1
00:00:06,521 --> 00:00:08,580
- In this lesson, 21.4,

2
00:00:08,580 --> 00:00:11,970
we're gonna talk about
forensics examination.

3
00:00:11,970 --> 00:00:14,760
Digital forensics is the
application of science

4
00:00:14,760 --> 00:00:17,760
to the identification,
collection, examination,

5
00:00:17,760 --> 00:00:20,970
and analysis of data that we're
gonna refer to as evidence

6
00:00:20,970 --> 00:00:24,243
while preserving the
integrity of the information.

7
00:00:25,350 --> 00:00:26,430
Now, I wanna caution you

8
00:00:26,430 --> 00:00:29,190
that forensics work is really complex,

9
00:00:29,190 --> 00:00:32,160
and it should be conducted
only by trained investigators

10
00:00:32,160 --> 00:00:34,260
and digital forensic professionals.

11
00:00:34,260 --> 00:00:36,780
It's also an absolutely fascinating field.

12
00:00:36,780 --> 00:00:39,578
So if you like this area of investigation

13
00:00:39,578 --> 00:00:43,053
your next certification maybe
will be on digital forensics.

14
00:00:44,010 --> 00:00:45,990
But for this exam and in general,

15
00:00:45,990 --> 00:00:49,020
security operations
personnel are not expected

16
00:00:49,020 --> 00:00:51,180
to be forensic specialists.

17
00:00:51,180 --> 00:00:53,790
But you should be familiar
with the terminology

18
00:00:53,790 --> 00:00:56,970
and with basic operation
because you might be expected

19
00:00:56,970 --> 00:01:01,020
to manage and or participate
in an investigation.

20
00:01:01,020 --> 00:01:03,270
And of course, you'll probably
be an evidence collector.

21
00:01:03,270 --> 00:01:04,470
So the more you understand

22
00:01:04,470 --> 00:01:07,170
about the backend digital
forensics process,

23
00:01:07,170 --> 00:01:09,620
the better evidence
collector you're going to be.

24
00:01:10,710 --> 00:01:13,860
So let's take a look at the
digital forensics process.

25
00:01:13,860 --> 00:01:16,020
It starts with evidence collection, right,

26
00:01:16,020 --> 00:01:18,840
which is what we talked
about in the last lesson.

27
00:01:18,840 --> 00:01:21,210
Then there'll be data acquisition,

28
00:01:21,210 --> 00:01:24,660
examination, analysis and reporting.

29
00:01:24,660 --> 00:01:27,840
That's all gonna be done
by our forensic experts.

30
00:01:27,840 --> 00:01:30,510
Then that forensic
expert may be called upon

31
00:01:30,510 --> 00:01:34,440
to testify, if necessary, if
it actually goes to court.

32
00:01:34,440 --> 00:01:36,390
And then lastly, we'll have archiving,

33
00:01:36,390 --> 00:01:38,790
which is archiving both the evidence

34
00:01:38,790 --> 00:01:41,400
as well as any data we acquired

35
00:01:41,400 --> 00:01:43,893
as part of the forensic examination.

36
00:01:46,131 --> 00:01:48,540
So let's look at digital
forensics categories

37
00:01:48,540 --> 00:01:51,570
'cause it's not just one
category because it's digital.

38
00:01:51,570 --> 00:01:54,000
There's computer, there's
memory, there's software,

39
00:01:54,000 --> 00:01:56,970
there's network, there's
multimedia, there's mobile,

40
00:01:56,970 --> 00:01:58,710
and there's cloud.

41
00:01:58,710 --> 00:02:01,620
Now, computer digital
forensics would be examination

42
00:02:01,620 --> 00:02:03,600
and analysis of digital devices, right,

43
00:02:03,600 --> 00:02:07,650
such as computers, laptops,
servers, storage, and media.

44
00:02:07,650 --> 00:02:10,050
Memory is the examination and the analysis

45
00:02:10,050 --> 00:02:11,940
of volatile memory or RAM

46
00:02:11,940 --> 00:02:15,037
and any associated caches or registers.

47
00:02:15,037 --> 00:02:17,640
Software is the examination and analysis

48
00:02:17,640 --> 00:02:20,880
of software source code or binary code.

