughly 15 minutes of presentation time left. [29:48.750 --> 29:57.650] I can either take questions or I can discuss a little bit of the technical details of what we do or I can demonstrate how bars scroll across things while you wait. [29:59.090 --> 30:01.070] Because that's the key to forensics. [30:01.630 --> 30:02.210] What's that? [30:03.090 --> 30:03.750] Do both. [30:03.750 --> 30:03.790] Do both. [30:04.030 --> 30:04.230] Excellent. [30:04.430 --> 30:05.870] I was afraid you were going to say that. [30:08.830 --> 30:09.270] Okay. [30:10.370 --> 30:17.670] This is from another presentation that I just like because somebody who is really technical goes, man, Cal, you are such a dork. [30:20.150 --> 30:20.990] Looking at data. [30:21.170 --> 30:21.950] Now this is the fun stuff. [30:22.050 --> 30:24.810] This is the hacking of forensics, if you will. [30:25.070 --> 30:26.950] This is not using the standard tools. [30:27.090 --> 30:28.710] This is not doing things a certified way. [30:28.810 --> 30:32.130] This is what does that little fragment in a page file mean? [30:32.290 --> 30:35.090] Or what is that in the slack but we don't get that anymore? [30:35.390 --> 30:36.790] This is kind of the old stuff. [30:37.790 --> 30:40.970] And when I explain it to students, I want them to know there's data out there that can be discovered. [30:43.270 --> 30:45.310] So, oh, yeah. [30:45.510 --> 30:45.830] Let's go back. [30:47.250 --> 30:47.650] All right. [30:48.470 --> 30:49.230] I've hidden. [30:49.530 --> 30:51.770] I've obfuscated a file here. [30:51.950 --> 30:53.090] Do you know what type it is? [30:55.250 --> 30:57.030] You know, it's E. [30:57.090 --> 30:59.590] Don't overthink this one because this is the shallow end. [30:59.710 --> 31:00.270] We'll get deeper. [31:01.870 --> 31:03.270] Do you think it's a JPEG? [31:04.350 --> 31:04.750] Okay. [31:04.950 --> 31:07.810] The reason for that is there's another one with the same name without the extension. [31:07.990 --> 31:10.390] It's the same size and you can't see but they have the same date. [31:12.190 --> 31:13.170] It's good, wasn't it? [31:13.550 --> 31:15.750] I mean, seriously, sometimes the answers are easy. [31:15.950 --> 31:19.950] And if you get too busy looking for hard answers, you'll miss the easy ones. [31:20.370 --> 31:20.730] Right? [31:20.790 --> 31:25.830] If you spend all your time looking for the deleted email and you don't actually check the inbox, you can miss it. [31:26.970 --> 31:29.250] Not that that's happened to me often. [31:31.810 --> 31:32.250] Right? [31:32.670 --> 31:41.050] On any system that you have access to, and let's assume you want to do active running forensics or, you know, you want someone, like, the police are just all shuttering. [31:41.110 --> 31:42.710] Like, oh, no, you can't get on the active system. [31:42.810 --> 31:43.670] And I'm like, no, we're civil. [31:43.770 --> 31:46.930] We can do anything we want and civil judges don't know either. [31:48.170 --> 31:50.430] So, you can always get in and take a look with a hex editor. [31:50.990 --> 31:51.050] Right? [31:51.110 --> 31:53.670] There's always one, you know, VI, notepad, something's going to be there. [31:55.470 --> 31:58.790] So, what do you think, what kind of file do you think this is? [32:00.930 --> 32:01.530] Text file. [32:01.610 --> 32:01.870] Text file, yes. [32:02.290 --> 32:02.450] All right. [32:02.490 --> 32:06.430] I wish I had T-shirts to give out because this would be more interesting for you then, but I'm cheap. [32:07.830 --> 32:08.270] All right. [32:08.790 --> 32:10.450] What kind of file do you think this is? [32:11.470 --> 32:11.830] Yay. [32:12.330 --> 32:12.630] All right. [32:13.310 --> 32:16.310] You are about to get the Cal certification for forensics. [32:16.470 --> 32:18.990] Just ask for a guy named Greg Newby. [32:19.350 --> 32:20.310] He has a certificate. [32:20.510 --> 32:20.870] No, I'm kidding. [32:23.290 --> 32:23.750] All right. [32:23.950 --> 32:25.610] Here's the coal with a big