1
1

00:00:00,000  -->  00:00:02,040
<v Tutor>Forensics Procedures.</v>
2

2

00:00:02,040  -->  00:00:02,873
In this lesson,
3

3

00:00:02,873  -->  00:00:06,150
we are going to talk about the basic forensics procedures
4

4

00:00:06,150  -->  00:00:09,570
and this is essentially going to be a four-step process.
5

5

00:00:09,570  -->  00:00:11,610
Now, the first thing you need to know about forensics
6

6

00:00:11,610  -->  00:00:14,550
is everything we do we use written procedures.
7

7

00:00:14,550  -->  00:00:16,350
These written procedures are going to ensure
8

8

00:00:16,350  -->  00:00:19,380
that personnel handle forensics properly, effectively
9

9

00:00:19,380  -->  00:00:22,050
and in compliance with the required regulations.
10

10

00:00:22,050  -->  00:00:24,450
This way, we always follow what is written down
11

11

00:00:24,450  -->  00:00:26,160
and we always do it the same way.
12

12

00:00:26,160  -->  00:00:28,020
Now, as we go through our forensic procedures,
13

13

00:00:28,020  -->  00:00:30,000
there are four main areas.
14

14

00:00:30,000  -->  00:00:34,590
We have identification, collection, analysis and reporting.
15

15

00:00:34,590  -->  00:00:35,423
In this lesson,
16

16

00:00:35,423  -->  00:00:37,140
we're going to talk about each one of those.
17

17

00:00:37,140  -->  00:00:39,150
First, we're going to have identification.
18

18

00:00:39,150  -->  00:00:41,010
This is going to ensure the scene is safe.
19

19

00:00:41,010  -->  00:00:42,450
We have made sure we secure the scene
20

20

00:00:42,450  -->  00:00:44,340
to prevent any evidence contamination
21

21

00:00:44,340  -->  00:00:47,400
and we identify the scope of the evidence to be collected.
22

22

00:00:47,400  -->  00:00:48,840
Now, when you think about this,
23

23

00:00:48,840  -->  00:00:50,640
especially in the digital forensics world,
24

24

00:00:50,640  -->  00:00:51,630
I like to think about it
25

25

00:00:51,630  -->  00:00:53,790
as if you're working for the police department,
26

26

00:00:53,790  -->  00:00:56,340
they break down the door, they arrest the person
27

27

00:00:56,340  -->  00:00:57,630
and what do you need to do?
28

28

00:00:57,630  -->  00:00:58,830
Well, as you walk in the door,
29

29

00:00:58,830  -->  00:00:59,730
the first thing you need to do
30

30

00:00:59,730  -->  00:01:01,200
is make sure the scene is safe.
31

31

00:01:01,200  -->  00:01:02,820
There's not a bad guy hiding in the other room
32

32

00:01:02,820  -->  00:01:04,380
that's going to come out and hurt you
33

33

00:01:04,380  -->  00:01:06,480
and try to stop you from collecting the evidence.
34

34

00:01:06,480  -->  00:01:08,640
We want to make sure everything is safe there.
35

35

00:01:08,640  -->  00:01:10,440
Then once we know everything is safe,
36

36

00:01:10,440  -->  00:01:11,670
we move on to the next step,
37

37

00:01:11,670  -->  00:01:14,580
which is making sure nobody contaminates our evidence.
38

38

00:01:14,580  -->  00:01:17,160
We want to record the scene using video and photography
39

39

00:01:17,160  -->  00:01:19,410
to make sure we know exactly what was there,
40

40

00:01:19,410  -->  00:01:21,120
before we touched anything
41

41

00:01:21,120  -->  00:01:22,710
and then we want to start identifying
42

42

00:01:22,710  -->  00:01:24,840
the scope of the evidence to be collected.
43

43

00:01:24,840  -->  00:01:27,660
If I go into a store as part of this investigation
44

