Wednesday, September 9, 2009

LiveDetector - H11 Digital Forensics

I spent some time testing LiveDetector from H11 Digital Forensics. The program(s) can be run from a CD however, I chose to run it from a USB thumbdrive to allow the output files/report to be exported.

When I first looked at the tool, I noticed that is uses Mantech Memory DD to capture RAM. Although this product captures a nice variety of 32-bit Windows OS's, it is "governed" by a 4GB RAM maximum and I read nothing about it working for 64-bit machines. The GUI is very easy to understand but does not allow for configuration of process (to run). The tool allows you to "Collect Volatile Data" (including or excluding RAM) and "Collect Nonvolatile Data".

Data is exported to a directory defined during the initial screen which allows you to enter case "tombstone" information. Reporting is actually quite nice. Sharp HTML reports with links to report generated by the individually-run apps. The apps are almost exclusively Nirsoft apps.

Overall, the program ran very nice. I'm not sure if the program is at the level that I could recommend it for "forensic" or "incident response" but perhaps for non-evidentiary type data collection. Two other suggestions: consider a more robust RAM acquisition tool and allow a greater degree of configurability ie: allowing user to chose which tools/features to run. .... now that Win32dd has been renamed Windd and supports 64-bit systems. Thanks Matthieu!!
Price: free



Wednesday, September 2, 2009

Accessdata Imager Lite and RAM


Accessdata has recently released it's lite version of Imager, which now has the ability to image RAM - Imager v2.6.1. The full install version came out a while back, but recently they update their lite version. Haven't had an opportunity to test it beyond 32-bit XP, but the free all-in-one product is appealing. Only tools you'll need is forensically clean USB Thumbdrive. Give yourself some room to spare and consider imaging the RAM to the thumbdrive. I'm waiting for information on the memory footprint. Updates like this certainly add polish to v2.2.1 of it's full FTK product which I've recently added to my arsenal. Take my word - it's now worth the upgrade from v1.8.
Next.....speed. I'm really thinking that my new Digital Media card - SanDisk Extreme III -(30MB/Sec) may allow faster acquisition. Certainly faster than my cheap $9 thumbdrive. Time to dig out the benchmark software.

Monday, August 31, 2009

"Click" kiddies

I was doing an assessment today and thought to myself....outside of using our traditional commercial forensic software, what steps has this employee taken to the "why" and "how" the software does what it does.

Have we become too reliant on software that does "what it is supposed to do" or are you routinely validating the software to ensure it's accuracy? It seems to me that the course materials being taught in the SANS Forensic tracks do just that - teach us how to use more of a "grassroot type" forensics whereby we are able to better validate our results.

My conclusion - we need a little bit of both. The commercial software is polished and quite frankly, I don't know if we could keep up without it. That being said, as a Forensic Analyst I believe it is important for us to "question the obvious", "test our theories" and quite frankly, do what we can to disprove our assumptions. Back to basics - when we can answer the 5 "W's" and "how", perhaps we can truly be confident of the integrity of our results.

Saturday, August 29, 2009

Internet Evidence Finder - IEF

Trying a tool from JadSoftware which can be run against a physical drive, or a logically mounted drive (PDE, Mount Image Pro) or a single file (such as a imaged memory, pagefile or hyberfil). Tool now extracts:
  • Facebook Chat
  • Yahoo Messenger Chat
  • Live Messenger Chat
  • GoogleChat
  • Yahoo Mail Chat
  • Facebook Page Fragments
  • Limewire Search History
  • GMail fragments

Output is placed into folders that are created for each type of evidence being searched for. From initial testing, it appears to work quite nice and has even pulled chat that EnCase EnScripts have missed. The program references the physical sector where the chat/fragments, etc are located allowing for a manual verification.

v2.0.1 now released. Price: Free.

Update August 31st, 2009
And v2.0.2 was released today to correct the accuracy of a LimeWire Keyword Search.