Transcription
Good afternoon everyone and welcome to Cyberics Digital Masterclass. Cyberics is a cyber security focus initiative committed to cyber awareness, digital safety, and industry-relevant education, with a strong focus on bridging the gap between theory and real-world cyber crime challenges.
Today's session will be conducted by Mr. Yugal Patak, popularly known as Cyber UV. He is a digital forensics and response professional with over five years of hands-on experience across law enforcement, defense, and enterprise environments. Cyber UV has worked on national-level digital forensic investigations and cyber incidents impacting critical information, infrastructure, and national security. His expertise spans computer, mobile, network, and malware forensics, along with ransomware and financial fraud investigations. He is also an experienced trainer, mentor, and speaker, having delivered sessions for law enforcement agencies, defense forces, judiciary members, corporate teams, and academic institutions. His teaching approach is deeply practical, focusing on real-world case studies, forensic defensibility, and incident response readiness. We are honored to have him with us today. Let us begin the session.
Hi, good morning. Am I audible?
>> Yes sir.
>> Uh, good morning. So, I welcome you all to this session. I know you have waited a lot. I was uh seeing your enthusiasm in the group and uh, I hope uh, you are as enthusiastic in the session also, uh, in asking your questions and asking your queries. So, uh, it's a pleasure first of all to be here between you all because uh, mentoring has always been uh, all time been my pleasure. So, yeah, uh, it's good to be with you and uh, I would definitely request you to have uh, good questions, okay? Have your doubts and uh, with that, we'll uh, finish up with uh, you know, a basic knowledge of digital forensics today and uh, I'll hope that you keep learning digital forensics. So, without wasting time, let's start.
Uh, please uh, host, please tell me if you are able to uh, see my screen. I'm sharing my screen.
>> Okay sir.
[clears throat]
>> [snorts]
>> Are you able to see my screen?
>> Yes.
>> Okay. So, good morning to all of you. Today, our topic will be digital forensics. I don't know how many of you are aware about digital forensics or not. Uh, but yeah, digital forensic uh, has been my subject uh, from years and uh, my name is Yugal Patak. I'm working as a digital forensics examiner with the Government of India right now and uh, the topic for today is "Digital Forensics: A Storehouse of Challenges." Now, why do I say "A Storehouse of Challenges"? uh, that we'll discover slowly during uh, you know, the presentation. But the simple meaning of writing this title here, which seems a bit, you know, unique, is digital forensics, a field which is full of challenges, also which is full of new opportunities, also which is full of uh, you know, different kinds of cases, scenarios which you will come across during your career in this field. And uh, one thing is guaranteed: you'll never get bored out in this field. uh, you'll never get uh, something which is uh, you know, uh, repeated in this field because every case is different, every artifact is different, every store is different. So, I start the session with saying a lie: "Security is a myth." We always say security is a myth, everything can be hacked, right? I say, no more, it's a nightmare in digital forensics now.
[snorts]
That's my studying. So, my name name is Patak and I'm working as a digital forensics examiner with the Government of India. And before that, I have been working uh, with Effort Technology Policy Tools NCR and a lot of organizations in different roles. And I have also conducted trainings for NCI, PCIRU, NEPA, and different kinds of defense and judiciary institutes. And my main focus is uh, on mobile forensics, memory forensics, social media forensics, and incident response. So, if you have any kind of queries or doubts or something regarding that, my LinkedIn is mentioned there. You can connect me there also.
Now, let's start with a basic question. Everyday, most of us contribute to an evolving public presentation of who we are and that anyone can see and we cannot erase. Okay. So, for example, whenever you are using your phones, you're creating your ID on Facebook, you're creating your ID on Instagram, you're creating your ID on uh, you know, Tinder, you're creating your ID on uh, you know, any kind of social media platform, whether be Threads or WhatsApp, what you're doing, you [clears throat] are leaving some kind of data, some kind of footprint which is non-eradicable. Secondly, that footprint can be copied and distributed anywhere. For example, you make a public post on Instagram, anyone can view it, anyone can download it, anyone can reproduce it or edit it in any way. And uh, with the advent of AI today, it has become more convenient and more easy to do any kind of uh, you know, misalignment or changes or mishaps with your post, with your pictures, or anything. So, we think we are very safe on our laptops, on our cell phones or iPads because we have enabled all the security controls. But do we know what is behind the scene? Where does the data get stored? Where does our data get distributed? So, we never know on which server our data is located. On which server uh, you know, the data is being uh, stored. And if there is some data breach, where the data will go, who will hack it, who will be able to uh, you know, uh, sell the data, who will purchase the data, what can all be done with it? So, basically, in reality, we are in a huge auditorium speaking into a public address system to a world which can record our every action. They can see our every action, but we cannot see what is happening behind the screen. So, what we leave in everyday life in form of these traces is called a digital footprint.
