Transcription
So hello guys, I hope you are doing well in your life. So from now onwards, we are starting our digital forensic course. So I'm dividing the digital forensic course into two parts: the digital forensic part one and the digital forensic part two. Because digital forensic is not an easy topic. As the name suggests, uh, many students think that digital forensic is easy. We can learn some tools, we can learn some techniques, some procedures, and then we can easily do the forensic. But forensic is, is not an easy job as a cyber security. Because attacking on some machine is okay, because we have some great tools. But doing forensic, we don't have any great tools because this field isn't in now, growing phase. So forensic is not developed at all. But yeah, we can say that it is in a growing phase. So that's why we have many hurdles to achieve our goals in digital forensic. So no worries, we are here, I am here. So I will guide you how to basically proceed in digital forensic and what is the key point that you have to keep in your mind while doing the forensic.
So some very important guidelines before starting the course: that keep your cell phone on vibration mode or you can also on silent mode. You are allowed to attend calls only from three people because this is the normal rule that I always follow: the teacher, parents, and the, you know. So if you have any doubt, you can basically disturb me, but not your neighbor, okay? Not your neighbor means you don't allow to ask, ask with your friends who don't have the knowledge of this field because, uh, there is one quote, uh, that half knowledge is far more dangerous than the great knowledge or the full knowledge. So that's why half knowledge is also always dangerous. That's why. And, uh, these are the normal terms, but I don't, I don't want to discuss right now.
Okay, so this is our, uh, the path that we are covering. The first one is the computer forensic. We will study the standard procedure, okay? Incident verification, system identification, recovery of erased and damaged data, disk imaging, preservation, data encryption, compression, automated search techniques, forensic software. And after completing our for computer forensic, then we will move on to the network forensics, in which we will see the tracking new network traffic, reviewing the network logs, tools, performing live acquisition, order of volatility. I will talk to you what is the order of volatility and then a standard procedure. The basically the standard procedure is different in all the different fields. So digital forensic is the main node, or you can also say that this is the, uh, the main branch in which there are many subdivided, there are many subdivided branches into it. So the first one is the computer, then network, then internet. And two or three fields all. But in digital forensic part one, we will study only or focusing only these three parts: the first one is the computer, then network, then internet. And the last two is the forensic investigation and evidence presentation, okay? And then legal aspects of digital forensic. Internet forensic is very vast, as you can say that this is the only part that have around, uh, more than five or six lines because the computer forensic is easy, we can cover it very easily. Network forensic is also not as hard as the internet forensic. And then in internet forensic, we will see the internet worldwide threats, or an example, email, search engine, hacking, illegal access, okay? So this is what we are trying to cover.
Okay, then the first question, the first question arrives in our mind is that what is digital forensic? Okay, so, uh, before starting anything, before we are starting any topic, starting any chapter, the first thing is always a teacher asks, or always the students having his or her mind that what is this? What is the meaning of this? So that's why, uh, what is digital forensic? So digital forensic, sometimes known as digital forensic science, okay, is a branch of forensic science encompassing the recovery and investigation of material found in digital devices, often in relation to computer crime. So in a layman's language, digital forensic is the way to recover, to recover the data or to investigate something in a digital device that often find in the computer crime. So for an example, in a, in a company, some attacker attacks the server, that is the mail server or the web server, anything that attack happened. Now the company thinks, what to do? Uh, where to go? How we can recover these threats again? Uh, how can we, uh, do the countermeasure for the future? So this is all have the solution because we have the countermeasure, we have the firewall, we can easily implement anything. So we never encounter the same problem in the future. But for an example, if the CEO or the any head member wants to know who is the person behind that crime? So here the digital forensic came. Come. So countermeasuring any attack is easy because we have the solution. But investigating that who is the person behind this crime is not an easy task because we have to investigate each and everything: the logs, the events, the time, uh, the attacker did the attack on which time zone, and we are in which time zone. Then the, the volatility of evidence that I told you in the previous slide, uh, there are many things that the, for an example, the attack happened on the device, the device is open, or the, uh, the device is basically in a working state, or it is in shutdown state. Many things matter in a digital forensic. So that's why I told you in the starting of this lecture that this subject is not, not an easy that you are thinking, okay? So, and I'm not basically warning you, but I'm just telling you the fact that it is not an easy job. So that's why we have to keep our mind fresh, active, and learn as much as we can.
Okay, so again, this forensic is basically to recover or investigate the data that often find in the computer crime, okay? And in other words, the digital forensic is the process of uncovering or interpreting electronic data. That I told you that if some attack is happened, then who is the person behind it? How actually the attack happened? Okay, the, uh, proof of concept, the indicator of compromise, many things that we have to notice and then find out that, yeah, XYZ person sitting in this state or this country, uh, did this attack. And we have to prove in the court. The game is not over after identifying the attacker, okay? So we have to prove in the court that, yeah, this is the evidence that can state that this person did the attack, okay? So digital forensic, uh, is the process of uncovering and interpreting electronic data. The goal of the process is to preserve any evidence in its most original form while performing a structured investigation. Here, the chain of custody will come by collecting, identifying, and validating the digital information for the purpose of reconstructing past events. So while manipulating or engaging with the devices, we have to keep in our mind that that the data must be in the original form, okay? So for an example, I'm, I find out some device that is in working phase, okay? The power, power switch is on, and some CMD is going through, some Word file is open, mail ID is open. Then what should I have to do? I don't have to basically bother about the application that is in working phase. I have to capture the image of the system. And right now, the imaging part is a little confusing because you don't know what actually the image is. In a layman's language, image is something that we can see easily or we can capture, that is known as only image. But in the digital forensic, image is something different, okay? So while uncovering and interpreting with electronic data, we have to basically be very active that it must be in the original form. And the collecting, identifying, this one, the collecting, identifying, and the validating the digital information for the purpose of reconstructing the past event. So we have to collect the data, we have to do some, uh, manipulation with it, we have to understand that, yeah, this will come first, this will go after it, and then arranging in a sequence way, we will reconstructing the past event and we will come to the conclusion that, yeah, in this way, the attack happened. So this is known as reconstructing the past events. So you have to keep in mind that this definition is very easy. The first one that digital forensic is a branch of forensic science. You can also ignore the forensic science. So digital forensic encompassing the recovery and investigation of material found in digital evidence, often in relation to computer crime. And this is the normal definition you can keep remembering in your mind.
Then, what does a digital forensic professional do? So if you want to, if you want to build your career in digital forensic, then what you, what you have to do, or what are the fields in the digital forensic, what are the roles that you basically apply for it? The first one is the computer forensic analyst. As in cyber security, the first role for a fresher that is SOC analyst, Security Operation Center. So in this, we have computer forensic analyst, the first one. So what this position demands? So this position requires uncovering digital data like erased files or emails, preserving it for use as evidence, and analysis of the data associated with the suspected crime. So this part is not much harder as compared to the information security manager or the special agent. So this is the normal task that you have to perform. For an example, you have to basically uncovering the deleted data, then preserving the evidence in a most real form, then analysis of the data with you, with use of tools, and you don't have to find the conclusion, but you have to do some task related to, uh, data related to the result, something like that. So in a SOC analyst, we, what we have to do basically, we have to do the monitor the network 24 into 7 to find out some alerts, and we have to generate tickets, we have to resolve the tickets. So these are the basic steps that we are doing in SOC analyst. And in computer forensic analyst, we also do the basic things.
Then comes ethical hacker. You also get confused that why ethical hacker come into the digital forensic? It is already in the cyber security. Cyber security is a very vast field, or is a very big field, okay? There are many things come to cyber security. Digital forensic is a part of cyber security. So what ethical hackers have to do in digital forensic is basically find out the vulnerabilities in the computer network system in order to resolve them for their organization. So in digital forensic, the main role of ethical hacker is came after the attack happened or before the attack. So for an example, I can, uh, understand your feeling that why ethical hacker is coming in this forensic. So let me tell you one normal example. Uh, XYZ company, uh, uh, had faced one attack, okay? So that attack happened. Then the digital forensic team came. Then they did the investigation. They find out that the, any person or the ABC person did this attack. And the digital forensic team proved the, uh, evidence in the court, and the ABC person, uh, go into the jail, okay? The role of the digital forensic ends here. Then company thinks that, yeah, we find out the criminal and we give them the punishment, give him the punishment. What's about the vulnerability that causes that attack? So after resolving all things, after the digital forensic did their job, then the ethical hacker is basically, uh, uh, sponsored, or basically, uh, the ethical hacker is basically hired by the company. We can say that that is the ethical hacker is hired by the company. And the company says him that, you have to basically, uh, resolve this vulnerability because I don't need, I don't want that the same attack, uh, occur in future. So here the ethical hackers came. And another example is, for an example, the attack is, uh, not happened on the company, but company knows that this vulnerability exists in their system. Then what do you think that company wait for the attack? No. Company acquire, the company basically employ one ethical hacker to their organization and told him and tell them that to basically resolve the vulnerabilities. So the ethical hacker comes in this two picture.
Then the information security manager. This position is typically for experts who have advanced to management level within the digital forensic department. So in digital forensic, basically the own fieldwork is done by the computer forensic analyst and the special agent. But the overall guidance, the overall permission is given by the higher authority that is known as information security manager. Manager is basically a person who manages all the things that this team will go in this place, this team will report this to me, this team will do this thing, okay?
Then came a special agent. So forensic experts may work for governmental agencies like the Department of Homeland Security, CIA, FBI, IRS, and may specialize in counter-terrorism or counter-intelligence as it applies to the online drill. So here, the special agent, a special agent means that the government is basically come into the picture. So that's why it is a special agent. There is no difference such as much, but yeah, this is the main thing for the specialization.
Now, the important modules of the digital forensic. The first one is the modern forensic: how forensic starts, how it is progressing. Then the investigation process, or we can say that incident handling. Some incidents happened, then how to handle it, or the what is the process of the investigation. So the first one is the modern forensic: how forensic starts and then how it is right now in progressing phase. After the investigation, we will see that searching and seizing: searching the evidence, then seizing the evidence. So the original form will be maintained. Then the digital evidence. So seizing, we will, we will seize what? We will seize the PC, we will seize the phone, we will seize the desktop. So after seizing and searching, we will maintain the digital evidence that is in the device. Then the first responder. The first responder is the person who basically arrive at the place where the attack happened, that is known as first responder. So for an example, the area known as XYZ where attack happened, and we have to go there. So the first person who enters into the room, the first person who sees the evidence, who sees the, uh, devices and all the stuff, that is one of the first responders. Then building a forensic lab. We have to build our forensic lab for the investigation. Then the file system and the hard drives for analyzing the, uh, or basically maintaining the sequence of the events, the analyzing the deleted data, recovering the data from the file system, the hard drives. Then the Windows forensic. After doing all the things, what we have to do? Data acquisition: getting out the data from that device. Then deleted files and the partition: seeing the, what is deleted, how many, how many partitions on that system. There are many things, but I'm just mentioning some of the important key points that you have to keep in your mind. Then FTK, the forensic toolkit. The toolkit basically specifies many tools into it, that's why it is known as toolkit. Then in case, then Steganography, image files, password crackers, logs and events, network forensic, wireless, then the mobile forensic. This is another module. Then Linux, then incidents handling. This is all the parts of digital forensics. There are many parts, and in each part, there are many subfields. So that's why we are dividing this into two parts: the digital forensic 1 and the two.
Now, see the evolution. How the modern forensic basically is started and right now, how it is going. So I don't have too much data, but yeah, I have, as I have the data that you will understand the flow of the forensic. So the first one, the evolution is started from 1822 to 1911: that is fingerprints, where the fingerprints came. Then 1887 to 1954: blood grouping. Sorry. Then 1891 to 1955: firearms. Then 1858 to 1946: documentation. Then 47 to 15: criminal investigation. Then on 1932: FBI came into the picture. 1984: Computer Analysis and Response Team. And then the 1993: the first International Conference on Cybercrime. So the important point, sorry, the important points I already highlighting in this PB, so you have to focus on this, the green one. Then the 1995: International Organization of Computer Evidence. The 1998: Forensic Science. Then 2000: FBI Regional Forensic Offices deployed. In 2013, the first cyber forensic laboratory of India, India was stabilized in Tripura on 11th August 2013.
So how many types of attack? So this is the normal thing. If you have familiarity or you have the knowledge of cyber security, the attack will only occur from the internal or the external. So that's why I'm mentioning the types of attack is internal attack and the external attack.
Then digital forensic: physical, physical signs to find the truth and prove it. So this, this is the shortest definition of digital forensic: the physical science to find the truth and prove it. Then preservation of evidence and the contamination.
Now, this is the big picture of modern forensic process. So if you understand this process, you will easily understand the flow of digital forensic in any subfield. The many sub, many fields or in their subfield. So the process is basically different by something or some steps, but the main or the big picture of digital forensic is this. The first one is the identification of digital evidence. So I, for an example, I'm giving my own example. If I arrive on the crime scene, so then what's the first step that I have to do? The first one is the identification: that what is the digital evidence? What is the devices? What is the technology that plays an important role for this, for the attack, successful attack? So I have to identify. So that is identification. After identification, what I have to do? The preservation of evidence. And that is also known as chain of custody. Why it is chain of custody? I will teach you in the next lecture. And the after the next lecture, the preservation of the evidence. So for an example, some evidence is in the RAM. Then if we turn off the PC, the evidence will erase. So the preservation is the important thing because if you have the numerous of logs, for an example, the 1,000, 5,000 logs, then you can easily find out the way that that happened. But for an example, you only have the five or 10 logs, or only the 50 logs, then how we will come to the conclusion that in this way the attack is actually happened? So you have to the numerous of data to prove the attack that, yeah, or you can also say that that you have the such amount of data to prove that that this person is basically, this person is the owner, or this person is the, this person is the liable to this attack, okay? So we have to prove. If we have the as much data, then after having the data, what we have to do? The extraction of evidence. Then in interpretation of evidence. For an example, interpretation is, uh, basically the defender and the prosecutor. So the, in the court, we can also say that that if we go into the court, then there are two sides, that one is the defending party and one is the attacking party. So that is known as interpretation of evidence. Then the documentation and the last one is the presentation. So basically, we have to think, for an example, I am saying that this IP address at that time is in this location. But the, uh, defender party says that at this time, my, my client is in this place. Then how can you say that this IP address belongs to this person? So we have to assume the scenario, sorry, we have to assume the scenario that if we prove, or basically if we, uh, if we showcase this evidence in the court, then how the defender or how the prosecutor react to this evidence? So we have to basically think all of the scenario before going to the court, okay? And after having this scenario, what we have to do? We have to make one document that we will present in the court in a very standard way. So documentation is also a very tough part. But yeah, if we have the too much data, if we have the, the, uh, proof, or basically if we have the correct evidence, we have the, we have the proof of the concept that, yeah, see, this is the proof that, yeah, this person is liable to this attack, then we can easily make a document. There is one quote: truth, truths have no fear about the, truths have no fear. So basically, if you are saying the truth, then you don't have to care about the defender, that what that, how he will defend himself, okay? So after interpretation, we will make one fine documentation that we will present in the court. And the last one is the presentation part.
Then the basic steps in modern fencing. So see, the first step is crime happens, okay? Then identify a crime scene. So crime happened, then we will identify a crime scene. Then we will do some documentation, or we will do some, what we can say in ethical hacking, that we have to sign of the agreement, okay? NDA, non-disclosure form. So the same way here, it is warrant. That I have the warrant that I can investigate your organization. I will come to this place. This is my warrant. You can't go anywhere and say that, yeah, I am from digital forensic this department and I came here for the investigation purpose. This is not the actual way to investigate. So you have to keep the warrant. So that's why after identifying a crime scene, you have to keep a warrant. Then the first respondent, that I told you, the first person who enters to the crime scene is known as first responder. After arriving at the first scene, what we have to do? Seizing the evidence, okay? After seizing the evidence, we will transport the evidence to our forensic science or laboratory. Then we have to copy the bits by bit the evidence to another device in which we will do the analyzing, we will manipulate with the data. So that's why it is known as bit by bit copy. After doing the copy, we will acquire the hash of the original device and the, the copy device where we get the copy of the evidence. And then we will match both of the MD hashes. If the hashes are same, then we can say that, yeah, the successful copy is basically occurred. After this, then the chain of custody. How you are basically, uh, one person is not accountable for all the things. So that's why, for an example, I am good at networking, then I will do the analyzing on the networking part. But some other person is good at email forensic, then I will provide the data. So that is known as chain of custody. How the data, how the evidence is basically traveling from one person to the next person, that is known as chain of custody. Then the storage part, then analysis, then the last is report. After making the report, or the documentation part, the court, and the court will says that who is the, who is the basically the person who did this attack, or the evidence is provided by the digital team is right or not. All results basically comes in the court at the end.
So the characteristic of digital evidence: whole means complete. We will do the analysis on the whole data. Admissible: relevant. We will not say anything that is not relevant. So we have to keep in our mind that providing some data in the court, it must be relevant to the attack, okay? Then the accurate: the data must be trustworthy. Then the authenticate: the true, best, or original. And the last one is the acceptable.
Then types of modern crimes. If you search on Google, the how many types of cyber attack? For an example, I have, I wait a second, I just made one thing, uh, this one, okay? Sorry, I think I didn't download the thing. No worries, no worries. So basically, I have one file in which the around 400 or 600, the types of cyber attacks. So there are many cyber attacks, but we have to focus on the, uh, basically the attack that is demanded in the, uh, cyber attack or that that has very too much demands. So these are the some attacks that's demands, that's needs attention of the cyber security expert to resolve this attack. So the first one is the clickjacking. I will explain what is actually, but I'm just mentioning some of the modern crimes that you will basically note down that, yeah, you have to study this attack first, and then go for the next attack. So these are the modern crimes that you can also go through it.
Then the investigation process. That I already told you: the assets, meaning basically the asset, then the acquire, then analyze, then the management, chain of custody, report, and court preparation for investigation process. The first one is the build the workstation, okay? Then a build a team. Then search warrant and, sorry, build a workstation and build a team. So we have the workstation and we have the team, then we can do the digital forensic big picture of investigation. The warrant part, that it must be an entire company or some devices in warrant. It is me listening that which devices we have to check or what are the area that we are allowed, okay? Then secure the scene, the photography, the label, okay? That you don't have to enter that normal public can't enter in this place, that is labeling, okay? Then collect the evidence, secure the evidence, the chain of custody or the management, acquiring the data, bit by bit copy, that I told you, then analyzing and the documentation and report. So there is not too much difference in the previous slide or whatever we studied. The naming is different, okay? The steps is basically different. Here we can see that only seven steps, but in the previous slide, they are nine, there are eight steps. Are sometimes it is in large way or it is in a very long steps. But the main things that we have to keep in mind that the normal, the normal things is the warrant, then the securing part, collecting, okay? Securing the evidence, search warrant, secure the scene, evidence, secure evidence, acquire the data, analyze, and then prove in the court. This is the introduction to digital forensic. I hope you would like this lecture. And in the upcoming lecture, we will see more about the digital forensic. So happy learning, guys, of digital forensic.
So before starting the digital forensic course, okay, there are some golden rules that we have to keep in our mind, okay? So whatever the field in digital forensic, you are doing a forensic, these rules are always applied, okay? Or we can also say that basically these are the golden rules for the digital forensic. So let's note down some golden rules, okay? Before proceeding further. So let me settle it down, yeah. So golden rules.
The first rule that you have to be in your mind that whenever possible, it is best to have a trained computer forensic examiner, or we can say that the analyst, collect the electronic evidence. So don't try to be smarter in giving anybody permission to go and take the evidence. This is not the best practice, okay? So whenever possible, it is best to have a trained computer forensic examiner or analyst to collect the evidence. This is, this is the first rule, okay?
Then the another one is the, another one is that, uh, do you, do you have a, sorry, do you have a legal basis to seize the computer, or we can say that the plain view search warrant, and the consent that do you have or not, okay? So don't go anywhere and say that, yeah, I came from this organization and I, I want to basically do the forensic. That is not a legal way. It is not the suitable way to do the forensic, okay? So you have the basically the search warrant. You can't go anywhere and say that, yeah, I want to do the forensic in your organization. I got a notice that some crime happens here. So this is not a good way, okay?
Then the another one is, if you, if you have reason to basically believe that the computer is involved in the crime you are investigating, investigating, then take immediate steps. Take immediate steps to basically preserve the evidence, okay? Take immediate steps to preserve the evidence. These are the third golden rule.
Then the fourth one is, if this is the main point that you have to note down, if the computer is off, okay, then leave it off. Don't try to open it or don't try to be smart, okay? Then do not power it on to basically begin the, begin the searching through the computer, okay? If it is off, let it be off. Whatever you want to analyze, it's basically done in the lab, not the crime scene, okay?
Then the fifth point, for an example, if the computer is on, then what to do? If the computer is on, then what to do? What to do? So the answer is basically, uh, we have to basically add a properly, sorry, add, I'm getting, add a properly trained computer forensic because you can't handle if it is on, okay? So we have to basically add a properly trained computer forensic to handle it and then use some, uh, the electromagnetic secure bag to basically protect it, or you can also do the imaging part, or you can also do the imaging part. What is the imaging part? I will tell you. We just focus in this thing, okay? Then this is the fifth point.
Then the another important point that you have to keep in mind that if you think, the sixth point is that if you, if you think that the computer is basically, uh, destroying your data, basically destroying the evidence. So suppose you visit the crime scene and you are see, and you are basically able to see that the attack is going on, or basically some malware is working and basically erasing the registry, erasing the logs. If you might think that that something is working or something is basically in a way that erasing the data, okay? Then what to do? Then, then basically what you have to do? Basically immediately, as soon as possible, immediately, immediately, what to do? Immediately shut down. Yeah. Now, immediately shut down the computer. Immediately shut down the computer by, by pulling the power cord, by pulling the power cord from the back of the computer. If you think that it basically destroys the data, then you can do this step, okay? Here must be this, I just, this error, you can also understand, okay? So what is the first point that we see that whenever possible, it is best to have a trained computer forensic analyst to basically collect the electronic evidence. You can't, uh, allocate any person to basically collect the evidence, okay? So basically, a computer forensic analyst had the role to collect the electronic evidence. Then, do you have the legal basis to seize the computer, okay? So whenever you are visiting a crime scene, you have the, uh, the search warrant in which all things are mentioned that which device you have the permit, which area you have to go, and whatever the baseline that you can cover it, okay? Baseline means that, yeah, you can only go to this server and you can only access this computer. You can't access this computer because this is very high authority, okay? So the contract, in the contract, everything is mentioned. Then you have the reason to believe that the computer is involved in the crime you are investigating, then take immediate steps to preserve the evidence. I think the third point and the fifth point is relative, is related to each other, okay? So these are the one thing, but in a different way. So if the computer is off, we don't do any science, we don't do any, we don't have to basically think about it. If the computer is off, take, take the PC and go to the lab and do the imaging part and do your analysis, okay? Don't try to open it. And the last one is that, if you think, this is the very important point, if you think the computer is basically destroying the evidence, so immediately shut down the computer by pulling the power cord from the back of the computer. So these are the some basic points. And you can also note down one point also, the seventh one is that in all instances, all instances, take photographs. Take photographs of the computer, okay? The location, the location of the computer, and any electronic media attached, okay? If the computer, if the computer is on and the screen is blank, okay? This is another case. If the computer is on, but the, the screen is blank, then what to do? Then move the mouse or press the space bar. This will basically display the PC and then photograph this. This is also a good practice before collecting any evidence that you are basically proving yourself that this is the computer that I find out on the crime scene. This thing is going on, and I take the photograph for the proof. So these are the general principles to follow when responding to any crime scene in which computer and electronic technology may be involved. Several those principles and considerations that I basically write down this. So these are the seven points that you have to keep in your mind, okay? So you can also take this screenshot. So for now, these are the golden rules. In the upcoming lecture, if we find some another golden rules, then I will add, okay? But for now, or beginning of this course, these are the golden rules that you have to kept in your mind. So happy learning, guys. We will see, uh, another thing or we will start with the computer forensic from the next lecture. Thank you.
