Transcription
[Music] Everybody, thank you for joining in and being a part of this evening. This is Shri Kuran on behalf of TCSON. I welcome you all to this webinar where we will talk about three master classes on digital forensic evidence collection.
Today, we are diving into the fascinating world of digital forensic evidence collection. How technology is transforming and solving cybercrimes. We will explore how digital currency helps uncover crucial evidence, analyze cyber incidents, and strengthen cybersecurity measures. From understanding the fundamentals of evidence identification and data preservation to advanced techniques in analyzing digital trails and cyber threats, this session will provide a glimpse into the crucial role of digital forensics in the powering sector.
Whether you are new to the field or looking to enhance your expertise, this master class will provide you with the practical knowledge essential for navigating the ever-evolving cybersecurity landscape. So, I'm thrilled to introduce our expert speaker for today. Please give a warm welcome to Mr. Pratap. Welcome, sir.
Thank you, Shri. Let me give a quick introduction of him. Mr. Pratap brings over 30 years of experience with TCS and currently serves as a domain consultant in cybersecurity for the higher education unit. He has led diverse teams, including managing 400+ professionals in TCS, delivering complex migration projects, and heading the fresher training programs. With expertise as a database administrator for government departments in India and abroad, and active involvement as a board of studies member for various universities, Mr. Pratap has significantly contributed to academia and industry, holding an impact from IIT Delhi and a BT from Shri Venkateswara University. His rich experience bridges technology and education seamlessly.
Once again, a very warm welcome, sir. I'm sure you will find today's session both inspiring and informative. Now, Pratap sir, before we dive deeper into the exciting master class, could you briefly explain what digital forensic evidence collection is and why it is so important in today's technology-driven world? Also, since we have a diverse audience from both IT and non-IT backgrounds, can you share if this field is only for IT professionals or can non-IT professionals also build a career in it?
Yeah, questions about digital forensics. Uh, before I answer all the questions, let me give some introduction about uh digital forensics and then I'll answer all the questions one by one. Um, let me share my uh, let me share the presentation. Then, uh, hopefully, that presentation will answer all the questions. And still, if any questions are unanswered, uh, I'll be able to answer in between also.
Good evening, all the participants. Thanks for joining. Uh, I can see 370 people. So, very nice to see so many people joining the session. And also, I could understand that all of you want to learn about digital forensics or understand what it is all about. So, I'm not trying to make you expert in digital forensics in today's session, but my intention is to provide an overview about the topic so that it'll develop interest and then further, we will be able to learn more about this co-, about this topic in the uh, duration of the, in the duration of the certificate.
So, this is the agenda I would like to cover about digital forensics. Then I'll try to show some solved cases using digital forensics. Then, what is the process followed in the forensics domain? How data gets stored in uh, in a computer systems and where are the places where the analysts will go and then search for information. And there is something called anti-forensics. If you have not heard about it, that is fine. I'll try to explain what is anti-forensics, then why it is important, then what are the challenges faced in the digital forensics world, um, in current times. So, this is my agenda. Uh, let's see how much we can cover in the next 45 minutes. Obviously, I'll take few questions also at the end. Uh, but please do uh, type your questions. So, our team will be able to collect all the questions and then they, I will be able to answer those questions at the end of the course.
At a high level, digital forensics is a part of forensic science. So, there is a difference between forensic science and digital forensics. Forensic science tells you that it is an application of science to solve a legal problem. So, that's forensic science. Then, what is digital forensics? Digital forensics, that see, this is the definition. I'll read out the definition in a few seconds, but before that, let me explain the digital importance of digital forensics here. See, whenever we do some activity on the internet or on the, on our computer systems, laptops, or on our mobile devices, we leave some traces, and it also captures the systems also capture all the activities, and all these systems record the activities in their own memory.
So, if you look at the kind of data that has been accumulated so far, so at the end of 2025, it is expected that we have created 180 zettabytes of data. So, if you want to know what is a zettabyte, zettabyte is it goes like this. So, we are, we normally talk about gigabytes. So, you have a byte, you have a kilobyte, you have a megabyte, then you have gigabytes. Usually, we talk about gigabytes in terms of memory or storage or whatever. So, on top of gigabytes, you have terabytes, then you have petabytes, you have exabytes, then you have zettabytes. So, you can see the kind of number of zeros that gets added to zettabytes, and we have accumulated 1,000, uh, sorry, 180 zettabytes of data so far. Yottabyte is one level above zettabyte. I'm sure in, in coming few years, we will be creating yottabytes of data. So, we have created so much of data over the year. At the same time, when criminals, when they do some uh, illegal activities, they leave some traces, they leave some footprints. So, digital forensics is all about finding out those evidences from that uh, digital space or digital universe.
So, the definition goes like this. It says, "The application of computer science and investigative procedures for a legal purpose involving the analysis of digital evidence after proper search authority of custody validation with mathematics, use of uh, validated tools, repeatability, reporting, and possible expert presentation." This is the definition came out in the Forensic magazine. If you really want to follow some forensic cases and then technology advancements happening in the forensic world, subscribe into this magazine, Forensic magazine. So, you will get latest updates about uh, digital forensics. And this is the definition.