Now, what is a digital footprint? Digital footprint is the presence that you leave behind online. And digital footprint is basically not a single message or not a single uh, you know, uh, you can say artifact. It's a trail of data that is associated with your online name, whether you say it's an email, whether you say it's your mobile number, whether you say it's your any kind of personal identifiable [snorts and clears throat] information or personally identifiable health information or personally identifiable financial information. [snorts] So, your digital footprint is permanent.
Now, what is digital forensics? Digital forensics is a process of applying scientific and analytical techniques to computers, networks, digital devices, and files to discover or recover admissible evidence. Now, here comes the catch. You have to use scientific techniques. It cannot be something which is, you know, just anyone says and you believe. It cannot be something like hearsay. Okay. So, it's a process of applying scientific and analytical techniques to computers, networks, digital devices, and files to discover or recover admissible evidence. Admissible evidence means the evidence whatever you recover should be acceptable into the court. Secondly, whatever process you are doing should give equivalent and same result every time you do it. Okay. So, it is an integration of identification, assessment, seizure, preservation, imaging, analysis. All these processes combined to find out relevant data or the root cause of incident of crime.
Now, let's see how it works. So, when, for example, you get a smartphone in digital forensics, you do not work on the direct smartphone because it is prohibited. Law says you cannot work on the original evidence. So, you take the smartphone, you connect it to some forensic tool, whether it be any forensic tool. So, then that forensic tool extracts all the data from your device. Now, it depends upon the device and the type of tool you are using that your deleted data is recovered or deleted data is not recovered, or what extent of data can be recovered. But the maximum extent of data can be recovered is all the deleted data of your device from the last format. Then, then comes the process. You do not directly analyze the data on the same system. You create a backup image of the data. You can say whether it be in any form, a file, a zip, or a, you know, dub, which then you are processing into a forensic tool. What that forensic tool will do? That forensic tool will classify the data, churn out the data, and clean out the data for you. Plus, it will also do your recovery part, like deleted data recovery. After that, you get the evidence or data in a, you know, tabular form into proper uh, you can say, uh, different, different uh, categories like documents, different images, different videos, different, okay. And once you get it in that way, then you find the evidence. Now, the question comes, the main logic: how do you find the evidence? Because when you are dumping the data from a 128GB smartphone of Android, you are getting almost 50,000 to one lakh to five lakh files, depending upon the phone. Okay. So, how do you find your evidence from so much large amount of data? The answer is, here comes the process of digital forensic principles. So, if I know what are the possible artifacts, means what are the possible files which can give me the answers of my questions which have been asked by the police or judiciary or the investigating agency, I will analyze only those files and I will leave out all the unused data. Because in your phone, there may be anything and everything present. Today, a person's entire life is inside your mobile phone. From your personal data to your health data, to your bank accounts, to your call records, to your location history, to your browsing history, everything is in your mobile phone. So, I should know what is my scenario and what should I have to find. That is what is the main art in digital forensics. Okay? Because data recovery is a different domain also. You see, normally the people are doing data recovery in shops also. Normally, the uh, you know, you see there are many of the organizations like Stellar or something, data recovery labs where data is being recovered. But people think digital forensics is just limited to data recovery. No, not at all. Data recovery can be done anywhere with free software, with paid software, anything. But digital forensics is the main part where you are actually finding out the evidence from a bunch of data. And that evidence, you are not only finding it, you are writing it into a proper report and you are signing that report which goes to the court. It is validated in the court based on your credentials and findings, and based on that report, the justice is delivered.
So, for example, there is a case. I'll give you an example of the case. There was a case of uh, Gorgo, where a girl was cut down in 84 pieces by her husband. You remember that case? It was unsolved [snorts] till the time the police found out an evidence into her husband's phone. In her husband's phone, police found out that he had searched in Google Chrome the chemical to preserve the body from getting decayed. So, why we cut the pieces and he was throwing it away one by one. He used that chemical, and that basically became the entire backbone for solving the case. So, in that case, just the Google browsing history was an evidence that solved the entire murder mystery. Many such cases you can take into account. If you search on Google, if you search on the internet, a lot of cases are there where no physical evidence was found, no footprints, no blood samples. Okay. In rape cases, there were no semen samples, there were nothing, but just a CCTV footage was there which proved the crime. Just a mobile phone was there which proved the crime. Okay. So, digital evidence is something which is very, very indispensable. Indispensable means something which can prove the crime directly. You need not to argue if you get a digital evidence regarding someone. For example, in the CCTV footage, if it is shown that the person arrived at the venue at 11:00 hours, then definitely the person arrived. There is no if and but for that. Again, you have the process of forensics. You can do the forensic verification of that CCTV footage. CCTV [clears throat] forensics is there. Audio video verification is there. That will definitely prove that the image is not being changed. The video has not been tampered, or no changes have been done in the video. It is an original video, and the crime is proved with a simple evidence. You need not to take the testimony of 10 people who passed through there, or you need not to ask 20 people in nearby shops that whether this person came or not. Just a simple digital evidence, and the case is solved. So, this is the power of digital forensics. That's why the government is now implementing and enhancing digital forensics architecture in India because this can lead to solving of your pendency of cases very, very fast.
