Digital Forensics
Evidence collection, analysis techniques, forensic tools, and legal considerations.
Overview
Digital forensics investigates cyber incidents for evidence.
Forensic Process
Architecture Diagram
1. Identification ā Locate evidence
2. Preservation ā Secure evidence
3. Collection ā Gather evidence
4. Examination ā Analyze evidence
5. Analysis ā Interpret findings
6. Reporting ā Document results
Evidence Types
| Type | Source | volatility |
|---|---|---|
| RAM | Memory | High |
| Registry | Windows | Medium |
| Logs | Systems | Medium |
| Disk | Storage | Low |
| Network | Traffic | Medium |
Forensic Tools
| Tool | Purpose |
|---|---|
| Autopsy | Disk analysis |
| Volatility | Memory analysis |
| FTK | Forensic toolkit |
| EnCase | Forensic suite |
| Sleuth Kit | File system analysis |
Memory Analysis
# Volatility analysis
import volatility.conf as conf
import volatility.commands as commands
# List processes
volatility -f memory.dmp --profile=Win7SP1x64 pslist
# Extract network connections
volatility -f memory.dmp --profile=Win7SP1x64 netscan
# Dump process
volatility -f memory.dmp --profile=Win7SP1x64 procdump -p 1234
Disk Forensics
# Create forensic image
dd if=/dev/sda of=/evidence/disk.img bs=4M
# Calculate hash
md5sum /evidence/disk.img
sha256sum /evidence/disk.img
# Mount image
mount -o loop,ro /evidence/disk.img /mnt/evidence
# Search for files
find /mnt/evidence -name "*.doc" -o -name "*.pdf"
Chain of Custody
Architecture Diagram
Evidence Log:
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā Evidence ID: E-2024-001 ā
ā Description: Hard drive from suspect PC ā
ā Collected: 2024-01-15 14:30 ā
ā Collected by: John Smith ā
ā Location: Office 101 ā
ā Condition: Sealed in anti-static bag ā
ā Hash (MD5): abc123... ā
ā Hash (SHA256): def456... ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
Legal Considerations
- Authorization ā Proper warrants
- Chain of Custody ā Evidence tracking
- Documentation ā Detailed logs
- Expert Testimony ā Court presentation
- Privacy Laws ā Data protection
Practice
Analyze a forensic image using Autopsy and document findings.