CMIT 424: Digital Forensics Analysis and Application
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
1
Lab 4: Analysis of Partitions, File Systems, and Unallocated Space
WinHex (Specialist License) is a trimmed down version of a very powerful suite of digital forensics software called X-Ways Forensics. In this lab, you will learn how to use WinHex to perform advanced analytical techniques.
One of the limitations of the “Specialist” license is that WinHex will only allow analysis and processing for raw format image files. “Container” files, .i.e. E01, can be viewed in WinHex but, no searching or processing is allowed.
Note: for some processing operations in this lab, an estimated time-to-complete is provided. During times of heavy system loading for the Virtual Lab or if there are significant network delays between your location and the Virtual Lab hosting facility, these times may be significantly longer.
The lab is divided into sections which can be completed independently provided that you save your work products in between sessions.
Guided Practice #1: Converting a Forensic Image File from E01 to Raw Format
In this Guided Practice, you will use FTK Imager to convert a compressed and encrypted forensic image “container” file (E01 format) to an uncompressed and unencrypted format (Raw / dd format) so that you can examine it using WinHex Specialist. The output file(s) will have a numeric file extension beginning with .001. If additional files are needed, the extensions will be .002, .003, etc. To open the set of files containing the raw format forensic image, you will always choose the .001 file. (If you cannot see the file extensions, change your folder view options. Unselect “hide file extensions for known files.”)
1. Create a folder to hold your converted file (C:\Users\StudentFirst\Desktop\Cases\Images) 2. Launch FTK Imager using the short cut found in the “Lab Resources” folder on the Virtual
Lab desktop.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
2
3. Select File > Create Disk Image from the FTK Imager menus
4. In the “Select Source” window, choose “Image File” as your source evidence type. Then click Next.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
3
5. In the “Select File” window, click Browse.
6. In the “Open” window, navigate to H:\Lab Resources\Resources\Lab4 and select file Lab4_USB1.E01. Then click Open.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
4
7. Verify that the correct file is shown under “Evidence Source Selection” in the “Select File” window. Then click Finish.
8. In the “Create Image” window, click Add (under “Image Destination(s)”).
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
5
9. Select “Raw” in the “Select Image Type” window. Then click Next. 10. Click Next in the “Evidence Item Information” window.
You do not need to enter “Evidence Item Information” since this information is not stored with the raw format file and we will not be using the text log file from this acquisition.
11. Click Browse in the “Select Image Destination” window.
12. In the “Browse for Folder” window, navigate to C:\Users\StudentFirst\Desktop\Cases\Images (the folder you created in Step #1). Select the folder then click OK. Note:
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
6
13. In the “Select Image Destination” window, enter “Lab4_USB1” in the “Image Filename (Excluding Extension)” field. Then click Finish.
14. In the “Create Image” window verify that the correct image destination has been set. Then click Start. (Note: you may check “Verify images after they are created” and “Pre-calculate Progress Statistics” if you wish to have status updates during the conversion process.)
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
7
15. The conversion process should take less than 2 minutes. Verify that your file has been created by opening a File Explorer window and navigating the Images folder you created within your Cases folder. You should have two image files in the set: Lab4_USB1.001 and Lab4_USB1.002 (You can ignore the .txt file.)
16. Close FTK Imager and return to the Virtual Lab desktop.
Guided Practice #2: Examination of Partition Structures and Recovery of Lost Partitions
1. Open WinHex using the shortcut icon on the Virtual Lab desktop in the Lab Resources > Applications folder.
2. Close the “Case Data” pane if it is open. We will not be using this feature. To close the pane, go to View > Show in the menus and then uncheck the option for Case Data.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
8
3. Select File > Open from the menu.
4. In the “Open Files” window, navigate to Desktop\Cases\Images then select “Lab4_USB1.001” (You will always choose the first file – .001 – when processing a set of image files in Raw format.)