Now, what is computer forensic investigation? Computer forensic investigation has two roles. Computer forensic investigation and digital forensic investigation are similar names. They are taken, you know, like uh, uh, in adjacent. So, you say whether it is computer forensics or it is cyber forensics or it is digital forensics. It is similar. So, first responder: what is a first responder? First responder records the crime scene, collects volatile evidence, images the hard disk, contains intrusion. Means, for example, if you have to check anything on the crime scene or for example, you have to uh, find out something on the crime scene or do any kind of crime scene investigation, that is also done by the first responder. His duty is also to preserve, protect, pack, and seal the evidence and send it to the computer forensic lab for analysis. What is the second one? Second one is computer forensic analyst. The investigator people like me who are sitting in the forensic lab and who are doing the analysis of the digital evidence and finding out the data and making the reports. So, there are two roles here. You start with the first responder because you should have the knowledge of the crime scene and how to pick up the evidences, and you end up with the senior analyst in the lab.
So, what are potential digital evidences of a crime scene? The first one is old trend. What used to happen earlier? We used to have computer systems containing hard disk, remote media. We used to have floppy disks, CD drives, USB drives. Okay. Computer network devices like routers, switches. Okay. Any kind of handheld devices like uh, earlier you people used to use iPod or something like that, right? But today, but today, what we have? Today we have device logs, video footage and images, which are screenshots. Then we have archives, we have active data, metadata. Metadata is something very, very important today. Residual data, volatile data, IoT device data, emails, drones. Drones are a very big threat today. Okay. After drones, we have DVRs, which are CCTV boxes. The boxes store the CCTV footages, that are called DVRs or NVRs. Then social media accounts, cloud workspaces, and gaming consoles.
[clears throat] [snorts]
Now, what are the different branches of DFIR? Different branches of DFIR. If you see serially, we have storage media forensics. What is storage media? Storage media means something which is related to any kind of hard disk, which is related to any kind of pen drive, which is related to any kind of uh, you know, USB [snorts] or something.
>> Yeah.
Okay. Next is what you have? You have memory forensics. Memory forensics is related to RAM or RAM dumps. Okay. Then third is cloud forensics. Extracting the data from cloud accounts and doing the forensics of it. Then automotive forensics means you have vehicles. Nowadays, in your vehicles, you have different kinds of automotive devices like Android Auto, you have GPS devices, forensics of that. Then satellite forensics, drone forensics, mobile forensics, card forensics, IoT device forensics, okay, network forensics, analyzing the dumps, social media forensics. So, these are all the branches which encompass DFIR, and many such new branches have also come like blockchain forensics, okay, like AI forensics. You have also got deepfake forensics now. So, you know, the digital forensic domain is evolving with new technologies. And yes, as the crime evolves, this field will keep evolving lifetime. It will never going to end because the type of crime may change, the type of investigation may change, but crime cannot stop. So, digital forensics is a never-ending domain.
Now, what are the essential requirements for digital forensics? First is, you need to determine the scope of investigation and amenable platform for establishing your lab. Whether it be a lab in a laptop or it will be a full-fledged lab. Also, you need to determine the cost factor included in procuring the hardware for the lab. Like, you need a proper laptop. The laptop should be of a good configuration. Okay? Like, for example, 4GB or 8GB won't work. You should have at least 16 to 32GB laptop if you want to run good forensic tools. Okay? But the basics can be minimum 16GB. Determining the users in the lab and capacity of the evidence to be analyzed. Then connect the software and tools required, which are open source also and paid also. They are available in both the modes. Trial can be available for the paid ones. Install the tools and test keys. Okay. For each tool, expected output, and if required, upgrade or change is required, you can change the tool. And last, you have to maintain the record of tools versions and updates and make sure all the tools are reliable.
[clears throat and cough]
>> [snorts]
>> Next comes now, security, a hindrance to digital investigations. So, security, a hindrance to digital investigation, meaning that means, I don't know how many of you know about it or not. WhatsApp, right? WhatsApp. WhatsApp. Important. WhatsApp. Let me come back to chat. All right. Privacy. End-to-end encryption. Very good. Anyone else? Two-factor authentication. Very good. So, comes the main word which is called encryption, right? Encryption. So, what is encryption? Encryption means making your data unreadable. In fact, instead of A, B, C, D, it will become some random, unreadable alphabets which cannot be read by someone. Numerical string, anything based on my algorithm which I'm using. Encryption software. Example: hardware encryption. Can anyone give me an example of hardware encryption?
