Basic Digital Forensics
Basic Digital Forensics
FORENSICS
1
2
Forensic
DNA F
Digital Forensics ၂ ။
Electronic Device
. Elec
.Electronic PC LaptopTablet
IOT Device
။)
၂ ။
2
3
....
....
....
3
4
၇ Heal
1822-1911
1847-1915
1858-1946
1887-1954
1891-1955
1932
4
5
1993
1995
1998The Internatio
2000
Case
vi
5
6
( ...
၁ A++
၂ Operationsystem(window,linux,MAC,etc..)
၃ BasicNetworking
၄ RoutingandSwitching
၄ ProgrammingBasic
၅ Server/Vmware/Bigdata -Virus
၆ Webapplication
၇ SocialNetwork(Facbook,twitter,linkedlin,etc....)
၈ Mobilephone..Tablet(software,hardware)
၉ wirelessDevice..
- I orensics C
- ။
- ။
6
7
....
device ။ ။
.. dumps
7
8
၇ ၇
8
9
၇ ၇
....
။ wri
Original ima ၇ ၇
write
၇ ၇
9
10
foren
:)
10
11
၇ ၇ ၇
evidence
tracking softwar
၁။
၂။
၃။
၄။
၅။
၆။
၇။
Anti-DigitalForensics
11
12
device
- ........
VolatileData
history,
12
13
....
Non-VolatileData Data)
TransientData Data)
websi
FragileData Data)
TemporarilyAccessData
ActiveData
ArchivalData
BackupData
( ) ...
13
14
Collection Evidence
st
Example
server log, event logs , system file , swap file, printer pools
ev
14
15
Electronic
...
- (eg..database,excel,paper),-
tar,....
Id
Writer
CreditcardGenerator
15
16
excel,world,database)
Imagefile
Email,Note,Letterbrowser,chatrecord,
excel,world,database)
Imagefile
Email,Note,Letterbrowser,chatrecord,
SimcardClone(hardware)
userdatabase ElectronicSerialnumber(ESI)
MobileidentificationNumber(MIN)
Browser,socialNetworkRecord
Steganography
16
17
DVD/
။Eg..... bitstream
17
18
(10111111) (10111110)
(10111110) (10111111)
- ။
E-mail Forensics
(Cyber Stalking)
(Fraud Mail)
phishing)
(Ema
-----
18
19
- (Bank Securit
(www.google.com www.gooogle.com
၇ email serve
gmail.com=>yahoo.com
(S (listeningport)
25
SMTP Serv
yahoo.com
19
20
E-MailHeader
(IPaddres
။ ။
။ KBZ ba
20
21
Heade
။ ။
Memory forensics
။ ။
21
22
။ ။
။ Pos
၁ ။
၂ ။ ၇
22
23
၄ ။
၅ ။
၆ ။
၇ ။
23
24
24
25
stab
Application
25
26
User Information
System Information
Network Information
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_CURRENT_CONFIG
=========================
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
။ ။
26
27
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_CURRENT_CONFIG
======================
၅ ။
Software
System
SAM
Security
Default
================
Software
System
SAM
Security
27
28
Default
===============
1.REG_BINARY
Raw Binary
2.REG_DWORD
------------------------
Device Dri
3.REG_EXPAND_SZ
----------------------------
4.REG_MULTI_SZ
--------------------------
28
29
5.REG_SZ
-----------------
6.REG_FULL_RESOCE_DESCRIPTOR
------------------------------------------------------
29
30
Login Time
Account Level
Browser activities
Windows\System32\Config
---------------------------
HKEY_USERS.DEFAULT : \system32\config\default
================================
30
31
Passwo
။ Pa
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
========
31
32
Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\NetworkCards
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USB\
HKEY_LOCAL_MACHINESYSTEM\CurrentControlSet\Enum\USBSTOR\
HKEY_LOCAL_MACHINE\SYSTEM|MountedDevices
=====
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\Explorer\RunMR
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current
32
33
Registry
.။ Window Forensics
။ Forensics
Law Enforcement
...
..
window registry
။ (Key point
Forensics Tools .
..
Investigator Knowledge )
....
