|
|
NITRO
Lesson 10 - Terrorism
Lesson 10:
Historical accounts vary but it is generally agreed that terrorism
Terrorism
has been on the Internet years before the attacks of September 11th.
Any time that the Internet is used by a person or group to
intimidate and instill fear in others, it is called terrorism.
Lesson 10
• Describe some of the common Terrorist Attacks
Learning
• Discuss the methodologies used in these cases
Objectives
• Describe some of the responses to these attacks
Lesson 10 Topics
Here are the topics to present.
Topic
Key Points
Internet Terrorist
• Terrorism
Methodologies
• Fear
• Intimidation:
• Psychological warfare
• Propaganda
• Fund-raising
• Message center for coordinating activities
• Launch network attacks
• Data mining
• Denial of Service attacks against enemies
• Site defacements of web sites counter to
their cause
• Spam e-mail attacks against enemies
• Phishing attacks for banking information to
help fund activities
My Notes:
Investigative
• Capture
Response
• Preservation
• Warrants
• Reporting
• Education
My Notes:
70
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Module 9 - Phases of an Intrusion
Module 9
In order to understand how network intrusions happen you need
Overview
the understanding of the phases which occur as the attacker plans
and then executes the intrusion. This module illustrates those
phases in depth.
Module 9
None, other than the procedures in the manual.
Exercises
Module 9 Testing This module is not tested.
Module 9
• Define network intrusions.
Objectives
• Understand the phases of an intrusion
• Understand the information that an attacker can gather offline
• Understand the goals, strategies and techniques employed by
the attacker.
• Know attacker profiles
In this Module
The following table shows the contents of this module.
Topic
See Page
Lesson 1 - Defining an Intrusion
72
Lesson 2 - Reconnaissance
73
Lesson 3 - Network Attacks
76
Lesson 4 - Entrenchment
78
Lesson 5 - Infiltration and Extraction
80
5-2008
For Official Use Only - Law Enforcement Sensitive
71
NITRO
Lesson 1 - Defining an Intrusion
Lesson 1: Defining Technically complex network intrusions can be difficult to
an Intrusion
identify. To do so you need to understand how intruders conduct
these attacks.
Lesson 1 Learning
• Define Network Intrusion
Objectives
• Discuss the vulnerabilities attackers look for in a target
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Intrusions
• Explain the definition of Intrusion,
Vulnerability, Exploit and Threats or
Threat Agents.
• Explain the goals of the intrusion and how
they can be combined in several ways.
• Explain the types of intruders and their
profiles.
• Touch on how insiders are the largest threat
to any system.
• Describe the phases of an intrusion.
Mention how once the attack has succeed
the phases will start again from the inside
and propagate throughout the internal
network.
My Notes:
72
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 - Reconnaissance
Lesson 2:
In this lesson, the topic of how an attacker will do research on the
Reconnaissance
system and resources to better understand the target.
Lesson 2 Learning
• Explain the purposes and methods of reconnaissance.
Objectives
• Explain the difference between direct and indirect methods
• Describe some specific tools and techniques used
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Goals
• Discuss the information gathering mindset
and methodologies.
• Describe the types of data that are searched
for and used.
My Notes:
Direct vs.
• Describe how direct actions can be logged
Indirect
by the target, but indirect actions are not.
My Notes:
General Web
• Explain how site administrators will
Browsing
inadvertently leave information on a site
that can be used by attackers.
My Notes:
Public Records
• Discuss the amounts of information that is
available from public data repositories.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
73
NITRO
Lesson 2 Topics, continued
Topic
Key Points
DNS & Whois
• Show how the information in a DNS entry
can be a wealth of information to an
attacker.
My Notes:
The Wayback
• Show how the archive site can display
Machine
information that has been removed from a
site but is still available from an archive
copy.
My Notes:
Other sources
• Cover the other misc sources of
information that may be available to
attackers.
My Notes:
Target site
• Discuss how the source code and
Examination
information on all the pages of a target site
can be examined freely.
•
My Notes:
74
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 Topics, continued
Topic
Key Points
Attack vectors
• Show how any way into a system that has
been discovered is a possible vector.
• Modems, faxes, telephone systems and any
other in-route is a possible target of
opportunity.
• Wireless is a popular attack vector because
of the many weaknesses in that area.
My Notes:
Identification
• Any information that is in a packet of data
Live Host
coming from the host is used.
information
• Probing these areas will potentially give
information to the attacker.
• Any open port or protocol will be
discovered and probed.
• Banners and other identifiers will be
gathered and used to determine versions
and known weaknesses.
My Notes:
Vulnerability
• The same scanning tools that system
scans
administrators use to harden a system are
used by the attackers
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
75
NITRO
Lesson 3 - Network Attacks
Lesson 3: Network In this lesson, we look at the attack phase of an intrusion
Attacks
Lesson 3 Learning
• Explain the goals of the attack
Objectives
• List the major strategies used in an attack
• Understand some of the techniques an attacker can use to
damage the functionality of a system or network
Lesson 3 Topics
Here are the topics to present.
Topic
Key Points
Goals
• Discuss how the attacker wants to gain a
foothold and advance his presence on the
target
My Notes:
Authentication
• Discuss how authentication attacking
and Guessing
works.
• Talk about the many types of guessing and
cracking tools there are.
• Note that there are all types of value
metrics used to generate an attack.
• Credential discovery and reset techniques
should be covered
My Notes:
76
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 3 Topics
Here are the topics to present.
Topic
Key Points
Identification
• Any information that is in a packet of data
Live Host
coming from the host is used.
information
• Probing these areas will potentially give
information to the attacker.
• Any open port or protocol will be
discovered and probed.
• Banners and other identifiers will be
gathered and used to determine versions
and known weaknesses.