>> [snorts]
>> Hardware. No, not HDMI. Okay. [snorts and clears throat] Apple iPhone M1 chip, M2 chip encryption. Secondly, external hard drives. Password. It shows blank. That has encryption. Then TPM, Trusted Platform Module. What is Trusted Platform Module? That means, no, it will not boot. Now comes software encryption. Software encryption. Common apps like Instagram, then your WhatsApp, Signal, your uh, Signal Secure, Telegram has encryption, then your BitLocker, VeraCrypt. Okay. This is again encryption software. Secure and claim Samsung, that is also an example of software. And I'm a forensic analyst. How tough will it be for me to find out the evidence from it? And I don't have the key. Can you imagine how tough it will be? It is indeed very, very tough. Second, data hiding in storage devices, overlay, HPware, in places. Then third is slack space. What is slack space? The partition where all your deleted data resides. That is slack space. Then TPM, already discussed. Then comes [clears throat] third, covered communication channels. What means underground kind of [clears throat] something which is undiscoverable, something which is not traceable, right? [snorts] Then VPN. VPN, private, public VPN, data VPN, IP is tough sometimes. Then comes private messaging apps like Snapchat, feature un-WhatsApp, delete for everyone. Again, it is very, very tough. But again, it depends on permutation, combination, and the condition. Next, I see very few people active on the chat. Anyone knows about steganography? [clears throat] Yeah. Hiding information inside a file. But usually silent operations. That is steganography. Yes. Like Morse code. For example, you are actually paying someone. [snorts] QR codes people usually show them in the phone or people usually show them dynamic QR. Next is anti-forensics cloaking techniques and offers. Forensics for example, legal perspective of privacy and evidence collection, jurisdiction issues. For example, Police Department, then policies to govern data between law enforcement and intermediaries for WhatsApp. WhatsApp, that is also a very big issue in digital forensics. Last comes social media, cloud workspaces, IoT. Are we able to extract it all? [snorts] The answer can be yes or no.
Now, [clears throat] mobile phones again, they are a storehouse of challenges. Why? You get a mobile phone from a crime scene. Okay, that mobile phone contains a password. Can you turn off the mobile phone? No, you cannot turn the mobile phone easily [snorts] because nowadays mobile phones require passwords for turning off. Second is mobile operating systems. iOS, Android, Blackberry, Windows, Web, Symbian OS, Vivo OS, Oxygen OS, Xiaomi Hyper OS, MIUI OS, security patches, modifications, then factory reset log or bootloader log. Uh, sorry for the mistake. It's a bootloader lock. Boot lock means the device will be locked and the data will be wiped. You will not be able to get the data. Next, lockdown mode. Samsung lock. If I enable lockdown mode, USB charging. If my phone is unlocked, if my phone is locked, till then no data connection can be made to my phone. Secondly, USB jackown lock. Then phone password. What you will do? Like iPhones and Samsung phones, again a challenge. You have to put the phone in a device called bag. Then comes secure wiping. Secure means erase your data using. Finding is also a big challenge because evidence is gone. Preventing data modification. Apple's iPhone has a secure enclave feature that encrypts all the data on the device. Rooted phones. I'm forgetting the. Then secret chat of Telegram, uns feature of Instagram, and whatnot. Next comes now, second example, digital currency, Bitcoin. Bitcoin. Whether the payment is transferred or not, there should be no frauds. Because, right, inflation, it is privacy preserving. Your identity cannot, cannot be revealed. Okay. You pay for anything which is you don't want to tell the world, still you can use it. But problem. Why Bitcoin? Why digital currency? Why blockchain? Why cryptocurrency? Criminals because decentralized, tracing the root is hard or sometimes impossible. Chain, chain means 0.1, 0.1, 0.1. He cannot trace it. Then chain hopping. For example, blockchain to Tether, Tether to Ethereum, Ethereum to any other currency, Monero or something, anything. I move to 10, 20 different currencies, local Chinese, which I don't know also. I'll have to first study about it. I'll have to first learn about it. The people who are using blockchain or people who are using cryptocurrency, they must be knowing cryptocurrency world, right? It's a dynamic world. So, again, tracing it is a very big challenge in forensics. Tornado Cash. Tornado Cash is a kind of a mixer that acts as a digital shredder to restore the transaction history provided by the blockchain and in process is making it impossible to track the transaction effectively. So, drug operative, terrorist, blockchain transaction. Do you think it is easy to trace? No, it may take months, it may take years, and a lot of manpower, of course.