Can we move to the next slide, please? So, we will talk about all these things, all the uh, terminology given in this particular definition in our session today. Um, let's come to the next slide, please, Sonali, or yeah. So, let's come to the solved cases here, uh, now. So, how digital forensics has helped us? If you look at the number of cases that are being solved, there are huge number of cases being solved nowadays. Lot of cases which were unsolved over years, they are called cold, cold cases. So, those cases are being solved using digital forensics.
So, the first and foremost is, I just wanted to highlight the Arushi Talwar double murder case. I'm sure a lot of you have heard about it. So, this case has been solved using digital forensic methods. So, digital forensics has actually helped to establish communication between the suspect and the uh, uh, victims. Uh, in this, in this particular case, lot of data has been analyzed. Uh, the data has been collected from the laptops, computer systems, mobile phones, and communication patterns were established between the suspects and then victims.
The second case is the SSR Rhea Chakraborty case. Anyone can tell me what is SSR I'm referring here? I'm just trying to see somebody's response. SSR. Yeah. Sushant Singh Rajput. True, actually person. Yeah. Yeah. I just wanted to check how attentive you are. So, most of you are really following my uh, session today. Very good. So, Sushant Singh Rajput and Rhea, Rhea Chakraborty case here. So, for those who people who do not know about Sushant Singh Rajput, at least you know MS Dhoni. So, there was a movie made on MS Dhoni, and then Sushant Singh Rajput had actually played a uh, leading actor role in that movie. So, uh, this case, and he passed away a few years back, and then forensics specialists entered into the case, and then they actually solved or at least they found initial clues using digital forensic methods. So, in this case, what has happened was, um, the police people were able to identify the digital trails and then social, social media activity that happened in those devices that were captured from Sushant Singh Rajput's residence. So, all the, all the social, social media activities were able to uh, capture, and they were able to find some motives behind his uh, death.
The other case that I wanted to highlight here is the IPL spot-fixing scandal. So, I just wanted to bring this case here because currently, we are having IPL season. So, lot of people are involved in illegal bettings. There are a lot of online betting apps that are being uh, uh, available. And don't get involved in any of these online betting activities, and it is highly illegal. And if you are caught in doing any of those activities, uh, you will be losing money, that is definitely. But at the same time, you will be losing your career, and then it will be a bad remark on your entire life. So, don't get involved in these kind of scandals. And this IPL spot-fixing scandal happened in 2013. So, several players got uh, banned because of this scam. And uh, again, digital forensics came into place, and then they, they were able to identify unlawful betting patterns that happened, how money got transferred from one account to another account, and how many people got involved in uh, uh, yeah, teams also got banned, especially the Chennai team and then few other teams got banned. They moved to other, other cities for for a couple of years, and then they came back to their own cities. Um, yeah, illegal betting activities were able to identify using digital forensic methods. Uh, and it also happened that a lot of, a lot of people were involved in this case. So, and again, digital forensics methods uh, helped in uh, solving this case.
The 26/11 Mumbai terror attacks is another uh, infamous case that that actually got solved uh, using digital forensics methods. Uh, in 2008, there was a terror attack happened uh, in Mumbai, in uh, November 26th. Uh, apparently, if you have followed uh, the news in the last couple of days, the main person who plotted this attack was brought back to India from USA. So, he was extradited from USA and brought back to India for further investigation. Yeah, Rana from USA is now in India.
The other case is the Vyapam case. Again, this is a very infamous case happened uh, in Madhya Pradesh, recruitment and examinations. So, a lot of people got affected, and again, digital forensics helped uh, this case to some extent to to identify the kind of complexities involved and what are the irregularities involved, and where money got transferred, and who are all the people involved, all those things are able to solve using digital forensics methods.
The Nirav Modi PNB Punjab National Bank bank fraud case. And I, and see, this particular presentation, I prepared a few weeks or few weeks back, but only I think yesterday, there was some progress happened in this particular case. Nirav Modi PNB Punjab National Bank fraud case. Mehul Choksi, who is one of the accused person, he got arrested in Belgium, uh, and hopefully he'll be brought to India for further investigation. Nirav Modi is again, is, is arrested in in one of the countries, and hopefully will also be brought back to India for further investigation. And again, this particular case also got solved using uh, digital forensics methods. Lot of financial irregularities were able to uncovered using uh, forensic methods. Uh, and in this process, the analysts, they found a lot of encrypted data, protected data, and by applying proper tools, proper standard investigation methods, uh, the analysts, we were able to uh, found out who are who all got involved.
And again, Sunanda Pushkar death case. I'm sure most of you have heard about Sunanda Pushkar. She is the, she is the wife of famous politician Shashi Tharoor. And uh, again, digital forensics methods came into picture to identify what exactly has happened before her death. Uh, social, social media accounts were investigated, and online activities were able to traced to find out the motive behind the case. And again, of in all these cases, the digital forensics came into help because these are all high, high-profile crimes, and a lot of uh, systems, softwares, tools were used. So, the forensic people, forensic analysts were able to uh, investigate and and identify the digital evidence in all these cases.