33
34
...
inch ။platter
။ 01 ။
Hard disk 6
34
35
platter
။ Platter ။
======================
Spindle ။
၇ 5,400 rpm
10,000 RPM ။
======================
Head Platter
0.5 microinches ။ hd
data ။
======================
Actulator
======================
Actulator Arm
Head ။
35
36
.. ။ ။
======================
======================
track
track ။
k data ။
======================
Cylinder
head
track number
။ cylinder
access
track ။
======================
36
37
Sector
Sector
။ sector ၄
data
Gaps: data
======================
Cluster
။ ။
======================
volume
37
38
38
39
Sector
Bad sector
( )
platter sector ။
/ power Off
sector ။arm
head Track
====================================
Slack Space
39
40
။ ။
။ cluster ။
choice ။
====================================
HD firmware
HD firmware HD software
40
41
HD firmware ။ HD power on
PCB microcode ။
firmware
Boot Loader , Boot Sector , Master Boot Record (MBR) & Window System Boot Process
41
42
Operation System ။
Track Sector ။
bootstrapping system ။
===============================
Boot Sector ၂ ။
။ loading ။
===============================
။ VBR partition ။
(multi boot)
42
43
===============================
===============================
===============================
setup parameters) ။
43
44
6. POST CPU ။
install device OS
9. OS The BIOS OS
OS
Control ။
Run Run ။
===============================
44
45
file
Delete
) ( Recycle bin
Restore )။
Shift+Delete
45
46
။ Hard disk
=====================================
file ၂ ။
၂. Cluster Bitmap.
Cluster ။
46
47
Cluster
==========================================
==========================================
file ။
။ file ။
===============
Recovery ။
47
48
=======================================
RAID data
mirroring, parity, ။
Striping။
Block Size
။ Block
။ ။
Mirroring
48
49
Save ။ ။
Parity
Disk ။. Xor 0
Disk 1 = 1 0 1 0
Disk 2 = 1 1 0 0
Disk 3 = 0 0 1 1
------------------------------------------------
------------------------------------------------
Disk 1 = x x x x
Disk 2 = 1 1 0 0
Disk 3 = 0 0 1 1
49
50
------------------------------------------------
------------------------------------------------
Result
Disk 1 = ၁ ၁
Disk 2 = 1 1 0 0
Disk 3 = 0 0 1 1
------------------------------------------
============================================
=============================================
==============
- Raid 0 (Striping ) ။
50
51
HD
- ။
- ။
RAID 1 (Mirroring )
==============
- Raid 1 Mirroring ။
750 500 GB ။
- Read ။
- ။
====================
- Hard Disk 3 ။
51
52
- ။
- Read ။
=============================================
.။ ။
============================================
============================================
52
53
။ Or SATA ။
53
54
===============
Specific -------
Window 10 64 bit
RAM Size 16 GB
========================================
။ Raid0 window
။ (Network )
54
55
....Hard disk
Ok ...
======================
Recovery process ။
။ ။
:D ။
Clone ။
Hash ။ (Problem )(
55
56
။ ။ Window
..... :)
digital forensics
...။
scientific ။ Philosophy 2
Methods ။
။ forensics
။ ...
Crime Case Back Ground (NOTE: Base On CHFI&CCFP Note Not Real Wold Case)
======================================
56
57
။ ။
( (korea) :D)
A USB Stick 2
။A File usb ။ ။ C
Forensics Process ။
။ usb formant
....
... A
..
...
A File
... usb
...
.. Ok Let it Be ...
57
58
... ။ (
..... ( Hypothesis )
philosophy Verification
။ Falsifiability)
Peer view
===========
( Cyber Law )
============
58
59
" ။
Physical Investigation
Theory ။
Digital Evidence ။
Evidence Evidence
Skill ) ။
inman-Rudin Paradigm
...
Transfer
(Locard's principle) ။
Identification
Case Evidence
Individualization
Evidence ။ Case
59
60
Association
Reconstruction
Self-Encrypting
Drives (SED) ။
Forensics process
90 ။
60
61
PC Repair ။ Forensics
detail ။
HD ......... ?
User password :)
Feature )( Problem
61
62
Platter Data
... ( post )
Youtube ..
PLATTER head
SPINDLE RPM ..
...
...
===============
- HD Cover ..
- arm ...
62
63
.. .. )
head Spindle
..Platter
- ....
===================
- spindle .. Head
.. 50 ..
- Testing
- ...40%
- 60 % ...
- .
63
64
Hard Disk
Block ။
data input-out ၊
၊ data
။ Storage SSD
64
65
SSD ။
Controller
SSD Input-Output
Buffer Memory
Device ။ .....
SSD SATA ,SSD M2, SSD msata, SSD U2 , SSD Pcie , SSD sas ,
Garbage Collection
65
66
read-write Operation
Post )
User data
Block Erase ။
Garbage Collection ။ HD
SSD ။
Wear leveling
66
67
write ။
။ SSD ။ Trim on
။ Garbage Collection ။
...
67
68
။ SSD Write -
SSD - ။
OS file system
:)
။ . Process
Knowledge ။ EC
။ SSD
- SSD Boot ။
68
69
- Encryption ။
amount .
