Network Intrusions Responder Program (NITRO). Instructor Guide - page 2

 

  Index      Manuals     Network Intrusions Responder Program (NITRO). Instructor Guide

 

Search            copyright infringement  

 

   

 

   

 

Content      ..      1      2      3      ..

 

 

 

Network Intrusions Responder Program (NITRO). Instructor Guide - page 2

 

 

NITRO
Lesson 10 - Terrorism
Lesson 10:
Historical accounts vary but it is generally agreed that terrorism
Terrorism
has been on the Internet years before the attacks of September 11th.
Any time that the Internet is used by a person or group to
intimidate and instill fear in others, it is called terrorism.
Lesson 10
Describe some of the common Terrorist Attacks
Learning
Discuss the methodologies used in these cases
Objectives
Describe some of the responses to these attacks
Lesson 10 Topics
Here are the topics to present.
Topic
Key Points
Internet Terrorist
Terrorism
Methodologies
Fear
Intimidation:
Psychological warfare
Propaganda
Fund-raising
Message center for coordinating activities
Launch network attacks
Data mining
Denial of Service attacks against enemies
Site defacements of web sites counter to
their cause
Spam e-mail attacks against enemies
Phishing attacks for banking information to
help fund activities
My Notes:
Investigative
Capture
Response
Preservation
Warrants
Reporting
Education
My Notes:
70
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Module 9 - Phases of an Intrusion
Module 9
In order to understand how network intrusions happen you need
Overview
the understanding of the phases which occur as the attacker plans
and then executes the intrusion. This module illustrates those
phases in depth.
Module 9
None, other than the procedures in the manual.
Exercises
Module 9 Testing This module is not tested.
Module 9
Define network intrusions.
Objectives
Understand the phases of an intrusion
Understand the information that an attacker can gather offline
Understand the goals, strategies and techniques employed by
the attacker.
Know attacker profiles
In this Module
The following table shows the contents of this module.
Topic
See Page
Lesson 1 - Defining an Intrusion
72
Lesson 2 - Reconnaissance
73
Lesson 3 - Network Attacks
76
Lesson 4 - Entrenchment
78
Lesson 5 - Infiltration and Extraction
80
5-2008
For Official Use Only - Law Enforcement Sensitive
71
NITRO
Lesson 1 - Defining an Intrusion
Lesson 1: Defining Technically complex network intrusions can be difficult to
an Intrusion
identify. To do so you need to understand how intruders conduct
these attacks.
Lesson 1 Learning
Define Network Intrusion
Objectives
Discuss the vulnerabilities attackers look for in a target
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Intrusions
Explain the definition of Intrusion,
Vulnerability, Exploit and Threats or
Threat Agents.
Explain the goals of the intrusion and how
they can be combined in several ways.
Explain the types of intruders and their
profiles.
Touch on how insiders are the largest threat
to any system.
Describe the phases of an intrusion.
Mention how once the attack has succeed
the phases will start again from the inside
and propagate throughout the internal
network.
My Notes:
72
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 - Reconnaissance
Lesson 2:
In this lesson, the topic of how an attacker will do research on the
Reconnaissance
system and resources to better understand the target.
Lesson 2 Learning
Explain the purposes and methods of reconnaissance.
Objectives
Explain the difference between direct and indirect methods
Describe some specific tools and techniques used
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Goals
Discuss the information gathering mindset
and methodologies.
Describe the types of data that are searched
for and used.
My Notes:
Direct vs.
Describe how direct actions can be logged
Indirect
by the target, but indirect actions are not.
My Notes:
General Web
Explain how site administrators will
Browsing
inadvertently leave information on a site
that can be used by attackers.
My Notes:
Public Records
Discuss the amounts of information that is
available from public data repositories.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
73
NITRO
Lesson 2 Topics, continued
Topic
Key Points
DNS & Whois
Show how the information in a DNS entry
can be a wealth of information to an
attacker.
My Notes:
The Wayback
Show how the archive site can display
Machine
information that has been removed from a
site but is still available from an archive
copy.
My Notes:
Other sources
Cover the other misc sources of
information that may be available to
attackers.
My Notes:
Target site
Discuss how the source code and
Examination
information on all the pages of a target site
can be examined freely.
My Notes:
74
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 Topics, continued
Topic
Key Points
Attack vectors
Show how any way into a system that has
been discovered is a possible vector.
Modems, faxes, telephone systems and any
other in-route is a possible target of
opportunity.
Wireless is a popular attack vector because
of the many weaknesses in that area.
My Notes:
Identification
Any information that is in a packet of data
Live Host
coming from the host is used.
information
Probing these areas will potentially give
information to the attacker.
Any open port or protocol will be
discovered and probed.
Banners and other identifiers will be
gathered and used to determine versions
and known weaknesses.
My Notes:
Vulnerability
The same scanning tools that system
scans
administrators use to harden a system are
used by the attackers
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
75
NITRO
Lesson 3 - Network Attacks
Lesson 3: Network In this lesson, we look at the attack phase of an intrusion
Attacks
Lesson 3 Learning
Explain the goals of the attack
Objectives
List the major strategies used in an attack
Understand some of the techniques an attacker can use to
damage the functionality of a system or network
Lesson 3 Topics
Here are the topics to present.
Topic
Key Points
Goals
Discuss how the attacker wants to gain a
foothold and advance his presence on the
target
My Notes:
Authentication
Discuss how authentication attacking
and Guessing
works.
Talk about the many types of guessing and
cracking tools there are.
Note that there are all types of value
metrics used to generate an attack.
Credential discovery and reset techniques
should be covered
My Notes:
76
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 3 Topics
Here are the topics to present.
Topic
Key Points
Identification
Any information that is in a packet of data
Live Host
coming from the host is used.
information
Probing these areas will potentially give
information to the attacker.