You can follow this link and then see other cases that were solved using uh, digital forensic methods. And if you look, if you if you follow any standard uh, textbook or reference books on digital forensics, these are the two cases that mention that that they mention in in the in the textbooks. One is the BTK killer. BTK stands for Bind, Torture, and Kill. So, this is a famous BTK killer case that gets mentioned in many of the digital forensics books, and the 9/11 terror attack case. 9/11 stands for the month in USA date notation. This is September. This is 11th September. There was a bombing happened in USA. So, these are the two cases that you get to see in many of the digital forensics textbooks.
So, briefly, I'll just explain what happened in these cases. So, BTK killer, so there was a serial killer in the 1980s and 1990s. So, he used to, he used to kill a lot of people and get unnoticed. And he used to hide from the police, and he used to leave some cryptic messages to the police, and then, and and the police were unable to catch hold of them, catch hold of this person for about 20 to 30 years. Finally, in the early 2000s, early part of the 2000, uh, he left a message uh, to the police saying that, "I'm sending a floppy disk, and let's see, and don't try to trace me using the floppy disk." So, he sent a floppy disk. Floppy disk, by the way, is a storage medium in early uh, part of 2000 and the late '90s. It comes in 3-inch size or 5.5-inch size, and it actually holds around 1 megabyte of data, 1 megabyte of information. So, that's called floppy disk. You, you, you guys nowadays see USB drives, CD, CD-ROM discs, or DVD discs. So, in the late '90s, you see floppy disks.
Um, so, he left a floppy disk to the police, uh, and and he left, he, he created a file in that disk. So, when police uh, try to read that file, they were unable to see any useful information in that particular file. But forensic analysts came into picture. They actually saw more information on that file. So, they, they actually saw the metadata of the file. So, what is the metadata here? Metadata is nothing but data about the data. So, the investigation, people, the forensic analysts, they could see uh, the metadata of the file. So, that metadata actually gave some information about the killer. So, it actually mentioned or gave information about who created that file and where it got created, when it was created. So, the information they got is about a church. Is the place where the file got created, and uh, person who created that file actually works in a church. So, with that information, police went to, police took a search warrant, and then visited the church. Then they arrested the person who actually created that file, and further investigation they have done. Because just because of the uh, uh, metadata, they cannot actually uh, create a case and then arrest a person. So, they further did an analysis, they to, they obtained DNA from the from the people who got killed and the DNA of the person whom they got arrested, and they found a match. So, that's how the digital forensics helped person, helped the police people to solve a case which was actually unsolved for 30 plus years.
And 9/11 is the uh, case. Again, this is a terror attack case happened in USA. So, in this particular case, what happened was, just before uh, the 9/11 bombing happened, police actually arrested a person uh, who, who was, who was staying in the USA on an overstaying visa. So, as you know, uh, it is very illegal to stay in a country when the visa is not valid. So, they arrested a person. They actually seized uh, a laptop and then few of uh, external uh, uh, storage drives from that person. And further investigation of the laptop, what they found was, there are 20 other people who got involved in communicating each other, uh, at some place. So, the place is called Kingo Place. Kingos, Kingos is an internet cafe in USA. Um, so, uh, these all 20 people used to collaborate each other using Kingo internet cafe systems. So, when police went to the Kingos for further investigation, unfortunately, what they found was, all the King Co machines were uh, reset every 24 hours. So, they clean up those systems because of the performance reasons. So, because of that activity, police could not do further investigation.
So, these are some of the cases which actually get mentioned in the digital forensics, and these are uh, like case studies for any person who wants to work in the digital forensics.
Next slide, please. Yeah. So, let's see what is the process that a digital forensic analyst will follow to find out the evidence. And this particular slide answers some of your questions. So, how is encryption different from hashing? I, I'll, I think these things will, this particular slide will uh, answer those questions.
So, the first step in any digital forensics process is search authority. So, without having proper permission from the search authority, like court, police people cannot enter into any particular private space and then do some uh, investigation. They need to obtain a proper search authority, proper search warrant, and then uh, get into somebody's residence and then do a search. See, without proper search authority, without proper search warrant, if police people uh, seize any particular device, that is inadmissible in the court. So, you need to have a proper search warrant, and only then you can conduct a search and then find out all the digital devices that store information for further investigation. However, there are some exceptions here. Let's say, if a cell phone is captured in a, in a battlefield, and there is an exception here. You don't need a search warrant to seize that particular cell phone found in the battlefield. Similarly, if a child is in danger, or if a child is missing, in those cases, you don't need a search warrant. Police people can conduct a search uh, to mitigate this particular activity. But in most of the cases, search warrant is required.
