1
00:00:00,570 --> 00:00:01,403
In this lesson,

2
00:00:01,403 --> 00:00:04,140
we're going to discuss data collection procedures.

3
00:00:04,140 --> 00:00:05,490
During an incident response,

4
00:00:05,490 --> 00:00:08,310
we often need to collect evidence of the cyber attack

5
00:00:08,310 --> 00:00:10,410
for further analysis.

6
00:00:10,410 --> 00:00:12,000
For example, if your main server

7
00:00:12,000 --> 00:00:13,860
has been infected with some kind of malware

8
00:00:13,860 --> 00:00:15,330
as part of an attack,

9
00:00:15,330 --> 00:00:16,770
you want to get that cleared up

10
00:00:16,770 --> 00:00:19,380
and get the server back online as quickly as possible

11
00:00:19,380 --> 00:00:21,960
to minimize the disruption to your operations.

12
00:00:21,960 --> 00:00:23,220
But if you do that,

13
00:00:23,220 --> 00:00:25,620
you may erase the evidence of the attack.

14
00:00:25,620 --> 00:00:28,410
That will make it impossible to figure out who did it.

15
00:00:28,410 --> 00:00:30,360
Now, to overcome this challenge,

16
00:00:30,360 --> 00:00:32,850
we often use digital forensic collection techniques

17
00:00:32,850 --> 00:00:35,790
to make forensic images of the data on the servers,

18
00:00:35,790 --> 00:00:38,970
and we use that as evidence for later analysis.

19
00:00:38,970 --> 00:00:41,250
Doing that allows your incident response team

20
00:00:41,250 --> 00:00:43,260
to help you get your server back online

21
00:00:43,260 --> 00:00:46,080
as quickly as possible and resume operations,

22
00:00:46,080 --> 00:00:48,780
but also maintain the evidence.

23
00:00:48,780 --> 00:00:52,110
Your incident response team may need the evidence

24
00:00:52,110 --> 00:00:54,180
because they may be working with law enforcement,

25
00:00:54,180 --> 00:00:55,320
and if you're doing that,

26
00:00:55,320 --> 00:00:57,360
you're probably going to seek criminal prosecution

27
00:00:57,360 --> 00:01:00,000
for the attacker who broke into your system.

28
00:01:00,000 --> 00:01:01,560
As part of your data collection

29
00:01:01,560 --> 00:01:03,150
and evidence collection efforts,

30
00:01:03,150 --> 00:01:05,040
you're going to do a lot of different things.

31
00:01:05,040 --> 00:01:06,660
For example, you're going to capture

32
00:01:06,660 --> 00:01:08,400
and hash the system images.

33
00:01:08,400 --> 00:01:12,030
This means you're going to use tool like FTK Imager

34
00:01:12,030 --> 00:01:14,670
to make an exact copy of the server's hard drive,

35
00:01:14,670 --> 00:01:15,990
and then hash it

36
00:01:15,990 --> 00:01:19,200
to make sure it doesn't change while you're analyzing it.

37
00:01:19,200 --> 00:01:21,780
Then you're going to analyze the data you collected

38
00:01:21,780 --> 00:01:23,100
using software tools.

39
00:01:23,100 --> 00:01:25,830
You're going to use forensic tools like FTK,

40
00:01:25,830 --> 00:01:29,100
Forensic Toolkit, or EnCase.

41
00:01:29,100 --> 00:01:30,960
Then you're going to have to capture

42
00:01:30,960 --> 00:01:32,910
screenshots of the machine.

43
00:01:32,910 --> 00:01:33,870
What was the machine looking like

44
00:01:33,870 --> 00:01:35,310
when you arrived on the scene?

45
00:01:35,310 --> 00:01:36,930
You want to capture pictures of that

46
00:01:36,930 --> 00:01:38,730
so you know exactly what it looked like.

47
00:01:38,730 --> 00:01:39,990
You might also go back

48
00:01:39,990 --> 00:01:42,090
and look at your network traffic logs and captures

49
00:01:42,090 --> 00:01:44,280
and go and review all of that

50
00:01:44,280 --> 00:01:46,650
and see how they moved throughout the network

51
00:01:46,650 --> 00:01:48,870
as you're trying to trace back the attack,

52
00:01:48,870 --> 00:01:51,180
and if you think someone was physically on your property,

53
00:01:51,180 --> 00:01:54,510
you may want to capture video from the closed circuit TV.

