Transcription
Why entry into DFIR is so difficult compared to SOC and pentesting? Digital forensics itself is not a career. It's a path. You have to live or you have to go by that path to reach a point wherein you can feel that, "Okay, I am into digital forensics." Now, from a forensics perspective, you have to have an investigative perspective. The main thing is that the patience which you should have. Network side also, you have to have a visibility and expertise how DNS works, how TCP/IP fundamentals work, how EDR, XDR, firewalls work. And after that, you have to have a legal perspective also to get your evidence admissible into the court of law.
>> What are the top challenges you have seen when you did the investigations on mobile?
>> So, first of all, everybody is using mobiles. Everybody is having hundreds of applications on that. Even they might not be opening that application, but they are having it for the sake of having it. Terabytes of storage is coming with the latest mobile. So, these are the factors which increase the challenges to address mobile forensics. So, we had a case wherein the entire phone was clean. The entire application was clean. No application was malicious. But again, data was getting exfiltrated to a particular location, and it's no jailbreak for... no.
Hi guys, welcome to the session on Coffee with PR. And today, we have a special guest, my friend, Mr. Dipin Nyer. Uh, this sir doesn't need an introduction. He has seasonal experience on computer forensics, incident response, and so the day when we used to do computer networking, this guy is playing with the forensic tools and having a rich experience of militaries and all that. And it is a privilege for us to have a guy who really practically worked on the forensics field. And our goal is to make sure you get the insight of the forensics. And mark my word, it is the first kind of video on YouTube which practically talks about the forensics career, the internal aspect of the computer forensics, incident response, which, and also we're going to discuss about the career mapping. And we also going to discuss about the tools.
Hi sir, welcome to this podcast on Coffee with Prab. And I will be your first student, which is going to write a lot of notes and I'm going to understand from your perspective about the forensics, the career in forensics, and also if someone wants to make a career, what should be the step-by-step process and your insights about how this entire thing works in detail. So, hope you're going to share a lot of wisdom, thoughts about your experience in this area.
Yeah, first of all, thank you for arranging such a wonderful session wherein I will be interacting with you because I have always seen you on YouTube delivering different sessions on CISSP's governance and risk. It's my privilege to have myself here interacting with you. Uh, going ahead, talking about the digital forensics, so I bagged 20 years of experience as you mentioned, but again, the entire 20 years is not of digital forensics. That path which led to digital forensics has many hurdles, ups and downs. Sometimes it's entirely cut off from our information security field or IT field because you understand the difference works like that. So, my career started in 2005 wherein I was introduced to the defense forces as a communication engineer, which we mentioned as a security analyst. The prime job was to secure the endpoints, reviewing the logs and communication equipments. And from there, I gradually graduated to senior security specialist after working for 10 years in the security field, wherein with technology advancement and attacks getting persistent like APT attacks and systems getting compromised, my task was not only to review the configurations and securing the endpoints, but was to contribute towards the investigation perspective and contributing towards the finding of the root causes, which was mandated by the policy of the organizations to understand how the things are going.
So, so I want to interrupt here. Is, you know, what was the moment, you know, you, you, or the case that made you realize about the digital forensics is where you belong? Because as you said, you started from a communication engineer and all that. And what was it, a curiosity? Or was it a problem-solving thought process? Or >> Or legal aspect that attracted you?
Yeah, see, when I started working in IT, I always had a limited approach towards computers because back then in 2005, it was limited. So many less people get an opportunity to work on it and to get hands-on on network switches, hubs, and routers. So, how I got that thought is the process when I was having audits, type of things, when I was understanding how operating systems were working. So, systems behave in a manner. So, I was curious how these systems are behaving in a different manner than each other. How the systems are communicating to each other? Why it is not communicating to an extent where it is not configured to communicate? What stops that? How policies are working in a registry? How we can manage that particular policy from an AD level? Why the AD policies are over-empowering the systems on-prem policies? So, these are the curiosities which brought me to understand how operating systems are working. Then I started exploring the registries, started exploring the event logs, wherein I understood these are the things who controls the operating system. So, these are the curiosities which brought me into an investigative perspective of the forensics side.
>> Oh, wow. And what was the one incident which triggered you? Yes. Because, um, but are you prepared for that? Because as you said, about the transition from a communication engineer, right, a system engineer, like >> Did you ever think in your life that you will be a forensics expert?
No, never. That's what I am mentioning. When the moment when I have never heard of a word forensics, that time I was doing root cause analysis because that time I was not even knowing it's called root cause analysis. Because some compromises take place, some incident takes place, I was told to find out why it is happening, which log sources are triggering, how to analyze. I was contributing to the root cause analysis, and back end, that forensics guy was created inside me, and that's the area how I mentally and physically drawn towards forensics.
>> But during that time, do you have this feeling that nowadays we have a burnout or, you know, this is basically taking my 12 hours of job? Do you have that kind of feeling?
When >> No, because that again, the curiosity kills that. Because many people believe, that's what I was mentioning. When we talk about digital forensics, people think it is a lavish type of career wherein we will be handling sophisticated tools, expensive labs, and high-profile incidents and high-profile cases. But it's not like that. You have to spend hours. You should have the patience because patience is the biggest key to forensics. 90% of the time, you fail to solve a case because then you have to fight again and come back with a different thought process to identify the root causes because attackers always keep things sophisticated. You have to think from an attacker's perspective. You have to think from an administrative perspective to break a case. So, burnout that time, no, because we used to work, and forensics and investigation mandates that type of mentality wherein you contribute 12 to 14 hours continuing with operating systems. Then only you will be having hands-on and expertise in how things are working in operating systems.
Excellent. And what was the one event which triggered you to get into this forensics? Oh, I know they used to talk, you talk about the curiosity and all, but yes, there will be some one incident like >> example of the person become wisdom bringing his thought process after getting married, that was one incident, right? >> So in your life, what was that incident?
You will not believe the incident is very childish in nature. There was one senior to me when I was not so matured in defense forces. He used to tell, "Okay, okay." I used to spend months researching why it is like that. And that was a point wherein I started investigating the things, opened RAM, cleaned the RAM, opened the entire board out of the PCs and started troubleshooting the things. Why it is not working when we are vertically keeping it? So, that triggered me to get an investigative perspective. And then slowly, when I started hardening the system, that time I got an insight, key, what is the power of registry? How we can control the registry? But again, that was hardening part, not an investigative part. But again, as I mentioned, these are the areas wherein a person with an investigative purpose perspective was building behind me.
>> Oh, wow. So starting from the understanding of the placement of computer and motherboards and all that. And that insight has given me a good perspective. And that's why we have a next follow-up question on that for the audience who came from a non-IT background, because they are also watching our podcast.
>> Yeah. According to you, what do you mean by digital forensics? And could you break the digital forensic into major types? Like we talk about memory forensics, we have disk forensics, uh, we have mobile forensics, cloud forensics now. And we are now you'll see the future of AI forensics. >> So, what is digital forensics? And what are these types of forensics? Can you just share your thoughts on this area?
>> Yeah, see, on a layman language, when, sorry to tell, but when a person dies, we recommend that body for a postmortem to understand how he died and what are the reasons behind that. The same is with the digital equipment. When a crime has happened, when a crime takes place, forensics gets into the job to identify what has happened, how it has happened, and who is behind that. And is there any evidence to prove that to recreate that entire scenario? So, basically, digital forensics is a science which involves extraction of data, analysis of data, and presentation of data in a manner where it is admissible in the court of law to prove the entire scenario. So, coming to the next question, we have got multiple. Again, when it started, it was only computer forensics, which deals with media forensics, like hard disk, pen drive, and all. So, again, as technology evolved, cloud forensics came, storage, memory forensics came, network forensics, IoT device forensics. As you mentioned, AI forensics. So, these entire fields dedicatedly deal with the particular vertical. Like memory forensics, if I take it, particularly deals with the memory, the file system, the page file, hibernate file, swap files, memory dumps. We focus entirely on the memory. How processes are running, how processes are obfuscated, how DLLs are swapped. These are things which we study in memory forensics. When we talk about computer forensics, the entire operating systems are studied to create a timeline, to analyze what is happening with respect to user-based behavior, with respect to system-based behavior, whether there is any persistency, is there any exfiltration of data, is there any communication of C2 type of things? When we get into cloud, because most of the computers right now are connected with cloud, so there are challenges because of the data server. But again, that is again a vertical which deals with forensics into cloud. Coming back to IoT and smart devices, as you've mentioned, right now people are using smartwatches, people are using different smart devices. So, again, that mandates to introduce forensics into these fields as well.
>> Okay. And I'm sorry, I'm going to deep dive into this area. And I'm sure our students and subscribers also >> love to understand that in which condition we do memory forensics or in which conditions we do mobile forensic? Because when you're talking about one system investigations, >> we talk about the gold mine information is in the memory. >> Correct. >> Okay. And if you shut down the system, you lose the data. >> Yeah. >> Tell me about the case where, you know, memory forensics played an important role in your journey.