44

00:01:27,660  -->  00:01:28,493
and they say,
45

45

00:01:28,493  -->  00:01:31,110
"Hey, we're looking for this type of data,"
46

46

00:01:31,110  -->  00:01:32,010
well, I need to start looking
47

47

00:01:32,010  -->  00:01:33,450
at all the computer systems around there
48

48

00:01:33,450  -->  00:01:36,510
and say where can this type of data be hidden?
49

49

00:01:36,510  -->  00:01:37,770
Is it going to be on a tablet?
50

50

00:01:37,770  -->  00:01:38,880
Is it going to be on a phone?
51

51

00:01:38,880  -->  00:01:40,770
Is it going to be on a smart TV?
52

52

00:01:40,770  -->  00:01:42,300
Is it going to be on a server?
53

53

00:01:42,300  -->  00:01:44,010
And based on the type of data I'm looking for,
54

54

00:01:44,010  -->  00:01:45,900
I'm going to scope my evidence collection,
55

55

00:01:45,900  -->  00:01:47,850
because a lot of times your warrant,
56

56

00:01:47,850  -->  00:01:49,620
will tell you exactly how large
57

57

00:01:49,620  -->  00:01:51,270
or how small the scope you have
58

58

00:01:51,270  -->  00:01:52,680
and what you're allowed to collect.
59

59

00:01:52,680  -->  00:01:54,600
And then we're going to move into collection.
60

60

00:01:54,600  -->  00:01:55,800
Now, when we do collection,
61

61

00:01:55,800  -->  00:01:57,480
we have to ensure that we have authorization
62

62

00:01:57,480  -->  00:01:58,890
to collect the evidence.
63

63

00:01:58,890  -->  00:02:01,440
Now, this might take the form of something like a warrant
64

64

00:02:01,440  -->  00:02:02,970
and then we're going to document
65

65

00:02:02,970  -->  00:02:06,090
and prove the integrity of the evidence as it's collected.
66

66

00:02:06,090  -->  00:02:07,110
Now, what this means is
67

67

00:02:07,110  -->  00:02:09,810
as I start collecting the information from the computer,
68

68

00:02:09,810  -->  00:02:11,190
I'm not just going to take the hard drive
69

69

00:02:11,190  -->  00:02:12,270
and throw it in a bag.
70

70

00:02:12,270  -->  00:02:15,240
I need to actually do a bit by bit copy of that hard drive,
71

71

00:02:15,240  -->  00:02:16,650
because all my analysis later on
72

72

00:02:16,650  -->  00:02:19,380
is going to be done on the copy, not on the original.
73

73

00:02:19,380  -->  00:02:20,250
Now, I also need to make sure
74

74

00:02:20,250  -->  00:02:22,140
that that hard drive is an exact match,
75

75

00:02:22,140  -->  00:02:23,850
once I make the copy of it
76

76

00:02:23,850  -->  00:02:25,290
and I am going to take into evidence
77

77

00:02:25,290  -->  00:02:27,000
to make sure that I have the original,
78

78

00:02:27,000  -->  00:02:28,620
so that if we ever need to go back to the original
79

79

00:02:28,620  -->  00:02:31,530
for analysis and make another copy, we could.
80

80

00:02:31,530  -->  00:02:32,820
We also want to make sure we prove the integrity
81

81

00:02:32,820  -->  00:02:34,444
to make sure I haven't changed any data on it
82

82

00:02:34,444  -->  00:02:37,080
and nobody else has changed anything on it.
83

83

00:02:37,080  -->  00:02:38,940
That's the idea here With collection.
84

84

00:02:38,940  -->  00:02:40,380
Then we move into analysis.
85

85

00:02:40,380  -->  00:02:41,820
So, now that we have a copy,
86

86

00:02:41,820  -->  00:02:43,890
we are going to create a copy of this evidence
87

87

00:02:43,890  -->  00:02:45,360
and we're going to take that for analysis.
88

88

00:02:45,360  -->  00:02:48,960
And we use repeatable methods and tools during the analysis.
89

89

00:02:48,960  -->  00:02:51,570
Again, everything here is going to be written down.
90

90

00:02:51,570  -->  00:02:54,660
We are going to use procedures that tell us exactly what to do.
91

