darwinism via forensics - tpia · recovering/analyzing deleted information keyword searching...

44
DARWINISM VIA FORENSICS 31 March 2019 Bill Dean Senior Manager, LBMC Information Security CCE People Make Dumb Decisions with Today’s Technology

Upload: others

Post on 16-Aug-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

DARWINISM VIAFORENSICS

31 March 2019

Bill DeanSenior Manager, LBMC Information Security

CCE

People Make Dumb Decisions with Today’s Technology

Page 2: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

AGENDA

DARWINISM VIAFORENSICS

Digital Forensics Basics

Applicable Case Studies

Pro-Tips Along the Way

This Will Not Be Boring

Page 3: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

DIGITAL FORENSICS BASICS

Recovering/Analyzing Deleted Information

Keyword Searching

Digital Communications

Internet Activities

Pictures/Movies

File Activity

External Storage Usage

Metadata/EXIF Data

Application Execution Histories

Anti-Forensics Efforts

Page 4: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

TECHNOLOGIES WE ANALYZE

Computers

Servers

Memory

Mobile Devices

Cloud Storage

Removable Media

GPS Devices

Watches/FitBits

Page 5: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

DELETED INFORMATION

Page 6: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

DELETED INFORMATION

Page 7: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

KEYWORD SEARCHINGValuable..But Boring

Very Flexible

• Operators (and, or, not)

• Proximity (plum w/5 pear)

Stemming

Fuzzy

Synonym

Page 8: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

COMMUNICATIONSConventional Email

Webmail (Gmail, Hotmail, etc.)

Associated Attachments

Social Network Communications

We will discuss TXT messaging later

Page 9: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

INTERNET HISTORIESTells a Story

We Know What You Are Thinking

Google Keeps Your Search Histories (and more)

We Recover Deleted Internet Histories

We Don’t Care Which Browser You Use

Page 10: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

FACEBOOK CHATSSuspected Affair

Suspect Learned About Investigation

• Cleared All Chat Histories

• Deleted Internet Histories

Didn’t Matter

282 Facebook Chat Messages Recovered

Exactly What Was Suspected

Page 11: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

EMPLOYMENT MATTERWorkplace Injury

“Diminished Quality of Life”

Internet Research

• Condition Symptoms

• Workers’ Compensation Calculators

• Computer Forensics

Personal Pictures

• Vacations

• Orange/White Game

• Lake Activities

Page 12: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage
Page 13: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage
Page 14: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

FILE ACTIVITYCreation

Modification

Accessed

Deleted

Opened

• From Where

Page 15: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

EXTERNAL STORAGE USAGEWe Know Every USB Device Used

• USB Storage

• Mobile Phones

• GPS Devices

• Anything Else

First and Last Times Used

• Sometimes Each time

• And How Long

Model and Serial Number

Page 16: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

EXAMPLE

Page 17: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

EXAMPLE

Page 18: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

INTELLECTUAL PROPERTY THEFT12/22 – Employee Resigned from Company

12/02 – Google Search for “Is ____ a good company to work for?”

12/10 – Copied “Projects” Folder to Desktop

Folder Contained 5000+ Proprietary Designs

Page 19: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

INTELLECTUAL PROPERTY THEFT

12/22 @ 1:10AM – Laptop was powered on

12/02 @ 1:11AM – Laptop recognized USB drive

12/22 @ 1:13 – The “Projects” folder was moved to USB

12/22 @ 2:03 – Laptop was powered off

Page 20: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

APPLICATION EXECUTIONSWe know the first execution date/time

We know the last execution date/time

We know how many executions

We know what user executed the application

Page 21: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

“EASY” TRADE SECRET THEFTEmployee Resigned on May 6, 201x

Google Query “How do I link another email account to Gmail if that other account uses IMAP?”

Copied sensitive information to USB

DropBox installed March 3, 201x

DropBox uninstalled May 6, 201x

Page 22: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

“EASY” TRADE SECRET THEFT

Page 23: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

“EASY” TRADE SECRET THEFT

Page 24: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

“EASY” TRADE SECRET THEFT

Page 25: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

DROPBOX ≠ “EASY” TRADE SECRET THEFTAnalysis of home machine

Business secrets “synchronized”

Copied sensitive information to USB

Copied to USB drive on May 7, 201x

DropBox uninstalled May 6, 201x

Page 26: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

METADATA/EXIF DATA “Information about Information”

• Dates of Creation or Access

• Authors

• Prior Histories

• Editing Histories

• Printing

Email

Spreadsheets

Office Documents

Pictures

Page 27: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

METADATA CASE STUDY #1

Page 28: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

METADATA CASE STUDY #1

Page 29: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

METADATA CASE STUDY #2

Page 30: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

IMAGES – EXIF DATA

Page 31: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

IMAGES – EXIF DATA

Page 32: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

IMAGES – EXIF DATA

Page 33: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

ANTI-FORENSICS EFFORTSEffort to Conceal/Destroy

Most Often Noticeable

Special Programs

System Utilities

Page 34: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

ANTI-FORENSICS CASE STUDY

Page 35: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

ANTI-FORENSICS CASE STUDY

Page 36: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

KLUMB VS. GOANYoung Attorney Marries Established Businessman

We Need to “Monitor” the Children

Speculation of a “Plan”

Page 37: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

http://www.goklg.com/2012/08/01/ex-spouse-hit-with-20k-in-damages-for-email-eavesdropping-klumb-v-goan/

KLUMB VS. GOAN

Page 38: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

DIVORCE GRAND SCHEMEAll Computers Involved

Hundreds of YahooMail! Emails Recovered

Discrepancies of Emails Produced in Discovery

“I don’t have a USB drive”

Conflicting Antenuptual Agreements

http://cyb3rcrim3.blogspot.com/2012/08/eblaster-wiretapping-and-prenup.html

Page 39: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

RUTHLESS BUSINESS PARTNERCompany Ownership Split

Competing Company Knew “Everything”

Thought Offices Were Bugged

Page 40: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

TRIPLE CROWN WINNER11/10 – Employee Dismissed (All Access Not Removed)

1/24 – Someone Connected and “Cracked” Passwords

1/25 – Someone Installed Remote Control Software

• Began Accessing Sensitive Computers

• Began Accessing CCTV Systems

• Accessed Sensitive Information

Page 41: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

TRIPLE CROWN WINNER2/20 – Connected to Computer

• Recovered Passwords

• Accessed Email of

–IT Director

–Purchasing Manager

Placed Online Orders

Searched for More Credit Card Info

Page 42: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

iMESSAGE SYNC = $ DIVORCESuspected Affair

iMessage Communications

Borrowed Son’s iPad

Entire Conversation Synced

Page 43: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

iMESSAGE SYNC = $ DIVORCE

Page 44: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

QUESTIONS?

ANY QUESTIONS?

[email protected]

(865) 862-3051

Bill DeanSenior Manager