69
70
.. Forensics Detail
.. ..
...
E goverment
..Device ..
Forensics
...
Detail
..
..
....
.Electronic
..
70
71
user
Password Company
..
FORENSICS
. Flash Gate
checking
... EC
SSD ...
...HD PCB
71
72
PCB EC
Mobile Phone EC .. IT
Product ..
... :-)
.. ...
..
:-)
:-) :-)
power :-)
Warranty :-)
Switc ...
... :-)
72
73
EC Diode Capactor
... ...
..
...
။ CCTV
CCTV
Time ။
CCTV Record
။ CCTV
CCTV
73
74
Embedded DVRs
Hybrid DVR
Storage Media
TB)
.။
Connector Type
Camera Cable
(BNC Male to RCA Female Adaptor ,BNC Female to RCA Male Adapter,Female To
74
75
RG59 Coax Male BNC Twist On Connector Adapter,Female Jack Connector Adapter ,
etc...... )
type ။
။ CCTV Forensics
CCTV Video
။ compression
။ Compression Methods
။, - Video
rate ) transmit ။
Video bandwidth
====================
H.264
75
76
I-frame P-frame ။
P-Frame Frame
Save ။ Motion
save ။ Storage ။
File
=======================
။ Thanks
DVD ,Stick ။
76
77
Resolution
DVR, NVR
(DVR )( )
(DVR )
...
။ record
။ :)
Concept ။ Recovery
77
78
Demonstrative Comparison
Height Calculating
etc .... ။
။ IQ EQ AQ ။
example case
bamakhit
CCTV ။(Download :)
. Resolution
Hardware
1 Video file ။
410 ။
78
79
CCTV ။ ။ Motion
Sorry ။ ။
Raspberry Pi Forensics
Raspberry Pi IT EC
79
80
။ portable
. Pentest
memory Chip ။
How To Forensics
... ?
(What Happen ?)
80
81
Vmware Forensics
Operation System
Virtual System ။
Virtual Box
VMware
Window Virtual PC
Hyper -V
Oracle VM
Parallels
81
82
Docker ။
Vmware
nvram – Keeps ’
.Vmdk
.vmem
82
83
.vmem
Forensics ။ vmem
.log
။ ။
VMware
How to Forensics ?
Simulation ။
) Knowledge
Wireless Forensics
83
84
Wireless Device
Wireless
Wireless Router
။.
video, Photo ။
။ point to point ,
84
85
use => window tools (or) Kali wireless hacking tools or Other OS
How to Forensics ?
Post ။
85
86
Event Log
MS Server ။
incident Response ။
Event Log
User
Access ။ WS OS MS
MS Server 2008 ။
Case log ။
MS server subcategory ။
(subcategory)
86
87
Event log ။
.xml .cvs ။
C:\Windows\System32\winevt\Logs
။ MS Window , MS Server ။
87
88
Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog
Event Log
USB attachment ။
disable
investigator
save
Tools
88
89
။ Case
89
90
Second War TV
။ ။
။ ၊ ၊
၊ ၊
OSINT
90
91
… ။
Social Media
Selfie
Electronic Device ။
။ Second war
။ facebook,
91
92
Reuters Facebook
. Operation ။
online
Team Leader
။ Facebook Report ။
...
...
...
92
93
Crush
... ..
amazon
... Review
...
..OSINT
. ...
Vi ။
Cyber Security ။
( OSINT Counter
93
94
Station Stuxnet
။ Threat
။ Forensics
။PLC ။
Engineering ။ Routeable
Forensics ။
Security ။
94
95
။ Volatile
။ video record ။
။ Restore Plan
Forensics ။ Forensics
Forensics Process
Device Attack
Program bug
Attack
95
96
Forensics
။ Case
Expert Witness
။ .
Electronic Law IT
Electronic Law
။ Investigator
။ Law
96
97
၊ IT
။ Expert
Witness Lawer ။ ၊
Witness ။
၊ ၊ IT Certificate၊
Foreneics ။
Law Firm .
၊ IT Certificate၊
Technical Expert
investigator .
Example
) (Irrawady
English New ၊။
97
98
forensics Hardware ။
Case
IoT device
Iot device
Iot Device
98
99
…..
( )
( )
။ IoT device
save Device
။ ?
(LAB )
။ ။
IoT Device ။
Manual guide
99
100
Iot Device
Iot Forensic
100
101
what ? File
Where? File
Why ? file ႕
How ?
Who?