>> Okay. So, so I will get one step back to get a background. So, when we receive an incident like exfiltration of data or a particular PC communicating to a C2 server or outside the organization's perimeter, so the first step is to identify which is that PC to narrow down the investigation. We identify that. And there are many steps to identify that. We can correlate the SIEM logs, we can correlate with EDR, firewalls, the C2 servers which are talking into the inside PCs. We can narrow down using this type of analysis. Once we identify that, the IR team rushes to that PC to confiscate or to isolate that PC from the network so that that particular incident is not spreading to other PCs within the network. So, when we reach to the location, what happens is that most of the time PCs are running. So, so there are two conditions as you mentioned, the difference between memory forensics and disk forensics. So, when the once the PC is in an on condition, the prima facie evidences which we collect is dumping the memory because as you mentioned, the juice of forensics lies in there because as you speak, fileless malware, living off the land malwares, any compromise with the DLL, any registry manipulation, any persistency, the entire things runs in memory. So, whatever you can extract from memory is beyond what you can get in a disk because that is live. Again, if that machine is shut down, these things can be correlated using multiple files like hibernate files, page files, swap files. But again, these are the old files. The current files reside in memory. So, again, if the PC is on, the first prima facie evidence is dumping the PC, taking the documentations, pictures of the PC, take documenting the passwords. These are the things which we generally advise when the PC is in an on condition. If PC is off, memory dumping is not possible. Then we move ahead with computer forensics wherein we will be confiscating the things, transporting the evidences, maintaining the integrity, creating hash value, and bringing this to the forensics table, wherein we create a separate image to work on, and then we start analyzing the things using this standby options like hibernate file, page file, swap files.
>> This >> What is this file all about?
>> See, when we use RAM, because when the machine is up, it uses memory as RAM. Entire live action which is happening is on RAM. But when the RAM is occupied 100%, it subsidizes some operations to swap files and hibernate files. So, hibernate files will be having content, but that is old with respect to the live data. So, you will get the artifacts of what all are the processes running, what all are the DLLs which are swapped, DLLs which are offloaded. And the traces you will get. But again, the live, which is live, that is only possible when you have a dump of RAM.
>> Okay. >> Yeah.
>> And uh, do you want to share any incidents where you have seen that memory forensics changed the entire case studies and all that?
>> Yeah. Uh, coming to that, we had an investigation wherein we received an incident from outside agencies telling that our organization's PC is communicating to a C2 server. We narrowed down the incident from our IR team. We identified the system. But when we identified the system during collection of prima facie evidences, we could not find it.
>> What's prima facie?
>> Prima facie evidence is the first evidence which you see >> which is collected on that spot. >> Okay. >> That that is legally it is called prima facie evidence because that is the first thing which you identify on a crime scene and you collect that. That's prima facie evidence. So, on prima facie evidences, we didn't find any persistency in the PC. We didn't find any files, malicious files within malicious locations, no startup, no run, no run once, nothing. No persistency was there. But again, whenever we are switching on the PC, the system is getting connected to a C2 server. Then we started thinking of memory forensics. Uh, when we dumped the memory and analyzed the thing, then we came to know that the file is getting executed within the memory and it is getting decrypted, running the script, and getting encrypted before it is moving to the hard disk. So, that's the power of having a fileless malware on your memory. You will not be able to identify that particular malware on your PC. You will not get an IOC. You will not get any hash value to identify that. So, it is very peculiar and difficult to find out. If you don't have a memory dump, then you will, it is very difficult to identify that type of thing. Then you have to re-go live with that particular PC to identify any such activity.
>> Wow. And that's why I say the power of memory is very important. >> Yes. Correct.
>> And uh, what are the top challenges you have seen when you did the investigations on mobile?
>> Okay. See, as I >> Android is easy to investigate or iOS? That depends upon the many factors. Like, let me get into that. So, first of all, everybody is using mobiles. Everybody is having hundreds of applications on that. Even they might not be opening that application, but they are having it for the sake of having it. So, storage, terabytes of storage is coming with the latest mobile. So, these are the factors which increase the challenges to address mobile forensics. Again, most of the applications which are running on Android, Apple, or you take any mobile applications, mobile operating system, entire application is having a connectivity to the cloud. Like, if I take WhatsApp, entire data is in cloud. If I take any other application, entire data is in cloud. So, the challenge is to address to have to get access to that cloud environment for the investigation perspective. So, we had a case wherein the entire phone was clean, the entire application was clean, no application was malicious. But again, data was getting exfiltrated to a particular location.
>> And it's no jailbreak for? >> No, no.
>> So, that was the installation of a fake app by a social engineering type of thing. Attacker led the user to install a malicious app from a non-trusted sources, and that application got run and exfiltrating data to a Cloudflare location wherein he was having an engine X type of thing, and from behind, he was taking the entire data from the phone.
>> But, but my question is basically when it comes to the, um, the phone, if it's not jailbroken, how is it possible for someone to install the external APK files? >> Okay. >> Is it possible?
>> See, uh, no attack by an attacker's perspective is possible until and unless a user is intervened in that. Everywhere, the user's intervention is required to install anything. And that is the power of social engineering and phishing.
>> But is it possible to install APK without jailbreak?
>> Without jailbreak, it is very difficult because you have to have a consent from the user side to >> User consent has been given? >> Yeah, then it will be installed. >> So, without Play Store also, we can install? >> Yeah, exactly. We can install. So, um, again, coming to that question, there are many challenges. Like, if an application is installed, if you receive a PC and wherein it got compromised, the first thing is that you should have a password to access it, which is with the user. Sometimes the user denies to give the access or a password or a passkey. Now, even having a physical access to the laptop or a system, you will not be able to do the forensics or get into the investigation underground unless you have the passkeys or a password. So, that is the first challenge. Second challenge, even though you don't have the password from the user side, it's very difficult within the current scenario to break that using any brute force attack. And because even if you brute force the password, until and unless it is getting cleared by the user's end, the entire disk is full disk encryption. Because Android is using full disk encryption, computers are coming with full disk encryption like BitLocker, FileVault, and all. So, these are the challenges which every forensic analyst faces during the investigation.
>> Okay, that's that's interesting. And, you know, moving ahead, I want to understand if someone wants to make a career in computer forensics or digital forensics. Because there's a lot of resources on how to make a career in pentesting, how to make a career in SOC, how to make a career in GRC, how to make a career in IAM. But when it comes to the digital forensics, how to make a career in digital forensics or, you know, there's a lot of young people want to make in digital forensics and response, but very few actually able to make it.
>> Yeah. >> So, why entry into DFIR is so difficult compared to SOC and pentesting?
>> Yeah. So, it's a >> And we can go by the step by step.
>> It's a good question because many people reach out to me with the same question, how we can make a career in digital forensics. See, digital forensics itself is not a career, it's a path. You have to live or you have to go by that path to reach a point wherein you can feel that, "Okay, I am into digital forensics." Why I'm telling that? Because it's a collection of experiences on different verticals. Like, you have to have an experience and expertise of operating system, how file system works, how files are interacting with each other, how event logs work, how registry works. These are from the operating system side, which technological skill you require. From a forensics perspective, you have to have an investigative perspective. You, the main thing is that the patience which you should have, because without patience, you will not, you will not be able to survive for a single day into digital forensics. Uh, uh, second thing, third thing, network side also, you have to have a visibility and expertise how DNS works, how TCP/IP fundamentals work, how EDR, XDR, firewalls work. So, these are the different areas. And after that, you have to have a legal perspective also to get your evidence admissible into the court of law. Um, coming to after that, even if you clear the entire thing, you have to have a drafting skill, communication skill, soft skill to address the entire thing and bring this entire thing into a report. So, what people does is that they take one vertical and get the expertise. Now, they think that they can get entry into digital forensics. But again, as I mentioned, you have to have expertise of all these mentioned verticals. Then only you will be able and to achieve the expertise in each vertical, you have to spend a minimum of four to five years experiencing hands-on on these type of verticals. Then only you will be able to correlate the things. Because many career graduates after completing cybersecurity in digital forensics think that they can start a career with digital forensics. But again, they have studied what digital forensics is, but to implement that knowledge, you have to have hands-on of how operating system works, network works, how networks are integrated, and networks are related to operating system. And beyond this, how difficult is to get admissibility of a particular evidence into court of law, how difficult is to convince a court for a particular evidence. These are the challenges which people face. So, my recommendation will be to slowly, gradually get into a particular field, expertise that, move on to a different field, expertise that, move on to a different field with an investigative perspective altogether.
>> Curiosity. >> Yeah. Curiosity. Then only you will be, then only you will be addressing yourself as a digital forensics investigator.
>> No. Uh, this is really great insight. And uh, I, I got content for my next video, actually. So, sir, before we, you know, you talk about the skills and all that, can you just tell me about how the forensic investigation works? And what is the step-by-step process? There's a lot of buzzword around that area. There's a lot of bookish knowledge is there, but what is exactly the practical process of forensic investigations from collecting evidence and how we submit in the court and how we have an entire closure process and where the things get failed?
>> Yeah. Yeah. See, uh, first thing, entering into digital forensics, the first thing you receive is a digital device. So, that is a computer device. So, you have to have an experience of interacting with operating system.
>> Excellent. Again, if an operating system is working in a system, it has to have a communication outside. It has to communicate with different PCs and different servers, and the network comes into the place. Once these two things are there, then you can start with your analysis.
>> At least you can start with your analysis to >> Address your sequence of analysis.