So, what are the data traces we leave in the digital world which can become digital evidence? Apps are collecting our data. Social media freaks reaction, right? Then comes, then comes single sign-on. Single sign-on, Facebook, but do we know? Do we keep a track of it? This website will have access to your data till you do not. Imagine third-party apps which are as means of fun. Does uninstalling mean your account is deleted? No. Data is still there. I can find out. And don't believe that. Next, trusting private apps and services. Then mod apps. GB WhatsApp, GB Instagram, FM WhatsApp, FM Instagram. Right. Snapseed for editing photos. Download. Do you know what data they are taking from you? Never. [snorts] You get many additional functionalities from these free applications. But what price do we pay in return? That is our data. And data is a lot more important than any kind of money because even many people have done suicide. They are arrested. They are digitally blackmailed. So, is it all forensically accessible, acceptable, and evidence? Yes. Anything such we get in any digital device, it's evidence for us, and we use it.
Now, why forensics is so important? Crimes, financial fraud, fake social media account, cyber stalking, cyber defamation, trolling, crimes, the fake, fake image, fake video, use of AI, fake accounts using AI, data feeding. China, they just need to launch few free apps, which are security places, which are restricted. You know, India influencing the person can track you live. You never see it. Private information. So, you need to think what you are posting. And all this becomes a digital evidence.
So, now, this was the start. If you want to learn more about this, then there is a training which is "Digital Forensic Foundation Batch," a 15-day digital forensic program by Cyber Ethics, okay, and Cyber Social. And here you will learn all these things. How digital forensic experts are usually finding out all these evidences. What you'll learn is not only what is mentioned here, but also real-world life cases where you can find out how police, how forensic experts, and how law enforcement usually track these criminals. You can also find out how to prevent leaving your traces so that you tomorrow do not become the part of any unknown crime which you have never committed. Because mobile number, police won't ask you whether you have done it or not. They will simply say one line: "Is it your email? Is it your phone number?" But that's enough. If any evidence is against you, you don't say anything. So, the syllabus broadly covers email and document forensics, fake documents, altered documents, image forensics, images, deleted file recovery, mobile forensics, network investigation, cyber crime case studies, and the fundamentals of digital forensics. And since it's the pilot, pilot in the first batch, the fees is very low, and there are limited seats. Rest will be briefed to you by the host. So, thank you for joining, and this was all from my side. If anyone has any questions now, you can please ask them.
[clears throat]
>> [snorts]
>> Uh, hello. Yeah. Yeah. No, ask, um, about carding account.
>> About?
>> Carding account.
>> You want to learn carding?
>> Yeah.
>> Do you know carding is legal or illegal?
>> Yeah. Yeah, I know it's illegal. Instead of asking it.
>> Actually, any, but I promise. [clears throat] Sorry, we are not promoting these things. So.
>> Okay. Just tell me one thing. Okay? Just tell me one thing. You ask me, "I want to learn shooting." Okay? "I want to learn firing from a gun." But I assure you, I will not use it to kill someone.
>> Yeah.
>> Do you think it is valid?
>> No, it is not valid.
>> If you are in a police, if you're in a law enforcement organization protecting something, then it is different. But if a general person says me, "I want to learn shooting and I want to know how to kill someone using a gun, but I'll not kill someone."
>> Sorry. You know, I, I, I'll not uh, say anything much. But I'll just give you one advice. You know what?
>> Yeah.
>> People think that law enforcement cannot track you. But you know, maybe you are much excited about it. You may learn carding not from here, but somewhere other platforms. Someone will teach you. There are a lot of resources and platforms available. Telegram, web, anywhere you can learn it. But you know what? If you start here, you know where you'll end. So, you don't see the end right now, but you will see later. And when you'll see the end, maybe you'll remember me. Bus.
>> Uh, can I have [clears throat] hi, you uh, can I uh, may I get uh, okay, uh, thank you so much for all this uh, beautiful session. Uh, I, I have a query uh, that is related to, for example, if you're working uh, so for what we have understood that, okay, we are going into the digital forens. But what else uh, what in that case, if you're working in an enterprise where we are suppose we are not supposed to do any mobile institutional, but yes, if there is a something from the perspective of SOC analyst, in that case, if we want to uh, leverage or elevate our career into DFIR uh, section, then your session or your workshop will cover something such as like, how we can do something memory dumping, memory analysis, uh, uh, from that perspective, will those things will be covered if there is a vulnerability?
>> It will cover. It will cover how you do incident response. Basically, incident response is what you want to ask, uh, like you're in SOC, you find out an incident has come up, you find something uh, fishy on the SIM or some alert, and then you want to know that uh, we have to seize the system, we have to take the RAM dumps, or we have to do the initial investigation so that we can give the data to the forensic team later for the full-fledged investigation. Right.
