1
1

00:00:00,090  -->  00:00:02,640
<v ->In this section of the course, we're going to play detective</v>
2

2

00:00:02,640  -->  00:00:05,160
and start our coverage of digital forensics.
3

3

00:00:05,160  -->  00:00:06,840
Now, this is an area that I really love
4

4

00:00:06,840  -->  00:00:09,540
inside the cybersecurity world, having spent several years
5

5

00:00:09,540  -->  00:00:11,010
as a digital media collector
6

6

00:00:11,010  -->  00:00:13,200
and digital forensic examiner myself.
7

7

00:00:13,200  -->  00:00:14,670
Now, in this section of the course
8

8

00:00:14,670  -->  00:00:17,460
we're going to be focused on domain one, security operations
9

9

00:00:17,460  -->  00:00:20,010
and domain three, instant response management
10

10

00:00:20,010  -->  00:00:23,670
with a focus on objectives 1.3 and 3.2.
11

11

00:00:23,670  -->  00:00:26,460
Objective 1.3 states that given a scenario,
12

12

00:00:26,460  -->  00:00:28,350
you must be able to use appropriate tools
13

13

00:00:28,350  -->  00:00:31,080
or techniques to determine malicious activity.
14

14

00:00:31,080  -->  00:00:33,270
In our case, we are specifically going to be looking
15

15

00:00:33,270  -->  00:00:36,030
at file analysis inside digital forensics
16

16

00:00:36,030  -->  00:00:38,340
and our use of hashing to verify the integrity
17

17

00:00:38,340  -->  00:00:40,320
of our evidence along with using hashes
18

18

00:00:40,320  -->  00:00:43,260
as an indicator or compromise on a given system.
19

19

00:00:43,260  -->  00:00:45,930
Objective 3.2 states that given a scenario,
20

20

00:00:45,930  -->  00:00:48,840
you must be able to perform instant response activities.
21

21

00:00:48,840  -->  00:00:51,210
Here, we're really going to be focused on the detection
22

22

00:00:51,210  -->  00:00:53,640
and analysis phase, including the determination
23

23

00:00:53,640  -->  00:00:56,250
of indicators or compromise, collection of evidence
24

24

00:00:56,250  -->  00:00:57,690
and the concepts surrounding the chain
25

25

00:00:57,690  -->  00:00:59,670
of custody of that evidence.
26

26

00:00:59,670  -->  00:01:01,860
As we begin this section, it's going to be important
27

27

00:01:01,860  -->  00:01:03,570
to realize that we're going to be focused on
28

28

00:01:03,570  -->  00:01:04,650
digital forensic techniques
29

29

00:01:04,650  -->  00:01:07,890
for workstations, desktops, laptops, and servers
30

30

00:01:07,890  -->  00:01:09,510
in this section of the course.
31

31

00:01:09,510  -->  00:01:11,910
Now, in a later section of the course, we're going to return
32

32

00:01:11,910  -->  00:01:14,190
to forensics and look at how they're used specifically
33

33

00:01:14,190  -->  00:01:17,880
for virtualized systems, mobile devices, and the cloud too.
34

34

00:01:17,880  -->  00:01:19,800
As we move through this section of the course though,
35

35

00:01:19,800  -->  00:01:21,120
we're going to be starting out with a look
36

36

00:01:21,120  -->  00:01:23,100
at the role of a digital forensic analyst
37

37

00:01:23,100  -->  00:01:25,050
inside of the cybersecurity field.
38

38

00:01:25,050  -->  00:01:26,850
Then we're going to be discussing the different
39

39

00:01:26,850  -->  00:01:28,290
forensic procedures that are used
40

40

00:01:28,290  -->  00:01:31,230
by the cybersecurity analyst in their daily jobs.
41

41

00:01:31,230  -->  00:01:33,210
Next, we're going to take a look at the concepts
42

42

00:01:33,210  -->  00:01:35,820
of work product retention, which is basically saying
43

