Forensics
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
EVIDENCE PRESERVATION#
# Create forensic image (dd) dd if=/dev/sda of=/mnt/evidence/disk.img bs=4M status=progress dd if=/dev/sda of=/mnt/evidence/disk.img bs=64K conv=noerror,sync # Create forensic image (dc3dd - with hashing) dc3dd if=/dev/sda of=/mnt/evidence/disk.img hash=md5 hash=sha256 log=disk.log # Create forensic image (dcfldd) dcfldd if=/dev/sda of=/mnt/evidence/disk.img hash=md5,sha256 hashlog=hash.log # Using FTK Imager (Windows) # GUI tool for forensic imaging # Using Guymager (Linux) # GUI tool for forensic imaging
HASH VERIFICATION#
# MD5 md5sum disk.img md5sum -c hash.md5 # SHA256 sha256sum disk.img sha256sum -c hash.sha256 # SHA1 sha1sum disk.img # Multiple hashes hashdeep -c md5,sha256 disk.img
MOUNT FORENSIC IMAGE#
# Read-only mount mount -o ro,loop disk.img /mnt/evidence # Mount with offset (for partitions) fdisk -l disk.img # Find offset mount -o ro,loop,offset=1048576 disk.img /mnt/evidence # Using losetup losetup -r -o 1048576 /dev/loop0 disk.img mount -o ro /dev/loop0 /mnt/evidence # Mount NTFS mount -o ro,loop,show_sys_files disk.img /mnt/evidence # Mount with noatime mount -o ro,loop,noatime,noexec disk.img /mnt/evidence
TIMELINE ANALYSIS#
# Using Sleuth Kit fls -r -m / disk.img > bodyfile.txt mactime -b bodyfile.txt > timeline.txt mactime -b bodyfile.txt -d > timeline.csv # Using plaso (log2timeline) log2timeline.py timeline.plaso disk.img psort.py -o dynamic -w timeline.csv timeline.plaso
FILE RECOVERY#
# Foremost foremost -t all -i disk.img -o output/ # Scalpel scalpel disk.img -o output/ # PhotoRec photorec disk.img # Bulk Extractor bulk_extractor -o output disk.img # Testdisk testdisk disk.img
SLEUTH KIT COMMANDS#
# File system info fsstat disk.img # List files fls disk.img fls -r disk.img # Recursive fls -rd disk.img # Include deleted fls -l disk.img # Long format # Extract file by inode icat disk.img <inode> > extracted_file # File information istat disk.img <inode> # Search for strings srch_strings disk.img # Find file type file disk.img
WINDOWS ARTIFACTS#
# Registry hives /Windows/System32/config/SAM # User accounts /Windows/System32/config/SYSTEM # System config /Windows/System32/config/SOFTWARE # Software config /Windows/System32/config/SECURITY # Security policies /Users/<user>/NTUSER.DAT # User settings # Parse registry with RegRipper rip.pl -r SAM -f sam rip.pl -r SYSTEM -f system rip.pl -r SOFTWARE -f software rip.pl -r NTUSER.DAT -f ntuser # Event logs /Windows/System32/winevt/Logs/ evtx_dump.py Security.evtx # Prefetch /Windows/Prefetch/ # Analyze with PECmd or prefetch-parser # Recent files /Users/<user>/AppData/Roaming/Microsoft/Windows/Recent/ # Browser history /Users/<user>/AppData/Local/Google/Chrome/User Data/Default/History /Users/<user>/AppData/Roaming/Mozilla/Firefox/Profiles/ # USB devices # In SYSTEM registry: USBSTOR key # Shellbags # In NTUSER.DAT and UsrClass.dat
LINUX ARTIFACTS#