Any open port or protocol will be
discovered and probed.
Banners and other identifiers will be
gathered and used to determine versions
and known weaknesses.
My Notes:
Input attacks
Discuss how using too much input or
incorrect input the system can be brought
to a stop or exploited
SQL injection attacks are popular and
effective. Describe them
Directory traversal is another popular
attack type.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
77
NITRO
Lesson 4 - Entrenchment
Lesson 4:
In this lesson, we look at the entrenchment phase of an intrusion
Entrenchment
Lesson 4 Learning
Explain the goals of entrenchment
Objectives
List the major strategies used
Understand some of the techniques an attacker can use to hide
traces of unauthorized activity
Lesson 4 Topics
Here are the topics to present.
Topic
Key Points
Goals
Discuss how the attacker wants to preserve
his presence on the exploited system.
My Notes:
Log Cleaning
Explain how the attacker will remove
traces of his presence on the system.
My Notes:
Automatic
The attacker will setup programs to run on
execution
system startup to ensure his continued
access.
My Notes:
78
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 4 Topics, continued
Topic
Key Points
Hooking
Discuss how the attacker will attach
programs to other programs to hide his
work.
My Notes:
File types and
Show how the attacker will change file
naming
extensions and names to obfuscate his use
conventions
of known attacker tools.
My Notes:
Remote
Explain how the attacker will use remote
connections and
connectivity and backdoor programs to
Backdoors
make use of the system easier.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
79
NITRO
Lesson 5 - Infiltration and Extraction
Lesson 5:
In this lesson, we look at the infiltration and extraction phase of an
Infiltration and
intrusion
Extraction
Lesson 5 Learning
Explain the purpose and methods of inflitration
Objectives
Explain the importance of trust relationships
Determine the data types targeted by attackers and how these
types are extracted.
Lesson 5 Topics
Here are the topics to present.
Topic
Key Points
Sniffers
Describe how once the attacker is on the
system he uses it as a springboard to repeat
the phases of an intrusion on other nearby
systems.
Show how sniffing of the target network is
beneficial to the attacker.
My Notes:
Trust
Explain how dangerous these relationships
Relationships
are once the attacker is on the network.
My Notes:
Data Extraction
Discuss the types of data the attacker is
interested in and how it is typically
transferred.
My Notes:
80
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
This page intentionally left blank.
5-2008
For Official Use Only - Law Enforcement Sensitive
81
NITRO
Module 10 - Report Writing
Module 10
Investigations require comprehensive reporting that documents
Overview
actions and summarizes findings. The best reports are clear,
concise, and accurate and report only information relevant to the
facts of the case.
Objectives
Discuss the importance of writing an organized, clear, concise
and accurate report
Write an organized, clear, concise, and accurate report
Discuss the appropriate interviewing techniques for conducting
investigations in a highly technical environment
In this Module
The following table shows the contents of this module:
Topic
See Page
Lesson 1 - General Report Writing Techniques
83
Lesson 2 - Cyber Case Interviewing Techniques
89
82
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 - General Report Writing Techniques
Lesson 1: General
Forensic reports involving the analysis of digital evidence should
Report Writing
address the same basic information. No matter how well an
Techniques
investigator conducts analysis, it is of little value if results cannot
be reported in an organized, clear, complete and concise manner.
Lesson 1 Learning
Discusses the purpose and need for forensic analysis
Objectives
Explains what physical and/or logical evidence was analyzed
Defines programs, terms, and their relevance
Explains findings in an orderly manner
Associates relevant evidence with users
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
The Forensic
Culmination of a process often involving
Report
intensive and painstaking work
Should reflect the time, effort and
professionalism involved in building the
case and acquiring the information
Should be well organized, include only
relevant information, and be free of
grammatical, punctuation and spelling
errors
Recipient should be able to read it one
time and have a very clear understanding
of the message you are trying to convey
Consider the report a reflection of your
professionalism and develop it as such
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
83
NITRO
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Examiner Notes
Documentation that is created during the
analysis process provides basis for
examiner to report results of case
Should be preserved and may be
discoverable in court
Foundation on which many digital
media-related cases are built
Should present a clear timeline of the
actions taken and the results of those
actions
Provide a repeatable roadmap of your
examination
Number, date, and initial all note pages
Ensure that you can accurately testify to
actions taken during the examination
My Notes:
84
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 Topics, Continued
Topic
Key Points
Forensic Reporting
Should contain all relevant evidence
found during examination
Clearly identify persons related to
examination including you, requestor,
suspects, and other pertinent individuals
Provide details about purpose for forensic
analysis
Describe physical and/or logical evidence
analyzed
Define related programs, terms and their
relevance
Clearly and concisely explain items of
evidentiary value found on suspect media
as a result of analysis
Identify location and relevance of items
of evidentiary value as relating to reason
for analysis and/or investigation
Report heading
Support requested, reason or purpose for
analysis
Summary of findings
Digital media analyzed
Analysis/Suspect Software Listings
Glossary of Technical Terms
Detail of Findings
Items Provided
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
85
NITRO
Lesson 1 Topics, Continued
Title Page
Provides an overview of the case
Report Header
Support Requested
Current Case Status
Summary of Findings
Title (To:)
From
Subject
Support Requested or Purpose for
Analysis
Status
Summary of Findings
Footer
My Notes:
Items Analyzed
Describes in detail analyzed physical
and/or logical evidence
Always include original and verified
hash values of all evidence items
Physical Items:
Manufacturer
Model, serial, and part number (when
possible)
Item description
Any specific markings