91

00:02:54,660  -->  00:02:57,030
This is going to say, step one, do this,
92

92

00:02:57,030  -->  00:02:58,080
make a copy of the drive.
93

93

00:02:58,080  -->  00:03:00,090
Step two, create a hash of the drive
94

94

00:03:00,090  -->  00:03:01,440
to make sure you have integrity.
95

95

00:03:01,440  -->  00:03:04,110
Step three, form an analysis on the drive,
96

96

00:03:04,110  -->  00:03:05,760
using X, Y, Z tool.
97

97

00:03:05,760  -->  00:03:07,350
It'll tell you exactly what you need to do
98

98

00:03:07,350  -->  00:03:10,260
as an analyst using a checklist that can be repeatable
99

99

00:03:10,260  -->  00:03:11,880
and followed each and every time.
100

100

00:03:11,880  -->  00:03:14,160
And then we got step four, which is reporting.
101

101

00:03:14,160  -->  00:03:15,900
At the end of all of our analysis,
102

102

00:03:15,900  -->  00:03:18,330
we need to create a report of the methods and the tools
103

103

00:03:18,330  -->  00:03:20,040
that we used in our investigation.
104

104

00:03:20,040  -->  00:03:22,410
And then we also need to present detailed findings
105

105

00:03:22,410  -->  00:03:24,810
and conclusions based on that analysis.
106

106

00:03:24,810  -->  00:03:27,630
If I was looking for child pornography on this hard drive
107

107

00:03:27,630  -->  00:03:28,950
of the victim's computer,
108

108

00:03:28,950  -->  00:03:30,390
I need to say I found it,
109

109

00:03:30,390  -->  00:03:32,490
it was located here, and here's how I prove it.
110

110

00:03:32,490  -->  00:03:34,860
All the things I did, how I found it,
111

111

00:03:34,860  -->  00:03:37,740
all the locations, all the files, screenshots of it,
112

112

00:03:37,740  -->  00:03:38,880
all that kind of stuff
113

113

00:03:38,880  -->  00:03:41,190
to put into the final report to give to the judge
114

114

00:03:41,190  -->  00:03:43,890
and into the court so that person can go to trial.
115

115

00:03:43,890  -->  00:03:45,900
Again, as I said in the last lesson,
116

116

00:03:45,900  -->  00:03:48,960
you may be called to go into court to testify,
117

117

00:03:48,960  -->  00:03:50,610
based on what you have
118

118

00:03:50,610  -->  00:03:52,200
and based on your report that you're going to give
119

119

00:03:52,200  -->  00:03:53,490
and the analysis you've done.
120

120

00:03:53,490  -->  00:03:55,050
Now, this is really important to realize,
121

121

00:03:55,050  -->  00:03:57,990
because everything you do is going to come under question,
122

122

00:03:57,990  -->  00:03:59,670
once you get on that stand.
123

123

00:03:59,670  -->  00:04:01,500
They're going to ask every method you've used,
124

124

00:04:01,500  -->  00:04:03,540
any mistakes you possibly could have made.
125

125

00:04:03,540  -->  00:04:04,710
They're going to try to find fault
126

126

00:04:04,710  -->  00:04:06,690
with everything you could have done,
127

127

00:04:06,690  -->  00:04:09,390
because if they can find fault with anything you've done
128

128

00:04:09,390  -->  00:04:11,970
your evidence and everything you found from it,
129

129

00:04:11,970  -->  00:04:13,380
can be thrown out of court
130

130

00:04:13,380  -->  00:04:14,769
and that can get their client off.
131

131

00:04:14,769  -->  00:04:16,650
Attorneys are paid a lot of money
132

132

00:04:16,650  -->  00:04:19,350
to help get their clients off of these criminal charges.
133

133

00:04:19,350  -->  00:04:21,030
And so if you're working in the criminal sector
134

134

00:04:21,030  -->  00:04:22,380
as a forensic analyst,
135

135

00:04:22,380  -->  00:04:25,590
you need to be very careful to do everything exactly right
136

136

00:04:25,590  -->  00:04:26,850
by the procedures.
137

137

00:04:26,850  -->  00:04:29,490
This is going to bring us to the concept of a legal hold.
138

