1
1

00:00:00,360  -->  00:00:01,920
<v Instructor>Data acquisition.</v>
2

2

00:00:01,920  -->  00:00:02,910
In this lesson,
3

3

00:00:02,910  -->  00:00:06,630
we're going to talk about how you start acquiring evidence.
4

4

00:00:06,630  -->  00:00:08,640
This involves data acquisition,
5

5

00:00:08,640  -->  00:00:10,170
which is the method and tools used
6

6

00:00:10,170  -->  00:00:12,528
to create a forensically sound copy of the data
7

7

00:00:12,528  -->  00:00:16,830
from a source device, such as system memory or a hard disk.
8

8

00:00:16,830  -->  00:00:18,360
Now, when you deal with acquisition,
9

9

00:00:18,360  -->  00:00:20,010
the first question you have to ask
10

10

00:00:20,010  -->  00:00:22,020
is do I have the right to search
11

11

00:00:22,020  -->  00:00:23,940
or seize this thing legally?
12

12

00:00:23,940  -->  00:00:25,200
This is an important question
13

13

00:00:25,200  -->  00:00:26,790
because in your organization
14

14

00:00:26,790  -->  00:00:29,400
not all the devices are owned by the company.
15

15

00:00:29,400  -->  00:00:30,570
If it's owned by the company,
16

16

00:00:30,570  -->  00:00:32,850
yeah, you have rights to go ahead and collect on it
17

17

00:00:32,850  -->  00:00:35,370
because you work for the company and they want you to.
18

18

00:00:35,370  -->  00:00:37,770
But what if you allow bring-your-own-device?
19

19

00:00:37,770  -->  00:00:40,260
If you allow bring-your-own-device in your organization,
20

20

00:00:40,260  -->  00:00:43,110
these policies can complicate data acquisition
21

21

00:00:43,110  -->  00:00:44,970
because you may not legally be able to search
22

22

00:00:44,970  -->  00:00:46,020
or seize that device
23

23

00:00:46,020  -->  00:00:48,840
because you don't own it, the employee does.
24

24

00:00:48,840  -->  00:00:49,980
And so, you have to make sure
25

25

00:00:49,980  -->  00:00:51,480
that any evidence you're gathering
26

26

00:00:51,480  -->  00:00:53,280
you have permission to gather,
27

27

00:00:53,280  -->  00:00:56,100
otherwise that search could be inadmissible.
28

28

00:00:56,100  -->  00:00:57,990
Another thing that makes data acquisition
29

29

00:00:57,990  -->  00:01:00,627
very complicated is that when you get to a crime scene
30

30

00:01:00,627  -->  00:01:02,910
you're not just dealing with the physical world,
31

31

00:01:02,910  -->  00:01:04,710
you're dealing with the digital world.
32

32

00:01:04,710  -->  00:01:06,210
And so, when I come into a room
33

33

00:01:06,210  -->  00:01:08,827
and I see that the lights are on and a computer is on,
34

34

00:01:08,827  -->  00:01:11,520
how am I going to collect the data off that computer?
35

35

00:01:11,520  -->  00:01:12,660
Am I going to shut it down?
36

36

00:01:12,660  -->  00:01:13,710
Am I going to power it off?
37

37

00:01:13,710  -->  00:01:15,780
Am I going to collect it when it's powered on?
38

38

00:01:15,780  -->  00:01:17,280
All of these are valid options,
39

39

00:01:17,280  -->  00:01:19,620
and each one has drawbacks and benefits
40

40

00:01:19,620  -->  00:01:21,240
depending on what you're trying to collect.
41

41

00:01:21,240  -->  00:01:22,980
But for now, I just want you to keep in mind
42

42

00:01:22,980  -->  00:01:25,039
the fact that when you're dealing with a digital crime scene
43

43

00:01:25,039  -->  00:01:27,240
as opposed to just a physical one
44

44

00:01:27,240  -->  00:01:29,400
there is some evidence that could be lost
45

45

00:01:29,400  -->  00:01:31,620
when you turn off a computer or shut it down.
46

46

00:01:31,620  -->  00:01:33,690
And so, you need to make sure you understand
47

47

00:01:33,690  -->  00:01:34,530
what you're going to do
48

48

00:01:34,530  -->  00:01:36,780
and the procedures you're going to do with.
49

49

00:01:36,780  -->  00:01:38,940
Now, this brings us to the idea that some of this data
50