My Notes:
Input attacks
• Discuss how using too much input or
incorrect input the system can be brought
to a stop or exploited
• SQL injection attacks are popular and
effective. Describe them
• Directory traversal is another popular
attack type.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
77
NITRO
Lesson 4 - Entrenchment
Lesson 4:
In this lesson, we look at the entrenchment phase of an intrusion
Entrenchment
Lesson 4 Learning
• Explain the goals of entrenchment
Objectives
• List the major strategies used
• Understand some of the techniques an attacker can use to hide
traces of unauthorized activity
Lesson 4 Topics
Here are the topics to present.
Topic
Key Points
Goals
• Discuss how the attacker wants to preserve
his presence on the exploited system.
My Notes:
Log Cleaning
• Explain how the attacker will remove
traces of his presence on the system.
My Notes:
Automatic
• The attacker will setup programs to run on
execution
system startup to ensure his continued
access.
My Notes:
78
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 4 Topics, continued
Topic
Key Points
Hooking
• Discuss how the attacker will attach
programs to other programs to hide his
work.
•
My Notes:
File types and
• Show how the attacker will change file
naming
extensions and names to obfuscate his use
conventions
of known attacker tools.
•
My Notes:
Remote
• Explain how the attacker will use remote
connections and
connectivity and backdoor programs to
Backdoors
make use of the system easier.
•
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
79
NITRO
Lesson 5 - Infiltration and Extraction
Lesson 5:
In this lesson, we look at the infiltration and extraction phase of an
Infiltration and
intrusion
Extraction
Lesson 5 Learning
• Explain the purpose and methods of inflitration
Objectives
• Explain the importance of trust relationships
• Determine the data types targeted by attackers and how these
types are extracted.
Lesson 5 Topics
Here are the topics to present.
Topic
Key Points
Sniffers
• Describe how once the attacker is on the
system he uses it as a springboard to repeat
the phases of an intrusion on other nearby
systems.
• Show how sniffing of the target network is
beneficial to the attacker.
My Notes:
Trust
• Explain how dangerous these relationships
Relationships
are once the attacker is on the network.
My Notes:
Data Extraction
• Discuss the types of data the attacker is
interested in and how it is typically
transferred.
My Notes:
80
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
This page intentionally left blank.
5-2008
For Official Use Only - Law Enforcement Sensitive
81
NITRO
Module 10 - Report Writing
Module 10
Investigations require comprehensive reporting that documents
Overview
actions and summarizes findings. The best reports are clear,
concise, and accurate and report only information relevant to the
facts of the case.
Objectives
• Discuss the importance of writing an organized, clear, concise
and accurate report
• Write an organized, clear, concise, and accurate report
• Discuss the appropriate interviewing techniques for conducting
investigations in a highly technical environment
In this Module
The following table shows the contents of this module:
Topic
See Page
Lesson 1 - General Report Writing Techniques
83
Lesson 2 - Cyber Case Interviewing Techniques
89
82
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 - General Report Writing Techniques
Lesson 1: General
Forensic reports involving the analysis of digital evidence should
Report Writing
address the same basic information. No matter how well an
Techniques
investigator conducts analysis, it is of little value if results cannot
be reported in an organized, clear, complete and concise manner.
Lesson 1 Learning
• Discusses the purpose and need for forensic analysis
Objectives
• Explains what physical and/or logical evidence was analyzed
• Defines programs, terms, and their relevance
• Explains findings in an orderly manner
• Associates relevant evidence with users
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
The Forensic
• Culmination of a process often involving
Report
intensive and painstaking work
• Should reflect the time, effort and
professionalism involved in building the
case and acquiring the information
• Should be well organized, include only
relevant information, and be free of
grammatical, punctuation and spelling
errors
• Recipient should be able to read it one
time and have a very clear understanding
of the message you are trying to convey
• Consider the report a reflection of your
professionalism and develop it as such
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
83
NITRO
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Examiner Notes
• Documentation that is created during the
analysis process provides basis for
examiner to report results of case
• Should be preserved and may be
discoverable in court
• Foundation on which many digital
media-related cases are built
• Should present a clear timeline of the
actions taken and the results of those
actions
• Provide a repeatable roadmap of your
examination
• Number, date, and initial all note pages
• Ensure that you can accurately testify to
actions taken during the examination
My Notes:
84
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 Topics, Continued
Topic
Key Points
Forensic Reporting
•
Should contain all relevant evidence
found during examination
•
Clearly identify persons related to
examination including you, requestor,
suspects, and other pertinent individuals
•
Provide details about purpose for forensic
analysis
•
Describe physical and/or logical evidence
analyzed
•
Define related programs, terms and their
relevance
•
Clearly and concisely explain items of
evidentiary value found on suspect media
as a result of analysis
•
Identify location and relevance of items
of evidentiary value as relating to reason
for analysis and/or investigation
•
Report heading
•
Support requested, reason or purpose for
analysis
•
Summary of findings
•
Digital media analyzed
•
Analysis/Suspect Software Listings
•
Glossary of Technical Terms
•
Detail of Findings
•
Items Provided
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
85
NITRO
Lesson 1 Topics, Continued
Title Page
• Provides an overview of the case
• Report Header
• Support Requested
• Current Case Status
• Summary of Findings
• Title (To:)
• From
• Subject
• Support Requested or Purpose for
Analysis
• Status
• Summary of Findings
• Footer
My Notes:
Items Analyzed
• Describes in detail analyzed physical
and/or logical evidence
• Always include original and verified
hash values of all evidence items
• Physical Items:
• Manufacturer
• Model, serial, and part number (when
possible)
• Item description
• Any specific markings
• Logical Items:
• List the image files
• Original file name and include any hash
or other validation mechanism
My Notes:
86
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 Topics, Continued
Topic
Key Points
Relevant Software
•
Identifies software found on evidence
media relevant to case as well as identity
of forensic software used to perform
analysis
•
Analysis Software
•
List all software applications used during
the forensic examination
•
Version and brief description of
software’s functionality or use
•
Suspect Software
•
Software name and version
•
Full path to where application located on
suspect media
•
Brief description of program
functionality and how it relates to
Request for Analysis and/or investigation
•
Be prepared to further explain items in
this listing during prosecution
My Notes:
Glossary
• Defines technical terms, document
formats, and procedure details referenced
in report that may not be readily
understood by average non-technical
reader
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
87
NITRO
Lesson 1 Topics, Continued
Topic
Key Points
Details of Findings
• Provides detailed information about any
items of evidentiary value found on
suspect media during forensic
examination
• Should be thorough, concise, only
contain details relevant to request for
analysis and/or investigation
• Should not contain information about
processes executed that did not produce
relevant information, unless negative
result is relevant
• Discuss organization
• Discuss use of hyperlinks
My Notes:
Items provided
• Details all of physical items returned to
requestor with report
• Should include all items specified in
Items Analyzed section
My Notes:
Reporting scenario
• Discuss example and how it incorporates
information discussed in lesson
My Notes:
88
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 - Cyber Case Interviewing Techniques
Lesson 2: Cyber
Interviews are an essential element of developing information that
Case Interviewing
is relevant to a criminal investigation. When conducting a cyber
Techniques
crime investigation, investigators must prepare for the interview,
develop rapport with interview subjects, ask questions that
generate corroborative information and leads, and terminate the
interview in a way that leaves the door open for further questions.
