Showing posts with label ief. Show all posts
Showing posts with label ief. Show all posts

Friday, October 22, 2010

Updated Windows Registry and Mac resources & Jad's Software....updated

As several sites have rightfully pointed out....Accessdata has made a huge jump ahead with their recent release of FTK Imager v3.0.  (not to mention FTK 3.2 and their most recent "Volatile tab.")   Just finished testing it today by mounting physical images and using VFC to virtually boot XP and Win7 systems.  Flawless!    While wandering around their site (actually looking for updated RSR files to add to their most recent Registry Viewer version), I stumbled across two additional documents that I believe are very worthy of a good read - or at least printing out as a permanent reference.

Registry Quick Find Chart - a very recently updated 34-page reference documenting Registry locations for the standard 5 Registry files.  The document has a few new columns in the document - one which lists what versions of Windows the reference pertains to (ie: XP, Vista or Win7) and a second column that states when the Registry reference is updated (immediately, when document opened, at logon...)    This document would also be great starting reference to initiate further research on Registry locations and extractable artifacts.  D/L it....know it....print it and keep it handy!

Mac System Artifacts - another reference document which provides 7 pages of Mac Artifact locations.  With FTK's amazing ability to parse out the Mac OS (including Plists), this document is another one to print off.  Updated in 2010.

Jad has also updated three of his applications:
Internet Evidence Finder (IEF) - updated to v3.6 to handle recent updates to Facebook Live chat.  Commercial - Cdn $49.00; Free for Law Enforcement.
FChat - updated to v1.20.    Commercial - Cdn $29.99
FJF - Facebook JPG finder - updated to v1.2.1.  Currently free for use.

Sunday, October 3, 2010

Kindle 3G Wireless Reading Device - forensically speaking

Having just acquired the new model of Kindle, I got to wondering what kind of information was stored on the device and if necessary, how would I go about accessing this information in the most forensically-sound manner possible.  Here's what I found.

1.  Using a Digital Intelligence Tableau Ultrablock USB write-blocker, I connected my forensic computer to the device through the micro-USB cable that was provided with the Kindle. 
2.  Realizing that it was necessary to power on the device, I did so.  I noted the date/time to compare this with the date/time stamps that were likely to change upon boot. 
3.  When powered on, I immediately checked to ensure the 3G/Wireless was turned off.  Select "Menu", toggle the five-way controller up to "Turn Wireless Off" and select the five-way controller (center button).  Alternatively, I could conduct the acquisition within our Faraday tent.
4.   Using FTKImager v2.9.0.5, identified the physical drive attributed to the Kindle.


5.  As noted, the drive recognized as "Kindle Internal Storage" with a size of 3240MB.  I noted that this differs from the stated size of the device (4GB).  Specifically, Amazon states the device has "Storage 4GB internal (approximately 3GB available for user content)."  I then acquired the physical drive as a RAW (DD) format to allow a more robust selection of analysis tools.

Here's what the partition looks like:


And contents of the "documents" directory:


6.  Made note of the filesystem, and VBR header - as noted in the following screenshot.


The filesystem is FAT32, formatted with mkdosfs - DOS formatting within a Linux environment.  From looking at the USER partition which was available, I'm asking whether the SYSTEM partition is ARM Linux Kernel (?).

While admittedly, my Kindle had not been populated with a lot of user interaction, the Kindle definitely does not appear to readily give up information.  It was obvious what books and documents were on my Kindle, and what the last document I accessed was, but as far as other artifacts,  my brief analysis was not overly productive.  I have surfed the Internet, opened several websites and likely populated the device with considerable Internet History.  I could not readily locate any of this history.


Just for heck of it, I through Jad's Internet Evidence Finder at it - nothing.   I'm thinking that a GREP search for Internet History might have more success.  I'm also interesting in running a search for my Wireless Access Point SSID and see what other artifacts might show up.

Other things I found:
- IMEI (3G) information on the device.
-  lots of deleted information.
- a significant number of dictionary terms (including in the unallocated space).

Eric Huber has a posting on the Kindle at A Fistful of Dongles - more great information.

More to come....perhaps I'll see how a boot CD such as Caine interacts with the device.  I'm going to continue to see what the imaged USER image is willing to give up in terms of forensic artifacts.  ps..EnCase will also be involved.

