1
1

00:00:00,450  -->  00:00:01,920
<v Jason>Forensic tools.</v>
2

2

00:00:01,920  -->  00:00:04,950
In this lesson, we are going to talk about forensic tools,
3

3

00:00:04,950  -->  00:00:06,720
which is specialized applications
4

4

00:00:06,720  -->  00:00:09,360
and hardware that we use to do data collection,
5

5

00:00:09,360  -->  00:00:12,030
data analysis, and data acquisition.
6

6

00:00:12,030  -->  00:00:13,950
Now, digital forensic kits are something
7

7

00:00:13,950  -->  00:00:14,820
that we're going to put together
8

8

00:00:14,820  -->  00:00:16,500
with a lot of different tools in it.
9

9

00:00:16,500  -->  00:00:18,300
This is going to be a kit containing the software
10

10

00:00:18,300  -->  00:00:19,560
and hardware tools required
11

11

00:00:19,560  -->  00:00:21,570
for us to acquire and analyze evidence
12

12

00:00:21,570  -->  00:00:25,230
from system memory dumps and mass storage file systems.
13

13

00:00:25,230  -->  00:00:26,130
Now, this is important
14

14

00:00:26,130  -->  00:00:29,040
because digital forensic software is specialized software
15

15

00:00:29,040  -->  00:00:31,560
that's designed to assist in the collection and analysis
16

16

00:00:31,560  -->  00:00:33,120
of this digital evidence
17

17

00:00:33,120  -->  00:00:35,850
because you can't just copy it like you would a file
18

18

00:00:35,850  -->  00:00:38,280
from your hard drive onto a USB drive.
19

19

00:00:38,280  -->  00:00:39,720
You can't just drag and drop it.
20

20

00:00:39,720  -->  00:00:41,340
There's special ways you have to do this
21

21

00:00:41,340  -->  00:00:43,410
to make sure it's forensically sound.
22

22

00:00:43,410  -->  00:00:45,150
Now, there are lots of different tools out there,
23

23

00:00:45,150  -->  00:00:46,530
but the ones we are going to focus on
24

24

00:00:46,530  -->  00:00:48,840
in this lesson is EnCase,
25

25

00:00:48,840  -->  00:00:51,450
the Forensic Toolkit also known as FTK,
26

26

00:00:51,450  -->  00:00:52,890
and The Sleuth Toolkit.
27

27

00:00:52,890  -->  00:00:54,750
These are the three big ones that we're going to cover
28

28

00:00:54,750  -->  00:00:57,120
inside the CySA+ curriculum.
29

29

00:00:57,120  -->  00:00:58,860
Now, just an exam note here,
30

30

00:00:58,860  -->  00:01:02,070
you don't need to know how to use these tools for the exam.
31

31

00:01:02,070  -->  00:01:04,440
You should know what they are, and if you see their name,
32

32

00:01:04,440  -->  00:01:06,720
you should know they're digital forensic tools.
33

33

00:01:06,720  -->  00:01:08,220
First, we have EnCase.
34

34

00:01:08,220  -->  00:01:11,040
And EnCase is a digital forensic case management product
35

35

00:01:11,040  -->  00:01:13,110
that was created by guidance software.
36

36

00:01:13,110  -->  00:01:15,900
It uses built-in pathways or workflow templates
37

37

00:01:15,900  -->  00:01:17,190
that will show you the key steps
38

38

00:01:17,190  -->  00:01:19,170
in many types of investigations.
39

39

00:01:19,170  -->  00:01:20,700
Remember how I said it was really important
40

40

00:01:20,700  -->  00:01:22,470
to follow a written process?
41

41

00:01:22,470  -->  00:01:25,650
Well, these pathways and workflows help you do that.
42

42

00:01:25,650  -->  00:01:27,390
They give you all the key steps that you need
43

43

00:01:27,390  -->  00:01:28,890
as you're going through your process,
44

44

00:01:28,890  -->  00:01:30,480
almost like a checklist.
45

45

00:01:30,480  -->  00:01:31,710
Now, when you look at EnCase,
46

46

00:01:31,710  -->  00:01:35,280
it is a graphical user environment, and it runs on Windows.
47

47

00:01:35,280  -->  00:01:36,810
The great thing about it is you can use it
48

48

00:01:36,810  -->  00:01:39,210
for both acquisition and analysis.
49

49

00:01:39,210  -->  00:01:41,190
EnCase is a very powerful tool,
50

50

00:01:41,190  -->  00:01:44,250
and it can read bit-by-bit copies of the hard drive
51

51

00:01:44,250  -->  00:01:46,350
and do the analysis inside the slack space
52

52

00:01:46,350  -->  00:01:48,870
and the deleted files and bring those back to life.
53