>> Yeah. So, and addressing that, when, see, when you are addressing incident response, it has got seven steps. That's the same way digital forensics also has some steps. So, first step is to identify. And identify specifies what has happened and what needs to be investigated.
>> So, first question is, what has happened? So, you have to identify the attack vector. You have to identify whether it is a malicious code execution, whether it is a ransomware, whether it is a phishing mail, whether it's a user privilege escalation, whether it's a lateral movement. You have to identify the attack. Once you have identified the attack, now you come to know key, what is to be analyzed? Because if it is a user privilege escalation, you know only a particular PC is to be analyzed. If it is a lateral movement, then multiple PCs, network will be analyzed. If it is a ransomware, then we have to immediately remove that traces into different pieces, we have to analyze. So, first stage is identification of the attack and device. So, what has happened and what is to be analyzed. Once you know what is to be analyzed, the second stage is preservation.
>> So, preservation is, once you identified this particular PC is to be taken into custody for investigation, you will be with integrity and avoiding tampering to that device, you will be preserving it. Now, for preserving, you will be having some mandate like creating a panchnama, creating a seizure memo, creating... What is panchnama?
>> Yeah. And that's an Indian legal document which mandates for any seizure of any digital device.
>> Chain of custody.
>> Yeah. Different than chain of custody. It annotates from where it is. It's just introduction of that device, where it was found, who is the owner, who is the custodian, prima facie evidence is collected. That's all. That's a panchnama. Again, seizure memo is there for seizure. You will be taking signature and consent of the user, any password and all. After that, when we collect the devices, we raise three forms: that is panchnama, seizure memo, and digital forensic request form to any law enforcement agencies who deals with the seizure of these devices. Raises these three forms. These are mandatory in a court of law because you will not be able to admit any evidences without these three devices. Basic requirement. Okay. Going ahead, the preservation. Preservation, you have to create a hash value of that hard disk. You have to keep it in a separate bag to avoid any interference. Faraday bags are used. Yeah. You have to safely transport that to the nearest location. Um, can be a police station, can be a law enforcement agency, can be an investigation agency who is leading that. You will be placing it there. Now, again, starting from seizure memo, panchnama, digital forensics request form, you will be having one more form that is called chain of custody. That is very important because you complete the entire case, that is of no use if that chain of custody is broken.
>> It is also admissible in the court? Yes, it has to be there. Um, so the chain of custody means from seizure to the end trial in the court, you have to have that chain of custody without broken.
>> So, any action which is handling, any person which is handling that device, any action which is happening on that device is to be annotated on this chain of custody. Uh, that is a preservation. Again, after preservation, collection. Collection means once you have that device on your table, you will be collecting the artifacts. Now, here, many people are having a confusion between what is artifact and what is evidence. So, artifacts are the raw, non-correlated thing which aids an investigation for correlating the things and opinion. Yeah, for opinion purpose. So, um, before analysis, entire thing is artifact only. So, we will be extracting the artifacts. First artifact, first collection will be creating a disk image using forensic tools, using write blockers, creating a hash value of that. Every stage will be there will be a comparison of hash value of created and stored hashes in that. And after collection of artifacts, we will be using multiple forensic industry-level tools for analyzing the things. Now, analyzing and examination. Again, people get confusion in analyzing the things and examining the things in digital forensics. Analyzing is straight away giving keywords, correlation patterns to the tool so that he can analyze within the collected artifacts. Now, he will throw out some outputs onto our console, onto our tool, telling that these are the keywords which I identified on multiple locations. These are the registry values which you were finding, and I found it on multiple locations. These are the analysis which the tool gave us. Now, here, manual intervention starts, wherein an analyst sits on that PC and does the examination part. Now, examination is very important because many people in digital forensics believe that forensics is entirely a tool game. So, so I wanted to specify here, tool plays only 10% of the role in digital forensics. Entire 90% of the role is done by a forensic examiner because tool, tool is just a helping hand to understand, to get a clear GUI format of the artifacts. Now, examiner, what examiner does is that whatever analysis part is thrown onto the console by the tool, he creates a timeline, analyzes the entire thing, correlates, creates a timeline framework, and he, with this, the examiner tries to recreate the entire crime scene. And evidence is one thing which supports correlation between multiple log sources, correlation between multiple events, correlation, multiple users. Then only he will be able to recreate the crime scene. So, this comes under examination. Now, after examination, he comes up with a recommendation or a conclusion, telling that key, after analyzing these type of evidences, I came up with these artifacts, I came up with these evidences which supports this crime. Now, the case is solved. Now, he has to submit the entire thing to court of law or to the investigation agencies. Now, the catch comes is that no court, no legal authority will accept that without a proper documentation.
M >> Chain of custody, panchnama, seizure memo was a part of documentation. But other than that, what happened from seizure to examination, everything should be documented. Visited to the location, collected the PC, I saw this person sitting on that PC, he was using this password, we collected on this time, we created, we generated panchnama, we generated seizure memo. After the chain of custody started, we stored this particular PC here, came to forensics, and after receiving the devices in the forensics, many steps are there before it is getting to the table of the analyst, like storing, imaging, alerting the case to that particular case, allotment of a particular examiner for that particular case. These are the documents which are required to submit that particular evidence in a court of law. So, documentation is also important. If there is no document, no court will trust you for that particular evidence which you have created in last one month, two months, three months. Your hard work will be neglected in court of law. There's the importance of documentation. Now, after documentation, you have to have a skill of presenting the entire thing in front of people.
>> And this is where the communication skill matters. >> Yes. Yes. Yes. Because when you are addressing the things in the court, your audience is judge and advocates. They are not so technically strong. They don't understand the technical jargon of cybersecurity. You can't, like, you can't mention that volatile memory was having a remnants of credential. They will not understand. So, you have to clearly mention that RAM was having a password saved in it. Simple. So, in this way, you will be able to gain that trust. And once you gain that trust, they will trust your evidences and cases. In that way, they can, the case proceeds. Now, when you are addressing the entire thing to the case, again, subsets of presentation comes in, wherein the court seeks for four points: like integrity is to be maintained. That is with the documentation, hash value, imaging, right blockers. It will be matched with that part. Repeatability is very important because if you have mentioned some evidences by correlating for particular artifacts, and you are strongly telling that this is the evidence which I came up with, and this supports this crime, and we are recreating the entire scenario. Now, judge can order a separate investigation with a different investigator. So, your case will be, must be repeatable, and the same evidence he should also get. Then only it is repeatable, otherwise it will be turned down in court of law. Third is, you, you should have a legality. Legality with that case. Like, wherever warrant is mandated, you should have, suppose if you want to confiscate a personal device, personal phone, so you should have a warrant. Without warrant, you can't. If you want to have an investigation, prima facie investigation, like opening your galleries and all, again, you have to have a warrant. So, these are the legalities which court of law mandates to a part of presentation. Now, after that, skill, again, calm skill, soft skill also comes for fighting with opposition advocates and all. So, these are the multiple steps which are involved starting from a seizure to a trial in the court.
So, sir, there's a lot of buzzword around, you know, make a career. You know, it is easy to make a career in, um, you know, pentesting, or we have a lot of career videos on on SOC, a lot of career videos on GRC. But there's much videos on how to make a career in digital forensics. And when it comes to the digital forensics part and all that, you know, there's a very limited resource we have. And there's a lot of young people, they want to enter into DFIR, but what is So, what the very few actually >> make up >> make into that particular field? And and why there's an entry to DFR is so difficult compared to SOC and pentesting?
>> So, uh, >> And we need to know the exact blueprint because if any student is watching this video or listener watching this video or listener listen to this podcast, might be he having a copy pen with him.
>> Yeah. And what is a roadmap blueprint to make a career in forensics?
>> Yeah. So, as you mentioned, accessing SOC, accessing pentest is easy as compared to digital forensics. So, digital forensics is huge. Why? Because it mandates the expertise required as a pentester, as a SOC, as an incident responder. Finally, as a forensics investigator. First thing. Second, getting into DFIR, you have to have a perspective of an investigator along with patience that lacks with new generation people because they want a quick result. That's the first challenge for them to enter into digital forensics because they are result-oriented, and the forensics field is not easy to get a result. You have to wait, you have to analyze, you have to rethink because it's not necessary the way you are thinking is the correct way the attacker thinks. So, you have to change your thought process to derive to a result or to solve a case. So, that's the second challenge. You have to build this capability to get into forensics. Third, learning curve is very high. Learning curve means you have to thoroughly, you have to have a thorough understanding of operating system, file system, network, um, cloud, legal. The entire thing makes up digital forensics. As you mentioned, pentesting is one vertical which is required for digital forensics. People are expert in that. Now, that doesn't mandate that he is an expert in digital forensics. Again, getting into SOC operations is directly easy because you are dealing with logs, dealing with the network traffic. You don't have to have an exact understanding of what the operating system is doing because an L1 in a SOC or L2 deals with logs. So, again, that mandates as a requirement for digital forensics, but only having a SOC exposure will not certify you as an investigator. So, it is very easy as a straight career to enter into SOC and pentesting, but you have to have multiple expertise in different fields to combine as a digital forensic investigator. That's the third. Fourth thing is that the tools used for investigation and forensics are very expensive, which are way beyond the reach of normal students.
