← All cheat sheets

Forensics

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

EVIDENCE PRESERVATION#

# Create forensic image (dd)
dd if=/dev/sda of=/mnt/evidence/disk.img bs=4M status=progress
dd if=/dev/sda of=/mnt/evidence/disk.img bs=64K conv=noerror,sync

# Create forensic image (dc3dd - with hashing)
dc3dd if=/dev/sda of=/mnt/evidence/disk.img hash=md5 hash=sha256 log=disk.log

# Create forensic image (dcfldd)
dcfldd if=/dev/sda of=/mnt/evidence/disk.img hash=md5,sha256 hashlog=hash.log

# Using FTK Imager (Windows)
# GUI tool for forensic imaging

# Using Guymager (Linux)
# GUI tool for forensic imaging

HASH VERIFICATION#

# MD5
md5sum disk.img
md5sum -c hash.md5

# SHA256
sha256sum disk.img
sha256sum -c hash.sha256

# SHA1
sha1sum disk.img

# Multiple hashes
hashdeep -c md5,sha256 disk.img

MOUNT FORENSIC IMAGE#

# Read-only mount
mount -o ro,loop disk.img /mnt/evidence

# Mount with offset (for partitions)
fdisk -l disk.img    # Find offset
mount -o ro,loop,offset=1048576 disk.img /mnt/evidence

# Using losetup
losetup -r -o 1048576 /dev/loop0 disk.img
mount -o ro /dev/loop0 /mnt/evidence

# Mount NTFS
mount -o ro,loop,show_sys_files disk.img /mnt/evidence

# Mount with noatime
mount -o ro,loop,noatime,noexec disk.img /mnt/evidence

TIMELINE ANALYSIS#

# Using Sleuth Kit
fls -r -m / disk.img > bodyfile.txt
mactime -b bodyfile.txt > timeline.txt
mactime -b bodyfile.txt -d > timeline.csv

# Using plaso (log2timeline)
log2timeline.py timeline.plaso disk.img
psort.py -o dynamic -w timeline.csv timeline.plaso

FILE RECOVERY#

# Foremost
foremost -t all -i disk.img -o output/

# Scalpel
scalpel disk.img -o output/

# PhotoRec
photorec disk.img

# Bulk Extractor
bulk_extractor -o output disk.img

# Testdisk
testdisk disk.img

SLEUTH KIT COMMANDS#

# File system info
fsstat disk.img

# List files
fls disk.img
fls -r disk.img           # Recursive
fls -rd disk.img          # Include deleted
fls -l disk.img           # Long format

# Extract file by inode
icat disk.img <inode> > extracted_file

# File information
istat disk.img <inode>

# Search for strings
srch_strings disk.img

# Find file type
file disk.img

WINDOWS ARTIFACTS#

# Registry hives
/Windows/System32/config/SAM       # User accounts
/Windows/System32/config/SYSTEM    # System config
/Windows/System32/config/SOFTWARE  # Software config
/Windows/System32/config/SECURITY  # Security policies
/Users/<user>/NTUSER.DAT          # User settings

# Parse registry with RegRipper
rip.pl -r SAM -f sam
rip.pl -r SYSTEM -f system
rip.pl -r SOFTWARE -f software
rip.pl -r NTUSER.DAT -f ntuser

# Event logs
/Windows/System32/winevt/Logs/
evtx_dump.py Security.evtx

# Prefetch
/Windows/Prefetch/
# Analyze with PECmd or prefetch-parser

# Recent files
/Users/<user>/AppData/Roaming/Microsoft/Windows/Recent/

# Browser history
/Users/<user>/AppData/Local/Google/Chrome/User Data/Default/History
/Users/<user>/AppData/Roaming/Mozilla/Firefox/Profiles/

# USB devices
# In SYSTEM registry: USBSTOR key

# Shellbags
# In NTUSER.DAT and UsrClass.dat

LINUX ARTIFACTS#

# User information
/etc/passwd
/etc/shadow
/etc/group

# Login history
/var/log/auth.log
/var/log/secure
/var/log/wtmp            # last
/var/log/btmp            # lastb (failed)
/var/log/lastlog         # lastlog