138

00:04:29,490  -->  00:04:31,230
Now, a legal hold is a process
139

139

00:04:31,230  -->  00:04:34,020
that's designed to preserve all the relevant information
140

140

00:04:34,020  -->  00:04:36,960
when litigation is reasonably expected to occur.
141

141

00:04:36,960  -->  00:04:40,530
Now, litigation is just a fancy word for lawsuit.
142

142

00:04:40,530  -->  00:04:41,363
Essentially,
143

143

00:04:41,363  -->  00:04:43,050
if we think what we are going to be dealing with
144

144

00:04:43,050  -->  00:04:45,690
and collecting could end up in court one day,
145

145

00:04:45,690  -->  00:04:48,060
we need to make sure we don't destroy any evidence.
146

146

00:04:48,060  -->  00:04:50,250
We need to collect it all and preserve it all.
147

147

00:04:50,250  -->  00:04:52,380
Now, one of the biggest challenges when you start dealing
148

148

00:04:52,380  -->  00:04:55,020
with this is that you can actually have your computer
149

149

00:04:55,020  -->  00:04:57,240
or server seized as evidence,
150

150

00:04:57,240  -->  00:04:59,280
inside of some kind of criminal conspiracy.
151

151

00:04:59,280  -->  00:05:01,200
Let's say you ran a web hosting company
152

152

00:05:01,200  -->  00:05:03,930
and somebody bought storage space on your server
153

153

00:05:03,930  -->  00:05:05,820
and they put illegal files on there,
154

154

00:05:05,820  -->  00:05:07,740
whatever the bad content is.
155

155

00:05:07,740  -->  00:05:10,080
Well, if the police want to take that evidence,
156

156

00:05:10,080  -->  00:05:11,790
they might take your server
157

157

00:05:11,790  -->  00:05:14,370
that holds not just that person's stuff on it,
158

158

00:05:14,370  -->  00:05:16,980
but also all of your other clients on it as well.
159

159

00:05:16,980  -->  00:05:18,930
And that can go away for a long period of time,
160

160

00:05:18,930  -->  00:05:20,160
because of this legal hold.
161

161

00:05:20,160  -->  00:05:22,020
The legal hold can actually take that computer
162

162

00:05:22,020  -->  00:05:25,680
or server as evidence for the entire duration of that trial,
163

163

00:05:25,680  -->  00:05:28,050
which could be months or even years.
164

164

00:05:28,050  -->  00:05:29,790
So, this is something you have to think about
165

165

00:05:29,790  -->  00:05:31,170
as an organization.
166

166

00:05:31,170  -->  00:05:32,668
Do you have backups for your servers?
167

167

00:05:32,668  -->  00:05:34,740
How quickly can you get them back online
168

168

00:05:34,740  -->  00:05:36,690
if you have some kind of a evidence collection
169

169

00:05:36,690  -->  00:05:38,670
that's going to happen because that is something that you need
170

170

00:05:38,670  -->  00:05:40,770
as part of your business continuity plan as well.
171

171

00:05:40,770  -->  00:05:42,090
Now, another thing I recommend
172

172

00:05:42,090  -->  00:05:43,590
when you're dealing with the law
173

173

00:05:43,590  -->  00:05:44,790
is you should always have somebody
174

174

00:05:44,790  -->  00:05:47,760
from your organization appointed as your liaison.
175

175

00:05:47,760  -->  00:05:50,610
And that person should have legal knowledge and expertise,
176

176

00:05:50,610  -->  00:05:53,910
so they can be the point of contact with law enforcement.
177

177

00:05:53,910  -->  00:05:55,710
So, when somebody comes in from law enforcement
178

178

00:05:55,710  -->  00:05:57,360
and they want to start collecting evidence,
179

179

00:05:57,360  -->  00:05:59,550
you need to have somebody who can work with them.
180

180

00:05:59,550  -->  00:06:01,350
This person is going to be your point of contact,
181