43

00:01:35,820  -->  00:01:37,740
how long are we going to keep that evidence
44

44

00:01:37,740  -->  00:01:40,590
and what kind of evidence are we going to keep.
45

45

00:01:40,590  -->  00:01:43,470
After that, we're going to be moving into data acquisition
46

46

00:01:43,470  -->  00:01:45,930
for later forensic analysis, and we'll be describing some
47

47

00:01:45,930  -->  00:01:47,970
of the most common forensic tools that are used
48

48

00:01:47,970  -->  00:01:49,770
by analysts out in the field.
49

49

00:01:49,770  -->  00:01:52,470
Then we're going to be discussing how system memory images
50

50

00:01:52,470  -->  00:01:54,420
and disc images are going to be acquired
51

51

00:01:54,420  -->  00:01:56,580
by those forensic analysts out in the field
52

52

00:01:56,580  -->  00:01:58,710
because there are different procedures used for each
53

53

00:01:58,710  -->  00:02:00,960
of these types of collections that we're going to do.
54

54

00:02:00,960  -->  00:02:03,510
Next, we're going to discuss how we maintain the integrity
55

55

00:02:03,510  -->  00:02:05,310
of the evidence that's being collected
56

56

00:02:05,310  -->  00:02:08,130
by using hashing of forensic images that have been acquired
57

57

00:02:08,130  -->  00:02:09,870
by those forensic analysts.
58

58

00:02:09,870  -->  00:02:11,970
After that, we're going to need to discuss how
59

59

00:02:11,970  -->  00:02:14,820
we can generate a timeline in order for us to analyze data
60

60

00:02:14,820  -->  00:02:17,700
across all the forensic evidence that we've been acquiring
61

61

00:02:17,700  -->  00:02:18,960
from all of our different devices
62

62

00:02:18,960  -->  00:02:22,110
and systems and networks during our forensic collection.
63

63

00:02:22,110  -->  00:02:25,170
Sometimes though this evidence isn't collected cleanly.
64

64

00:02:25,170  -->  00:02:27,690
For example, a criminal may be trying to delete files
65

65

00:02:27,690  -->  00:02:29,610
or scramble the contents of their hard drive
66

66

00:02:29,610  -->  00:02:31,290
in order to hide those contents
67

67

00:02:31,290  -->  00:02:33,720
from an analyst who's looking at that hard drive.
68

68

00:02:33,720  -->  00:02:35,130
But that's okay
69

69

00:02:35,130  -->  00:02:37,620
because we have ways to uncover that data too.
70

70

00:02:37,620  -->  00:02:39,690
And we're also going to be covering how an analyst
71

71

00:02:39,690  -->  00:02:42,680
can overcome this issue by using things like data carving,
72

72

00:02:42,680  -->  00:02:45,300
be able to recover these thought to be deleted files
73

73

00:02:45,300  -->  00:02:48,210
from a given hard drive and bring them back to life.
74

74

00:02:48,210  -->  00:02:50,580
Then we're going to be discussing the legal concept
75

75

00:02:50,580  -->  00:02:52,140
known as a chain of custody
76

76

00:02:52,140  -->  00:02:54,270
and I'm going to demonstrate how an analyst can collect
77

77

00:02:54,270  -->  00:02:55,830
and validate digital evidence
78

78

00:02:55,830  -->  00:02:58,620
in a step-by-step video demonstration for you.
79

79

00:02:58,620  -->  00:03:00,360
And finally, we're going to take a short quiz
80

80

00:03:00,360  -->  00:03:02,520
to see what you learned during this section of the course
81

81

00:03:02,520  -->  00:03:04,620
and review each of those quiz questions fully
82

82

00:03:04,620  -->  00:03:05,580
to ensure you can explain
83

83

00:03:05,580  -->  00:03:07,500
why the right answers were correct.
84

84

00:03:07,500  -->  00:03:09,120
So let's jump into the world
85

85

00:03:09,120  -->  00:03:11,670
of digital forensics in this section of the course.