So hello guys, welcome to the another lecture of digital forensic. Uh, in this lecture, what we are going to do is to basically set up our lab because for digital forensic, lab is a very necessary thing. So what we are doing? As you can see that we need two things. The first one is the VirtualBox, in which we are going to install some virtual machine. So right now, we are using Kali, but in future, we need Windows, okay? So let's see that how to download VirtualBox. So simply open your favorite browser, whatever you are using, type on Google, VirtualBox, okay? Simply VirtualBox. Then the first link is this, the https://www.virtualbox.org. Just click on it, okay? Then in the left side, you can see there is a download section. Click on the download section. Then you can download as per your platform. So the latest version right now is 7.0.8. You can download it for Windows, Mac, Linux, okay? So according to your need, just select. So for, uh, if you want to download this, then you just have to click on for Windows. But I have already installed, so I'm just canceling right now. So after downloading the VirtualBox, you have to go through this some normal procedure. So basically, what, what I canceled is the .exe file. So only you have to run this .exe file, okay? And then just go through the flow, whatever he is asking, just click on next, next, next, and your virtual machine is, uh, VirtualBox is installed properly, okay?
Then after the VirtualBox, what we have to download the Kali machine? So simply search Kali download, okay? Yeah, so Kali download. Then the same thing goes here also, that the first link that is https://www.kali.org. So just click on the Get Kali. And there are lots of variety in Kali. Basically, there are installer image, then there are for virtual machine, then some raw, then for mobile, Kali is also there, then cloud, then containers. There are more. If you click on cloud, then there are more variety for AWS, for digital, okay? So don't worry about the variety. In future, you will learn all the things. But for starting our lab, we need some basic things. So we are not going to download the virtual machine, the Kali virtual machine. Basically, it is not set up properly, or basically the things that you are not going to, uh, set it properly because what I see in many PCs that after downloading this virtual box, this is the ISO file, okay? This is the ISO file. So let me see, um, let me cancel it, okay? This is the zip, you have to unzip and then you will get the ISO file. Yeah, so what's the main issue with them are the setup? So for an example, you downloaded it, but you are not able to set the proper RAM, you are not able to set the proper hard disk and the number of CPU. Then in future, you will face some problems. For an example, your Kali gets shut down automatically, your PC will shut down automatically. So these are the normal problems that you will face. So for easy process, what you have to download is basically click on the installer images, okay? These are the images that you don't have to worry about the downloading, okay? Just click on this complete offline installer, okay? And you are good to go. And let me show you what I have, uh, this one. If you download, then you will find these things, okay? So these are the different things. Let me explore it for you guys. Uh, so for an example, I'm clicking on VirtualBox, okay? And what starts downloading? The same one, the that we did before, okay? So don't worry about this. Just go for the installer image for now, okay? So these are the normal things.
Then what you have to do after downloading all the things that I, I told you that for VirtualBox, you have to just go with the flow, okay? Just go with the flow. This is our VirtualBox. So after installing the VirtualBox and after downloading the Kali Linux, what you have to do is to add the Kali here. So these are the normal steps. What you have to do? Only just click on the new, okay? After clicking on the new, after clicking on the new, type the name as per your need or whatever you want. So for an example, I'm typing Thor, for example. Then you have to select the, uh, the file where you downloaded it, okay? So you have to select the file. After selecting the file, it will automatically select all the other options. For an example, type, it will automatically select the D, then the version, it will automatically select. So only you have to select the ISO image path. After selecting the path, then you have to focus on these things, these hardware. So up to green, you are okay. But what I suggest you to don't use the whole green. You can basically go with the half of it, but don't cross it. As a beginner, I don't suggest you to go to the whole green part, but yeah, up to the half, it is fine. And then processor, right now the number is two, is okay, okay? After selecting the hardware, these are the hard disk. Then, uh, up to 20 GB is okay. So in future, if you need more space, then you can edit it, or you can simply uninstall it. Or uninstall doesn't mean that you are basically deleting from your PC. Uninstall means just click on the right, right button on it, the Kali part here, and then just, uh, remove. If you click the remove, then it will ask you that you want to delete all the file related to this machine, or just you want to delete this part. Then select the only delete this part, and then you can, uh, repeat the same process, just clicking on the new, adding the Kali machine.
One more thing that we have to download is, is the, uh, the Windows that I told you that Windows is also necessary. So what you have to type for Windows? Just type Windows Virtual Machine, okay? After clicking on the W, these are the Microsoft website, developer.microsoft.com. So simply click on download a Windows Virtual Machine. Then these are the, uh, variety of things that you also see in the Kali part. So you downloaded the VirtualBox, so you just have to select the VirtualBox because you are downloading the Windows for VirtualBox. Click on the VirtualBox and then it starts downloading. You can see it is around 21.6 GB. So I'm just canceling right now because I have already, but I didn't, uh, add it into the Kali because I want to show you that how to do it because it is not the easy process as we did, as we did for Kali Linux, okay? So for Windows, I will show you how to basically add a Windows into a virtual, into a VirtualBox. So for now, uh, this is our lab setup, in which we have downloaded the VirtualBox, then Kali, and in the next lecture, we will see that how to download a Windows for the VirtualBox. So thank you guys. Happy learning.
So hello guys, welcome to this lecture. In this lecture, we are going to see that how we are, uh, downloading the Windows virtual machine. So simply type Windows 10 ISO download, okay? And you can see this ISO file, just click on it. Then click on the download tool, okay? So if you click on the download tool, it will start downloading things for you. So it will download the, uh, let me show you, yeah, the Media Creation Tool, okay? So just click double click on it, okay? And go through the normal steps, and then you are good to go for the Windows. So let me show you my Windows Virtual Machine. So this is, and you can keep some configuration that I'm showing you right now. So in the advanced tab, you can enable the bidirectional for the copying paste from the original Windows to the virtual. So this is the drag and drop bidirectional. You can, I'm not using because I don't need it, okay? Then the system, uh, in the base memory, so when, go up to the half of the green section to allocate the RAM, okay? Not more than or not less than because this is the good practice. And the CPU must be the two. In my case, the CPU is two, okay? Then, yeah, that's it for the disable. And, uh, yeah, the storage is around 50 GB, okay? Then the network must be NAT for your security purposes. And then you can share folder. If you want to share some folder from your original Windows to the virtual Windows, then you can just click on it and then select the folder, and you are good to go. And click on the OK. So this is all about how to download Windows Virtual Machine in VirtualBox and how to add. Let me show you again. So just click on the add button, okay? Then select the, uh, folder where you downloaded. So in my case, I'm downloading here, uh, where it is? I downloaded here, uh, part. Let me go back, back. This is the Windows 10. I already using it, so that's why it is not focusing me again. So just select your folder, okay? And then open it. And then you are good to go. And then select the some, uh, add some normal term. So for an example, the name is Windows 10, then, and then it will automatically, automatically take the inputs, okay? After selecting the ISO file. So this is all about.
So hello guys, welcome to this lecture. So in this lecture, we are going to study the computer forensic, okay? The subfield of digital forensic, or we can say that this is our first subfield of digital forensic. So before starting this topic, I just want to say one thing that computer forensic and digital forensic is not the same thing. Most of the students have doubt in their mind that the computer, okay, digital means the digital data that is normal, normal things that digital data is always reside in computer. So digital forensic and computer forensic is not the same thing. Digital forensic is the main branch. Computer forensic is the sub-branch of digital forensic, okay? Because there are many things in this that we can store our digital data. For an example, we are storing the, uh, digital data in, basically, the mobile, we are storing the mobile, then we are storing the digital data in tab, then the laptop, and laptop, then memory. There are many fields where we are storing the data, okay? So that's why I just want to basically clear this doubt before starting this module. So now you are basically familiar the difference between the digital forensic and the computer forensic. So let's begin our computer forensic, okay? So computer forensic refers to a set of methodological procedure and techniques that help identify, let me write that help, basically this is the key point that you have to keep in in mind that help us to basically identify, identify, gather, preserve, reserve, extract, interpret, interpretation that is interpret, then document, document, then after document, the present evidence, the present.
Evidence, okay? From whom? From where? From the computing equipment. So, in a way, we can say that computer forensics is basically the methodological procedure or the technique that helps, what does computer forensics help us do? To help to basically identify, gather, preserve, extract, interpret, document, preserve, or, uh, sorry, present the evidence. So, all these things come under the normal procedure or techniques in computer forensics. So, this is a smart way to basically remember. For example, whosoever or whoever basically asks you, "What is computer forensics?" If you have this point, okay, you can easily make one definition of computer forensics.
So, for example, somebody asked me that, "What is computer forensics?" Then I know these points. I kept them in my mind. So, basically, I, uh, define the definition of computer forensics. Computer forensics refers to a set of techniques in which we basically identify, gather, preserve, extract, interpret, or make the document of the present evidence. Because we are playing with the data, okay? In forensics, the main and the important role is only the data. We are searching for data to prove something. We are interpreting data to know something, that how actually the attack happened. We are representing the data to, uh, to the in the court to prove that who is wrong and who is right. So, we are playing with the data. That's why it is digital forensics. And digitally, digital stands here that we are not always digital data, but yeah, most of the time we are basically, uh, playing with the digital forensics because here we are not able to investigate that who murdered this person. Not this is not the dist forcy. I think you have heard about the CID, okay? So, this will come in that sense. So, we are focusing on computer forensics. So, these are the normal definitions of computer forensics that you have to keep in your mind. Or, in summary, we can also say that, uh, let me write the summary part.
In summary, in summary, what we can basically say that that computer forensics deals with the process of finding usable evidence related to a digital crime, related to a digital crime, to find the perpetrators and initiate legal action against them. Against them. So, this is the definition, definition of computer forensics, we can say that, okay? So, you have to keep this in your mind that computer forensics deals with the process of finding usable evidence related to a digital crime, to find the perpetrators, and initiate legal action against them. Okay?
Then, uh, what is the objective of basically computer forensics? Okay? So, the main objective, I'm just writing down here that what is the main objective, okay? Objective behind it. So, first objective, we can say that that is mentioned in basically in the definition part. So, identifying, gathering, or preserving the evidence. So, identify or gather the evidence. This is the first objective that we can say easily. Okay?
The second objective is basically gather evidence of cyber s in a forensically sound manner. We are not gathering anything in any way. So, forensically sound manner means some procedure, some standards that we have to follow while investigating, while collecting the data. So, this is the second objective we can kept in this, kept in our mind.
Then another objective, support the prosecution of the perpetrators of an incident. Or, we can also say that the another is minimize the tangible and intangible losses to the organization. Or, main objective, we can also say that the estimating, estimating the potential, potential impact of malicious activity, activity on the victim. So, these are the normal or some objectives that come under the forensic. Or, there are many. I'm just mentioning something. There are many. We can also say that, that, uh, finding the vulnerabilities. Finding the vulnerabilities is also the objective, we can say that. Then, uh, the other objective is basically recovering the deleted files, hidden files. So, recovering of data. Recovering of data. This is another objective.
So, there are many, guys. That's why I'm just mentioning the main, main points that you can easily remember. That is known as notes. Notes doesn't mean that you are writing the whole down the definition. So, for example, I wrote here that what is computer forensics in only four or five lines. And in actual copy or in original form, it is only these two lines, I think. So, this is known as notes. Notes is something that only you have to see for one time and then you can remember the whole scenario. So, you know that there are many big stories, but at the end, the summary will tell us the whole story that what's actually the, what's actually the, uh, uh, what's actually basically happened, or who is the main hero, who is the main villain, that is summary. Okay? So, there are many objectives, but I'm only just mentioning some importance after covering the definition, then objective part.
The another thing that why we need computer forensics. This is the normal question that you, you have encountered or you will be encountered in your future. So, I'm just preparing you for that part. Okay? So, just keep in my words that, or you can also note down. I'm just saying, I'm not writing down it. What is the need of computer forensics? The first one is to basically to ensure the overall integrity and continued existence of IT systems and network infrastructure within the organization. Or, there are many needs. Where there are many needs, you can also make by by your own. This is not any physical. This is not any rocket science that you have to go and research why we need comp forensic. Okay? Then another point, to protect the organization, you can say. Then another, to efficiently track down the perpetrators from different parts of the world. So, these are the normal things that you have to keep in your mind.
Now, after covering the basic of computer forensics, this basically I just want to include one more point that is not related to computer forensics, that is related to the whole digital forensics. And this will basically help us to in any subfield of digital forensics. And the topic is basically the types of attacks. The types of attack, or you can also say the types of, as in a digital line, this and this, types of cyber crimes. So, always keep this point. There are only two types. One and two. There are only two types of cyber crimes happened whole over the world. And these are based on the line of attack. Okay? So, the first one is the internal, or we can also say that insider attack. In Hindi, we can say that those who don't know Hindi, so just ignore it and just pronounce one, uh, quoto in Hindi to describe the internal and insider attack. Okay? Then another one is the external attack. And now you can easily, uh, write down the example that what is internal attack? The employee basically do some malicious thing. What is external? The black hat hacker. Okay?
Then, if I mention the two types of attack, then you can also note down some example of cyber crimes. Some example that is important, that's why I'm mentioning here. Examples of cyber crimes. Example of side. And one thing, just I want to say that for an example, I'm mentioning one cyber crime that is this page. Okay? Yeah. For example, you don't know what is this attack or what is this cyber crime, then what to do? A good learner always has one basic skill that is research. If you don't know anything, go and Google it. You have Google. You are not paying something extra, except that you are only recharging your mobile packages for monthly basis or yearly basis. So, whatever you don't know, just copy it. I'm just seeing, I'm just showing you the live research that how to do. Just copy it. Okay? Open your Chrome. Type, "What is what is sorry, what is?" And then paste it. "What is this?" Okay? Then there are many basically websites came. Come. And what to do? You have to basically type a perfect thing. So, "What is this?" doesn't make any sense. But "What is this attack?" because you are because you are copying from what part? That is the attack. So, write down. Then see. These are the answers. Cyber responses is a form of cyber attack that steals classified sensitive data or intellectual property to gain an advantage over a competitive company or government entity. For example, if this things doesn't make any sense for you, then go and open some great website. So, here you can see that the BMW is basically, uh, prompting that basically write down the definition. What is cyber? Just cyber response is a form of cyber attack that steals classified sensitive data. And then let's define. Then there are whole definition. Okay? Go through it. If you don't understand what is this, let me.
So, going back to our paint and just note down some important cyber crimes. Okay? I'm just noting them around 12 or 10. 10 is okay because excess of everything is bad for health. That's why 10 cyber crimes is okay for you. The first one I mentioned. Then second one is the phishing, or you can also say the spoofing. Okay? Then the Trojan horse attack. I'm just mentioning the importance at the time. Okay? Trojan horse attack. Then the brute force attack. Brute force attack. Then the cyber warfare. Cyber war. Then denial of service. Denial of service. And then there is another one, this distributed denial of. Go and discard. What is this? What is this? Okay? Then the, you can also add data manipulation, in which there are many attacks. Con. That's why I mention data manipulation. Then, then what? Yeah. Then privilege. Privilege attacks. The last is say. [Music] Last. Yeah. Ransomware. Okay? So, these are the some important cyber crimes. Yeah.
So, let's move forward. So, after what we are going to see that, uh, let me clear one thing that what is actually the digital evidence. I, I think that there are many students that basically confused that what is actually digital evidence. So, what is what is digital evidence? Okay? So, answer is that any information, any information of probative value that is either stored or or transmitted in in a basic form. So, this is the best example of what is. So, any information of probative value that is either stored or transmitted or in progress. We can also include that stored, transmitted, and progress. Only three types of the, uh, state of the data. Okay? In a digital form, that is known as digital evidence. Then you can also say that what is the types of digital evidence? Then keep this point in your mind that then we, that types of digital evidence. Okay? Let me see. Types of digital evidence. Then there is only two types. Same goes that the attack scenario. Yeah. Let me. Yeah. The types of cyber crimes. Here, types of cyber crimes. This is types of cyber crime. Same goes here that types of digital fory. So, the first one is the volatile. The first one is volatile. And then another one is non-volatile. Non-data. Volatile data. And that is volatile data. Yeah. So, two types of digital evidence. And let me explain that what is actually volatile data and non-volatile data. So, data that are lost as soon as the device is powered off. The normal example. The normal definition of volatile data. Let me repeat it again. Data that are lost as soon as the device is powered off. That is known as volatile data. What is non-volatile data? Permanent data stored on secondary devices. And what is secondary devices? The hard disks, the memory cards, the chips that we used in previous around past 10 years or before 10 years. Right now, it is also in use. But there are many devices that is not allocating the slot of chip right now. That is memory chip around up to 16 GB, 32 GB, that's it, I think. Okay? So, permanent data stored on secondary storage device such as hard disk, memory cards. That is known as non-volatile data. Basically, it, it can basically, it never tamper if the power off or on. If it stores, it permanently stored. If it's deleted, it will permanently. But what's about the, uh, volatile data? It comes for a short period of time. Okay? And the volatile data basically present in the RAM, we can see. Okay? Examples include basically the system time, logged on user, open files, network information, process information, whatever the process is going on in on your system, that is for some particular period of time. So, that is known as volatile data. If their period is over, or if their process, if they basically the task gets over, then the data is basically lost for permanent. That is known as volatile data. Okay?
Then the digital evidence. I covered. Then this part is also covered. I think this is okay for the basic of computer forensics. In the next lecture, we will continue the computer forensics. Okay? And do some practical. We will do some practical. We will, uh, use some tools. Okay? They will explore some tools that is related to computer forensics. So, I hope this lecture basically good as per your expectation. If not, you can also tell me that what should I basically improve in myself. Okay, guys? Happy learning.
So, hello guys, welcome to this lecture. So, in this lecture, we are going to see the roles and responsibilities of a forensic investigator. Okay? So, let's start with the lecture. C Lo is own. Sorry. So, roles and responsibilities of forensic investigator. Roles and responsibilities of investigator. Okay? So, by using their skills and experience, okay, a computer forensic investigator, uh, helps the organization and law enforcement agency to identify, investigate, and prosecute the perpetrators of cyber crimes. Okay? So, you know that upon arrival on the scene, uh, the investigator inspects the suspect system or devices and then, uh, extracts and acquires data of evidence value and analyzes it with the right forensic tools for, uh, to determine the root causes of security incidents. Okay?
So, the first question arises here that why we need a forensic investigator? Okay? So, there are three needs. Why, why for? Let me write down. Why we need. Why? So, there are three reasons why we need. Not be, not be stuck on these three reasons only. There are many reasons, but I'm just discussing the important ones. The first one is to cyber crime investigation. Cyber crime investigation. Okay? Then sound evidence handling. Wait a second, guys. I and is the sound evidence. Sound evidence handling. And the third one is the incident handling and response. The third one is for incident handling and response. So, if somebody asks that what is, why you need the roles and responsibilities of forensic investigator, then you can say that and the first one is for the cyber crime investigation, then the sound evidence handling, then the incident handling and response. Okay? So, let me explain a little bit about each term. So, the in the cyber crime investigation, so the forensic investigators, uh, by virtue of their skills and experience, help organizations and law enforcement agencies to investigate and prosecute the perpetrators of cyber crime. Okay? So, this is the first need. Then the sound evidence handling. So, in this, if a technically inexperienced person examines the evidence, okay, so it might become inadmissible in a court of law. So, that's why sound evidence handling. It means that we need a technically experienced guy. Okay? Then the third point, for the incident handling and response. So, forensic investigation help organizations to maintain forensic readiness and implement effective incident handling and response. So, why need to here point is the, uh, the point is to effective, effective incident handling and response. For sound evidence, because we need the technically experienced one. And for the cyber crime investigation, for the investigate and prosecute. So, these are the three why we need. And I explained you a little bit about each term. Okay?
Then see that a forensic investigation performs what tasks? Okay? So, the tasks related to the forensic seeing that what is the, uh, the forensic investigation performs what's the task? Okay? So, tasks related to the forensic investigation. Let me open the new tab. Okay? So, the foreign investigation, sorry, investigator performs the following tasks. Now, let's see what are the tasks. The first task is to determine the extent of any damage done during during the crime. Okay? So, it's determine the extent of any damage during the crime. Then recovers data of investigative, sorry, investigative value from from computing devices involved in crime. Okay? This is the second task. Then the third one is to create an image of the original evidence without tampering with it to maintain integrity. Okay? Then the fourth one is the guides the officials carrying out the investigation. Fifth point is to analyze the, uh, sorry, analyze the evidence, evidence data found. Then prepares the analysis report and, uh, updates and updates the organization just about various attack methods and data recovery techniques and maintain a record of them. Okay? And the last, sorry, and the last one is to basically, uh, last point is to, uh, address the issue in a court of law and attempts to win the case. Y test fine in court. Okay? So, these are the eight points that the investigator have to do. So, the first one is to determine the extent of any damage done during the crime. So, it is the, uh, role of the investigator to see that, uh, the extent of any damage done during the crime, whatever the damage, uh, that occurs during the crime, so the investigator have to notice that. Okay? Then they recover data of investigative value from computing device involved in crime. Okay? So, the value, it must be recovered from the devices involved in the crime. Then for the image part, to make the original evidence tamper-proof. Okay? Then the guides the officials to carrying out the investigation. Okay? Then analyze the evidence data found, prepare the analysis report, update the organization or related to the various attacks and the methods. And the last one is to address the issue in court of law. Okay? So, these are the tasks for the forensic investigator.
Now, what makes a good computer forensic investigator? So, if you're doing the forensic investigation, then as if you want to do a best or become a best investigator in your organization, then what makes a good computer forensic? So, let me describe verbally. Interviewing skills to gather the extensive information about the case. So, first of all, in hacking, what we do? If we gather as much as information, that is done in the first phase of the hacking, the ethical hacking, the reconnaissance part. So, if you have the too much information, then it is easy to do the hacking. So, similar way, so interviewing skills to gather extensive information about the case from the client. Okay? Then excellent writing skills to detail findings in the report. So, report making, as we see that in OSP exam, report making matters a lot. Okay? So, when you are doing the pen testing, report matters a lot. So, these are the normal skills that, uh, basically identify you that, yeah, you are a good investigator. Okay? Then excellent communication skills. So, these are the basic, basic things that you have to keep in your mind.