Lesson 2 Learning
• Develop a plan to conduct interviews in a cyber investigation
Objectives
• Explain the psychology and culture of the technology world
and
• ways to apply that knowledge to the interview process
• Ask questions that will provide you with information that will
assist the investigation
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Cyber Crime
• Investigator must obtain information
Interviews
from all people who are involved with the
incident.
• Interview of a suspect may assist in
revealing true scope of investigation and
provide information needed to ensure
conviction of a suspect
• Integral part of any investigation,
victims, witnesses, and perpetrators all have
pieces of puzzle that investigator is trying to
put back together
• Investigator must skillfully navigate
human landscape to develop leads, confirm
events, and obtain complete picture of crime
• Accusatory versus Non-Accusatory
Interviews
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
89
NITRO
Lesson 2 Topics, continued
Topic
Key Points
Interview Process
• Planning/Research
• Opening/Rapport
• General Questioning
• Detailed Questioning
• Interview Termination
• Interview Psychology
• Investigator Initiated Contact
• Organization Initiated Contact
• Witness and Victims
• Issues to Address During Interviews
• Suspects
My Notes:
90
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
This page intentionally left blank.
5-2008
For Official Use Only - Law Enforcement Sensitive
91
NITRO
Module 11 - Legal Issues
Overview
No matter how solid a case may be or incriminating the evidence,
all computer crime investigations must be conducted in way that
adheres to established legal principles. If legal standards are not
met the case could be jeopardized and even dismissed, thus
allowing a perpetrator to walk free.
Purpose of this
The purpose of this module is to familiarize students with some of
Module
the basic legal issues that must be considered when conducting an
investigation involving digital data.
Objectives
After successfully completing this module, you will be able to:
• Understand some of the legal issues involved in a digital
investigation
• Employ practices during an investigation that that will pass
legal challenge
In this Module
The following table shows the contents of this module:
Topic
See Page
Lesson 1 - Search Warrants
93
Lesson 2 - ISP’s
95
92
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 - Search Warrants
Lesson 1: Search
Searches of an individual or a location require a search warrant or
Warrants
a valid exception under the 4th Amendment to the U.S.
Constitution
Lesson 1 Learning
• Understand how the 4th amendment of the United States
Objectives
Constitution is interpreted by the Courts
• Recognize situations in which the investigators may search or
seize without a warrant
• Discuss the types of consent and their requirements
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Search Warrants
•
4th Amendment Overview
•
What is an unreasonable search
•
Probable Cause
•
Affidavit
•
Items to be Seized
•
USDOJ-CCIPS
•
Warrant Execution
My Notes:
Search Warrant
• Consent
Exceptions
• Stop and Frisk
• Search Incident to Arrest
• Immediate threat to life or serious bodily
injury
• Immediate threat of the destruction of
evidence
• Fresh pursuit
• Plain view
• Vehicle searches
• Custodial searches
• Border searches
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
93
NITRO
Lesson 1 Topics, Continued
Topic
Key Points
Consent
• Voluntary Consent
Searches
• Informed Consent
• Withholding Consent
• Withdrawing Consent
•
3rd Party Consent
My Notes:
Stop and Frisk
• May not seem applicable to digital
Searches
investigations
• If cell phone, PDA or other digital device
found during search you may request
consent to browse text messages
My Notes:
Search Incident
• Again, may not seem applicable to digital
to Arrest
investigations
• If cell phone, PDA or other digital device
found during search you may request
consent to browse text messages
My Notes:
94
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 - Internet Service Providers
Lesson 2: ISP’s
Many crimes involve the use of commercial and private networks
and communications facilities. These records are usually
maintained by entities often referred to as Internet Service
Providers (ISPs). ISPs often maintain records of accounts, billing,
transactions, and content of the communications and data that
travel over their networks.
During an investigation, you will need to gather this pertinent
information from ISPs. It is imperative that an investigator
understands the proper way to request these records, so they are
admissible as evidence in a criminal proceeding.
Lesson 2
• Explain which laws apply to a given authority and know where
Objectives
to find those laws
• Describe the search authorities for gathering records
• Prepare requests for records
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Legal
• ECPA
Framework
• Consent
• Express Consent
• Written Consent
•
3rd Party Consent
My Notes:
Preservation
•
18 USC § 2703(f)
letters
•
Time Limitations
•
Limitations (Snapshot at time of receipt)
•
One renewal for additional 90 days
•
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
95
NITRO
Lesson 2 Topics, Continued
Subpoenas
• Business Records
• Testimony
• Subscriber Records
•
My Notes:
”D” Order
•
18 U.S.C. § 2703(d)
•
Transactional Records
•
Content
•
Reasonable Grounds and Relevant
My Notes:
96
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
This page intentionally left blank.