# Command history
/home/<user>/.bash_history
/root/.bash_history
/home/<user>/.zsh_history

# Cron jobs
/etc/crontab
/var/spool/cron/
/etc/cron.d/
/etc/cron.daily/

# System logs
/var/log/syslog
/var/log/messages
/var/log/kern.log

# Network
/var/log/apache2/access.log
/var/log/nginx/access.log

# Persistence
/etc/rc.local
/etc/init.d/
~/.bashrc
~/.profile

MEMORY FORENSICS#

# Acquire memory (Linux)
sudo dd if=/dev/mem of=memory.img bs=1M
sudo lime-forensics/LiME-memory.ko format=lime path=memory.lime

# Acquire memory (Windows)
# Use DumpIt, WinPmem, or FTK Imager

# Volatility 3
vol3 -f memory.img windows.info
vol3 -f memory.img windows.pslist
vol3 -f memory.img windows.psscan
vol3 -f memory.img windows.pstree
vol3 -f memory.img windows.cmdline
vol3 -f memory.img windows.dlllist
vol3 -f memory.img windows.handles
vol3 -f memory.img windows.netscan
vol3 -f memory.img windows.filescan
vol3 -f memory.img windows.registry.hivelist
vol3 -f memory.img windows.hashdump

# Volatility 2
volatility -f memory.img imageinfo
volatility -f memory.img --profile=Win10x64 pslist
volatility -f memory.img --profile=Win10x64 psscan
volatility -f memory.img --profile=Win10x64 netscan
volatility -f memory.img --profile=Win10x64 hivelist
volatility -f memory.img --profile=Win10x64 hashdump
volatility -f memory.img --profile=Win10x64 malfind
volatility -f memory.img --profile=Win10x64 dumpfiles -D output/

NETWORK FORENSICS#

# Capture traffic
tcpdump -i eth0 -w capture.pcap
tshark -i eth0 -w capture.pcap

# Analyze with tshark
tshark -r capture.pcap
tshark -r capture.pcap -Y "http"
tshark -r capture.pcap -Y "dns"
tshark -r capture.pcap -T fields -e ip.src -e ip.dst

# Extract files from pcap
tcpflow -r capture.pcap -o output/
foremost -i capture.pcap -o output/

# NetworkMiner (GUI)
# Extracts files, images, credentials from pcap

# Zeek (Bro)
zeek -r capture.pcap
cat conn.log

MALWARE ANALYSIS#

# Static analysis
file suspicious.exe
strings suspicious.exe
strings -el suspicious.exe    # Unicode
objdump -d suspicious.exe
readelf -a suspicious.elf

# PE analysis
pefile suspicious.exe
peframe suspicious.exe
pescan suspicious.exe

# Dynamic analysis (sandbox)
# Use Cuckoo, Any.Run, VirusTotal

# YARA rules
yara rules.yar suspicious.exe

EMAIL FORENSICS#

# Parse PST files
readpst mailbox.pst -o output/

# Parse EML files
# Standard text-based format

# Headers to examine
- Received headers (trace path)
- X-Originating-IP
- Return-Path
- Message-ID
- Authentication-Results
- SPF, DKIM, DMARC results

MOBILE FORENSICS#

# Android
adb backup -all -f backup.ab
# Use Autopsy or Oxygen for analysis

# iOS
# Use libimobiledevice or commercial tools

# SQLite databases
sqlite3 database.db
.tables
.schema tablename
SELECT * FROM tablename;

REPORTING#

# Document everything:
- Chain of custody
- Hash values
- Tools used
- Commands executed
- Timestamps
- Screenshots
- Findings with evidence

TOOLS SUMMARY#

Imaging: dd, dc3dd, dcfldd, FTK Imager, Guymager
Analysis: Autopsy, FTK, EnCase, X-Ways
Memory: Volatility, Rekall, LiME
Network: Wireshark, NetworkMiner, Zeek
Carving: Foremost, Scalpel, PhotoRec
Timeline: log2timeline (Plaso), Sleuth Kit
Malware: YARA, Cuckoo, PEstudio
Mobile: Cellebrite, Oxygen, Autopsy