54
00:01:54,510 --> 00:01:56,880
Now, as you're collecting this data and evidence,

55
00:01:56,880 --> 00:01:58,560
you want to consider the order of volatility,

56
00:01:58,560 --> 00:02:01,920
which means which order things get modified quickest.

57
00:02:01,920 --> 00:02:03,450
The quickest thing that gets modified

58
00:02:03,450 --> 00:02:05,370
is the cache inside of the processor,

59
00:02:05,370 --> 00:02:07,380
then the memory, then the swap files,

60
00:02:07,380 --> 00:02:09,180
then the hard drives, right?

61
00:02:09,180 --> 00:02:12,090
And you think about which one is going to get changed first.

62
00:02:12,090 --> 00:02:14,130
When you do that, you have to collect things

63
00:02:14,130 --> 00:02:15,840
based on that order as well,

64
00:02:15,840 --> 00:02:18,330
and anything on the victim machine can be modified

65
00:02:18,330 --> 00:02:21,300
if there's a threat actor on the machine, right?

66
00:02:21,300 --> 00:02:24,210
We also want to collect the evidence as quickly as possible.

67
00:02:24,210 --> 00:02:25,680
Then we want to take statements

68
00:02:25,680 --> 00:02:27,270
from witnesses and administrators.

69
00:02:27,270 --> 00:02:28,350
What did they see?

70
00:02:28,350 --> 00:02:30,150
What made them think that there was an incident?

71
00:02:30,150 --> 00:02:31,597
Maybe there was just someone who said,

72
00:02:31,597 --> 00:02:33,180
"Hey, the mouse from my computer

73
00:02:33,180 --> 00:02:35,760
all of a sudden started jumping all over the screen."

74
00:02:35,760 --> 00:02:38,100
That's something you need to collect the information from

75
00:02:38,100 --> 00:02:40,680
and figure out why did that happen.

76
00:02:40,680 --> 00:02:43,410
Then we want to review our licensing and documentation,

77
00:02:43,410 --> 00:02:44,243
and figure out

78
00:02:44,243 --> 00:02:47,190
do we have the proper license for all of our systems,

79
00:02:47,190 --> 00:02:49,350
and do we understand how they work,

80
00:02:49,350 --> 00:02:51,450
and are they working the way that they were designed

81
00:02:51,450 --> 00:02:53,640
based on the documentation?

82
00:02:53,640 --> 00:02:54,480
And then of course,

83
00:02:54,480 --> 00:02:57,090
we're going to track our man hours and our expenses,

84
00:02:57,090 --> 00:02:58,680
because at the end of the day,

85
00:02:58,680 --> 00:02:59,880
this is an incident response.

86
00:02:59,880 --> 00:03:02,490
Someone is going to say, "How much did it cost us?",

87
00:03:02,490 --> 00:03:05,520
and if you look at the most recent data breaches in the USA,

88
00:03:05,520 --> 00:03:06,780
large companies are suffering

89
00:03:06,780 --> 00:03:09,090
millions and millions of dollars of losses

90
00:03:09,090 --> 00:03:10,680
in the cost of these data breaches,

91
00:03:10,680 --> 00:03:12,300
both in their response efforts

92
00:03:12,300 --> 00:03:15,240
as well as the value of the data that was lost.

93
00:03:15,240 --> 00:03:17,670
Now that we have some basic understanding,

94
00:03:17,670 --> 00:03:20,010
let's talk about data acquisition.

95
00:03:20,010 --> 00:03:21,990
Data acquisition is a method and tools

96
00:03:21,990 --> 00:03:24,240
used to create forensically sound copy

97
00:03:24,240 --> 00:03:26,190
of the data from a source device,

98
00:03:26,190 --> 00:03:28,083
such as system memory or hard disk.