Chain of custody. So, this is the most critical aspect where most of the uh, evidences that that analysts produce, but they don't see the light in the court because of this particular step, chain of custody. So, the moment you capture the uh, device from the crime scene till it gets produced in the court, the entire process needs to be documented. So, what time it got captured, who captured it, and then from the capturing place, what happened next, where it was brought, how it was, I mean, what kind of transport mechanism was used to bring to that uh, that particular device, entire steps need to be documented. So, in the digital forensics world, there is a saying, "If you are not documenting it, it doesn't exist." So, it is like this. So, chain of custody, moment you pass that evidence or device from one person to another person, it needs to be documented. And also, let's say you have captured a device which, uh, a hard disk, which is, let's say, it is a Windows-based hard disk, but it actually has some information. But you are not a Windows expert. Let's say you are a Unix expert. So, you need a Windows expert to do some investigation on that particular hard disk. So, you will hand over the device from yourself to the person who is going to uh, do the investigation. So, that transfer process need to be documented. So, that's called chain of custody. So, in most of the cases, if chain of custody is, is, is broken, then the evidence will not see the court. Evidence will be inadmissible in the court.
Then, imaging and hashing. So, this is a very critical step because once you capture a particular device, you cannot destroy the device because it needs to be, it needs to be produced in the court. So, without destroying that particular device, you need to conduct an investigation. Let's say you have brought a uh, hard disk, or you have brought a USB drive, or you have brought a drone or IoT device, whichever captures the information or has some RAM. So, that particular device needs to be investigated. So, before we conduct, investigation means what is there in that particular device, before you actually see what is there in the device, it needs to, the originality needs to be protected. But so, without uh, without actually seeing the, without actually opening the drive, how can you actually investigate? So, that's where the imaging and hashing comes into picture.
So, imaging means the complete copy of that device into uh, into the labs, on a lab, laboratory's system. So, you need to create a bit-by-bit image so that further investigation can happen on the cloned copy. So, usually people will make two copies from the master, from the master device. One for reference purpose, and one for the uh, regular investigation. If any damage happens on the second copy, so they will do further cloning from the reference copy. Some cases, what happens is, you are running a business, but, that you are running a business, and your business has got some hard disks or some uh, storage devices there. So, you cannot actually afford to lose that storage device. If you lose the storage device, your business may be uh, disrupted. So, you want that that device uh, to be brought back to your business to continue, your to continue day-to-day operations of your business. So, sometimes police will do the cloning of the device, and then they will give it back to the business for their regular day-to-day operations. So, imaging is nothing but uh, the bit-by-bit copy of the device.
And hashing is, is, is an answer to the court saying that whatever we have copied is actually an exact copy of the original device. So, hashing is a mathematical function. So, you can apply hashing to a particular file or folder, or to your device, or to even a particular simple text also. So, hashing produces a unique string at the end. So, let's say you have a, there is a hashing algorithm called MD5. So, MD5 algorithm, when you apply to a particular string, it'll give you, it'll give you a cryptic result. Yeah. SHA 256, SHA, SHA 1, there are different algorithms that are available. So, these hashing, it is Vive is asking one question that, "How is encryption different from hashing?" Yeah. Okay. I'll tell you. Okay. In a simple way, encryption and hashing are two different things. Encrypt, see, using encryption, you can, once you, let's say you have a plain text. Let's say this is a, this is the search, this is a text, search authority. And when you apply encryption algorithms, search authority will become illegible, you cannot read what is there. But you can actually do a reverse process, you can apply decryption process, and then you can get the plain text back from decryption to plain text. But hashing is not like that. Once you, hashing is a one-way process. You can produce a hash from search authority to a message digest, that's called. See, once you get a result out of a hashing function, it's called message digest. So, from message digest, you cannot go back to the original message. So, that's the prime difference between encryption and hashing. Hashing is usually very small in size. It will be 512 bytes or 256 bytes, depending on the algorithm that you use. But, uh, encryption, it depends on your file size. Let's say your file size is 1 MB. Your encrypted file also will be 1 MB or even more than that, because you need to get the original file back from the encrypted file. So, that's a primary difference. Encryption, you can get back to the old file, but hashing, you cannot. It is a unilateral process. So, using hashing, so that, does it answer, the questions?
Yes, perfectly, sir. Yeah. In fact, with this, Madhu is also asking that, "Imaging and hashing is same or different?" Okay. So, imaging and hashing are different. Imaging is a, is a, is a bit-by-bit copy of the hard disk. Hashing, you will produce a digital signature. It's like a digital thumbprint of that of that hard disk. So, using thumbprint, you can identify that, okay, this is, I mean, each thumbprint is unique. So, you produce hashing for each and every image. So, in the court, you can always say that, "This is my image. This is a, this is a thumbprint of the image, or this is a hashing, and it is exactly the same as the hashing that was there on the original device." So, using hashing, you can inform to the, inform to the court that we have not actually altered any particular device or any piece of information. This is an exact copy what we have brought from the crime scene. So, that's how image will protect the originality. Hashing will ensure that you have not altered, altered any uh, information in that original disk. That's how court will accept that this image is uh, is admissible. Okay. So, we have got good, in good uh, debate on, good discussion on the imaging and hashing. Absolutely. Let's move to the next one.