Logical Items:
List the image files
Original file name and include any hash
or other validation mechanism
My Notes:
86
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 Topics, Continued
Topic
Key Points
Relevant Software
Identifies software found on evidence
media relevant to case as well as identity
of forensic software used to perform
analysis
Analysis Software
List all software applications used during
the forensic examination
Version and brief description of
software’s functionality or use
Suspect Software
Software name and version
Full path to where application located on
suspect media
Brief description of program
functionality and how it relates to
Request for Analysis and/or investigation
Be prepared to further explain items in
this listing during prosecution
My Notes:
Glossary
Defines technical terms, document
formats, and procedure details referenced
in report that may not be readily
understood by average non-technical
reader
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
87
NITRO
Lesson 1 Topics, Continued
Topic
Key Points
Details of Findings
Provides detailed information about any
items of evidentiary value found on
suspect media during forensic
examination
Should be thorough, concise, only
contain details relevant to request for
analysis and/or investigation
Should not contain information about
processes executed that did not produce
relevant information, unless negative
result is relevant
Discuss organization
Discuss use of hyperlinks
My Notes:
Items provided
Details all of physical items returned to
requestor with report
Should include all items specified in
Items Analyzed section
My Notes:
Reporting scenario
Discuss example and how it incorporates
information discussed in lesson
My Notes:
88
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 - Cyber Case Interviewing Techniques
Lesson 2: Cyber
Interviews are an essential element of developing information that
Case Interviewing
is relevant to a criminal investigation. When conducting a cyber
Techniques
crime investigation, investigators must prepare for the interview,
develop rapport with interview subjects, ask questions that
generate corroborative information and leads, and terminate the
interview in a way that leaves the door open for further questions.
Lesson 2 Learning
Develop a plan to conduct interviews in a cyber investigation
Objectives
Explain the psychology and culture of the technology world
and
ways to apply that knowledge to the interview process
Ask questions that will provide you with information that will
assist the investigation
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Cyber Crime
Investigator must obtain information
Interviews
from all people who are involved with the
incident.
Interview of a suspect may assist in
revealing true scope of investigation and
provide information needed to ensure
conviction of a suspect
Integral part of any investigation,
victims, witnesses, and perpetrators all have
pieces of puzzle that investigator is trying to
put back together
Investigator must skillfully navigate
human landscape to develop leads, confirm
events, and obtain complete picture of crime
Accusatory versus Non-Accusatory
Interviews
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
89
NITRO
Lesson 2 Topics, continued
Topic
Key Points
Interview Process
Planning/Research
Opening/Rapport
General Questioning
Detailed Questioning
Interview Termination
Interview Psychology
Investigator Initiated Contact
Organization Initiated Contact
Witness and Victims
Issues to Address During Interviews
Suspects
My Notes:
90
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
This page intentionally left blank.
5-2008
For Official Use Only - Law Enforcement Sensitive
91
NITRO
Module 11 - Legal Issues
Overview
No matter how solid a case may be or incriminating the evidence,
all computer crime investigations must be conducted in way that
adheres to established legal principles. If legal standards are not
met the case could be jeopardized and even dismissed, thus
allowing a perpetrator to walk free.
Purpose of this
The purpose of this module is to familiarize students with some of
Module
the basic legal issues that must be considered when conducting an
investigation involving digital data.
Objectives
After successfully completing this module, you will be able to:
Understand some of the legal issues involved in a digital
investigation
Employ practices during an investigation that that will pass
legal challenge
In this Module
The following table shows the contents of this module:
Topic
See Page
Lesson 1 - Search Warrants
93
Lesson 2 - ISP’s
95
92
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 - Search Warrants
Lesson 1: Search
Searches of an individual or a location require a search warrant or
Warrants
a valid exception under the 4th Amendment to the U.S.
Constitution
Lesson 1 Learning
Understand how the 4th amendment of the United States
Objectives
Constitution is interpreted by the Courts
Recognize situations in which the investigators may search or
seize without a warrant
Discuss the types of consent and their requirements
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Search Warrants
4th Amendment Overview
What is an unreasonable search
Probable Cause
Affidavit
Items to be Seized
USDOJ-CCIPS
Warrant Execution
My Notes:
Search Warrant
Consent
Exceptions
Stop and Frisk
Search Incident to Arrest
Immediate threat to life or serious bodily
injury
Immediate threat of the destruction of
evidence
Fresh pursuit
Plain view
Vehicle searches
Custodial searches
Border searches
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
93
NITRO
Lesson 1 Topics, Continued
Topic
Key Points
Consent
Voluntary Consent
Searches
Informed Consent
Withholding Consent
Withdrawing Consent
3rd Party Consent
My Notes:
Stop and Frisk
May not seem applicable to digital
Searches
investigations
If cell phone, PDA or other digital device
found during search you may request
consent to browse text messages
My Notes:
Search Incident
Again, may not seem applicable to digital
to Arrest
investigations
If cell phone, PDA or other digital device
found during search you may request
consent to browse text messages
My Notes:
94
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 - Internet Service Providers
Lesson 2: ISP’s
Many crimes involve the use of commercial and private networks
and communications facilities. These records are usually
maintained by entities often referred to as Internet Service
Providers (ISPs). ISPs often maintain records of accounts, billing,
transactions, and content of the communications and data that
travel over their networks.
During an investigation, you will need to gather this pertinent
information from ISPs. It is imperative that an investigator