5. Click Open. WinHex will display the contents of the image file in “raw” format.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
9
6. Using the WinHex menus, select Specialist > Interpret Image File As Disk
7. Review the partition structure shown in the Directory Browser pane. You should see a total of 4 partitions plus 3 regions of “Unpartitioned space” (this is the label that WinHex gives to “inter-partition gaps”). There will also be a region of “Unpartitionable space” (these are the sectors at the end of the physical device which could be allocated to a partition during the re-partitioning operation).
You should also note the partition sizes, file system types (“Ext.” column), sizes (for both partitions and inter-partition gaps), and “1st Sector” information provided by WinHex.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
10
Next, we will scan the image file for “Lost Partitions.” This will update the display in the Directory Browser pane.
1. Using the WinHex menus, select Tools > Disk Tools > Scan For Lost Partitions.
2. In the “Scan For Lost Partitions” window, check the boxes for a. FAT 12, FAT 16, FAT 32, exFAT, NTFS partitions b. Ext2, Ext3, Ext4 partitions c. MBR partition tables d. All
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
11
3. Click OK to start the scan. When it finishes, WinHex will display the results in a pop-up
window.
4. Read the message and then click OK to dismiss the window.
We will not be excluding the newly found partitions at this time. If you needed to do so, you would right-click on the partition name and then select “Exclude” from the pop-up menu.
5. Review the changes in the Directory Browser pane. Note the locations of the new partitions (5,
6, & 7), the type of file system, size, and starting location.
6. Double-click on “Partition 5” to open this partition in a new tab. 7. You may receive a warning message about the length of the image file. Read the message
and then dismiss the pop-up by clicking OK. This type of error could be caused by a
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
12
corrupted boot sector. If the error message stated that the image file was larger than expected, this could indicate that the boot sector had been manipulated to conceal sectors at the end of the disk. This technique can be used to “hide” files and folders” in a place where they could be recovered later (by changing the boot sector).
8. Review the information about Partition 5’s file system structure (in the Directory Browser pane in the new tab).
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
13
9. Click on the (root directory) line to view the contents of the directory in the Contents pane. Note that there is a volume record (“References”) but no directory entries for files. (After you have completed your review of this partition, you may close it using the close box.)
10. Return to the Lab4_USB1 tab. Then, double-click on Partition 6 to open it in a new tab. Dismiss the warning pop-up (image file size warning).
11. Click on the (root directory) line to view the contents. Note that we again have a volume record. In this partition, it shows the name “STUFF.”
12. Repeat steps 10-11 for Partition 7. You should again see a volume record (in the root directory) which shows the name “STUFF.”
13. Return to the Lab4_USB1 tab.
We could continue our manual review of the active and lost partitions for some time. But, there is a quick way to gather much of the required information using a WinHex feature – the Technical Details Report.
14. From the WinHex menus, select Specialist > Technical Details Report.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
14
15. Dismiss the warning message about image file size (click OK). 16. The “Technical Details Report” window will open.
17. Click “Copy All” to copy the report to your clip-board (the Windows “paste buffer”). 18. Close the “Technical Details Report” window and minimize the WinHex window. 19. Switch to the Workspace tab and open Word from the Microsoft Office section. Paste the
contents of the clip-board into this document (control-V).
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
15
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
16
20. Save your document to the Desktop as lastname_Lab4_TechnicalDetails Report.docx
21. Scroll through the document to review the information reported by WinHex for each partition (both Active and “Lost”).
22. Examine the information for “Partition 4.” This was one of the original “active” partitions. The information reported in the Technical Details Report (“File system:”) does not match what is displayed in the Directory Browser pane.
As you scroll through the report and compare the information against the Directory Browser and the contents of the MBR for each partition you will find additional discrepancies. The easy answer is that there is conflicting information in the MBRs and the active / recovered partition tables. Determining how the “corruption” happened would require a substantial amount of low-level analysis and research into the characteristics and behavior of partition editors and file systems for both Windows and Linux.