99
00:03:28,980 --> 00:03:30,840
Now, when you deal with acquisition,

100
00:03:30,840 --> 00:03:32,347
the first question you have to ask,

101
00:03:32,347 --> 00:03:33,270
"Do I have the right

102
00:03:33,270 --> 00:03:36,090
to search or seize this thing legally?"

103
00:03:36,090 --> 00:03:38,760
This is an important question, because in your organization,

104
00:03:38,760 --> 00:03:41,460
not all devices are owned by the company.

105
00:03:41,460 --> 00:03:42,810
If it's owned by the company,

106
00:03:42,810 --> 00:03:44,573
yeah, you have the right to go ahead and collect it

107
00:03:44,573 --> 00:03:46,320
because you work for that company

108
00:03:46,320 --> 00:03:47,880
and they want you to do it.

109
00:03:47,880 --> 00:03:50,760
But what if you're allowed to bring your own device?

110
00:03:50,760 --> 00:03:52,350
If you're allowed to bring your own device

111
00:03:52,350 --> 00:03:53,340
into the organization,

112
00:03:53,340 --> 00:03:56,130
these policies can get very complicated very quickly,

113
00:03:56,130 --> 00:03:58,530
because you might not be legally able

114
00:03:58,530 --> 00:04:00,150
to search or seize that device

115
00:04:00,150 --> 00:04:01,680
because you don't own it.

116
00:04:01,680 --> 00:04:02,940
The employee does.

117
00:04:02,940 --> 00:04:04,470
And so you have to make sure

118
00:04:04,470 --> 00:04:06,150
that the evidence you're gathering,

119
00:04:06,150 --> 00:04:07,920
you have permission to gather it.

120
00:04:07,920 --> 00:04:10,413
Otherwise, that search could be inadmissible.

121
00:04:11,250 --> 00:04:14,460
Another thing that makes data acquisition very complicated

122
00:04:14,460 --> 00:04:16,500
is that when you get to a crime scene,

123
00:04:16,500 --> 00:04:18,540
you're not just dealing with the physical world.

124
00:04:18,540 --> 00:04:20,610
You're dealing with the digital world.

125
00:04:20,610 --> 00:04:22,410
And so when I come into a room

126
00:04:22,410 --> 00:04:24,780
and I see the lights are on, the computer's on,

127
00:04:24,780 --> 00:04:27,600
how am I going to collect the data off of that computer?

128
00:04:27,600 --> 00:04:30,540
Am I going to shut it down? Am I going to power it off?

129
00:04:30,540 --> 00:04:32,670
Am I going to collect it when it's powered on?

130
00:04:32,670 --> 00:04:34,290
All of these are valid options,

131
00:04:34,290 --> 00:04:36,450
and each one has its drawbacks and benefits

132
00:04:36,450 --> 00:04:38,490
depending on what you're trying to collect,

133
00:04:38,490 --> 00:04:40,590
but for now, I just want you to keep in mind

134
00:04:40,590 --> 00:04:42,600
the fact that you're dealing with a digital crime scene,

135
00:04:42,600 --> 00:04:44,400
as opposed to just a physical one.

136
00:04:44,400 --> 00:04:46,170
There is some evidence that could be lost

137
00:04:46,170 --> 00:04:48,600
when you turn off a computer or shut it down,

138
00:04:48,600 --> 00:04:49,950
and so you need to make sure

139
00:04:49,950 --> 00:04:51,750
that you understand what you're going to do

140
00:04:51,750 --> 00:04:54,180
and the procedures that you're going to deal with.

141
00:04:54,180 --> 00:04:55,800
Now, this brings us to the idea

142
00:04:55,800 --> 00:04:57,600
that some of this data can only be collected

143
00:04:57,600 --> 00:04:58,890
when a system is on.

144
00:04:58,890 --> 00:05:00,390
Some of the data can only be collected

145
00:05:00,390 --> 00:05:01,500
once the system is shut down

146
00:05:01,500 --> 00:05:03,780
or you suddenly remove the power.

147
00:05:03,780 --> 00:05:06,060
Now, an analyst always has to think

148
00:05:06,060 --> 00:05:07,590
about the order of volatility

149
00:05:07,590 --> 00:05:09,180
when they collect their evidence.