53

00:01:48,870  -->  00:01:49,800
It can also help you with things
54

54

00:01:49,800  -->  00:01:52,200
like timeline generation and lots more.
55

55

00:01:52,200  -->  00:01:53,040
We're going to talk about more
56

56

00:01:53,040  -->  00:01:55,710
of these features later on throughout this section.
57

57

00:01:55,710  -->  00:01:58,950
Next, we have FTK, the Forensic Toolkit.
58

58

00:01:58,950  -->  00:02:01,080
This is a digital forensic investigation suite
59

59

00:02:01,080  -->  00:02:03,780
by AccessData, and it runs on Windows servers
60

60

00:02:03,780  -->  00:02:06,150
or server clusters that allows for faster searching
61

61

00:02:06,150  -->  00:02:08,790
and analysis due to the way it does data indexing
62

62

00:02:08,790  -->  00:02:10,500
whenever you import evidence.
63

63

00:02:10,500  -->  00:02:12,780
Now, most of the features you're going to find in EnCase
64

64

00:02:12,780  -->  00:02:14,730
you're going to find in FTK as well.
65

65

00:02:14,730  -->  00:02:16,440
They are really the two big competitors
66

66

00:02:16,440  -->  00:02:18,510
in the digital forensic software market,
67

67

00:02:18,510  -->  00:02:19,980
and they're both commercial solutions
68

68

00:02:19,980  -->  00:02:21,510
that cost a lot of money.
69

69

00:02:21,510  -->  00:02:22,980
Now, when you look at FTK,
70

70

00:02:22,980  -->  00:02:24,930
it looks a lot like EnCase, right?
71

71

00:02:24,930  -->  00:02:26,220
You see a lot of the same things.
72

72

00:02:26,220  -->  00:02:28,740
It has the same kind of style inside the windows.
73

73

00:02:28,740  -->  00:02:30,090
You can see, down at the bottom,
74

74

00:02:30,090  -->  00:02:32,580
the binary data written in hexadecimal value
75

75

00:02:32,580  -->  00:02:34,260
with the ask key off to the side.
76

76

00:02:34,260  -->  00:02:36,510
You can see the files up and top in the file list
77

77

00:02:36,510  -->  00:02:38,457
that it's found as it's gone through this hard drive.
78

78

00:02:38,457  -->  00:02:40,710
And you can see it has basically the same type
79

79

00:02:40,710  -->  00:02:42,660
of stuff that you found in EnCase.
80

80

00:02:42,660  -->  00:02:44,670
Next, I want to talk about The Sleuth Toolkit.
81

81

00:02:44,670  -->  00:02:46,230
Now, this is a good one for you
82

82

00:02:46,230  -->  00:02:48,540
to start learning how to use digital forensics.
83

83

00:02:48,540  -->  00:02:49,373
The reason for this is
84

84

00:02:49,373  -->  00:02:51,540
it's an open source digital forensics collection
85

85

00:02:51,540  -->  00:02:53,550
of a lot of different command-line tools
86

86

00:02:53,550  -->  00:02:55,500
and programming libraries for disc imaging
87

87

00:02:55,500  -->  00:02:56,880
and file analysis,
88

88

00:02:56,880  -->  00:02:59,400
and it interfaces with a program called Autopsy
89

89

00:02:59,400  -->  00:03:02,850
that is the graphical user front end interface for this kit.
90

90

00:03:02,850  -->  00:03:04,830
Now, the great thing about The Sleuth Toolkit
91

91

00:03:04,830  -->  00:03:07,800
it is a completely free and open source solution.
92

92

00:03:07,800  -->  00:03:10,440
So you can go Google The Sleuth Toolkit
93

93

00:03:10,440  -->  00:03:12,750
and download it and install it on your machine right now
94

94

00:03:12,750  -->  00:03:14,400
and start playing with it.
95

95

00:03:14,400  -->  00:03:16,860
Now, The Sleuth Toolkit looks a lot like the other ones
96

96

00:03:16,860  -->  00:03:18,660
when you're using it on Windows,
97

97

00:03:18,660  -->  00:03:20,430
again, graphical environment
98

98

00:03:20,430  -->  00:03:23,790
and it's basically made to be a clone of FTK or EnCase
99

99

00:03:23,790  -->  00:03:27,210
but in the open source, free for you to use market.
100

100

00:03:27,210  -->  00:03:28,537
So you may be wondering,
101

101

00:03:28,537  -->  00:03:31,320
"Jason, which one should I learn to use?"
102

102

00:03:31,320  -->  00:03:32,700
Well, it really comes down
103

103

00:03:32,700  -->  00:03:34,950
to which one your organization uses.
104

104

00:03:34,950  -->  00:03:36,930
Now I like to start out with The Sleuth Toolkit,
105