49
00:02:20,880 --> 00:02:23,670
The network would be the
examination and analysis

50
00:02:23,670 --> 00:02:26,250
of network traffic and data packets,

51
00:02:26,250 --> 00:02:29,913
as well as audit, event,
and security logs.

52
00:02:31,110 --> 00:02:33,870
Multimedia is examination and the analysis

53
00:02:33,870 --> 00:02:37,560
of digital images, videos,
and audio recording.

54
00:02:37,560 --> 00:02:40,770
Mobile is the examination
analysis of smartphones

55
00:02:40,770 --> 00:02:43,680
and tablets and other mobile devices,

56
00:02:43,680 --> 00:02:45,990
which can get really
complicated by the fact

57
00:02:45,990 --> 00:02:48,810
that so many of those
devices now are secured

58
00:02:48,810 --> 00:02:51,770
by biometrics and encryption.

59
00:02:51,770 --> 00:02:55,470
And then cloud forensics is the
examination and the analysis

60
00:02:55,470 --> 00:02:58,770
of digital evidence that is
stored in cloud environments

61
00:02:58,770 --> 00:03:01,590
such as cloud storage or in a software

62
00:03:01,590 --> 00:03:03,060
as a service platform.

63
00:03:03,060 --> 00:03:05,940
And each of these different
categories really require

64
00:03:05,940 --> 00:03:07,680
kinda almost a different skillset

65
00:03:07,680 --> 00:03:09,933
but certainly a different set of tools.

66
00:03:10,860 --> 00:03:13,732
But let's look at some general tools.

67
00:03:13,732 --> 00:03:16,830
We have memory imaging
tools, a write blocker,

68
00:03:16,830 --> 00:03:19,260
a bit stream image, and a clone.

69
00:03:19,260 --> 00:03:22,920
A memory image tool is
used to acquire or dump.

70
00:03:22,920 --> 00:03:24,630
That's the term when
we're extracting memory.

71
00:03:24,630 --> 00:03:26,580
You'll hear the term dumping memory.

72
00:03:26,580 --> 00:03:28,560
Dump short-term volatile data,

73
00:03:28,560 --> 00:03:30,750
which is RAM or virtual memory.

74
00:03:30,750 --> 00:03:32,700
A write blocker is going to be used

75
00:03:32,700 --> 00:03:36,093
to intercept any inadvertent drive writes.

76
00:03:37,170 --> 00:03:39,960
A bit stream image is when
we're going to make an image

77
00:03:39,960 --> 00:03:44,280
or a copy that's a bit-by-bit
copy of the source material

78
00:03:44,280 --> 00:03:46,740
that preserves all of the latent data

79
00:03:46,740 --> 00:03:50,100
in addition to the file
and directory structure.

80
00:03:50,100 --> 00:03:54,300
A clone is an exact copy of
an entire physical hard drive,

81
00:03:54,300 --> 00:03:57,030
including all active and residual data

82
00:03:57,030 --> 00:03:59,550
and unallocated or slack space.

83
00:03:59,550 --> 00:04:01,440
Now, you can put a clone into a computer

84
00:04:01,440 --> 00:04:02,700
and it will boot right up

85
00:04:02,700 --> 00:04:04,743
as if it had the original drive in it.

86
00:04:06,750 --> 00:04:08,520
But if you are making copies,

87
00:04:08,520 --> 00:04:12,210
we want to be able to
ensure the integrity, right,

88
00:04:12,210 --> 00:04:16,200
of the media, the copy, that
you're actually examining.

89
00:04:16,200 --> 00:04:19,860
So we use checksums. Checksums
are very much like a hash.

90
00:04:19,860 --> 00:04:22,470
A checksum is a single value derived

91
00:04:22,470 --> 00:04:25,050
from a block of digital
data for the purpose

92
00:04:25,050 --> 00:04:27,600
of detecting errors that
may have been introduced

93
00:04:27,600 --> 00:04:29,730
during the transmission or storage.

94
00:04:29,730 --> 00:04:32,850
Again, checksums are a lot
like a hash or a message digest

95
00:04:32,850 --> 00:04:36,180
as they're used to verify data integrity.