181

00:06:01,350  -->  00:06:02,730
between the forensics team,
182

182

00:06:02,730  -->  00:06:05,520
which may be an outside company or law enforcement
183

183

00:06:05,520  -->  00:06:06,900
and your CSIRT team,
184

184

00:06:06,900  -->  00:06:09,300
which is your Cybersecurity Instant Response team.
185

185

00:06:09,300  -->  00:06:11,130
If you're dealing with a data breach for instance,
186

186

00:06:11,130  -->  00:06:13,170
is your company going to try to pursue legal action,
187

187

00:06:13,170  -->  00:06:15,240
against the person who broke into your systems?
188

188

00:06:15,240  -->  00:06:16,890
If so, you're going to have a forensics team
189

189

00:06:16,890  -->  00:06:19,680
from law enforcement coming in and collecting that evidence.
190

190

00:06:19,680  -->  00:06:21,030
And so having this liaison
191

191

00:06:21,030  -->  00:06:22,320
who can be that single voice
192

192

00:06:22,320  -->  00:06:23,790
and that single point of contact,
193

193

00:06:23,790  -->  00:06:25,800
can really make things work a lot better for you.
194

194

00:06:25,800  -->  00:06:27,810
Now, the last thing we need to talk about in this lesson
195

195

00:06:27,810  -->  00:06:29,100
is ethics.
196

196

00:06:29,100  -->  00:06:32,160
Forensic analysts have to follow a code of ethics
197

197

00:06:32,160  -->  00:06:34,246
and there are three main points to this code of ethics
198

198

00:06:34,246  -->  00:06:36,390
that you really do need to follow,
199

199

00:06:36,390  -->  00:06:38,220
otherwise you're going to have a problem
200

200

00:06:38,220  -->  00:06:39,451
when you get on the stand.
201

201

00:06:39,451  -->  00:06:43,890
First, analysis must be performed without bias.
202

202

00:06:43,890  -->  00:06:46,590
This means any conclusions or opinions that you form,
203

203

00:06:46,590  -->  00:06:48,600
should only be based on the direct evidence
204

204

00:06:48,600  -->  00:06:49,890
that you've observed.
205

205

00:06:49,890  -->  00:06:50,760
You shouldn't be thinking,
206

206

00:06:50,760  -->  00:06:54,000
well I don't like this person because X, Y, Z.
207

207

00:06:54,000  -->  00:06:56,070
It's not based on their color, their creed,
208

208

00:06:56,070  -->  00:06:59,370
their nationality, what they look like or anything else.
209

209

00:06:59,370  -->  00:07:01,920
It should only be based on the evidence you find.
210

210

00:07:01,920  -->  00:07:04,260
In fact, it's much better for a forensic analyst
211

211

00:07:04,260  -->  00:07:06,690
to be completely removed from the situation.
212

212

00:07:06,690  -->  00:07:08,790
A lot of places that I've worked with before,
213

213

00:07:08,790  -->  00:07:11,550
they have one set of people who collect the information
214

214

00:07:11,550  -->  00:07:13,500
and another set that analyzes it.
215

215

00:07:13,500  -->  00:07:15,000
So, all they see is the data.
216

216

00:07:15,000  -->  00:07:17,370
They don't know anything about the case up to that point
217

217

00:07:17,370  -->  00:07:20,070
and that can help eliminate some of that bias.
218

218

00:07:20,070  -->  00:07:21,096
The second thing,
219

219

00:07:21,096  -->  00:07:25,200
analyst methods have to be repeatable by third parties.
220

220

00:07:25,200  -->  00:07:28,200
Now, what I mean is that if I take the exact same evidence
221

221

00:07:28,200  -->  00:07:30,030
and I give it to somebody else,
222

222

00:07:30,030  -->  00:07:31,650
they should get the same result
223

223

00:07:31,650  -->  00:07:33,780
if they use the same methods you did,
224

224

00:07:33,780  -->  00:07:35,970
and again this is why it is so important
225

225

00:07:35,970  -->  00:07:38,010
that you document every single thing you do
226

226

00:07:38,010  -->  00:07:39,660
when you're doing your analysis.
227

227

00:07:39,660  -->  00:07:41,130
For instance, when I do my analysis,
228

228

00:07:41,130  -->  00:07:43,920
I will write down the time, the action I took,
229