understands the proper way to request these records, so they are
admissible as evidence in a criminal proceeding.
Lesson 2
Explain which laws apply to a given authority and know where
Objectives
to find those laws
Describe the search authorities for gathering records
Prepare requests for records
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Legal
ECPA
Framework
Consent
Express Consent
Written Consent
3rd Party Consent
My Notes:
Preservation
18 USC § 2703(f)
letters
Time Limitations
Limitations (Snapshot at time of receipt)
One renewal for additional 90 days
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
95
NITRO
Lesson 2 Topics, Continued
Subpoenas
Business Records
Testimony
Subscriber Records
My Notes:
”D” Order
18 U.S.C. § 2703(d)
Transactional Records
Content
Reasonable Grounds and Relevant
My Notes:
96
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
This page intentionally left blank.
5-2008
For Official Use Only - Law Enforcement Sensitive
97
NITRO
Module 12 - Fundamentals of Log Analysis
Module 12
The analysis of computer network intrusions is a difficult task. The
Overview
Scientific Method provides a general framework that can be used
to effectively guide the investigation.
Module 12
None, other than the procedures in the manual.
Exercises
Module 12 Testing This module is not tested.
Module 12
Describe the main steps of the Scientific Method
Objectives
Explain how the Scientific Method can be applied to digital
forensic analysis
Use the initial observations in a case to determine the most
likely location of additional, related artifacts
Apply the analysis techniques learned in the previous modules
to analyze log files that contain evidence of an intrusion
In this Module
The following table shows the contents of this module.
Topic
See Page
Lesson 1 - The Scientific Method and Intrusion
99
Analysis
Lesson 2 - Observing Intrusion-related Activity
100
and Generating a Hypothesis
Lesson 3 - Predicting the Nature and Location of
103
Intrusion Artifacts
Lesson 4 - Using Log Analysis to Evaluate an
105
Intrusion Hypothesis
98
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 - The Scientific Method and Intrusion Analysis
Lesson 1: The
The Scientific Method is used as a guide for investigating any
Scientific Method
problem, including a network intrusion. It is a simple but effective
and Intrusion
process by which you generate a hypothesis based upon observed
Analysis
events, then design and select analysis tasks to help you evaluate
that hypothesis.
Lesson 1 Learning
Define the Scientific Method
Objectives
Explain how the Scientific Method can guide an intrusion
investigation.
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
The Scientific
Observation: Observing one or more events
Method
or sets of events. Observation establishes
the facts surrounding these events to
identify their cause and consequences.
Hypothesis: A hypothesis is generated that
explains the observed events, including
their root cause, interrelationship, and
consequences.
Prediction: Predictions are made as to the
possible nature and location of artifacts in
the evidence that will either support or
contradict the hypothesis.
Evaluation: Performing procedures that test
for the presence of artifacts that support,
falsify, or modify the hypothesis.
Conclusion: Formation of a conclusion,
based upon the results of tests performed
during the Evaluation step..
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
99
NITRO
Lesson 2 - Observing Intrusion Activity and Forming a Hypothesis
Lesson 2:
The first step of the Scientific Method applied to an intrusion is to
Observing
identify the current set of observations and form a hypothesis
Intrusion-related
based upon those observations.
Activity and
Forming a
Hypothesis
Lesson 2 Learning
Describe common intrusion-related observations
Objectives
Form a hypothesis
Describe common incident classifications
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Common
Discuss how network intrusion
Observations
investigations should normally begin with
one or more specific observations. These
observations guide the formation of a
hypothesis as to what may have occurred.
My Notes:
Common
Many different events can spark an intrusion
Primary
investigation. Some examples include:
Observations
Antivirus alerts
IDS/IPS alerts
System/applications errors
Abnormal authentication patterns
Access control list violations
Generic unusual activity
My Notes:
100
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 Topics, continued
Topic
Key Points
Supplementary
The incident responder should make
Observations
supplementary observations before creating
a hypothesis. Examples of this data are:
Network diagrams
Device documentation
Contact information
My Notes:
Common
Observations made during network
Observation
intrusions will have attributes that should
Attributes
be recorded. These attributes include, but
are not limited to the following
Date/Time
IP Addresses
Port Numbers
Accounts and aliases
Host names and aliases
Files
General description.
My Notes:
Recording
Observations can be recorded in many
Observations
different forms including written notes,
office documents, and databases. You
should use the approved and tested method
used by your organization. This course uses
a spreadsheet template for recording this
data.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
101
NITRO
Lesson 2 Topics, continued
Topic
Key Points
Hypothesis
This hypothesis should include a statement
Formation
regarding each of the following
What/How
Where
Who
Why
My Notes:
Multiple
Cover the concept of breaking a large
Hypothesis
hypothesis into smaller sections and
proving each in turn.
My Notes:
Incident
Discuss the various classifications that
Classifications
incidents fall into including:
Denial of Service (DOS)
Malicious Code
Unauthorized Access
Inappropriate Usage
Suspicious Activity
Multiple Components
My Notes:
102
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 3 - Predicting the Nature & Location of Intrusion Artifacts
Lesson 3:
The purpose of this lesson is to teach you how to determine
Predicting the
potential locations of artifacts related to your hypothesis.
Nature and
Location of
Intrusion Artifacts
Lesson 3 Learning
Determine the applications and network traffic types that were
Objectives
involved in observed events
Determine the flow of network traffic related to observed
events
Predict artifact location based upon the network architecture,
probably traffic flow and related applications
Lesson 3 Topics,
Here are the topics to present.
Topic
Key Points
Finding Intrusion
Discuss the plan and mapping of artifacts
Artifacts
to make the evaluation of facts easier.
My Notes:
Relating
You need to correlate all observed events