96
00:04:36,180 --> 00:04:39,480
The difference is they
use a simpler algorithm,

97
00:04:39,480 --> 00:04:41,910
and they're smaller
than the type of hashes

98
00:04:41,910 --> 00:04:43,710
we've talked about previously.

99
00:04:43,710 --> 00:04:46,336
But we would take a checksum
of the original media,

100
00:04:46,336 --> 00:04:48,210
a checksum of the cloned media,

101
00:04:48,210 --> 00:04:51,030
and then a checksum of the examined media.

102
00:04:51,030 --> 00:04:53,100
And ultimately, they should all match,

103
00:04:53,100 --> 00:04:55,140
and that will tell us that
there's been no errors

104
00:04:55,140 --> 00:04:56,913
or changes introduced.

105
00:04:58,830 --> 00:05:01,650
So next, let's do some
file recovery terminology.

106
00:05:01,650 --> 00:05:05,730
Cluster, slack space,
unallocated or free space,

107
00:05:05,730 --> 00:05:07,470
and then metadata.

108
00:05:07,470 --> 00:05:10,530
A cluster is going to
be a fixed-length block

109
00:05:10,530 --> 00:05:14,490
of disk space that's indexed
in the file allocation table

110
00:05:14,490 --> 00:05:15,720
or the equivalent.

111
00:05:15,720 --> 00:05:18,660
Now, clusters could be
4K clusters 8K clusters,

112
00:05:18,660 --> 00:05:20,490
16K clusters, right?

113
00:05:20,490 --> 00:05:22,170
And they're just blocks

114
00:05:22,170 --> 00:05:24,070
is the way you wanna think about them.

115
00:05:25,301 --> 00:05:29,598
Now, slack space is the space
between the end of a file

116
00:05:29,598 --> 00:05:31,890
and the end of a cluster.

117
00:05:31,890 --> 00:05:35,130
Now, slack space can contain data or RAM

118
00:05:35,130 --> 00:05:37,979
or segments of deleted files.

119
00:05:37,979 --> 00:05:40,380
So let me show you how that would work.

120
00:05:40,380 --> 00:05:43,830
So let's say I have three clusters,

121
00:05:43,830 --> 00:05:46,800
and these are all 4K clusters.

122
00:05:46,800 --> 00:05:50,280
And I go to write a
file or I delete a file

123
00:05:50,280 --> 00:05:53,040
that was in there, right,
across those clusters.

124
00:05:53,040 --> 00:05:55,140
And then I go to write a new file.

125
00:05:55,140 --> 00:05:59,430
Now, these were all 4K
clusters, so we've got 4, 8, 12.

126
00:05:59,430 --> 00:06:03,840
I go to write a new cluster,
let's say, that is 10K.

127
00:06:03,840 --> 00:06:06,600
So it writes all through that cluster

128
00:06:06,600 --> 00:06:09,090
and it writes all through
the second cluster,

129
00:06:09,090 --> 00:06:12,990
but it only writes through
half of the third cluster.

130
00:06:12,990 --> 00:06:16,200
Why? Because it was
only 10K and I have 12K.

131
00:06:16,200 --> 00:06:17,970
So what's left there?

132
00:06:17,970 --> 00:06:20,370
Sorry, this is in yellow.
It might be hard to read.

133
00:06:20,370 --> 00:06:23,010
But what's left there is the original data

134
00:06:23,010 --> 00:06:26,940
that we thought we deleted but
now has not been overwritten.

135
00:06:26,940 --> 00:06:29,430
And that space is referred
to as slack space.

136
00:06:29,430 --> 00:06:31,650
And it can contain data from RAM,

137
00:06:31,650 --> 00:06:33,240
maybe used by virtual memory,

138
00:06:33,240 --> 00:06:36,603
or it can contain
segments of deleted files.

139
00:06:38,430 --> 00:06:40,110
Let's clear that up for you.

140
00:06:40,110 --> 00:06:42,720
Next we have unallocated or free space.

141
00:06:42,720 --> 00:06:44,850
Unallocated space are clusters

142
00:06:44,850 --> 00:06:47,250
that are not allocated to a file.