5-2008
For Official Use Only - Law Enforcement Sensitive
97
NITRO
Module 12 - Fundamentals of Log Analysis
Module 12
The analysis of computer network intrusions is a difficult task. The
Overview
Scientific Method provides a general framework that can be used
to effectively guide the investigation.
Module 12
None, other than the procedures in the manual.
Exercises
Module 12 Testing This module is not tested.
Module 12
• Describe the main steps of the Scientific Method
Objectives
• Explain how the Scientific Method can be applied to digital
forensic analysis
• Use the initial observations in a case to determine the most
likely location of additional, related artifacts
• Apply the analysis techniques learned in the previous modules
to analyze log files that contain evidence of an intrusion
In this Module
The following table shows the contents of this module.
Topic
See Page
Lesson 1 - The Scientific Method and Intrusion
99
Analysis
Lesson 2 - Observing Intrusion-related Activity
100
and Generating a Hypothesis
Lesson 3 - Predicting the Nature and Location of
103
Intrusion Artifacts
Lesson 4 - Using Log Analysis to Evaluate an
105
Intrusion Hypothesis
98
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 - The Scientific Method and Intrusion Analysis
Lesson 1: The
The Scientific Method is used as a guide for investigating any
Scientific Method
problem, including a network intrusion. It is a simple but effective
and Intrusion
process by which you generate a hypothesis based upon observed
Analysis
events, then design and select analysis tasks to help you evaluate
that hypothesis.
Lesson 1 Learning
• Define the Scientific Method
Objectives
• Explain how the Scientific Method can guide an intrusion
investigation.
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
The Scientific
• Observation: Observing one or more events
Method
or sets of events. Observation establishes
the facts surrounding these events to
identify their cause and consequences.
• Hypothesis: A hypothesis is generated that
explains the observed events, including
their root cause, interrelationship, and
consequences.
• Prediction: Predictions are made as to the
possible nature and location of artifacts in
the evidence that will either support or
contradict the hypothesis.
• Evaluation: Performing procedures that test
for the presence of artifacts that support,
falsify, or modify the hypothesis.
• Conclusion: Formation of a conclusion,
based upon the results of tests performed
during the Evaluation step..
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
99
NITRO
Lesson 2 - Observing Intrusion Activity and Forming a Hypothesis
Lesson 2:
The first step of the Scientific Method applied to an intrusion is to
Observing
identify the current set of observations and form a hypothesis
Intrusion-related
based upon those observations.
Activity and
Forming a
Hypothesis
Lesson 2 Learning
• Describe common intrusion-related observations
Objectives
• Form a hypothesis
• Describe common incident classifications
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Common
• Discuss how network intrusion
Observations
investigations should normally begin with
one or more specific observations. These
observations guide the formation of a
hypothesis as to what may have occurred.
My Notes:
Common
Many different events can spark an intrusion
Primary
investigation. Some examples include:
Observations
• Antivirus alerts
• IDS/IPS alerts
• System/applications errors
• Abnormal authentication patterns
• Access control list violations
• Generic unusual activity
My Notes:
100
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 Topics, continued
Topic
Key Points
Supplementary
• The incident responder should make
Observations
supplementary observations before creating
a hypothesis. Examples of this data are:
• Network diagrams
• Device documentation
• Contact information
My Notes:
Common
• Observations made during network
Observation
intrusions will have attributes that should
Attributes
be recorded. These attributes include, but
are not limited to the following
• Date/Time
• IP Addresses
• Port Numbers
• Accounts and aliases
• Host names and aliases
• Files
• General description.
My Notes:
Recording
• Observations can be recorded in many
Observations
different forms including written notes,
office documents, and databases. You
should use the approved and tested method
used by your organization. This course uses
a spreadsheet template for recording this
data.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
101
NITRO
Lesson 2 Topics, continued
Topic
Key Points
Hypothesis
• This hypothesis should include a statement
Formation
regarding each of the following
• What/How
• Where
• Who
• Why
My Notes:
Multiple
• Cover the concept of breaking a large
Hypothesis
hypothesis into smaller sections and
proving each in turn.
My Notes:
Incident
• Discuss the various classifications that
Classifications
incidents fall into including:
• Denial of Service (DOS)
• Malicious Code
• Unauthorized Access
• Inappropriate Usage
• Suspicious Activity
• Multiple Components
•
My Notes:
102
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 3 - Predicting the Nature & Location of Intrusion Artifacts
Lesson 3:
The purpose of this lesson is to teach you how to determine
Predicting the
potential locations of artifacts related to your hypothesis.
Nature and
Location of
Intrusion Artifacts
Lesson 3 Learning
• Determine the applications and network traffic types that were
Objectives
involved in observed events
• Determine the flow of network traffic related to observed
events
• Predict artifact location based upon the network architecture,
probably traffic flow and related applications
Lesson 3 Topics,
Here are the topics to present.
Topic
Key Points
Finding Intrusion
• Discuss the plan and mapping of artifacts
Artifacts
to make the evaluation of facts easier.
My Notes:
Relating
• You need to correlate all observed events
Observed Events
to the applications involved. This will help
to Applications
you to locate potential artifacts.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
103
NITRO
Lesson 3 Topics,
Here are the topics to present.
Topic
Key Points
Identification
• Any information that is in a packet of data
Live Host
coming from the host is used.
information
• Probing these areas will potentially give
information to the attacker.
• Any open port or protocol will be
discovered and probed.
• Banners and other identifiers will be
gathered and used to determine versions
and known weaknesses.
