DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching...

44
DARWINISM VIA FORENSICS 31 March 2019 Bill Dean Senior Manager, LBMC Information Security CCE People Make Dumb Decisions with Today’s Technology

Transcript of DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching...

Page 1: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

DARWINISM VIAFORENSICS

31 March 2019

Bill DeanSenior Manager, LBMC Information Security

CCE

People Make Dumb Decisions with Today’s Technology

Page 2: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

AGENDA

DARWINISM VIAFORENSICS

Digital Forensics Basics

Applicable Case Studies

Pro-Tips Along the Way

This Will Not Be Boring

Page 3: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

DIGITAL FORENSICS BASICS

Recovering/Analyzing Deleted Information

Keyword Searching

Digital Communications

Internet Activities

Pictures/Movies

File Activity

External Storage Usage

Metadata/EXIF Data

Application Execution Histories

Anti-Forensics Efforts

Page 4: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

TECHNOLOGIES WE ANALYZE

Computers

Servers

Memory

Mobile Devices

Cloud Storage

Removable Media

GPS Devices

Watches/FitBits

Page 5: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

DELETED INFORMATION

Page 6: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

DELETED INFORMATION

Page 7: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

KEYWORD SEARCHINGValuable..But Boring

Very Flexible

• Operators (and, or, not)

• Proximity (plum w/5 pear)

Stemming

Fuzzy

Synonym

Page 8: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

COMMUNICATIONSConventional Email

Webmail (Gmail, Hotmail, etc.)

Associated Attachments

Social Network Communications

We will discuss TXT messaging later

Page 9: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

INTERNET HISTORIESTells a Story

We Know What You Are Thinking

Google Keeps Your Search Histories (and more)

We Recover Deleted Internet Histories

We Don’t Care Which Browser You Use

Page 10: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

FACEBOOK CHATSSuspected Affair

Suspect Learned About Investigation

• Cleared All Chat Histories

• Deleted Internet Histories

Didn’t Matter

282 Facebook Chat Messages Recovered

Exactly What Was Suspected

Page 11: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

EMPLOYMENT MATTERWorkplace Injury

“Diminished Quality of Life”

Internet Research

• Condition Symptoms

• Workers’ Compensation Calculators

• Computer Forensics

Personal Pictures

• Vacations

• Orange/White Game

• Lake Activities

Page 12: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage
Page 13: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage
Page 14: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

FILE ACTIVITYCreation

Modification

Accessed

Deleted

Opened

• From Where

Page 15: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

EXTERNAL STORAGE USAGEWe Know Every USB Device Used

• USB Storage

• Mobile Phones

• GPS Devices

• Anything Else

First and Last Times Used

• Sometimes Each time

• And How Long

Model and Serial Number

Page 16: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

EXAMPLE

Page 17: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

EXAMPLE

Page 18: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

INTELLECTUAL PROPERTY THEFT12/22 – Employee Resigned from Company

12/02 – Google Search for “Is ____ a good company to work for?”

12/10 – Copied “Projects” Folder to Desktop

Folder Contained 5000+ Proprietary Designs

Page 19: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

INTELLECTUAL PROPERTY THEFT

12/22 @ 1:10AM – Laptop was powered on

12/02 @ 1:11AM – Laptop recognized USB drive

12/22 @ 1:13 – The “Projects” folder was moved to USB

12/22 @ 2:03 – Laptop was powered off

Page 20: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

APPLICATION EXECUTIONSWe know the first execution date/time

We know the last execution date/time

We know how many executions

We know what user executed the application

Page 21: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

“EASY” TRADE SECRET THEFTEmployee Resigned on May 6, 201x

Google Query “How do I link another email account to Gmail if that other account uses IMAP?”

Copied sensitive information to USB

DropBox installed March 3, 201x

DropBox uninstalled May 6, 201x

Page 22: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

“EASY” TRADE SECRET THEFT

Page 23: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

“EASY” TRADE SECRET THEFT

Page 24: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

“EASY” TRADE SECRET THEFT

Page 25: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

DROPBOX ≠ “EASY” TRADE SECRET THEFTAnalysis of home machine

Business secrets “synchronized”

Copied sensitive information to USB

Copied to USB drive on May 7, 201x

DropBox uninstalled May 6, 201x

Page 26: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

METADATA/EXIF DATA “Information about Information”

• Dates of Creation or Access

• Authors

• Prior Histories

• Editing Histories

• Printing

Email

Spreadsheets

Office Documents

Pictures

Page 27: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

METADATA CASE STUDY #1

Page 28: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

METADATA CASE STUDY #1

Page 29: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

METADATA CASE STUDY #2

Page 30: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

IMAGES – EXIF DATA

Page 31: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

IMAGES – EXIF DATA

Page 32: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

IMAGES – EXIF DATA

Page 33: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

ANTI-FORENSICS EFFORTSEffort to Conceal/Destroy

Most Often Noticeable

Special Programs

System Utilities

Page 34: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

ANTI-FORENSICS CASE STUDY

Page 35: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

ANTI-FORENSICS CASE STUDY

Page 36: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

KLUMB VS. GOANYoung Attorney Marries Established Businessman

We Need to “Monitor” the Children

Speculation of a “Plan”

Page 37: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

http://www.goklg.com/2012/08/01/ex-spouse-hit-with-20k-in-damages-for-email-eavesdropping-klumb-v-goan/

KLUMB VS. GOAN

Page 38: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

DIVORCE GRAND SCHEMEAll Computers Involved

Hundreds of YahooMail! Emails Recovered

Discrepancies of Emails Produced in Discovery

“I don’t have a USB drive”

Conflicting Antenuptual Agreements

http://cyb3rcrim3.blogspot.com/2012/08/eblaster-wiretapping-and-prenup.html

Page 39: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

RUTHLESS BUSINESS PARTNERCompany Ownership Split

Competing Company Knew “Everything”

Thought Offices Were Bugged

Page 40: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

TRIPLE CROWN WINNER11/10 – Employee Dismissed (All Access Not Removed)

1/24 – Someone Connected and “Cracked” Passwords

1/25 – Someone Installed Remote Control Software

• Began Accessing Sensitive Computers

• Began Accessing CCTV Systems

• Accessed Sensitive Information

Page 41: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

TRIPLE CROWN WINNER2/20 – Connected to Computer

• Recovered Passwords

• Accessed Email of

–IT Director

–Purchasing Manager

Placed Online Orders

Searched for More Credit Card Info

Page 42: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

iMESSAGE SYNC = $ DIVORCESuspected Affair

iMessage Communications

Borrowed Son’s iPad

Entire Conversation Synced

Page 43: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

iMESSAGE SYNC = $ DIVORCE

Page 44: DARWINISM VIA FORENSICS - TPIA · Recovering/Analyzing Deleted Information Keyword Searching Digital Communications Internet Activities Pictures/Movies File Activity External Storage

QUESTIONS?

ANY QUESTIONS?

[email protected]

(865) 862-3051

Bill DeanSenior Manager