143
00:06:47,250 --> 00:06:50,370
Now, clusters can also contain
deleted file fragments.

144
00:06:50,370 --> 00:06:53,578
And carving is the process
by which deleted files

145
00:06:53,578 --> 00:06:56,520
or fragments are recovered.

146
00:06:56,520 --> 00:06:58,530
And then lastly, we have metadata.

147
00:06:58,530 --> 00:07:02,160
So metadata is really
just data about data,

148
00:07:02,160 --> 00:07:04,833
and we'll talk more about
metadata in another lesson.

149
00:07:05,670 --> 00:07:08,700
Now, after the relevant
information has been extracted

150
00:07:08,700 --> 00:07:12,630
the forensic analyst can
study and draw conclusions.

151
00:07:12,630 --> 00:07:14,430
Now, a key component of the analysis

152
00:07:14,430 --> 00:07:17,700
is gonna be correlating
data from multiple sources.

153
00:07:17,700 --> 00:07:19,290
But here's something I
really wanna stress to you,

154
00:07:19,290 --> 00:07:20,760
and that's why it's bolded.

155
00:07:20,760 --> 00:07:22,320
In digital forensics,

156
00:07:22,320 --> 00:07:25,380
the absence of evidence
doesn't necessarily mean

157
00:07:25,380 --> 00:07:26,790
that nothing happened.

158
00:07:26,790 --> 00:07:30,030
It could mean that either we
didn't collect the evidence

159
00:07:30,030 --> 00:07:32,670
during the evidence collection time

160
00:07:32,670 --> 00:07:34,740
or we just didn't have the
evidence to begin with.

161
00:07:34,740 --> 00:07:37,800
So maybe what we really
needed were log files,

162
00:07:37,800 --> 00:07:39,180
but we weren't logging.

163
00:07:39,180 --> 00:07:41,220
The answer might have
been in those log files,

164
00:07:41,220 --> 00:07:43,087
but if we didn't collect the log files,

165
00:07:43,087 --> 00:07:45,360
you know, or create the log files,

166
00:07:45,360 --> 00:07:47,010
then we don't have them to work with.

167
00:07:47,010 --> 00:07:48,120
So in digital forensics,

168
00:07:48,120 --> 00:07:50,460
the absence of evidence
doesn't necessarily mean

169
00:07:50,460 --> 00:07:51,995
that nothing happened.

170
00:07:51,995 --> 00:07:56,130
Now, analysis may also lead
to additional data collection,

171
00:07:56,130 --> 00:07:58,623
examination, and further analysis.

172
00:07:59,580 --> 00:08:02,430
And then we get to the
reporting out phase.

173
00:08:02,430 --> 00:08:04,470
Now, reporting is the process of preparing

174
00:08:04,470 --> 00:08:07,920
and presenting the information
from the analysis phase.

175
00:08:07,920 --> 00:08:09,510
The report should always be written

176
00:08:09,510 --> 00:08:10,830
with the audience in mind.

177
00:08:10,830 --> 00:08:12,750
That's really true for any report.

178
00:08:12,750 --> 00:08:15,090
All conclusions must be substantiated.

179
00:08:15,090 --> 00:08:18,930
And if an event has more than
one plausible explanation,

180
00:08:18,930 --> 00:08:22,230
both should be presented or
they all should be presented.

181
00:08:22,230 --> 00:08:24,570
And if the evidence is incomplete,

182
00:08:24,570 --> 00:08:27,450
it may be possible to
only present findings

183
00:08:27,450 --> 00:08:29,463
and not present a conclusion.

184
00:08:30,840 --> 00:08:34,320
And then at the end of the
forensic investigation, right,

185
00:08:34,320 --> 00:08:36,930
we're going to retain that data

186
00:08:36,930 --> 00:08:39,330
using the process of archiving.

187
00:08:39,330 --> 00:08:41,310
So throughout the retention period,

188
00:08:41,310 --> 00:08:44,490
all original data and
related media, documents,

189
00:08:44,490 --> 00:08:46,980
and ancillary items should be secured.