hole in its side. [32:25.730 --> 32:25.870] Yes. [32:28.190 --> 32:30.290] You know, I hope everybody here understands hex. [32:30.470 --> 32:34.830] If you don't, I'll be happy to explain it, but everybody else will hate you. [32:37.290 --> 32:38.630] This is what I thought was fun. [32:39.030 --> 32:49.230] Taking these byte histograms, and what it does is it just counts the number of empty bytes, all zeros, full bytes, all ones, and everything in between. [32:49.230 --> 32:52.270] Can anybody guess how many columns there are in this histogram? [32:54.090 --> 32:54.690] 256. [32:54.690 --> 32:55.130] No, 256. [32:55.510 --> 32:55.710] That's right. [32:55.930 --> 32:57.250] Because we start counting. [32:57.850 --> 32:59.470] This one is number 255. [32:59.890 --> 33:00.710] Let's go back. [33:02.530 --> 33:03.590] Yes, exactly. [33:04.630 --> 33:08.930] And each different file type has a look to it. [33:08.930 --> 33:10.890] And I wish I could be more definite than that. [33:10.990 --> 33:16.250] I wish I could say we could eventually someday pattern match it with algorithms, and maybe some of you could, but I can't. [33:16.370 --> 33:19.590] So what I do is sit there and look at them, and Bill, by the hour. [33:23.640 --> 33:24.080] All right. [33:25.680 --> 33:26.460] Yes, we were right. [33:26.580 --> 33:27.100] It is a picture. [33:27.360 --> 33:28.400] It is actually in poor taste. [33:28.540 --> 33:29.780] I didn't mean this to be given in New York City. [33:30.280 --> 33:32.240] But no, that's not funny. [33:34.740 --> 33:35.060] Sorry. [33:35.920 --> 33:37.180] It was disturbing to me. [33:37.280 --> 33:41.860] I did this right after the event, and I was, you know, I wanted to make it part of it. [33:42.120 --> 33:43.660] Now, this is a different kind of file. [33:43.740 --> 33:50.740] Now, obviously, you've got the name of it up there in the title bar, but you see that there's a very different look to it. [33:51.000 --> 33:52.260] This is a bitmap file. [33:52.400 --> 33:56.700] It is an 8-bit bitmap file, so you see that there are a lot of bytes that aren't used. [33:56.960 --> 33:57.300] Right? [33:57.380 --> 34:02.800] Not just colors that are underused, but there are some bytes that simply don't get used in an 8-bit bitmap image. [34:06.600 --> 34:07.420] Surely I had something... [34:07.420 --> 34:07.520] Oh. [34:09.060 --> 34:24.840] Statistically, and you've got to leave the deterministic computer science mindset here for a minute, and go into social science, which is where I scammed, I mean, got my PhD, and think, probabilistically, a small sample of a relatively homogenous data set. [34:24.960 --> 34:28.400] Now, this doesn't work with the executable files so well because those aren't homogenous. [34:28.660 --> 34:32.380] But the more data you have, the more homogenous it's likely to be across at all. [34:32.920 --> 34:38.160] And any given sample of that should relatively well represent the whole. [34:39.420 --> 34:43.020] It doesn't work all the time because bytes aren't randomly distributed in programs. [34:44.720 --> 34:46.280] But the idea is there. [34:46.700 --> 34:51.000] So if you have enough data in your sample, you can make inferences from a small fragment. [34:51.180 --> 34:58.100] So you don't have the header, so you don't have the extension of a deleted file, but you do have this pile of bytes that is otherwise useless. [34:58.540 --> 35:05.240] You can identify where that might have come from, which would make it easier to match it to byte patterns in another file. [35:05.800 --> 35:10.580] Now, again, if it's one of those known files that happens all the time, it's not so useful to you. [35:10.580 --> 35:20.800] But if it's a unique file, like an image, you can take a small fragment of an image and take those byte patterns, search for them within other images, and maybe find it. [35:20.940 --> 35:23.540] And then it's really just a matter of how well can you make the case. [35:23.640 --> 35:24.460] It's not a done deal. [35:24.900 --> 