For this lab, it is sufficient for you to make note in your summary report that the conflicting information exists and that there are multiple indications (warning messages, lost partitions and partition tables) that the drive was repartitioned at least once. You should also note which partitions overlap each other (use the starting – ending sector ranges as reported in the Technical Details Report) and which partitions (“STUFF”) were resized.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
17
23. Close the MS Word window after you have finished reviewing the Technical Details Report. Return to the Virtual Lab desktop.
24. Open HashCalc using the shortcut found in the “Lab Resources” folder on the Virtual Lab desktop.
25. Before starting the HashCalc lab section, click the desktop icon on the taskbar
26. Right click on the detail report document you saved from the previous exercise and select Copy
27. Select WINFOR01 on the taskbar, in the blank area on the desktop, right click and click paste
28.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
18
29. Click the button next to the “Data:” field. 30. In the “Find” window, navigate to the Desktop and select your
lastname_Lab4_TechnicalDetails Report.docx file. Click Open.
31. In the HashCalc window, click Calculate.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
19
32. Select the text in the MD5 field. Then type control-C to copy the text to the clip-board. (Your hash value may be different from the value shown above – use YOUR calculated hash value for YOUR file.)
33. On the WINFOR01 Desktop, right click on the entry for your technical details report document. Select “Rename” from the pop-up menu.
34.
35. Add the MD5 hash value to the end of the filename (before the .docx extension). This will save the MD5 hash value in a convenient place. (Alternatively, you could write the MD5 hash value into your examiner notes.) You will need the MD5 hash value when preparing your summary report for your lab 4 deliverables.
36. Follow the instructions from the link below to transfer your technical details report document to your local PC. You are able to download a file from within your Workspace to
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
20
your physical computer. See instructions below:
• Click Download from the top menu bar (This opens the Desktop folder) • Select the file(s) you want to download or browse to the Desktop to select the file(s) and
click Open • At this point you get the option to select a location on your Personal Computer to save the
files you want to download • Select where you want to save the file and click Save
37. Close any unneeded Windows on the desktop and return to the WinHex window to continue
with the next Guided Practice.
Guided Practice #3: File Recovery and Examination (Data Carving)
Before you Begin
Create a folder to hold the results of your data carving: C:\Users\StudentFirst\Desktop\Cases\ Lab4_WinHex_Export
Data Carving
There are two different ways to perform data carving using WinHex:
a. Tools > Disk Tools > File Recovery by Type b. Specialist > Refine Volume Snapshot
Of the two options, “Refine Volume Snapshot” is the more powerful tool and is the one that WinHex will ask you to use. “File Recovery by Type” could also be used, but the recovered files will be exported to disk. Since we do not know if we have child pornography or other types of materials that should not be copied (e.g. national security or “classified information”), we should start with “Refine Volume Snapshot.” This tool will not export files automatically.
When you select “Refine Volume Snapshot,” WinHex will display a warning that this tool will reset the image and all analysis performed previously (which includes the results of our search for lost partitions). Since we have already saved the technical details report for the lost partitions, the “reset” should not adversely impact our analysis.
1. From the menus, select Specialist > Refine Volume Snapshot. 2. In the “Refine Volume Snapshot: Lab4_USB1” window, select the following options:
a. Take a new one b. Particularly through file system data structure search c. File header signature search
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
21
d. Compute Hash: MD5 (use button to open selection menu) e. Apply selected operations to “all” files
3. Verify your options settings then click OK. 4. In the “File Header Search on Lab4_USB1” window, you will select the file types for the
carving operation. Use the plus sign to the left of the category name to expand it. (Do not check the category box at this time.)
5. Under “Pictures” select the following file types: JPEG, PNG, GIF, and Bitmap. Click the minus sign to collapse the category.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
22
6. Under “Documents” select the following file types: Rich Text Format, MS Office/OLE2, MS Office 2007+, Adobe Acrobat (pdf). Click the minus sign to collapse the category.
