1
1

00:00:00,330  -->  00:00:02,580
<v Narrator>Digital forensic analysts.</v>
2

2

00:00:02,580  -->  00:00:05,670
As a cybersecurity analyst, there is a variety of tasks
3

3

00:00:05,670  -->  00:00:07,080
that you're going to need to perform
4

4

00:00:07,080  -->  00:00:10,230
during and after an incident to ensure forensic analysts
5

5

00:00:10,230  -->  00:00:12,810
will be able to do their jobs effectively.
6

6

00:00:12,810  -->  00:00:14,820
One of the jobs that a cybersecurity analyst
7

7

00:00:14,820  -->  00:00:18,600
may graduate into is that of a forensic analyst as well.
8

8

00:00:18,600  -->  00:00:20,340
Now, you might be called upon to perform
9

9

00:00:20,340  -->  00:00:22,500
a variety of forensic activities as part
10

10

00:00:22,500  -->  00:00:24,660
of your incident analysis and threat hunting.
11

11

00:00:24,660  -->  00:00:26,850
And so in this lesson, we are going to focus
12

12

00:00:26,850  -->  00:00:29,430
on the role of a digital forensic analyst.
13

13

00:00:29,430  -->  00:00:31,470
Now, when we talk about digital forensics,
14

14

00:00:31,470  -->  00:00:32,790
we are talking about the process
15

15

00:00:32,790  -->  00:00:35,550
of gathering and submitting computer evidence to trial,
16

16

00:00:35,550  -->  00:00:37,290
and then interpreting that evidence
17

17

00:00:37,290  -->  00:00:39,240
by providing expert analysis.
18

18

00:00:39,240  -->  00:00:41,880
A forensic analyst has many different job titles,
19

19

00:00:41,880  -->  00:00:43,470
depending on where they work.
20

20

00:00:43,470  -->  00:00:46,230
You might hear them called a forensic computer examiner,
21

21

00:00:46,230  -->  00:00:47,910
or a digital forensic examiner,
22

22

00:00:47,910  -->  00:00:50,160
or a computer forensic detective.
23

23

00:00:50,160  -->  00:00:51,540
All of these are valid names,
24

24

00:00:51,540  -->  00:00:53,760
as well as many others you may come across.
25

25

00:00:53,760  -->  00:00:57,150
Now, what exactly does a forensic analyst do?
26

26

00:00:57,150  -->  00:01:00,120
Well, they're going to use specialized tools and skills
27

27

00:01:00,120  -->  00:01:02,670
to recover information from computer systems
28

28

00:01:02,670  -->  00:01:04,710
from memory and from storage.
29

29

00:01:04,710  -->  00:01:06,840
Now, the reason they have to do this is because
30

30

00:01:06,840  -->  00:01:09,390
unlike evidence that you could see with the naked eye,
31

31

00:01:09,390  -->  00:01:11,970
all of this digital stuff can't be seen,
32

32

00:01:11,970  -->  00:01:13,830
and so you have to be able to collect it
33

33

00:01:13,830  -->  00:01:16,410
and then analyze it and produce that as a report
34

34

00:01:16,410  -->  00:01:18,300
that can then be used in court.
35

35

00:01:18,300  -->  00:01:20,190
Because if I just give you a hard drive,
36

36

00:01:20,190  -->  00:01:21,510
that doesn't tell you anything,
37

37

00:01:21,510  -->  00:01:24,180
it's what's inside the hard drive that's really important.
38

38

00:01:24,180  -->  00:01:27,090
We use forensics, and digital forensics specifically,
39

39

00:01:27,090  -->  00:01:28,980
to be able to pull out the information we need
40

40

00:01:28,980  -->  00:01:31,650
from that hard drive and present it in court.
41

41

00:01:31,650  -->  00:01:34,170
Now, one of the things that a forensic examiner may do
42