Validated tools. So, in the digital forensics, whatever tool that we apply, we use, it has to be properly tested and properly proven. We cannot use any tool that is not tested, that is not accepted by some of the boards, some of the laboratories. You cannot use those tools because the end result cannot be reproduced, or end result cannot be uh, foolproof. So, all the tools that we use are very much uh, authentic tools and needs to be uh, verified. Even the upgrades of the tools need to be verified on a day-to-day basis.
And repeatability is another step which is very uh, uh, important step. What it says is, uh, let's say you are the analyst, you are the forensic analyst, you have analyzed the device, you have produced the results. The same results should be obtained by a third person also. So, the third person should be able to use the same device, apply the same tools, apply the same steps, and then get the same results. So, that's, that's a repeatability. Court will only accept such kind of processes, such kind of tools, and such kind of steps. So, it is very important important to adopt those steps and then record those steps, document those steps, so that any third person can do the same thing uh, in their own uh, time.
And analysis is the most critical thing in the entire digital forensic processes. This is where the experience, the skills, the tools will come into picture. So, here the analyst will do the analysis on the data, on the, on the device. So, what is the analysis here? So, here analysts will try to find out what kind of files got downloaded. So, what kind of sites were visited, what programs got involved, what, whether there was any encryption, how to, how to break that encryption, and how, how they can attribute the activity to a particular user. Let's say you have a home computer, and there are, let's say five people working. I log in using my account. So, whatever activity I do, so those activities are attributed to myself. So, these analysts will try to do that attribution, so that the activity is related to a particular suspect. So, that is very important. And um, any files that got deleted, they will be able to recover using some of the tools. As somebody mentioned, Autopsy is one of the tools, which is an open-source tool. There are many other licensed tools as well. There is a tool called FTK Forensic Toolkit. There is a tool called EnCase. These are licensed and commercial tools. So, many corporates use these commercial tools, but Autopsy is also one of the good tools, which is an open-source.
And then, seventh step is reporting, which, see, once you do the investigation, that needs to be reported. And when you are doing a reporting, when you are creating the report, it should not include the technical jargon, because we do not know who are, who are all the people who are going to read, read your report. So, report need not be 100 pages or 200 pages. It can be very, very short, crisp, concise. It can be two pages also, but it should convey the right information in layman's terms. So, that's where the reporting skill will come into picture. So, many people who are not IT savvy, people, or who are not from a technical background, they can actually start their career in this particular area. So, you can start your, if you are good at articulation, if you are good at reporting, you're good in writing, if you're good in English, so you can start your career as a report writer in digital forensics. So, that's a, that's a good way to start. Once you do that, you will try to know, you will get to know the tools that are being used, then you can learn those tools, then you can move up, move up in the ladder. So, this is the, this is a seventh step.
The next step is the presentation. Once the report is prepared, you need to present it to the court. So, unless the judge convinces what you have presented, he will not be able to take any, any decision. So, so presentation is also a great skill. And you, and again, you cannot use technical jargon uh, when you are presenting. If you use technical jargon, if the judge is not a computer literate, he will, he will say that, "Okay, I don't understand this, so I will not consider this evidence." So, all the good work that you have done will go waste. So, all the, see, I have mentioned eight steps here. It need not be eight steps. Some books will mention 10 steps, some books will mention six or four. But more or less, they all cover the same process. So, you need to have a proper search authority, you need to follow the same chain of custody, you need to preserve the originality of the device, you need to use the valid, right tools, and all the processes should be able, you should be able to repeat those processes, and right amount of analysis should be conducted, and findings need to be properly documented, and finally, it should be presented to the court. Only then the forensic process gets completed.
So, these are some of the organizations that are present in the globe or in the world. Um, they are mostly American-based companies, but they are present all over the world. Uh, they, they actually uh, created standards, methods, controls, practices, tools, uh, training materials, so that people who want to learn, or start their career, this is the first place where they can go and then find out some information.
See, this is one of the very uh, relevant principles that Locard has uh, mentioned here. So, what he says is, "Whenever perpetrators enter or leave a crime scene, they will leave something behind and take something with them." Examples include DNA, latent prints, hair, and fibers. So, actually, he is referring to a physical crime here. But the same analogy works for digital forensics also. If, if a perpetrator actually performed any crime on a particular system, they will leave some evidence. They will leave some traces. So, that's called digital footprints. So, that is where the forensic specialists need to identify what has been left on the device so that uh, further investigations, evidence can be uh, identified. So, that's the uh, digital forensic process at a high level. I have not gone into details of lot of steps, but since this is only a master class, I think uh, explanation at this level, I think should be fine.
Let's move to the next slide, please. Yeah. So, I'm trying to go into the little deeper, but not too deeper, not going to too technical here. So, how data gets stored in a particular computer device. So, I'm taking, I'm taking a very simple example here, and how forensic analysts can actually find out uh, information which a normal user cannot see. So, I'm trying to explain it here.