Observed Events
to the applications involved. This will help
to Applications
you to locate potential artifacts.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
103
NITRO
Lesson 3 Topics,
Here are the topics to present.
Topic
Key Points
Identification
Any information that is in a packet of data
Live Host
coming from the host is used.
information
Probing these areas will potentially give
information to the attacker.
Any open port or protocol will be
discovered and probed.
Banners and other identifiers will be
gathered and used to determine versions
and known weaknesses.
My Notes:
Network Traffic
One simple way to identify devices that
Flow and
may contain relevant data is to locate all
Intrusion
devices that related traffic may have passed
Artifacts
through
My Notes:
Predicting
Discuss prediction of artifacts on:
Artifact Location
Devices
File
Directories
My Notes:
104
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 4 - Using Log Analysis to Evaluate and Intrusion Hypothesis
Lesson 4: Using
The purpose of this lesson is to describe how log analysis
Log Analysis to
techniques are used to evaluate an intrusion hypothesis.
Evaluate an
Intrusion
Hypothesis
Lesson 4 Learning
Determine the format of log files
Objectives
Use search, filter, and extraction techniques to evaluate a
hypothesis
Record findings and keep track of new leads
Lesson 4 Topics
Here are the topics to present.
Topic
Key Points
Hypothesis
Discuss how a hypothesis is evaluated
Evaluation
using digital forensic data acquisition and
analysis techniques
My Notes:
Procedure
Explain how there are multiple methods of
Selection
searching and filtering log files.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
105
NITRO
Lesson 4 Topics, continued
Topic
Key Points
Acquiring Log
Log files may be provided directly to you
Files
by an incident responder or network
administrator who collected them from the
original source media.
You may obtain a physical or logical image
of the original storage media containing the
log files, and then extract the logs from that
image.
You may logically copy log files from the
source system or device.
My Notes:
Previewing Log
Before analyzing collected logs, you
Formats
should first preview the format of those
logs to ensure that you know how to read
them properly and use the correct methods
for searching them.
My Notes:
Determining File
The first step in previewing log format is to
Type
determine the file type.
My Notes:
Determining
Once you know the file type for each log,
Data Format
you should identify the format of the data
within a Log
within. For network traffic capture logs,
this is relatively uniform. Text logs will
vary.
My Notes:
106
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 4 Topics, Continued
Topic
Key Points
Search/Extractio
Describe the general goal will be to search
n Criteria
for and extract log entries, or portions of
log entries that support or contradict your
hypothesis.
My Notes:
Correlation:
The main task of correlation is the
Timeline
establishment of a unified timeline.
Unification
My Notes:
Correlation:
Verify events by checking each log entry
Event
for another recording of the same event
Verification
from other sources.
My Notes:
Correlation:
The dates/times for events verified against
Using Event
multiple sources can also be compared to
Verification to
see if there is a time skew between the data
Synchronize
sources.
Times
My Notes:
Lead Tracking
In addition to your investigative notes,
leads should be recorded in your Attribute
List spreadsheet along with other relevant
data.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
107
NITRO
This page intentionally left blank.
108
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Module 13 - Log Sources
Overview
Knowing where the logs of interest reside on a system is a key
piece of information when starting a network investigation. This
module will show you some of the typical locations of logs for
select applications and systems.
Objectives
Describe the storage locations of typical log files
Be able to discuss some of the log file formats
Be able to recognize IDS logs and their contents.
In this Module
Here are the lessons in this module:
Lesson
See Page
Lesson 1 - Windows Log Sources
110
Lesson 2 - Linux Log Sources
113
Lesson 3 - Solaris Log Sources
115
Lesson 4 - Log Searching
117
Lesson 5 - IDS Logs
119
5-2008
For Official Use Only - Law Enforcement Sensitive
109
NITRO
Lesson 1 - Windows Log Sources
Lesson 1:
This lesson will cover the most common logs found in a Windows
Windows Log
environment.
Sources
Lesson 1 Learning
Know where Windows Logs are stored
Objectives
Understand naming conventions of log files
Know some of the file formats for these files
110
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Windows Logs
Mail - Outlook or Outlook Express as a
mail client
Default log files in Windows 2000, Server
2003 and XP inside each user’s profile
Outlook’s MAPI accounts, found at:
C:\Documents and Settings\username\Local
Settings\Temp\Opmlog.log
If user established Hotmail account in
Outlook, events logged in: C:\Documents and
Settings\username\Local
Settings\Temp\Outlook
Logging\Hotmail\http0.log.
Microsoft SQL Databases - stores its log
files in C:\MSSQL\LOG
ERRORLOG
SQLAGENT.OUT
SQLDump9999.txt/SQLDump9999.mdmp
MySQL - free, open source database
application that is also popular on many
Windows systems
Default location for installation of MySQL
C:\Program Files\MySQL\MySQL Server X.X
Cover subdirectories under this
Microsoft Access - Errors in Windows
Event log
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
111
NITRO
Lesson 1 Topics, Continued
Topic
Key Points
Windows Logs,
Internet Information Server (IIS)
Continued
Service used by Windows based servers to
host web, FTP, and e-mail services
Depending on version, logs found in
different locations
IIS versions 4 and 5, on Windows NT 4.0
and Windows 2000, log files stored in:
C:\winnt\system32\logfiles
IIS version 6 and 7, on Windows XP and
newer systems, log files stored in:
C:\windows\system32\logfiles
Log file names will be named “W3SVC”
FTP and DNS messages mingled in same
file if services active
System Logs
Application, Security and System
Use Event Viewer to view
Logs can be exported
Directory Services
Events will be in Event Viewer in
Directory Services
Remote Logs
My Notes:
112
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 - Linux Log Sources
Lesson 2: Linux
This lesson will cover the common and most used logs found in a
Log Sources
Linux environment.
Lesson 2 Learning
Know where Linux Logs are stored
Objectives
Understand naming conventions of log files
Know some of the file formats for these files
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Linux Logs