7. On the right-hand side of the “File Header Search” window, set your options as follows: a. Filename Prefix: Lab4_ b. Check the box for “Intelligent naming …” c. Check the box for “Always ignore start sectors of known files”
i. Select complete byte-level search 8. "Optional subdirectory of \Path Unknown\Carved files:” Do not change this setting. 9. Review your settings and then click OK to start the data carving operation.
10. WinHex will display a warning pop-up. Read the text in the window and then click OK to dismiss it.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
23
11. Monitor the carving operation using the “File header signature search …” pop-up window.
12. WinHex will display a completion status pop-up window that provides the number of recovered files.
13. As you can see, a large number of “carved” files were recovered. Think back to the Lab 4 lecture and other readings for this lab … remember that not all of the “carved” files will actually be usable files. Many will be false positives.
14. Review the results shown in the Directory Browser pane. After the “Unpartitioned Space” line, you will see a large number of carved files. These are files that were found inside the gap between the start of the media and the start of the first partition. Double-click Carved Files.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
24
15. Next, we will preview the contents of several carved files. Right click on the first carved file Lab4_000001.docx. In the pop-up menu, choose Viewer Programs > Associated Program. This will launch MS Word and display the contents of the file.
16. Next, we want to screen the carved files for child pornography. This is in preparation to exporting the files for easier review using another tool. (We will be randomly checking a subset of the image files in WinHex.) Record this screening in your examiner notes (just in case child pornography is found in the exported files at a later date).
In a forensics lab, we would export the carved files to a hard drive volume (partition) or removable media which could be “wiped” (forensically sterilized) in the event that child pornography (or, in the case of national security investigations – classified materials) were to be recovered and exported.
17. Click on the “Ext.” column to sort the files into groups by file types. 18. Select at least 3 files each in the picture/graphic file types that we carved for: bmp, gif, jpg,
png. Choose files from the beginning, middle, and end of the image. This will serve as your “due diligence” scan for child pornography (which must be conducted before you export files from this image). Make a note of which files (by name) were reviewed and record a general description of the picture or graphic image.
If you find child pornography, contact your instructor and wait for permission prior to exporting any files from this image. (Note: there shouldn’t be any pictures of “cats” or “kittens” but, just in case … we include this warning.)
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
25
19. Next, we will export both a file inventory and the individual files (including the carved files). 20. Select the first file listed in the Directory Browser pane.
21. Scroll down to the last “file” item in the pane. Press and hold the SHIFT key. Then use your mouse (left click) to select the last “file” item in the pane. This should select ALL of the file items, from first to last.
22. Right-click (once) in the Directory Browser pane. From the pop-up menu, choose “Recover/Copy”
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
26
23. In the “Select Target Folder” window, select navigate to your export folder (C:\Cases\Lab4_WinHex_Export) then click OK.
24. Leave the “Recover/Copy” default options selected and click OK.
25. After the export operation completes, WinHex will display the number of files and/or directories which were exported (“copied”). Click OK to dismiss the window.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
27
26. Right click again in the Directory Browser pane. (Your selection region should still be highlighted.)
27. Choose “Export List” from the pop-up menu.
28. In the “Export List” pop-up, choose “TSV” for your export format. Then select “Unicode” and “Clip-board”
29. In the “Fields to output” list, select the following items: Name, Ext., Size, 1st sector. Deselect any other highlighted items. (You will need to hold down the CONTROL key in order to make multiple selections.) Then, click OK.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
28
30. Navigate to the Virtual Lab Desktop. Click the Start icon and open a new Excel spreadsheet (“blank workbook”).
31. Click in cell A1. Then, type control-V to paste the clipboard contents into the spreadsheet. 32. Save the new Excel spreadsheet to the desktop as: lastname_Lab4_FileInventory.xlsx
33. Close your windows for Excel and WinHex. (Ignore any “file in use” errors from WinHex.)
Guided Practice #4: Review & Categorize Exported Files Using EnCase
As you have seen, WinHex has a better (more comprehensive) set of file signatures for use in file carving. But, reviewing the recovered files using WinHex can take a long time. One solution is to split the work between two tools – WinHex and EnCase. In this guided practice, you will load the exported files from your WinHex processing into an EnCase Case. Then, you will be able to use the capabilities of EnCase to quickly review and sort between “forensically important” and “not important” files.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
29
1. Open your WinHex export folder in a File Explorer window (use the Folder icon on the desktop toolbar).
2. Set your viewing option to: Large Icons.
3. Scroll through the displayed icons to quickly preview the file contents.
4. Next, we will load these files into an EnCase case so that we can use its features to reduce our workload for reviewing and categorizing the contents of the exported files.
