digital forensics track schroader-rob when forensics collide

37
When Computer Forensics & Mobile Forensics Collide

Upload: issa-la

Post on 28-Jan-2018

377 views

Category:

Technology


1 download

TRANSCRIPT

Page 1: Digital forensics track schroader-rob when forensics collide

When Computer

Forensics & Mobile

Forensics Collide

Page 2: Digital forensics track schroader-rob when forensics collide

Speaker Introduction

• Rob Schroader, CEO• [email protected]• 801-796-0944

• 10 years of experience with digital forensic professionals

• iPhone addict

Page 3: Digital forensics track schroader-rob when forensics collide
Page 4: Digital forensics track schroader-rob when forensics collide

The Forensics of Things

• What is a Computer?

• What is a Mobile Device?

• What Else Connects to Internet/Social Media?

Page 5: Digital forensics track schroader-rob when forensics collide

The Forensics of Things

• iPhone 6 – A7 Processor: • Dual Core 1.38 GHz Processor

• 1 GB LPDDR3 RAM

• 128 GB Storage

• Huawei Ascend Mate 7• Quad Core 1.8 GHz Processor

• 2/3 GB RAM

• 32 GB Storage

• microSD Slot (128 GB)

Page 6: Digital forensics track schroader-rob when forensics collide

The Forensics of Things

• My Laptop• Dual Core 2.0 GHz Processor

• 2 GB RAM

• 122 GB Hard Drive

Page 7: Digital forensics track schroader-rob when forensics collide

What you do is the same as your suspect does with…• A computer

• Surf the internet

• Type documents

• Games

• Email

• A tablet• Play games

• Surf the internet

• Email

• A cell phone• Call friends

• Text friends

• Social Media

• Apps, Apps, Apps

Page 8: Digital forensics track schroader-rob when forensics collide

Know Your Risks• Device Type

• Computer

• Mobile

• Environment• Weather

• Signals

• People• There is no license to operate a computer/mobile.

Page 9: Digital forensics track schroader-rob when forensics collide

Where’s the Data?

•Computer

•Mobile Device

•Mobile Data on Computers

•The Cloud…The Dreaded Cloud!!!

Page 10: Digital forensics track schroader-rob when forensics collide

Forensic Rules• Chain of Custody

• First Responder is lab

• Documentation• Set procedures

• Hash Validation• Math is your friend

• Tools & Methodologies• Validate tools before the field

Page 11: Digital forensics track schroader-rob when forensics collide

Forensic Tools Questions• Is it read only?

• Yes

• No

• Can I repeat my results?

• What are your validation steps?

Page 12: Digital forensics track schroader-rob when forensics collide

Forensic Tools Questions• Is the data verified and if so how?

• What hash values are used?

• Can those values be repeated?

• Are there other validations?

• Was it designed for forensics, and are the images gathered valid?

• Is it a commercial tool that is being used in forensics?

• How is the image file created?

Page 13: Digital forensics track schroader-rob when forensics collide

Non-Forensic

• Does Anything Go?

• Preserve Data

• Do No Harm

• Tools You Use

Page 14: Digital forensics track schroader-rob when forensics collide

Outsourced vs. Internal

• Costs

• Time

• Capabilities• Tools

• People

• Collection Only?

• Collection Plus Analysis?

Page 15: Digital forensics track schroader-rob when forensics collide

Computers vs. Mobiles

• File Systems• Windows (NTFS, FAT – Registry)

• MAC (HFS, HFS+)

• iPhones (iOS – Applications)

• Drives vs. Memory

• Logical vs. Physical

• Amount of Data

Page 16: Digital forensics track schroader-rob when forensics collide

Computer Triage• Targeted Collection

• Deleted Data• Is it necessary?

• Email

Page 17: Digital forensics track schroader-rob when forensics collide

Computer Triage• Chat Logs

• Internet History

• Recent Documents

• Registry Data

Page 18: Digital forensics track schroader-rob when forensics collide

Mobile Triage• Logical Acquisition

• Deleted Data• Is it necessary?

• Backup Files

• Call Logs

Page 19: Digital forensics track schroader-rob when forensics collide

Mobile Triage• SMS

• Email – Not Likely

• Contacts

• Internet History• Chrome Account?

Page 20: Digital forensics track schroader-rob when forensics collide

Computer Triage Example• DP2C

• Targeted Data Collection

• Bootable

• Easy to Use

• P2C Data Triage• Windows Systems

• iTunes Backups

• Mobile Device Acquisitions (DS Case Files)

Page 21: Digital forensics track schroader-rob when forensics collide

Computer Triage Example• DP2C

Page 22: Digital forensics track schroader-rob when forensics collide

Computer Triage Example• DP2C

Page 23: Digital forensics track schroader-rob when forensics collide

Computer Triage Example• DP2C

Page 24: Digital forensics track schroader-rob when forensics collide

Computer Triage Example• DP2C

Page 25: Digital forensics track schroader-rob when forensics collide

Computer Triage Example• P2C Data Triage

Page 26: Digital forensics track schroader-rob when forensics collide

Computer Triage Example• Limitations

• Not Comprehensive

• Registry and System Files

• Time Constraints

Page 27: Digital forensics track schroader-rob when forensics collide

Storage Devices• SD Cards

• Used for Computer or Cell Phone?

• Significant Data Storage (128 GB)

• Computers• Documents

• Program Files (QB, Quicken, Photoshop, Flow Charts, etc.)

• Multimedia

• Phones• Photos

• Multimedia

• App Data

Page 28: Digital forensics track schroader-rob when forensics collide

Examples

• From Device

• From Computer

Page 29: Digital forensics track schroader-rob when forensics collide

Examples

• Apps• Parsed

Page 30: Digital forensics track schroader-rob when forensics collide

Examples

• Apps• Not Parsed

Page 31: Digital forensics track schroader-rob when forensics collide

Examples

• Drop Box on Computer

Page 32: Digital forensics track schroader-rob when forensics collide

Examples

• Drop Box on iPhone

Page 33: Digital forensics track schroader-rob when forensics collide

Examples

• Computer Shows• 135 Files

• iPhone Database Shows• 978 Files

• Not All Listed Files Still on Phone

Page 34: Digital forensics track schroader-rob when forensics collide

Examples • Mass Storage Devices (SD Cards, USB Drives, Etc.)

Page 35: Digital forensics track schroader-rob when forensics collide

Should You Triage?

• Can be Easy

• Cost Savings

• Immediate Results

• Expanded Skill Set

• Anyone Can Do It

Page 36: Digital forensics track schroader-rob when forensics collide

Any Questions?

Page 37: Digital forensics track schroader-rob when forensics collide