Do you not have any open-source tools? Like >> We have open-source tools like FTK also provides light, FTK Lite for imaging. Autopsy is there. SIFT tool is there. But again, for a better visibility, capability-wise, each and every different tool has different capabilities. So, we have to have multiple tools to have hands-on. And the important thing is that whenever you are entering into a forensic environment or forensic industry, they are asking tool-based experiences, which is not in the capacity of a student to have the hands-on experience. Again, that is a challenge. Now, uh, uh, to have that hands-on, many organizations are providing internships. Internships are there which exposes the students to address high-profile cases, to handle sophisticated tools, to have a, again, the next challenge is we don't have a big matured forensic labs addressing students' requirement to get into digital forensics. So, these are the challenges which mandates a student to overcome to get into forensics.
>> Okay. And and when you're talking about the learning sequence, >> how to start? Like, okay, like when we say in cyber, we say network fundamentals. As we're doing a forensic investigation, we starting with the computer forensics. So, what is a learning sequence? You know, I know you cannot directly go to investigate. >> But what is a learning sequence we need to consider?
>> Okay. So, so a student graduating. >> Yeah. I'm in front of you. I'm a BA pass. >> Yeah. >> I'm not talking about you. I'm a technical. I >> Is it possible the technical guy can, non-technical can do the forensics?
>> Absolutely. Absolutely. Again, the only difference between a non-technical guy and a technical guy entering into digital forensics is the prerequisite of understanding a computer. The only thing if a technical graduate, um, or doing a B.Tech or M.Tech and getting into an industry, he knows how a computer works. A non-tech guy after doing a graduate in BA has to spend some time to understand how a computer works. That's the only difference. Other than that, it's core curiosity and an investigative perspective which makes a man a perfect investigator. First thing. Second thing, to as you are asking, what should be the roadmap? I always suggest to pick any two operating systems, like Windows or Linux, or Windows and Apple system. Study thoroughly.
>> Why two? Because, um, see, why two servers are running maximum, mostly on Linux? >> Windows >> Client side. >> Yeah. Client side, most of the side Windows are there. Many less, there are many less opportunities wherein you will be having an opportunity to work on Mac system for forensics. True. So, so you can choose two systems because Linux, why I'm preferring Linux over Mac system? When you are doing, when you're learning Linux, you will be having hands-on on scripting, hands-on on Python, hands-on on Bash scripting. That will add your capabilities when you're going into digital forensics because that requires as automating the forensic tools for getting the artifacts and all. So, so you can choose two operating systems. Study thoroughly.
>> What need to be studied in that?
>> Yeah. Okay. When, when we are, when we're talking about Windows operating system, operating system internals, how files communicate with each other, what is the power of registry, how registry manages the entire operating system, what all are the important locations which contributes maximum towards the working of the operating system. How users are created? What all are the registry keys affected when a user is created? What all, simple, the most common thing which we do, which we mostly do in our operating system is copy-paste. What is happening when we are doing a copy-paste? What all our registries are affected by copy-paste? Okay. Recent jump list, cache, shim cache, shell bags. These are the things which gives you a juicy information what is happening around an operating system.
>> Okay. Yeah. Second. Now, going one step ahead, once you identified how systems are working, now you have to think in an attacker's perspective, how things can be hidden in these type of areas.
>> So, some for some pentesting skills you need to, because in order to think like an investigator, you also need to think like a hacker.
>> Hacker, exactly, exactly. To defend, you have to have an understanding of how to exploit the things. So, um, so basically, what attacker's perspective is, whenever he is getting into a system, the first thing he does is maintain a persistency. So, what all are the locations which contributes towards the persistency, like run keys, startups, user-based persistency, system-based persistency. These are the areas which the attacker uses for maintaining the persistency. Now, once the persistencies are made, persistency, like if I mention a run value, it only gives a value which triggers an EXE which is again stored in some different locations. So, you will get a path to reach there. So, these are the correlations you are required to understand within an operating system. Where the logs are there? If I take an example of Linux, where logs can, the entire logging system is there, you have to have an understanding of how to interpret that logs. This is operating systems perspective. Now, choose any two OS, master that two OS. Now, come to network. You should have a thorough understanding of fundamentals of IT. How TCP/IP works, how DNS works, how firewall works, IDS, IPS, because this will contribute for the correlation when you are doing a forensic analysis. Okay. Second thing, third, you have to have an understanding of legal aspect of having a case. So, um, so when you have these two understandings, you will be able to correlate legally. So, legal in the sense that is not directly contributing the forensic examination, but indirectly when you are going for an admissibility in the court of law. So, legal legality mandates that you should have some certificates, you should have some documents, you should have prerequisites when you are submitting the entire thing to court of law. So, on that aspect also, he is required to have a knowledge and calm skill and presentation skill and soft skill to present the entire case in front of non-technical, non-technical, and non-technical background people. So, uh, you, any student who wishes to get into digital forensics has to go through these four verticals, master them, and, um, because these are not small verticals, he has to spend sufficient amount of time on each vertical to understand. And it's not, you start with OS, complete OS, then network. It's not required. You can have hands-on hand in hand, parallelly to master the things with a, you, the two things which you have to maintain across this is persistency, consistency, and >> discipline, which includes patience.
>> I agree. >> Yeah.
>> And and coming to the part is, do you recommend any books for the beginners who want to go through forensics and all that? Any books you have to recommend?
>> Yeah. See, ma'am, truly speaking, for TCP, I haven't referred any book as a mandate to study for forensics. But again, for understanding the network, I used to study TCP/IP Illustrated, Volume 1, Volume 2. For operating system, I used to refer Windows Internals and Windows Internals. For Linux, I referred RSE and RCSA. These are the, these are the
Verticals wherein I tried to learn the things going for a CCNA, CCNP because there is no single book which will lead you to digital forensics. That particular book will lead you how to approach for a digital foreign, but you have to have an understanding of different things to address that book or to understand that book.
Excellent. And the person who comes from a background who has a very limited budget and wants to learn forensics, as you said about these are the basic fundamentals are required. Now in pentesting, now we use the backtrack Kali. Uh, for doing malware research analysis, we have Gira. Yeah, Gira is there. Raptor is there. Yeah, Velocity Raptor is there. Do you recommend any beginner-friendly tools they should use? And, uh, there's a lot of, uh, pcap files are there which we use for network forensics and all that. So, do you recommend any user-friendly tools in the initial stages which students can practice and do the investigations? Because not everyone has, question, not everyone, not everyone has a privilege. Yeah, yeah. To have those machines and product.
Same on my side. If I talk about myself, when I started, uh, I was not having any exposure to any sophisticated or expensive tool. What I did is, I set up my lab on my laptop or a desktop with small, light tools like Autopsy, which is the best tool to start with for a new, uh, beginner. Uh, as you mentioned pcap, you can have Wireshark to analyze the network packets. You can have a lab wherein you will be having one side, you can install SIFT, which is by SANS, which also gives maximum capability to analyze and do forensics on a Linux machine as well as for a Windows machine.
What, what is the name of the? SIFT. S-I-F-T. SIFT. Okay. Mhm. And what was the computer configuration when we used this for investigations and all that? It was, my hard, my desktop was 8 GB RAM then and 500 GB hard disk with i5 processor in 2012.
Goes into it. Okay. And do we have, like the way we have TryHackMe and Hack The Box nowadays are available? Do you have any kind of these online labs for forensic practice?
Yeah, it's there. SANS also provides free. It's, yeah, it's a December one is free. Okay. Yeah. The CTF they sponsor the CTF in the month of December that is free. Uh, and many more opportunities are there. CTFs, hackathons happen. Hackathons are a single day, one full day, they focus on digital forensics because it's a young area.
Earlier when I was doing forensics, we never used to have a privilege to attend any conferences with respect to forensics. We never had visibility with respect to podcasts or conference videos. We used to learn from. There's no problem. Our videos were there. So, so accessibility for students at this stage is huge. So multiple videos are there, books are there, conferences are there, CTFs are there which focuses primarily on forensics. So there are multiple platforms wherein they can, they can evaluate themselves hands-on for forensics.
And it is an interesting question because it is a follow-up question for this, you know, how was forensics 10 years ago and now? Like, you know, the reason of asking this question is, uh, initially there were limited resources, but along with that, we had limited functionality. Absolutely. We don't have cloud that time. People are working from office, but now we have a hybrid workforce. We have, no, we have geo access. We have, uh, people are working remotely. We are using cloud. So what technologies changed the field the most and the challenges we have seen 10 years back and today, or what is the transformation you have seen in forensics?
So earlier, as you mentioned, technology was not so expanded, uh, across many verticals. So when I was doing forensics back then, uh, back 10 years ago, if I take an example of logs, the capacity of Windows maintaining a log was 4 MB to 20 MB. So we just have to go through that 20 MB of logs. Storage was limited. We just have to focus on 100 GB of copy disk. Yeah. On this concept and memory was also very less. 2 GB was maximum, 4 GB was maximum. So, uh, it was easy, but again, encryption was not there. Floppy disk, we can, we can remove it and we can proceed, process it as an evidence.