150
00:05:09,180 --> 00:05:11,520
First, we always want to collect anything

151
00:05:11,520 --> 00:05:12,390
that is short term,

152
00:05:12,390 --> 00:05:13,770
anything that is highly volatile.

153
00:05:13,770 --> 00:05:15,450
So, if you start thinking about things

154
00:05:15,450 --> 00:05:17,490
like the CPU registers and the cache memory,

155
00:05:17,490 --> 00:05:20,280
that is very small amount of memory inside that processor,

156
00:05:20,280 --> 00:05:22,170
so it's getting changed very frequently,

157
00:05:22,170 --> 00:05:24,780
so you want to collect that as soon as possible.

158
00:05:24,780 --> 00:05:27,210
Then we move onto other volatile memory,

159
00:05:27,210 --> 00:05:29,850
which are things like system memory, routing tables,

160
00:05:29,850 --> 00:05:31,890
ARP caches, process tables,

161
00:05:31,890 --> 00:05:34,410
temporary swap files, and things like that.

162
00:05:34,410 --> 00:05:35,243
All of those things are volatile

163
00:05:35,243 --> 00:05:37,080
and are changing quite rapidly,

164
00:05:37,080 --> 00:05:38,430
but not nearly as quickly

165
00:05:38,430 --> 00:05:41,010
as the CPU register or cache memory.

166
00:05:41,010 --> 00:05:44,640
Then we move onto data that's on persistent mass storage.

167
00:05:44,640 --> 00:05:47,220
Now, in the old days, we would just say hard drive,

168
00:05:47,220 --> 00:05:49,320
but nowadays, we just say mass storage,

169
00:05:49,320 --> 00:05:51,330
because this includes our hard drive,

170
00:05:51,330 --> 00:05:54,060
our solid state drives, and our flash drives.

171
00:05:54,060 --> 00:05:57,210
All of these are persistent mass storage devices

172
00:05:57,210 --> 00:05:58,740
because they will retain information

173
00:05:58,740 --> 00:06:00,030
when you take the power away,

174
00:06:00,030 --> 00:06:00,930
unlike memory,

175
00:06:00,930 --> 00:06:03,180
but it does still change quite often,

176
00:06:03,180 --> 00:06:04,590
as long as the computer is on

177
00:06:04,590 --> 00:06:07,470
and people are writing or reading to that disk.

178
00:06:07,470 --> 00:06:08,850
Then we're going to go ahead

179
00:06:08,850 --> 00:06:10,920
and collect the things that are remotely logged,

180
00:06:10,920 --> 00:06:13,290
things like our SIEM and monitoring data.

181
00:06:13,290 --> 00:06:14,280
This is important

182
00:06:14,280 --> 00:06:17,070
because while it is not on the system that you're analyzing,

183
00:06:17,070 --> 00:06:19,680
it was already remotely logged somewhere else.

184
00:06:19,680 --> 00:06:21,720
That other place somewhere else

185
00:06:21,720 --> 00:06:23,610
is still being read and written to

186
00:06:23,610 --> 00:06:26,100
over and over again by other systems,

187
00:06:26,100 --> 00:06:28,260
and so it could modify some data,

188
00:06:28,260 --> 00:06:31,380
so we want to collect that as well.

189
00:06:31,380 --> 00:06:34,140
After that, we want to get anything that's physical.

190
00:06:34,140 --> 00:06:36,990
This is the physical configuration and network topology,

191
00:06:36,990 --> 00:06:38,310
and things of that nature.

192
00:06:38,310 --> 00:06:39,720
So, if I go into the network

193
00:06:39,720 --> 00:06:42,420
and I start looking at the way it's wired

194
00:06:42,420 --> 00:06:45,930
and just say, "Okay, this computer was talking to a switch,

195
00:06:45,930 --> 00:06:47,280
which talks to this router,"

196
00:06:47,280 --> 00:06:50,760
and I can start mapping out and collecting the information.

197
00:06:50,760 --> 00:06:53,250
After that, we're going to collect archival media.

198
00:06:53,250 --> 00:06:54,450
Now, what is that?

199
00:06:54,450 --> 00:06:57,060
It's things like backup tapes and offsite storage.