101
102
MCAB Time
W10 window 7
102
103
window 7 ။ vmware
103
104
Thirdeye.World file
Company company ။
company file
။ ။
။ clock
backdate ။
104
105
Back Da
Methodology ႕ Hypothesis I
nternet History ,User ,Create time, USB history, ႕ System window
time back ႕ ႕
105
106
Categories 5
106
107
(read) ။
107
108
and Save)
Metadata Forensics
Metadata (data)
။ Metadata file
, ။ Metadata
108
109
။ Metadata
save ။ edit
test1 file
save metadata ။
109
110
110
111
Metadata ။
111
112
http://exif.regex.info/exif.cgi
http://metapicz.com/#landing
https://www.get-metadata.com/
What
Where
Who
When
How
What
Cyber Crime Case
Where
or
or
Who
( )
When
How
112
113
Case
႕ ႕
႕
VSS ႕
႕ ႕ Example Encase
Volume Sha
113
114
Bit by Bit
႕
accessories
႕
La
႕ ႕
႕ ႕
႕ ႕
114
115
႕
႕
႕
႕
(Example)
Password
Elec
-----------------------------------------------------------
TRAIGE METHOD
႕ .
႕
☺ ´
Digi
႕ Special
႕
115
116
116
117
117
118
118
119
.Non
Border .
၃
( )
Computer
Computer
( Computer )
Computer
၂ ၆ Gordon Ford
Type 1
Type 2
႕
Eg.Online Gambling
119
120
( )
120
121
Chemical
-
-
- DNA/
- Mobile Device
- Lab ႕ ႕ (Eg. ) Label
- Lab ႕ ႕
OTG Stick/ Laptop/Desktop/ Paper pieces/USB Stick /Externa; Hard Disk / Sim Card / Etc .......
Device Information document
International Mobile Equipment Identity (IMEI),
Mobile Equipment Identifier (MEID),
Mobile Carrier
Mobile Phone Serial
Mobile Phone Condition (Good or Damage )
Pin Password Pattern
Etc ............
121
122
122
123
E -SIM Forensics
Information / Call Detail Record / IPDR / Location Operator
Manual Extraction
Mobile Device Mobile Device
App /
Telecom / Wireless AP document
႕
123
124
Logical Extraction
Mobile Device Memory Storage System data / user data
Back Up ႕ ႕ OS
Model Logical Extraction Recovery
Physical Extraction
Mobile Device Memory Storage Internal Memory /
External Memory Bit by Bit Copy
(Recovery )
Mobile phone Physical Extraction
JTAG ( Joint Test Action Group)
Mobile ph Mobile Ph
Chip Set / ႕ ႕
JTAG Connector ႕ Circuit Board
Memory Chip JTAG ႕ Wire ႕ TAP (Test Access
Port) ႕ ႕ Mobile Ph ႕ Processor Memory Chip
Command Full Memory Record Lock
႕ (JTAG ႕
adapter/ Reader/ software JTAG ႕ ႕ cpu memory
Chip OFF
JTAG ႕ Memory Chip Chip Set Reader Memory Chip
JATG
Android 6.0
Encryption
Micro Read
Memory Chip
Chip Gate Microscope ႕ Gate ႕
Binary HEx , HEX data ႕
124
125
125
126
SPN and SDN (Service Provider Name and Service Dialing Numbers) Telecom Operator
႕ Customer Care ph no ႕
Temporary Mobile Subscriber Identity(TMSI)
(TMSI) Cell Tower
႕ Cell
Tower IMSI
Phone Contact Sim Card : Abbreviated Dialing Numbers (ADN ) LND (Last
Numbers Dialed) Call Log Call
Log
Short Message Service (SMS)
(SMS) Si Card Sim Card
Sim Card ႕Dedicated Files (DF) Location Information (LOCI) the Location
Area Identifier (LAI) Mobile Country Code (MCC) Mobile Network Code (MNC) the Location
Area Code (LAC) Routing Area Code (RAC) the Routing Area Information (RAI) Location
Update Information ႕ MCC,MNC, LAC RAC RAI ႕ (Call Detail Record
)
126
127
CCTV
DVR
Video Forensics
႕ (Monitor Video
) (Resolution )
( DVR )
Compression Methods
=====================
CCTV Record
=====================
Laptop
127
128
USB Extension
CCTV Record
=====================
Camera Channel
Channel
(Physical CCTV )( CCTV
Record )
Documented
=====================
-DVR Location Address (ph No, Etc ... )
- DVR
-DVR model, and serial number
-DVR password & username(s)
128
129
- Camera Camera
- DVR
( DVR )
- DVR
-DVR Video
- DVR Hard Disk Storage
- Storage Over Write
( Over Write Eg- 7 day or 30 days )
(NVR ) (LAN/Wireless/DHCP )
DVR
========================
DVR
129