My Notes:
Network Traffic
• One simple way to identify devices that
Flow and
may contain relevant data is to locate all
Intrusion
devices that related traffic may have passed
Artifacts
through
My Notes:
Predicting
• Discuss prediction of artifacts on:
Artifact Location
• Devices
• File
• Directories
My Notes:
104
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 4 - Using Log Analysis to Evaluate and Intrusion Hypothesis
Lesson 4: Using
The purpose of this lesson is to describe how log analysis
Log Analysis to
techniques are used to evaluate an intrusion hypothesis.
Evaluate an
Intrusion
Hypothesis
Lesson 4 Learning
• Determine the format of log files
Objectives
• Use search, filter, and extraction techniques to evaluate a
hypothesis
• Record findings and keep track of new leads
Lesson 4 Topics
Here are the topics to present.
Topic
Key Points
Hypothesis
• Discuss how a hypothesis is evaluated
Evaluation
using digital forensic data acquisition and
analysis techniques
My Notes:
Procedure
• Explain how there are multiple methods of
Selection
searching and filtering log files.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
105
NITRO
Lesson 4 Topics, continued
Topic
Key Points
Acquiring Log
• Log files may be provided directly to you
Files
by an incident responder or network
administrator who collected them from the
original source media.
• You may obtain a physical or logical image
of the original storage media containing the
log files, and then extract the logs from that
image.
• You may logically copy log files from the
source system or device.
My Notes:
Previewing Log
• Before analyzing collected logs, you
Formats
should first preview the format of those
logs to ensure that you know how to read
them properly and use the correct methods
for searching them.
My Notes:
Determining File
• The first step in previewing log format is to
Type
determine the file type.
My Notes:
Determining
• Once you know the file type for each log,
Data Format
you should identify the format of the data
within a Log
within. For network traffic capture logs,
this is relatively uniform. Text logs will
vary.
My Notes:
106
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 4 Topics, Continued
Topic
Key Points
Search/Extractio
• Describe the general goal will be to search
n Criteria
for and extract log entries, or portions of
log entries that support or contradict your
hypothesis.
My Notes:
Correlation:
• The main task of correlation is the
Timeline
establishment of a unified timeline.
Unification
My Notes:
Correlation:
• Verify events by checking each log entry
Event
for another recording of the same event
Verification
from other sources.
My Notes:
Correlation:
• The dates/times for events verified against
Using Event
multiple sources can also be compared to
Verification to
see if there is a time skew between the data
Synchronize
sources.
Times
My Notes:
Lead Tracking
• In addition to your investigative notes,
leads should be recorded in your Attribute
List spreadsheet along with other relevant
data.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
107
NITRO
This page intentionally left blank.
108
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Module 13 - Log Sources
Overview
Knowing where the logs of interest reside on a system is a key
piece of information when starting a network investigation. This
module will show you some of the typical locations of logs for
select applications and systems.
Objectives
• Describe the storage locations of typical log files
• Be able to discuss some of the log file formats
• Be able to recognize IDS logs and their contents.
In this Module
Here are the lessons in this module:
Lesson
See Page
Lesson 1 - Windows Log Sources
110
Lesson 2 - Linux Log Sources
113
Lesson 3 - Solaris Log Sources
115
Lesson 4 - Log Searching
117
Lesson 5 - IDS Logs
119
5-2008
For Official Use Only - Law Enforcement Sensitive
109
NITRO
Lesson 1 - Windows Log Sources
Lesson 1:
This lesson will cover the most common logs found in a Windows
Windows Log
environment.
Sources
Lesson 1 Learning
• Know where Windows Logs are stored
Objectives
• Understand naming conventions of log files
• Know some of the file formats for these files
110
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Windows Logs
• Mail - Outlook or Outlook Express as a
mail client
• Default log files in Windows 2000, Server
2003 and XP inside each user’s profile
• Outlook’s MAPI accounts, found at:
C:\Documents and Settings\username\Local
Settings\Temp\Opmlog.log
• If user established Hotmail account in
Outlook, events logged in: C:\Documents and
Settings\username\Local
Settings\Temp\Outlook
Logging\Hotmail\http0.log.
• Microsoft SQL Databases - stores its log
files in C:\MSSQL\LOG
• ERRORLOG
• SQLAGENT.OUT
• SQLDump9999.txt/SQLDump9999.mdmp
• MySQL - free, open source database
application that is also popular on many
Windows systems
• Default location for installation of MySQL
C:\Program Files\MySQL\MySQL Server X.X
• Cover subdirectories under this
•
• Microsoft Access - Errors in Windows
Event log
•
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
111
NITRO
Lesson 1 Topics, Continued
Topic
Key Points
Windows Logs,
•
Internet Information Server (IIS)
Continued
•
Service used by Windows based servers to
host web, FTP, and e-mail services
•
Depending on version, logs found in
different locations
•
IIS versions 4 and 5, on Windows NT 4.0
and Windows 2000, log files stored in:
C:\winnt\system32\logfiles
•
IIS version 6 and 7, on Windows XP and
newer systems, log files stored in:
C:\windows\system32\logfiles
•
Log file names will be named “W3SVC”
•
FTP and DNS messages mingled in same
file if services active
•
System Logs
•
Application, Security and System
•
Use Event Viewer to view
•
Logs can be exported
•
•
Directory Services
•
Events will be in Event Viewer in
Directory Services
•
Remote Logs
My Notes:
112
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 - Linux Log Sources
Lesson 2: Linux
This lesson will cover the common and most used logs found in a
Log Sources
Linux environment.
Lesson 2 Learning
• Know where Linux Logs are stored
Objectives
• Understand naming conventions of log files
• Know some of the file formats for these files
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Linux Logs
•
Mail Logs
•
Mail services provided by sendmail
processes
•
Logs for these services can usually be
found in the file: /var/log/maillog
•
Databases
•
MySQL most popular database program in
Linux
•
Logs typically be found in
/var/log/mysqld.log file
•
Services
•
Show the log files here, bringing up live
examples on a demo session.