So, let's discuss some legal compliance in computer forensic. Okay? Let's discuss some legal compliance. So, I'm just discussing some of them, not the all. So, let me write down here. Computer forensic and legal compliance. So, let's discuss what is legal compliance. So, legal compliance in computer forensic ensure that any evidence, okay, that is collected and analyzed, it is admissible in the court of law. So, compliance with certain regulations and standards plays an important part in computer forensic investigation. Okay? And the analysis, some of which are as follows. That is, I'm writing down, uh, the first one is the Gramm-Leach-Bliley Act. Okay? That is also known as GLBA. Then the, uh, Federal Information Security Modernization Act of 2014. That is FISMA. Okay? Then the HIPAA, that stands for Health Insurance Portability and Accountability Act. HIPAA. And the fourth one is the Payment Card Industry Data Security Standard. That is the PCI DSS. Okay? Then the next one is the Electronic Communications Privacy Act. Then General Data Protection Regulation. The seventh one is the Data Protection Act that is invented in 2018. The eighth one is the Sarbanes-Oxley Act. Okay? That is written in the SOX. So, these are the some of the compliance that you have to keep in your mind. Let me discuss some of them. So, the, uh, the important ones. Okay? Not the whole. So, the HIPAA Act. So, the HIPAA Privacy Rule basically provides the federal protection for individually identifiable health information held by covered entities and their business associates and offers patients an array of rights with respect to such information. So, this is the HIPAA because you know that health, health, health-related data is very crucial to, uh, protect from tampering. Okay? And the health-related data is is in misuse very well. So, that's why we have to protect. Then the GDPR. So, the GDPR basically replaced the Data Protection Directive was designed to harmonize data privacy laws across Europe to protect and empower all United, sorry, European citizens' data, providing and to revive the way organizations across the region approaches the data privacy. You can also see the, uh, as in India, there is only one, uh, law that is the IT Act. Act. Okay? So, I also want to discuss the, I'm just writing. You can go through on Google also. So, IT Act in India. There is only one act. So, this is all about the investigator and the compliance part. So, happy learning, guys.
So, hello guys, welcome to this lecture. So, in this lecture, we are going to go deep, okay, into the forensic investigation process. Okay? So, how our flow goes? That first we study the, understand the basically understand the forensic, forensic investigation process and its importance. Then we will go further and then we will go further and see the forensic investigation process. Forensic investigation process. And this is divided into three parts. The first part, the second part, and the, and the third part. So, in the first part, we will see the, uh, pre-investigation phase. Pre-investigation phase. And then we will see the investigation phase. Uh, sorry. And then we will see the investigation phase. Investigation phase. And at last, we will see the post-investigation phase. Uh, post-investigation. So, this is our flow of this lecture. Okay? So, let's start with the understand the forensic investigation with the forensic investigation. So, let me open the new paint. Forensic investigation process. Forensic investigation process. So, what is forensic investigation? So, a sorry, a method, a methodological approach to investigate, investigate, then seize, okay, and then seize and analyze digital evidence and then manage the case. Manage the case from the time of search and search and seizure to reporting the investigation result. So, this is the forensic investigation process. So, as you know, the computer forensic investigation process includes a methodological approach to investigate, seize, and analyze the digital evidence. So, what is the importance of forensic investigation process? As we know that as a digital evidence, okay, so as a digital evidence, M digital evidence, okay? So, as a digital evidence is fragile in nature, so following a strict guidelines and thorough forensic investigation process that ensure the integrity. So, as we know that it is in fragile in nature, so we have to follow the, uh, investigation process in a strictly way, okay, to ensure the integrity. So, our main focus is to maintain the integrity. If we are dealing with the incidence, sorry, digital forensics, then we have to maintain, maintain its integrity. So, this is the main purpose that we have to keep in our mind while dealing with the digital evidence. Okay? And the forensic investigation process is to be basically followed. Should comply with local laws and stabilized precedence. Okay? So, must follow a repeatable and well-documented set of steps. So, these are the important things that you have to keep in your mind. So, the important things is the first one is the maintain the integrity. Okay? Then another one that you have to keep in your mind, the local laws and they stabilized the precedence. Precedence. These are the two important points. And the last one is the, the last one is the must follow, must follow a repeatable and well-documented set of steps. So, these three points, these three one is the important points for the forensic investigation process. Okay? So, keep this in your mind.
Then the phases involved in forensic investigation process. We see the importance one. We see the what is the digital forensic investigation process. Now, let's discuss with the three parts of the process. The pre, then investigate, and then the post. And then we will go deep into it one by one. So, let's start with the pre-investigation phase. Okay? Let's us start with the pre part. So, I'm just writing down here the pre-investigation. Pre-investigation phase. Pre-investigation phase. So, the pre-investigation phase involves all the tasks performed prior to the commencement of the actual investigation. Okay? So, this case includes some steps such as related to the planning the process, defining the mission goals, and getting approval from the relevant authority. So, setting up a computer forensic lab is a basically the CFL, stands for the computer forensic lab, and is a location that houses instruments, software, and hardware tools, and the forensic workstation that required for conducting a computer-based investigation with regard to the collected evidence. So, let's do it in a step-by-step way. So, the first one is the planning and budgeting consideration. So, how to make a computer forensic lab? Okay? Let's see it now. Computer forensic lab setup. Computer forensic lab setup. So, hello guys, let's consider continue with the computer forensic lab setup. Okay? So, we left over here and then we are continuing from this. So, a CFL stands for the computer forensic lab. Okay? Is a location that houses instruments, for example, the software and hardware tools, forensic workstation required for conducting a computer-based investigation with regard to the collected evidence. So, how you can set up a computer forensic lab? I'm writing down the steps. Okay? So, the first step is to planning and budgeting consideration. So, planning and budgeting considerations. Okay? Physical and structural design consideration. Of physical and structural design consideration. And third one is the work area consideration. Okay? Then the fourth step is the physical security consideration. And the fifth point is human resource consideration. Okay? Then the sixth one is the forensic lab licensing. Forensic lab licensing. So, these are the three steps in which you can build your own computer forensic lab. So, let me explain a little bit more about it. So, in planning and budgeting consideration, you will consider the number of expected cases, the type of investigation, okay, the manpower and the equipment and the software requirement. Okay? So, this is for the first point. And the second, for you need, you have to consider the lab size, then the access to essential services, and the heating, ventilation, and the air conditioning, all the stuff. Okay? So, work area consideration is the basically the workstation requirements. And for example, the internet, network on the communication line, or the lighting system, and the emergency power. Then for the fourth point, you consider the fire suppression system or the intrusion alarm system. Okay? Then the fifth, number of required personnel or training and certification. And for the last one, the forensic lab licensing, you have to basically consider the, uh, the ISO. Okay? The ISO part. So, this is the setup, setting up a lab. Okay?
Now, after setting up lab, what you will do? You will consider that building the investigation team. Okay? So, after this, after this part, you will do build a, build the investigation team. Build the investigation team. Sorry, the investigation. You know the spelling of the investigation. Okay? So, you have to keep the team small, okay, to protect the confidentiality of the investigation. Okay? And then identify the team members, assign them responsibility. So, uh, and then ensure that every team member has the necessary clearance and the authorization. And assign one team member as the technical lead for the investigation. So, these are the basic points for the investigation team. Then people involved in the investigation team. How many people you need? Okay? So, these are the important points. So, let me write down here. People involved in an [Music] investigation team. Okay? Let me give the numbering. One, two, three, four, five, six, seven. And the. So, let's us start with the first point that is the photographer. Photo graph. Okay? Then the incident. Incident responder. Okay? Then the incident analyzer. Then you need evidence examiner or the investigator. Then the fifth one is the evidence custodian. Mentor. Then evidence manager. And evidence witness. And the last one is the attorney. So, let me explain the role of each one. So, as you know, the photographer, photograph the crime scene and the evidence gathered. Okay? For the incident responder, responsible for the measures to be taken when an incident occurs. Then for the incident analyzer, analyze the incidents based on their occurrence. Then the evidence examiner or the investigator, examines the evidence acquired and sorts the useful evidence. Then the documents all the evidence. Then the manager, manages the evidence. And the witness, evidence witness basically offers a formal opinion in the form of testimony in the court of law. And attorney is the provides legal advice. So, these are the people you need if you are making a team. So, that we discussed.
Then understanding the hardware and software requirements for a forensic lab. Because a digital forensic lab should have all the necessary hardware and software tools, okay, to support the investigation process. So, starting from the searching and seizing the evidence to reporting the outcome of the analysis. So, let me discuss the hardware and the software requirements that you need. So, let me open a new paint. Okay? And then start drawing. So, let's see this way. Yeah. Cool. So, this is for the hardware. Hardware part. And this is for the, this is for the software part. Okay? So, the hardware. For the first thing is the two or more forensic workstation with good processing power and RAM. So, two or more workstation. Sorry, forensic workstation. Okay? Then you need a specialized cables. Specialized cables. Then you, uh, sorry, then you, then you need the write blockers. The write blockers. So, nobody can manipulate. And the drive duplicator. Duplicator. Then you need the archive and restore devices. Then media sterilization system. [Music] Okay? Then you need other equipment that allow forensic software tools to work. And, uh, the computer forensic hardware toolkit. So, such as the Paraben's First Rate Responder Bundle. So, I'm just writing down the Paraben. Paraben First First Responder First Responder Bundle. Then DME Disk Imager. Then FTK Forensics Workstation. And etcetera. So, these are the points related to the hardware section. Then come here on the software part. Then the first, you need is, uh, let me this the software part. Okay? So, the first one, first thing that you need is operating system. Then you need data discovery tools. Then you need password tracking tools. Password cracking tools. Okay? Then, then acquisition tools. Then data analyzers. Then data recovery tools. Then the file file viewers. Then the file type conversion tools. Then security, security and utility security software. Okay? And then computer forensic software tools, such as the Wireshark, AccessData FTK, and etcetera. So, these are the tools. And this is the normal, uh, the requirements. Okay? For the forensic lab. The hardware and the software things. So, just keep a note on it. Okay?
So, let's get into the an sure we going discuss the investigation phase itself. Okay? So, happy learning, guys.
So, hello guys, welcome to the another lecture. In this lecture, we are continuing with the forensic investigation process. Okay? So, in this lecture, we are going to study the investigation phase. In the previous lecture, we discussed the pre-investigation phase. And this lecture, we are going to study the investigation steps for investigation case. So, let me print my pain. So, investigation. Investigate. So, so after obtaining the required permission, okay, and having the access to the case prerequisites, the investigator is ready to investigate the incident. So, we are now good to go. So, the investigation phase and the post-investigation phase include various stages, okay, and the processes that need careful and systematic execution to obtain better results. So, each step in this phase is equally crucial for the acceptance of the evidence in a court of law or the prosecution of the perpetrators. So, let's discuss in a very careful manner. So, first, understand the investigation methodology. Okay? Investigation methodology. How the actual methodology work? It starts from the documenting the electronic crime scene. So, first, documenting the electronic crime scene. Okay? Then after it, we will do the search and seizure part. So, search. And then we will do the evidence preservation. After it, data acquisition. Then we will do data analysis. Then case analysis. Then the reporting. And at last, move testifying. Testifying as an expert witness. So, this is the investigation methodology. Okay? So, let me explain each step briefly. So, in documenting the electronic crime scene, so documentation of the electronic crime scene is necessary to maintain a record of all forensic investigation process, okay, performed to identify, extract, analyze, and preserve the evidence. So, points to be remembered when documenting the crime scene is the document the physical crime scene. Okay? Noting the position of the system and other equipment, if any. So, physical crime scene. So, let me write down here the important points. Uh, noting document the physical crime scene. Okay? And, uh, document details any related or difficult to find electronic components. And they record the state of computer system. And and record the state of computer system. So, this is the, this is the points that you have to keep in your mind for the first thing, that is for the documenting the electronic scene. Okay?
After documenting, search and seizure. Okay? So, plan the search and seizure. So, for an example, seeking the consent, obtaining witness signature, obtaining the warrant for search and seizure. So, initial search for the scene. Then, then the secure, securing and evaluating the crime scene. And lastly, seizing evidence at crime scene. So, these four substeps cover in the search and seizure. So, let me write down here what are the fourth scene that we have to keep. The first one is the planning the search and seizure. Then, then, then initial search of the scene. Then securing and evaluating the crime scene. Wait for a [Music] minute. After this, evaluating the crime scene. So, these go here, the, uh, the secure and search seizing part. So, there are many sub-points related to each step. Okay? So, I'm just explaining you one or two points. So, planning and search, uh, planning the search and seizure. So, you can also plan the search and seizure. So, a search and seizure plan should contain basically the, uh, the description of the incident, the case name, the location of the incidents. Okay? Creating a chain of custody document. Then health and safety precautions. So, these are the points.
Then came to the evidence preservation. So, in evidence preservation, basically refers to the proper handling and documenting of the evidence to ensure that it is free from any contamination. Okay? So, any physical and or any physical and or digital evidence seized should be isolated, secured, and transported and preserved to protect its true state. So, and then the date and time of transfer, you have to write down. So, these are the things that you can do in the evidence preservation.
Now, it's time for data acquisition. So, forensic data acquisition is the process of imaging. So, in data acquisition, basically the imaging. Imaging the processing of imaging or collecting the information. Or, let me write. Imaging or collecting information. Then investigator can then for instance simply process and examine the collected data. So, these are the things that comes under the data acquisition part. One of the, uh, basically it is one of the most critical steps, okay, of digital fencing, as improper acquisition may alter data in evidence media and render it inadmissible in the court of law. So, this is the important point. So, investigators should be able to verify the accuracy of acquired data. So, this is for the data acquisition.
Then the data analysis. Okay? So, data analysis refers to the process of examining, identifying, separating, converting, and modeling data. So, in data analysis, techniques depends on the scope of the case or the client, uh, requirements. So, these are the some points.
Then the case analysis. So, investigator can relate the evidential data to the case details for understanding how the complete incident took place and determine the future action, such as the, uh, flowing, for an example, the possibility of expiring additional information or relevance of component. So, this is all about the, the investigation phase. And in the next lecture, we will see the post-investigation phase. So, happy learning, guys.
So, hello guys, welcome to this lecture. So, in this lecture, we will see the post-investigation phase. Okay? So, just begin. So, we will see the post-investigation phase. So, the responsibility of investigators, uh, doesn't end with the finding and analyzing the evidence data. So, this would also be able to explain how they arrived at the conclusion to the prosecutors, attorneys, and judges. So, the post-investigation phase involves the reporting, okay, and the documentation of all the actions undertaken and the findings during the course of an investigation, and the procedure of testifying as an expert witness in the court. So, gathering and organizing on information. Okay? So, basically, the identification path. So, documentation in each phase should be identified to decide whether it is appropriate to the investigation and should be organized in a specific categories. Okay? So, identification and procedure for the gathering and organization, uh, organizing the information. So, procedures. There are some, uh, following are the procedures for the gathering and organizing the required document. Okay? So, let's see that the, uh, procedure part. That the identification is a normal thing, but procedure. List procedures for gathering and organizing the required document. Okay? So, basically, we have to gather all notes from from different phases of the investigation, investigation process. The first thing. Then identify, identify the facts to be included to be included in the, uh, in the report, in the report for supporting the conclusion. Then you can also list all the evidence, evidence to submit with the report. And, uh, list the conclusion. You can also add more points. So, for an example, organize and classify the information gathered to create a concise and accurate report. So, these are the some points related to the, uh, procedure for gathering and organizing.
So, writing the investigation report is very tough. Okay? So, report writing is a crucial stage in the outcome of the investigation. So, the report should be clear, concise, and written for the appropriate audience. So, let me write some important aspects of a good report. Okay? Let me change the color for this. Uh, so, important aspects for a good report. That are the important points that you can notice. The so, the first one, that it should accurately define the details of an incident. So, accurately define the details of the report, sorry, details of an incident. Details of an incident. Okay? Then it should cover convey all necessary information. So, conveying the all necessary information in a concise manner and organized manner. Then it will be technically sound and understandable to the target audience. So, technically sound and understandable to the audience. Because if you, uh, mention too many technical terms, technical terms in the report, so as a normal guy can't able to understand that what is this. So, that's what technically sound, understandable to the audience. Then it should be structured. Okay? So, structured in a logical manner. Structure in a logical manner. So, that the information can be easily located. Okay? Then it should be able to withstand legal inspection. So, withstand legal inspection. And it basically, uh, adhere to the local laws. So, the last point is the adhere to local, local laws. So, these are the points for a good report. Okay? For a good report.
Then what are the templates? So, basically, forensic investigation report template. So, if a forensic investigation report template contains the following things. So, for an example, the templates, investigation template contains such as, let me write down here, such as the executive summary. Executive summary. Then the investigation objective. Then the details of the incident. Okay? And the last one is the investigation process. Investigation process. So, let me explain you a little bit about it. So, executive summary, in which the case number, the name, and the social security numbers of authors, investigators, and examiners. Then significant findings, signature analysis. Okay? The objective, mentioned clearly point to point. Then the details of the incident, means that the date and time, the date and time the incident occurred. Then date and time the incident was reported to the agency. And the details of the person or the person reporting the incident. And the last investigation process contains basically the date and time the investigation was assigned. Okay? And allocated investigators. Okay? So, these are the investigation process. And there are more. So, let me add more points. So, I don't want that some points will remain. So, the fifth one is the evidence information. Evidence information. Then you, you can also add the relevant findings. Then this, supporting files. Then evaluation and analysis. Evaluation and analysis process. So, basically, an evidence information contains the location of the evidence, uh, then list of the collected evidence. Okay? Then the supporting files have the attachments and the appendices, full path of the important files or the expert reviews and the opinions. And in the evaluation and analysis process, the initial evaluation of the evidence, investigative techniques. So, these are the points that must be mentioned.
Then the testifying as an expert witness. So, presenting detail, presenting digital evidence in the court requires knowledge of new, specialized, evolving, and sometimes complex technology. Okay? So, things that take place in the courtroom. So, there are many things that can take place in the courtroom. As a cyber, as a digital forensic, okay, investigator, you have to know that what are the things that take place in the courtroom. Okay? So, familiarize the expert witness with the usual procedures that are following during the trial. The attorney introduces the expert witness. The opposing counsel may try to discredit the expert witness. That only leads the expert witness through the evidence. And the lastly, later it is followed by the opposing counsel's cross-examination. So, cross-exam. These are the some points related to the courtroom. Okay? So, don't worry about that. So, yeah, this is all about the investigation, the post-investigation. So, happy learning, guys.
So, hello guys, welcome to the another lecture. So, in this lecture, we are going to study the data acquisition fundamentals. Okay? So, data, data acquisition fundamentals. Okay? So, to perform a forensic examination on a potential source of evidence, the first step is to create a replica of the data residing on the media found in the crime scene, such as the hard disk or any other digital storage devices. So, forensic investigator can either perform the data acquisition process on-site or first transport the device to a safe location. So, these are the two scenarios. So, what is data acquisition? So, the basically, the data acquisition is the use of stabilized methods to extract electronic stored information from suspect computer or storage media to gain insight into a crime or an incident. So, what is data, what is data acquisition? Is basically the extraction part. So, extracting electronically, extracting electronically stored information that is also ESI. Sorry, ESI. So, this is the normal definition of data acquisition. Okay? So, investigators must be able to verify the accuracy of acquired data. And, uh, the complete process should be auditable and acceptable in the court. So, the categories of data acquisition is the live acquisition or the data acquisition, or we can say that the static. So, let's see the data, the categories. Yeah. So, the first category is live acquisition. Live, live acquisition. And the second one is the data acquisition, or the static. Let me write both that, data acquisition, or the static acquisition. Okay? So, in the live data, in the live acquisition, it involves the collecting data from a system that is powered on. As the name suggests, we are capturing data from the live system. And what is data? So, it involves collecting data from a system that is powered off. In summary, uh, the system is powered on. Power on. And here's the system is powered off. That's it. Okay? So, let me describe a little bit. So, in live data acquisition, the data is acquired from a computer that is already powered on. Okay? Either logged on or in a sleep mode, that doesn't matter. So, this enables the collection of volatile data that are fragile and lost when the system loses power or it is switched off. Uh, such data reside in registries, caches, and the RAM. Further, volatile data such as that in RAM are dynamic and change rapidly. So, therefore, must be collected in real time. But in data, or static data acquisition, non-volatile data that remains intact in the system even after the shutdown is collected. Okay? Even after the, the system is shut down. So, investigators can recover such data from hard drive as well as from the slack space, swap files, unallocated.
Drive space. So, other sources of non-volatile data include the CD, HS, USB thumb drives, and the smartphones, and the PDs. Okay, so these are the two acquisition methods: the live and the... okay. Then the types of data captured during the live acquisition. Okay, so the types of data, let's see the types of data. Types of data captured, yeah. So, there are two types of data. The first one is the system data. Let me change the system data. The another one is the network data. Network data. So, in system data, what we can collect is the uh current configuration, configuration, then running state, running state, then the date and time, date and time, date and time, then current system of time, then running processes, running processes, then the logged-on users, then the DLLs, the dynamic link libraries or the shared libraries, and the last is the swap files and temp files. So, these are the data that we can collect from the system part. Then, what's about the network? So, from the network, we can find out, not as large compared to the system, but yeah, not less. So, the first one is the routing tables, then the ARP cache, and then network configuration, and the network connections. Okay, so these are the data that we can collect.
So, now, after collecting the data, we can uh we have to keep these things in our mind that the order of volatility. So, basically, the order of volatility means that when collecting evidence, okay, an investigator needs to evaluate the order of volatility of data depending on the suspect machine and the situation. So, order of volatility means that which is more uh which has the more power to erase its data as compared to others. So, for an example, registers and cache, not registers and cache, have too much spaces. So, it means that the data changes or data is lost in a fraction of a second. So, the order of volatility of registers and cache is high as compared to the temporary file system or the routing table. So, let's see the order of volatility. So, we can uh write down from the high to low. So, let me write down the order of... and why we are knowing the order of volatility is to basically, the more volatile the data, we have to capture that data firstly. Okay? So, that's why we are writing down the order of volatility. So, let me give the numbering first. The third, fourth, fifth, fifth, sixth, seventh. Okay. So, the first one that I told you that is the registers and the cache. So, registers and cache. Then the routing table. Then the process table, kernel, kernel statistics, and the memory. After that, the temporary file system. Then the disk or other storage media. Then remote logging and monitoring data that is relevant to the system in question. And the sixth one is the physical configuration or and the network topology. And the last one is the archival media. So, this is the order of volatility. Okay.
So, let's us start with the first one, the registers and the processor cache, because the information in the registers or the processor cache on the computer exists for nanoseconds. Okay? It is constantly changing and can be classified as the most volatile data. Then, what about the second one? So, the routing table, the ARP cache, the kernel statistics reside in the ordinary memory of the computer. So, these are slightly less volatile than the information in the registry, with a lifespan of about 10 nanoseconds. Okay. Then, the temporary system files tend to persist for a longer time on the computer compared to the routing tables and the ARP caches. So, these system are eventually overwritten or changed, means sometimes in seconds or minutes later. Then, the disk, then the remote logging. These are the common that you can easily understand. Okay.
Then the live is done. Then, what's the data acquisition? So, rules of thumb for data acquisition, we will discuss. But let's see that static data recovered from a hard drive include what we see that live includes what. Then, let's see the uh the static data recovered. So, static data, what? So, let me get the numbering first. So, the first one is the temporary files, temporary of TMP, temp files. Then the system registries. Then the uh event or system logs. Then boot sectors. Then the web browser cache, web browser cache. And the last one is the copies and the hidden files, copies and hidden files. So, these are the data that can include in this static data. So, the acquisition, we see that is defined as the acquisition of data from a suspected machine that is powered off. Okay? So, uh usually involves the ing data from storage devices, mostly. Okay? Example of a static data, you can see the example of static data are the emails, then the Word documents, then the web activity, then the spreadsheet, slack space, and what else? Yeah, unallocated drive space. The last one is the various deleted. So, these are the example of static data.