Mail Logs
Mail services provided by sendmail
processes
Logs for these services can usually be
found in the file: /var/log/maillog
Databases
MySQL most popular database program in
Linux
Logs typically be found in
/var/log/mysqld.log file
Services
Show the log files here, bringing up live
examples on a demo session.
Directory Management
Third party add-on tools provide service
Seek documentation for specific AD tool
and determine location of logs for each
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
113
NITRO
Lesson 2 Topics, Continued
Topic
Key Points
Linux Logs,
System Logs
Continued
Most Linux system log entries are located
in /var/log/message file
Remote Logs
My Notes:
114
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 3 - Solaris Log Sources
Lesson 3: Solaris
This lesson will cover the common and most used logs found in a
Log Sources
Solaris environment.
Lesson 3 Learning
Know where Solaris Logs are stored
Objectives
Understand naming conventions of log files
Know some of the file formats for these files
5-2008
For Official Use Only - Law Enforcement Sensitive
115
NITRO
Lesson 3 Topics
Here are the topics to present.
Topic
Key Points
Solaris Logs
Mail
May find file in /etc directory called
syslog.conf, and it may have the location of
sendmail logs listed inside
Databases
Logs in default locations of either
/usr/local/mysql/data or /opt/mysql/mysql/data.
Services
Most services put log messages in
/var/adm/messages log file, general catch
all file for log entries in Solaris
Directory Management
Third party add-on tools available
providing this service
Seek documentation for specific AD tool
System
System log files will be located in /var
directory in Solaris
Usually several nested directories of log
files under /var directory
Cannot open files in use
Remote Logs
Search for pipes and hard links to mounted
volumes in order to discover whether logs
are being stored remotely on Solaris
My Notes:
116
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 4 - Log Searching
Lesson 4: Log
This lesson will cover several ways to manually search through a
Searching
log file.
Lesson 4 Learning
Know how to use the findstr command
Objectives
Know how to use Grep/Egrep
Understand the basics of regular expressions
Lesson 4 Topics
Here are the topics to present.
Topic
Key Points
Log Searching
Flexibility is most important feature for
any tool used
Variety of log files require search for
different types of values
GREP / EGREP - Primary applications
used for searching and filtering text logs
Many advanced functions only work in
egrep, not in grep, so egrep is standard
Regular expressions are most common
method for defining search parameters,
used in many other popular applications,
such as PERL, Snort, and EnCase
Typically found in just Unix, Linux, and
OS X environments
Versions available for the Windows
FINDSTR
Windows equivalent of Grep
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
117
NITRO
Lesson 4 Topics, Continued
Topic
Key Points
Regular
Patterns used for executing searches and
Expressions
filters
Combining literal text and special
characters, called metacharacters, to create
a pattern
Provide examples of items that use set
patterns:
IP addresses
Dates and time
Phone numbers
URLs
Credit card numbers
Social Security numbers
Literal Character Searches - Simplest
type of regular expression
Grep is much more powerful than what is
presented here, but keep information very
light unless the class is technically
advanced. If so, bring up “* . ^”,
metacharacters as an introduction.
My Notes:
118
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 5 - IDS Logs
Lesson 5: IDS
This lesson will cover Intrusion Detection System logs
Logs
Lesson 5 Learning
Understand the importance of IDS logs
Objectives
Understand how Snort is used
Lesson 5 Topics
Here are the topics to present.
Topic
Key Points
IDS Logs
Intrusion Detection Systems prolific, found
in many networked environments
Most logs generated are binary rather than
text files
May have to use proprietary program to
view or convert the file to text
Some IDS save logs in libpcap format, you
can use packet sniffer tools like Wireshark
to open, view and export these files as
needed
Snort
Popular IDS and intrusion reporting tool
Allows administrators to flag alerts on both
live traffic and traffic captured with packet
sniffer
Will generate a text log displaying all alerts
of suspicious traffic it encountered
Requires complex set of steps to configure
properly, configuration will change with
each type of log or capture
By default, all of Snort’s log files on a
Linux, Unix, or OS X system will be found
in: /var/log/snort
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
119
NITRO
This page intentionally left blank.
120
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Module 14 - Log Analysis
Overview
Log data must not only be found, but properly formatted and
assembled into reports. Log entries can be used directly as items of
evidence, or assembled into other forms of data, such as statistics,
charts, graphs, and other representations.
Objectives
Generate statistics from log data
Format log data into report-friendly formats
Form visual charts and graphs with log data
In this Module
Here are the lessons in this module:
Lesson
See Page
Lesson 1 - Binary Traffic Analysis
122
Lesson 2 - Manual Log Analysis
126
Lesson 3 - Automated Log Analysis Tools
128
Sawmill
5-2008
For Official Use Only - Law Enforcement Sensitive
121
NITRO
Lesson 1 - Binary Traffic Analysis
Lesson 1: Binary
Binary logs require different filtering and searching techniques
Traffic Analysis
than those that are used with text logs. Due to the size of binary
logs and their required processing power, it is often more efficient
to filter binary network captures with command line tools
Lesson 1 Learning
Describe the types of criteria that can be used to filter binary
Objectives
logs
Convert binary logs to text files
Understand how to filter and search binary logs with
Wireshark
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Introduction to
Powerful, open source protocol analyzer,
Wireshark
can be used to view full network traffic
capture logs
Open a variety of binary log formats
Act as a sniffer
Translate, or decode, known protocols
within a binary log to human readable
format
Display highly detailed information on a
frame-by-frame basis
Search through a capture log for frames
that match specific criteria
Automatically reconstruct TCP sessions
Walk through procedure for importing logs
Walk through procedure for viewing binary
logs
My Notes:
122
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 Topics, continued
Topic
Key Points
Converting
Discuss binary vs. text and converting
Binary Logs to