•
Directory Management
•
Third party add-on tools provide service
•
Seek documentation for specific AD tool
and determine location of logs for each
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
113
NITRO
Lesson 2 Topics, Continued
Topic
Key Points
Linux Logs,
• System Logs
Continued
• Most Linux system log entries are located
in /var/log/message file
• Remote Logs
My Notes:
114
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 3 - Solaris Log Sources
Lesson 3: Solaris
This lesson will cover the common and most used logs found in a
Log Sources
Solaris environment.
Lesson 3 Learning
• Know where Solaris Logs are stored
Objectives
• Understand naming conventions of log files
• Know some of the file formats for these files
5-2008
For Official Use Only - Law Enforcement Sensitive
115
NITRO
Lesson 3 Topics
Here are the topics to present.
Topic
Key Points
Solaris Logs
• Mail
• May find file in /etc directory called
syslog.conf, and it may have the location of
sendmail logs listed inside
• Databases
• Logs in default locations of either
/usr/local/mysql/data or /opt/mysql/mysql/data.
•
Services
•
Most services put log messages in
/var/adm/messages log file, general catch
all file for log entries in Solaris
•
Directory Management
•
Third party add-on tools available
providing this service
•
Seek documentation for specific AD tool
•
System
•
System log files will be located in /var
directory in Solaris
•
Usually several nested directories of log
files under /var directory
•
Cannot open files in use
•
Remote Logs
•
Search for pipes and hard links to mounted
volumes in order to discover whether logs
are being stored remotely on Solaris
My Notes:
116
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 4 - Log Searching
Lesson 4: Log
This lesson will cover several ways to manually search through a
Searching
log file.
Lesson 4 Learning
• Know how to use the findstr command
Objectives
• Know how to use Grep/Egrep
• Understand the basics of regular expressions
Lesson 4 Topics
Here are the topics to present.
Topic
Key Points
Log Searching
•
Flexibility is most important feature for
any tool used
•
Variety of log files require search for
different types of values
•
GREP / EGREP - Primary applications
used for searching and filtering text logs
•
Many advanced functions only work in
egrep, not in grep, so egrep is standard
•
Regular expressions are most common
method for defining search parameters,
used in many other popular applications,
such as PERL, Snort, and EnCase
•
Typically found in just Unix, Linux, and
OS X environments
•
Versions available for the Windows
•
FINDSTR
•
Windows equivalent of Grep
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
117
NITRO
Lesson 4 Topics, Continued
Topic
Key Points
Regular
•
Patterns used for executing searches and
Expressions
filters
•
Combining literal text and special
characters, called metacharacters, to create
a pattern
•
Provide examples of items that use set
patterns:
•
IP addresses
•
Dates and time
•
Phone numbers
•
URLs
•
Credit card numbers
•
Social Security numbers
•
Literal Character Searches - Simplest
type of regular expression
•
Grep is much more powerful than what is
presented here, but keep information very
light unless the class is technically
advanced. If so, bring up “* . ^”,
metacharacters as an introduction.
My Notes:
118
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 5 - IDS Logs
Lesson 5: IDS
This lesson will cover Intrusion Detection System logs
Logs
Lesson 5 Learning
• Understand the importance of IDS logs
Objectives
• Understand how Snort is used
Lesson 5 Topics
Here are the topics to present.
Topic
Key Points
IDS Logs
•
Intrusion Detection Systems prolific, found
in many networked environments
•
Most logs generated are binary rather than
text files
•
May have to use proprietary program to
view or convert the file to text
•
Some IDS save logs in libpcap format, you
can use packet sniffer tools like Wireshark
to open, view and export these files as
needed
•
Snort
•
Popular IDS and intrusion reporting tool
•
Allows administrators to flag alerts on both
live traffic and traffic captured with packet
sniffer
•
Will generate a text log displaying all alerts
of suspicious traffic it encountered
•
Requires complex set of steps to configure
properly, configuration will change with
each type of log or capture
•
By default, all of Snort’s log files on a
Linux, Unix, or OS X system will be found
in: /var/log/snort
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
119
NITRO
This page intentionally left blank.
120
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Module 14 - Log Analysis
Overview
Log data must not only be found, but properly formatted and
assembled into reports. Log entries can be used directly as items of
evidence, or assembled into other forms of data, such as statistics,
charts, graphs, and other representations.
Objectives
• Generate statistics from log data
• Format log data into report-friendly formats
• Form visual charts and graphs with log data
In this Module
Here are the lessons in this module:
Lesson
See Page
Lesson 1 - Binary Traffic Analysis
122
Lesson 2 - Manual Log Analysis
126
Lesson 3 - Automated Log Analysis Tools
128
Sawmill
5-2008
For Official Use Only - Law Enforcement Sensitive
121
NITRO
Lesson 1 - Binary Traffic Analysis
Lesson 1: Binary
Binary logs require different filtering and searching techniques
Traffic Analysis
than those that are used with text logs. Due to the size of binary
logs and their required processing power, it is often more efficient
to filter binary network captures with command line tools
Lesson 1 Learning
• Describe the types of criteria that can be used to filter binary
Objectives
logs
• Convert binary logs to text files
• Understand how to filter and search binary logs with
Wireshark
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Introduction to
•
Powerful, open source protocol analyzer,
Wireshark
can be used to view full network traffic
capture logs
•
Open a variety of binary log formats
•
Act as a sniffer
•
Translate, or decode, known protocols
within a binary log to human readable
format
•
Display highly detailed information on a
frame-by-frame basis
•
Search through a capture log for frames
that match specific criteria
•
Automatically reconstruct TCP sessions
•
Walk through procedure for importing logs
•
Walk through procedure for viewing binary
logs
My Notes:
122
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 Topics, continued
Topic
Key Points
Converting
• Discuss binary vs. text and converting
Binary Logs to
binary to text
Text Format
My Notes:
Filtering and
• Discuss filtering in Wireshark
Searching in
• Capture filters
Wireshark
• Display filters
• Color filters
• Find menu
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
123
NITRO
Lesson 1 Topics, Continued
Topic
Key Points
Filtering and
• Walk through procedure for setting up a
Searching in
capture filter
Wireshark,
• Walk through procedure for creating a
continued
display filter
• Discuss creating a display filter for a
keyword
• Discuss creating display filter for a hex
value
• Discuss directly entering display filter
expressions
• Review syntax of display filters
• Discuss altering and combining
expressions
My Notes:
Colorizing Data
• Walk through procedure for creating a
Using Filters in
color filter
Wireshark
• Walk through procedure for searching in
Wireshark
My Notes:
Generating
• Discuss Statistics Menu
Statistics with
• Discuss Endpoints List
Wireshark
• Discuss Protocol Hierarchy Statistics
• Discuss Conversations List
• Discuss HTTP Requests Stats Tree
My Notes:
124
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 Topics, Continued
Topic
Key Points
Exporting Data
• Discuss Exporting Statistics from
from Wireshark
Wireshark
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
125
NITRO
Lesson 2 - Manual Log Analysis
Lesson 2: Manual For those times when automated tools for log analysis are not
Log Analysis
readily available, we will now look at ways to manually examine
and search log files for evidentiary information.