>> Right. For example, if, if there is uh, if uh, we got a situation where we want to check whether the lateral movement was happened in any system or not. Somehow the EDR is not giving uh, sign or EDR is not giving any signs that the lateral movements had happened or not, or whether the registry, there is a modification has been done in a registry or not. So, well, in that case, if you want to do this kind of the analysis, and I'm sure that the DFIR team is the one who can get all the things. So, to cover all these things, what will be your approach for us when we get uh, when we enroll ourselves into your workshop? Then how the things is going to happen? Will you also show us those uh, tools like EDR or anything, Splunk or something like SIM solution? Like how you will cover those things?
>> Uh, see, basically, I'll not cover the EDR or SIM or something because it's the part of SOC. But yeah, I'll cover from the entire perspective that if you get the log of something, for example, you get a SIM log, or you get an EDR log, or you get an alert, then what are the approaches you have to find out from a forensic perspective or from an incident response perspective to do in the system? Like how you need to uh, you know, isolate the system, how you need to take the RAM dumps, how you can do the preliminary analysis to uh, find out whether there is a malware infection or not, or uh, if you ascertain there is a malware infection, what are the next steps which you should take? Okay? And what are the ways you should prevent the uh, digital evidence from getting any kind of uh, you know, tampering in the evidence or something. And plus, forensic investigation will be definitely the core focus of the course. Right. Inspired and encouraged, motivated. But topics that was very much around like mobile, they want to damage your website, SQL injection, DOS alert, and you just make yourself proactive. False positive basis on that, you escalate the ticket to the next level. It will be during those things. Workshop, RAM dump building, RAM dump will be covered. RAM dump. Okay. RAM dump is basically your dumping the data from the memory. And memory forensics is the part which will be covered. Memory forensics, registry analysis.
>> Okay. Thank you so much. Classes Saturday, Sunday?
>> Yeah, Saturday, Sunday.
>> Saturday, Sunday. Will be conducted.
>> Saturday, Sunday. If you talk about the 15 classes, right?
>> Yeah.
>> Okay. Or tentative time. I, I guess this will help to everyone. Timings, Sunday will be communicated into the group by the host.
>> Okay. Okay. Thank you so much for all for giving the response for all this query. I, I, I really thank you so much.
>> Yeah. Next. Anyone else? I see a lot of hands here.
>> Hello.
>> Yeah.
>> Hi. Uh, this is Prashant here. Um, nice to attend your session and nice to listen to you. I just have a couple of questions. Number one, are we doing any capstone type of project at the end of this thing? Uh, um, a real-time uh, project type of thing or something on those those lines?
>> Uh, P uh, please.
>> Uh, yes, we will cover the projects as well.
>> Right. Right. And uh, so the, the, the Saturday, Sunday, so it's about 2 hours each or no? What is the probable uh, duration of the classes?
>> Like, we are doing uh, duration for 15 days, uh, that is around 2 months, okay? And uh, each day uh, 2 hours to 3 hours.
>> Okay. Okay. And will the recordings and material be available?
>> Yes, yes, yes. You will get the LMS and you will uh, access the LMS for a lifetime.
>> Okay. That's great. Even that was also our query. Maybe class. So, thank you so much for covering this.
>> Thank you so much, Prashant, for asking this query.
>> Thank you. Thank you. Pleasure. Yeah, please. I work. I have also attended that that was related to email security and cyber security. But in that case, that class, that session, it was not communicated effort from the perspective of DFP DK by DM RCB compromise, whether it is it has been compromised or not by that hacker to deliver email by bypassing all the email security tools such as like Proofpoint. So, will this also be get covered where we can understand, okay, these are the things where the attacker from the perspective of attacker, they can compromise, and from there we can get that evidence, okay, this is uh, compromised even though it is showing as a pass?
>> Uh, I think it will be covered. That actual thing will be uh, told by Mr. Yugal sir. So, please confirm, sir, if this topic is will be covered.
>> Yeah, in forensics, it will be covered. SPF analysis and uh, you know, DMARC analysis, SPF analysis, DKIM analysis, then also the deliverability tracing, it will be covered. We can confirm.
>> Okay. Thank you.
>> I got it.
>> Uh, hello sir. Uh, good afternoon, sir.
>> Good afternoon.
>> So, thank you for this interactive session. It was really a good experience uh, while uh, attending this uh, so uh, so basically, I'm a university student and I have interest in this cyber security networking domain. Uh, basically, I have not started yet anything. Uh, I don't have any prior knowledge of this. Uh, so can you uh, give me a basic uh, like how can I start into this uh, like that type of. I am just uh, I was scrolling yesterday and I go, I go through this and uh.