Ordered data acquisition that we can get. Now, that I told that what we least discussed last is the rules for thumb, rules of thumb for data acquisition. So, let's see it also. Rules of thumb for data data acquisition. Now, the first rule is, do not work on original digital evidence. So, do not work on original digital evidence. Why? Because we can lose the, we will lose the original evidence from okay. So, create a bitstream logical image of a suspect drive file to work on. Not, don't ever use or work on the original evidence. Then, the second one, will use C media to store the copies, to store the copies. Okay. Then, produce two or more copies of the original media. So, you can also backup in the original. So, backup, backup the original copy. You can also and copy of the evidence. Okay. And then you can also, uh, do the upon creating copies of original media, verify the integrity. So, verifying the integrity of copies with the original. So, these are the some thumb rules of the data acquisition.
So, this is all for this lecture, guys. So, happy learning.
So, hello guys, welcome to the another lecture of the data acquisition. So, in this lecture, we are going to study the uh different types of data acquisition. Okay? So, let us start with our main topic that is different types of data acquisition. Okay? So, the types of data acquisition is basically depends on the three things. Okay? So, the logical acquisition, sparse acquisition. These two things and one more thing that is the bitstream imaging. So, bitstream imaging creates a bit-by-bit copy of a suspected drive, which is cloned and copy of the entire drive, including all its screen. So, let me give you the overview that how the flow is going of this lecture that we are studying the three types. Okay? We are studying the three types. The first one is the logical acquisition. So, I'm just writing the logical. Okay? So, logical. Then the second one is the sparse. Then the second one is the sparse. And the third one is the bitstream imaging. What's happening? Yeah, bitstream imaging. Imaging. Okay? So, we will be studying these three things one by one. So, let me draw one another line. Okay?
So, in logical acquisition. Okay? So, in logical acquisition, basically, it allows an investigator to capture only selected files or file types. So, only allows to capture only allow to capture only allow to capture the selected files or file types of interest to the case. Okay? So, this is the first point of the logical. Then, example of logical acquisition, if we see, then the email investigation that requires collection of only the outlook.pst or the OST files. This is one example. Or collecting the specific records from a large RAID server. Okay? So, if we see the example, then only mail extension files, while while email forensic and the RAID server. So, this is the example for the logical acquisition. Then, what is a sparse execution? So, sparse execution is similar to logical acquisition, which in addition collects fragments of unallocated data, allowing investigators to acquire deleted files. So, what does it do? It collects fragments of unallocated data. And allowing, allowing investigators to acquire deleted files. So, this is the minor difference between the sparse and the logical. Okay? So, in sparse, if we are in this method, then inspection of the entire drive is not required. Okay? So, we are not, worry about the whole things. So, in logical, only the file and the file types. But in this sparse, one more adding point that is the collect the fragments of unallocated data, allowing investigator to acquire deleted files. Then, what is bit-by-bit, sorry, bitstream? So, bitstream imaging creates a bit-by-bit copy. So, we can write down here, bit-by-bit copy of a sub of a suspect drive, which is a clone copy of the entire drive, including all its sectors and clusters, which allows forensic investigators to retrieve deleted files or further. So, bit-by-bit copy of a suspected drive. This is bitstream imaging. Then, in bitstream imaging, there are two things. The first one is the bitstream disk to image file, and another one is the bitstream disk to disk file. Okay? So, we are exploring bitstreaming a little bit more. So, in bitstreaming, there is two things. The first one is the bitstream, bitstream, sorry, disk to disk to image, disk to image file, and another one is the bitstream disk to disk, disk to disk. Let me draw one line between them. Yeah. So, let's start with the bitstream disk image, bitstream disk to image file. So, it is the most common method used by the forensic investigator. So, the created image file is a bit-by-bit replica of the suspect drive. So, what is this? Created image file is a bit-by-bit replica of the suspect drive. This is bit-by-bit, sorry, bitstream disk to image. Then, tools used, what are the tools? So, let me write down the tools also. So, the tools is the ProDiscover, then EnCase, FTK, then the SL, Sleuth Kit, and many more.
Now, the disk to image part, disk to disk. So, disk to disk, basically, the disk to image copying is not possible in situations where the suspect drive is very old. Okay? So, we can't do the disk to image thing. Very old and incompatible with the imaging software. If you are, basically, investigating some older device, so we can't do the acquisition from disk to image. So, in this case, our disk to image will fail. Okay? So, investigator needs to recover credentials used for websites and user accounts. In this case also, the disk to image will fail. So, to overcome this situation, investigator can create a disk to disk bitstream copy of the target media. Okay? So, while creating a disk to disk image, investigator can adjust the target disk geometry. So, for an example, its head, cylinder, and the track configuration to align with the suspect drive. And this results in this smooth data acquisition process. So, I'm just writing the tools because you know very well with the, the heading name that what is this. So, just writing down the tool names. The first one is the EnCase, then the another one is the Tableau, and the Forensic Forging Imager. Imager, etc. Okay? So, these are the different types of data acquisition techniques.
Then, let's see one more thing that the data acquisition format. Okay? Let's just start one more topic that is the data, data acquisition format. What is this? Because if you are covering the whole thing, then why we left with the some a small topic. So, determine the data acquisition format. Okay? So, the first format is the raw format. The first format is the raw format. Okay? So, raw format creates a bit-by-bit copy of the suspect drive. Images in this format were are usually obtained by using the DD command. Okay? So, there are some advantages and the disadvantage. For example, the advantage is fast data transfer, and the disadvantage is basically the require same amount of storage as that of the original media. So, this is the first format, the raw format. Then, the another format is the proprietary format. So, proprietary format. So, commercial forensic tools acquire data from the suspect drive and save the image files in their own format. So, that's why it is the proprietary format. And they offer many features. Okay? For an example, the certain one is the save spacing, space will be saved, then the ability to split an image into multiple segments, and ability to incorporate metadata. And there is only one disadvantage of this proprietary format is the image file format created by one tool may not be supported by another tool. Okay? Every coin has two faces. So, this is one case or the one disadvantage. Then, another format is the Advanced Forensic Format. Advanced, advanced forensic format. And also known as AFF. AFF. So, Advanced Forensic Format is an open-source acquisition format. Okay? Let me write down that it is, it is open source. Which is open source. The first thing. And there is no size limitation for this two image files. Simple design and customizable. Okay? And file extension, file extension include file extension is the AFM for AFM for AFM metadata, for AFM metadata, and AF for segmented image files. So, these are the two extensions of the Advanced Forensic Format. Then, another one is the Advanced Forensic Framework 4. Okay? Let me write down here the Advanced Forensic Format 4. That is also many time you see the AFF 4. Okay? So, we are basically understanding the different types of format. Let me draw one line also from here. We studied the raw format, then the proprietary format, then the Advanced Forensic Format, and we are right now dealing with the Advanced Forensic Format 4. Okay? So, basically, they use large amount of disk space in this format. And basic types of AFF 4 objectives, objects is volume streams and the graphs. Then, another point is allows the stage of disk image metadata. So, these are the some things, some points related to this format. So, I just only want to discuss with the format. So, if somebody asks you the data acquisition format, then you can easily answer it. So, that's why I discuss it.
So, this is all for this lecture. And there is one remaining lecture in which we will see the acquisition methodology. Okay? So, this is the, the another one is the last lecture for the data acquisition part. So, happy learning, guys.
So, hello guys, welcome to this lecture. So, in this lecture, we are going to complete our data acquisition part. So, the last thing that we are covering is the data acquisition methodology. Okay? So, forensic investigator must adopt a systematic and forensic sound approach while acquiring data from suspect media. Why? Because to increase the chances that the evidence is admissible in the court of law. So, let's start. So, we are firstly understanding the methodology and then we will see each of the term. So, data acquisition methodology. Methodology. Okay? So, let me, make the chart first for you to understand that how actually the flow is working. So, uh, the first one is the start, start thing. Okay? Then, after this start, we are going to draw the arrow for you guys. Then, determine the data acquiring method. Then, determine the data acquisition acquisition methods. Okay? After this, we will do the select the data acquisition tool. Okay? Then, selection of the data acquisition tool. So, select the data acquisition tool. Then, we will sanitize the target method. Then, uh, sorry, yeah. Then, we will sanitize the target media. Sorry. Sanitize the target media. Yeah. And then, after this, if computer is on or not, then the case arises. Okay? So, let's see if computer is on or not. [Music] So, there it is. Yeah. Then, we will see if computer is on or not. Computer is on. Okay? If computer is on, so, for an example, if yes, here we will write yes. Then, we will do what? We will do two things. Firstly, the thing is I'm mentioning in orange. If the computer is on, then we will acquire, then we'll acquire the volatile data. Acquire the volatile data. And then we will do the turn off the, turn off the computer. Okay? So, this is when the computer is on. Okay? And for an example, if computer is off. For an example, is computer is off. So, I'm writing here the offing part. If the computer is off, then we will, what do we will? We will remove the hard disk. Okay? Then, we will right-protect the suspect data. Right-protect the suspect data. And then, lastly, we will acquire non-volatile data. And then plan for contingency. And lastly, validate data acquisition. Let me set it properly for you. Acquire. Okay? So, let's understand the whole flow. Whole flow again. So, we will start the data acquisition methodology. Okay? We will start the methodology. Then, determine the data acquisition method. We will choose the method. Then, we will select the data acquisition tool. Okay? We studied the method. Then, we studied also the tool. Then, we sanitize the target media. Okay? Then, the remaining for remaining processes depends on the computer is on or off. So, for an example, is computer is on, then we will do the two things. First, the first one is the acquiring the volatile data. And then turn off the, turn off the computer. Okay? And after that, if, uh, it is no. So, so, yes part is including the this one. And also the no one. But no part is not including the yes one. So, if no, then remove the hard disk. Remove the hard disk. Then, write-protect the suspect data. Then, acquire non-volatile data. Then, plan for contingency. And then, validate data acquisition. So, these are the methodology. Okay? So, while performing forensic data acquisition, so potential approaches must be carefully considered and methodologically aimed at protecting the, protecting the integrity and accuracy of the original evidence must be followed. So, these are the methodology.
So, the first thing is to determine the best data acquisition method. Okay? So, in this part, an investigator needs to identify the best data acquisition method suitable for the investigation. Basically, it depends on the situation. Okay? So, the situation include the size of the suspect drive. So, the situation for the first part is the, the size of the suspect part. Okay? And then the time it has, basically the time required to acquire the message. And whether the investigator can retain the suspect drive or not. Okay? So, these are the, situation. Then, it depends after the situation, then it selects the one of the method. Okay? So, investigation need to needs to acquire only the data that is intended to be acquired. So, this is the first step. And the, method and the method is selected if the method is all method is selected after after knowing the situation. Okay? After knowing the situation of this crime scene, then the step two. Okay? In the step two, so let me pause the video because my PC is not charged too much. So, let me plug the charge in. Okay. Describing the step one. Then, the step two is select the data acquisition tool. So, the tool should not change the original content. Okay? So, these are the requirements before selecting any tool. So, the tool should not change the original, content. The tools should log the input output error. Okay? Then, the tool must have the availability to pass a scientific and peer review. The tools will alert the user if the source is larger than the destination. And the tools would create a bitstream copy of the original content. And there are no errors in accessing the source domain. So, these are the some considerations while choosing the tool. Okay? Then, the sanitizing the, sanitize the target media. So, there are some standards for sanitizing the media. Okay? So, there are Russian Standard, then the German, then the American. Okay? But only keep one standard for now that is the NIST 800-88 for now. You will keep this point in your mind. Okay? And what is it? The NIST part is the, the, the purpose of this is to basically, it has the three sanitizing methods. The first one is the clear, then the purge, and then the destroy. Okay? So, the National Institute of Standards and Technology has issued a set of guidelines. Okay? So, that's why I'm telling you to keep this standard in your mind. Then, acquiring the volatile data. Okay? So, volatile data acquiring involves the collecting data that is lost when the computer is shut down or restarted. And we discussed that what are the volatile data in the order of volatility. Okay? We already discussed. Then, after this, and enable right protection on the evidence. Okay? Because nobody can, destroy the data. So, enabled right protection means that if it's only allowing the read-only access. Okay? Keep this point in your mind. Then, we do the acquire non-volatile data. So, non-volatile data can be acquiring both live acquisition and the dead acquisition. It mainly involves the acquiring data from hard disk. Okay? And then the remaining part is okay. So, plan for contingency. This is already discussed. And you can also use the hardware acquisition tool or the or the drive decryption. So, these are the normal things that you have to keep in your mind. Then, the step eight is the validate data acquisition. Validate the data acquisition. And this is the last step for our methodology. Okay? So, this is all about this data acquisition methodology. So, happy learning, guys.
So, hello guys, welcome to this lecture. So, in this lecture, we are going to study the network forensic fundamentals. Okay? So, let me write down forensic fundamentals. So, let us start. So, as an integral part of digital forensics, the network forensics involves investigation of any cybercrime occurring on the network level. So, network forensic investigation entails probing into the various network-based sources of evidence to identify anomalies or the breaches. So, this in, so the investigator deals with a large amount of dynamic information to trace the source of network security incidents and present them as evidence in the court of law. So, let's start with the network forensics with the introduction. So, let me define you the what is network forensics. So, it is, so basically, it is the capturing, recording, and analysis of network events in order to basically discover the source of security incidents. Okay? So, this is the normal definition of network forensics. So, it is the, it is the capturing, recording, and analysis of network events in order to discover, uh, the source of security incidents. So, network forensics reveals many. Okay? So, for an example, it reveals the source of security incident, source of security incidents, incidents. Okay? Then, it can also the path of the intrusion, path of the intrusion, then the intrusion techniques and attacker used. So, in intrusion techniques, we can write intrusion technique and the lastly is the traces and the evidence. So, these are the things. Source. Let me collect this of source. So, these are the things that we can get from the network forensics. Okay?
Then, the postmortem and the real-time analysis. So, forensic examination of logs can be divided into two categories. Okay? Forensic examination of logs can be divided into two categories. Let me write down current examination of logs. Okay? The first one is the postmortem. Okay? And another one is the real-time analysis. The first one is the postmortem. And another one is the, uh, sorry, and another one is the real-time analysis. So, in postmortem analysis of logs is connected to investigate an incident that has already happened. So, here you can make one note that in this, in this, attack, attack is already happened. Attack is already happened. But in this, but in this, attack is ongoing. So, this is the normal difference of the postmortem and the real-time analysis. Okay? Then, let's see the some network attacks because we are discussing the network forensics. So, let's see the most common attacks on the network. So, let me write down in the header itself. Most common attacks on networks. So, the first attack is the eavesdropping. You can go and search on Google that what is this attack. I'm just telling you the most common. So, you can go and study about it. Data modification, data modification, then the IP address spoofing. Okay? [Music] Um, then the denial of service, the denial of service attack. Then, another one is the man-in-the-middle attack. Then packet sniffing. Then the enumeration. Session hijacking. Session hijacking. Then buffer overflow. Buffer overflow. Then the email infection. Then the, uh, malware attack. You can also add. And then, uh, password attack. And then the router attack. Okay? So, these are the common attacks that happen on the network. And let's see some attacks specific to wireless networks. Okay? So, some attacks specific to, some with the attacks specific to the wireless network. Okay? So, attacks related to, attacks related to wireless network. So, there are many attacks, but I'm discussing the important ones. Okay? So, the first one is the rogue access point attack. Rogue access point attack. Then the client, client deauthentication. Then the misconfigured access point attack. Access point attack. Then the unauthorized, unauthorized association. Association. And the last one is the jamming attacks. So, that's it for the wireless attacks because there are many more. But, but I think that, yeah, this is important ones. So, I'm discussing here. So, you can go on the Google and search about the each attack. Okay? So, there are many resources. So, this is all about the introduction to the network forensics. So, happy learning, guys.
So, hello guys, welcome to this lecture. Okay? So, in this lecture, we are going to study the event correlation concept and the types. So, let me type it down here. The, the event correlation concepts and concepts and the types. So, so, as the complexity of a network increases, okay, the number of alarms, the alerts, and the messages generated by applications and other devices also increased. So, uh, it is not sufficient to merely collect data from the hosts and devices and applications. As investigators also need to know when, where, and how incidents occur. So, correlating events based on certain parameters provide the investigator with insight into that how the evidence followed and whether they relate to each other or not. Okay? So, the normal definition of event correlation is that we write down here, uh, that it is the process of relating a set of events that have occurred in a predefined interval of time. Okay? That have in predefined, sorry. So, this is the process of relating a set of events that have been occurred in the predefined interval. So, it includes analysis of the events to determine how it could add up to become a bigger event. Okay? And it is usually performed on a log management, uh, platform after identifying the logs having similar properties. Then, what are the steps in event correlation? Okay? So, let me write down the steps. Steps, steps in event correlation. So, the first is the event aggregation. I will explain what is this. Event aggregation. Then, the event masking. Then, the event filtering. And the last one is the root cause analysis. Okay? These are the four steps for the event correlation. So, let's see, let's understand with an example. So, if a user gets 10 login failure events in 5 minutes, so this generates a security attack event. Okay? So, this is a small example. Then, let's see that what is event aggregation. So, event aggregation is also called event de-duplication. So, it compiles the repeated events to a single event and avoids the duplication of the same event. So, what actually that? Avoiding, avoiding the duplication of the same event. Okay? This is the event aggregation. Then, what is event masking? So, it refers to missing events related to systems that are downstream of a failed system. So, it avoids the events that cause the system to crash or fail. Avoid the events. So, uh, let me write down for you because these are the new terms. So, avoid the events. Avoid the events that, what? That basically cause the system, cause the system to crash or fail. So, this is event masking. Then, what is filtering? As the name suggests, the event correlator filters or discards the irrelevant events. So, so, you can filter it. And root cause analysis. The most complex part of the event correlation because, so, during a root cause analysis, the event correlator identifies all devices that became inaccessible due to network failures. So, then the event correlator categorizes the event into symptom events and root cause events. So, the system considers the event associated with the inaccessible device as system as a symptom events, and the other non-symptom events as a root cause events. So, these are the normal definitions.
Then, types of event correlation. Okay? How many types? So, there is only two types of event correlation. So, let me write down here for you. The types of event correlation. Okay? So, the first one is the same platform correlation. The first is the same platform correlation. And another one is the cross-platform correlation. Cross-platform correlation. So, as the name suggesting, was that in the same platform, this correlation method is used when one common operating system is used. And in this, the different operating systems of the network hardware platform for are using the network. Okay? So, let me write down the example only because as the name suggesting, we don't need the definition for it. So, for an example, an organization, an organization running only, uh, Microsoft. So, I'm writing down in shortcut, MS operating system on their, on their server, may collect event log entries and perform trend analysis diagonally. Diagonally. So, this is the example for the same. [Music] platform. And for cross, for the cross-platform, the example would be that, uh, the clients may use, may use the Microsoft Windows, but, but, but they use a, they use a Linux-based firewall and email gateway. So, here the operating systems are different. So, this is the main difference between them. Okay? Then, prerequisites of event correlation is the transmission of the data, normalization, and the data reduction. This is, these are the normal three prerequisites. So, I don't think that you need this. So, we now focus on the event correlation approaches because approach matters a lot. If you know the approach, then you are good to go. So, let me write down the approaches. Choose different color. Event correlation approaches. So, let me here, yeah, writing down in the sequence. I'm just giving the numbering. Okay? 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, and 13. So, the first one is the graph-based approach. Graph approach. Then, neural, neural network-based approach. And the third one is the codebook-based approach. Then, the fourth one is the rule-based approach. Then, file-based approach. Okay? Can, then auto-correlation. Then, the packet parameter or the payload correlation for or network management. Then, the profile or fingerprint-based approach. Then, the vulnerability-based approach. Then, open port-based correlation. The 11th one is the Bayesian correlation. P a y s i n. The 12th one is the time clock, time or role-based approach. And the 13th one is the route correlation. So, these are the 13th event correlation approaches. Okay? So, search on Google by yourself. I'm just giving you the name of it. Okay? So, this is all about for this lecture, guys. Happy learning.
So, hello guys, welcome to this lecture. Okay? So, in this lecture, we are going to see the indicator of compromise. Okay? So, basically, we are targeting the network logs. So, indicator of compromise that is also written in the IOCs. Yeah. So, after collecting the logs from various network devices and applications, investigator must monitor and examine them. Okay? For the indicator of compromise. So, basically, the indicator of compromise here stands for the, the sum indicator means the data or the proof or the compromise that, yeah, compromise happened. Okay? So, which indicates that a security breach may have occurred. So, IOCs are generally found in the metadata of logs, which require careful monitoring and the examination. So, let's start with the analyzing the firewall logs. Okay? So, analyzing the firewall logs. So, here, what things that you will notice that firewalls are the first point of entry into a network. Okay? And it stores details of all the data packets moving in and out of the network. So, the network firewall logs collect the network traffic data. Then, such as, for an example, the request source, the destination, then the port used, time, date, and the priority. Okay? So, these are the details that basically helps the investigators. Okay? And correlate the data with other suspicious files to identify the source and other targets of attack. So, timing and suspicious IP addresses, then, uh, application generated requests, DNS query, suspicious IP address, and URL. So, in firewall logs, what you will notice or what you will check? So, you will check for the application generated requests, then the DNS queries, then the suspicious IP address, and the last is the URLs. So, these are the things that you will notice in the analyzing while analyzing the firewall logs. Okay?