Lesson 2 Learning
• Understand how to build keyword lists for searching
Objectives
• Know how to execute simple searches using EGREP
• Understand the basic concept of correlation of data.
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Filtering and
• Identify all log entries with a specific value
Searching Text
or range of values
Logs
• Modify view of one or more log files based
upon existence of an arbitrarily defined
parameter
• Flexibility is important feature of tools
• Will encounter wide variety of log files that
require search for different types of values
My Notes:
Regular
• Discuss GREP / EGREP
Expressions
• Regular expressions common method for
defining search parameters, used in
applications, such as PERL, Snort, and
EnCase
My Notes:
126
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Deciding What
• Keywords
to Search For
• Rarely will a ‘shotgun’ or broad focused
search turn up useable data
• Decide on keywords that might be
available in logs and possibly locate
artifacts of intrusion
• Sample keywords for intrusion:
o
“Error” or “err”
o
“Overflow”
o
“Password” or “Pass”
o
“Admin”
o
“Unauthorized”
o IP addresses of interest
My Notes:
Example Log
• Walkthrough and discuss example log is
text
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
127
NITRO
Lesson 3 - Automated Log Analysis Tools
Lesson 3:
There are not many automated tools that allow you to search log
Automated Log
files. Most require complex programming and setup prior to use.
Analysis Tools
We will now look at one of the better tools on the market -
Sawmill.
Lesson 3 Learning
• Install and configure the Sawmill program.
Objectives
• Describe the function and use of the Sawmill program
Lesson 3 Topics
Here are the topics to present.
Topic
Key Points
What is
• Sawmill is a tool that will assist analyst in
Sawmill?
parsing network text logs and organizing
logs into an easy-to-read report
• Can process various text logs generated by
a variety of network security devices
• Converts text log to a cross-linked report
that allows analyst to customize report
according to output requirements
• Can be purchased and downloaded from
My Notes:
Installing
• Walkthrough procedure for installing and
Sawmill
configuring
My Notes:
128
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 3 Topics, continued
Topic
Key Points
Network Log
• Discuss The Administrative Interface
Analysis Using
• Walkthrough procedure for creating a
Sawmill
report profile
• Discuss the Report Environment
• Discuss the Report Header
• Discuss the Report Toolbar
• Discuss Report Menu
• Discuss Zoom To Filters
• Discuss Final Output Report (Log Detail)
• Discuss Single Page Summary
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
129
NITRO
This page intentionally left blank.
130
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Module 15 - Live Data Collection and Analysis
Module 15
Collecting live data from a system can uncover critically valuable
Overview
information for an investigation due to the fact that volatile data is
lost once the system is shut down. This module will guide you
through using LiveWire tools to collect and analyze the volatile
data on a remote system.
Module 15
This module contains exercises in this manual to be walked
Exercises
through with the instructor As well as those for the students to go
through themselves.
• XP-Pro-LiveWire-CookBook - Walkthrough in book
• Carly Sizemore - Practical and test to help prepare for final
• Alt tools Cookbook - Walkthrough and test
• Alt tools Carly Sizemore - Walkthrough and test
• Final Practicals - Set of three practical and tests
Module 15 Testing This module is tested. The testing will include investigating 3
VMware images wish LiveWire along with multiple choice
questions. A question pool of 30 questions per image has been
provided for the instructor to create tests from as they see fit.
Module 15
• Properly prepare for a live digital investigation.
Objectives
• Use live digital investigation tools introduced in this module.
In this Module
The following table shows the contents of this module.
Topic
See Page
Lesson 1 - Data Collection
133
Lesson 2 - Introduction to LiveWire
135
Lesson 3 - Network Mapping
137
Lesson 4 - Volatile Data Analysis
138
Lesson 5 - Evidence Collection
141
Lesson 6 - Malicious Code Analysis
144
Lesson 7 - Alternate Data Collection Tools
146
5-2008
For Official Use Only - Law Enforcement Sensitive
131
NITRO
Module 15 Exercise Configuration Details
Module 15 Exercise Details
VM Image:
XP-Pro-LiveWire-CookBook
VM Snapshots:
Anarchy CookBook - truecrypt
Description:
This virtual machine will be used throughout this module. Each
exercise builds off of the previous exercises. The VM should be run
at the specified snapshot to load the artifacts into memory that will be
discovered by the students.
This Virtual Machine has the Anarchy CookBook Chapter 2 - Credit
Card Fraud opened in open office. This document is stored in a
truecrypt volume.
