Saturday, May 7, 2011

Quick Post: Forensic 4cast 2011 Awards/ Digital Forensics With Open Source Tools

The Forensic 4cast Awards are upon us and Lee Whitfield has compiled the nominations (in case you missed it....nominations are BY the digital forensic community that WE voted on, so as Douglas Brush stated, file your complaint here ), and it's time to commence voting once again. So get over there and VOTE! Congratulations to the nominees:
Harlan Carvey, Rob Lee, Ryan Kubasiak, Ken Pryor, Matt Churchill, Jonathan Rajewski, Joe Garcia's CyberCrime101 podcast, Lee Whitfield's Forensic 4cast podcast, Ovie Carroll's CyberSpeak podcast, et al. The Forensic 4cast Awards will be presented in Austin, Texas at the 2011 SANS Forensics Summit in June. 


Digital Forensics With Open Source Tools by Cory Altheide & Harlan Carvey

DFWOST is available and shipping! I ordered mine Wednesday afternoon and received in Friday afternoon. Good job Syngress! 
I "broke the seal" and began drinking from the well of digital forensic youth and couldn't put it down. It'll definitely be a great addition and practical field-guide for my digital forensic arsenal! As Rob Lee stated, "Digital Forensics- MacGyver style!"
There are plenty of books out there that cover bit level forensic analysis and DFWOST focuses on the practical aspect and application of open source tools for the forensics practitioner. At first look, DFWOST appears be a solid contribution that should be welcomed by the community, re-affirming this argument. I plan on completing a full Amazon book review once I complete DFWOST.

Saturday, April 2, 2011

The new Digital Forensic Source blog

This is just a quick entry to inform readers that the CFS blog is now the DFS (Digital Forensic Source) blog, located at www.digitalforensicsource.com. Please update those bookmarks and RSS feeds to www.digitalforensicsource.com, if you bookmarked computerforensicsource.com. For those of you that have been following the blog, you'll recall my blog post "Computer Forensics: What's in a name. After all it's only a name." We need to be consistent with our terminology in all facets of digital forensics and the community seems to be steering to digital forensics vs. computer forensics, and I want the blog to be consistent with the voice of the DF community.

Community
Speaking of community, David Kovar wrote a great blog post to his blog, called "Fragmentation of the digital forensics community". Jonathan Krause delivered a response on his blog to David's post, which is also a good read. David discusses his viewpoints and divisive things we continue to do to fragment our community. David Sullivan also blogged about Belonging and Community; Harlan also discusses community in his blog.

Twitter
Are you on Twitter? Twitter seems to be where it is happening these days. I remember when our little forensic twitter community was just made up of a few folks, most of whom I knew through Twitter and had the pleasure of meeting during a SANS Conference in Chi-town (you know who you are). Now the #DFIR twitter forensic community has really grown and brought DF practitioners together, using Twitter as a networking and communication tool. #DFIR is the official hash tag the digital forensic community is using on Twitter. Join in the conversation!

April Fool's Day
Lee Whitfield with Forensic 4cast calls it quits to join Mark McKinnon in tag team wresting. Lee Whitfield is The Blue Dongle! Of course, Douglas Brush with The Digital Forensics Group, completed some spring cleaning with his Disk Images blog post.

News

Thursday, March 10, 2011

Computer Forensics: Top 5 Posts and More

Here are the top 5 all-time CFS blog posts:
  1. Computer Forensic Book Review: Mac OS X, iPod, and iPhone Forensic Analysis DVD Toolkit
  2. Book Review: Windows Registry Forensics
  3. Intro to Report Writing for SANS DFIR blog.
  4. Forensic 4cast Awards "The Digital Forensic Oscars"
  5. Internet Evidence Finder Part II: Intro to IEF v3.3 for SANS DFIR blog
CFS blog continues to receive awesome traffic (thank you). Keep those bookmarks, RSS feed subscriptions, and tweets coming! If you have a blog and have linked to CFS let me know; as I'll be more than happy to add you to "My Blog List". I'm working on another book review that I hope to post soon. The readers seem to enjoy the book reviews, just as I enjoy writing the reviews.

So how are readers being directed to the CFS blog? 


Here are the top search keywords:
  1. internet evidence finder v3.6.0
  2. "forensic discipline" "computer forensics"
  3. cindy murphy "cell phone evidence extraction process"
  4. digital forensic report template
  5. "mac memory reader"
  6. day finder v3.3
  7. dfrws 2010 challenge winner
  8. internet evidence finder
  9. internet evidence finder v3.3
  10. mac forensics book

Newsworthy Items


    Forensic Tools

    Job Opportunity links

    Wednesday, February 2, 2011

    Book Review: Windows Registry Forensics

    Harlan Carvey has done it (again) and continues to raise the bar. It's a must read for the digital forensic analyst! Harlan has brought his many years of experience and research in forensic analysis of the windows registry, into one book. As Rob Lee (SANS Institute) stated, “Windows Registry Forensics provides extensive proof that registry examination is critical to every digital forensic case.”


    Dave Hull, fellow SANS Computer Forensic blog editor and SANS Instructor, is the Technical Editor for Windows Registry Forensics (WRF).           