>> See, the session which we are talking about is basically for from the basics only. You'll be started to cover from the very basics and uh, you'll go to the intermediate level. I will not say advanced because forensics is a very big domain, so advanced takes a lot of time. That's why it is said it's a beginner-friendly one. So, you start from the beginner level and you go to mid-level, so that your basics are clear. Your basics are clear because digital currency completely depends on your basics. If your basics are clear, you'll be able to do anything here. So, actually, my question is just like this, that how should I start this networking and cyber security stuff like by starting the CCNA or just going through the networking first and then?
>> No, CCNA is not uh, something uh, which is the everything. Like I'll say, you know, uh, if you're in B.Tech, start with your coursework only. Have a basic knowledge of computer organization, computer operating system, networks. Then try to apply that knowledge in your real life. Like, for example, when you are connecting your devices to the internet, see how it is connected, what is DHCP, what is uh, you know, dynamic IP allocation, how the IPs are located, classes. Then when you use your Windows, see the operating system artifacts, what you are using every day. If you're using Linux, see the command line, how it works, what are the different applications. Okay? So, you know, your coursework, you have to apply in your real life if you want to learn actually. That is a simple business and nothing.
>> What should, what should be the first step for me as for now that?
>> I don't know. The first step, first, know your coursework. Your coursework. If you're doing any kind of course, B.Tech or BCA or something, then learn that. Have the knowledge foundation of that first, and try to apply it in your real life. Yes. Yes. Free courses available, open-source platforms, you will be able to move further. But you said if you don't have any base in it, start making base. Network basic, operating system knowledge, basic computer architecture, basic programming, database, that is essential.
>> Thank you, sir, for kind response. Okay. Can you share a QR code only so that we can make a payment and make a registered ourselves?
>> Uh, yes, I'm sharing the link in the group. Link. Sharing. Sharing. Just sharing. Just give me two minutes.
>> Yeah, sir. Or SOC analyst. Uh, hello.
>> Huh?
>> Uh, sir, am I audible to you?
>> Yeah, you're asking the question again, right? Huh? I'm the question. I'm asking the question. I'm maybe the curious. I'm asking that from the SOC perspective or the SOC operation, what could be uh, the content can be covered?
>> You can do one thing. You can, you can do one thing. You can connect to me. I'll definitely brief you in personal also in the group.
>> Okay. There is something you can ask in the group because there are a lot of people other also. You need to give them also the chance to ask. I request you. I have already cleared your query, but other people are also there who want to ask their questions. So, I believe should be given to everyone because many people are asking right.
>> Uh, definitely. Me, I will share you the complete overview. Okay. Admin. So, what are the computer requirements for this course? Can you please tell?
>> You should have a laptop with around 8GB of RAM and Windows operating system, preferably. In the future, for undergraduates who are pursuing this PE club.
>> Pardon? Sir, could you please tell the opportunities for undergraduate [clears throat] students in the government sector?
>> In the government sector, you can get internships uh, because of the basic knowledge of it. Then after internships, you can get jobs because the government is publishing jobs on a contract basis also in the forensics domain, plus in permanent basis also. You can get jobs in both places uh, using this course. With that, you can also work in the corporates like EY or uh, any Big Four or any companies which are having digital forensics. And now, government has since mandated that every organization needs to report uh, cyber incidents within 6 hours to CERT-In and do a digital forensic investigation. So, private, private forensic labs. So, private and government sector opportunities. And in fact, you can also work with the police departments. Police departments, private for experts hire for the cases because government evidence.
>> Thank you so much, sir.
>> Yeah. Thank you.
>> Uh, someone has written a very big question here in the chat. I see. I have a question. Let us assume there is a mobile device with 10GB of storage. I filled the entire 10GB with a video and then deleted that video. Later, when I checked the storage, it showed 10GB available. After that, I stored another video on the device. When I performed a forensic analysis, I was able to recover both the deleted video and the newly stored video. Can you explain how a deleted file can be restored? Specifically, where is the deleted image or video stored after deletion? If the file is deleted, how does the storage still appear as empty? And how does the data appear later in the forensic image?
>> I guess the question which you have asked, you have given the answer yourself in it that you were able to recover it. And since you were able to recover it, uh, you know the concept behind it. But I guess this question is just to test my knowledge whether I know it or not, which you have asked in the audience. But still, no problem. I respect your question and I will answer it. See, basically, what happens uh, when you are deleting a file, usually you are deleting the entry of the file from the index table or the master file table. Usually, in case of mobile, uh, you have a flash storage, right? Now, flash storage has limited read/write cycles. So, deleting the file sometimes is not beneficial for that. So, in that case, metadata-based recovery will give you the older file. Actually, you deleted the entry of the file, but the data still exists in the uh, storage device. So, whenever you are rewriting the new file, some of the part is being allocated to the new file by the operating system, but the remnants of the older file will also exist. Okay. In the uh, this slack space. So, from slack space, you can get the remnants of the old image also, means old video also, and the new video also. That is the simple scenario what has taken place here. Now, it also depends upon whether you are using UFS storage or eMMC based storage. It depends upon. But yes, after deletion also, the data remains intact. Sometimes it depends upon basically the memory addressing and the indexing how it is stored. Okay. And it also depends upon what kind of flash you're using, whether you're using NAND flash or UFS or whatever you're using. It depends upon the memory also. But with your question, I suppose you have good knowledge of forensics, but still, you asked the question, so it was good from an audience perspective.
