Tuesday, October 14, 2014

Advanced topics - Search by FileTime

This is in progress, but the main idea is that we should be able to find FileTime ranges in $MFT, FAT DE, and in many SQLite databases, or log files by directly searching the stored time stamp.

We can use PowerShell to give us a range of FileTime values for a particular date range that will allow us to search the evidence for artifacts that we might not even realize yet, but stores the time stamp in its structure.

PS C:\> (Get-Date -Date "2014-10-14T00:00:00").ToFileTime()
130577364000000000
PS C:\> (Get-Date -Date "2014-10-14T23:59:59").ToFileTime()
130578227990000000
PS C:\> [convert]::tostring((Get-Date -Date "2014-10-14T23:59:59").ToFileTime(),16)
1cfe834debe7180
PS C:\> [convert]::tostring((Get-Date -Date "2014-10-14T00:00:00").ToFileTime(),16)
1cfe76bb4ed4800

So, now that we know a time stamp range, we can reverse the time stamps to little endian, if needed, and locate values matching the range.

The image below is just a sample of a simple regular expression based search for a pattern matching a time range.



Also, get date and time by entering the fileTime value:

PS > Get-Date 129442497539436142
or
PS > [datetime]::FromFileTime("129442497539436142")

What did I do? - Pattern is the key

In this case, you need to decide if this case has anything that might be relevant to illegal animal trade.

Our hypothetical law states that it is illegal to own and store any image of animals with feather or fur.

You are given the suspect's computer and you see the following in the C:\temp\images folder.  The scope of the investigation restricts you to this simple folder, so you need to write your report examining data in the given folder.

You can ask for any other information you'll need to find the answer.


Remember computers store data visible, deleted, or hidden format that are either clear text, encoded, or encrypted and generated by operating system, application, or users.  So, as you analyze the image above, write your conclusion from these data characteristics in mind.

DON'T CHEAT, THE VIDEO IS FOR CHECKING IF YOU ARE ON THE RIGHT TRACK!!!





Monday, October 13, 2014

What did I do? - Google search

Sometimes you might think that it would be valuable to validate your findings and establish a base for your opinion.  There are many analysis of user actions without validating against actual user actions, so here we go.  I will give you specific scenarios with screenshot of relevant evidence data here on this blog, but you will also be able to watch a video of the actual actions I perform that generated the relevant data.  Depending on the activity type, I can even provide the relevant evidence specific artifact if needed.  All times displayed on the video will be Central Time with the actual daylight offset applied.

So, what was I doing last night?  Create your theory and sequence of events that I have performed.  Then, look at the video to find out if you were correct with your analysis.  Pay attention to sequence of events and the timeline of actions performed.  Don't forget to predict how many times I have visited each websites and what links I have clicked.  Look at the URL bar to find patterns for each actions and compare them to the report to see any discrepancy.


DO NOT CHEAT, WATCH THE VIDEO AFTER YOUR THOROUGH ANALYSIS!!!

File to be analyzed if you want to confirm these findings by manual analysis or use
C:\Users\<UID>\AppData\Local\Google\Chrome\User Data\Default\History

System setup:
Windows 8.1 Pro
Intel Core i7
16GB RAM
64 bit OS

Google Chrome - Version 35.0.1916.153 m
ChromeHistoryView v1.17 - http://www.nirsoft.net/



Let me know how accurate you were in your prediction!!!

Saturday, October 11, 2014

Back to Basics - Security by Monitoring

Security vs. convenience or privacy vs. security or freedom vs. control?  Sometimes we have a hard time deciding what is better for us and what makes sense.  For those in the cybersecurity field, convenience is un-security, your privacy is protected by monitoring your activities to identify the normal patterns in order to alert for abnormal signs.  You can not have it both ways, you do need to give up control ( not freedom ) in order for some else to help you provide your with the desired level of security.  The fundamental premise of security is monitoring.  Think about your kids, you can not protect them unless you know where they are and what are their plans in order to be preemptive instead of reactive.  Without this kind of access to their lives, you could not provide preventative services, you will always be reactive to events and will be late to protect anyone.  It is not about losing freedom, but providing protective services so you can be productive and focus on your assigned tasks instead of reducing your productivity due to your lack of skills to protect yourself.  Keeping up with the skills required to provide meaningful services is a full time job, so you have to outsource that skill to someone else who is qualified for the job.  It is like mowing your own lawn since you do not want to give up control of your grass.  It is convenient, cheaper, and more efficient to let professionals handle trivial tasks.  Have you aver tried to do something yourself to save money and it ended up costing you more time and money than if you hired some else to do the job for you?  I think, every one has.

So, think about cybersecurity and monitoring not as a loss of freedom, but a service that allows you to focus on what you good at, but only give access to those who have a vested interest to protect you, not to profit from it.