5. Launch EnCase and click New Case. Before doing this, you may want to create the Lab4 folder under “Cases” - C:\Users\StudentFirst\Desktop\Cases\Lab4
6. Select the below options. If you choose, “enable” backups but understand that there could be performance issues in the Virtual Lab. As described in Lab1, you should routinely “force” a backup from the top level menu bar Case > Case Backup > Use Current Case.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
30
7. Click OK, click “Evidence”. 8. In this exercise, we will add evidence using the “Single Files” option. In order to do this, you
will need to drag the Lab4_WinHex_export folder into the Evidence window. Open Windows Explorer so you can view it along with EnCase.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
31
9. Drag the entire folder into the “Evidence” tab.
10. Now click the Single Files link to open the evidence and expand the folder contents.
11. At this point we can navigate and view the files but in order to fully process, an image file must be created. In order to do this, we will create a logical forensic file of the Lab4_WinHex_export folder and then add that file back into the case.
12. With the export folder highlighted as above, select all the files by checking the box next to the export folder.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
32
13. Then right-click on the export folder under “Entries”, Acquire > Create Logical Evidence File.
14. Fill in the next window with the following information using your name as the examiner. For the output of this file, create a folder beforehand in your “Cases\Lab4” folder named “Images”.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
33
15. Next select the Format tab and change the file format to “Legacy (L01). We are doing this as some other forensic applications do not accept the most current file format from EnCase so this will enhance future compatibility if required. Click OK to create the image file(s).
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
34
16. The .L01 image file should now be placed in the “Images” folder.
11. Uncheck all files in the EnCase Tree Pane under “Entries” and return to the “Evidence” tab. You can also navigate there via “View > Evidence”.
12. From the top menu bar, “Add Evidence > Add Evidence File”. Browse to the newly created .L01 file and add.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
35
13. Browse to the newly created .l01 file, select, and OK.
17. Now in the “Evidence” tab you should see the .L01 image file.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
36
18. To avoid confusion, remove the “Single Files” by selecting the item, right-click, “remove”.
19. Acknowledge ‘Yes” to remove.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
37
20. At this point, processing evidence is like any other evidence item. Click “Process Evidence, Process”.
21. Leave “What to Process” unchanged (one evidence item in this case). 22. Leave “Immediately queue the evidence” selected. 23. Leave the “Processing Options” label unchanged. 24. Under “EnCase Processor Options”, select:
● File signature analysis ● Protected file analysis ● Thumbnail creation ● Hash analysis ● Index text and metadata (expand to include “Personal Information”).
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
38
25. Click OK to process and acknowledge “Yes” to the message.
26. Save your case file (Case > Save) once the processing blue progress bar (bottom right of screen) has completed.
27. From the “Evidence” tab, switch over to the “Entries View” and review the files that are now
ready to be reviewed in EnCase. You can also click the blue evidence name “Lab4 Export Files” to “Open” an item that is selected. As you have probably realized at this point, there are multiple ways to navigate.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
39
28. Homeplate the entry in the Tree Pane and observe to the right all 486 files. Double-click on “Category” for your primary sort. Drag next to the “Names” column if desired. Review the data in the other columns for important information i.e. signature, dates, etc.
29. Do not be misled by the dates and hash values shown in the File List panes. This information was generated by your export operation and does not reflect “true” information about the case.
