desktop imaging using encase - jurinnov - eric vanderburg

50
Desktop Imaging Using EnCase October 2009 Timothy Opsitnick, Esq Senior Partner Eric A. Vanderburg Manager, Information Systems and Security © 2009 Property of JurInnov Ltd. All Rights Reserved

Upload: eric-vanderburg

Post on 18-Nov-2014

47 views

Category:

Technology


3 download

DESCRIPTION

Desktop imaging using enCase - JurInnov - Eric Vanderburg

TRANSCRIPT

Page 1: Desktop imaging using enCase - JurInnov - Eric Vanderburg

Desktop Imaging Using EnCase

October 2009

Timothy Opsitnick, EsqSenior PartnerEric A. VanderburgManager, Information Systems and Security

© 2009 Property of JurInnov Ltd. All Rights Reserved

Page 2: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Overview• What is a Forensic Acquisition• Why is it done• I’ve Never Done it before! How am I supposed to

do it?

•Please interrupt us if you have a questions

2

Page 3: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

What is Computer Forensics?Computer Forensics is a scientific, systematic inspection of the computer system and its contents utilizing specialized techniques and tools for recovery, authentication, and analysis of electronic data.

Forensic Acquisition is the foundation on which the Forensic examination is set. Without the proper foundation, anything else an examiner does is open to question.

3

Page 4: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

What is Forensic Acquisition?Forensic Acquisition is a specific process to capture every single piece of digital data available on storage media.

It is a bit by bit copy. Every single digital 1 and 0 are capturedIt is not a mirror image nor a clone, although some people think these terms are interchangeable.

4

Page 5: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

An actual clone drive

5

Page 6: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

WHY?Why not just use windows to copy the

files?Special software is used to capture not only

active files (files that are available to the operating system), but deleted files, system configuration data and their associated metadata. Data is preserved unchanged. Special files called image files are created and can be used to clone a hard drive or used directly in an examination. They are easily verifiable, portable and often are standardized between different brands of forensic software. No windows limitations.

6

Page 7: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Logical vs Physical

• Forensic Harvesting - Logical v Physical– Logical

•Data that is visible via the O.S.

– Physical•Logical + File Slack + Unallocated

Space + system areas (MBR, Partition table, FAT)

7

Page 8: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Forensic Tools

8

• Foresnsic Acquistition software include:• EnCase• FTK• WinHex• Ilook• Specially modified Linux software

Page 9: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Acquisition (HOW?)

Cables from Rear of Computer

9

Page 10: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initial Setup

Connect Destination Hard Drive

10

Page 11: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initial Setup

Data and Power Cable from Computer

11

Page 12: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initial Setup

Rear of Hard Drive

12

Page 13: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initialize and Format

13

Page 14: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initialize and Format

14

Page 15: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initialize and Format

15

Page 16: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initialize and Format

16

Page 17: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initialize and Format

17

Page 18: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

DO NOT select dynamic disk!

18

NO

Page 19: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initialize and Format

19

Page 20: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initialize and Format

20

Page 21: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initialize and Format

21

Page 22: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initialize and Format

22

Page 23: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initialize and Format

23

Page 24: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initialize and Format

24

Page 25: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initialize and Format

25

Page 26: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initialize and Format

26

Page 27: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Initialize and Format

27

Page 28: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Create Folder Structure

28

Step 3

Page 29: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

29

Connect Source Drive

Page 30: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

30

Connect Source Drive

Page 31: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

31

Connect Source Drive

Page 32: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

32

Connect Source Drive

Page 33: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

33

Power On Write Blocker

Page 34: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

EnCase-Start New Case

34

Page 35: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

New case dialogue box

35

Page 36: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Add Device

36

Page 37: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Select Local Drive

37

Page 38: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Check the Box for your drive

38

Page 39: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Your Drive will be Added

39

Page 40: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Right Click on your drive

40

Page 41: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Select

41

Page 42: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

NO Compression!!

42

Page 43: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Acquisition Will Start

43

Page 44: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

When completed-Need Log

44

Page 45: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Verify your destination

45

Page 46: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Log will be saved here!

46

Page 47: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

Need to Insure a Match• Presentation Suspect Images• Description: Physical Disk, 39102336 Sectors, 18.6GB • Physical Size: 512• Starting Extent: 1S0• Name: Presentation Suspect Images• Actual Date: 03/24/09 03:17:21PM• Target Date: 03/24/09 03:17:21PM• File Path: E:\Presentation image.E01• Case Number: Presentation Drive• Evidence Number: Presentation Suspect Images• Examiner Name: Stephen W. St.Pierre• Drive Type: Fixed• File Integrity: Completely Verified, 0 Errors

• Acquisition Hash: 5cfa3830c3af83741da4f9adcfb896e1 • Verify Hash: 5cfa3830c3af83741da4f9adcfb896e1• GUID: 04d345276275524c8a111824be6eb170 • EnCase Version: 5.05j• System Version: Windows 2003 Server• Total Size: 20,020,396,032 bytes (18.6GB)• Total Sectors: 39,102,336

47

Page 48: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

What else?

• Photograph• Maintaining Chain of Custody (Data

Storage Location)• Logging• Utilize Sanitized Drives• BIOS/CMOS Time

48

Page 49: Desktop imaging using enCase - JurInnov - Eric Vanderburg

© 2009 Property of JurInnov Ltd. All Rights Reserved

For assistance or additional information

• Phone: 216-664-1100• Web: www.jurinnov.com• Email: [email protected]

[email protected]

JurInnov Ltd.The Idea Center

1375 Euclid Avenue, Suite 400Cleveland, Ohio 44115

49

Page 50: Desktop imaging using enCase - JurInnov - Eric Vanderburg

50

© 2009 Property of JurInnov Ltd. All Rights Reserved