Any thoughts or ideas are welcome.

Friday, November 13, 2009

Internet Evidence Finder - new release and more

Jad from JadSoftware has released v3.0 of Internet Evidence Finder. While the program has now made the move to commercial, I doubt you'll find another tools that is as effective at parsing out artifacts as does this program. The pricing ranges from $29.99 for a single licence, to $129.99 for an unlimited site licence. In the field of forensics, we pay more for add-ons.


I'm not sure where Jad finds the time, but he has added several more features. Included in the 10 new features are Limewire® ver 5.3.6 Search History, Limewire.props files, IE8 InPrivate/Recovery URLs, Yahoo!® Messenger Group Chat, Yahoo!® Webmail email, Hotmail® Webmail email, AOL® Instant Messenger chat logs, Messenger Plus!® chat logs, MySpace® chat, Bebo® chat. He includes an index.htm page to index the some the searches and made several tweaks to the existing searches. The program is FREE for Law Enforcement use (thanks Jad!).

On top of that, he has created another program called Facebook JPG finder (v1.0.0). The program will search for images, and provide details about the date/times of the file, MD5, location, and possible ID/Profile name. He qualifies the program by indicating that the user must realize that the program locates the photo and cannot guarantee the photos are from Facebook.

Oh yeah...those in Law Enforcement and may be looking for an "Incident Response/Live Analysis" scripted tool, head on over to NRDFI.net . They have been kind enough to post the law enforcement version of DriveProphet for free use. I realize that those who consider themselves "masters" of all, this program (an in fact Cofee) can be defined as scripted tools that simply automate the use of other freely available tools. You know WHAT...we aren't all as gifted as others....we occasionally need formatted and trusted tools which we are confident will do the job, in a prompt and efficient time, and punch out a nicely formatted report for our investigations. Maybe it's just me, but I simply cannot recall the commands and switches for 20-50 commands, which I like to run during incident response. FWIW....

Thursday, October 29, 2009

FTK 3.01 and IEF

I realize that there are many who are still sore over the troubles with v2.0 of FTK. But I've been using v3.01 (x64) for a few weeks now, and I'm quite impressed. While there are a few of the nagging issues that continue to annoy me (lack of ability to use "sweeping bookmarks"), the product seems to have integrated several other features that make up for these other small annoyances. First of all, it's MUCH faster. Remember trying to sort a column in v1.8x - no more! The time to sort a column, remove checkmarks, load images.... everything seems to move much faster. I like the integration of Registry reporting, indexed search results and the flexible reporting options. The carving and sorting of files into various categories is impressive. If only you could find a way to make it easier for an investigator to go through thousands of HTML pages in search for emails, banking artifacts, etc!

Admittedly, I installed FTK onto a new clean machine but colleagues in our office have upgraded from v2.0x and are also seeing similar advantages.

My suggestion to Accessdata - more research and whitepapers ie: Vista Registry, more information on using FTK for Mac analysis, etc.

Overall, very impressed by these significant upgrades and improvements.


Also, take a look at Jad's site. He's been busy working on his program, Internet Evidence Finder and has made some significant improvements - now up to v2.07. A quick poll at our last office meeting - over 1/2 of our investigators are using his product. Keep it coming Jad- much appreciated!

Saturday, August 29, 2009

Internet Evidence Finder - IEF

Trying a tool from JadSoftware which can be run against a physical drive, or a logically mounted drive (PDE, Mount Image Pro) or a single file (such as a imaged memory, pagefile or hyberfil). Tool now extracts:
  • Facebook Chat
  • Yahoo Messenger Chat
  • Live Messenger Chat
  • GoogleChat
  • Yahoo Mail Chat
  • Facebook Page Fragments
  • Limewire Search History
  • GMail fragments

Output is placed into folders that are created for each type of evidence being searched for. From initial testing, it appears to work quite nice and has even pulled chat that EnCase EnScripts have missed. The program references the physical sector where the chat/fragments, etc are located allowing for a manual verification.

v2.0.1 now released. Price: Free.

Update August 31st, 2009
And v2.0.2 was released today to correct the accuracy of a LimeWire Keyword Search.