So, there are Cisco firewalls. Okay? So, Cisco firewalls use mnemonics as identifiers to represent the severity of events. So, there are many severities. So, for an example, uh, the severity starts from the 1 up to 6. Okay? So, Cisco firewall logs include something. Okay? Then, Cisco firewall logs in the details. So, if you're using the Cisco firewall, then you have to know that what are the details that you will find in the Cisco firewall or in the Cisco firewall logs. So, the first one is the date and time. Then, the mnemonic, mnemonic messages. Then, the firewall action. And the fourth one is the source and the destination IP and port. Okay? And the type. And the last one is the type of request. So, these are the some important things that you will notice while analyzing the firewall logs. Okay? So, the severity from the 1 to 6 that I already told you. Then, the important things while analyzing the Cisco firewall logs. Okay? So, there are some checkpoints while analyzing the firewall logs. So, basically, the checkpoint firewall logs can be viewed through the viewed through a checkpoint viewer. Okay? So, there are some icons. You can go on on Google and search for this. Some icons used in checkpoint logs. And then you will study. So, there are mail allowed icons, URL allowed icons, connection accepted, or the connection decrypted. So, there are many types of icons. So, checkpoint firewall log when view, log when viewed through checkpoint log viewer. Okay? So, if you want to checkpoint the firewall log, then you will use the checkpoint log viewer that displays the result. And, uh, the event log color coding is in three, that is for the red, orange, and blue. So, the color is red, that indicates the error messages. Error message. Then, the orange, that tells us the warning message. And the last one is blue, that tells us the information. Okay? So, these are the colors and indicators. You can see easily on the Google itself. Then, after analyzing the firewall logs, we will see the analyzing the IDS logs. Let me change the color. So, analyzing IDS logs. So, IDS stands for the Intrusion Detection System. So, IDS logs provide information help in finding suspicious packet types. Okay? Determining the props generating the new attack signature and measuring the attack statistics. Okay? So, general indicator of intrusion that you can see is the, so, general indicators of intrusion. The first one is the request targeted towards known vulnerabilities. Okay? So, request targeted towards known vulnerability. Wait a second. Okay? Then, the failure, failure to comply with protocols. Okay? Is the second point. Then, the address, address anomalies in traffic. Okay? So, these are some points that you can notice. So, these are some general indicators of intrusion. Okay? Then, you can also note the occurrence of M-type commands. So, M-type commands. Okay? So, these are the indicators. Then, the checkpoint for the IDS is the, uh, the first one is the good. If you are using the, the inbuilt software. Okay? So, for the managing device. So, steps to view and access logs in checkpoint IPS is the go to the Smart Dashboard and click on the Smart Console. So, you can just, you can explore by using the tool itself. Okay? So, if I'm telling you the steps, then you can't understand. Okay? So, basically, the checkpoints also provide the details of each log. So, to view the details of any log, go to the Smart View Tracker record list and double-click on the event, and then you can usually see the logs. So, after that, we will see the, the analyzing the honeypot logs. Let me change the color. Will be open. So, and analyzing the honeypot logs. So, what is honeypots? So, honeypots are devices. Okay? That are deployed to fool the attackers. Okay? So, basically, these are paired to contain very useful information to lure the attackers and find their whereabouts and the techniques. So, for an example, in your organization, you deploy the honeypots. Okay? So, if the attacker wants to attack in your organization, then they will encounter the honeypot first. So, what they think that, yeah, this is the main device. So, from this device, I can gather too much information or can I steal information. But the main scenario is that we deployed that thing to fool the attacker or to lure the attacker for what? To find their whereabouts and their techniques. Okay? So, the KEEPO is one of the most commonly used honeypot. So, what the name it is? KEEPO. You can search on Google for more description. And KEEPO contains the four things. The first one is the timestamp. So, what it contains? The first one is the timestamp. Okay? Then, the type of session. Type of session. Then, the session ID and the source IP address. Session ID and source IP address. Okay? And the last one is the message. The collected details for messages. So, these four things that KEEPO contains. Then, we will see the analyzing the, uh, router logs. In the routers, so, basically, the router stores the network connectivity logs. Okay? Which details, such as the date, time, source and destination IP, and the port used. And this information can help investigators in verifying the timestamps of an attack. So, this also enables investigators to correlate various events to, uh, identify the source and destination IP. So, the incoming log details contain some throwing data. Okay? So, the incoming log details are as follows. The first one is the date and time. And the second one is source IP. Let me write source IP. IP. Then, the source IP, then the destination IP, then the source port, source port, and the destination port. So, these are the some metadata. So, the outgoing logs contain. So, this is the incoming part. So, outgoing log details are, uh, the date, then the time, then the source IP, then the source port, then the URL access. Okay? And the URL IP addresses and the port use. So, these are the outgoing log details. Okay? So, you can also analyzing router logs with the help of the Cisco. So, Cisco routers run on a specific operating system that is known as the Cisco IOS. And the operating system has a built-in security manager that defines policies regarding basic logging and the parameters. So, the right router compiles with CIS log standards to define severity levels with numeric codes. Okay? So, the, uh, let me write some Cisco router logs. It is the same as the, you can see there are data that is common in that we studied till now in this lecture. The date, time, the source and the destination IP, and then the protocol use. So, in the network, this is the normal thing that can occur in every device. Okay? So, writing down the same thing is not a good practice. So, that's why I'm not writing down. So, let's see the analyzing the DHCP logs. Analyzing the DHCP logs. So, where the DHCP logs are saved in the, in your PC? The path is the C directory, then the Windows, then the System32, and DH. So, this is the path where the logs is stored. So, DHCP server logs file format. So, there are some formatting or the format type is the basically the ID, the source IP, then the destination. Only the two, two things that will add. The first is the hostname and the MAC address. And the rest is rest remain same that we discussed till now. So, these are for the DHCP part. So, yeah, this is all about the indicator of compromise where you see the data. Happy learning, guys.
So, hello guys, welcome to this lecture. So, in this lecture, we are going to see the functionality of Wireshark. Okay? So, if you are doing the network forensic, so you must have the knowledge related to network, that how actually the network is working, what are the things that you have to notice, what are the, uh, filtration techniques, okay, how packets look like. So, let's start with the network forensic basic practical. So, we are opening the Kali. Okay? And then we are using the Wireshark. And then let's capture the live network and analyze it. Okay? Yeah. So, it is open. [Music] So, just click on the symbol, the left one, the Kali symbol. Okay? And then type Wireshark. Okay? This is the Wireshark. Click on it. Open this screen. Then, select the eth0. Because whatever we are using, it is eth0. Because in Kali Linux, we don't have the Wi-Fi by default. So, we are using the Ethernet by the internal side. So, we are selecting the Ethernet adapter. Okay? So, double-click on it. It will start capturing the traffic. So, it will start. Let's open the browser. This is the normal traffic, uh, for the my. There are many traffic that is ongoing for this simple Network Management Protocol. Okay? Then load balancing, then routing protocol. So, don't worry about it. Okay? Just open your favorite browser and let's just start with the, uh, face for. So, this is the website of facebook.com. Stop the capturing of the packet. We already captured around, I think, this is 627 packets. Okay? So, let me see the three-way handshake. Okay? I think that you are familiar with the three-way handshake that how three-way handshake actually occur. So, uh, first, let me tell you my IP addresses. Okay? That what's my IP addresses. Then, we will, uh, then we will see that this, new tab, and the command for seeing your IP addresses is IP config. Sorry, ifconfig. I always confuse between the IP config and ifconfig. So, click on ifconfig and you'll be able to see your IP addresses. So, my IP address is 10.0.2.15. Okay? So, let's see the traffic that we captured and let's notice that where actually the three-way handshake happened. So, uh, what's our IP address? A 10.0.2.15. So, our traffic will start from this. Then, we send our this to the private IP addresses for the DNS. Then, again, DNS for the standard query. This is for type A addresses. And this is for type 6 addresses. Because we can see single A, and here it is 4A, stands for the IP bases. Okay? So, let's, let's see that where is here. You can see that if, uh, the DNS is happened. Okay? So, after happening the DNS, we will get the IP addresses. We can also see that we will get or not. So, let's analyze one of the request coming from our private network to the, this, this is a domain name, uh, so this is the domain name response, standard query, noer authority, name server, the type, this is the queries, content server, type triple4, flag is this query is this, okay? So, this is, then, um, this one. Let's see. No, this is not. This is here. From this, from packet number 14, our sync starts. Okay? So, let's see the, 13 packets answer. The answer type, this is the IP addresses. You can see 34.117.18.188 and 166. So, this is the answer from the DNS that our system did pass it firstly. And then we are going to, basically, going for the three-way handshake for the Facebook part. Okay? Then, uh, you can also confirm the IP addresses by pinging it also. So, let's ping 34.117.18. [Music] 8.18.188. And dot 166. So, you can see the IP is working fine. And [Music] command. So, so, let's see. Let's forget this. We are focusing on the same part. So, after having the IP addresses, the public, this is for the Facebook, the sync starts. So, let's focus on the 15 packet. Okay? We are basically distracting from our main topic. So, let's focus on the network forensic for now. So, we are focusing packet number 15 of this one. This one, packet number 15. So, you can see, sorry, starting from the 14, my, my, my bad. So, packet number 14, you can see that the first message is for the sync. The source port is randomly selected, that is 57796, and the destination is 443. Okay? And this is the sync packet. So, we can go into the TCP, go into the flag, and we can see that there, the SYN set one. Okay? The SYN is happened. Then, from the destination or the Facebook part, we
Will we receive the SYN act, okay? And the source is 443, and the destination is 577, uh, sorry, 96. So this is our second step of the three-way handshake, okay? And at last, we're sending the ACK message to the Facebook that, okay, we completed the three-way handshake. And after that, there is the HTTP connection request, the hello request, okay? Then the hello cipher. And this is the application part, but we are only focusing on the networking part, okay? You can also filter out by HTTP, then you can only see the HTTP part. Then let's see from where we get our, uh, this one. There is one more thing we can also do, starting from the SYN. Where is this 14 packet number? Uh, this is the 14. Just click on the right, okay? Just click on the right, follow and TCP stream. So this will give you the whole packet information, okay? So this is only for the three, 3. But if we click on the 30th packet and go again, follow TCP stream, then you will see here the data part. Wait a second, application data, follow with TCP stream. So I think it is requesting the data. Long, it's sending the data. This, this is okay, no worries. So here we completed the, we see how actually the three-way handshake happens, okay? We see some protocols that TCP is using in this thing. The three-way handshake, we are using the HTTPS with TCP. The TLS version is version 1.3. So this is all about the basic network fencing, okay? And in later, we will see more about network fencing. So happy learning, guys.
Hello guys, so welcome to this section. So from this section, we are going to start the malware forensic. So before starting the actual malware forensic, okay, we are basically starting the introduction to malware. So without the basic knowledge of malware, we can't do the forensic, okay? So that's why I just want to, uh, cover the introduction to malware and then we will keep forward for the malware forensic part. So let me start with my paint. So we are starting with the introduction to, introduction to malware, okay? Introduction to. So what is a malware? So in a normal way, a malware, a short form for malicious software, okay? It is a program that is capable of altering the properties of a target device or application for providing limited or full control of the device to its creator. So if we see what is malware in a layman language, then it is the, then it is the malicious software. It is the, or we can say that, uh, harmful, harmful software or line of code, okay? Harmful software or line of code. So this is the normal definition and very easy definition of what is malware, okay? And a malware is useful when an unauthorized person wants to illegally access a logged or secure device. So there are different types of malware, okay? So for an example, if you want to see some of them, then starts with the, uh, for an example, the this one. No. [Music] Sorry, this one. Let me draw it for you. This, wait. So start with the first type that is the virus. That is the virus. Then we have worms. Then we have, sorry, then we have trojan. Then we have rootkits. Then we have rootkits. Then we have ad-ware. Okay? There. Then we have adware. After adware, spyware. Spy. So there are many, okay? We will study what is this, okay? I'm not just, uh, explaining you the name that this is the type of the malware, but also going to explain a little bit about that what is virus, what is worms, and what is trojan, and all of them, okay? So be patient. So these are basically can delete files, slow down the computer, steal personal information, send spam, or commit fraud. So malware can perform various malicious activities, okay? So ranging from simple email advertising to complex identity theft and password theft. Then the question arises, malware programmers develop and use it for what? For attacking, for attacking the browser, for altering the system performance, or causing hardware failure, some stealing information, okay? Erase the important information, okay? So these are the uses of malware. Why hackers are creating malware for these purposes? Basically, it uses malware to break down the cybersecurity. In summary, it uses some malware, let's say it uses to break down the, break down the cybersecurity. We this, uh, sphere of cybersecurity, first security, okay? So the main uses of malware to break down the cybersecurity. Now, the most common ways an attacker can send the malware. So let it draw, uh, yeah, ways to send the malware. So again, there are many ways, we will see the important ones, okay? Sorry for the drawing, I'm just trying to make as clean as I can. So the first way to send is the instant messenger, instant messenger, and, uh, internet, internet relay chat, okay? This is the first way that malware can be sent. Then another one is the, uh, removal devices, removal devices. Then the most common way is the email and attachments, okay? Then from the browser and software bugs, okay? Then many more. So I'm writing down here whatever the file downloads, file downloads, we can, they can use them, the network file system, okay? And there are many more, okay? So these are the ways to send the malware. Let me open the new tab.
Okay, so now let's see the components, basic components of malware, okay? [Music] So, basic components of malware. What are the components of malware, okay? So we will start with the first one that is the crypter. That is the crypter. So this is the software type that that disguises malware as a legitimate product through encryption or obfuscation, thus protecting it from detection by security programs. So we can see, we can write that protecting from detection. The the crypto helps us to protecting from detection. This is the normal way to write, okay? Then the another one is the downloader. The another one, downloader. Let me see that, is it wrong? Yeah, downloader. So the type of trojan that downloads other malware from the internet onto the PC. Usually, attackers install downloader software when they first gain access to a system. So, um, to download more things, okay? Uh, such as more, more malware. They can say this is its working of window. Then the third one is the dropper. As the name suggests, a type of trojan that installs other malware files onto the system, either from the malware package or the internet. So this is kind of the dropper. The same functionality of the downloader and dropper, but only the minor difference is that in downloader, a trojan that downloads other malware from the internet on the PC, okay? And dropper is that installs other malware files onto the system, either from the malware package or the internet. So a dropper can download the things from itself, from the malware package, or the internet. But the downloader only downloads the other malware from the internet itself, okay? So to download the same, to download, to download on the malware packages, okay? This is the working of dropper. Then exploit. Exploit, we can write down that is the malicious code for the exploit. Then there are many fields, but we are just only using the some of the, uh, some of the components, okay? So let me write now the another, uh, other components for you. Others are, you can read about yourself, okay? So the another one is the injector, then office getter, okay? Then the packer, then the malicious code, and the last one is the fileless malware. So these are the components of malware, okay? You can search on the Google and you have the many description or many, many definition of it. So you can go through it by your own. I'm not explaining each of the time, but I explained a little bit about it. Common ways I already told the techniques attackers used to distribute the malware, okay? And there are also, uh, ways to distribute across wave is the, if the, uh, basically the malicious hacker wants to distribute the malware across wave, then what it will use for the distribution is the, the first one is the black, let me change the color, is the first one is the black hat search engine optimization, black hat search engine optimization, okay? What it does? It basically, uh, increases the chances of occurring the malicious website to the top of the search. So for an example, we go to Google and type that, uh, uh, tutorial for Python, okay? So there are many sources for the Python, but if you do the black hat search engine optimization, then the first website or the top three, top four websites in which our website will be there because we did the black hat search engine optimization, okay? Then there is another way is the social engineer clickjacking, social engineered clickjacking, okay? Then they also malware, malvertising, okay? Are the another way, malvertising, and there are different ways, okay? The one famous one is the drive-by downloads. So user don't know about it and they got the malware as a gift, okay? So these are the normal techniques. So this is all about the basic malware, okay? If you want to go through the, that I told you the different types of malware, so let me recap once if I'm not a little, uh, I, so you can go through the, go through on the internet, okay? You can easily find many sources that is defining you that what is virus, what is worms, okay? So this is all about the basic for the malware part, and let's see, let's meet on the another lecture, okay? Happy learning, guys.
So hello guys, welcome to this lecture. So in this lecture, we are going to study the understand the malware forensic fundamentals, okay? And also see the types of malware analysis. So let's start with the malware forensic fundamentals, malware fundamentals, okay? So, so once it is suspected that a machine is infected with malware, okay? So a digital forensic team is often called for verification and further investigation. So forensic investigation needs to locate the malicious software and determine its functionality, origin, and possible impact on the system, as well as the network. So let us start with the, what is malware forensic? Okay? So often attackers use malware such as that we discussed, the viruses, worms, trojans, and spyware, and the ransomware to commit a crime on the intended target system. So for an example, if anybody asks you that what is malware forensic, so you can say that that malware forensics, malware forensic deals with identifying, identifying and containing malicious, malicious code and examine, sorry, and examine its behavior, behavior in a controlled environment because if you don't use a controlled environment, then it can affect another system on that network. So that's why a controlled environment is necessary, okay? In a controlled environment, okay? So performing malware analysis enables investigators to know the types of malware, how it works, their behavior, and its impact on the target system. So it helps us to know, it helps us to know, uh, the type of the, type of malware, type of malware, then how it works, how it works, then its behavior, behavior, and its impact and target system, okay? So these are the things that we came to know after the analysis. And you can use a set of tools and techniques to conduct the different types of analysis, okay? So in, in basically, in a few minutes, we will discuss the types of malware analysis, okay? So for now, this is the introduction part. So let's analyze that why analyze malware? So if somebody asks that why we need to analyze the malware, then what you will say? For an example, why analyze malware, malware, okay? So there are different answers, okay? Let's start with the first one, to, to determine what exactly happened, okay? After the malware analysis, you came to this conclusion, and to determine the malicious intent of the malware, intent of the, intent of malware, okay? Then there are many, okay? So for an example, to find the indicator of compromise, okay? Then to identify the exploited vulnerability. So you can also to find vulnerability or exploited. Let me write down the whole sentence, vulnerability, okay? And there are many more points. So for an example, to identify the extent of damage, okay? To find signatures for host and network-based intrusion detection systems. So these are the reasons that why we need malware analysis, okay? Then came, then come to the point that what are the challenges of malware analysis? Because malware is not an easy job. If you are performing a malware analysis, it is same like performing a very tough task as compared to the memory forensic that is volatile, and malware is also works in the RAM. For an example, most of the malware resides, not exactly resides in the RAM, but yeah, resides on the hard disk, but its working is happened on the RAM. So it is not an easy job. And the main thing that we have to keep in mind that the malware can travel to another system, okay? So we have to be, basically, we have to keep our environment very, uh, restricted way. So for an example, if we, uh, do some mistakes by during the analysis, okay? So the chances of malware to go beyond the network is less. So that's why. So let's see that what are the challenges. So challenges, challenges that we will face. The first one is the accuracy of the analysis process, so accuracy of the analysis process, okay? Then the second one is the detection of malware pieces and threads, so detection of malware pieces and traits, okay? Then third one is the amount of data to be analyzed, amount of data to be analyzed, okay? Then, uh, changing technology. This is the more challenging thing for changing technology because we have to keep ourselves updated, okay? If the new technology came, new attack came, new methodology of doing attack came, then we have to change our methodology for analysis, okay? So these are the challenges we will face. Now, how you can identify and extract the malware? So if a user has reported a suspicious activity, okay? On his or her system, you must examine the following areas of the compromised system to find traces. So what will be the areas you will notice to find the, uh, basically identify and extracting the malware? So areas to be focused, okay? If you find something malicious, then what are the areas that you will notice or you will suspect? So identifying, identifying and extracting the malware, identifying and extracting the malware. So the first area is the installed program, okay? Then the scheduled jobs, then logs, then the registry entry, then the services, services, and many more. So the file system, okay? Uh, then the modules, you can also notice, and the, yeah, executable files, executables, okay? So these are the areas that you will focus if you find any suspicious activity. Then how you could, basically, prominent of setting up a control malware analysis lab? Okay? So this is the main part of the malware analysis that how you can control the malware analysis lab. So importance of virtual environment for malware analysis is very high because it protects real systems and networks from being infected by the malware under analysis and easy to analyze malware interaction with other systems. So virtual environment for malware analysis, this is the best practice that you can follow. So this practice is to, this practice is, sorry, this practice is to use, use the virtual environment for malware analysis, okay? Don't use in your system. Now, after covering the basic of malware forensic, uh, let's see that how we will prepare a test bed for malware analysis, okay? The test bed. So let's write down the test bed. So preparing test bed for malware analysis, yeah. So the first point that you will note in your notes that allocate a physical system for the analysis lab, allocate a physical system for the analysis lab, okay? Then install malware analysis tools, okay? And then you can also disable the, disable the shared folders, disable the shared folders, and the, guest isolation, guest isolation. Then install virtual machine, install virtual machine, and, uh, then generate hash value of each operating system and tool, okay? So these are some key points. And one more point that is very important that isolate the system, isolate the system from the network, from the network by, by ensuring that the NIC card, NIC card is in, and NIC card is in host-only mode, okay? So these are the test bed for malware analysis. So we covered, covered many things. So we covered the best practices, we covered the pre-bade, we covered the definition of malware forcing, then the challenges, then the identifying and extracting malware where you will see if you find something suspicious, then why analyze malware, okay? The last thing that is supporting tools for malware analysis, okay? Tools, because we can't do analysis without tools. So let's see the supporting tools. So tools for malware analysis. So the first one is the hypervisor that comes under, uh, the virtual machine, okay? Hypervisor such as the VirtualBox, VirtualBox, or VMware, VMware, okay? Then the network and internet simulation tool, so network, network and internet simulation tool. So comes under here is the, the NetSim, okay? Then the NS3, and you can also include the QualNet. Then screen capture and recording tools, screen capture and tool in which you can use the Camtasia, Camtasia, and the, this, uh, Saget. And the last thing that is the backup, backup and imaging tools. So here you can use the hard drive, hard drive image, or the backup, backup and disk image, disk image. So these are the supporting tools for the malware analysis, okay? Now let's, uh, note the point what I'm saying, uh, the general rules for malware analysis. So during the malware analysis, pay attention to the key features instead of looking at each and every detail, okay? And you can also use, try different tools and approaches to analyze the malware, okay? And then identify, understand, and de-obfuscate new malware analysis prevention techniques. So these are the general rules for malware analysis. Then the types of malware analysis. Then we will see the types of malware analysis, types of malware analysis, okay? So there are only two types for malware analysis. So the first one is the static malware analysis, static malware analysis, and another one is the dynamic malware analysis. So let me tell you the difference, what are the main difference between them, okay? That are the main difference between them. So static malware analysis is also known as code analysis, okay? Static malware analysis is also known as code analysis. So it is also called code analysis, okay? And dynamic one, it is also called as behavior, behavioral analysis. So these are the first point or the difference between them, okay? Then in a static, it involves going through the executable binary code, okay? Without its actual execution, have a better understanding of the malware and its purpose. But in the dynamic, it involves execution, the malware code, okay? So here it involves, it, it involves going through binary, going to the, uh, executable binary, executable binary, okay? We are not running it, only studying our analysis by seeing the code. But here, but here it involves executing, okay? Keep this point, executing the malware code. So these are the second points and the important points of both of them, okay? Then in static malware analysis, this, this assembler such as IDA Pro can be used to disassemble the binary files, and in dynamic, debuggers such as GDB, WinDbg are used to debug a malware. So here, this works, here this assembler works, and here debugging, here debuggers work, okay? So these are the main, main difference between them. But both techniques are intended to understand the how the malware works, but the different tools used, and the time and the skills required for performing the analysis, okay? Both static and dynamic analysis are recommended to better understand the functionality of a malware. So these are the difference. But at the end, what we have to do is to basically understand the, what is malware and what is, what it is working, what its intent to do, how many things it will harm, okay? So these are the main points. So this is all about this lecture. And in the further lecture, we will start with the, uh, static malware analysis, and then the dynamic malware analysis, okay? So happy learning, guys.