105

00:03:36,930  -->  00:03:39,390
'cause again, it's free and it's open source,
106

106

00:03:39,390  -->  00:03:42,120
but if you can get access to EnCase or FTK,
107

107

00:03:42,120  -->  00:03:43,890
it's great to try learning those as well.
108

108

00:03:43,890  -->  00:03:45,570
And both of those do have free demos
109

109

00:03:45,570  -->  00:03:47,580
that you can download and use.
110

110

00:03:47,580  -->  00:03:48,750
Now as an analyst,
111

111

00:03:48,750  -->  00:03:51,030
which one are you going to become proficient in and use?
112

112

00:03:51,030  -->  00:03:54,390
Well, most likely you're going to be using EnCase or FTK.
113

113

00:03:54,390  -->  00:03:55,223
Why?
114

114

00:03:55,223  -->  00:03:56,790
Because if you're doing forensic analysis,
115

115

00:03:56,790  -->  00:03:58,560
you're probably working for a corporation
116

116

00:03:58,560  -->  00:04:00,420
or you're working for law enforcement,
117

117

00:04:00,420  -->  00:04:01,500
and most police stations
118

118

00:04:01,500  -->  00:04:04,620
and law enforcement use either FTK or EnCase,
119

119

00:04:04,620  -->  00:04:06,120
and which one you're going to use is going to be based
120

120

00:04:06,120  -->  00:04:07,230
on the place that hires you.
121

121

00:04:07,230  -->  00:04:08,490
If they're already using EnCase,
122

122

00:04:08,490  -->  00:04:09,780
that's what you're going to use.
123

123

00:04:09,780  -->  00:04:12,240
If they use FTK, that's what you're going to use,
124

124

00:04:12,240  -->  00:04:13,440
and that's the idea here.
125

125

00:04:13,440  -->  00:04:15,030
As a student, I would go ahead
126

126

00:04:15,030  -->  00:04:16,350
and download The Sleuth Toolkit
127

127

00:04:16,350  -->  00:04:17,910
and start learning how that works,
128

128

00:04:17,910  -->  00:04:20,340
and I'll actually show you how I use The Sleuth Toolkit
129

129

00:04:20,340  -->  00:04:22,200
a little bit later on in this section
130

130

00:04:22,200  -->  00:04:24,150
as I do a demonstration for you.
131

131

00:04:24,150  -->  00:04:25,770
Now, in addition to having the software,
132

132

00:04:25,770  -->  00:04:27,330
you also need hardware.
133

133

00:04:27,330  -->  00:04:29,940
And when you start dealing with a forensic workstation,
134

134

00:04:29,940  -->  00:04:32,160
these things have to be powerful.
135

135

00:04:32,160  -->  00:04:34,230
Now, these are standalone forensic tools.
136

136

00:04:34,230  -->  00:04:36,930
They're going to have lots of power behind them.
137

137

00:04:36,930  -->  00:04:39,840
You're going to have multiple processors in this system.
138

138

00:04:39,840  -->  00:04:42,390
You're going to have multiple cores inside the system.
139

139

00:04:42,390  -->  00:04:46,890
You're going to have 32 or 64 or 128 gigabytes of main memory
140

140

00:04:46,890  -->  00:04:48,090
in these systems.
141

141

00:04:48,090  -->  00:04:49,800
You're going to have fast SSDs
142

142

00:04:49,800  -->  00:04:51,540
to be able to run all this stuff,
143

143

00:04:51,540  -->  00:04:53,220
and you're going to have a wide variety
144

144

00:04:53,220  -->  00:04:55,050
of drive host bus adapters.
145

145

00:04:55,050  -->  00:04:58,080
Things like EIDE, SATA, SCSI,
146

146

00:04:58,080  -->  00:05:01,380
SaaS, USB, FireWire, Thunderbolt,
147

147

00:05:01,380  -->  00:05:04,110
and pretty much any other connection mechanism you may need
148

148

00:05:04,110  -->  00:05:05,250
because you might need to connect
149

149

00:05:05,250  -->  00:05:07,110
an external drive of some kind
150

150

00:05:07,110  -->  00:05:09,630
to your system to import that evidence.
151

151

00:05:09,630  -->  00:05:11,700
So you want to make sure you have access to all of that.
152

152

00:05:11,700  -->  00:05:13,860
In addition to that, you're going to have optical drives.
153

153

00:05:13,860  -->  00:05:16,320
You're going to have CD, DVD, Blu-Ray,
154

154

00:05:16,320  -->  00:05:19,710
and even memory card readers, all of this in one machine.
155