50

00:01:38,940  -->  00:01:41,160
can only be collected when the system is on
51

51

00:01:41,160  -->  00:01:43,500
and some of this data can only be collected
52

52

00:01:43,500  -->  00:01:45,120
once the system is shut down
53

53

00:01:45,120  -->  00:01:47,490
or you suddenly remove the power.
54

54

00:01:47,490  -->  00:01:48,323
Now, an analyst
55

55

00:01:48,323  -->  00:01:50,490
always has to think about the order of volatility
56

56

00:01:50,490  -->  00:01:52,170
when they collect their evidence.
57

57

00:01:52,170  -->  00:01:54,150
You should have learned about the order of volatility
58

58

00:01:54,150  -->  00:01:56,490
back in A+ and back in Security+.
59

59

00:01:56,490  -->  00:01:58,890
So the rest of this lesson should be a review,
60

60

00:01:58,890  -->  00:02:00,120
but if it's been a while,
61

61

00:02:00,120  -->  00:02:01,890
let's go ahead and cover it anyway.
62

62

00:02:01,890  -->  00:02:05,670
First, we always want to collect anything that is short term,
63

63

00:02:05,670  -->  00:02:07,380
anything that is highly volatile.
64

64

00:02:07,380  -->  00:02:09,750
So if you start thinking about things like CPU registers
65

65

00:02:09,750  -->  00:02:11,010
and cache memory,
66

66

00:02:11,010  -->  00:02:14,220
that is very small amounts of memory inside those processors
67

67

00:02:14,220  -->  00:02:16,470
and so it's getting changed very frequently
68

68

00:02:16,470  -->  00:02:18,840
so you want to be able to collect that as soon as possible.
69

69

00:02:18,840  -->  00:02:21,090
Then, we move on to the other volatile memory,
70

70

00:02:21,090  -->  00:02:22,830
which is things like system memory,
71

71

00:02:22,830  -->  00:02:26,160
routing tables, ARP caches, process tables,
72

72

00:02:26,160  -->  00:02:28,680
temporary swap files, and things like that.
73

73

00:02:28,680  -->  00:02:30,390
All of those are things that are volatile
74

74

00:02:30,390  -->  00:02:32,010
and are changing quite rapidly
75

75

00:02:32,010  -->  00:02:35,790
but not nearly as quickly as a CPU register or cache memory.
76

76

00:02:35,790  -->  00:02:37,050
Then we move onto the data
77

77

00:02:37,050  -->  00:02:39,120
that's on persistent mass storage.
78

78

00:02:39,120  -->  00:02:41,340
Now, in the old days, we would just say the hard drive,
79

79

00:02:41,340  -->  00:02:43,050
but nowadays we just say mass storage
80

80

00:02:43,050  -->  00:02:44,910
because this includes our hard drives,
81

81

00:02:44,910  -->  00:02:47,250
our solid state drives, and our flash drives.
82

82

00:02:47,250  -->  00:02:49,110
All of these are persistent mass storage
83

83

00:02:49,110  -->  00:02:50,640
because they will retain the information
84

84

00:02:50,640  -->  00:02:52,705
when you take away power, unlike memory,
85

85

00:02:52,705  -->  00:02:55,020
but it does still change quite often
86

86

00:02:55,020  -->  00:02:56,430
as long as the computer is on
87

87

00:02:56,430  -->  00:02:59,130
and people are writing or reading to that disc.
88

88

00:02:59,130  -->  00:02:59,963
Then we're going to go ahead
89

89

00:02:59,963  -->  00:03:01,680
and collect the things that are remotely logged,
90

90

00:03:01,680  -->  00:03:04,920
things like our seam and any other kind of monitoring data.
91

91

00:03:04,920  -->  00:03:05,753
This is important because,
92

92

00:03:05,753  -->  00:03:08,520
while it is not on the system you're analyzing,
93

93

00:03:08,520  -->  00:03:10,620
it was already remotely logged somewhere else,
94

94

00:03:10,620  -->  00:03:11,880
that other place somewhere else
95

95

00:03:11,880  -->  00:03:13,530
is still being read and written to
96

96

00:03:13,530  -->  00:03:15,600
over and over again by other systems
97

97

00:03:15,600  -->  00:03:17,010
and so it could modify some data
98

98

00:03:17,010  -->  00:03:18,810
so we want to collect that as well.
99

99

00:03:18,810  -->  00:03:21,090
After that, we want to get anything that's physical.
100

100

00:03:21,090  -->  00:03:22,650
This is the physical configuration
101

101

00:03:22,650  -->  00:03:25,050
and network topology and things of that nature.
102

