Digital Forensics Evidence
Road MapBasic Digital ForensicsTraditional Digital ForensicsLive Digital Forensics Anti-Digital Forensics Questions
Basic ForensicsRegistry Thumbs.dbIndex.dat Commands
Registry Last LogonHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogonSecurity CenterHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center Recent DocumentsHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.doc Typed URLshkcu\software\microsoft\internet explorer\typedurls
Thumbs.DBPictures opened in Windows OSFilmstripThumbnails Thumbs.DB Viewer
Index.DATContains all of the Web sites Every URLEvery Web pageAll email sent or received through Outlook or Outlook ExpressAll internet temp filesAll pictures viewed
CommandsDir: Lists all files and directories in the directory that you are currently in.Ls: List the contents of your home directory by adding a tilde after the ls command.Ps: Displays the currently-running processes.Fdisk: A utility that provides disk partitioning functions, and information.
Traditional ForensicsHardware Write Block/Software Write BlockCell PhonesDigital Forensics Programs Hex EditorFTKEnCaseProDiscover
Hardware Write Block
Hardware Write BlockHard Drive Connected
Hardware Write Block Image in process
Destination Drive
Safe Block XP
Software Write BlockRegistry Edit USB BlockHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\StorageDevicePoliciesWrite protectDisable WriteProtect dword:00000001Enable WriteProtect dword:00000000
Cell Phone
USB Drive
Hex Editor
FTK
EnCase
EnCase Continued
ProDiscover
Live Digital Forensics ProDiscover IRHelixSleuth Kit & Autopsy CaineFTK/EnCase making them live?Both newer offerings have live capabilities
ProDiscoverIR
Live environment warnings
Helix
Helix Continued
Sleuth Kit & Autopsy
Caine
FTK/EnCase Live?Older versions no. EnCase 4.6 no.FTK 1.8 no. New versions yes EnCase 6 supports network and live digital forensics.FTK 3 supports live digital forensics
Problems Firewalls/Routers/SwitchesProxiesIP packetsTTL issuesIDS
Anti-Digital Forensics SteganographyEncryptionData WipingMetadata SpoilageAlternative Data StreamsIndex.DatThumbs.db Death of digital forensics
SteganographyDetectionWetStone Technologies' GargoyleNiels Provos' Stegdetect  HidingStegoMagicwbStegoHIP (Hide In Picture)
StegoMagic
wbStego
HIP
EncryptionFile encryptionFull disc-encryption
Data WipingM-Sweep Pro Data Eliminator DBANDOD 5220.22MFile Shredder Beyond DOD
M-Sweep Pro Data Eliminator
DBAN
File Shredder
Metadata spoilage MetaspolitTimeStompSlackMetachanger
Metasploit
Timestomp
MetaChanger
Alternative data streamsData fork Resource fork old Macintosh Hierarchical File SystemImpossible to protect your system against ADS.Cannot be disabledNo way to limit this capability  redirect [>] and colon [:] to fork one file into another.C:\test> type c:\windows\notepad.exe > ads.txt:hidden.exe
Alternate Data Streams scan engine
Locations of Index.DAT files VISTA\Users\<Username>\AppData\Roaming\Microsoft\Windows\Cookies\index.dat\Users\<Username>\AppData\Roaming\Microsoft\Windows\Cookies\low\index.dat\Users\<Username>\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.datC:\Users\<UserName>\AppData\Local\Microsoft\Windows\History\Content.IE5\index.dat
Index.DAT Analyzer
Thumbs.DB Viewer
Death of Digital ForensicsSSDs are much like memorySmallest part written too is a sectorErases data in a block Anything changes physical placement of dataLogical placement stays the same. Black boxes from a system's point of viewProperty
ConclusionWe can see the live digital forensics is best used for starting an investigation. Traditional Digital forensics is best for collecting the data And knowing the techniques of Anti-digital forensics can help the investigator find data that he/she might not other wise be able to find.
Questions
Digital Forensics

Digital Forensics