Many times, people are afraid of government agencies and ignore the businesses.  Agencies like NSA has a vested interest to enforce laws and protect citizens, not to snoop or to profit from collected information.  Collection is part of providing security in a legally controlled manner where no on person has authority over all data and their usage.  On the other hand, businesses have a vested interest to continually and in real time monitor as many individuals as possible in order to provide advertisement or directed sales pitches.  They thrive on knowing you more tan you know yourself regardless of law or regulation, if the can profit from it, they will use this information to anyone who is willing to pay for it.  There is no write or wrong here since we use services mostly provided for free, thus we willingly give up privacy to our information.  Like I'm using this blog, so by the end of this blog, I will get advertisements based on words I use in this blog and websites I might mention.  When I click on save, the words will be indexed and associated with my id and a profile is built about me that will be marketed to anyone interested focusing customers like me.

So, while NSA might collect data on my international calls, it might be used to generate some basic profile about me and if I break the law, that information can be pulled and analyzed to find out what made me change or to act in a certain way.  For profit organizations are like a wild wild west, they hire the best of the best to find ways to figure out how to make me buy things I don't need.  They are interested in all my button clicks and even on clicks I was thinking about, but decided not to click.  All this is in real time and marketed for profit.  We never even bother to read policies on websites we sign up for and use.  We never question what businesses do with the information we share or where this information is stored or even who owns the data we publish on the web.

My point, is that cybersecuriy is about monitoring to protect you and that is what agencies do for you, so you can focus on creating your wealth in whatever business you are in.  Businesses are the entities that we should be more concerned about and limit what they do with information we provide.  After all, the Internet was created for information sharing and just because I'm being analyzed as I'm writing this, I did not give up my freedom to talk about what I feel strongly about.  I'm being analyzed to make sure we can reach many people in a secure and responsible way.

Technology pose challenges to those who provide services since data grows exponentially and it is harder to distinguish approved traffic from malicious traffic.  Monitoring activities allows intelligent systems to identify normal traffic and learn consistent behaviors.  I like to fill up my car at the same gas station and fill up to a value divisible by 10 plus $0.01.  Security is about establishing consistency, so if I see charges on my credit card for $50.01 at a gas station, I can see that it is normal, but a charge of $50.54 is not.  Now, that is a pattern that can be coded and entered into a system or an intelligent system can learn this pattern and alert for out of pattern charges.  I might make a mistake and fill up my can to $50.75, but that is just a false positive that I can handle even if I get alerted for that charge.

Security is consistency!

Learn about the type of monitoring software can do and think about the patterns that might help professionals in this field do their job effectively.  If you think about consistency and not monitoring, then you might appreciate monitoring and the purpose of cybersecurity.

http://youtu.be/RR3bS5g-KTE

Back to Basics - Little Endian in PowerShell

Reverse little endian value for 64 bit FileTime entries and show the actual time value.

The basic concept of the code below is the rule of binary ANDing.  Any number logically ANDed with 255 ( 0xFF ) will result of a number itself and any number logically ANDed with 0 will result in zero.

Let's see how that works with an example:
The number is: 01101011 01010110
0x00FF:          00000000 11111111
===========================
The result:        00000000 01010110

Thus, you can see that using binary operation, we can separate a value from a sequence of binary values.  Also, this can be done in a decimal format like 23 AND 255 = 23.  So, if we have a longer Base-16 value like the little endian 64bit FileTime, we can reverse it by logically ANDing it with 0x00000000000000FF or just 0xFF.  At that point, we'll end up with the last 8 bits or the right most byte value.  At that point, we can remove those bytes by shifting the values to the right 8 times.  At that point, the last byte will be the second right most byte in the original byte string.  So, we can just repeat the ANDing and shifting of values and adding the appropriate Base-256 values to the total result.

  

function revEndian{
param($a=0x23BBCCDDEEFFAA01)
$result=0

#Binary AND to identify the lowest byte value
$temp=$a -band 0xFF
#Shift the binary string to the right by 8 bits to replace the lowest byte value
$a=$a -shr 8

#Keep identifying and shifting the bytes to the right and calculating the proper Base-256 value

for($i=7; $i -ge 1;$i--){
    $result=$result+$temp * [math]::pow(256,$i)
    $temp=$a -band 0xFF
    $a=$a -shr 8
   }
#Binary OR to add the last byte to the final value
$result=$result -bor $temp
return ,$result
}

#Call the function with specified Little Endian FileTime value
$value=revendian(0xE87B9127C826CF01)
write-host "The value in Base-16 is:",("{0:x}" -f [convert]::touint64(($value)))
write-host "... and the date value of it is",([datetime]::FromFileTime($value))

Run the above script and you should see the following.

PS C:\> .\Convert.ps1
The value in Base-16 is: 1cf26c827917be8
... and the date value of it is 2/10/2014 7:25:31 PM

Friday, September 26, 2014

Back to basics - NTFS Data Runs

This is not really the basics, but an advanced knowledge from a technical point-of-view.  Since it is a published process explained in great details, it becomes basic knowledge.  Those in non-scientific fields are not used to calculating and verifying steps and procedures and that basic premise moves the field of digital forensics into an educational definition of STEM fields.  STEM stands for Science Technology Engineering and Math.