So, uh, let's say you have a hard disk, which actually stores data in sectors. So, that's a sector is a, is a minute part of the unit where the data gets stored. Each sector is 512 bytes. Okay. And, and sectors get clubbed, and they are called clusters. So, data gets stored in clusters. So, sector is bottommost, and the next, next level is cluster. So, here in this cluster, we have four, four sectors here. So, each sector is 512 bytes. So, we have one cluster is 2048 bytes, 512 into 4 is 2048 bytes. So, let's say we have a text file which is of 2304, 2304 bytes. Okay. So, when you want to store this particular file, you need two clusters because one cluster is not sufficient. And so, you go to the second cluster, and each cluster will have four sectors. So, in the first sector of the second cluster, you will use some space to store the data. So, this black portion is actually the uh, the data of the file. So, you will see some space that is left out. So, what the system does is, it fills the space with zeros. So, this is not empty space. So, we'll find all zeros in this particular uh, uh, space, and these sectors are empty. They are not given to any other storage for any other storage purpose. Nobody will be able to store information in this because this cluster is assigned to this particular text file. So, you cannot store anything else in these three clusters, uh, three sectors. So, that's the situation.
Go to the next slide. Is asking, "What is cluster?" Cluster. Yeah. Go back. Cluster is four sectors. Each cluster will have a four clust-, four sectors. Each sector is 512 bytes. Each sector. Yeah. And Sar is asking, "If the traces are erased, then what is that process called?" Yeah. I'm coming to that. Go to the next slide.
Yeah. Now, let's say text file one got deleted. Okay. So, you have removed the text file one. So, deletion means the only the space is available for further use, but actually the file stays in the system forever. Okay. So, though the text file one got deleted, and this space is, this particular cluster still has the data, whatever is there in the text file one. Okay. Now, let's say text file 2.doc is there, and which is of 780 bytes only. So, our earlier file is, is more than 2048 bytes. So, now the second file is 780 bytes. Since the text file one got deleted, this particular space is available for the second file for, for its own use. Usually, it will not happen because once that file, uh, file is got deleted, the, the possibility of using the same space for another, another file, it is very, very less because you have lots of space available in the system. So, the same space will not be reused. But in case if it gets reused by the second file, and let's say this file size is lesser than the previous file, and let's say it occupies only 780 bytes, which means it occupies the first, first sector, and part of the second sector. So, this second sector, the empty space is all filled with zeros. But these two sectors, the third sector and fourth sector, you still have the traces of the first file. Normal user will not be able to see those, I mean, what is there in the third and fourth sector, but for forensics analysts, by using tools like Autopsy or EnCase or FTK, they can actually see what is there in this particular sectors. So, they can see the headers, f-headers or footers, or the file types, or the part of the image, or part of the text. So, that is sometimes that is good enough for forensic analyst to conclude some, some conclude the case. So, this particular space is called slack space. So, it is not visible to a normal user, but the system will uh, retain that space forever. So, and forensic analyst will be able to see what is there in the slack space using some forensic tools. And there is also another concept called allocated space and unallocated space. So, unallocated space is usually is a free space that gets assigned to a file which needs to be returned. And slack space is something which is actually occupied by a previous file, but it is not visible to the end user. See, all these, I just went into a little technical because this, this is how the forensic analysts will go deeper and then try to find information from the flat, SL, from the slack space or other unallocated space.
Any further questions on this, Shri? Yes. Uh, uh, Raki is asking that, "Files are not erased, but only the status of being used." Exactly, that that's true. So, let's say, I will give you a simple analogy. Let's say you have a textbook. Let's say there are uh, 200 pages, and at the end of a textbook, you will see an index. Let's say the index is, let's say five pages. And in the index, you will actually see a particular uh, heading of a particular topic, and using that heading, you can go to the textbook and then refer what is there in that. So, deletion of a file means removing something from the index only. But actually, that information is there in the textbook. You don't see that in the index, but the actual information remains in the textbook. Similarly, when you, when you, when you have deleted a file, that information is there on the hard disk, but only the mapping got deleted.
And was asking that, "Is PE used for this?" What is PE? P used for this? I think it could be a some tool, but I'm not aware about about the tool. But yeah, any, there are hundreds of forensic tools available, but better to use a standard tools like EnCase or Autopsy or FTK to find out information that got deleted. In fact, is asking about the traditional autopsy tools also, that how, yeah, what are the traditional way? Autopsy is the name of the tool. There are many other tools available like Autopsy. I hope you got your answer. Yeah. Shall we continue? Shri. Yes, sir. Yes, sir. Yeah.