30. All files that begin with “Lab4_” were generated by the WinHex data carving operation.
Some files will have numeric suffixes. Others have file names that were generated by WinHex using information from the carved file’s metadata (internally stored information).
31. Click the “Gallery” tab and maintain visibility (homeplate) the for Lab4 Export Files
evidence item.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
40
32. Scroll through the Thumbnail images displayed at the top of the window. As you see files that appear to contain forensically interesting information, click on the thumbnail to display the file contents in the bottom View Pane. For example, we see that Lab4_000015.png looks very similar to the “Purple.PNG” file (which had GPS coordinates) from an earlier lab. This file should be marked for further processing so check the entry block for the file (make a note in your examiner notes). Note that you can perform this same procedure in the Table Pane but for graphic files, this is much quicker.
22. Right-click on the filename in the Table Pane. Right-click, “Bookmark”, “Selected Items”.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
41
23. Create a New Folder named “Hidden Information” with Bookmarks highlighted so it does not nest in another default bookmark. Click OK
24. Go to the “Bookmarks” tab (View > Bookmarks) and make sure this item has been
bookmarked properly.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
42
25. Continue scrolling through the thumbnails to review the contents of the pictures/graphics
files. You should find both “adult pornography” (dogs) and “narcotics contraband” (flowers). Make sure to deselect your previous finding(s) or else you may bookmark duplicate items in error.
It is recommended to routinely observe the “Selected” box to know the # of items you are bookmarking before you place in bookmark folders.
26. Go back to the Evidence tab still in Gallery view. Find the first “adult pornography” thumbnail. Click on the thumbnail to select the file. Do this for all the adult pornography graphic files (dogs and puppies). Select each file for bookmarking.
27. Verify that each file does in fact contain adult pornography (by viewing the larger image in the View Pane). To bookmark, right click on one of the selected files or anywhere in the Gallery view, and as before, select “Bookmark” but this time “Selected Files”. Before doing this verify that only 2 files are selected by observing the “Selected” box at the top of the Gallery View.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
43
28. Create a Bookmark folder called “Adult Pornography”, click OK. Make sure the root of
Bookmarks is highlighted to avoid inadvertent misplacement (nesting) of the folder.
29. Go to the “Bookmarks” tab and verify this bookmark is correct.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
44
30. When selecting more than one item at a time (unlike bookmarking a “single item), the examiner can enter comments once the folder has been created in the “Bookmarks” tab.
With the “Adult Pornography” folder highlighted, right-click, “Edit”.
31. Add the comment, “Images of adult pornography (dogs and puppies). Click OK.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
45
32. Note: Now that the “Adult Pornography” bookmark folder has been created, you can always add additional findings throughout the course of your examination as needed. This applies to any created Bookmark folder. Just remember to ensure the correct files are selected, right-click, bookmark, and point to a bookmark folder or create a new one as previously illustrated.
Some examiners go to the “Bookmarks” tab at the onset of an examination and “pre-create” Bookmark folders if they have an idea of what type of files of forensic interest may be located. This may be something to consider for the Forensic Report assignments as you grow comfortable with the application.
33. In the same manner as searching for adult pornography, now conduct a search for “Narcotics”. These are represented by pictures of flowers but do not include any pictures of official seals that may contain flowers. Clear prior selections for adult pornography (uncheck) and select each image displaying narcotics (flowers).
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
46
34. Once all “narcotic” graphic files have been selected, right-click, “Bookmark > Selected Items”. Create a New Folder named “Narcotics”. Click OK and open the “Bookmarks” tab (View > Bookmarks). The tab should still be opened.
35. Once the folder has been added to the Bookmarks tab, highlight the folder, right-click, and
“Edit” the comments tab. Enter “For review, images of narcotics” and OK.
36. Continue adding files to bookmarks until you have processed all the graphic files of interest.
37. Switch to the Table Pane in the “Evidence” tab. View in the “Table Pane” and sort on the “Protected” column. There appears to be 3 files that are using some form of protection (some of which EnCase can circumvent). View the contents of each file in the View Pane
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
47
below. Reminder: uncheck any previous files prior to adding these 3 files to a new bookmark.
