RE: P2V - Live Forensics
David Howe <[email protected]> Wed, 2 Mar 2011 09:36:09 +0000
| Newsgroups | gmane.comp.security.forensics |
|---|---|
| Message-ID | <[email protected]> |
Ah, but I didn't. That's the good bit - you alter the drive before the user= ever brings it in, and the chain of evidence only needs to start once it i= s on your desk. You need never admit or even mention that you broke it in t= he first place. Your "investigation" starts when the user brings in a non-b= ooting device, and whatever happened before that isn't your problem :) You only correct the copy to boot again, the original stays intact (and if = you want one to play with, you make a second copy for that). -----Original Message----- From: Paul Schmehl [mailto:[email protected]]=20 Sent: 28 February 2011 16:59 To: Dave Howe; [email protected] Subject: Re: P2V - Live Forensics --On February 22, 2011 10:18:52 AM +0000 Dave Howe=20 <[email protected]> wrote: > On 15/02/2011 15:13, [email protected] wrote: >> Ladies, Gentlemen, and otherwise: >> >> I have a situation whereby I need to obtain an image of an individual's >> laptop suitable for potential prosecution in a US court; however, I only >> have a limited window in which to grab the image, and was looking for >> alternatives in order to not "spook" the poor guy or his co-workers who >> would no doubt tell him about me, as I go into his office and randomly >> image his drive! > > Here's one I have done in the past. > Use psexec, mapped drives, whatever to gain access to the machine while > running. rename ntldr to something else - next time the machine shuts > down, it won't come up again. > > User screams, brings in machine for maint > Very clever, but it will cause you problems in court. You altered the=20 drive before you removed it. Can you prove you didn't alter anything else?= =20 If not, your image isn't forensically sound and won't hold up in court. To obtain a forensically sound image, you need to capture the drive, either= =20 physically or over the network, without making any changes to it. You also= =20 need to be able to prove that the image is identical to the drive you=20 captured, which means the md5 sum checks out and the image needs to be=20 read-only --=20 Paul Schmehl, Senior Infosec Analyst As if it wasn't already obvious, my opinions are my own and not those of my employer. ******************************************* "It is as useless to argue with those who have renounced the use of reason as to administer medication to the dead." Thomas Jefferson "There are some ideas so wrong that only a very intelligent person could believe in them." George Orwell =20 David Howe Technical Analyst T:0161 227 1010 F:0161 227 1020 E: [email protected] =20 Disclaimer The information contained in this communication from [email protected]= .uk sent at 2011-03-0209:36:33 is confidential and may be legally privilege= d. It is intended solely for use by [email protected] and others = authorised to receive it. If you are not [email protected] you ar= e hereby notified that any disclosure, copying,distribution or taking actio= n in reliance of the contents of this information is strictly prohibited an= d may be unlawful. ANS Group Plc Terms & Conditions apply, all prices are s= ubject to VAT, expenses excluded,E&O,E.=20 ANS Group Plc 2010, Registered Office is Synergy House, Manchester Science = Park, Manchester, M15 6SY. Reg No. 3176761. (Registered in England & Wales) ----------------------------------------------------------------- Certify Software Integrity - thawte Code Signing Certificates This guide will show you how Code Signing Certificates are used to secure code that can be downloaded from the Internet. You will also learn how these certificates operate with different software platforms. http://www.dinclinx.com/Redirect.aspx?36;5000;25;1371;0;2;946;005be7f5c872ea1f