Legal challenge was that, before this, IT Act coming in in 2013, 2023, before that, electronic device was not presented to court as a primary evidence. It was a secondary evidence. So that was also a challenge. Now, it was easy then with compared to, uh, present scenario, because present scenario challenges are many more. Storage increased terabytes of storage, we have to scan, uh, for investigating in, uh, logs. Earlier logs were of 4 to 20 MB, limited security logs were there, application security, minimum three to four logs, logs were there in event logs. So registries were less. So that entire thing shifted. Uh, in the present scenario, multiple terabytes of storage are there, event logs, and there is a capability of log forwarding. You can have retention of four to five years logs in a SIEM solution or a SOC solution.
Cloud-based challenges in cloud-based is that clouds are spread across geographical locations where in physical server access, yeah, physical server access to mil, again, jurisdictional laws are there. For example, a country A's data is not accessible by country B's data, and everything is hosted on country A's data center. So that again, a challenge. So challenges are there, and AI coming in, deepfakes coming in. Um, these are the challenges which will be there and which, um, which, which is there at present and which will be there, which will increase the, uh, capability of expert investigator as well. And see, when I am addressing AI, it is a two-way sort. You can use it for destruction, you can use it for investigation purpose also. So it depends upon the investigator how you want to use it. Or because we are also, many tools are coming with AI features, but again, manual intervention is required at a large scale to, to correlate the things.
Practice. Uh, there's a way to drive the car. One is you read the book and drive the car, and when you actually drive the car. Exactly. And we never learn car on a, on car classes until we don't buy our own car, we don't learn from that. So outside the textbook, the real world is always messy. Yes, because textbooks talk about static knowledge, whereas, uh, the real life talks about dynamics. So what is the hardest part in your life when you're dealing with forensics? Like handling the evidence integrity, or we talk about data lacks, or you talk about lack of logs, or chain of custody, pressure from management? So what do you think was the most toughest thing you have faced and how you overcame that? And do you share any case study on that, any, without revealing any confidential information?
So, so the biggest challenge, globally, what digital forensics is facing is the backlog. Backlog. Can you just explain that? So, so as I mentioned, the stages, getting a device from a configuration site to digital forensics, still we spend more larger time on migrating that or transporting that from the site to a digital forensic lab, if it is recommended for, to have a digital forensic investigation. Now, because why? Because there are multiple stages to bring that devices. Initially, law enforcement IR team goes there, raises a panchnama, then it is handed over to law enforcement agencies. Law enforcement agencies present it to the court of law, then they will mandate for some, for state-sponsored forensic labs. Then, uh, then it will be communicated to them and transported to the forensics lab. So this requires time. So, um, and digital forensics is a field wherein, the more you lose the time, the evidence credibility also loses, because delayed justice is again, it's not addressed. Exactly. So that's the first challenge. Um, that's what I was mentioning. And again, coming, if, if at all that device is received at the forensics lab, and there will be a backlog in the forensics lab. Multiple cases, cyber cases are addressing. So many cases are there. So to get onto that particular case again, is a challenge. So these are the two big challenges.
Other than that, when you receive, as you were mentioning, uh, use cases. So, uh, there were multiple use cases which, which I personally handled, which were of a sophisticated nature. Like, if I want to start, uh, the use cases, I will start with the thing which most of the attackers use, that is phishing. Okay. So phishing is the best thing an attacker can use to deliver the exploit to the victim. So how they deliver? So I had a case wherein a person, wherein I had a complaint from an IR team, telling that a particular PC was compromised and he is exfiltrating the data to the C2 server. When my IR team responded to that, we received, uh, we found that a, a person or a front desk employee was at a reception counter was handling a PC. And when asked, he, when asked, he said that she is only responding to the incoming mails and just opening the mail because she was handling a reception and reception was supposed to receive registration forms. So she was, she was handling that thing. So when we asked, she, she was, she told that, I never clicked on any link, I never opened any malicious thing, and as usual. As usual. So, so we confiscated, thing, confiscated the PC because we trashed that in the incident occurred on that particular PC. So we removed that from the network, taken the image, and confiscated the PC, brought that PC to our lab. When we started imaging this and started analyzing and examining these things, we came to know that morning hours, she received a mail XLS file attachment wherein the, the name of that file, yeah, the wherein the name of the file was registration membership form. So he clicked on that, and this script got run in behind, and the entire system, the first stage downloader, second stage download, the entire system got compromised, and she was not knowing anything of that nature. And from last 3 to 4 days, the entire data was exfiltrated to the C2. This is one of the phishing, uh, case which I encountered.
Second, I will take some different scenario, that is social engineering. Uh, again, that is again an interesting field for an attacker to lure some user for credential harvesting and exfiltrating the data. I received a same, same on same line, I, we received an incident telling that a system is compromised. And when we got that device for forensics, we identified that, uh, some, some attacker responded to a person on a WhatsApp and he lured, some, he lured or he convinced that particular person to install that application, and the same way, his mobile got compromised. Next time when he contacted, when the attacker contacted, he convinced again, he convinced the user to download laptop version of that particular application on that laptop, and he also got convinced, he installed that fake or malicious application on its laptop. It laptop also got compromised. So in this way, phishing and social engineering, these type of cases. Again, but as I mentioned, no, no attack will be completed until and unless you have consent from the user. So it is very important to educate the user on that part to identify any malicious or any, any attack vectors which he is encountering or he, she is encountering on a day-to-day life.
Sir, my next question is a, uh, very interesting question because, uh, not everyone covers in the podcast. So I thought it's a privilege for me to have a question from you. Uh, you know, many analysts, many analysts don't realize that your final audience is not a CISO. Because if you, you are a CISO, I know you are a CISO, you know security. I will prepare the report according to that. It is often a lawyer or a judge. So what makes the digital evidence inadmissible in court? What are the parameters and how do you defend your investigation in a cross-examination? Two questions.
Yeah. Okay. Uh, so admissibility of evidence in the court of law is the most important part because if you do a process and that is not justified in a court of law, the entire process is of no use. So, uh, so addressing that is very important and is to be addressed in a nature wherein non-technical persons, layman language, should be addressed so as to, so as to bring the truth to them. Then only they will be able to give a justice to, uh, to the case. So when I usually tell the people or tell the students that when you are handling a digital forensic, don't consider it as a case. I take it as if you are handling a life because you are one wrong or misinterpretation can cost his life or his reputation. So it is very important to, uh, to seriously address this issue.
Now, coming back to your first question, admissibility. Uh, court mandates, before before going into the trial, court mandates multiple documents. So as we were discussing earlier, two, three documents are, Caesar memo, panchnama, digital forensic investigation request, required warrants, chain of custody. Other than that, as per, uh, the latest Bharatiya Sakshya Adhiniyam, which is evidence act, as per that, you should have a certificate under section 634C or B, which mandates, uh, the admissibility of electronic evidences in the court of law. Uh, there is a difference between, uh, two certificates. Um, if I refer, uh, 634C or 4C, it is to be presented by subject matter expert. B can be produced by anyone who is handling with digital device for the extraction of any evidences. So, so earlier it was not there. Earlier it was under section 65B, which was only a single certificate, and it was not a clear communication who will be presenting it. Whether a person not having any digital forensics expertise or background can submit evidence to the court of law, or is it to be submitted by subject matter expert only? So in, uh, latest evidence act or Bharatiya Sakshya Adhiniyam 2023, they came up with a clear clarification that any person who handles a computer or extracts any evidences out of it can submit 634B. Now, if court thinks that despite of admitting a evidence, if the court requires to have a thorough investigation, then he can again forward that entire case to a forensic laboratory. Now, the forensic lab, court actually recommends to forward the case to the state-certified forensic laboratories. Now, state-certified forensic laboratories are considered to be the subject matter expert. They will be using the form 634C. So, these are the two certificates which are also recommended, uh, along with the, uh, evidence admissibility in the court of law.
Okay. Okay. So the, and the most important part after admitting these three, the, when the trial starts, the most important thing is to address the, uh, opposition advocates because they will screw you up asking. Great example. Uh, not revealing confidential, but, yeah, yeah. Uh, I had a privilege of addressing a court for the digital forensics as a subject matter expert, wherein, wherein the advocate asked about the modification time. Now, in forensics, you have two times, MAC time and file time. What is that? One which is not editable by the, uh, normal user, and one which, which we can have a modification or what. So we generally give the MAC time, birth time, create time, modify time, which the file system maintains. So he started interrogating me with respect to time, and he was not having a knowledge of that MAC time. So then next one hour, I was teaching him what is the MAC time. Then he convinced, then he got into the second question. So they, as I mentioned, they will not be having the technical knowledge to understand or to smudge what you are talking of, what you want them to understand. So as I mentioned, when, when my report reflected that we found some remnant of credentials material in volatile memory, he again started questioning, what is volatile memory? How you can define it as a volatile memory? How you can define it is a remnant? What is the definition of a remnant? And what type of cred, how you define credential material? So these are the questions which you have to face, and you, in this part, your calm skill and soft skill, is used to address the entire non-technical audience to make them understand and recreate the entire scenario in front of them so that they can have a correct judgment with respect to the case.