38. Select all three protected files and Bookmark as before. Name the Bookmark folder “Protected Files”.
39. Go to the “Bookmark” tab and verify the folder has been created. Right-click, edit, and add
the comment, “For review, files using protection technology”. Note: you also right-click on individual files in the Table Pane to add comments, but this will only apply to that single file. In this exercise, we’ve entered comments at the folder level to apply to all files.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
48
40. Return to the “Evidence” tab and sort all files by the “File Ext” column. Remember to
deselect previous findings first to avoid duplicate bookmarks.
41. There are many types of documents included in the “Category” column. Review the “File Ext” column and focus on “.doc or .doc(x)” extensions. All the documents appear to be “business correspondence” (except for the one that is encrypted and can’t be reviewed). There is also another file, Lab40000023.doc that identified some form of protection but that was already bookmarked under the “Protected Files” bookmark. The remaining files (6) that indicate no form of protection (in the “Protected” Table Pane Column) should be added to a “Business Documents” bookmark.
42. For the “Business Documents” bookmark, add comment “For review, business records.” in the previous manner for the other created Bookmark folders.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
49
Process the remaining file categories by remaining sorted on the “File Ext” column. You should have at least one presentation slide deck and one spreadsheet. Review both of these files to determine if they should be bookmarked and if so, what bookmark category they should be added to or create a new one. Be sure to add a Bookmark comment to each new folder that has been created. Ignore any documents with “openxml” extensions.
There are a large number of .PDF documents (89). There is no need to bookmark any form of government documentation for further review.
As a learning point, choose the four (4) related to Webinar training which could be of relevance but unknown at this point. Bookmark these files, and add a bookmark folder comment “For review, Adobe files” in the same manner (right-click, edit).
In order to enlarge the bottom View Pane images, right-click, and either select “zoom” or the “full screen” option. To exit out of full screen, press “escape” on your keyboard.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
50
After you have finished reviewing files and adding them to categories (bookmarks), you will need to generate a report which presents the results of your analysis. Remember to save and backup your case file.
43. Go to the “Bookmarks” tab and review the seven (7) folders that have been created during this examination.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
51
44. At this point, we will add a section to the Report Template named “Carved File Analysis” and then add each of our custom bookmark folders to this section. To do this, go to “View > Report Templates.
45. Highlight the “Body”, click “New”, and add a section named “Carved Files Analysis”. Click OK (If for some reason “Body” is not available, you can create this section under the root of “Examination Report”
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
52
46. Verify the new report section is now under the “Body”. Then return to the “Bookmarks” tab.
47. From the Bookmarks tab, add each of these folders to the newly created Report Template
section one at a time. As a reminder, highlight the bookmark folder, right-click, and “Add folders to report”.
48. As an example, add the “Hidden Information” bookmark first to the newly created report section seen below.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
53
49. Click “Next”.
50. Select “Customize metadata”. Highlight “Item Fields” and select “Name” and “MD5” from the choices to the right. Move each section over to the display order window via the >> icon (or double-click). Click OK at the bottom of the window when complete.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
54
51. Click “Finish”.
52. Repeat these steps for all other created bookmark folders during this exercise. Be sure to customize the metadata in the same manner.
53. When complete, go to “Reports > Edit Report Templates” to select the correct report
sections to be included in the final report.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
55
54. Once at the “Report Templates” tab, select the “Carved Files Analysis” report section. From the “View Report” drop-down tab, open this section.
55. Review this short report and make note that your name and place for your signature is available at the bottom of each page. As with most reports, the examiner often will first export as a Word document to perform additional edits and comments.