190
00:08:46,980 --> 00:08:50,130
So we're talking about this
data that we collected, right,

191
00:08:50,130 --> 00:08:52,170
the evidence we collected,
plus anything else

192
00:08:52,170 --> 00:08:55,923
that we created during the
forensic investigation.

193
00:08:56,895 --> 00:09:00,450
Now, evidence retention
parameters are required to ensure

194
00:09:00,450 --> 00:09:02,820
that the evidence is
available when needed.

195
00:09:02,820 --> 00:09:05,640
We might not go to court for
two or three or four years.

196
00:09:05,640 --> 00:09:08,040
But they should also
consider the costs involved

197
00:09:08,040 --> 00:09:10,680
so evidence isn't retained indefinitely.

198
00:09:10,680 --> 00:09:13,530
And for that, you wanna
consult legal counsel.

199
00:09:13,530 --> 00:09:15,300
And at end of life,

200
00:09:15,300 --> 00:09:19,413
all evidence and findings
must be securely disposed of.

201
00:09:20,643 --> 00:09:23,670
And that my friends, brings us
to a three-second challenge.

202
00:09:23,670 --> 00:09:26,570
Five challenge questions, three
seconds each. Let's do it.

203
00:09:27,660 --> 00:09:29,430
It's a bit by bit copy of source material

204
00:09:29,430 --> 00:09:31,620
that preserves all latent data.

205
00:09:31,620 --> 00:09:34,050
1, 2, 3.

206
00:09:34,050 --> 00:09:35,583
That's a bit stream image.

207
00:09:36,540 --> 00:09:39,633
Number two, the process of dumping RAM.

208
00:09:40,530 --> 00:09:42,363
1, 2, 3.

209
00:09:43,320 --> 00:09:45,570
And that's memory imaging.

210
00:09:45,570 --> 00:09:46,530
Number three,

211
00:09:46,530 --> 00:09:51,060
the tool used to intercept
inadvertent drive writes.

212
00:09:51,060 --> 00:09:52,833
1, 2, 3.

213
00:09:54,360 --> 00:09:55,710
And that's a write blocker.

214
00:09:57,720 --> 00:10:01,170
Number four, the space
between the end of a file

215
00:10:01,170 --> 00:10:02,793
and the end of a cluster.

216
00:10:04,290 --> 00:10:06,960
1, 2, 3.

217
00:10:06,960 --> 00:10:09,540
And that's gonna be your slack space.

218
00:10:09,540 --> 00:10:12,780
And lastly, number five, data about data

219
00:10:12,780 --> 00:10:14,700
that I said we'd talk more about later.

220
00:10:14,700 --> 00:10:16,440
1, 2, 3.

221
00:10:16,440 --> 00:10:18,834
And that's metadata.

222
00:10:18,834 --> 00:10:20,790
That brings us to a security in action

223
00:10:20,790 --> 00:10:22,110
so we can apply our knowledge.

224
00:10:22,110 --> 00:10:24,870
And this one's about data acquisition.

225
00:10:24,870 --> 00:10:28,050
The CFO's workstation is
infected with ransomware,

226
00:10:28,050 --> 00:10:30,630
and very critical files
have been encrypted.

227
00:10:30,630 --> 00:10:33,390
This appears to have
been a targeted attack.

228
00:10:33,390 --> 00:10:35,859
Now, the FBI has been alerted.

229
00:10:35,859 --> 00:10:37,530
I guess they're probably pretty busy

230
00:10:37,530 --> 00:10:39,630
because they've asked your organization

231
00:10:39,630 --> 00:10:43,110
to collect, acquire, and
preserve the evidence.

232
00:10:43,110 --> 00:10:47,130
And they'll do the
examination and the analysis.

233
00:10:47,130 --> 00:10:48,330
That's an unusual request.

234
00:10:48,330 --> 00:10:49,830
Usually you would just do the collection,

235
00:10:49,830 --> 00:10:50,663
they would do the rest.

236
00:10:50,663 --> 00:10:52,560
But in this case, they're asking you

237
00:10:52,560 --> 00:10:55,620
to collect, acquire, and preserve.

238
00:10:55,620 --> 00:10:57,930
So what I wanna know from
you is what are you gonna do

239
00:10:57,930 --> 00:11:00,870
to comply with the FBI's request?