Okay. And, and if I want to say in short, precise. Mhm. These things always you have to follow when you're presenting the evidence in the court. So what are those parameters? See, um, the entire precise. Precise. The, so the entire step is very important. You can't miss a single step. You can't. But one, there should be one framework which should be common for all the. Yeah, yeah. Talking on that line, if you are asking about the standard, there are 27035 standard which talks about handling digital evidences with respect to the admin. That's fine. I'm talking about here, not that standard, but a common practice. Is, you know, like, example, when I teach CSSB, I say, okay, first I will cover the content, then I practice the questions, which I follow for all the trainings. Any incident has to be reported, it should be reported by the user. We validate it. It's a common practice. So these, this is the common framework which we follow to present the evidence in the court.
So, um, on a legal aspect. On legal aspect. On the legal aspect, uh, following evidence act, correlating the entire thing with IT Act, then only it is admissible. So when I was talking about the electronic evidence admissibility, that is covered under IT Act, and how that is to be presented in the court of law, that is covered in Bharat Sakshya Adhiniyam. So these are the two baseline documents which we have to follow, which covers the entire thing, raising a panchnama, how we should raise, what, what should be the content of that, when we are raising certificate with respect to section 634C and B, how we have to mention the hash value, how we have to generate, who will sign it, whether we have to show up our inventory or not, who is the authorized reviewer of the report, who is the authorized releaser of the report, the entire thing is covered by these two things with respect to the legality aspect of admissibility of evidence in the court of law.
Excellent. And that's why I have a follow-up question for that. You know, handling evidence is not about skill. Yeah. It is about discipline. It is in the same way, you know, handling a partner when angry and all that. So what does, what does the ideal evidence submission process look like?
Okay. From a step one to step 10, or whatever steps. Yeah. Yeah. So when we talk about the admissibility of, uh, uh, the evidence in the court of law, you have to rethink the entire process what we followed, uh, from Caesar to this. First thing is that you should have the documentation. If documentation is not there, uh, your admissibility, uh, will be rejected. If you don't have warrants in place, your admissibility will be rejected. Integrity, the most important. The first question which court asks is to, to prove the integrity of the device. Uh, that can be, uh, with respect to the hash value you generate, the right blockers you use at the time of acquisition and image creation. Repeatability, you have to prove the repeatability of that thing. Legality. When, when I talk about the integrity, there are multiple stages to prove the integrity. The documents which contribute to showcase the integrity, chain of custody, hash value at the time of confiscation, at the time of imaging, proving the correlation of the images integrity with respect to the industry-level tools you are using. It should be licensed. It should be registered on the lab's name. Certificates should be valid. These are the main challenges which we face when we are admitting, we, when we are at putting the evidences in the court of law, and the court only asks three, four points: integrity, repeatability, legality, and documentation.
So, okay, fine. But we understood this is best practices. What is step one? Like, you know, okay, we are doing a transition of the evidence submission from the office to the court. Yeah. What is the first step? Like, once we collect, sort, everything has been done. Okay. Now we are preparing the evidence to be submitted in the court. Okay. What is the ideal process?
Okay. So forensics lab never submit the report to the court of law. Okay. Uh, you can see forensic lab as a helping hand to the law enforcement agencies. You are never directly involved with any user, any victim, any attacker, any agencies, any court. Fine. So the case comes to you through law enforcement agencies or investig. In India, if I take an example. Okay. India is an investigation agency. IB is an investigation agency. Police departments is a law enforcement agency. They can forward the case. What about the private? Private can also. That's what any IR team or any organizations have their own IR teams. Uh, they, as a part of, see, where the digital forensic comes in incident response. So we have got multiple stages in incident response. So when the eradication stages come, when it mandates the recovery of root causes, cleaning of root cause of that particular incident, that time, incident team will recommend that particular incident for forensic investigation to identify the root cause analysis. That's that's when a forensic team pitches into an incident response. Okay. Thing. Now, for, in, for forensics, this incident response acts as a sponsor of case to, uh, forensics. So this is a law enforcement agency. This can be a law enforcement agency. This can be an incident, private, uh, private organization having an incident response team within their organization. So digital forensic team will help these teams to get a conclusion or to find out a root cause analysis, finding out the IOCs, finding out the root. That is done. That is done. Now, now they will now they will transfer the entire case along with panchnama, chain of custody, and, uh, the certificate. Forensic team. Forensic team will submit the entire thing along with that particular certificate 634C or B to. From where we get the certificate? You can download that from Bharat Sakshya Adhiniyam 2023. An is there, 634C and B. C is for, uh, yeah, C is for subject matter expert, which are issued by the forensic labs, registered forensic lab. So what we do, we, uh, we, uh, give a report. Initially, we submit an executive report, then final, we, uh, provide an full through exhaustive report of that particular evidence, forensics to investigation agencies or IR team.
Okay. Here I want to stop. So when you say forensic lab approved forensic lab, what is the meaning of this approved forensic lab? Okay. There are. Sorry, guys. Uh, it is a very interesting part, that's why I'm interrupting my speaker. Yeah. Yeah. There are two types of forensic labs in India. One which is privately owned labs. Second, state, uh, owned labs. And state-owned labs are mandated to have a certification from Ministry of IT, uh, as a registered, there's a word called Examiner of Electronic Evidence. Okay. Triple E. The candidate has to pass the exam also. Oh, yeah. Same like forensic for fraud examiners. Yeah. Exactly. But this, this Examiner of Electronic Evidence is a, it's not an individual certification. It's for a lab. So, um, I, Ministry of IT mandates the certificate for that particular lab. And once you are certified, you are eligible to have an entire scope to be presented to the court of law. And court also mandates cases to state-owned labs only. So we will be submitting the entire thing along with certificate to the investigation agencies. Now, if I talk about private lab, they can also do the same thing. They can also submit the entire thing along with the certificate to the investigation agencies or IR team.
Okay. Now, credibility for both the evidences which the forensic labs is providing to the law enforcement agencies or IR team stands same. But in court of law, what Supreme Court mandates is that if there is an case which a state law enforcement agencies like IB, ME, or police department or any cyber crime police is handling, they mandate that this to be, these to be get forensically analyzed by a state-certified lab. Okay. Not every case, but if you think it's a critical case where national, national crime is involved or something critical is involved, we can involve. Case other than if, if an organization plans to go with a private lab, they can also go with a private lab. Like we had a GPS spoofing and all that, they want to investigate. So they prefer to have a government-approved labs instead of having a private lab. That depends upon the criticality and how that incident is going.
Now, coming back to your question, we submit that particular report to the law enforcement agencies. Now, it's their call to go with that report to the court or not. If an organization internally sorts out, uh, depending upon the recommendation of the digital forensics, then they can close that incident there and then, no need to go to the court of law. Now, if you want to fix someone or fix some process or fix some particular thing which affects their credibility or reputation, they go to the court of law. So that is their decision to go, uh, to access the legal aspect of.
In which condition things get sorted internally, in which condition they go to court? Any idea? See, when there is, see, with my background, I haven't came across such things. But yeah, the cases wherein there is a reputational, damage, damage, you can sort it out. Yeah, compensation, you can settle down out of court type of thing. When you are violating copyright, when you are violating patents, if you require, if the damage is beyond the payment condition of that particular person, then you can have an accessibility to the court of law. Otherwise, these things are adjusted outside the court. And when you are, when you are going ahead for, uh, clearing the things out of the court, then you won't be requiring a certified lab to do digital forensics. True. So they will go for a private lab, private type of thing, a private setups. But once it is in the trial, for any high-profile case or a high reputational state case, they prefer to have a certified government labs.
Okay. So this is the way how the evidences are presented to the court. Uh, digital forensics labs never submit anything to the court of law directly. They submit the entire thing to the law enforcement agency. Law enforcement agency files a case with the court, and if required, if court feels that we will be, we required to have a subject matter expert to define particular things or explain particular thing, they will be asking for presenting the same with any of the subject matter expert from that particular lab.
So, not, not in every case, we need to involve the team. If the, the advocate can able to explain, it will be great. Exactly. And I think this is where the opportunity comes where the GRC professionals can appear, prepare for LB and all that. And the future, it's, it can be a very good combination because. Correct, correct. Because, uh, India also providing cyber law courses. Courses. And but degree is different because, yeah, degree is also different because LL, after doing LLB, also people prefer to specialize in cyber crime law, so that particularly defines with cyber laws. M. So, so this is how the entire process has a submission. So, but when you're doing the submissions and all that, uh, we're talking about the very important part is logs and artifacts. So have you seen something as routinely ignored on regular, like, you know, something like while submitting something, they do some mistakes, and does it create a turning point for the investigations?
Yeah, that's the, that's the challenge when we are addressing a digital policy because as the technology is evolving, every crime comes with a new technology. So we had an opportunity where in a particular case, it was very difficult to, uh, find out the traces because of use of anti-forensics techniques, clearing of the logs. These are the challenges which we face while, while performing forensic investigations. Many attackers are smart enough to clear out the traces. They clear out the logs. They clear out the applications. They uninstall the applications. They swipe the memory. Uh, they, they move the entire thing to the cloud, and clear the PC. You will not get any traces that anything was moved to the cloud or not. So encryptions. So these are the challenges which comes when you are addressing the things, and you, and here your expertise and skill works, yeah, matters. So that, that's what I was mentioning. These skills which are required to address these type of situations never comes with a bookish knowledge. You have to have a practical, hands-on experience to address that particular situation. That's why I said that no one can, you know, if, if you want to have a thought process and all that, let's learn practical sort of things.
