Posts

Showing posts with the label Digital Forensics

Chain of Custody: Documentation That Survives a Legal Challenge

Chain of custody is the documented history of a piece of evidence: who had it, when, and what they did with it, from collection until it is presented. It exists to answer one question a defense attorney will certainly ask — can you prove this is the same data you seized, unaltered? If the answer is no, the evidence may be excluded regardless of what it contains. That outcome is the reason the paperwork matters. What the Record Must Contain Every entry documents a transfer or an action: Description of the item — make, model, serial number, capacity, distinguishing marks. "One laptop" is not a description. Who collected it , with date, time including time zone, and physical location. Cryptographic hash of the acquired image, recorded at acquisition. Every transfer — who released, who received, when, and why. Every examination — who accessed it, what was done, what tools were used. Storage conditions between transfers — which safe, which loc...

Order of Volatility: The Collection Sequence That Preserves Evidence

Order of volatility is the rule that evidence should be collected most perishable first . Some data disappears in microseconds, some survives a reboot, some sits on tape for years. Collect in the wrong sequence and the volatile material is gone before you reach it, which is why this is one of the most reliably tested concepts in incident response. The sequence From most to least volatile: CPU registers and cache change with every instruction. In practice they are captured as part of a memory image rather than separately. Routing tables, ARP cache, process table, kernel statistics, and active network connections live in memory and change constantly. The ARP cache expires entries in minutes; network connections close. System memory is the big one. RAM holds running processes, injected code, decrypted data, encryption keys, clipboard contents, unsaved documents, and network activity that never touched disk. It is lost entirely on power-off. Temporary file systems — swap, p...

Journaling File Systems: Crash Consistency and What the Journal Tells Investigators

Writing a file is not one operation. The data blocks are written, the allocation map is updated, the directory entry is created, and timestamps are changed — and a power loss between any two of those leaves the file system inconsistent. Journaling solves this by recording what is about to happen before doing it. The problem journaling solves An interrupted write can leave blocks marked as in use that belong to no file, a directory entry pointing at nothing, or a file whose length does not match its allocated blocks. None of these are detectable without checking, which is why non-journaling file systems require a full consistency scan after an unclean shutdown. That scan walks the entire file system, and its duration scales with size. On a multi-terabyte volume it takes hours — hours during which the system is unavailable, which is the operational argument for journaling quite apart from correctness. How it works Before modifying the file system, the intended changes a...

NTFS Alternate Data Streams: How Files Hide Inside Other Files

Every file on an NTFS volume has at least one data stream — the unnamed one, which is what you see when you open the file. NTFS also permits additional named streams attached to the same file. Their contents do not appear when the file is opened, do not affect the size shown in Explorer, and survive an ordinary copy within NTFS. That combination makes alternate data streams a durable hiding place, and knowing they exist is the difference between finding data during an investigation and missing it entirely. How They Work The syntax is a colon: filename.txt:hidden refers to a stream named hidden on the file filename.txt . Reading filename.txt returns only the default stream. The named stream is reachable only by asking for it specifically. Consequences that matter in practice: Explorer shows the default stream's size. A one-kilobyte text file can carry a fifty-megabyte alternate stream and still look like a one-kilobyte text file. Disk free space changes; the file...

Forensic Acquisition: Write Blockers, Image Formats and Verification

Acquisition is making a copy of evidence that can be shown to be identical to the original and that did not alter it in the making. Everything about the discipline follows from those two requirements, and the techniques are specific enough to be examinable. Physical, logical and targeted Physical acquisition copies the storage device sector by sector, including unallocated space, slack space, deleted file remnants and areas the filesystem does not reference. It is the most complete and produces the largest image, and it is what allows recovery of deleted material. Logical acquisition copies files and folders as the filesystem presents them. Smaller and faster, and it captures nothing deleted and nothing in unallocated space. Appropriate when the question concerns existing documents rather than what someone tried to remove. Targeted acquisition collects specific artefacts — event logs, registry hives, browser history, prefetch data — and is the practical approach at s...

Packet Capture with tcpdump: Filters, Placement, and What Encryption Leaves

Packet capture is the ground truth of network troubleshooting. When the logs disagree and the vendors blame each other, the packets settle it. The skill is not running the tool — it is capturing the right traffic in the right place and knowing what you can still learn when the payload is encrypted. Filters are the whole technique An unfiltered capture on a busy interface produces gigabytes of traffic you will never read. Berkeley Packet Filter expressions applied at capture time keep the file small and the analysis possible. The vocabulary is compact. Filter by host to capture traffic to or from an address, by net for a range, by port for a service, by protocol for tcp, udp or icmp, and by direction with src or dst. Combine with and, or and not. Two distinctions matter. Capture filters are applied by the kernel before packets reach the tool, which is efficient and irreversible — what you filtered out is gone. Display filters in an analysis tool operate on an already-c...

Reverse Engineering Basics: Static and Dynamic Malware Analysis

Reverse engineering a binary means working out what it does without source code. In security work the goal is almost never full comprehension — it is answering specific questions: what does this sample do, what does it talk to, what did it leave behind, and what indicators can I hunt for across the estate. Static analysis Static analysis examines the file without running it, which makes it safe and fast. Start with the cheap signals. The file hash checked against reputation services often identifies a known sample in seconds — though note that submitting a hash discloses that you have it, and uploading the file discloses the file, which matters for targeted samples and internal tooling. Extracting printable strings frequently yields URLs, domain names, file paths, registry keys, error messages, and command fragments. It is crude and it is the highest return per minute of any technique. The file header tells you the format, the target architecture, the compile timestamp...

Steganography: Hiding Data in Plain Sight, and How It Is Detected

Steganography hides the existence of a message. Encryption hides the content . That distinction is the whole topic: encrypted traffic is obviously encrypted and invites attention, while a steganographic payload looks like an ordinary holiday photograph and invites none. The two are complementary, and serious use combines them — encrypt first, then hide the ciphertext. How it works in images The standard technique is least significant bit substitution. A pixel's colour is stored as numeric values, and changing the last bit of each value alters the colour by an amount no eye can perceive. Spread across a photograph's millions of pixels, that yields a substantial hidden payload in a file that looks completely normal. The constraint is the file format. Lossless formats such as PNG and BMP preserve every bit, so the payload survives. Lossy compression recalculates pixel values, which destroys LSB data — so hiding data in a JPEG requires techniques that work within the compre...

Malware Types Part 3: Rootkits, Fileless Malware and Persistence

Part 1 covered how malware arrives and Part 2 covered what it does. This article covers the two problems every attacker must solve after that: staying hidden, and surviving a reboot. Rootkits and the level they operate at A rootkit hides the presence of malware by interfering with what the system reports about itself. What it can hide depends entirely on how deep it runs, and the exam cares about that hierarchy. User-mode rootkits hook application-level functions, so a process or file is missing from a listing produced by normal tools. They are the easiest to write and the easiest to find, because anything querying the kernel directly sees past them. Kernel-mode rootkits load as a driver and manipulate the operating system's own data structures. At that point the system is lying to every tool running on it, including security software, because they are all asking the compromised kernel. Driver signing requirements and kernel integrity protections exist specifically to make...