35:31.140] But if you get enough bytes in enough places, right, you know, how many bytes does it take to give you statistical certainty? [35:31.320 --> 35:35.840] It's, you know, whatever you're willing to stake your reputation on in court and end up looking like an idiot if you're wrong. [35:37.320 --> 35:41.340] And that's the forensic side of it, that argument process in court. [35:42.660 --> 35:43.480] There's the image. [35:43.920 --> 35:48.240] Now, for those of you who haven't actually done this before, this is compressed data, which is fun. [35:48.620 --> 35:54.540] Compressed data and encrypted data look very similar and pure random data look very similar, but there are differences. [35:55.040 --> 36:01.640] There are certain peaks, for lack of a better term, to this compressed data. [36:03.640 --> 36:04.140] All right. [36:04.380 --> 36:05.440] The original file was zipped. [36:05.600 --> 36:06.900] It's a sniffer program. [36:07.020 --> 36:07.860] I think it's the Italian one. [36:08.060 --> 36:08.520] I don't remember. [36:08.660 --> 36:09.540] I haven't used it in a long time. [36:12.240 --> 36:13.820] And this is an executable file. [36:13.940 --> 36:20.820] Now, the interesting thing about executable files, as many of you know better than I do, they have a lot of empty bytes or all zeros. [36:21.320 --> 36:22.940] It's just the nature of them. [36:23.120 --> 36:30.580] So if you get one of these files with an extremely high amount of white space, there's a good chance it's an executable. [36:30.580 --> 36:34.360] It's not a done deal, but it's one of the things that we do and have fun with. [36:38.690 --> 36:40.450] JPEGs have a very spiky structure. [36:40.610 --> 36:43.710] You know, JPEGs have an underlying compression pattern to them. [36:44.170 --> 36:44.510] Right? [36:44.610 --> 36:50.010] And it's hard to compress a JPEG, but if you look at this byte structure, you can see that there's a lot of room for homogenization in it. [36:50.830 --> 36:52.510] It's not like a zip file. [36:52.650 --> 36:53.890] The compression isn't as tight. [36:55.310 --> 36:58.210] How does this square up to the fact that your JPEGs don't compress real well? [36:58.970 --> 36:59.510] I don't know. [37:01.590 --> 37:03.950] And there's the basic image that it was on. [37:04.210 --> 37:05.130] Now, text is fun. [37:05.750 --> 37:07.730] Text is highly clustered in, guess what? [37:08.250 --> 37:09.310] The printable characters. [37:09.990 --> 37:10.410] Right? [37:11.470 --> 37:16.530] Unicode, and ASCII, and ANSI, or SI, I think. [37:17.050 --> 37:17.350] ANSI. [37:19.410 --> 37:28.330] A lot of people, or a lot of times I get my students on the test, is I give them a lot of white space, and then a bunch of letters, and they think it means spaces. [37:29.450 --> 37:29.810] Right? [37:29.890 --> 37:34.310] I'm trying to convince them the space is not represented by a binary string of zeros. [37:35.170 --> 37:35.530] Right? [37:35.670 --> 37:36.430] They think white space. [37:36.570 --> 37:36.930] You know what I mean? [37:36.990 --> 37:39.630] It's just an important distinction, and I'm a jerk on tests. [37:44.120 --> 37:44.600] All right. [37:46.540 --> 37:47.740] Unicode text encrypted. [37:47.980 --> 37:51.440] This is PGP, just like as I was going to send it out by email. [37:55.040 --> 37:56.460] There is the original file. [37:57.360 --> 37:59.740] Understand, the scale changes, so it all fits. [38:00.280 --> 38:10.140] The high amount of white space in the original file, because it was Unicode, really throws off those histograms, and I haven't found a good, reliable way to get rid of that, and force the other ones into higher relief. [38:12.780 --> 38:13.220] What's that? [38:14.660 --> 38:15.780] It's just the tool that I use. [38:15.880 --> 38:22.180] I mean, I could generate my own histograms, I guess, but I'm just too lazy so far. [38:23.160 --> 38:25.080] But you're right, yeah, there is a way to do it. [38:25.580 --> 38:26.860] I'm just too lazy to figure it out. [38:28.180 --> 38:33.800] And the last way, which I consider is the most reliable method, if you have access to it, is to take a look at the headers. [38:35.560 --> 38:36.560] I'm going to do it on time. [38:36.780 --> 38:37.760] Oh, five minutes left. [38:38.940 --> 38:42.180] How about an extended set of questions? [38:42.580 --> 38:44.060] Because I want this to be useful to you. [38:44.140 --> 38:45.840] I want to answer the questions that you have. [38:46.580 --> 38:48.280] And remember, I'm not trying to make a point here. [38:48.400 --> 38:49.560] I'm just trying to be helpful. [38:52.340 --> 38:53.260] You just don't care. [38:53.580 --> 38:54.020] Oh, there you go. [38:56.220 --> 38:57.340] Okay, it's on. [38:58.240 --> 39:01.900] I guess my question would be hard disk passwords. [39:02.660 --> 39:04.180] I don't know if you're familiar with them. [39:04.320 --> 39:05.820] I would imagine you probably are. [39:06.280 --> 39:06.360] Yeah. [39:06.920 --> 39:12.200] It's something I've had to deal with, with trying to recover data, and people forget them. [39:12.420 --> 39:14.200] Are you talking about ATA3 passwords? [39:15.680 --> 39:19.420] They're common on the IBM and Lenovo laptops. [39:20.400 --> 39:26.760] Hitachi is the company where I got the standard from, but I think they are ATA standards. [39:27.480 --> 39:29.320] There are two separate ways to do that. [39:29.400 --> 39:37.400] In fact, if anybody here has a chance to get file forensics books, a book by Brian Carrier, it is right now the best reference I've seen. [39:38.240 --> 39:40.320] It's not... how can I say this? [39:40.680 --> 39:42.960] It is the best reference I've seen. [39:43.160 --> 39:45.180] I have not a bad thing to say about it. [39:45.300 --> 39:48.540] That being said, you know, if I was... [39:49.760 --> 39:51.820] If I had written the book, there were other things I would have put in. [39:52.220 --> 39:54.420] But he was doing it from his perspective, and I respect that. [39:54.500 --> 39:55.700] It's better than anyone else's. [39:56.200 --> 39:57.180] And he covers that. [39:57.440 --> 39:59.340] Their utilities is what it boils down to. [39:59.340 --> 40:03.480] Well, everything I've seen on this, and I've done a little bit of research. [40:03.720 --> 40:05.360] I don't claim to be an expert or anything. [40:05.680 --> 40:18.940] But the passwords seem to be locked on the drive, where it's locked in a mode where you can't do anything other than give it the password or reset the password, which still requires giving it the password in the first place. [40:19.920 --> 40:27.540] And you can't... you can brute force it, but there's no other way to, like, get the password off the drive to actually get to it. [40:27.540 --> 40:34.660] I mean, is there anything out there other than, like, the special gotta have a forensics license, utilities, and... [40:34.660 --> 40:36.460] Or, I guess, it's not even a utility. [40:36.640 --> 40:38.460] It's more of a hardware... [40:38.460 --> 40:39.240] Yeah, I know. [40:39.380 --> 40:43.560] And it comes right from the manufacturers, and they're real snotty about giving it out except to law enforcement. [40:44.380 --> 40:50.500] This is one of those areas where the overlap, in my experience, has been bad, to give you an answer. [40:50.860 --> 40:55.720] Because the last time I thought about that question in a real serious way, it was within the law enforcement context. [40:56.160 --> 41:01.540] And I gave that answer to someone else, like, you know, you just go talk to the manufacturer, they'll talk to you about how to get past it. [41:01.780 --> 41:04.060] I haven't come into that in the civil side. [41:05.360 --> 41:06.720] It is possible to do. [41:06.920 --> 41:07.860] I know it's out there. [41:08.160 --> 41:11.560] And we use one of those expensive utilities to get around it. [41:11.620 --> 41:17.060] Well, if someone can come up with an open source hardware solution, please do post it somewhere. [41:17.880 --> 41:18.260] Thanks. [41:18.620 --> 