So hello guys, welcome to this lecture. So in this lecture, we are going to see the static malware analysis, okay? So let's begin with the static malware analysis. So, so static analysis is referring to the process of investigation, investigating an executable file without running or installing it, okay? So we don't need to run or install anything, only we are investigating something. So it is safe, yeah, to conduct the static analysis because we are not installing or executing any susceptible file. However, but some malware does not need installation for performing malicious activities. So, uh, for this, it is better for investigators to perform static analysis in a controlled environment. So let's start with the static analysis. So analyzing the binary code provides information, okay? Such as the data structure, then function codes, graphics, call graph, okay? Etc. So let's see the some techniques. You know what is malware, uh, sorry, you know static malware analysis and the dynamic, we discussed in the previous lecture. So we are, I'm not going to discuss again. So we are just come to the point that some static malware analysis techniques. So we will discuss the techniques for malware analysis, yeah. So let me write down techniques for static malware analysis. So the first one is the file fingerprinting. The first one is the file fingerprinting. We will do the file fingerprinting to see, is there any susceptible code or is there any susceptible, uh, code or some exploit residing in the file, okay? So and after then, online malware searching. Online malware searching. Then we will do performing the string search, string search, okay? Then identifying the, uh, packing or offer methods. So identifying the packing, we can say packing the methods. Then we will do the finding the portable executables, okay? We will finding the portable executables information. And the last, not last, the second last, identifying the file dependency. So identifying the file dependencies. And the last one is malware disassembly. So this assembly. So these are the points or techniques for static malware analysis, okay? I'm elaborating something. So in file fingerprinting, basically, we are examining the evident elements of the binary code, okay? Which include processes at a document level, yeah. And in online malware scanning, so for example, after the hash value of the susceptible file has been generated, so investigator can compare it to the online malware databases to confirm that it is malicious or not, okay? After generating the hash value. Then, performing the string search. So software programs include some strings that are commands for performing specific functions. So various existing strings can represent the malicious intent of a program, okay? So for an example, in a string, is there any path traversal? Is there any, uh, execution of command in a string? Okay? So we will have to notice these things. Then the identifying the packing or obfuscation methods. So the attacker uses packing, okay? By using jumbled structure or, uh, or a packet to avoid detection, okay? Then the PE format stores the information required by a Windows system to manage the executable code. So PE stores the metadata about the program, so which help us for, which help us in finding the additional details of the file. Then file dependencies, okay? Then the malware disassembly. Then for an example, we are doing the file printing, okay? So for, we are doing the file printing. Let's see, we are doing the file printing. Then it is recommended to compute the hash, okay? For the given binary code. Then common hash calculator, okay? So the flow is the, flow is the calculate the hash, okay? Then after calculating the hash, uh, then we will, we can use the computed hash value to periodically verify if any changes is made to the binary code, okay? So notice any changes periodically. So these things we can do, okay? This is for the file printing, file fingerprinting, okay? So there are many tools. So for example, the tools are hash my files. The tools are, tools are, tools, basically, they hash my files, okay? And there are many more. I'm just discussing the main, main tools. Then online malware scanning, you can also do on the VirusTotal. So the VirusTotal, you can also use VirusTotal, okay? VirusTotal. Then performing string search. For, we are basically, string communication information from the program to its user. So analyze the invented string, the ASCII value, the Unicode formats. So we will do with the help of the resource extract, okay? So resource extract is a small utility that scans DLL, EXE files and extract all resources stored in them into the folder that you specify. So we can use this tool in user interface mode or you can run in command line mode without displaying any user interface. So for, performing string search, we can use the resource extract, okay? So for this, we can use the resource extract. So this is for the online malware searching, okay? Then, uh, static malware, in which we will see the identifying the packing methods. So attackers often use packers to compress, encrypt, or modify a malware executable file, okay? So for this, we will use the PEiD. So basically, PEiD detects most common packers, crypters, and compilers, okay? So for this, we will use for performance string search, we will do the PEiD. I'm just sharing you with the few knowledge and the, the tools that help you to perform the analysis, okay? And, uh, then after this, the finding the portable executable information, okay? So for this, uh, we can use the, uh, PE, uh, PE Studio, okay? So the goal of PE Studio is to spot artifacts of EX files in order to ease and accelerate malware initial assignment. So this tool is used by computer emergency response teams, security operation centers, and labs worldwide. So identifying the packing method for this, PE Studio. So let me write down, okay? This, PE Studio is okay. Now, what's remaining? The identifying the file dependencies. So there are many DLL files. For an example, the kernel, adab, then user32, vinit, okay? So there are many DLL files. So we can use the Dependency Walker. So this tool lists all the dependent modules within an executable file and builds a hierarchical tree diagram. So for this, we are using the Dependency Walker. So let me write down here, Dependency Walker. Sorry, Depend, sorry, Dependency Walker for the sixth party, identifying the file dependencies. So note down it. And, uh, for the finding the portable executable, there is a PE Studio. So PE Studio is written correctly. PE Studio is for the fifth number. Keep notes. PE Studio is for the fifth number. And Dependency Walker for the sixth, okay? And then one remaining, one remaining that is the malware disassembly. So for malware disassembly, we can use only GDB, only GDB. HolyDBG. I think one tool is missed by myself. Let me notice one thing that, uh, for identifying the file system, it is the Dependency Walker, okay? So note down it. And, uh, for the finding portable executable, there is a PE Studio. So portable executable, PE Studio. The last three, one, the last three, one, the only the Dependency and the PE Studio is okay for the seventh, sixth, fifth, okay? Then what's missed by me? Let me explore it. Then finding the portable execution, it's done, the PE Studio. Okay? PEiD for the, uh, packing the methods. PEiD for the packing the methods. Yeah, it is written. Then performing string search. I think I missed. No, performing for performing string search, it is the resource extract, okay? So keep note it. Then on online malware searching, it is the VirusTotal. Yeah, all done, all done. And the file fingerprinting, it is the, it is the way. I'm not discussing the tool. So this is the way. And after the way, the calculate the hash, okay? So keep note that after this part, after this part, the first one, whatever I discuss, that is going in sequence way, okay? So the tool for the online malware setting is the this one, this tool one. And after that, all is just little bit the side is up. No worries. The format is up. No worries. So this is the malware analysis static. We can, we discuss all the tools and all the techniques that help us to do the, uh, static analysis. Then, then what we are remaining in the static malware analysis is, uh, yeah, I think it's done. The static malware analysis is all about this, okay? So we will discuss the dynamic malware analysis in the next lecture. So happy learning, guys.
So hello guys, welcome to this lecture. So in this lecture, we are going to study the dynamic analysis for, dynamic analysis for malware, okay? So malware dynamic analysis. So what is dynamic malware analysis? It refers to the process of studying the behavior of the malware by running, by running it in a monitored environment. So this is the definition of malware dynamic analysis, or we can say the dynamic malware analysis, okay? So there are two approaches, okay? So there are two approaches to dynamic malware analysis. It means, right down here, the two approaches, there is two approaches, okay? So the, so the first approach is the monitoring the host integrity, monitoring the host integrity, okay? And the another approach is observing runtime behaviors, sorry, observing runtime behavior. So monitoring host integrity involves taking a snapshot of the system. So what it involves? Let me write down the point, the snapshot of the system, okay? A snapshot of the system state using the same tools before and after the analysis to detect changes, okay? So this is the monitoring the host integrity. And here, observing runtime behavior means that it, it involves live monitoring, it involves live monitoring the behavior of the using malware as it runs on the system, runs on the system. So these are the main two types, or we can say that the two approaches to dynamic malware analysis, okay? So the pre-execution preparation for the dynamic memory, dynamic malware analysis, okay? So the pre-execution preparation, what it includes? The first one is the create a fresh baseline of the forensic workstation, okay? So you have to firstly create the baseline. So you compare, or then the take the snapshot of of the registry keys, registry keys, file system, running processes, and event log files. Then list all Windows services, drivers, and the startup programs, okay? And startup programs. Then the fourth one, the fourth one is install tools, okay? Installing tools. Installing tools that will capture the changes performed by the malware on system resources such as registry, file system, processes, etcetera, as well as network properties. Then I'm writing down here, okay? The fifth point is to generate hash values of the operating system and the tools. You have to also generate the hash value for tools also, okay? So keep this point. And then at last, run the malware on the forensic workstation, okay? So these are the six steps for the pre-execution preparation. So before doing the malware analysis, these are the prerequisites, okay? Let me explain it briefly, all the process. So creating a fresh baseline of both Windows and Linux workstations, which should include the details of the file system, registry, running processes, and the, uh, yeah, event log files, and etcetera, okay? So you can compare this baseline state with the system state after executing the malware, okay? Then monitoring the host integrity, okay? So monitor the host integrity is basically upon creating the baseline image and run the malware on the Windows forensic workstation for a certain time period. So we are basically monitoring that is there any changes in the host integrity part or not, okay? Then observing the, uh, runtime behavior. So system behavior analysis and network behavior analysis, we have to see, okay? So let me, uh, explain it more about the observing the runtime behavior because this matters a lot because we are observing the things that gives us a positive result, okay? Not the false, false positive. So let's write down the, observing runtime behavior, okay? So observing runtime behavior, okay? So it refers to the execution of the malware on forensic workstation and observing the operating system in real time to understand its intent and functionality. So you can also learn about the behavioral characteristics of malware by monitoring its activities on the system and the network. So observing runtime behavior is divided into two parts. The first one is the system behavior analysis, okay? And the another one is network behavior analysis. So let me write down the first one is the system behavior analysis, and the another one is network behavior analysis, okay? And let me explain a little bit about both of them. So in system behavior analysis, it involves the monitoring the changes on operating system resources upon the malware execution, okay? So, uh, system behavior analysis includes many things. So for an example, the monitoring the registry artifact, monitoring the processes, monitoring the services, and startup folders, and there are many more, okay? And the network behavior analysis, it involves the tracking the malware network level activities. So network analysis includes the monitoring the IP addresses, looking for the connected ports, or examining the DNS services, okay? So you can also perform the system behavior analysis and the network behavior analysis, okay? So system behavior analysis basically in which, uh, we can monitoring the registry artifact, okay? So malware manipulates the registry to ensure that it's runs automatically whenever the computer boots or the user logs, okay? So what we have to see for the monitoring the registry key, let me draw one chart for you, okay? So at the top, there is a monitoring registry artifact, okay? At the top, and let me draw a square for it, okay? Then, uh, delete it. The downside arrow I want to draw. Yeah. And after that, uh, there is monitoring registry activity after the analyzing auto start, auto start registry location, okay? Auto start registry location. So this is the second thing, okay? And then the three things, uh, let me draw in this way. The first one, the second one, and the third one, okay? Then the first one is the Run keys, Run keys. The second one is the Run, the second one is the Run once keys, and the third one, and the last one is the startup keys, okay? So this is the normal flow of the monitoring the registry artifact. So by running the malware on Forensic workstation, you can observe its activity on the registry and look for specific keys or values that are read, created, modified, or deleted by it. So look for Windows auto start registry locations that are commonly targeted by malware to present on the system, okay? Then Windows auto start registry keys in which there are more things. For an example, if you see the Run keys, then in which there are many, uh, keys, then startup, there are many things. So I'm not going too much deeper into it. You can also explore the registry key by your own, okay? You can use the Registry Reaper that comes with both GUI and the command line tools that can parse keys, values, and data from the registry, okay? So the tools for the auto start registry key, analyzing the Windows auto start registry key, the name is Registry Reaper. Let me write down for you. The tool name is, uh, the tool name is Registry Reaper, okay? So we covered the analyzing Windows auto start key. Then we will, for the system behavior analysis, we can also monitoring the processes, okay? So you also use Process Monitor that shows the real-time file system, registry, and process and thread activity. So for system behavior analysis, we can also monitoring the processes, and in which we are using the Process Monitor tool, okay? Then Windows, monitoring Windows Services, okay? For this also comes into the system behavior analysis, and this is a tool that can help trace malicious services, okay? So we covered the system behavior analysis, not at too much depth, but yeah, you cover at least the 80% of this, okay? Then for startup program monitoring tool, there is Autoruns for Windows, okay? So you can use the Autoruns. I'm not discussing the commands for the tools, but I'm just telling you the name of the tools, so you can go and explore by it yourself. Then there is another tool that is monitoring Windows Event Log, okay? So you can also go through it for this also. So this is all about the system behavior. Then let's cover the another part, little bit. So just wait for 1 minute. Basically, I'm searching one more tool so that I'm forget. Uh, no worries. Let's see the network, network behavior analysis, okay? So start with, let me open the new tab for you. Yeah, so we are doing the network behavior analysis, okay? So in which the first part is the monitoring network activities, the network activities. So malware tries to communicate with the network for various activities such as the propagation, downloading malicious content, transmitting sensitive files and information, okay? So while inspecting the forensic workstation upon malware execution, you should check the following aspects. So for an example, the aspects might be the, uh, IP addresses, okay? I'm just writing down here the IP addresses, then the ports, okay? And then the DNS entries, okay? So these are the three points that you can notice. And you can use Wireshark, okay? For the monitoring purposes. Wireshark is a great tool to use. Then you can also monitoring the port also, because port monitoring is also necessary, not only the network. So malicious programs open system ports to stabilize a connection, okay? So reviewing port activity in real time on the forensic workstation after the malware execution helps in understanding its network capabilities. So use command line tools, for example, the netstat to monitor all active ports. The tool name is netstat. So let me write down here the netstat tool for the port monitoring, for the port monitoring, you can use this tool, okay? And there you can use the help menu to see that how you can. Okay? Then there are more tools for the port monitoring. So let me know write down here also the TCPView, the TCPView, then the CurrPorts. So these are also tools for the port monitoring tools. So you can go and explore these tools for the port monitoring purposes. Then you can also monitoring the DNS, because, uh, why we are monitoring the DNS? Because the malicious program uses Domain Name System to communicate with the command and control server, as you know. So upon malware execution, review with the DNS record and how you can, before, uh, before executing the malware, clear the existing DNS cache. This is an important point, okay? So note down here how you can remove your DNS. Just type in your command prompt, ipconfig, then the forward slash, and type flushdns, okay? So this is the command to flush the DNS. Let me type, is it, typo, mytic, flushdns. So this is the command to flush your DNS. Then DNS monitoring tool is DNS Query Sniffer. Put down the tool name. So DNS monitoring tool is DNS Query Sniffer. So you can use this tool to monitor your DNS activity, okay? So we discussed the malware and the common techniques attackers used to spread malware. Then we, we discuss the fundamentals of malware forensic and the types of malware analysis, including the detail. And this module examined the analysis of suspicious Word documents and discussed the fundamental and approaches of dynamic malware analysis. So this is all about the dynamic malware analysis. I hope you liked this lecture. So I also discussed the different tools for the different parts. I mentioned all the tools. I explained you with the diagram. I'm not, I'm not writing the whole thing because it takes lots of time, okay? So that's why I'm giving you some picture, okay? Not the whole picture, but yeah, little bit about it. Whatever I think that it needs to be explained properly, I'm doing so. This is all about from my side. Happy learning, guys.
So hello guys, welcome to this lecture. In this lecture, we are going to study the basic of memory forensic, okay? So we are going to study the memory this, yeah. So basically, the memory forensic does the forensic analysis of the computer memory dump because, uh, we can't do the forensic on live memory. So we have to basically take the dump, or we can also say the capture dump. Capture, the easy way is the Mon, the inventor of the Wireshark 2DD and the V64DD memory dump programs have both are combined into a single executable. When executed, made a copy of physical memory into the current directory. So we can use the tools. But before going from the, uh, the process of the memory forensic, we are going to study the some architecture of memory, okay? Because directly starting the topic is not the good way. So let's start with the architecture, how the architecture of memory is. So architecture of memory. Now, the architecture are divided into many parts. The first one is the cache memory, the cache part. Then after the cache, then there is some, uh, there is main memory, the main memory. After the main memory, then I'm explaining a little bit about each topic. So I'm just writing down for you to make notes. Then another one is auxiliary memory. So these are the three types that we are studying. Then let's explain a little bit about each. So the starting with the CPU cache or cache memory, a CPU cache is a cache used by the CPU of a computer to reduce the average time to access data from the main memory. So for an example, you are using the same thing again and again. So, uh, for a normal device, it's taking lots of effort to go and search about it. But but the cache is the way to store something for a for a temporary time period of time, okay? So for an example, I'm always opening the facebook.com. This is the normal example that I'm telling. So for an example, I'm only always opening Facebook. Then there are many processes I'm requesting the Facebook website. Then there are some, uh, DNS lookup, then the IP addresses, then they requesting the website again and again. Then it's taking lots of time and lots of effort, okay? So what's the cache memory do is, cache memory stores the public IP addresses for reference or they store the website. So basically, the cache memory is storing the data that is used regularly by the user. And the cache is smaller but faster memory which stores copies of data from frequently used main memory locations. So most CPUs have different independent caches including instruction and data caches, where the data caches are usually organized as a hierarchy of more cache levels. So there are levels in cache, okay? There are levels in caches. How levels are assigned and what is the name? The first level, let me write down levels of cache, starts from the, the L1, then L2, then L3. So these are the levels of cache, okay? Then came to the main memory part. You, I think you are most familiar with the main memory. So the main memory of a computer is also known as RAM. Uh, how to, it is also known as RAM. The main memory thing, yeah. The main memory is also known as RAM, standing for the RAM stands for the Random Access Memory. So it can be accessed by cache memory or directly by the CPU. So the access time to read or write any particular byte are independent of where about the memory that byte is. And RAM is basically residing on your PC and it's differ from your according to your architecture. It must be of 6 GB RAM, 4 GB RAM, 12 GB, 16 GB RAM, okay? And this is broadly comparable with the speed at which the CPU will need to access the data. So if you have the 16 GB RAM, then CPU works faster than the person has the 8 GB RAM. So this is the main memory. Then came to the auxiliary memory. So auxiliary memory also known as auxiliary storage, secondary storage, or secondary memory, or we can also say that the external memory. It is also known as the, uh, external memory, external memory, okay? And it is a non-volatile memory. So it means that it does not lose stored data when the device is powered down. So you have to also note this point that it is, it is basically, yeah, so it will, it will not erase after the power is cut off. So this is the main difference between the main RAM and the auxiliary, sorry, main memory and the auxiliary memory. And it is also, what I told that it is non-volatile. This is the key point, non-volatile. But here, it is the RAM. Main memory is volatile. It is volatile. Then let's discuss CPU a little bit. So CPU is a central processing unit. Is a central processing unit? What is do actually? It basically uses the assembly language and its duty to do the manipulation with the data. For an example, adding and subtracting with the variables. So for an example, we are running any code. So what the code is actually doing in the back side? That code has its, what we can say, the programming language is written in the normal language that we can say. Then it has the translator that is known as compiler. So what's the actual flow? Let me write down the actual flow is the coding part, then the compiler part, then the assembly, assembly part, and last the CPU. Yeah. So this is the way we are executing all processes in our.
System. So if we see the overall of the system, then the CPU is normal things that basically execute our coding things with the help of some variables. Or there are some units. There are CPU life cycles. So that is for the architectural part. This is that is basically came into the microprocessor subject, not the digital fory that we are studying right now. So we are just covering each topic so so we can easily start our memory forensic. Then there is Process Management, the creation of process, then CPU scheduling. So these are all related to the microprocessor, but I'm just covering the main main things that we need for the memory forensic. Okay.
Then there is memory management part. And let me see you that how the operating system resides. Uh, draw one picture. And Lang is not to, but yeah. So I'm just creating a block. Yeah. So the first part contains the operating system, operating system. Then remaining things contains the processes. For an example, this is process one, this is process one. Then this is process two. So this way the whole flow basically works. And at last, what we have to see, not last, but let me cover it. The file system. The file system. How the file system actually works. Uh, there are some root part or the root folder in which there are some sub part. And then there are more sub part. We can say that the leaf. For an example, this one, this one, this one. So in this way, the whole file system is worked.
Then the main thing related to memory for instance is the, let me open a new tab. So the main thing for memory for is a registry key. There are only three or more, I think five keys that basically contain the important information related to Windows. So let me cover it all. The first one is H key classes root. HQ classes root. What it contains? That it contains information on file types, including including which programs are used to open a particular file type. So this is the first. Now it's better. This is the first key. Then the second, the second one is H Key current user. As the name suggests, I know it contains the user a specific setting. So let me write down in shortly that user contain user a specific setting.
Then the H key local machine. It contains computer specific information. And the fourth one is H key users. Contains information about the all users. So information of about the all users. And the last one is H Key current config. Let Key current conf. So contains information about the computer's hardware configuration. So these are the keys that you have to keep in your mind related to the registry. So as the name suggesting, you can easily answer the question, but you have to keep the name remember. Okay. So that's why I'm just boarding it. Yeah. So these are the keys. And there are some tools in the Windows that is the reg regit registry. The tools name is we are exploring the tool also in the practical. We are just covering the theory now. So tool to explore the things. So yeah. So this is all about the basic of not memory forensic, but yeah, we are good to go for the memory forensic part. So happy learning, guys.
So hello guys. So in this lecture, we are going to study the acquisition method for the memory forensic. Okay. So the angel of investigation that you take during the acquisition phase will depend mostly on the scenario that you are presented with and the requirements of the case. Okay. So it's all depend on the scenario or the case that you are having or you have to face. So it's not that whatever I'm saying is applying for all the thing because it depends on the operating system. Okay. So you are handling the Windows, then there are some different tools, different techniques. You are handling Linux, then Mac OS. So there are different techniques. But whatever I'm telling you right now, it is fine for all of them at some instance. Okay. But yeah, it's give you the overall idea that how to acquire or take the data or the method for acquisition method. Okay.
So let me write down the acquisition method. So yeah. Now generally, your investigation will focus on the activities of the user on the system or the evidence that proves that the system in question has been compromised. Or sometimes even encrypted keys and passwords can be uncovered if they are part of the evidentiary requirements of your case. So let me give you the some example of acquisition format. Okay. So first, let's discuss the formats that are used in the memory forensic. And there are different memory acquisition types, but these are the five of the most common methods that formats that are used today. So let me write down here the five uh formats formats. Okay. Yeah.
So the first one is the raw format. What is tells that the extracted from a live environment? Okay. So this is the first format that is raw format. Then the another format is crash. What is the states? The information gathered by the operating system. Then the third format is hybrid nation file. Iation F. So is saved snapshot that your operating system can return after hibernating. Then the another format is the page file. The page file. So this is a file that stores similar information that is stored in your stored in system RAM. Then the another one is the VM be snapshot. Another one is VM we snapshots. So this is a snapshot of a virtual machine of a virtual machine. So these are the five formats that you can acquire the data of memory.
Now there must be clear understanding of what needs to be stabilize on the target system and how it can help to advance your investigations. Okay. So once you have acquired your data, you can begin the process of examining the system. So we have acquired the data for now, for example. Then what we have to do next is to examining the system. And any suspicious activities will then be uncovered as you proceed. So data carving is a commonly used approach. Okay. And it's basically depending on the desired outcomes of your particular case. So there are many other approaches that can be looked at as well. So let me provide you some tools that are best for the memory forensic in the market. Okay. So before going for the analysis part, let's discuss some tools. So tools for memory forensics. There are many, but I'm just telling you the best one. Okay.
The first one is the volatility. Shot. What is do? It is a open source. Okay. So you can use it for free. So it is a open source. Then the next tool is recall. I will explain little bit about each tool, no worries. Then the next tool is recall. Okay. And what's it has that is it is it has the future. It has the future both acquisition and analysis. Both both you can do it. Okay. Then the another one is the Helix ISO. Then the uh Belkasoft. Belkasoft RAM p r capturer. And the last one for our top five is the process hacker. Process hacker. So let me explain a little about of each tool. So the first one is the volatility suit. The first one is the volatility suit. So as I told you that this is the open source for analyzing RAM and has support for Windows, Linux, and Mac operating system. Okay. So it's supporting both three operating systems. And it can analyze raw, crash, VMware, virtual box dumps with no issue. Okay.
Then the recall. So this is an end to end solution, sorry for incident responders and investigators and futures both acquisition and analysis tools. Then the Helix ISO. So this is a bootable live CD as well as standalone application that make it very easy for you to capture a memory dump. Then the Bela soft rme capture. So this is the another forensic tool that allows for the volatized section of system memory to be captured to a file. And the last one that is process hacker. So this is also a Open Source process monitoring application that is very useful to run while the target machine isn't used. So as you can notice that I'm just Bolding the two one that is the open source. Okay.