binary to text
Text Format
My Notes:
Filtering and
Discuss filtering in Wireshark
Searching in
Capture filters
Wireshark
Display filters
Color filters
Find menu
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
123
NITRO
Lesson 1 Topics, Continued
Topic
Key Points
Filtering and
Walk through procedure for setting up a
Searching in
capture filter
Wireshark,
Walk through procedure for creating a
continued
display filter
Discuss creating a display filter for a
keyword
Discuss creating display filter for a hex
value
Discuss directly entering display filter
expressions
Review syntax of display filters
Discuss altering and combining
expressions
My Notes:
Colorizing Data
Walk through procedure for creating a
Using Filters in
color filter
Wireshark
Walk through procedure for searching in
Wireshark
My Notes:
Generating
Discuss Statistics Menu
Statistics with
Discuss Endpoints List
Wireshark
Discuss Protocol Hierarchy Statistics
Discuss Conversations List
Discuss HTTP Requests Stats Tree
My Notes:
124
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 Topics, Continued
Topic
Key Points
Exporting Data
Discuss Exporting Statistics from
from Wireshark
Wireshark
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
125
NITRO
Lesson 2 - Manual Log Analysis
Lesson 2: Manual For those times when automated tools for log analysis are not
Log Analysis
readily available, we will now look at ways to manually examine
and search log files for evidentiary information.
Lesson 2 Learning
Understand how to build keyword lists for searching
Objectives
Know how to execute simple searches using EGREP
Understand the basic concept of correlation of data.
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Filtering and
Identify all log entries with a specific value
Searching Text
or range of values
Logs
Modify view of one or more log files based
upon existence of an arbitrarily defined
parameter
Flexibility is important feature of tools
Will encounter wide variety of log files that
require search for different types of values
My Notes:
Regular
Discuss GREP / EGREP
Expressions
Regular expressions common method for
defining search parameters, used in
applications, such as PERL, Snort, and
EnCase
My Notes:
126
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Deciding What
Keywords
to Search For
Rarely will a ‘shotgun’ or broad focused
search turn up useable data
Decide on keywords that might be
available in logs and possibly locate
artifacts of intrusion
Sample keywords for intrusion:
o
“Error” or “err”
o
“Overflow”
o
“Password” or “Pass”
o
“Admin”
o
“Unauthorized”
o IP addresses of interest
My Notes:
Example Log
Walkthrough and discuss example log is
text
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
127
NITRO
Lesson 3 - Automated Log Analysis Tools
Lesson 3:
There are not many automated tools that allow you to search log
Automated Log
files. Most require complex programming and setup prior to use.
Analysis Tools
We will now look at one of the better tools on the market -
Sawmill.
Lesson 3 Learning
Install and configure the Sawmill program.
Objectives
Describe the function and use of the Sawmill program
Lesson 3 Topics
Here are the topics to present.
Topic
Key Points
What is
Sawmill is a tool that will assist analyst in
Sawmill?
parsing network text logs and organizing
logs into an easy-to-read report
Can process various text logs generated by
a variety of network security devices
Converts text log to a cross-linked report
that allows analyst to customize report
according to output requirements
Can be purchased and downloaded from
My Notes:
Installing
Walkthrough procedure for installing and
Sawmill
configuring
My Notes:
128
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 3 Topics, continued
Topic
Key Points
Network Log
Discuss The Administrative Interface
Analysis Using
Walkthrough procedure for creating a
Sawmill
report profile
Discuss the Report Environment
Discuss the Report Header
Discuss the Report Toolbar
Discuss Report Menu
Discuss Zoom To Filters
Discuss Final Output Report (Log Detail)
Discuss Single Page Summary
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
129
NITRO
This page intentionally left blank.
130
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Module 15 - Live Data Collection and Analysis
Module 15
Collecting live data from a system can uncover critically valuable
Overview
information for an investigation due to the fact that volatile data is
lost once the system is shut down. This module will guide you
through using LiveWire tools to collect and analyze the volatile
data on a remote system.
Module 15
This module contains exercises in this manual to be walked
Exercises
through with the instructor As well as those for the students to go
through themselves.
XP-Pro-LiveWire-CookBook - Walkthrough in book
Carly Sizemore - Practical and test to help prepare for final
Alt tools Cookbook - Walkthrough and test
Alt tools Carly Sizemore - Walkthrough and test
Final Practicals - Set of three practical and tests
Module 15 Testing This module is tested. The testing will include investigating 3
VMware images wish LiveWire along with multiple choice
questions. A question pool of 30 questions per image has been
provided for the instructor to create tests from as they see fit.
Module 15
Properly prepare for a live digital investigation.
Objectives
Use live digital investigation tools introduced in this module.
In this Module
The following table shows the contents of this module.
Topic
See Page
Lesson 1 - Data Collection
133
Lesson 2 - Introduction to LiveWire
135
Lesson 3 - Network Mapping
137
Lesson 4 - Volatile Data Analysis
138
Lesson 5 - Evidence Collection
141
Lesson 6 - Malicious Code Analysis
144
Lesson 7 - Alternate Data Collection Tools
146
5-2008
For Official Use Only - Law Enforcement Sensitive
131
NITRO
Module 15 Exercise Configuration Details
Module 15 Exercise Details
VM Image:
XP-Pro-LiveWire-CookBook
VM Snapshots:
Anarchy CookBook - truecrypt
Description:
This virtual machine will be used throughout this module. Each
exercise builds off of the previous exercises. The VM should be run
at the specified snapshot to load the artifacts into memory that will be
discovered by the students.
This Virtual Machine has the Anarchy CookBook Chapter 2 - Credit
Card Fraud opened in open office. This document is stored in a
truecrypt volume.
Summary of Artifacts to be Discovered During This Module
Running processes:
truecrypt, open office writer
Document Open:
M:\anarchycookbook - credit card fraud.doc
TrueCrypt Volume:
My Documents\sweet-success.avi
Suspect images:
Located in My Pictures
Recent Documents:
shows files from M:\ and My Documents
Target VMWare Configurations
Computer Name:
HellRaiser
Operating System:
Windows XP SP2