41:21.880] Yeah, or mail it to me, and I'll put it out for you. [41:21.980 --> 41:23.500] I mean, I don't believe in keeping this stuff. [41:24.240 --> 41:24.700] It's free. [41:24.840 --> 41:25.180] It's out there. [41:25.340 --> 41:28.480] If you're interested in any of these slides, they're on my website for my classes. [41:28.980 --> 41:37.360] The only real inconvenience is I have to change the names every semester because the university's web server makes me, as we change the name of the semester, so I can't have an absolute path. [41:38.160 --> 41:38.940] Yeah, sir? [41:39.260 --> 41:49.560] I was just wondering if you have a recommended reading list someplace to start, and you just mentioned that book, but any others? [41:50.060 --> 41:50.360] Yes. [41:51.440 --> 41:54.040] And strangely enough, the book I have co-authored is not on it. [41:55.720 --> 41:59.420] Egan Casey, I can't recall the name of the book. [41:59.560 --> 42:01.100] I want to say it's Digital Evidence. [42:02.260 --> 42:09.580] If you go onto Amazon and look for storage forensics or computer forensics, you should be able to find that book. [42:09.700 --> 42:11.140] I've got it. [42:11.220 --> 42:12.420] I've actually assigned it this semester. [42:12.700 --> 42:23.640] Another book is, I want to say it's called Computer Forensics by Warren Kruse, K-R-U-S-E, is, at the time it came out, the best resource I'd ever seen. [42:23.980 --> 42:27.860] It surpassed several others in this particular arena. [42:27.860 --> 42:31.620] I understand these books I'm talking about are not the CS style forensics. [42:31.960 --> 42:38.300] Carrier's book is, but these other ones are my side of the house forensics. [42:40.420 --> 42:50.940] There have been a lot of articles in 2600 and mentions on the radio program about how to protect your data and what you might want to do if you're going to be throwing out a hard drive and things like that. [42:50.940 --> 42:58.020] I'm wondering what your recommendation is for, you know, hiding my porn from people like you. [42:59.440 --> 43:03.100] I'll answer it philosophically because I can't give you a definitive answer. [43:03.380 --> 43:07.940] Encryption, there's really no good rule, high bit encryption. [43:09.540 --> 43:13.100] You know, encryption can be broken, but then there's realistic breaking of encryption. [43:13.240 --> 43:16.500] There are toolkits out there, you know, we know about the rainbow tables. [43:16.500 --> 43:18.780] You can go through the Microsoft documents in about three minutes. [43:19.180 --> 43:23.260] I mean, literally three minutes, and your Excel spreadsheet is mine. [43:24.660 --> 43:27.940] Otherwise, we use the same attacks that anyone else does. [43:30.120 --> 43:34.820] Removable media is often a problem for me, so I'm not actually suggesting it. [43:35.460 --> 43:39.860] But you think about where, you know, ideally the first thing is not to have incriminating stuff. [43:42.280 --> 43:43.160] Call me crazy. [43:43.400 --> 43:51.680] Especially if you're trying to build up that solid reputation that gives you the high paid job that I've only recently been smart enough to figure out, you know, I could get because I've been really poor until this year. [43:53.860 --> 43:55.040] How else would you hide it? [43:55.500 --> 43:56.980] I would say don't obfuscate it. [43:58.020 --> 43:59.480] I'll tell you a brief story. [44:00.000 --> 44:06.840] Like, when police get this training back in the mid-90s, there was always a story about hackers booby-trapping their computers. [44:06.840 --> 44:11.980] Well, that means, like, if you don't give the right command, it starts erasing things. [44:12.500 --> 44:12.680] Right? [44:12.800 --> 44:16.100] You know, the general paranoia stuff, which I don't really believe in anyway. [44:16.540 --> 44:19.780] And they thought it literally meant that something was going to jump out of there and get them. [44:20.060 --> 44:22.660] Like a shotgun shell wired to some... [44:23.840 --> 44:31.700] I mean, I don't even know what