Digital Investigation Scenario

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *

Already have an account? Sign In »

4 hours
Video Transcription
hi and welcome to everyday digital forensics. I'm your host, Justin, he said, Not be guiding you through today. Digital discovery
on today's answer will go through a digital investigation scenario
for fun today work. We will use all the information we learned in the previous videos to find your coworker. For this video, I recommends having a digital physical copy off the current seen throughout as we go through the crime scene, as I will not always be able to display the image that will be using so you before sensitive picture
and you're gonna see which devices
contain forensics information that is useful steps taken for each item identified. Tills methodologies used to acquire forensics images, hardware tools and software programs. This is Ed's desk do coworker heads and working undercover for a Russian hacker. You spoke to Ed no more than half a hour ago.
You seem very anxious. Paranoid
Security reached out to you, reporting that he was connect after seeing two men enter with masks and carry him out unconsciously. He thought that a movie camera and showed you the image. You, his coworker, are the digital forensics investigator for the same PlayStation. What do you do? What do you look for? Once again, this is a scenario.
It's it's desk. He's undercover for a Russian hacker.
You spoke to help by half an hour ago. Security reached out to you to report that he was kidnapped after seeing the two month. So what do you do? And what do you look for? Let's take a look at that crime scene again and see what we can quickly examine for the purpose of his exercise. Once again, I recommend having additional physical coffee off the crime scene. Throughout.
They're about 13 items that I found that can be used for choosed
on used towards our investigation. What are they?
Take out a piece paper, Right. Some town take a minute to know. Take a screenshot
on just kind of identify
about 10 items or more that can be used to find clues based on the information that have given that can be used to find clues about where is that?
So this is what I identified. There may be other items that you have identified, and I definitely welcome suggestions so you can leave a comment or suggestions with your reasoning on the image.
Oh, This is just a quick points out of each objects. One of the items every identified was the desktop computer.
So what do we do with this appear?
Why don't we see that it's on? So we'll go ahead and perform live accusation.
We'll use the hardware where Gawker set up to prevent any files from running any malicious exodus. Any malicious scripts or anything that might run. We use the right box, forgot it. Taken account of open and accessible programs. Maybe add left recent eating house
a photo
in this image as a fingerprint. It could have been a identification of someone who was tracking capture volatile data. We don't know what he's saved in his brand memory. My memory can actually store information from your clipboard. So took board. We have a collection of cash and I'll data such as print jobs.
And, of course, the computer can identify what browser history overall user files, documentation, images.
I am email or social media data, but and communications that might make us a source
on anything that is connected to the device, like the U. S. Feet.
So this is the reason why we would choose the
the death.
Well, you saw for, like, abdicate imager on a case to run the
and make sure that we create duplicates all the original copy. We perform only actions on the duplicate copies. As part of the investigation process, we want to ensure that the original image we want to make sure that the original images not tampered with during the accusation
And make sure you document the documentation has see reproducible this way. If it set up in the court and all they can follow your steps and come with same sources and data always include information on, sir see searches that you wanted to perform,
which once you did perform their results and which ones you did not perform.
And for what reason?
That is an overview of what can be accomplished on me computer itself.
The Peter was my first choice because there's so much to it. This is a digital friends ex course, and most of it is tended around
biosystems and data that you can pull from a computer laptop that stop sort of thing. Our next is a cell phone. We have image accusation of it. There might be a second way to authenticate, but maybe even try and figure out his pen
were We have a copy of this rare something we can do to get into his phone and figure out if are actually able to access. He did mobile device. We can pull things like recent calls, text message.
If location it saves, we can go to Google Maps history.
Find where they've been.
We have what browser history and data within the phone And, of course, more apt data such as email, banking and social media. Once again, you would handle cell phone saying where you would handle the test. You will make sure it if it's live,
you connect as much data as you can.
Cell phone. Tough box. If the computer signs out,