155

00:05:19,710  -->  00:05:20,970
Now, in addition to all this,
156

156

00:05:20,970  -->  00:05:23,250
your forensic workstation has to have access
157

157

00:05:23,250  -->  00:05:25,620
to a high-capacity disc array subsystem
158

158

00:05:25,620  -->  00:05:28,350
like a RAID or a storage area network.
159

159

00:05:28,350  -->  00:05:32,370
And the reason for this is simple, evidence files are huge.
160

160

00:05:32,370  -->  00:05:33,840
If you took an evidence collection
161

161

00:05:33,840  -->  00:05:35,880
on my personal computer right now,
162

162

00:05:35,880  -->  00:05:37,980
you would have two terabytes worth of data,
163

163

00:05:37,980  -->  00:05:39,900
and that's just on one of my machines.
164

164

00:05:39,900  -->  00:05:41,190
I have four or five machines
165

165

00:05:41,190  -->  00:05:42,287
sitting around my office right now.
166

166

00:05:42,287  -->  00:05:44,910
And if you came in here and collected on each one of those,
167

167

00:05:44,910  -->  00:05:48,360
you would have 5, 10, 15 terabytes of information
168

168

00:05:48,360  -->  00:05:49,830
that you're going to have to store.
169

169

00:05:49,830  -->  00:05:51,480
If you came in to look at my server,
170

170

00:05:51,480  -->  00:05:53,550
that's 40 terabytes of information.
171

171

00:05:53,550  -->  00:05:54,660
And so you need to have access
172

172

00:05:54,660  -->  00:05:56,910
to someplace to put these huge evidence files
173

173

00:05:56,910  -->  00:05:58,680
as you're collecting them.
174

174

00:05:58,680  -->  00:06:00,420
Now, another thing I mentioned before
175

175

00:06:00,420  -->  00:06:02,460
was that we always want to do our analysis
176

176

00:06:02,460  -->  00:06:04,440
on the copies of your acquired images.
177

177

00:06:04,440  -->  00:06:07,350
You never do it on the actual drives themself.
178

178

00:06:07,350  -->  00:06:08,760
So the way this works is
179

179

00:06:08,760  -->  00:06:10,200
you're going to have the original evidence,
180

180

00:06:10,200  -->  00:06:12,600
say a hard drive or an SSD.
181

181

00:06:12,600  -->  00:06:15,120
You're going to make a bit-by-bit copy of that
182

182

00:06:15,120  -->  00:06:18,090
and acquire that using your digital forensic tools.
183

183

00:06:18,090  -->  00:06:20,100
Now that you have that acquired image,
184

184

00:06:20,100  -->  00:06:22,530
we're not going to do the analysis on that image either.
185

185

00:06:22,530  -->  00:06:24,060
We're going to make a copy of that image,
186

186

00:06:24,060  -->  00:06:26,220
and that's what we're going to do our analysis on.
187

187

00:06:26,220  -->  00:06:28,590
This way, we can always go back to the source image,
188

188

00:06:28,590  -->  00:06:29,580
make another copy,
189

189

00:06:29,580  -->  00:06:32,370
and do more analysis without affecting the original.
190

190

00:06:32,370  -->  00:06:34,710
One last big warning here in this lesson,
191

191

00:06:34,710  -->  00:06:36,930
as an analyst, you should always make sure
192

192

00:06:36,930  -->  00:06:39,390
your forensic workstation is prohibited
193

193

00:06:39,390  -->  00:06:40,830
from accessing the internet.
194

194

00:06:40,830  -->  00:06:42,780
You don't want it to connect to the internet.
195

195

00:06:42,780  -->  00:06:43,613
Why?
196

196

00:06:43,613  -->  00:06:45,240
Because if you can connect to the internet,
197

197

00:06:45,240  -->  00:06:47,280
that means the internet can connect to you.
198

198

00:06:47,280  -->  00:06:48,660
And if the internet connect to you,
199

199

00:06:48,660  -->  00:06:50,940
there's a possibility your forensic workstation
200

200

00:06:50,940  -->  00:06:52,920
could be compromised with malware,
201

201

00:06:52,920  -->  00:06:54,720
it can get a remote access Trojan,
202

202

00:06:54,720  -->  00:06:55,980
and then a bad guy could get in
203

203

00:06:55,980  -->  00:06:57,840
and start manipulating your evidence
204

204

00:06:57,840  -->  00:07:00,270
and making it not say what it's supposed to say.
205

205

00:07:00,270  -->  00:07:01,350
So you always want to make sure
206

206

00:07:01,350  -->  00:07:04,230
that your forensic workstation is cut off from the internet.
207

207

00:07:04,230  -->  00:07:06,150
This way, your evidence stays pure,
208

208

00:07:06,150  -->  00:07:07,400
and so does your machine.