exactly it is in the computer that would jump out and get you, but they were like, I actually knew people who swore, yeah, you do it behind plywood. [44:32.520 --> 44:34.080] Because that'll stop the shotgun shell? [44:34.200 --> 44:34.380] Okay. [44:35.880 --> 44:37.480] But, you know, the sophistication has gone up. [44:37.560 --> 44:39.480] I'm not making fun of law enforcement like anybody else. [44:39.560 --> 44:41.760] You know, a newbie hacker is really not all that swift either. [44:42.080 --> 44:43.100] It's just... it's newbie. [44:43.280 --> 44:44.220] It's newbie everywhere. [44:44.400 --> 44:48.300] Newbie forensic guy makes mistakes, bends pins on the evidence hard drive. [44:49.600 --> 44:56.300] I imagine you obtain most of the physical mediums, like the hard drives, before... [44:56.960 --> 45:00.480] Like, while someone's being arrested or before they have time to do anything. [45:00.620 --> 45:04.240] But is physical damage to the drive going to make your life a lot harder? [45:04.240 --> 45:06.000] We use a data recovery firm with a clean room. [45:06.460 --> 45:09.100] A guy that I know very well runs it. [45:09.220 --> 45:10.760] He has a huge warehouse full of spare parts. [45:10.760 --> 45:13.800] He can get you new controller boards for really, really obscure things. [45:13.980 --> 45:17.560] Like, he had a one megabyte hard drive for a Commodore 64. [45:18.300 --> 45:20.720] And I was like, damn, that's not right. [45:21.480 --> 45:21.940] But... [45:22.460 --> 45:23.180] There it is. [45:24.480 --> 45:27.980] But I wanted to actually bring that long, useless story back to it. [45:28.540 --> 45:33.080] People who hide evidence and use it a lot don't do really goofy obfuscation. [45:33.680 --> 45:34.380] I mean, think about it. [45:34.380 --> 45:39.260] If you knew that you were going to mistype your password once and all your data would be erased, I mean, you don't do that. [45:39.460 --> 45:42.000] And if you do, damn, what's wrong with you? [45:43.160 --> 45:46.660] You end up storing your backups a lot, which means you have your backup tapes nearby anyway. [45:46.880 --> 45:48.060] So, what's the point? [45:49.740 --> 45:53.320] For obfuscation, I just say use good passwords, use good encryption. [45:54.300 --> 45:56.040] And don't bother with the goofy stuff. [45:56.400 --> 45:57.560] That way I won't have to teach it. [45:58.920 --> 45:59.320] Thanks. [46:00.940 --> 46:02.460] My question is about certification. [46:03.140 --> 46:11.260] I heard that, I don't know what university, but this year was their first class of graduating people with a BA and a forensics degree. [46:11.800 --> 46:15.740] If you could talk about that and whether that's relevant, will it be relevant? [46:17.260 --> 46:22.400] You know, last year even, I would have said something stupid along those lines. [46:22.780 --> 46:27.660] My thought is the more people who do this, the more programs that are started, the better quality we're going to develop. [46:27.900 --> 46:30.240] And if people don't do things my way, they're not wrong. [46:30.240 --> 46:32.060] And I know that now and I'm very sorry. [46:32.960 --> 46:33.500] Oh, sorry. [46:34.120 --> 46:35.100] I was somewhere else for a minute. [46:35.520 --> 46:39.460] No, but, I mean, the more programs that are out there, the more people that are looking into this, the better. [46:39.760 --> 46:43.280] I would love to see more CS law side collaboration. [46:43.740 --> 46:45.160] I mean, I work with both faculties. [46:45.340 --> 46:48.620] And frankly, I think we do some really useful things when we do it. [46:49.760 --> 46:53.140] But those programs are good. [46:53.380 --> 47:03.620] I say the danger to them is, and if you're thinking about going out and getting a bachelor's or a master's in computer forensics, realize that ubiquitous encryption means the field doesn't exist anymore. [47:04.380 --> 47:05.340] Real quick. [47:06.000 --> 47:09.660] Until we come up with a whole new whiz-bang solution to get around it. [47:10.400 --> 47:10.660] Right? [47:10.760 --> 47:13.120] You know, because people were scared with Longhorn. [47:13.440 --> 47:15.220] What do we do if it's on and it's strong? [47:15.980 --> 47:17.300] We get it while it's still running. [47:17.440 --> 47:22.940] I mean, we were literally starting to come up with new training paradigms based on, oh, my God, we've got to get it while it's on. [47:24.740 --> 47:25.140] Right? [47:25.320 --> 47:29.900] So, and there are new forensic models being developed by some of the vendors. [47:30.280 --> 47:36.100] I really can't talk about them, but it has to do with a more dynamic forensic approach, especially this is the civil side. [47:36.380 --> 47:38.540] I don't do high-end development in law enforcement. [47:38.640 --> 47:39.060] I just teach. [47:41.180 --> 47:41.580] Sir? [47:41.900 --> 47:52.580] I wanted to know if you had any specific knowledge about of a program that can read the master file table in NTFS file systems. [47:52.860 --> 47:58.820] Because for a long time, I actually have done disk recovery for a while. [47:59.360 --> 48:08.080] And I used to use DiskEdit for FAT32 and FAT16 that could read that stuff and it could show you. [48:08.220 --> 48:11.940] But I've never found a program that did the equivalent of that on NTFS. [48:11.940 --> 48:13.780] And I was just wondering if you knew of any. [48:13.960 --> 48:15.280] Just automating the process? [48:15.860 --> 48:24.060] No, like being able to look at the master file table and say, this is, you know, this cluster points to this particular file. [48:24.920 --> 48:27.180] And, you know, obviously vice versa. [48:28.700 --> 48:30.460] I wish I had a good answer for that. [48:30.580 --> 48:31.680] We take a different approach. [48:32.100 --> 48:34.680] We take the whole disk intact and then we search it. [48:35.560 --> 48:43.160] So, you know, the automatic tools are the ones that just rebuild NTFS in a contained environment. [48:43.360 --> 48:44.400] Without starting up the software. [48:44.900 --> 48:46.680] But if you bring up an image... [48:49.480 --> 48:50.300] Let's go ahead and do it. [48:59.950 --> 49:04.490] By the way, while I'm doing this, I just want to say hello to all the people who are watching this on the web. [49:04.490 --> 49:06.310] Or the DVD in the future. [49:06.490 --> 49:07.370] Go ahead, yell at me. [49:10.780 --> 49:12.120] What are we looking for here? [49:12.220 --> 49:12.620] An image. [49:14.240 --> 49:15.160] Let's do this one. [49:17.900 --> 49:18.440] All right. [49:18.840 --> 49:28.480] This utility that is free allows you to bring up the file system. [49:28.560 --> 49:30.020] Now, this one is one that got wiped. [49:30.020 --> 49:34.600] But if there was a native file system on it, if it was a hard drive, you would be able to go down. [49:34.900 --> 49:36.480] It throws in a couple extra files. [49:36.700 --> 49:40.200] And one of the problems with recovery in that is people delete things. [49:40.300 --> 49:40.900] Things get hidden. [49:41.000 --> 49:42.560] And you need to find a way to represent them. [49:42.940 --> 49:47.520] So this tool takes the idea that it identifies what it's recovered for you. [49:47.560 --> 49:51.720] And you can distinguish it from what the user was able to see last time they logged in. [49:52.380 --> 49:53.980] But this rebuilds it. [49:54.660 --> 49:56.240] It will do it with NTFS. [49:56.320 --> 49:59.200] It will do it with riser, EXT2 if you have the drivers. [49:59.640 --> 50:05.560] Which, by the way, my favorite find is the EXT2 driver. [50:05.860 --> 50:17.040] So I can use that Linux acquisition kit and just open the images right up off the USB hard drive onto this machine or a real machine, not my laptop. [50:17.580 --> 50:20.040] What was the name of that program you just had? [50:20.040 --> 50:22.000] It's called FTK Imager. [50:22.800 --> 50:23.240] FTK? [50:23.440 --> 50:23.660] Yeah. [50:26.060 --> 50:26.260] Sorry. [50:27.100 --> 50:27.940] I'm talking to the camera. [50:28.380 --> 