Now how you can examine your data? We can capture the data. Okay. This is the way. This is the format we discussed. This is the tool we can use. At last, what we have to do? We have to examine our data. So examining data or examining the captured data, we can say also. So now let's see that how we are examining. So first of all, let me clear you that there are many avenues for an investigator to take when it comes to analyzing a target system. Okay. So many, in fact, that there are entire book series that are dedicated to the subject. But we are only, but we will instead take a look at some common approaches. Okay. That can be used by an investigator when trying to glean more information by memory forens. So let's discuss the important ones because I already told you there are books for this, but I'm just telling you the telling you the best part. Okay.
So the first thing that you can do is the open file associated with it. Open file associated with, sorry, process. So you can examine the open file that that is associated with the process. So this is an extremely useful approach as it shows which files are opened by a suspicious process on the target system. Okay. As you know that malware can often be identified just by the location of the associate files that are open. And uh knowing where these files are located is also beneficials.
Then the another approach is the decoded application in memory. Decoded applications in memory. So sometimes the author of The malware that is present on the target system will be encrypted. So it making it impossible for anyone but the perpetrator to successfully make use of the data that it has been collecting. However, sometimes a decrypted version of the application can be caught in the memory snapshot, which allows the investigator to more accurately. Okay. So this this way we can see the encrypted one and we can also decode it for our examining purpose.
Then another one is the time stamp comparison. The another one is time stamp comparison. Okay. So in some instances, malware can interfere with the target host time stamps on the system files, making them appear to be untouched by the infection. And this is known as uh time stomping, I think. Yeah, time stomping. And can seriously inhibit an investigator's ability to discover when the infection first occurred. Okay. By capturing the memory dump, investigator can compare the process time stamps to the system system file time in stands to stabilize when the system was first compromised. So this is the way to basically uh uh creating the flow of the process by with the help of time. So for an example, today some process is occur, okay, occurred during our analysis. We think we we are we came to a point that today some process is occurring or occurred. Already done their work. But after doing more examination, we are seeing that there are some more malicious processes that has been that had been occurred 2 days before. So there is no logic between these two processes. So that's why the time stamps matters a lot because we have to focus on the actual time stamp, not the time stamps are deferred by the malicious malware. Okay. So that's why we have to focus on it also.
Then the network Information. Network information. These are the four points. This is the network information. Okay. Yeah. Network information. And the last one is the user activity. Last one is the user activity. So these are the examining captured data. So at conclusion, what we can say that the memory forensic is a crucial skill for first responders and investigators alike, as it allows for the quick and complete capturing of live system data for lateral scity. And while this is a very important skill to learn, it is just one of the tools that you will beut you will be taught when enrolling in one of the many forensic training courses. So this is the normal flow of the acquisition method. We discussed the format, we discussed the some important tools, and we discussed that how we can examine the data. And again, I'm just saying you that it's totally depends on the scenario. It's totally depends on the operating system. There is no some specific process or methodology that we can follow it. Okay. So happy learning, guys.
So hello guys. So in this lecture, we are going to study the introduction to email crime investigation. Okay. So our topic is basically the intro for email crime investigation. So email crime investigation basically involves the extraction, acquisition, analysis, and review uh, Revival of email messages related to any cyber crime. So basically, we are collecting the data from email that founds in crime or the data is involved in the crime. So basically, the detailed analysis of email messages help investigators to gather useful evidence, such as the date when then time when the email was sent, the actual IP addresses of the sender. So let me note down the key point or the key data element. So basically, you are going to investigate an email though. So what are the key points that you will collect? Okay.
So the first one is the date and time. Date and time. Then after date and time, then we are basically the IP addresses. IP addresses of sender. Okay. IP addresses of sender and the recipient. Let me add it here. IP addresses of both sender and the recipient. Then what are the spoofing spoofing mechanism used? Spoofing mechanism used. So these are the key points that you have to basically collect while doing the email investigation. Okay. So this helps them locate the criminal behind the crime and report the finding in order to prosecute them in the court of law. So, uh, let's discuss the uh, basically the, let us discuss in detail the crimes committed by the sending emails. So let's discuss the crime. So crime related to email. Crime related to email.
So the first crime that you will notice is the email spamming. That is email spam. Spamming. So what is basically basically the spam is unsolicited by commercial or junk email. So spam spam mail involves sending the same content to a huge number of addresses. So for an example, uh, here it is user. Okay. My drawing is not too good, so I'm just using the circle to represent the people. So there are many people. Okay. There are many people and that is sitting here. So let me draw like this for attacker. Okay. So what attacker wants to do is to basically send an email that contains some link, some malicious link, some malicious payload, or anything that basically uh, helps helps the attacker to do the crime. So, uh, if the attacker sending a mail one by one, then it takes too much time. Okay. So what's the attacker do? Attacker basically sends the mail in a one go to all the people. And to all the people stands like a DoS attack. If you hear about the DoS attack, then it is the denial of service. But there is one more part of DoS attack that is a DoS. Uh, it is a stands for the distributed denial of service. So this is the email spamming, sending the same mail to a large people in one group. Okay. That is known as email spamming. So spamming of junk mail fills the mailboxes and prevents users from accessing their regular emails. Okay. So this is the first attack.
Then another attack is the phishing. Another attack is phishing. And these are the normal points that you have been asked or you will ask in an interview that can you please describe me the types of the uh, crimes related to email? So you have to keep this point in your mind that yeah, these are the some key points that way you can explain while giving the while giving the interview. Okay. Then another one is phishing. So phishing has emerged as an effective method for stealing personal and confidential data of users. Okay. So basically, it is an internet scam that tricks users into divulging their personal and confidential information by making interesting statements and offers. So basically, for an example, if I got one mail that hey, uh, basically you won this, uh, lottery. Okay. Or, uh, you got, you are the lucky winner. Kindly fill the details. Okay. We go in the mail. So basically playing with the people's mind and getting the information, getting the personal information. It is known as phishing. So this is the small and the perfect definition of phishing mail. Okay.
Then there are many types of phishing. So let me write down the types of phishing. So the first one is there. Then another one. And then the another one. Okay. So the types of phishing. The first one is this spear phishing. Let me write down first, then I will explain you. The sphere phishing. Then whaling. W H A L I N G. And whaling. Then the farming. Farming. And then the last one that I forget is the spamming. Think. So spear phishing is when instead of sending thousands of emails, some attacker, what they do? Basically use a specialized social engineering content. Okay. Directed at a specific employee or a small group of employees in a specific organization for collecting the uh, personal information. So if you want to remember what is the still facing, so rather sending the rather sending the mail to public, that send in the mail, it will target the small groups or the intended intended peoples for PII. PII is for personal information. Or you can say the PI, the personal information. Okay. This is spear phishing. Rather targeting the whole audience, what they do? Basically targeting these small groups of people.
Then after covering this spear phishing, the whaling. So here what they do is basically the targeting the CEO of the organization or the CFO or some politician because they are not uh, have the knowledge related to the cyber crime and they are not aware about the cyber crimes or they are not good at the technical steps stuffs. So that's why they are targeting the higher position peoples to get the personal information. So in the definition, this is basically the targeting the higher positioning people for PI personal information. So this is the whaling. Then what is farming? So this is the social engineering technique in which an attacker executes malicious programs on a victim computer or a server. We can say. So when the victim enters any URL or domain name, it automatically redirects the victim traffic to a website controlled by the attacker. Okay. And this is also known as, uh, this is basically an interview. Basically, the the interviewer, uh, tricks you. He asks you. He he didn't ask directly that what is farming. He asked that what is phishing without a lure. So you have to keep it the mind that phishing and there is another name that is also known as or also works like a farming. So this is also called phishing without a lure. So this is the social. This is the social engineering technique in technique. The attacker, the attacker executes the executes the payload. So this is the normal definition of farming. I'm not writing the whole definition so you can't remember it easily. So that's why I'm just writing down the main main points to help it very easily.
Then another one is this spimming. Spamming is also known as the spam over instant messaging. So this this is the another, uh, basically the EA that is EA. I think you hear about the EA that is stands for also known as. Okay. So, uh, it is also known as, uh, it is also known as the spam over instant messaging. And in bracket, we can say that is Spam. So if you remember this point that it is also known as the spam over instant messaging. So this is the normal technique in which you will get an messages on your smartphones for the uh, personal information. So so spam or spam spamming is also stands for spam exploits instant messaging platforms and uses IM as a tool to spread spam. So a person who generates a Spam over IM is called a spammer. So this is known as spammer who basically generates a Spam over IM in sent messaging. So let me write down the IM stands for IM. IM stands for instant messaging. Okay.
So these are the concepts related to the intro to email crime investigation. So we studied till now only the, uh, the parts of the phishing. So in phishing, what we studied? The spear phishing, then whaling, then farming, then spamming. Okay. So this is the second types of crime related to email. The first one that is the email spamming, then another one is the phishing. Then another one is the, uh, let me write down here also. The another one is the mail bombing. You can also search on the Google that what is mail bombing. I'm just noting down the whole attack or the crime related to the email. Then another one is the mail strong. Okay. So these are the normal crimes related to the email.
Now, now we are studying the steps to investigate email crime. So as you know that in digital forensic, what's matter a lot is the steps because we have to do all the forensic in a standardized way. We can't, uh, do the third step in a first. Okay. So that's why steps matters a lot. So in any digital forensic, in any subdomain, if you know the steps, so and in interview, they are basically, uh, wants to know the steps normally. So for an example, in risk management, in the, uh, vulnerability assessment, there are some life cycle. So on those terms, the term is life cycle. But for digital forensic, the steps is matters. Or we can also say the procedure. So steps are similar like a procedure. So let me note down the steps to investigate the email crime. The first one is the seizing part. And what we have to seize? The seize the computer and email accounts. Okay. So the first steps when you investigate email crime is to seizing the computer and the email account.
Then acquiring. Acquiring means getting the data. Getting something is acquiring. So acquiring the email data. We are working with the email. So all the things have work on the email itself. So after acquiring the data, we are, uh, we are examining. We are examining the email messages. Okay. Then then what we do? Then retrieving email headers. Retrieving email headers. Then analyzing email headers. We have to spend a lot of time while analyzing the email headers because in email, there are nothing too much areas that we have to focus. Uh, the first thing that I told you in the starting of the lecture, there are four key points. Uh, the the sending date and time, then the IP address of the sender and the recipient, then the data, and then the boxes. So these are the normal four key points that we have to collect while analyzing the email. But we are spending too much time while analyzing the email headers. Okay. So the sixth step is the and sixth and the last step is the recovering deleted email messages. So these are the six steps while investigating the email crime. Let me explain each steps little bit.
So in the first step, basically what we are doing, first thing that we have to obtain a search warrant that should include the permission to perform on-site examination of the suspect computer and the email server used to send the emails and investigation. Then what we have to do? This seize the all computers and email accounts suspected to be involved in the crime. And you can also, you can seize the email account by changing the existing password simply. Okay.
Then in the Second Step, acquiring the email data. Uh, before, uh, acquiring the email data, the investigators consider the following scenario. The first one is the, the suspect accesses his or her email by any desktop based email client. Okay. And then the suspect has an web based email account on which the crime has occurred. Then the email data acquisition method will be different for each scenario. Basically depends on scenario. So for an example, you are investigating on phone, you are investigating on web browser, then the application itself. So there are different scenarios. And forensic investigators need to locate the local folders and recover the email messages using the right forensic tools for the further examination. Then basically, there are different vendors also now. So it depends on the vendors part also. Some vendors use some other things, some vendors use some other file location. Okay. Then the format, their dashboard is also some kind of difference in there.
Then, uh, after acquiring the data, what we are going to do? Uh, then examine the email messages. So basically, what we have to examine? The first one is the subject, then the sender email address, then the email body, and the email attachment. So most of the cases that you will find that in email, there are some links. Okay. So we have to investigate that that link is authentic or not. The link is basically redirecting the user to some malicious server. The link is basically downloading something automatically. So there are too much scenarios. So we have to focus on all of them. Okay.
So after examining the email messages, we have to basically retrieve the email headers. Okay. So the email header plays a vital role in forensic investigation as it holds detail information on the email origin. So basically, we have to retrieve the email address. Then we will analyzing with the help of some tools. And at last, we are recovering the deleted email messages with the same tools. So these are the steps related to the investigation to email. And the remaining part related to the basic email investigation of the email forensic, we will studying in the next lecture. So thank you, guys.
So hello guys, welcome to the another lecture for the email forensic. And right now, we are going to discuss the main or this most important parts that is the analyzing the email headers. Okay. So our topic is analyzing the email heads because we all know if we are doing the email forensic, then there is only one thing that we have to analyze clear F and that is the email header thing. There are nothing too much in the email forensic. Only the if you understand the email headers clearly, then you are good to go for the email for. So let's start with. So first of all, I'm telling you the, uh, the parts of the email that how many types of, uh, metadata or the data it contains, what's its meaning? Okay. And then we are going for the analyzing part. If you don't know the terms, for an example, what is subject, what is received header, what is message ID, then how we are going to analyze it? Okay. So that's why I'm discussing the whole part. And there we can use tools and we can go for the analyzing thing. And the practical will be in lab. So let's start with the first thing that is the time stamp. The first is the time stamp. So what it shows? It basically shows the date and time when the mail was sent. That's it. This is the only thing of the time stamp.
Then after the time stamps, there is a from field. From field. So what it do? It shows the email ID of the sender as it is visible as it is visible to the recipient. And this can be forged in case of a spam emails. Spam emails. So this is the another. Then after the form, there is two field. So what it shows? That it shows the email of the recipient. Okay.
Then the message ID. Okay. So this is the crucial point. So be careful. The message ID. Message ID. So as per the RFC 2822, okay, a specific email message should have a globally unique message identifier. Okay. That's why it is ID for identifier. So the first part of the message ID before the at symbol contains the time stamp of the email. Okay. And, uh, the part of message ID after the at symbol contains the fully qualified domain name. So let me write down. Okay. So before the, uh, before the at symbol, symbol, it contains the time stamp of the email. Time stamps of the email. Okay. And, uh, after the add, the after the at symbol, it contains the fully qualified domain name. Sorry, domain name. Okay. Domain name. And domain name example, we can say that, uh, mail.yahoo.com. Okay. So this is the message ID. After the message ID, then subject. Subject. So it shows the it shows the subject as given by the sender. [Music] Okay.
Then MIM version. Then MIM version. M me version. Uh, basically, the Multi-purpose Internet Mail Extension is the full form of M. Multi-purpose Internet. Write down. So you can also make the report, sorry, make the notes very well. Uh, Multi-purpose Internet Mail Extension are used to support non-text attachments. Okay. For for an example, such as video, images, or audio. So this is the MIM. Okay.
Then the received header. Then see better. Let me write down here. Is very it is also we can also write down here also. Change the color. H yeah. So the increase in the received header are of significant forensic value. You for an example, as this cannot be forged unlike other emails header elements. So email receive header is can't be forged. So keep this point in your mind. Okay. The number of received headers found in an email message depends on the mail server, uh, that process the messages as it travel from the source to destination. So the number of received headers is depends total only that how many, uh, it basically from the source to destination, uh, how many, uh, mail server process it. Okay. Then investigators should start with the bottommost receive headers. Okay. As it closes to the source and then move toward the top header. So these are some important things that I'm noting down. Okay. So the first is the it can't be forged. That it can't be forged. Now, let me write out here the point. It can't be forged. Okay. Then the, sorry, then the second point is it depends on the mail server. What depends? The number of numbers of received headers. Numbers of received headers. Then the third point that we have to know that, uh, we have to analyze the bottom most received header. Received header. Okay. Because it is closest to the source and then move towards the top header. Then these are the some key points related to the receive header.
Then we are studying the another elements of the email that is return. Return path. That is return path. So it is the bounced address for emails that are sent but not delivered to the recipient. Okay. So it is the bounce address for emails. That's it. It is the bounce address for emails. And also if the sender email address and the return path address are different, it generally indicates email spoofing. So this is the normal case if the sender email address and the return path address are different. Okay. It means that some, there are some spoofing or this is this email, there is something malicious anyways. Okay. Because both of them must be same. So these are the return return path. After the return part, we will see the received SPF. Received SPF. This is SPF. So what is the states? Is basically that Sender Policy Framework. So SPF stands for Sender Policy. Let me write down here for you. Sender Policy Framework. Okay. The SPF part. Then so refers to the it basically refers to the, uh, process that enables organizations to mention servers that can send emails on behalf of their domains. Okay. So refers to the process that enables organizations to mention servers that can send emails on behalf of their domains. So an email header showing a failed SPF check can help detect spam messages. So what is do is to basically it, it, sorry, what happened? I don't know. Let me see what happened actually. Okay.
Now guys. So it basically it refers. It refers to the process that enables organizations to mention server to mention server that can send emails on behalf of their domains. So this is all about the received SPF. Then the last one is the important one. Okay. The last one is important. So that's why I'm just opening the new tab for it. The last one is the last one is the Domain Keys Identified Mail Signature. Let me write down. Let me choose the h color. Let's use this color for this. Yeah. So Domain Keys Identified Mail that is it stands for DK. Okay. Signature. So what it do is basically it offers a offers a cryptography cryptographic way of verifying whether a received email has actually originated from the from the sending domain. Okay. So it offers a cryptographic way of verifying whether received email has actually originated from the sending domain. So this is the working of domain key identified side mail signature. But there are different elements of the DKIM signature and this thing differs from the all of them that we discuss later. Okay. That we discuss right now. The all different elements. But whatever we have studied till now, there are no nothing nothing in them. Okay. So that's why we have to go into it. So there are different elements. Let me write down. Uh, different. [Music] Elements of the DK signature. Let's see what are them. The first one is the V is equal to field. Okay. So field stands for the domain signature version. So let me write them shortly so you are easily understand what is it. Then the A part. Let me write down all all the part. Okay. Then the three part. Then the D part. After it is S. Then it is T. Then BH. Then B. Yeah. So V for version. Okay. A field basically shows the algorithm used to generate the signature. So we can write the algorithm for the signature. That's it.
Then C. C basically field denotes the canonicalization algorithm used. So it shows if there is any modification in the email in terms of white spaces or wrapping. So the first value before slash is for the header and the rest is for the body. Okay. So we can see that it denotes the, uh, what we can write for you to remember easily that, uh, to. So is there any modification? To. So is there any modification? That's it. Remember now. D field basically refers to the domain of the sender. So domain of the sender. Then S field refers to the selector to identify the DNS public key. So refer to the selector to identify the denus public key. Now T. So field denotes the time stamps of the signature in Unix Epoch time. And so always match or be close to the time reflected in the received behavior and message ID field. So it is a time stamp. Let's keep it easy for you. So time stamp. Then DH field is the hash for the body. As for the hashing algorithm in use. And then encoded in Base 64. So it is the hash. That's it. Then the B field includes the DK signature that should be calculated as for the header field mentioned in the H. So is there any, let me discuss. Yeah. In B is H stands for the hash header. So then imported in the 64. So yeah. So B for the DK signature. I think there is one more field if I'm not wrong that is H. H for we will when when we will do the practical, then we will see all of the field. Okay. No worries. Then H for the header. So these are the DKIM elements. And what is the DKIM that I told you that DKIM is a signature. It offers a cryptographic way for verifying that whether a received email has actually originated from the sending domain or not. So this is all about the email. And when we will do the practical, so we will do the practical email header analysis. Okay, guys. So happy learning. And yeah, don't worry about these different elements. Only you have to keep the, uh, only you have to keep four to five points to be remembered, not all, because we can't remember all things. Okay. So just keep in your mind that what is DKIM because this is the important point of the whole email header. So just remember this point DKIM and some of the elements of the DKIM. That's it. So happy learning, guys.
So hello guys, welcome to this lecture. In this lecture, we are going to study the email header analysis. Okay. So we are using the tools that is the M Tech mail viewer. Okay. So let's start with our practical. So just open your Windows Virtual Machine because whatever we are doing, uh, the analysis part, we are doing in the virtual box. So there is no chances of any security misconfiguration or any malware coming our normal windows. So just go to your virtual box, open Windows, and, uh, open your demo mail account. So this is my demo mail account that you can see. I just logging the hack for now at gmail.com. And this is the Google, uh, security mail. So what I'm going to use, I'm going to use this mail for email header analysis. Just click on this right side of the three dots. And there it is. You can see that download message. Just click on the download message. So the mail will download. Yeah. Just click on the key. So the extension is EML. Okay. And you can also check by going through the file manager. Open the download section. And you can see, uh, it's all down. Yeah. Security alert. This is the mail itself. There we are not able to see. No worries.
So now go to the website that's name is M Tech mail. M I T E C Z/ M I M V I E W. HTM. Let's go to this website. Now you can see this is the main website. On the right side, you can see there is a download option. Click on the download button. Start downloading. Okay. The zip file will download. After downloading, we have to extract the EXE extension from them. Okay. So go to your download section. Right click. Extract all. And extract all the need location. So I'm giving the same location. Yeah. Distracted. Open the eyes. Then you have to open this file. Okay. So just double click on it. So here you can see this is the first interface. So you have to select the single EML file. Okay. After selecting this EML file, but the the file you downloaded for the email header analysis, you have to browse it. Okay. So click here on the file and go to your download section. Select the what EML extension and open it. And see the user s download security alert. EML. Okay. So after that, we have to click OK.
So this is the first view of mail viewer. For more details, click on the source. Here you can see the original email header here. So let me explain each part little bit. So here you can see that this is delivered to this mail ha 4@gmail.com. Okay. And, uh, if we go to the body part, so this is the body part. This is the body. Okay. This is the plain and this is the HTM. Here you can see the body. But if you click on this source, then you can go into the original header of the email. Okay. Then let's explore it. Okay. So we explored the delivered part that is delivered to hack for at the gmail.com. Okay. Yeah. Sorry. So now then this is received by the this is the IP V6 address with SMTP simple mail transfer protocol ID. So this is the ID. Okay. The date is Saturday, 29th June, and the timing is this 2024, 8:58:59 seconds. And this is in the PDP format. Okay. Then there are some more information related to that. Then you can see the algorithm is RSA SHA 256. Okay. Domain is google.com. Okay. Then this is the another security checkup. Then this is the signature. Okay.
Then the main thing that you have to notice is the authentication part. So this is you can see the authentication result. Okay. So this is the authentication check. From here to the DMARC that we discussed. What is DMARC? Okay. So you can see here that DMARC is passed. DMARC is passed. SPF is passed. DKIM is passed. Okay. Then the else, what we can notice? Yeah. This is the public IP addresses. Okay. Then there are this authentication result that is mx.google.com. Here you can also see DK pass, SPF pass, DKIM, DMARC pass. So for an example, if you receive one mail and you think that this is the spam mail, then what you want to, what you want to go, what you will do to check that this is the authenticate or not? You can just download the message, open the mail Tech mail viewer, and just see that the authentication part is passed or failed. Okay. So if there is all pass, then it is okay. But if there is some failure, it means that this is a spam. This is the first way to check. Okay.