229

00:07:43,920  -->  00:07:46,980
I clicked this button, I ran this command,
230

230

00:07:46,980  -->  00:07:49,680
here was my results and I put a screenshot in there.
231

231

00:07:49,680  -->  00:07:51,630
That way, anybody who comes behind me,
232

232

00:07:51,630  -->  00:07:53,370
can see exactly what I did,
233

233

00:07:53,370  -->  00:07:55,230
when I did it, how I did it
234

234

00:07:55,230  -->  00:07:56,490
and if they run those same commands,
235

235

00:07:56,490  -->  00:07:58,170
they should get the same results.
236

236

00:07:58,170  -->  00:07:59,070
If they don't
237

237

00:07:59,070  -->  00:08:01,800
that could be reason to get your evidence thrown out.
238

238

00:08:01,800  -->  00:08:04,770
And the third thing is that evidence must not be changed
239

239

00:08:04,770  -->  00:08:05,970
or manipulated.
240

240

00:08:05,970  -->  00:08:09,900
We never want to do analysis on the actual device itself.
241

241

00:08:09,900  -->  00:08:13,140
Instead, we always want to do it on a copy when we can.
242

242

00:08:13,140  -->  00:08:14,910
So, if I'm taking evidence from a hard drive,
243

243

00:08:14,910  -->  00:08:16,603
I'm going to do a copy of that hard drive.
244

244

00:08:16,603  -->  00:08:19,230
I'm going to run an integrity check on both the drive
245

245

00:08:19,230  -->  00:08:22,020
and the source to make sure they match such as a hash.
246

246

00:08:22,020  -->  00:08:24,870
And if they do, I can then do my analysis on the copy.
247

247

00:08:24,870  -->  00:08:27,630
That way I don't have the possibility of modifying
248

248

00:08:27,630  -->  00:08:29,040
or changing the original.
249

249

00:08:29,040  -->  00:08:30,450
And we'll talk about a lot of other things
250

250

00:08:30,450  -->  00:08:32,820
of how we can make sure we don't modify the original
251

251

00:08:32,820  -->  00:08:34,385
as we go through this section.
252

252

00:08:34,385  -->  00:08:37,020
Now, here is a big warning for you.
253

253

00:08:37,020  -->  00:08:38,880
If you're ever going to do this professionally,
254

254

00:08:38,880  -->  00:08:40,080
keep this in mind.
255

255

00:08:40,080  -->  00:08:43,020
Defense attorneys will try to use any deviation
256

256

00:08:43,020  -->  00:08:45,076
from your ethics or from your procedures
257

257

00:08:45,076  -->  00:08:48,090
as a reason to dismiss your findings and analysis.
258

258

00:08:48,090  -->  00:08:51,240
Remember, these attorneys get paid big dollars
259

259

00:08:51,240  -->  00:08:52,920
to be able to get their clients off.
260

260

00:08:52,920  -->  00:08:54,150
That's their job.
261

261

00:08:54,150  -->  00:08:56,250
They're trying to get that case thrown out.
262

262

00:08:56,250  -->  00:08:58,770
Anytime they can get your evidence thrown out
263

263

00:08:58,770  -->  00:09:00,627
that is one less thing against their client.
264

264

00:09:00,627  -->  00:09:02,280
And so they're going to do that.
265

265

00:09:02,280  -->  00:09:03,600
They are going to go after you,
266

266

00:09:03,600  -->  00:09:04,920
they're going to go after your credentials,
267

267

00:09:04,920  -->  00:09:06,120
they're going to go after your methods,
268

268

00:09:06,120  -->  00:09:07,830
they're going to go after your processes
269

269

00:09:07,830  -->  00:09:09,990
and you're going to have to defend all of that in court
270

270

00:09:09,990  -->  00:09:11,820
to make sure your evidence can be admissible
271

271

00:09:11,820  -->  00:09:13,220
and can't stand up in court.