>> As you mentioned, a new thing has been developed by the government for the security platform here. Have stopped pasting QR. They have stopped. Now show QR on their phone. But a new scanner generated for every new payment won't uh, they won't generating so many scanners for each payment and for every receiver?
>> Be haptic? No, you don't have to do it. Nowadays, these scanners are basically uh, dynamic. Means, when you do a payment, automatically the QR code changes. So, if you see the machines from HDFC, you see the machines from Paytm also, they come with a, you know, uh, two things. Firstly, they come with a sound box. Soundbox is mandatory now because if you receive the payment, you listen to the sound, then only you let the customer go. That is one method which is being incorporated now. Second method is this dynamic QR. Dynamic QR because like, as one payment is done, the QR code changes. If you're doing multiple payments on the same QR, sometimes it also gives you issues because if one transaction is not committed completely, it freezes down and your entire payment channel is blocked. Then you see that uh, you know, there is an issue with your bank account or something. So, this has also improved that issue that uh, now after every payment, like you pay 10 rupees on a uh, you know, on a scanner, automatically as your payment is completed, it shows the payment is done and new QR generated automatically. You don't have to do it manually for any payment. So, if a person is doing a payment of 10 rupees, 50 rupees, 20 rupees, or any kind of amount, new dynamic QR will come, sir.
[clears throat]
>> What law enforcement agencies work in digital forensics? In digital forensics, digital forensic experts work with law enforcement agencies. And in law enforcement agencies, they are cyber experts or law enforcement experts. Okay. Yeah. One more thing to tell you all, digital forensics is not a technical field. It is a technical field. Cyber security forensics, I should know also. I should know forensics also because I have to stand in the court. So, there I can also be asked some legal questions. I can also have some legal arguments. Plus, police is also depending on me that to have give them the evidence or give them the, you know, clues how this evidence can be used based on different cyber laws. Evidence. Yes, legal part is also there in forensics. Forensic is a technical field. Cyber law, different domain. Cyber law can be pursued from any organization. We have also planned a cyber law course here in the coming future. But, yeah, uh, cyber law can be pursued uh, in any form, like you can have a certification also, you can have a diploma also, you can have any kind of uh, you know, degree also. So, it depends upon like, I have done postgraduate diploma in cyber law and cyber forensics, foundational law, University Bangalore, NSLU. So, yes, you can pursue it from any institution. But, yeah, I would say for a technical person, cyber law is a bit different, a bit difficult. Uh, because the reason is, uh, law is something very subjective, and we are very, very objective people. So, personally, it was a tough call for me to do it. It took time uh, to learn and do things, but fortunately, I did it.
>> Are global certifications necessary for employment in government or private sector? At my college, companies primarily recruit for CCS roles rather than cyber security roles. The institution states that global certifications are essential for securing placements in organizations offering cyber security positions.
>> Okay. So, see, I'll tell you one thing. Although yes, global certifications are necessary and they're important. Uh, the base certification we say will be CHFI. But forensics is a domain skills, then certifications. Because certification won't do much if you will not have any kind of knowledge. Forensics, you'll go to the police, police will keep the evidence before you, keep the tool before you, they'll ask you to find out the data and give it to them logically. Even you don't have a global certification, then also you can work very well. I don't have a proper any global certification which I have taken by paying any money or something. Still, I'm working in forensics from 5 years. So, certifications are not mandate here. What mandates is your knowledge and your skills. If you can find out data from the evidences, if you can work on tools, if you can work on technologies, if you know the base of digital forensics, you can do it.
So, I guess that was all for the session today. And uh, we'll wind up here. Okay. Uh, because it's already 1:30. And yeah, before going, I'll say you one thing. Yes. Yes. I teach ethical hacking also. I started from red and I'm in blue now. Okay. So, yes, I'll uh, say before going one thing that uh, this course will be a very good uh, you know, eye-opener for you also, plus it can be a good career path for you also. So, I'll request you uh, you know, today we are spending a lot of money on many of our hobbies or many of our uh, you know, you can say anything like buying clothes or something, or you know, on trips. So, yeah, I don't believe that this amount is a very big amount. Uh, because since uh, I believe in uh, you know, affordable education for everyone. This was my request to keep the amount very affordable and uh, very, you know, convenient for the college students because you are college students. So, yes, let's see and meet you in the course. Okay. And Jai from my side. Happy New Year and same digital year.