This post will discuss the complex process and understanding of data storage in the New Technology File System ( NTFS ) specifically the $80 attribute's lesser understood structure of it's data runs.


This image is from the book "Guide to Computer Forensics and Investigations", September 28, 2009, by Bill Nelson (Author), Amelia Phillips (Author), Christopher Steuart (Author) 


Thus, based on the image above, the data run can be extracted and analyzed for the actual data cluster locations.


If you want to create the same analysis and documentation of the data clusters, here is the actual string of the data runs: 32B1078C8C0022630795ED32BC063C360122350302FA210B6CFE229E01E904

The example above contains 6830 clusters for the file with positive and negative offsets to cluster runs.  You can not get any more complex than this one.  If you understand this example, you understand how NTFS saves non-resident files.  If you are into programming, I would suggest you do this analysis by hand or with a simple application like I did here with Excel before attempting to write a program in a lower level programming language.

Good luck practicing and getting better in understanding technology at a deeper level.

Sunday, September 21, 2014

Back to basics - Create Your Own Evidence

One of the most important skills one can have in forensics is to be able to create a controlled evidence where all aspects of the evidence is known in order to test the reliability of tools and methodologies.  In this case, I wanted to explore a few options in enCase and create a test image that can help test the keyword search capabilities.

You can watch my video on the details and you can also request the final evidence file.  http://youtu.be/iP9UzHG19Gw
If you need to request the evidence file than I failed to get my point across that you need to be able to create a baseline evidence in order to test any tool that you might come across.

The evidence is based on Central Daylight Savings time and NTFS file system.

D:\>dir /t:c                                                                    creation times
 Volume in drive D is NTFS_1024
 Volume Serial Number is F807-E907

09/21/2014  03:06 AM            10,241 file_c.txt
09/21/2014  03:08 AM             2,049 file_d.txt
09/21/2014  03:06 AM             2,049 file_e.txt
09/21/2014  03:06 AM             2,049 file_f.txt
               4 File(s)         16,388 bytes
               0 Dir(s)      53,191,680 bytes free

D:\>dir /t:a                                                                  last access times
09/21/2014  03:06 AM            10,241 file_c.txt
09/21/2014  03:08 AM             2,049 file_d.txt
09/21/2014  03:06 AM             2,049 file_e.txt
09/21/2014  03:06 AM             2,049 file_f.txt

D:\>dir /t:w                                                                last written times
09/21/2014  03:04 AM            10,241 file_c.txt
09/21/2014  03:05 AM             2,049 file_d.txt
09/21/2014  03:05 AM             2,049 file_e.txt
09/21/2014  03:05 AM             2,049 file_f.txt

MFT record location in sector and the two data run sector locations for the file called file_a.txt where a keyword "keyword2" is spanned between two data run locations and the file is deleted.  enCase allows for the file to be un-deleted before searched for keywords, so this file will be crucial to test that capability.
42722   -   MFT record
280     -   file_a.txt
41230 ( custer 20615)

The VBR will need to be corrupted in order to write directly to the raw device, so the first 7 bytes will be zeroed out and restored after we are done with the evidence drive creation. ( Thanks to Chuck Black for researching and finding this simple trick )
EB 52 90 4E 54 46 53  - VBR

Details of keyword locations and offset values.
....akeyword2a....  file_a.txt 230b3
^keyword1-1^              23123
....keyword2....          1424042   second data run RAM slack
....keyword2....          1424305   second data run drive slack
...keyword1-1...          1424372   UNICODE  second data run drive slack
....keyword2zzzz          14243FD   split between last cluster and next unused cluster
...aaaakey                   25bfd   first half or split keyword datarun 1
word2aaaaa...             1421C00  second half of split keyword datarun 2

keyword2ccc...      file_c.txt 25c00
^keyword1-1^   25c91
^keyword1-1^ UNICODE 25D14
...keyword2...  RAM slack  28473
...keyword2...  Drive slack 28724

dddkeyword2ddd...      file_d.txt 28AC5
^keyword1-1^   28fb3
..keyword1-1.. UNICODE RAM slack 29063
...keyword2...  RAM slack  290D5
...keyword2...  Drive slack 292B4

bbbkeyword2bbb...      file_b.txt deleted 294c5
...keyword2...  RAM slack  2B0A3
...keyword2...  Drive slack 2B2C4

split between file_b.txt and file_f.txt
....keyword2fffff            2B3FD
ffffkeyword2ffff             2B454

...eeekeyword2eee...      file_e.txt 14D20F3
...keyword2...  RAM slack  14d28a4
...keyword2...  Drive slack 14d2ac4
...a2V5d29yZDI=...     drive slack Base64 encoded 14D2B34

...keyword2... File_f.txt MFT record  14DCA43

....keyword2... unused MFT record 14DDB04

...zzzzkeyword2zzzz...  unallocated space 3692683