Next slide, please. So, here, um, lot of information is available where to find such information from Windows operating system. I'm not going into the details of all the points mentioned here. That takes a detailed discussion of this particular topic. So, we will deal that in our actual uh, certificate course. But I would like to mention a couple of things here. One is recycle bin metadata and print spooling. So, these are the three things that I will mention because some of you have mentioned about recycle bin. See, when you actually delete a file, normal user, what they will see is that the file got deleted. But in fact, the file appears in the recycle bin. So, that's how the deletion operation takes place. But even in the recycle bin, you can do undelete and then you can get the file back. But from the recycle bin also, people try to do the deletion again, so that people think that it got permanently deleted. But that's not the case. As we saw in the previous uh, slides, even if you permanently delete the file, the content of the file remains on the hard disk forever until it gets replaced by another file. Even if it is replaced by other files, there will be some information that gets uh, that will be there as a, as in in the slack space. So, you can find out some meaningful information from that uh, space as well. So, recycle, so some people configure the recycle bin such a way that when you delete a file, it will not go into the recycle bin, but it will disappear from the from the disk itself. They think it is permanently deleted, but it is not the case. So, you can find out, you can retrieve information even if it is deleted from the recycle bin.
Then, second is print spooling. So, when you try to print, print a file from your uh, system to a printer. So, usually systems create two files. One is called EMF file. Uh, EMF stands for Enhanced Metafile. EMF Enhanced Metafile, which actually stores the entire image of the print, entire image of the document which you are printing. It stores in that EMF file. Second is a spool file. The spool file is, uh, like, it will have information about from which computer you started printing, and which printer you have sent the printer for printing purpose, and what is the name of the file. So, these files store information about the file that you are trying to print. But usually, these files will, will get deleted once the printing job gets completed. But some companies like law firms or data privacy firms, they configure the system such a way that even after printing a document, your EMF file, spool files get permanently stored on the system for further investigations. So, there are companies which actually configure systems to retain what all you print, so that they can do some actions. Sometimes people print information like stolen credit cards, stolen contracts, fudged contracts, or uh, maps of the body dumps. All those things they print. So, if a printer is not working properly, that's another piece of information for the forensic analyst to see what is getting printed and then try to find some information, or with the help of EMF and then spool files, they can also see what is getting hinted and then try to find some information.
The metadata, we briefly discussed in the DTK. Yeah. Yes. Ki. Yeah. Pa, on this, Rajender is asking, "Can we still retrieve the information even when there is no slack space available, not even a byte?" Um, it is possible that there are, there are some tools which actually, uh, literature says that those tools can actually retrieve information even if the data is overwritten seven times or eight times. So, there are tools. Okay. So, it depends on the quality of the tool and then how the forensic analyst will be able to retrieve the information. It's got it. Okay.
So, metadata is another piece of information in the Windows system, or in any system for that matter, uh, which will be able to provide a good amount of information, good amount of uh, uh, clues to solve a particular case. Metadata actually, it'll have two types of metadata. One is file system metadata. Second is application metadata. File system metadata actually tells you when the file got created, when it was modified, when it got lost, last accessed. So, sometimes, see, created, modified, and accessed. Usually, you will see the, these three things in a sequence. First, it has to be created, then it should be modified, then it can be accessed. But sometimes what will happen is, the created date will be a date which is after the modification date. You will see a modification date as an older date compared to the created date. How it can happen? If a file is moved from, from one storage device to another storage device. So, the creation date is the date when the file got created on that particular storage device. But the date modified is the actual date when it got modified. So, these are some of the metadata that gets stored in the file system metadata. And application metadata is like who is the author, when the author has created. So, all that information you can find it. So, this is the information that you can actually see in the Windows system. Similarly, you can find some information from the Linux systems, from Apple, iOS. So, you can find the different, different places where normally normal users will not be able to see, but you will see, forensics analysts will be able to see good information about that.
Can we move to the next slide unless if there are any questions on this slide? Not yet, sir, but it's already six, so we can take some last questions also once you wind up. Yeah. Yeah. Okay. Move to the next slide.
So, anti-forensics, I'll just touch upon this and then I'll close the session. So, anti-forensics is like say, whenever we have, we created a technology, there will always be bad people who wants to misuse the technology. So, anti-forensics is like that. So, definition goes like this: "An approach to manipulate, erase, or obfuscate digital data or to make its examination difficult, time-consuming, or virtually impossible." So, if you get a time after the session, go to your browser and type anti-forensics.com. So, anti-forensics. So, these are the people who try to make the forensic specialists' life miserable. So, they try.
to do activities which will which will delay the entire foreign process. So these are the some of the things that I would like to cover in my actual course.
hiding data. How they hide the data using wrong extensions. How they encrypt the data using encrypted file systems or using some of the operating system provider tools like Bit Locker, file, this is iOS tool and true crypt which is an open source tools. How passwords will be used to protect the data but how foreign six analyst will break the passwords that's another uh another uh interesting thing and steganography is another way to hide the information so how anti-forensics people try to utilize this steganography technique to hide the data so if there is a time I will just show one uh example of steganography uh towards end of my session.
And there are drive wiping tools which actually drives the entire information on the system but it will also depend on the quality of the tool. Though drive drive wiping tools claim that they have wiped out the entire data but it doesn't actually wipe out the entire data. Forensics analysts will be able to retrieve data even if it is even if the people use the drive wiping tools defragmentation other techniques. So these are some of the techniques which anti-forensics people will use to destroy the data. But forensic analysts with their uh skills, experience and then right use of tools, they will be able to uh retrieve the data even if it is even if it is destroyed.