IP Address:
10.15.4.210
Subnet Mask:
255.255.255.0
Administrator U/N:
Admin
Administrator P/W:
password
Target U/N:
Student
Target P/W
password
TrueCrypt Volume:
My Documents\sweet-success.avi
TrueCrypt Volume P/W:
anarchy
132
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 - Data Collection
Lesson 1: Data
When collecting data for any investigation it’s vital that the data
Collection
collection is conducted correctly.
Lesson 1 Learning
Discuss locating physical devices in a network environment
Objectives
Discuss collecting data for forensically clean media
Lesson 1: VMware
Throughout this module, each student will have his/her own
Setup
VMware image loaded and running on the server. Each group of 4
students will be assigned a number 1 through 4 that will
correspond with the last number of the IP address for the target
machine. IP address 10.15.4.211 will be the target machine for
student 1, IP address 10.15.4.212 will be the target machine for
student 2. etc. Therefore, there will be 4 different VMware images
for each exercise that is outlined in this instructor guide.
Cookbook VMware image - Load the snapshot named “Anarchy
CookBook - truecrypt”.
To load the correct image for the exercise in the book:
Open the Windows XP Pro CookBook VMware image.
On the task bar select VM > Snapshot > Anarchy CookBook -
truecrypt”.
NOTE: This snapshot will be used throughout this module for
students to extract investigative information.
The more students that are hitting the same machine, the slower it
will respond. Therefore, some actions should be expected to take
longer than others depending on the number of users extracting
data simultaneously.
5-2008
For Official Use Only - Law Enforcement Sensitive
133
NITRO
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Locating
Explain that there is a difference in logical
Physical Devices
and physical topologies.
Explain that logical topologies are used to
show the flow of data over a network.
Explain that physical topologies are used to
show how devices are physically connected
to other network components.
Explain that a tone generator can be used to
help trace network cables.
Network/systems administrator may be a
point of contact to interview but his
answers must be verified.
Explain that all findings should be
recorded.
My Notes:
Attaching
.Explain that captured evidence may be
Storage
extremely large.
Equipment
The investigator must ensure that there is
enough hard drive space necessary to store
the data on.
Investigations require that evidence is
stored on forensically clean media.
Storage media should be wiped and
verified before use.
Review wiping guidelines section
My Notes:
134
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 - Introduction to LiveWire
Lesson 2:
In this lesson, the students will be introduced to LiveWire. The
Introduction to
software will be correctly installed and configured.
LiveWire
Lesson 2 Learning
Explain the basic concepts of live digital investigations
Objectives
Successfully install, update, and setup LiveWire.
Successfully install and update LiveDiscover
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Live Digital
Live digital investigations are performed
Investigations
on systems that are currently active with
running processes.
Live systems are constantly changing.
Live investigations allow the investigator
to capture, view, and monitor the current
system activities in real time.
LiveWire requires an administrative
account to retrieve data from the system.
LiveWire uses Connect-Act-Disconnect.
Be aware of the possibility that a
knowledgeable user could become aware of
the system being investigated.
Discuss workstation requirements
My Notes:
LiveWire
Walk through installing LiveWire onto the
Installation
workstation.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
135
NITRO
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
LiveDiscover
Walk through installing LiveDiscover onto
Installation
the workstation.
My Notes:
Updating
Walk through installing updating
LiveWire
LiveWire.
My Notes:
Updating
Walk through updating LiveDiscover.
LiveDiscover
My Notes:
LiveWire Initial
Walk through the initial setup of LiveWire
Setup
to prepare the system for investigations.
The default LiveWire Administrator
account password must be changed.
Passwords require number and digits.
An investigator account must be created to
perform investigations.
My Notes:
136
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 3 - LiveDiscover
Lesson 3:
In this lesson, we will talk about finding the devices on the
LiveDiscover
network so they can be examined.
Lesson 3 Learning
Describe important functions of LiveDiscover
Objectives
Effectively scan a network for devices
Effectively identify devices found on the network
Lesson 3 Topics
Here are the topics to present.
Topic
Key Points
LiveDiscover
LiveDiscover will be used to find XP SP2
Network
at IP 10.15.4.210
Scanning
Data from LiveDiscover can be used with
LiveWire to perform analyses.
LiveDiscover can quickly scan ranges of IP
addresses.
Data is stored in a database.
Discuss the different tabs available.
Perform a scan to find the system that will
be investigated in later exercises.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
137
NITRO
Lesson 4 - Volatile Data Analysis
Lesson 4: Volatile In this lesson, we will perform the initial inquiry of the suspect
Data Analysis
system to retrieve begin the volatile data analysis.
Lesson 4 Learning
Conduct an initial inquiry.
Objectives
View the current open files on the system.
View the current network connections and configurations.
Image RAM over the network.
Lesson 4 Topics
Here are the topics to present.
Topic
Key Points
LiveWire Initial
Walk through the initial inquiry as in the
Inquiry
book.
IP 10.4.15.210
Username: Admin
Password: password
Make the point that live systems are
constantly changing and the investigator
must be aware of this.
Initial inquiries and other actives may
impact the performance of the suspect
system.
Point out that data should always be saved
to forensically clean media, but these
lessons will use the default local directory
for instructional purposes only.
Discuss that the information used to
perform the investigation was discovered
during the LiveDiscover section.
My Notes:
138
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 4 Topics, continued
Topic
Key Points
System State
Go over the exercise in the student book.
View the initial inquiry information and
discuss how this information can be
important to the investigation.
Acquire the physical RAM
Many factors impact the speed of the RAM
imaging process.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
139

 

 

 

 

 

 

 

Content      ..      1      2      3      ..