42

00:01:34,170  -->  00:01:36,660
is they may serve as an expert witness.
43

43

00:01:36,660  -->  00:01:39,120
Now, this is again because that information
44

44

00:01:39,120  -->  00:01:41,100
has to be extracted from the hard drive.
45

45

00:01:41,100  -->  00:01:42,960
It needs to be extracted from memory.
46

46

00:01:42,960  -->  00:01:45,540
It has to be extracted from the network or from the system.
47

47

00:01:45,540  -->  00:01:48,150
And based on that, your expert analysis
48

48

00:01:48,150  -->  00:01:50,940
of what you found and the process you used
49

49

00:01:50,940  -->  00:01:52,890
is going to be called upon in court
50

50

00:01:52,890  -->  00:01:54,600
if you're dealing with a criminal case.
51

51

00:01:54,600  -->  00:01:57,150
For example, I once served as an expert witness
52

52

00:01:57,150  -->  00:01:58,860
for one of these cases.
53

53

00:01:58,860  -->  00:02:01,200
There was a case where somebody was suing a hotel,
54

54

00:02:01,200  -->  00:02:03,810
saying that they hurt themself on the property.
55

55

00:02:03,810  -->  00:02:06,330
Now, they made a claim of how badly they were hurt
56

56

00:02:06,330  -->  00:02:08,160
and were trying to get a very big payout
57

57

00:02:08,160  -->  00:02:10,770
from this insurance company for the hotel.
58

58

00:02:10,770  -->  00:02:14,220
But we found video evidence showing that this person
59

59

00:02:14,220  -->  00:02:17,820
wasn't actually hurt, and I used my technical skills,
60

60

00:02:17,820  -->  00:02:20,220
as an analyst, to be able to get the information
61

61

00:02:20,220  -->  00:02:22,650
from the video, perform the analysis,
62

62

00:02:22,650  -->  00:02:25,560
and provide that as a written report to the court.
63

63

00:02:25,560  -->  00:02:27,720
Based on that, they were able to use that evidence
64

64

00:02:27,720  -->  00:02:29,310
with other evidence and be able to get
65

65

00:02:29,310  -->  00:02:30,930
the verdict they were looking for.
66

66

00:02:30,930  -->  00:02:32,310
If you are a forensic analyst,
67

67

00:02:32,310  -->  00:02:35,160
you may be asked to fill a lot of different roles.
68

68

00:02:35,160  -->  00:02:37,380
For example, you may be asked to help plan
69

69

00:02:37,380  -->  00:02:39,180
IT systems and processes.
70

70

00:02:39,180  -->  00:02:41,850
This way, we know that those systems and processes
71

71

00:02:41,850  -->  00:02:44,640
are set up ahead of time to be able to collect evidence
72

72

00:02:44,640  -->  00:02:47,160
if needed during a cybersecurity incident.
73

73

00:02:47,160  -->  00:02:49,740
Additionally, an analyst may be asked to help investigate
74

74

00:02:49,740  -->  00:02:51,480
or reconstruct an incident.
75

75

00:02:51,480  -->  00:02:53,100
Something bad happened to your network
76

76

00:02:53,100  -->  00:02:54,840
and they want to figure out what happened.
77

77

00:02:54,840  -->  00:02:56,940
Well, an analyst has that detective skill
78

78

00:02:56,940  -->  00:02:58,380
in the technical domain to help
79

79

00:02:58,380  -->  00:03:00,540
piece those things back together.
80

80

00:03:00,540  -->  00:03:01,860
Another thing you might be asked to do
81

81

00:03:01,860  -->  00:03:04,320
is to help investigate if a crime has occurred.
82

82

00:03:04,320  -->  00:03:05,400
By going through the systems,
83

83

00:03:05,400  -->  00:03:07,890
you can determine if something bad really happened
84

84

00:03:07,890  -->  00:03:09,810
and if that thing was a crime.
85

85

00:03:09,810  -->  00:03:11,850
For example, if you work for the police,
86

86

00:03:11,850  -->  00:03:14,070
you might be called in and search a computer
87

87

00:03:14,070  -->  00:03:16,200
to see if there's evidence of child pornography,
88