So uh sometimes suspects will claim that I have used these tools just to protect my own my own privacy private data. That is perfectly all right. But the intent is questionable here. So if if I have used these tools or methods to wipe out my data only when I came to know that investigation has started on me a couple of years a couple of hours later if I came to know that investigation has started and then I started using these tools then the intent is is questionable. Why did I use these tools only when I came to know that investigation has started. So that means there is some wrong intention. So these are the some of the things foreign analyst will uh will use to write find out some useful information.
Move to the next next one please. Yeah, these are some of the challenges in the foreign foreign analyst where the change in technology. So we'll discuss more in detail about change in technology in our actual certificate course. Then hiding data how um people hide the data but there are ways to find out that there are there are tools to uh it'll find out just like that uh even if the wrong extensions are used then cloud plays significant uh role in against to the forensics people cloud will bring its own uh difficulties we'll we'll see that in our uh course and solid state drives which is a which is most of the times you come across solid state drives where data gets stored in the hard disks but how they bring the difficulties in the life of foreign specialist we will see that and there are uh organizations like legal and forensic people and they find very slow changes very slow change in the life of uh legal domain and then foreign standards that also place significant delays in digital digital forensics investigations. So that's what I would like to share. If there is a time I will just show one example of steganography then we'll take up Q&A.
Okay. So I'll just share uh I'll try to share my screen again but I'm not then I can take a last question. Yeah, student is asking uh hersel that how is the integrity of digital evidence maintained during financing investigation. Good question. I think I tried to answer that using imaging and cloning we will be able to maintain the integrity of the uh uh of the device or evidence and it has to happen without that I think courts will not accept it as a uh admissible evidence. Imaging and hashing is an answer.
Can you see my screen? Yes sir. Okay. So quickly I want to show you one example. So okay this is the steganography. Steeno means um cover and graphy means writing. So it's basically it's a covered writing. So you see these two images. As a normal person we don't see any difference. So this is the image original image and steganography tools will help to embed a text message or a file. You can actually embed another file into this file itself. Here you can see attack at midnight. This is the message that is inserted in this particular image. But as a normal user you cannot actually differentiate anything between these two messages. So this is called carrier message and this is called payload. Payload gets inserted into the carrier message and this message will be transmitted to the other party. So to convey some message. So you can actually insert a image into image, a text into image, a video into a video, you you can do all these things using steganography. So people and it is sometimes it is very difficult to find out if there is any message inserted in into these steganographic images and even if you find out you need to have uh write passwords or keys to break that uh image so that you can see what is written in that hidden uh what is written in that particular image. But a lot of foreign tools have got uh signature of the standard steganographic uh uh software. So using those things they will be able to break uh identify these payloads and then carrier messages and try to find information. So that is what I wanted to show about steganography. Uh but yeah if there is a time uh in the later part of the course I will try to demonstrate other other aspects as well. So there there is something called um anti-obfuscation. So I can I I will explain that in the later sessions what is the difference between obfuscation and then encryption and we will also see some of the examples in autopsy in our actual certification course. So with that I'll take a pause if there are any further questions I'll be more than happy to answer you. Thank you.
Thank you so much. It's really our pleasure that you have come on this platform and the way you have been taking this session now the master it's really indeed a true master class in fact I learned one thing by this master class that eyes are no more so of the person on the contrary the computer or the hardest are actually so really thank you so much for this wonderful session.
So with this we come to the end of this session. So in case if you all have any more doubts, any more questions, you all can always reach out to us at the info.tcsionhub at the ratecs.com and uh sir uh uh if you would like to add something uh please.
Yeah. Yeah. Since you mentioned about eyes and windows, there is a saying called eyes are the windows to the soul. But in the foreign world, windows are the eyes of the soul. So, so absolutely I actually got it by listening all this master class. I really appreciate that really now that nowadays completely the technical language is totally different real world examples. So all the guys who whether you are a technical person, nontechnical person, digital foreign is is uh is applicable for everyone. I'm not a technical person. I started my career mean I am a technical person but not a digital foreign person. But I learned digital forensics based on my own interest. So if I can learn anyone can learn. So uh so don't get afraid to start learning something new and start at some place and then when you are trying to learn something you ask yourself what is this why is this what is more more about this? So that way you will expand your knowledge base and then sky is the limit. Digital foreign used to be one small topic in cyber security chapter in olden days but nowadays you find UG courses PG courses and PhDs on digital foreign itself. So that's the kind of uh uh vast knowledge or vast area that is available for all of us to grab. So yeah digital forensics. Yes, that's the future. Absolutely. Absolutely.
With this, I would like to add one line. The internet never sees and never do the threats. Step up and go for cyber security courses and be the shield. Yes. So, thank you so much audience for your active participation. Thank you once again sir for your time and presence and I Shut signing off. Have a pleasant evening. [Music]