For our purposes, right-click on the report view and “save as” a .PDF document. It should be approximately 4 pages in length. Save the report as “Lab4_GP4_MD hash_yourname”. If needed, review the steps in Lab 2 on how to hash the report file with HashCalc. Note that if an .html report was created, hyperlinks would be enabled from each of the file names to populate an exported copy for the reviewer.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
56
EnCase reporting is very robust and as stated previously could be a class on its own. For this course, focus on creating report sections that can be integrated or attached to the summary report template for the labs and forensic report assignments. You may be wondering why we have not used the bookmark folders that come with the template. The main reason is so the student can learn the granularity of the product and be able to tailor custom bookmarks as needed. The pre-made bookmark folders come with customized metadata that may or may not be wanted. As you become more familiar with the tool, experiment with these folders but always know how to create your own bookmark folders. Another reason is complexity. EnCase report templates can become challenging when trying to tailor results so defining the scope with custom bookmark folders often streamlines the process. As an example, in the report we created we used different bookmark folders depending upon what type of graphic file were discovered. Lastly, the focus of this course is to teach the methodology of the digital forensic process and not spend an absorbent amount of time on formatting reports. Most organizations have their own report templates that are complimented with findings from applications such as EnCase and WinHex.
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
57
Guided Practice #5: Report Writing
In this lab, you learned how to use WinHex to perform low-level analysis of partitioned media including examination of partition tables and how to recover lost-partition tables. You also learned how to use data carving to recover the contents of lost or deleted files including those which occur inside partition gaps or unallocated space. You reviewed the recovered items to determine which files required additional review as part of the case. In your review, you used two different tools, WinHex and EnCase, and learned about the strengths and weaknesses of each tool. You generated two reports and a file inventory to support your summary report for this lab.
During your examination of the evidence file and its partitions, you should have updated your processing notes (“Examiner’s Notes”) with information about the processing which you performed and the information learned from your analysis, i.e. media formats and sizes; partition locations, partition sizes and type of file system installed in each partition; locations and sizes of partition gaps; contents of file system data structures; names, locations, and contents of directories or folders including contents of files contained therein; types, contents, and locations for carved files; names, locations, and contents of files which were of “forensic interest” (business documents, personal documents, pornography, contraband, etc.). You should use these notes while preparing your summary report.
Deliverables
Your deliverables for this lab are as follows:
1. Incident Summary Report (use the Summary Report Template)
In this deliverable, you should provide information about the computer security incident response investigation that you conducted using the image file for Lab 3. You should begin by addressing the computer security incident as presented in the Case Scenario. You should also include information from the “provenance” section of the Case Scenario when writing your summary report. Your report must then provide answers to the case questions and mention where in the evidence the supporting information or artifacts can be found (Partition, inter-partition gap, file paths / names).
Your report must also include information about the specific types of processing which were performed to recover lost partitions and deleted / lost files. You should list all attachments at the end of the report including names and hash values for the files.
2. Attachments a. Technical Details Report (MS Word format) with MD5 hash b. WinHex File Inventory (XLSX format) with MD5 hash c. EnCase Report showing Bookmarks & Graphics (PDF format) with MD5 hash
CMIT 424: Digital Forensics Analysis and Application
Copyright © 2019 by University of Maryland University College. All Rights Reserved.
58
Grading for Lab Deliverables
1. Incident Investigation Summary Report 50% a. Overview 15% b. Findings & Answers to Case Questions 15% c. Description of Analysis & Processing 15% d. Evidence Handling (including use of hash values) 5%
2. Attachments 35% a. Technical Details Report (formatted, MS Word) 10% b. WinHex File Inventory 10% c. EnCase Report 15%
3. Professionalism 15% (formatting, grammar, spelling, punctuation, etc.)
- Lab 4: Analysis of Partitions, File Systems, and Unallocated Space
- Guided Practice #1: Converting a Forensic Image File from E01 to Raw Format
- Guided Practice #2: Examination of Partition Structures and Recovery of Lost Partitions
- Guided Practice #3: File Recovery and Examination (Data Carving)
- Before you Begin
- Data Carving
- Guided Practice #4: Review & Categorize Exported Files Using EnCase
- Guided Practice #5: Report Writing
- Deliverables
- Grading for Lab Deliverables