# User information /etc/passwd /etc/shadow /etc/group # Login history /var/log/auth.log /var/log/secure /var/log/wtmp # last /var/log/btmp # lastb (failed) /var/log/lastlog # lastlog # Command history /home/<user>/.bash_history /root/.bash_history /home/<user>/.zsh_history # Cron jobs /etc/crontab /var/spool/cron/ /etc/cron.d/ /etc/cron.daily/ # System logs /var/log/syslog /var/log/messages /var/log/kern.log # Network /var/log/apache2/access.log /var/log/nginx/access.log # Persistence /etc/rc.local /etc/init.d/ ~/.bashrc ~/.profile
MEMORY FORENSICS#
# Acquire memory (Linux) sudo dd if=/dev/mem of=memory.img bs=1M sudo lime-forensics/LiME-memory.ko format=lime path=memory.lime # Acquire memory (Windows) # Use DumpIt, WinPmem, or FTK Imager # Volatility 3 vol3 -f memory.img windows.info vol3 -f memory.img windows.pslist vol3 -f memory.img windows.psscan vol3 -f memory.img windows.pstree vol3 -f memory.img windows.cmdline vol3 -f memory.img windows.dlllist vol3 -f memory.img windows.handles vol3 -f memory.img windows.netscan vol3 -f memory.img windows.filescan vol3 -f memory.img windows.registry.hivelist vol3 -f memory.img windows.hashdump # Volatility 2 volatility -f memory.img imageinfo volatility -f memory.img --profile=Win10x64 pslist volatility -f memory.img --profile=Win10x64 psscan volatility -f memory.img --profile=Win10x64 netscan volatility -f memory.img --profile=Win10x64 hivelist volatility -f memory.img --profile=Win10x64 hashdump volatility -f memory.img --profile=Win10x64 malfind volatility -f memory.img --profile=Win10x64 dumpfiles -D output/
NETWORK FORENSICS#
# Capture traffic tcpdump -i eth0 -w capture.pcap tshark -i eth0 -w capture.pcap # Analyze with tshark tshark -r capture.pcap tshark -r capture.pcap -Y "http" tshark -r capture.pcap -Y "dns" tshark -r capture.pcap -T fields -e ip.src -e ip.dst # Extract files from pcap tcpflow -r capture.pcap -o output/ foremost -i capture.pcap -o output/ # NetworkMiner (GUI) # Extracts files, images, credentials from pcap # Zeek (Bro) zeek -r capture.pcap cat conn.log
MALWARE ANALYSIS#
# Static analysis file suspicious.exe strings suspicious.exe strings -el suspicious.exe # Unicode objdump -d suspicious.exe readelf -a suspicious.elf # PE analysis pefile suspicious.exe peframe suspicious.exe pescan suspicious.exe # Dynamic analysis (sandbox) # Use Cuckoo, Any.Run, VirusTotal # YARA rules yara rules.yar suspicious.exe
EMAIL FORENSICS#
# Parse PST files readpst mailbox.pst -o output/ # Parse EML files # Standard text-based format # Headers to examine - Received headers (trace path) - X-Originating-IP - Return-Path - Message-ID - Authentication-Results - SPF, DKIM, DMARC results
MOBILE FORENSICS#
# Android adb backup -all -f backup.ab # Use Autopsy or Oxygen for analysis # iOS # Use libimobiledevice or commercial tools # SQLite databases sqlite3 database.db .tables .schema tablename SELECT * FROM tablename;
REPORTING#
# Document everything: - Chain of custody - Hash values - Tools used - Commands executed - Timestamps - Screenshots - Findings with evidence
TOOLS SUMMARY#
Imaging: dd, dc3dd, dcfldd, FTK Imager, Guymager Analysis: Autopsy, FTK, EnCase, X-Ways Memory: Volatility, Rekall, LiME Network: Wireshark, NetworkMiner, Zeek Carving: Foremost, Scalpel, PhotoRec Timeline: log2timeline (Plaso), Sleuth Kit Malware: YARA, Cuckoo, PEstudio Mobile: Cellebrite, Oxygen, Autopsy