Hello and welcome to Cyber. My name is Max Alexander, and I'll be your subject matter expert for incident response and advanced digital forensics.
Today, we're gonna pick up where we left off last set of videos and cover the hands on portion of forensics and supported incident response.
So if you watch the last set of videos, we talked a lot about the preparation and process that are involved in doing the forensics portion of incident response. And if you remember from the last set of videos, we talked about the preparation phase, the preservation phase, the collection phase,
and then the reporting,
an analysis of that data.
So the first thing that we're gonna do, we're going to start off with the preparation of all the types of devices hardware and media that we're going to need for our forensic response.
So, in preparation for all this, we're going to want to gather up all of the software, all of the hardware and all of the necessary equipment that we're going to use in our forensic investigation.
And as far as software and hardware are concerned, some of the things that I'm going to show here on how to use and that we're going to use in this demonstration are going to be the access data forensic imager, the in case forensic imager
and the USB right blocker all Windows version 1.3.
Of course, there are other types of software out there. There are also hardware types of right blocker. You can use whichever is familiar with you, but these are some of the programs that were going to use today to do this demonstration.
So in order to get these programs,
you could just open up a window and you could navigate to the access data Web page.
And from there you can click on the digital forensics link.
And then from there it will take you to the current releases of your digital forensic software. And as you can see, they make quite a bit. Some of this software is free, and some software requires a paid subscription to use. We're going to use the F T K imager so you can click on that
and it's gonna give you three options.
You can click on any of these options. They all work fine. There are no issues with that. I am using the F T K version 3.4 point two. For this demonstration, however, you can also download the F K image or light version.
All these programs could be put on your forensic machine. They can also be put onto a thumb drive and used on a victim machine. But to download this, you'll just go to the download page,
and it will give you a link to download this now, and you can install that onto your forensic machine.
Ah, the in case imager is the same
process you could just navigate to the guidance software website guidance software dot com forward slash in case
dash forensic desh imager.
And then you can fill out
your contact information and click submit,
and you will be able to download,
uh, the encase forensic immature onto your
forensic machine. And you can also again download that to a thumb drive for use on your victim machine.
Also, we're going to have the U. S. Feet right blocker, all Windows version
1.3. To get there, you can get to the source porch website
just by typing in the USB right blocker, all windows and a Google search
that will take you to source forge dot net download page,
and you can download that from here,
and it will download, and then you can install that onto your desktop. So those are the three pieces of software that you're gonna use,
But again, also, this software portion is just one part of the preparation days. You're going to want to prepare your camera. You're gonna want to prepare any type of note taking equipment that you're gonna need pens, pencils,
evidence, tags, markers back up to your camera and preparation of any media that you might use in that acquisition process and by media. I'm talking about the SD card in the camera
and or your portable hard drives are thumb drives that you're going to use to start imaging
some of these victim machines that you're going to come across.
So that's what we're going to start with now is the wiping and sanitization
of our forensic media.
So the first part of the process, if you're going to actually insert your thumb, drive into your forensic machine
once you do that, you should see the drive letter pop up mind popped up His drive letter years might pop up. It's something different.
Um, we could just close out of that window
We're going to navigate to are in case
forensic imager. So double what? That? Get these pop up windows. Just click. Yes, I just re installed windows on my machines. Pop ups
I also have passed were set up. So you may or may not have passed. Where?
On your system. If you do, just click. Yes. To navigate through that, you'll eventually get to the incase imager.
eso from here, we're going to click tools.
We're going to go to white dry
and then select next.
And then from there, we're going to see that our drive letter e popped up.
So we have the logical portion and then the physical disk itself. So we're going to wipe the physical desk and we're going to select
and then we will go and click on the next key
from here. It's going to ask you if you want to verify white sectors, leave. That check is yes. And then it's going to ask you what type of characters you want to overwrite all of the data on your media whip. I just leave that as the default zeros.
that's going to ask you.
You want to destroy all information on your device and it's going to force you to type. Yes.
And then you will see a notification down the very bottom right hand corner of the incase imager that says it is wiping.
Eventually that will change to a time. A countdown timer telling you how long left in case is going to be in wiping your device.
So as you can see, I have one hour and 58 minutes left in wiping my device. And this is one of the reasons why you want to have all of your forensic media prepared beforehand because you don't have time to wait around for an hour and 58 minutes
when you're trying to do our forensic investigation. And time is,
uh, very much importance to you.
So I will save you all the trouble.
Have waiting here with me for an hour and 59 minutes to hours
for this thumb drive to be wiped.
Um, we can click on the white
and ask if we want to cancel
for this demonstration. We're going to click? Yes. However, in the field you would not want to do that. You would want for it to be wiped completely. So after that, it's finished y thing.
It will just go back to a blank bar down at the bottom. It won't really give you a notification that the white this complete
the notification will be that there is no more whitening being conducted. But at any event, we're going to cancel the process
However, from here after you, after you get this blank screen when your devices on wiping if you want to actually see what it did,
you can go to the console you
by clicking the application button underneath the in case imager,
uh, name and then go to view
and then scroll down to console.
And then from here, you can see that the incase imager was working. We canceled the process. This is our start, date and time and our stop dating time. This is the elapsed time that ran. It was working on one device and then the total sectors.
And this will tell you the read, write and verify errors If you let this run all the way through completion that will tell you exactly what it did. And if there were any errors, you can also take this and copy it. And if you're doing Elektronik notes,
paste that right over into your notes that what you you can see exactly when you started and stop this process.
Or hopefully you've already had this pre done, and you can verify that the device is wiped, which will go over a little bit later that the full week in verifying the device, we actually have to format it first,
so that is the next part of the process. We will go back
and it's going to tell us we need to format it before we can use it.
We're going to click format disc.
We see that it has a capacity of by 0.8 gigabytes. It will give us an option for the file system X factor in T. F s select expat for fat Possible. That way you can use your device across most operating systems
on not limit yourself to specific operating systems.
You can leave the default allocation size. If you want to label your volume, you can label it