    The book contains sidebars, tips, notes, and various analysis concepts of registry forensics, which the author highlights. Of course, this book wouldn’t be complete without tools. Windows Registry Forensics paperback includes a CD that contains forensic tools and code (w/perl, of course), discussed in WRF.
    In Chapter 1 (Registry Analysis), Harlan goes into the structure of the registry, which consists of binary data, and for the most part is unbeknownst to the user. Nomenclature of the windows registry (i.e. keys, sub-keys, values, and data) and analyzing registry cell structure data is covered thoroughly in this chapter.
    In Chapter 2 (Tools), Harlan discusses free and open source tools to the reader, which can immediately be used for conducting his/her own analysis of registry artifacts, such as Reg Ripper, Autoruns, Regshot, and MiTeC Registry File Viewer (RFV). This chapter walks the reader through live response and forensic analysis of registry artifacts using various free tools.
    Chapter 3 (Case Studies: The System) and Chapter 4 (Case Studies: Tracking User Activity) go hand-in-hand. These chapters are the practical application portion of the book, providing the reader with real-case examples, and outlining registry forensic artifacts (or lack thereof…remember, the absence of an artifact in itself is an artifact). Harlan discusses how to crack the SAM using free tools (e.g. Cain, OphCrack). I’ve read a lot of material the last few years covering USB device artifacts; I’ve not seen a more detailed analysis of USB artifacts through registry forensic analysis, until reading Windows Registry Forensics. The case studies chapters also cover real world scenarios (e.g. The Trojan Defense, Tying It Together) and how the analyst’s investigative goals can be guided by using registry analysis, during the intrusion investigation or forensic examination.

    In summary, there are a few grammatical and “print shop” errors that should have been caught by the publisher prior to printing the book; however, that does not keep me from giving this book a 5-star review. Once an author submits a final manuscript to a publisher, the publisher is responsible for ensuring the book and content are print (”showroom”) ready. Once again Harlan delivered an exceptional reference book to digital forensic community!
    What I’ve taken away from this book is the registry key structure and its nomenclature, key time stamps (data correlation and understanding LastWrite times), deleted registry keys, and the registry redirector (i.e. 64-bit OS calling on 32-bit application in registry). If you want to sharpen your forensic analysis skills, look no farther than Windows Registry Forensics. There’s a key for that!

    Wednesday, January 19, 2011

    Computer Forensics: What's in a name? After all it's only a name.

    "What's in a name? That which we call a rose by any other name would smell as sweet." -William Shakespeare
    While this may hold true in a literary setting, what about computer/digital forensics? How important is a name? I think as a community we need to truly define ourselves. The community seems to be steering towards digital forensics (computer forensics, mobile device forensics, etc. as sub-disciplines). John J Barbara had a two part series in DFI News on the Digital Forensic Sub-Disciplines, which was a great article outlining these sub-disciplines and ASCLD/LAB defining the lifecycle of one discipline into the next. Where does one discipline begin and where does one end? 
    For example, while you (forensic examiner/analyst) are performing a forensic analysis of a forensic image you carve out a deleted video (.AVI) of the alleged crime (e.g. armed robbery) from the suspect's seized computer. The case officer/investigator requests you to "enhance" the video quality to aid in the "forensic identification" of a second suspect. Have you crossed over from the computer/digital forensic discipline into video forensic analysis sub-discipline? Can you testify as a forensic video expert?
    I've had the opportunity to explain these separate disciplines of computer forensics and mobile device forensics to a jury. A lot of people feel that because you are an "expert" in the area of computer forensics that you should automatically be an "expert" in mobile device forensics. There are a lot of gurus out there that live and breathe mobile device forensics and are experts in the field; however, I'm not one of them. As a community and a computer/digital forensic discipline we must know where these boundaries exist and educate not only ourselves, but our teams/clients/attorneys/officers, etc. about these sub-disciplines. Remember, as the expert it is your responsibility to establish those boundaries with clients/attorneys and a jury.

    With these disciplines/sub-disciplines, it also brings up another ongoing issue in the community. What do we call ourselves? Are you a computer forensic technician/examiner/analyst, a digital forensic technician/examiner/analyst? The king of drive-bys, Ovie Carroll, brought up this very topic in this week's CyberSpeak. Besides telling us to go "PreFetch Ourselves" in this episode, Ovie discusses some important issues about the community defining itself (nothing but love for the Ovie).
    You wouldn't call an engineer, a technician; nor should you assume your technician is an engineer. Same methodology applies to computer forensics. A forensic technician/first responder's training and expertise will differ from a forensic analyst. Just as a forensic examiner and forensic analyst are different. Each person interacts with the digital evidence in a different manner with separate job duties and goals.
    So are you a technician, examiner, analyst, expert or even a scientist? These titles have been discussed on several forensic mailing lists in the past and the debates are always interesting.


    Honorable Mentions

     If you read a book you like or one that was a very painful process from beginning to end, write about it and share your viewpoints. Write an amazon book review. This is good for providing feedback to the author and it is good for the forensic community because you can let others know what books they need to have on their bookshelf and books they should not waste their money on.

    Thank you for the kind feedback and continuing to follow my blog; keep those tweets, e-mails, and page views coming! My next blog post I plan to share some forensic projects I'm working on and the power of sharing what you know outside of the computer forensic community.