50:28.640] Question. [50:29.400 --> 50:33.240] Have you ever used any sort of live imaging of memory tools? [50:33.620 --> 50:34.240] Hardware tools? [50:34.440 --> 50:34.840] I can... [50:34.840 --> 50:35.800] Which tools? [50:35.960 --> 50:36.560] Live imaging? [50:36.700 --> 50:37.140] Of memory. [50:39.200 --> 50:42.960] The problem with that is you've got to have the software installed in the system. [50:43.380 --> 50:45.120] And some of you in the crowd may know otherwise. [50:45.140 --> 50:49.200] I am not aware of a solution that allows you to do that well. [50:49.200 --> 50:51.820] So it's only on the civil side that we would do that. [50:52.060 --> 50:53.460] And yes, it is possible. [50:53.960 --> 50:56.740] I mean, any hex editor, a good hex editor will be able to open RAM. [50:58.640 --> 51:06.740] And the second part is for those who may not pursue civil, what do you know any recommendations for getting involved with the military or the police? [51:07.040 --> 51:12.820] I know absolutely nothing about the military, the NSA, CIA, any other three letters you want to put together. [51:13.680 --> 51:16.360] My advice overall is have a clean record. [51:16.740 --> 51:17.440] Be honest. [51:17.700 --> 51:21.440] Always be honest because integrity is what you're selling in forensics. [51:22.320 --> 51:28.240] If you give that up, if you get a track record, especially if you lie in court, you are just really out of the game. [51:28.580 --> 51:33.000] Just go sit on the bench, go away, because nobody will want to play ball with you anymore. [51:33.000 --> 51:33.980] Thank you. [51:37.040 --> 51:45.520] What issues do, say, RAID 0 or RAID 5 have an effect on the forensic end or recovery process? [51:45.680 --> 51:52.180] And how can you make sure that it doesn't get written to or somehow the evidence get tainted? [51:52.540 --> 51:53.680] RAID is a pain in the ass. [51:56.120 --> 51:56.920] It is. [51:57.180 --> 51:57.460] It is. [51:57.460 --> 52:03.420] Images of RAID disks, if you don't have the same controller, are just so probably not going to work. [52:03.900 --> 52:08.280] Really what we do now is we use that Linux disk to do dynamic acquisition of them. [52:08.620 --> 52:12.760] And that disk is so nice because it mounts everything read only. [52:12.980 --> 52:14.140] You don't need the write blockers. [52:14.380 --> 52:21.700] Throw the disk in, boot to that system, and then you just acquire a way right onto your little external drives. [52:22.660 --> 52:23.120] Thank you. [52:24.080 --> 52:25.220] And see, this is the thing. [52:25.700 --> 52:27.960] You're thinking you want answers on your terms. [52:28.180 --> 52:34.100] And I'm not saying this to you specifically, but one of the tricks that makes this work is we don't do it that way. [52:34.920 --> 52:37.220] We work around the problem a lot. [52:37.500 --> 52:38.700] So how do you get around this? [52:38.820 --> 52:39.200] Well, you don't. [52:39.300 --> 52:40.540] You just image the whole thing in search. [52:41.280 --> 52:41.600] Right? [52:41.680 --> 52:42.920] And then you don't have to worry about it. [52:43.000 --> 52:43.840] You know where the offset is. [52:43.900 --> 52:45.200] You know where it exists in the file system. [52:45.300 --> 52:47.640] If you want to go look for it, and boom, you've got what you need. [52:47.840 --> 52:48.880] How do you put a RAID together? [52:49.040 --> 52:50.120] Well, you don't put a RAID together. [52:50.120 --> 52:53.620] That's a work for someone who's employed as a system administrator. [52:53.900 --> 52:59.000] And what we do is just acquire it dynamically and get on with our analysis as quick as we can. [52:59.860 --> 53:00.200] Right? [53:00.400 --> 53:01.860] I'm not telling you that this is the end. [53:01.920 --> 53:02.480] I'll be all... [53:02.480 --> 53:03.920] Oh, I'm being told to stop. [53:05.720 --> 53:06.200] Thank you. [53:06.300 --> 53:08.060] I appreciate your attention and time. [53:08.060 --> 53:08.180] Thank you, Rob. [53:08.740 --> 53:08.920] Welcome.