And this is the last, second last part of this podcast, and it's a very interesting thing, and I, I personally want to know this process. Let's break down the few cases, high level, we can anonymize the data and all that, but with real lessons. Okay. So do you have any real use cases you want to discuss where, you know, talk about this forensics, like we had this coverage MFA push notifications or C-scout and all that. So do you, do you wish to share some thoughts on that?
Yeah. Um, as I mentioned, from last 7 to 8 years, I've been into this field, doing hands-on forensics. So I have multiple use cases, multiple cases which invoked the challenge and which invoked the capabilities within the analyst and examiner. Some of the use cases are coverage push notifications. What is that all about? Yeah. Uh, C-DAC is an application used by Indian government, NIC, for as a multi-factor authentication. So it's, it's available in open source also. So AP36 group, which operates, uh, from, uh, target country, they targeted government officials using NIC mail ID, by, by exploiting the push notifications feature.
When this happened? Uh, last to last year. Oh, okay. Uh, 2022 and three. So, so we used to get multiple incidents wherein, wherein notifies that particular NIC mail ID is compromised. You have to get an investigation on that and you have to submit a report for that. So whenever there is a credential leak type of thing, we generally focus on phishing or social engineering part of thing. What happens is that you will be, you will be given a malicious link or a suspicious link wherein you will click, and some login page will appear, and the attacker will trick you to insert your credentials there, and in the way, they will have access to your credential or mailbox. So, uh, so with this mentality, we approached that case, and we, we analyzed around 50 pieces, and we never, uh, got a success to break through how the credentials are reaching to the attacker. So there is no trace at all in the PC. There is, user is telling that, key, we haven't accessed the mailbox for months. How it is getting compromised? I don't know. We, we, and, and we had a mailbox forensics, we had network forensics, we had computer forensics. Nothing is coming. Nothing was coming up. So we started and started thinking in a separate way by analyzing not only the PC but also the applications. So we installed, we had a simulation within our office. We simulated the entire thing, then also nothing was coming up. So we started thorough analysis of C-DAC application, and we got a support from SANS as well. There was a feature called push notification, which works as same as Google. Whenever you try to open a Gmail, it sends a code to your phone. You can just say access, approve or disapprove. So the same way, if you are not able to put the OTP in that, you can have a push notification. It will give a push notification to the users or registered mobile number. You just have to accept it, and the mailbox will open. So attacker was using this, uh, push notification to, uh, to get the credential. They were simply creating a chunk of push notification to that particular, and he was overwhelming the user and irritating, and the user's patience. So most of the people ignore that, and they, they come to a mind state, and that's the moment wherein the attacker gets an access to the mailbox. So, so that was a great breakthrough, which is already available by in this open sources, and many different organizations have done their analysis on that part. And multiple, it's not only push notification exploitation, but again, C-DAC was exploited. C-DAC was exploited in a many way because there were one, one report in open sources, we also had analysis on that part, wherein upgrade, update to that particular application, update to C-DAC.exe or APK was released by adversary countries and leveraged the Google ad to get that on the top of the things like malvertising type of thing. Whenever you, whenever you type C-DAC update, the first malicious link will appear. You click on that, and how that modus operandi was working? Whenever you click on that particular application or fake link, uh, .exe will drop to your download, and the moment you click on that particular .exe, thinking that it is the genuine thing, it will create a genuine link to the NIC and download a genuine .exe and will run a genuine .exe. You will not be having any fear that, key, everything is working normal, because it is creating a genuine request to NIC, NIC server, and downloading a NIC, legitimate NIC, C-DAC application. Now, what is happening in the background? When you click that particular malicious .exe, it was dropping a JavaScript which runs behind, acts as a first load, first stage downloader, downloads the two, two or three applications, two or three .exe, including one PowerShell from the C2 server. And one, one PowerShell was there, which was creating a persistency in run once, and downloading the second stage downloader, which communicates with the C2, C2, and receives commands from the C2. And what it was doing? It was capturing the entire keystrokes, scanning through your directories, encrypting the entire thing in chunks. You will not be able to identify what are their.
How did they find this vulnerability? Uh, yeah, it was reported to C-DAC, and they patched that, and they turned, took down that particular application from, uh, web. That was not a vulnerability in C-DAC. Okay. It was masquerading the. Real user. Real user, telling that .exe. Okay. Because NIC rolled out advisory telling that, we are providing a major update to our application. You can download it from net. And people were doing C-DAC update, not going to the genuine website. They were Googling that, and whatever coming for the first link, and they are clicking on that. And this was the second use case, exploiting the C-DAC. Third use case is CV scout. It is not in open source, but again, targeted by AP group, AP36, which leveraged the employees for creation of CVS.
AP36. AP36. So, so what the modus operandi of this type of attack is, the operators contact you for the creation of CV. Okay. Yeah, CV. You will upload the entire information to them for creation of the CV. Uh, that is not important of uploading your detail, uh, for the creation of the CV. The important is, they will accept that thing, and they will create a registered, registration, um, the same way you register to any portal for logging into that system. They will send you the user ID and password to login and download the prepared CV. So what the user will do, he will click on that particular website and log into that portal. Now, your CV is ready on that portal. You can just download the thing. But that particular CV hosted there is a malicious PDF file or .exe. So you mean to say that you share your information, they make you feel, okay, this information, they convert into CV, and they provide you PDF, right? Correct. And they download the PDF, they run the PDF, and that boom. Bus. Oh, okay. And, um, not even, not even that, by downloading that, they, they identify from which device you are operating. Based on that, they will serve that .exe or they will serve the APK. So once we got a content. So once they identify that it's an Android device, if they, they don't, the attacker don't have the capability to compromise the Android OS or Apple OS, what they will do? They will again convince that you will not be able to read that PDF until and unless you login from your laptop or desktop, Windows PC. So they will convince the, uh, user to login from their desktop. That way, they, uh, lure the user to download the CV from the desktop environment. By downloading their CV, scout, APK or EXE, then they will compromise that well, that as well. And the capability was, uh, again, the same, get, uh, exfiltrating the entire data, running through your USB devices, if connected, if you, if you're connected to a network, they will travel to your network as well. So my, that was a peculiar type of thing which we encountered during our investigation.
Oh, okay. And, and there was a trap regarding the data exfiltration. Do you wish to share that case study?
Yeah, I will not be disclosing the main components. Yeah, please. But, uh, how this exfiltration happened? Yeah. So it's a, it's a social engineering type of thing or honey trap. You can call it as a honey trap, wherein, wherein an operator from our adversary country targeted one employee, which can be, uh, which can happen in any organization, be it a government organization, be it a private corporate organization. They lured, uh, them, uh, they convinced them on a pretext of earning some additional income. So they convinced them to share minimum documents with respect to your organization, which are not of a confidential nature initially. That's that's how they convinced the things. And this is the same recent happened. We don't need to take a name company. The same thing happened one of the. Correct. Bitcoin currency platform. Exactly. So they lure, initially they lure, they will sponsor you some, some visits, sponsor you some money, and then slowly they start blackmailing you on the pretext of your expenses which were which they backed up. And this way, uh, this way though that employee was not having an access to organizational, uh, contents, what they convinced the employer to do is, you visit your office, you download that things, you get the print out of that thing, and you share us, uh, via WhatsApp, via Signal, or via any other encrypted. So these are very important because these you can't, uh, detect within an organization by, by doing any digital forensic investigation. You will not be able to catch these type of because he's not doing any offense with the organizational assets. There is no outbound connection. There is no C2 connection. Nothing is there. But again, data is going out. So these are the peculiar things which, which can be identified by, which, uh, law enforcement agencies play a vital role in identifying these type of insiders, though they are forced to do on the pretext of some money and all. This is how this operators works. So we, uh, we had an opportunity to work on that type of case as well, wherein we identified law enforcement agencies identified this type of activities are happening. We confiscated their personal devices, had an investigation, because when you are investigating personal device, many legal aspects come in, because data privacy, personal belongings, you don't have the, until and unless warrants, you get a warrant from a legal authority to do so. So after getting, also sometimes user, uh, will not share the password to you. Then again, you have to move legally to get the passwords. So that, that are the, that were the challenges. So we confiscated the personal device. We investigated them, and then we found out that the operator guided the person in a way that there were no traces on his personal devices. The only proof what we got was a communication between a husband and a wife communicating that delete, delete. That was the only communication which we had from their mobiles, both the mobiles. Other than that, we were not having anything initially to conclude that this is a case of data exfiltration or espionage type of thing. But when we got this, uh, sound audio clip, we again reopened the entire case. We started, uh, with a different perspective, because whenever you are addressing, the most common thing is that to go through the operating system, network logs, event logs, registries. Nothing was there. Then we started going deep into the things, and we started carving the things. There's a one word called carving, wherein you start extracting the deleted or deleted or overwritten data from the hard disk. We started carving the things, then we came to know that, and anti-forensic tools were used to delete the things, and that was guided by the operator.
Okay. To do so. And, and we also got a communication between husband and wife telling that. Then we. What, what make you to go through that? Because I want to understand the psychology behind that.