it's gonna be more difficult for you to access. The information 100 is more open. Source. Toe Under is more accessible with the information side. Iowa's has more layers of protection. The original image enabled it as a watch, but I'm they were gonna ask Smartwatch just because when it's an aged at foreign watches to exist,
so smart watches can help
use a determined ownership. It may not be ads,
watch and maybe someone else's. Let's see if we can actually pull
some kind of forensic. Some biological forensics evidence off of a legitimate who? It iss uh, if it's a smartwatch to determine ownership is the case with any watch. With the Smartwatch, you may be able to access location,
some phones and some watches. Have a two by two connection to figure out where it is like looking my phone looking. My watch. We have Communication channel. Some people keep text messages media on their watches, and investigators may have
use your time accessing a smartwatch that it will try accessing a cell phone with a pin. If the device is Andrew, you can always enable a ZB for debugging
on the show. You able to see data cache system an SD card if one is applicable.
This is information that you receive from the site. Watch itself
up. Next is the voice over I p telephone. This you can just saying recent calls, contact information. Maybe you see a number that's repeated itself over and over. God, you could also say there's voicemails left over if you're able to access it or know his 10 contact. Last known numbers from this is just a small little
information as they go into other items.
The reasoning may be smaller, smaller, so you want to make sure that you prioritize your time and focused on the items that will produce more data. Possible
USB stick A USB stick is interesting. If it's connected to the laptop, you would run it as a live acquisition. You would verify that there's nothing running, and they used to be that may be communicating with a not set. So where's
you would isolate itself as well as make a copy of within the You escape
and work on only the copy, so use B will contain recent documents. It could be clues to find recent months or years within Windows, you could look into the registry and see recent devices that were connected. You can also find additional media files,
the guesthouse registering may sure that, you see it was Russi mount, depending on the information within the use fees, depending on whether or not you would categorize it as evidence.
We have his I. D card and his task board.
These two were kind of combined together as they're just a form of identification
the passport in seeing recent troubles.
photos, some kind of thing to identify the person in question. Both idea and password. Haven't image. So you can use that for identification,
body height and the photo,
The gun and the bullet is another portion of France six. We're not getting into this in this class,
but fingerprints, serial numbers.
Gunnar industry
was the gun recently shot was Was that weapon belonged to end? Does that working belonged to Heavy is that weapon belonged to any recent cases that at work you can use these kind of questions to relate whether that object
isn't evidence for your case.
Next object is his board. His board has sticking out. It has joined a connection, Sean, information that he's gathered
his research.
So within the board itself, you can find Cruz investigation.
Some of the documents may have been printed with the printed nearby. So within the test stop, you could find temporary. If I was an instrumental data document metadata that might correlate to when it was printed.
This one, I won't die too much into it. It's confidential documentation. Make sure you have a clearance, but it could contain case information suspects may be linked to these cases. It's kind of a point for you to review up next. So simply bag it could be from a recent gather
linked to one of the confidential documentations or something that you find within one of the other objects that you're searching for. Evidence.
These are recent notes would be pictures, maybe quotes, something that may give you a clue or even linked to some kind of document.
In today's reflection, we took crime scene investigation Photo identified, evidence on their types, discussed process and steps for accusation,
coronated independent evidence to look for additional evidence.
This is the notebook, the USB, the documents on the board,
the confidential information.
They're independent evidence. However, they could all relate to one case. So something on the board, something within the UC and something written in his notebook could be not too much. But we touched upon some tools and methodologies to be used within the vest IG ation process of this scenario. That's it for module one.
Yes, I want to thank you for watching this video
and future good usable
go into how to perform live and sad accusations. What happens when you delete a file performing data carving and this Senna graphic
techniques of extracting and importing hidden information within an image out of property. Check and execute malicious files
if foreign professional tools at both of beginner and in defense up.
So once again, thank you for watching and I'll catch the next one.
Up Next