200
00:06:57,060 --> 00:06:59,880
Things that are written once and then aren't touched again.

201
00:06:59,880 --> 00:07:03,810
For instance, you might write something to a CDR or a DVR.

202
00:07:03,810 --> 00:07:04,770
Once it's written to that disk,

203
00:07:04,770 --> 00:07:07,410
it's going to maintain that data on it

204
00:07:07,410 --> 00:07:08,820
until you destroy the disk,

205
00:07:08,820 --> 00:07:11,130
so it is our lowest priority of collection,

206
00:07:11,130 --> 00:07:12,900
but still something we want to collect

207
00:07:12,900 --> 00:07:14,580
at the end of the day.

208
00:07:14,580 --> 00:07:17,010
Now, one piece of warning that I want to give you

209
00:07:17,010 --> 00:07:18,750
is something that a lot of junior analysts

210
00:07:18,750 --> 00:07:20,370
would neglect to think about.

211
00:07:20,370 --> 00:07:22,560
When you're dealing with the Windows registry,

212
00:07:22,560 --> 00:07:24,510
a lot of people think about the Window registry

213
00:07:24,510 --> 00:07:26,160
as being on the hard disk,

214
00:07:26,160 --> 00:07:27,900
and while most of the Windows registry

215
00:07:27,900 --> 00:07:29,430
is stored on the hard disk,

216
00:07:29,430 --> 00:07:33,630
there are many key areas like the HKLM\Hardware component

217
00:07:33,630 --> 00:07:36,540
that only stores themselves in memory.

218
00:07:36,540 --> 00:07:39,090
So, you want to analyze that registry part

219
00:07:39,090 --> 00:07:41,220
using a memory dump instead.

220
00:07:41,220 --> 00:07:42,690
When I analyze the registry,

221
00:07:42,690 --> 00:07:44,820
I usually do it via memory dump first,

222
00:07:44,820 --> 00:07:46,170
and then I can go back

223
00:07:46,170 --> 00:07:49,170
and do it off the hard drive afterward.

224
00:07:49,170 --> 00:07:51,510
That way, anything that was missed in memory

225
00:07:51,510 --> 00:07:53,220
might get caught by the hard drive,

226
00:07:53,220 --> 00:07:55,170
and I could see both things.

227
00:07:55,170 --> 00:07:58,320
When you're dealing with things like the \Hardware hive,

228
00:07:58,320 --> 00:07:59,910
it's really important to capture that,

229
00:07:59,910 --> 00:08:02,310
because it's going to record every single disk

230
00:08:02,310 --> 00:08:05,910
that has been connected to or taken out of that computer.

231
00:08:05,910 --> 00:08:07,803
If I use a thumb drive on the computer,

232
00:08:07,803 --> 00:08:10,380
it's going to be logged in that HARDWARE hive,

233
00:08:10,380 --> 00:08:12,480
so that would tell me as an analyst

234
00:08:12,480 --> 00:08:13,470
that I need to start looking

235
00:08:13,470 --> 00:08:15,690
for that thumb drive or that flash drive,

236
00:08:15,690 --> 00:08:19,170
so I can find data that was written off of this computer,

237
00:08:19,170 --> 00:08:20,640
and so that's one of the reasons

238
00:08:20,640 --> 00:08:22,920
why it's really important to think about it.

239
00:08:22,920 --> 00:08:25,890
So remember, when it comes to data acquisition,

240
00:08:25,890 --> 00:08:27,750
we're talking about the method and tools

241
00:08:27,750 --> 00:08:30,900
used to create a forensically sound copy of the data

242
00:08:30,900 --> 00:08:34,530
from a source device such as a system memory or hard disk.

243
00:08:34,530 --> 00:08:36,210
When performing data acquisition,

244
00:08:36,210 --> 00:08:38,760
always follow your documented processes and procedures

245
00:08:38,760 --> 00:08:40,260
to ensure that you don't contaminate

246
00:08:40,260 --> 00:08:42,870
or lose any potential evidence of a cyber attack

247
00:08:42,870 --> 00:08:45,270
for the investigation that you're responding to.