Yeah. See, when we, uh, when we confiscate a mobile, we generally see there are many less capabilities with respect to the mobile forensics to have an access to the OS level. What we generally do is a gallery type gallery investigation, wherein we go through your photos, your audio clips, your video clips to identify any malicious activity is happening or not. Second stage is analyzing the application. If we didn't get anything from the gallery side, wherein there is an involvement from the personal side, we will be analyzing application. Then after analyzing the application, then we will come to the desktop version of that particular person, uh, whether there is a correlation between mobile and laptop or not. So when we were going through the, uh, audio clips, video clips, then we got this particular audio clip, wherein both were communicating to each other that, and all, which, which started, uh, us to think in a different, uh, perspective. Then we came back to desktop version, and we started analyzing his laptop, carving the things. Because carving takes humongous amount of time, depending upon the hard disk size, and at present, we don't have any laptop less than 1 TB, 2 TB of hard disk. So going through the entire hard disk took time, but again, we came up with a remnants of an application. We were not having an evidence of what type of application was that, but it was used for, uh, for anti-forensic activities, which cleared the entire traces. And multiple times. How you suddenly thought, okay, statement, delete. How, how did you catch that delete? Because see, the reason is, because I want to help my friend. This guy dating two girls. So if one girl caught multiple chats and all that, so other girl should not be able to trace it. Correct. So same with S also. So make sure I'm concerned about my brothers. Yeah. Yeah. Yeah. Absolutely. Absolutely. So, um, a good forensics success depends upon a good incident response. Oh, wow. True. Yeah. So whatever, whatever you require, you get from an incident response team. So we get a pretext about the scenario from incident response team, law enforcement agencies, that the case is for this type of things, because see, if you are addressing digital forensics as a whole, uh, if I give you my mobile and tell you to do a forensics, you will not be having any clue to start from. You have to have something to start from, and that that input is very valuable when you are addressing a forensics investigation, and that that input, the correctness of that inputs will lead you to correct, uh, way, correct path, and correct conclusion. And that that's where forensics is totally depending upon, uh, incident response. So many times I say, if my report is deviating from the subject, that truly depends upon the input which I am getting from the incident response. Whatever, how good is our my investigation, incident response team, I can contribute that much positively towards the closure of that.
Case so as you mentioned uh we got that input a pretext from law enforcement agencies that this is uh this type of involvement and all but we never thought of an involvement of a husband wife but again again that that that's where your skill and expertise comes in. That that is one thing I I want to ask you what that that skill I know that inputs are there but sometime instinct or your experience matter. What was that the psychological shift you had that yes these husband wife are figuring out this thing and all? Yeah.
See ma'am see when you are when you are in a shoes of an investigator everything is suspected. See even a father talking to a daughter or a son you have to get an investigative perspective of context of in which condition they can ask which condition you can ask. I had I had a case wherein a teacher school teacher is uh calling a parent and telling that key we have rolled out an application from school uh you have to download it from this and uh you have to install it on your mobile. So, so if you listen to that talk you will never come to a conclusion that why a student why a teacher will tell a father to compromise your phone you will not you will never identify that call as a malicious call. But again in our case we have to think in that perspective for each and every call whether zero no test but verified. Yes. So again that's that was also a good case wherein uh parent is telling parents phone is compromised. Both husbands and wife phones are compromised. They are excfiltrating data through some applications and they they never knew that. And when we go through uh when we went through the entire log uh calls the only call was uh with respect to the installation of any application was this teacher teacher parent communication. Then we asked them who was she and he told call up if you listen in that way you will not be able to judge that that's what I told education will lead you how you can address foreign and until and unless you do an hands-on for multiple cases um your perspective will not change for you have to change your perspective from a listener or a viewer to a investigator a question how this is happening who is doing this when did this happened can I have an evidence for this these are the four three questions which is very important when you are addressing a foreign six.
Excellent and and you know uh it remind me about your previous statement you said like there was a CV scout social engineering was happening where you upload your data they give you one PDF for download I want to come back to that question and I want to ask you like if I am a user. There's a lot of websites which say convert your uh doc to PDF and remove the DRM. There's no free lunch. There's no free lunch. How can we verify this file the PDF which I downloaded? Is it the same file which I upload as a content a doc or is it a malicious?
Okay. So see when you're uploading and when you're downloading it's not necessary that you will get a same hash first thing. So that is not a point to be discussed. Uh the same thing can't be there because internet will do modify some modify that particular thing. Uh there are various things. Uh the first thing is that you can use any Linux machine to check the files file type of that application. It shows as a PDF. When when you check the file type of that particular PDF it can be a XML. It can be an exe type of thing. So many opensource tools are there. Opensource websites are also there wherein you can upload that particular PDF and check whether it is a PDF or not. Make sure it's not sensitive file. Yes. Yes. Platforms are available. In-house commands are there. You will get multiple commands to check file type in Linux. Remnext is good tool and OS you can install it. Good capability to start with foreign 6. It provides multiple tools to check the credibility of a particular file to check the strings of particular file to if is there any JavaScript embedded in the PDF or not do we have any hard-coded IP within the script or not entire thing you can visualize the only thing is you have to change your approach uh not an easy approach go for a general process yeah that's what that's where the patience comes in.
Excellent and and this is the last closing note I have to asked for this broadcast. Uh after all the cases, investigations and courtroom experience, what you thought about and what is the one message you want every company to understand before they face their first breach, how they will be forensic readiness?
Okay. So um when I started my career in cyber security, what I first learned is that every incident will be having some traces. M. So first thing is that no nothing will happen until and unless there is an invocation of anything from a user side. So the first thing is you have to educate your employees. You have to educate your team to identify the basic difference between a malicious and genuine uh link. Identify the URL. These are the basic things. The awareness is the biggest element with which you can fight the uh cyber attack. True. uh first thing. Second thing you should have a control in place, IR team in place. The digital foreign readiness is very important because most of the organizations thinks that we are having a IR team whenever there is a requirement we will pull some foreign some person to do foreign 6 that is not correct. You should have the preparedness for foreign 6. You should have earmarked person to do that because that requires expertise. Uh that requires skill. You should have proper training for them. You should have minimum technologies in place to start with like many people do RAM dump using any tools. So again when you are addressing foreign 6 make sure that you are generating minimum noise on that particular operating system because the amount of noise you generate your evidences are getting uh manipulated. So you should have that type of expertise that type of tools go for industry level licensed tools with various capabilities. Never rely on single tool for one particular case because every tool has the or their own specific capabilities like FTK imager will go for good imaging with less noise. FTK tool will give you best carving facility. ENC case will give you best GUI experiences timeline creation. OS 46 will give you super timeline type of thing in mobile. So, so you you can't rely on single tool. So, you have to have multiple arsenals, multiple tools as your arsenals. And um yeah, the these are the basic readiness an organization can have to address and common.
Yeah. SOP again SOP has to be there to address see cyber attack can be of any nature. You can't have multiple SOPs to address the entire range of cyber attacks. But again what is to be done who will be doing what and what tool is to be used how much is to be addressed how to quarantine the things whether it is to be isolated entirely from the network or whether to be virtually isolate the thing the these are the things which should be readily available with an IR team to address foreign.
Excellent and and to be frank they um this is one of the longest podcast we had uh I had a podcast just uh 3 days back with my cousin Prashant Prashant Mo. Yeah. it went till 2 hours. I think it's more than 2 hours, right? uh you know I'm just knowing with a lot of stuff to be frank from this podcast and I'm sure the listeners who watching this video they will get a new perspective for six at least I got 85% new information even I did some of the practices because initially the days where I've been used to CHFI and other things but trust me those again those moments are like when you talk about this bharat saha or you talk about uh FIR that was a turning point for me and the case study was just amazing to be frank so I'm going with a lot of notes thanks to you because of you I got a lot of insights and I'm going to make a lot of content giving credits my the video will start with I just had a podcast with the penser and this is what I learned so one of the thing is CV Scott I'm going to cover the forex skills so that's something will be there can I share your LinkedIn profile on our YouTube description so you know if someone want to reach out to you, they can reach out to you.
Absolutely.
Excellent. And uh we're looking forward from you on the mentoring also on foreign 6. Yes. And uh those who are watching this video do let me know how do you find this video and do share your suggestions uh on a comment box what is the next video shall I make with the pinser. I have already have some new content to be lined up for you for next year. But um there will be a lot of works going to be done for my editing team because they have to cut a lot of things about the content they have to make. But thank you. Thank you so much Sam. It it was a worth weekend for me to go with a good.
It's a privilege to have myself on this forum interacting with you because I I have seen you multip seen you on multiple stages multiple podcast and I never expected to have an interaction like this and that to on a that on a subject which is near to my heart because foreign 6 is what life to.
I can see that. I can see that in the podcast. I can see the discussion what you had. There's no gimmick. There's no bluff. There's no AI generated content. Pure practical, technical and experience that matters.
Thank you so much, sir. Thank you so much.
Thank you, bro.
So, this is all from our team. Do let me know how do you find the podcast and if you're new to the channel, do subscribe to the channel and click on the bell icon to make sure you should not miss the future videos on a similar topic. Thank you so much. Good day. Bye.