Summary of Artifacts to be Discovered During This Module
Running processes:
truecrypt, open office writer
Document Open:
M:\anarchycookbook - credit card fraud.doc
TrueCrypt Volume:
My Documents\sweet-success.avi
Suspect images:
Located in My Pictures
Recent Documents:
shows files from M:\ and My Documents
Target VMWare Configurations
Computer Name:
HellRaiser
Operating System:
Windows XP SP2
IP Address:
10.15.4.210
Subnet Mask:
255.255.255.0
Administrator U/N:
Admin
Administrator P/W:
password
Target U/N:
Student
Target P/W
password
TrueCrypt Volume:
My Documents\sweet-success.avi
TrueCrypt Volume P/W:
anarchy
132
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 - Data Collection
Lesson 1: Data
When collecting data for any investigation it’s vital that the data
Collection
collection is conducted correctly.
Lesson 1 Learning
• Discuss locating physical devices in a network environment
Objectives
• Discuss collecting data for forensically clean media
Lesson 1: VMware
Throughout this module, each student will have his/her own
Setup
VMware image loaded and running on the server. Each group of 4
students will be assigned a number 1 through 4 that will
correspond with the last number of the IP address for the target
machine. IP address 10.15.4.211 will be the target machine for
student 1, IP address 10.15.4.212 will be the target machine for
student 2. etc. Therefore, there will be 4 different VMware images
for each exercise that is outlined in this instructor guide.
Cookbook VMware image - Load the snapshot named “Anarchy
CookBook - truecrypt”.
To load the correct image for the exercise in the book:
Open the Windows XP Pro CookBook VMware image.
On the task bar select VM > Snapshot > Anarchy CookBook -
truecrypt”.
NOTE: This snapshot will be used throughout this module for
students to extract investigative information.
The more students that are hitting the same machine, the slower it
will respond. Therefore, some actions should be expected to take
longer than others depending on the number of users extracting
data simultaneously.
5-2008
For Official Use Only - Law Enforcement Sensitive
133
NITRO
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Locating
• Explain that there is a difference in logical
Physical Devices
and physical topologies.
• Explain that logical topologies are used to
show the flow of data over a network.
• Explain that physical topologies are used to
show how devices are physically connected
to other network components.
• Explain that a tone generator can be used to
help trace network cables.
• Network/systems administrator may be a
point of contact to interview but his
answers must be verified.
• Explain that all findings should be
recorded.
My Notes:
Attaching
•
.Explain that captured evidence may be
Storage
extremely large.
Equipment
• The investigator must ensure that there is
enough hard drive space necessary to store
the data on.
• Investigations require that evidence is
stored on forensically clean media.
• Storage media should be wiped and
verified before use.
• Review wiping guidelines section
My Notes:
134
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 - Introduction to LiveWire
Lesson 2:
In this lesson, the students will be introduced to LiveWire. The
Introduction to
software will be correctly installed and configured.
LiveWire
Lesson 2 Learning
• Explain the basic concepts of live digital investigations
Objectives
• Successfully install, update, and setup LiveWire.
• Successfully install and update LiveDiscover
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Live Digital
• Live digital investigations are performed
Investigations
on systems that are currently active with
running processes.
• Live systems are constantly changing.
• Live investigations allow the investigator
to capture, view, and monitor the current
system activities in real time.
• LiveWire requires an administrative
account to retrieve data from the system.
• LiveWire uses Connect-Act-Disconnect.
• Be aware of the possibility that a
knowledgeable user could become aware of
the system being investigated.
• Discuss workstation requirements
My Notes:
LiveWire
• Walk through installing LiveWire onto the
Installation
workstation.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
135
NITRO
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
LiveDiscover
• Walk through installing LiveDiscover onto
Installation
the workstation.
My Notes:
Updating
• Walk through installing updating
LiveWire
LiveWire.
My Notes:
Updating
• Walk through updating LiveDiscover.
LiveDiscover
My Notes:
LiveWire Initial
• Walk through the initial setup of LiveWire
Setup
to prepare the system for investigations.
• The default LiveWire Administrator
account password must be changed.
• Passwords require number and digits.
• An investigator account must be created to
perform investigations.
My Notes:
136
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 3 - LiveDiscover
Lesson 3:
In this lesson, we will talk about finding the devices on the
LiveDiscover
network so they can be examined.
Lesson 3 Learning
• Describe important functions of LiveDiscover
Objectives
• Effectively scan a network for devices
• Effectively identify devices found on the network
Lesson 3 Topics
Here are the topics to present.
Topic
Key Points
LiveDiscover
• LiveDiscover will be used to find XP SP2
Network
at IP 10.15.4.210
Scanning
• Data from LiveDiscover can be used with
LiveWire to perform analyses.
• LiveDiscover can quickly scan ranges of IP
addresses.
• Data is stored in a database.
• Discuss the different tabs available.
• Perform a scan to find the system that will
be investigated in later exercises.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
137
NITRO
Lesson 4 - Volatile Data Analysis
Lesson 4: Volatile In this lesson, we will perform the initial inquiry of the suspect
Data Analysis
system to retrieve begin the volatile data analysis.
Lesson 4 Learning
• Conduct an initial inquiry.
Objectives
• View the current open files on the system.
• View the current network connections and configurations.
• Image RAM over the network.
Lesson 4 Topics
Here are the topics to present.
Topic
Key Points
LiveWire Initial
• Walk through the initial inquiry as in the
Inquiry
book.
• IP 10.4.15.210
• Username: Admin
• Password: password
• Make the point that live systems are
constantly changing and the investigator
must be aware of this.
• Initial inquiries and other actives may
impact the performance of the suspect
system.
• Point out that data should always be saved
to forensically clean media, but these
lessons will use the default local directory
for instructional purposes only.
• Discuss that the information used to
perform the investigation was discovered
during the LiveDiscover section.
My Notes:
138
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 4 Topics, continued
Topic
Key Points
System State
• Go over the exercise in the student book.
• View the initial inquiry information and
discuss how this information can be
important to the investigation.
• Acquire the physical RAM
• Many factors impact the speed of the RAM
imaging process.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
139
|
||
|
|
|