102

00:03:25,050  -->  00:03:26,310
So if I go into the network
103

103

00:03:26,310  -->  00:03:27,990
and I start looking at the way it's wired
104

104

00:03:27,990  -->  00:03:31,080
and I say, "Okay, this computer was talking to this switch,
105

105

00:03:31,080  -->  00:03:32,610
which talks to this router,"
106

106

00:03:32,610  -->  00:03:33,870
and I can start mapping that out
107

107

00:03:33,870  -->  00:03:35,475
and collecting that information.
108

108

00:03:35,475  -->  00:03:38,550
After that, we're going to collect archival media.
109

109

00:03:38,550  -->  00:03:39,630
Now what is that?
110

110

00:03:39,630  -->  00:03:42,570
It's things like backup tapes and offsite storage,
111

111

00:03:42,570  -->  00:03:43,696
things that are written to once
112

112

00:03:43,696  -->  00:03:45,540
and then they aren't touched again.
113

113

00:03:45,540  -->  00:03:47,010
For instance, you might write something
114

114

00:03:47,010  -->  00:03:49,140
to a CD-R or a DVD-R.
115

115

00:03:49,140  -->  00:03:50,355
Once it's written to that disc,
116

116

00:03:50,355  -->  00:03:52,650
it's going to maintain that data on it
117

117

00:03:52,650  -->  00:03:54,030
until you destroy the disc
118

118

00:03:54,030  -->  00:03:55,980
and so it is our lowest priority of collection
119

119

00:03:55,980  -->  00:03:58,110
but still something we want to collect at the end of the day.
120

120

00:03:58,110  -->  00:03:59,880
Now, one piece of warning that I want to give you
121

121

00:03:59,880  -->  00:04:01,440
is something that a lot of junior analysts
122

122

00:04:01,440  -->  00:04:02,725
will neglect to think about.
123

123

00:04:02,725  -->  00:04:04,650
When you're dealing with the Windows registry,
124

124

00:04:04,650  -->  00:04:06,630
a lot of people think about the Windows registry
125

125

00:04:06,630  -->  00:04:08,040
as being on the hard disk,
126

126

00:04:08,040  -->  00:04:09,690
and while most of the Windows registry
127

127

00:04:09,690  -->  00:04:11,010
is stored on the hard disk
128

128

00:04:11,010  -->  00:04:14,610
there are some key areas like the HKLM\Hardware hive
129

129

00:04:14,610  -->  00:04:16,530
that only store themselves in memory.
130

130

00:04:16,530  -->  00:04:18,557
So you want to analyze that registry part
131

131

00:04:18,557  -->  00:04:20,700
using a memory dump instead.
132

132

00:04:20,700  -->  00:04:22,260
When I analyze the registry,
133

133

00:04:22,260  -->  00:04:24,420
I usually do it via a memory dump first,
134

134

00:04:24,420  -->  00:04:25,470
and then I can go back
135

135

00:04:25,470  -->  00:04:27,480
and do it off the hard drive afterwards.
136

136

00:04:27,480  -->  00:04:29,160
That way, anything that was missed in memory
137

137

00:04:29,160  -->  00:04:30,420
might get caught by the hard drive
138

138

00:04:30,420  -->  00:04:31,830
and I can see both things.
139

139

00:04:31,830  -->  00:04:32,700
When you're dealing with things
140

140

00:04:32,700  -->  00:04:34,080
like the \Hardware hive,
141

141

00:04:34,080  -->  00:04:35,850
it's really important to capture that
142

142

00:04:35,850  -->  00:04:38,190
because that is going to record every single disc
143

143

00:04:38,190  -->  00:04:40,620
that has been connected or taken out of that computer.
144

144

00:04:40,620  -->  00:04:42,300
If I use a thumb drive in that computer,
145

145

00:04:42,300  -->  00:04:44,670
it's going to be logged in that hardware hive.
146

146

00:04:44,670  -->  00:04:46,080
So that would tell me as an analyst
147

147

00:04:46,080  -->  00:04:47,970
that I need to start looking for that thumb drive
148

148

00:04:47,970  -->  00:04:49,140
or that flash drive
149

149

00:04:49,140  -->  00:04:50,400
so I can find the data
150

150

00:04:50,400  -->  00:04:52,560
that was written off from this computer.
151

151

00:04:52,560  -->  00:04:53,640
And so that's one of the reasons
152

152

00:04:53,640  -->  00:04:55,790
why that's really important to think about.