Then for an example, if you're receiving some another language, so Chinese and another stuff, so you can just convert to in your own language. So right now I'm selecting the English. If you select the French, so it will convert into French. If it is in a French, but it is in English. So let me select the English. Then the client IP addresses. We notice the, uh, this is the receive SPF pass. Okay. This is the where is the client IP? Me, I think it must be here. Yeah. So this is the client IP. You can see the client IP is there. Now, after seeing the authentication pass, seeing the client IP, the source IP, the timing of the message, the authentication is passed or not. There are more things that you can not, uh, for an example, the DKIM signature version one. Okay. We can also check that it is okay or not. Then the SMTP source. Okay. And this is you can see the received by, received by thing, which means that how many servers is basically, uh, uh, process this mail. So that's why there are two or three received by. You can see. So the one received is this. Then one received is this. And then this is the HTML format. This part is the HTML. So you don't have to worry about the HTML thing. But you you only have to worry about the the HTML, the above part. So from this to the above, you can analyze that this is authenticate or not. The pass is not. What is the client IP addresses when the mail you received and all the stuff. Okay. Then you can also open another mail. Then there is a option for check for update and this and windows for basically TTI the vertically or horizontally in language. I I tell you. So this is all about the email header analysis. So happy learning, guys.
So hello guys, welcome to this lab. So let's start our practical. We are just opening our Windows Virtual Machine. So let it be open. Yeah. So this is my Windows 10. Now it is. So we are in this lab. We are using this is internal Tools in which all the tools are invented to help us monitor and diagnose the Windows system. So task manager only give us the overview of the whole process, but we can't detect, sorry, we can't detect the actual working of the process. So that's why we are using this tool to diagnose the windows. So let's start with the. So just follow the steps whatever I'm doing. Open your favorite browser. So in my case, I'm using the Edge. So after opening the type Sysinternal tools. Okay. Sysinternal tools download. Then click your download. Then you have to focus on the Microsoft part. The Sysinternal tools Microsoft doc something. So just wait. Let me see where it is. So this this internal tools, I think it is. So just click on it. Let it be open. Meanwhile, I'm using another tool. Just opening another tab. I is taking. So just click on this Sysinternal suit. Okay. Let me click another tab. Yeah. And download according to your architecture. So I'm downloading the Sysinternal suit that is 50.4. Just click on it. It is updated on June 20, 2024, the latest update. So let's see. Yeah. The start downloading. Tool is downloaded. So let's go and unzip it. Go to your download section and just click extract all and click on extract. So it is extracting. So wait for a second persons. Just wait. So in which there are many tools. Okay. So around 160 tools is in this. So we are exploring each tool one by one. So it is a long video, around 30 to 40 minutes, I think. So let's see. Yeah. So now you can see that, uh, there is 160 items in there. Okay. 160 items is present in this Sys tools file. Now we are starting with the Procmon. Okay. So let's search where is Procmon. More. Yeah. This is Procmon. So just click on Procmon 64. Double click on. So agree. Click on agree. And it's prompted for the permission. I will give the permission. So now this is the first phase of the Proc. Sorry, Procmon. Where we see all the processes that is running. So this is showing this is showing us the live processes that is running right now. Okay. So you can see here that REQ is running. This is the path from which the process is running. The result is Success. Then there are.
More details related to this. Then click on the process tree to see the structure of the process. So where is process tree? Yeah, here it is. Process tree. You can explore the tool by yourself also. Just move your cursor onto the symbol. It will tell you what is the, uh, what's the name of the symbol. Then open it, then explore the symbol. So you can, in this way, you can explore the whole tool. So you don't need any guidance. Okay, but for now, I'm just telling you the important things of this tool.
So just click on the process tree. Then this is the structure of the process where we see all the process mapped like a tree. Okay, here you can see that the tree is. So for an example, the csrs.exe is running. This is not a tree, but yeah, in logon.exe, there are two more processes that are running under which that is the fontdb.exe, then DW.exe. So this is the process tree. So this is the main process and then there are sub-processes. So for an example, if we see the Edge, Edge, Edge browser, so here you can see that the ID is 7808. I think this is the parent ID, and then there are some child processes that are running under their process. Okay, so in this way, you can explore the tree also. And there are many processes running. Icon you can see. So this is the live view of the process.
Then click on the option to see all processes that is running at the end of the tree. So you can also click on the option. So you see there only. So process is still running at the end of the current tree. So just click on it. Okay, then you can select the process and click on the right button to see the related details also. So for example, I'm selecting this and clicking the right button. Okay, just wait for a minute. Yeah, right. So we have to close it and then just click on the right button, then go to the properties, any of them. Then you can see the whole properties related to that process also. So the thread number is this, then classes, file system, operating system, this result, success, allocation size. Okay, then the process, the process name, then the command line from which the process is also able to run. Okay, and the PID, parent ID. There are more things here. So here you can also see the modules related to that.
Just close it. There's exploring a little bit about it. So this is the properties of the event. We can explore and the processes, and we see that all details related to a particular process also. So what is there parent ID, the physical address, and when it is started, and there are many things. So use the, we can also use the filter option as per your need. Okay, there is a mechanism of filter. So you can see here the filter option. Okay, the filter option here. Click on the filter option. Okay, then after clicking, you can choose according to your need. So if you want to see any date and time, you can select is less than whatever you want to click on option to see more or function such as we can highlight some portion, configure the symbol, and them, etc. So you can do according to your case. If you want to analyze more, a little bit, then you can click on the option button here. Okay, then at last, we can also save our details for further comparison in the future. So for an example, if you want to save this, okay, then just go on the click file button, click on the file, and click on the save. Okay, so you can save it also. Okay, so this is our first tool, and let's continue in the next lecture. Happy learning, guys.
So hello guys, welcome to another lab. Okay, so in this lab, we are exploring the RAM map. Okay, so just open your Windows, open your file manager where you downloaded this internal tool. Tools, go to the download section, open the unzipped file, and then search for the RAM map. Okay, then let me sorry, let me scroll down a little bit. Yeah, so here it is. RAM map. Click on the RAM map 64. Then accept it. Agree to the agreement. This. Yeah, so here we are. Here we are details related to our RAM. Okay, such as who is occupying it and how much and how much free. So you can see that the total, this is K 4,000. This is the active. Okay, uses. If you click on the uses and K stack is using this driver, logged at this paste pool, this session private this. Okay, so these are some. Then, uh, click on the here you can see that the above one uses total active standby. So here all identify. And bad sector in our RAM that is not used by the RAM. So now we can see that process with its page table. So how we can see that process with its page table is, uh, the, the processes. This is not the page table. The processes with the page table. Yeah, click on the page table. Right. Uh, this where is the RAM area? I'm just searching it. Where is the bad sector? The red one. Yeah, this is the. So this is the bad sector. Okay, which means that it is not used. Of see this is not usable. Okay, the bad sector. Now let's go to the, the red one. I'm looking for it. Now click on the processes. Okay, so this is the priority where all priority is defined. Uh, sorry, this is the processor. The priority summary is this. This is the processes, the PID, the private, all information is mentioned here. You can go through it that how many files are running right now, what is its PID? Okay, and the session, the page table, how many, uh, area this space it is basically occupying. So all the things you can see here. Now let's see the priority thing. Okay, the priority is the all priority is already defined from 0 to 7. Okay, then come to the physical pages. So here we see that the physical addresses. Okay, here you can see the physical addresses. The physical addresses is used by which component? As we see that physical addresses start with ZX, okay, that is in hexadecimal form. And there is also priority with the process as well. Priority with the process as well. As we see the whole path of the file from where the process is running. So here you can see that the path, whole path from the process is running. You can scroll down also to see more things. This is the Windows virtual machine. So there is not too much information, but yeah, it is enough for now. You can analyze. Okay, the path and the process and the priority and the, uh, physical address. All things are inside here. Then this, let's see the physical ranges and the total size. So physical ranges, you can see the physical ranges. Okay, then all file summary. The file summary is here. We can see easily with the help of the file summary. Okay, and yeah, so this is the file. And what is this? This is the file. MT file details. Sorry. Let file details. So you can also move to see the whole path of the file that which file we are looking for it. Okay, you can see the whole file that is running right there. Okay, so this is all about the RAM map. Let's use disk view. Okay, so let's continue with the disk view. Close the RAM map. Open again the Sysinternals. Then looking for the disk view. Where is it? It is this is the disk view. Disk view. Sys. Click on double click on it. And then the process is the popup came. User Access Control. Click on yes. Then agree to the agreement. Okay, then click on the refresh button. Okay, click on the refresh button. And here you you can see that the all blue color is showing the disk allocated with the data. So whatever blue color you are seeing right now, that is disk allocated with the data. You can see easily. And there are some bad line also if you can able to identify. Is the bad line? So the red line you can see here, the bottom, the red line. Okay, so there are some red line that means that space is not usable. Okay, this means that the. And there are some file errors. No worries, we continue with this. Okay, so we can click on whenever if you click here or there, then you can see above the file. The highlight is changing. You can notice here. The highlight is changing, which means that this process is running in this space. Understand? So whenever you click the process is changing, the whole path is changing. It means that here this process is running. So you can identify that this process is running on blue, red, green. Okay, and then we can click on file, then click on statistics. Statistics. Then here we see the all volume properties. Okay, with the file fragment and the free space. So this is all about the disk view. Okay, let's explore another tool that is the VM map. So let's search VM map. Uh, where it is? Yeah, VM map. L. Click on it. Ient. So this is the process that is running on the VM. Okay, you can also trace a particular application with the help of launch and trace a new process. Okay, so you can also click launch and trace on new process, type the application argument and just start directory. You can also do, but we are only exploring the running processes. Okay, yeah, so select the process and click on to see the further details regarding that process. So let's select one that is the one.d.exe. Right click on it. Uh, select and right click. Why it is not working? Let me see. So you have to only select and click. Okay. [Music] Hanging a little bit. No worri. So yeah, you can see that, uh, we selected the process that is 1.exe whose PID is 8792. Okay, and just wait for their information. Yeah, this is the data related to particular process. So if you want to see or target some particular process, so for an example, if you find that yeah, this PID has some doing malicious thing, so you can explore it. Okay, you can select the PID and just explore that how much it is taking, then the map file, then the page table, and there are lots of things. Okay, we can't cover everything, but yeah, I can give you the taste of the tools and you can explore it also. Go, I told you that if you want to explore, then just click on the option. The ele, the basically, how many types of option available. So here you can see the tools option, view option. So you can go through it and explore it by yourself. Okay, so there is no some rocket science here. You can explore by your own. Okay, so this is the window open where we see all the details in a colorful manner. So here, so we see how much space is stored in heap, stack, page table, committed portion. Okay, select the option tab. Select the option tab and select the free and, uh, the option tab. There it is. I'm talking about this. I think yeah, so free and unusable reason to see all free or unusable space for the particular space. So let's wait. So now I here unusable. Here this is the unusable space. This one. Okay, and then you can also go option, then click on color, and you can see that free is white color, heap is orange color, image color is, uh, purple, and then you can go through it. Okay, yeah, you can change the color according to our need also. And at last, what we can also do, we can also save the data for the future. Okay, so we can also save the data. So this is all about this tool. Now we are exploring another tool that is the autoruns. Okay, let's start with the autoruns. Yeah, here click on double click on autoruns 64. Agree the license. So here you can see that you can see the all processes that have the autorun permission. So it is, so this is the processes that run automatically. Okay, so click on category for further information. So is this click on category for further information? Okay, so you can we can select any process and see the related details below. Uh, so also click on properties for more information. We can go through this. Let me explore a little bit. So let's see this. Uh, I think I have to click. [Music] Right properties. Wa. So go category. [Music] Again category and select s the drivers. Drivers. So have this is adop type manager. So you can also categorize according to your needs. So for which category you want to see the details. Okay, and also click on properties for more information. So this is the properties option. After selecting, you can basically go to the properties part. F doesn't ex. No worries, we are using this properties. Yeah, so there you can see the whole properties of the particular process also. So we can also use the search box to identify the process for a particular properties. Okay, the search box is here. This is, but we are only analyzing this property. Proper. Sorry, properties. My bad. Okay, and then this is all about this tool. I think and at last, I think I will let's see one more that is interesting tool. Uh, that is the TCP view. Okay, TCP view. Yeah, TCP. Double click on it. Popup occurs. Click on yes. And agree the license. Here we see the which process is using the transport protocol such as TCP 4, TCP 6. So the whole details, the process with the process ID, with the protocol, with the state, the IP addresses. Okay, the IP addresses, then the port, remote addresses if it is there, then create time, module name. So there are many categories. You can also click on TCP V4 and then you can see all the related TCP V4. Then TCP V6 is you can also do it here. Okay, so select the protocol and to see the process who is using that protocol. So right now I'm selecting the UDP V6 and UDP V4. So that's why we are only seeing the UDP protocol. So let me unselect it and only select the TCP V6. Then this. See, we are only able to see the TCP that is using the version 6. I. So this is the way to basically filter out. Okay, and, uh, you can also explore a little bit more by just clicking on the properties, then process properties, and then this is the process properties. Okay, then there are more options, the processes, the properties, and you can also click the particular properties. For example, I want to click the, uh, which one? Let's choose the another that is safe to showcase here. For example, let's not explore our Windows get shut down, then it's create problems. I'm not killing any properties, but for now, if I want to delete this properties, the selected and only click on process, then kill, it will kill that process right now. Okay, so this is all. And you can also exclude this thing also. The process properties, not this one. Uh, where it is? Basically, I'm using this tool after a very long time. Okay, so view, then view the protocols also, the connection is St. Then same thing. You can also filter out with this also. Then, yeah, this is all about this tool. And at last, what I told you, you can also save for the future. Okay, so this is all about the tool. We explored this is internal tools. Very well. I discussed all the important tools related to Sysinternals. So happy learning, guys.
So hello guys, welcome to another practical of digital par. So in this practical, we are going to exploring the tool Autopsy. Okay, so let's start with the Windows virtual machine. So first, we have to download the tool. So open your favorite browser. Okay, let me just type Autopsy tool download. Go to the first website that is from the Autopsy itself. Okay, then you can click on the download 64-bit. Download 64-bit. So let's start downloading. Just wait for a minute till we will explore what is Autopsy. Okay, what is Autopsy tool and where where it is? So you can see the Autopsy is a open source digital forensic tool. Is downloading till now, we will study a little bit about the tools, what is the working, where to use, what is the things that we have to keep in our mind while doing while using the tools. Okay, so you can see the Autopsy is a digital forensic platform and graphical interface to the Sleuth Kit, another digital furnishing tool. Okay, it is used by law enforcement, military, and corporate examiners to investigate what happened on a computer. Okay, so law enforcement, military, and corporate examiners to investigate what happened on a computer. You can even use it to recover photos from your camera's memory card. Okay, but the basically the Autopsy is a free open source tool that supports a wide range of other digital forensic modules and things. Okay, then let's see the future. The future is the multi-user cases. So you can create multiple cases. Then the, uh, I think I click go back. Yeah, so multi-user cases, then the timeline analysis. Okay, then the keyword search. You can also do web artifacts. So you can go to this website. Okay, I'm just copying it and tting it for you. So you can just wait a minute. The tool is downloading. Okay, uh, it's turn around 50%. So let it be. I just open the, uh, notepad to you to basically give the whole link of the website because that website is fine. Okay, then how to install Autopsy? Go to the website and then download it. And this is the demo part. We'll be doing the demo thing. So don't need to see this. Just wait to. Okay, I'm just pausing the video. Only few members left down. So using Autopsy and classifying data. Okay, and tool we are using the Windows 10 and Autopsy. So first of all, we have to download and we downloaded very well. Then we have to install it by going through some, uh, default. What is this? Have to click on keep. Make sure you Autopsy. Keep anyway. I don't know why it's so. That's why we are doing testing in Virtual Box. Okay, because we are exploring tools. We are if we do the malware analysis, then we need malware itself. Okay, so this is not an easy job to do the practical, but yeah, we are, I think it's downloaded. Let me check download section and see that is there any Autopsy. Yeah, just double click on it and go to the manual installation. Open. Just click on the next, next, next, and that's it. Next. Install to start installing this. Installing. Okay, just wait. Downloading. You can see there the one symbol that is Autopsy 4.2.1.0. So this is the symbol of Autopsy tool after successfully downloading it. Okay, so just double click on it. As soon as this is start the application and interface like this will pop up. Okay, so this is the first interface of the Autopsy after clicking on it. So this is turning on modules. Just wait. [Music] Just fit. Let's click on okay. It is taking too much time. Let me close all other tabs. So loading modules. Windows Defender file has blocked some future of this, and we are giving the allow permission. Allow access. Click on the allow access after checking the private network such as my home or work network. You can give the allow access part. I think might see network issues that is causing. So now, yeah, it is downloaded successfully. So this is the first interface you can see. So we are, uh, basically we here we can start. So here we can start a new case also. We can work on, uh, the previous one, but we don't have any previous case. So we will go after, uh, no new case. So click on the new case. Okay, just click on the new case. Okay, we mention our case name, number, and store the data in the drive you want. So in my case, I am going for the C drive. So just case name is one. The base directory I will using the document file. This is the document. Then select okay. Then the single user. Just check the single user is mentioned here. Then click on the next button. Then the case number is one. The examiner, whatever you can see. I think the John the phone is whatever you want to mention. The email is just randomly mention it. And the notes is okay. Then click confidence. This is creating case database. So just wait. It is taking too much time. Much time. I don't know why. So what we are going to do? We are opening the notes and then see for the brief. Okay, so we are at this stage. I think we are this this. So we mention the name, the, uh, number, name, then the phone number, then email, and the notes. Okay, then we have to just click on the finish. Now we select of which drive we want to investigate in. In this case, we are selecting the USB drive. Okay, so we are selecting the select the data source type. Disk image or the VM file. You have to select this. Then select the time zone of the evidence. Then local disk, the USB that you are using. So select that USB drive. The time zone according to your location. Okay, and then click on next. Select the tools we want to use. So we are selecting all the tools. Okay, and then click on next. Then we are going to do. Then the processing data source and adding it to the local disk. Basically, the file analysis will start. And when it, when this finish, so just wait for to finish it. Okay, and then this is the output. Okay, this is the final output after doing the analysis. And now we easily access the file which are deleted or present depending on the tools we use. So here you can see that deleted files in the file system 89 and overall is also 89. Okay, so in this way, you can access the deleted files by using the Autopsy. So this is the way to recovering the deleted things. Okay, so happy learning, guys.
So hello guys, welcome to this lecture. Okay, so in this lecture, we are exploring the FTK Imager tool. So creating a clone by using a FTK Imager. So let me give you some brief idea about what we are going to do. So let's understand with the example. So suppose we get a pen drive. Okay, from a crime scene and we have to analyze the pen drive, but before analyzing, first we have to clone it. So our original data will not change. So that's why we clone first. And, uh, in this lab, we see how to clone by using FTK Imager. So from where you have to download this? I'm giving you the go to this website. Okay, go to this website and click here for downloading. Okay, so I already downloaded. So let me close this. And and then after downloading, you you will get one.exe file. So simply open it and then go to a normal installation. So next, I accept the terms and the license agreement. Agreement. Then next, then next, and install. So let's wait. Install it. It takes around few minutes around. So yeah, FTK access the data. FTK. So I think, yeah, this is the first view of the access the FTK Imager. So this is the first page. Okay, or we can say that the first interface. Then click on the file option. Okay, then select the create a disk. There it is. File option and then create a disk image. Okay, then after selecting this, select the option as per your requirements. So for my case, uh, it is a physical drive. So I'm just selecting the physical drive. Okay, and then next. So please select from the flowing AVB drivers. So this is the only driver. I think yeah, so I'm selecting it. Then click finish. Okay, then the selected drive and click on finish. And then, uh, image source is this. Image destination. Basically, the image destination we have to add. So click on ADD and, uh, click on ADD. Uh, then click on ADD and then select the E10 e01 option. Okay, then put the details here and click on the next option. So next, then case number, let's say Z 1. Evidence number is 1 2 3 4 5. Un description A B C D. Okay, examiner me sah. Notes nothing. So let's next. Then image destination folder. Browse and select where you save the image file. So I'm selecting the, uh, this PC and, uh, the document and the document, custom office template. I'm selecting. Okay, so custom office template. Then okay. Then image file name excluding the extension. So, uh, in my case, I'm just writing the image one. Oh, sorry. I changed the destination folder. Let me add it again. So click on browser house. Then select according to your needs. I'm selecting the in the, uh, the document in the documents, the custom template, custom office template, and then okay. Then the image name. So I M A G E image 1. Okay, after giving the image name, just you have to click on finish. Just click on, uh, wait. Just click on finish. Then, uh, basically you have to make the below option. So we get the accurate image file by matching the hash value from the original device and the, uh, original file and by matching the hash value from the original device and the image file. So just click on the checkbox of the first to verifying and just start it and click on the start button. Okay, so it starts creating image. Image processing begin. So you can see the progress here. The progress tab. Okay, so processing is done. When and after the processing will done, we see that there is a match, which means that we get the original image of the evidence. So let's complete the progress. Okay, so this we waiting to complete. So I'm pausing the video. Okay, covers around 30%. Okay, so I'm just stopping the recording again. And there it is. Almost 50% completed. Okay, so let's wait to complete it. Okay, so I'm again pausing the video for you. So as you can see that there is some failure related to my disk. So what I'm doing to demonstrate the lab is to basically explaining you the the PDF version because I don't know why the space is load. At least I allocated around 50 GB, but no worries. We see how to use, but let's demonstrate with the help of PDF file. Okay, so I'm just opening the PDF. I give me one minute, guys. Hold that. And I told you from where you to download. Okay, so we go further and where we stuck. Just go to that point only. So we selected the path, we give the name, uh, we we click on start. Finally, we click on the start. Okay, so the starts begin. Now image processing begin. After so processing is done. We see that there is the match, which means that we got the original evidence. So here you can see that verify is match. The image is blurred, but I did the lab. So I just telling you that here it is written match. It means that the image file is perfectly, uh, we captured. Then click on the file option. Here it is the file option mentioned in your tool. Then select the add evidence item. Select the add evidence item. Okay, then the image file. Then select the image file and then next. Then click on browse to select the path of the image file. Okay, so you browse and you select the path from where you downloaded that image file. So in our case, we selected the document and in which the template folder. So according to you, select the path. Okay, then select the first one. Then it automatically adds the remaining part. So there are around four images. You can see the four images. So we have to select the first one and then the remaining one is automatically selected. Okay, then click on finish. Okay, then click on finish. And this is our image data. This is our image data. But we know this is not for analysis purpose. So only for checking the integrity, this is used. Now capturing the memory. How to capture the memory? Okay, then click on the file option again. Select the capture memory. Here it is mentioned that capture memory. Okay, give the destination path from where you want to save. Then there are name. You can give the name. Then give the file name with the extension of M. So memory file has the extension.mm. M. Okay, then click on capture memory. Then click on capture memory. Capturing begin. So capture started. Then the capture completed. Then the capture completed. Select the add evidence item by selecting the file option. Okay, then the select the image file and click the okay button. Then just select the image file and click the okay button. Select the image file by path and browse that image file. Select the file and click the open option. File. You have to select the file and then open it. Finally, click on finish. And this is our image file. So this is our image file. So at the conclusion, FTK Imager can create perfect copies or forensic images of computer data without making the changes to the original image. And the forensic image is identically in every way to the original, including the file slack, unallocated space, or device free. So this is all about the FTK Imager. Sorry for the, uh, my side that my virtual machine got, uh, basically not working due to the less space. So this is my fault. No worries, I explained you with the lab practical file. So you can go through it. Okay, so happy learning, guys.