88

00:03:16,200  -->  00:03:17,700
because that would be a crime.
89

89

00:03:17,700  -->  00:03:20,070
You'd be able to determine if you found that evidence,
90

90

00:03:20,070  -->  00:03:22,350
and if so, that means a crime has been committed
91

91

00:03:22,350  -->  00:03:24,090
and that person's going to go to jail.
92

92

00:03:24,090  -->  00:03:25,530
Another thing an analyst might help do
93

93

00:03:25,530  -->  00:03:27,630
is to collect and protect evidence.
94

94

00:03:27,630  -->  00:03:28,980
As you're going through these systems
95

95

00:03:28,980  -->  00:03:31,380
and collecting information, you need to also make sure
96

96

00:03:31,380  -->  00:03:34,410
you're validating the information as it's being collected,
97

97

00:03:34,410  -->  00:03:36,750
and protect it to make sure it doesn't get changed
98

98

00:03:36,750  -->  00:03:38,100
after you've collected it.
99

99

00:03:38,100  -->  00:03:40,530
All of this is important to an analyst.
100

100

00:03:40,530  -->  00:03:41,970
Another thing an analyst might help do
101

101

00:03:41,970  -->  00:03:44,370
is to determine if data was exposed.
102

102

00:03:44,370  -->  00:03:45,720
So maybe you want to know,
103

103

00:03:45,720  -->  00:03:48,090
has your company been the victim of a data breach?
104

104

00:03:48,090  -->  00:03:50,610
You suspect you might have been, but you're not sure.
105

105

00:03:50,610  -->  00:03:52,170
Well, if you call in a forensic analyst,
106

106

00:03:52,170  -->  00:03:53,340
they can go through your systems
107

107

00:03:53,340  -->  00:03:55,680
and determine if your database was accessed
108

108

00:03:55,680  -->  00:03:57,720
and if those files were extracted.
109

109

00:03:57,720  -->  00:03:58,770
That's something that can help you
110

110

00:03:58,770  -->  00:04:00,810
figure out if the data was exposed.
111

111

00:04:00,810  -->  00:04:02,490
Or you might work for a forensic tool company
112

112

00:04:02,490  -->  00:04:05,070
and you have to develop tools and processes for those.
113

113

00:04:05,070  -->  00:04:07,410
All of that can be done by a forensic analyst,
114

114

00:04:07,410  -->  00:04:08,370
and they'll help out with those
115

115

00:04:08,370  -->  00:04:10,560
to make sure they're meeting the industry's needs.
116

116

00:04:10,560  -->  00:04:12,930
And finally, a forensic analyst might be called on
117

117

00:04:12,930  -->  00:04:14,700
to support ongoing audits.
118

118

00:04:14,700  -->  00:04:16,110
Now, this is because audits
119

119

00:04:16,110  -->  00:04:18,270
are essentially evidence collection as well,
120

120

00:04:18,270  -->  00:04:20,280
and so you can go through the auditing process
121

121

00:04:20,280  -->  00:04:22,230
and help people go through the different processes
122

122

00:04:22,230  -->  00:04:23,850
and records, and make sure everything
123

123

00:04:23,850  -->  00:04:26,400
is being kept up to date and has not been tampered with.
124

124

00:04:26,400  -->  00:04:28,320
Having a forensic analyst help with audits
125

125

00:04:28,320  -->  00:04:30,120
is really important, especially if you're in
126

126

00:04:30,120  -->  00:04:31,650
a highly regulated field.
127

127

00:04:31,650  -->  00:04:35,130
For example, if you fall under Sarbanes-Oxley, or HIPAA,
128

128

00:04:35,130  -->  00:04:37,170
or something like that, and you're going to have regulators
129

129

00:04:37,170  -->  00:04:40,080
come and audit you, it does help to have a forensic analyst
130

130

00:04:40,080  -->  00:04:42,330
on staff who can help them go through your information
131

131

00:04:42,330  -->  00:04:45,120
and verify that everything has maintained integrity
132

132

00:04:45,120  -->  00:04:46,670
and has not been tampered with.