240
00:11:00,870 --> 00:11:05,100
And it was the CFO's
workstation, it has ransomware.

241
00:11:05,100 --> 00:11:08,301
The FBI has said, "Can
you guys collect, acquire,

242
00:11:08,301 --> 00:11:10,707
and preserve evidence?"

243
00:11:11,910 --> 00:11:14,370
So put me on pause, write
up an action checklist,

244
00:11:14,370 --> 00:11:15,393
then come on back.

245
00:11:17,316 --> 00:11:19,380
Well, first and foremost,
when we're collecting,

246
00:11:19,380 --> 00:11:22,200
we're gonna maintain an
evidentiary chain documentation.

247
00:11:22,200 --> 00:11:24,090
Absolutely, we don't want any question

248
00:11:24,090 --> 00:11:26,010
about the evidence we're collecting.

249
00:11:26,010 --> 00:11:29,400
We need to identify the
relevant data sources, right?

250
00:11:29,400 --> 00:11:31,380
That could be the drive,
that could be logs,

251
00:11:31,380 --> 00:11:33,030
that could be memory.

252
00:11:33,030 --> 00:11:35,670
But we're gonna identify what
those relevant data sources

253
00:11:35,670 --> 00:11:37,710
are gonna be for our evidence.

254
00:11:37,710 --> 00:11:39,750
And then we're gonna acquire that data

255
00:11:39,750 --> 00:11:41,493
in the order of volatility.

256
00:11:42,810 --> 00:11:44,430
And we wanna really make sure

257
00:11:44,430 --> 00:11:47,463
that we're protecting that
evidence from contamination.

258
00:11:48,899 --> 00:11:52,080
Then we're gonna assign the
acquisition or the extraction

259
00:11:52,080 --> 00:11:55,080
of evidence to
knowledgeable professionals,

260
00:11:55,080 --> 00:11:58,129
either someone internal or external.

261
00:11:58,129 --> 00:12:01,680
And we're gonna require the use
of forensically sound memory

262
00:12:01,680 --> 00:12:03,600
and hard drive acquisition tools.

263
00:12:03,600 --> 00:12:04,530
And we're gonna make sure

264
00:12:04,530 --> 00:12:06,900
that they've documented the
tools that they're using

265
00:12:06,900 --> 00:12:10,080
and that they document
absolutely everything they do,

266
00:12:10,080 --> 00:12:11,400
right, absolutely everything.

267
00:12:11,400 --> 00:12:14,370
Every command that's written,
every action they take,

268
00:12:14,370 --> 00:12:16,591
needs to be documented.

269
00:12:16,591 --> 00:12:19,980
And since you're gonna be
examining a hard drive,

270
00:12:19,980 --> 00:12:23,250
we wanna require the
checksum of a hard drive

271
00:12:23,250 --> 00:12:25,050
both pre and post imaging.

272
00:12:25,050 --> 00:12:27,030
Of course, it's all gonna be documented

273
00:12:27,030 --> 00:12:29,460
because we don't want
there to be any question

274
00:12:29,460 --> 00:12:32,190
of evidence spoilation that
anything's been tampered with

275
00:12:32,190 --> 00:12:34,410
and anything's not the original.

276
00:12:34,410 --> 00:12:36,090
Be able to create this action checklist

277
00:12:36,090 --> 00:12:37,800
and then execute on it.

278
00:12:37,800 --> 00:12:41,430
You know what that is, right,
that's security in action.

279
00:12:41,430 --> 00:12:43,710
There's your word cloud.
It's quite a bit here.

280
00:12:43,710 --> 00:12:47,280
Maybe a lot of unfamiliar
terms, so take your time, right?

281
00:12:47,280 --> 00:12:49,110
Go through it all, make
sure you understand

282
00:12:49,110 --> 00:12:51,390
all of these terms, all of these concepts.

283
00:12:51,390 --> 00:12:53,910
If not, go back to the lesson again.

284
00:12:53,910 --> 00:12:56,040
And then when you're ready,
head on over to the next lesson.

285
00:12:56,040 --> 00:12:57,840
I'll be waiting for you right there.
