+ All Categories
Home > Documents > Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must...

Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must...

Date post: 12-Jan-2016
Category:
Upload: karen-gibbs
View: 212 times
Download: 0 times
Share this document with a friend
28
Preserving Evidence Number one priority Must also find incriminating evidence Must search the contents of the hard drive Can not change the hard drive
Transcript
Page 1: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Preserving Evidence

● Number one priority● Must also find incriminating evidence● Must search the contents of the hard drive● Can not change the hard drive

Page 2: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Procedure

● Retrieve the hard drive from the evidence locker and update the chain of custody record.

● Calculate the MD5 Hash of the drive.

● “Image the hard drive.”

● Validate the M5D hash of the drive is the same as the MD5 hash of the image.

● Make a copy of the “Image”

● Store the actual hard drive together with the original “image” in the evidence locker.

● Remember to update the chain of custody record.

Page 3: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Procedure (cont’d)

● Use the copy of the hard drive image to perform your forensic analysis.

● You can always go back to the original image.● Or if necessary you can go back to the hard drive

and validate the MD5 hash.

Page 4: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Disk Image

● A disk image is an exact copy of everything on the disk.

● Not merely a copy of all the files.● It is an exact copy – all mistakes, errors, erasures,

dates, times, ● etc.● You can prove that it is an exact copy.

Page 5: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Disk Image

● Forensic Software does it.● HW can assist.● Software can do it.

Page 6: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Technique must be Validated

● NIST - ww.ncjrs.org● Unix command dd● EnCase● SafeBack● etc.

Page 7: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Cautions

● The hard drive cannot be accessed.● The hard drive cannot be altered.● The hard drive is sacred.● If you mess with it you are gone!!!● Blame always falls somewhere.

● What to do?

Page 8: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Technology to the Rescue

● HW – Write blockers

● SW – Write blockers

Page 9: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Write Blocker

● Write blockers prevent writing to the medium.● The medium can be read but not written to.● The modify, access, create dates cannot not be

changed.● The contents cannot be modified.

Page 10: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Example

● Floppies – write protect thingee.

Page 11: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

HW Write Blocker

● Paraben● Accommodates a number of hard drives● Comes with cables● Forensically certified● Standard with Law Enforcement● Necessary for on site image acquisition

Page 12: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

SW Imaging

● Unix – dd if=??? of=???● NIST certifies that it does not corrupt the original.● The original and the image are identical.

● EnCase● Has an imaging function.

● WinHex ● Create Disk Image ...● Verifiable exact copy.

Page 13: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Week 4 Lab

1. Using WinHex image your floppy. Describe procedure in your lab report.

2. Validate that the copy is exact using MD5 hash signatures. Show in your lab report.

3. Using the image you made describe some of the contents of the floppy – floppy image.

4. E-mail the floppy image to yourself so you can use it at home.

Page 14: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Select Start Center

Page 15: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Click open disk

Page 16: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Click OK

Page 17: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

CalculateMD5 Hash

Page 18: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.
Page 19: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.
Page 20: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Select Raw image

Select a Filename and pathRemember where you put the image.

Calculate the MD5 Hash

Click OK

Page 21: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Hash of the Image

Is it the same as the floppy disk?

Page 22: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Open raw image file

Page 23: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Find the image file

Page 24: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Open the image file

Claculate the MD5 hash ofthe file.

Is it the same?

Page 25: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

MD5 Hash of image file

Page 26: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.
Page 27: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Explorer the floppy image.What files are there?

Page 28: Preserving Evidence ● Number one priority ● Must also find incriminating evidence ● Must search the contents of the hard drive ● Can not change the hard.

Week 5 Lab

1. Create a case folder on your F_Drive.

2. Using WinHex image your floppy. Save the image in your case folder. Describe procedure in your lab report.

3. Validate that the copy is exact using MD5 hash signatures. Show in your lab report.

4. Using the image you made describe some of the contents of the floppy – floppy image.

5. Recover an image and save it your case folder.

6. Keep all of your homework in your case folder.


Recommended