87
1 CNS 320 COMPUTER FORENSICS & INCIDENT RESPONSE Week 3 – LAB #1 Copyright © 2012, John McCash. This work may be copied, modified, displayed and distributed under conditions set forth in the Creative Commons Attribution-Noncommercial License. To view a copy of this license, visit http://creativecommons.org/licenses/by-nc/2.0/ or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.

CNS 320 Week1 Lab

Embed Size (px)

DESCRIPTION

asdf

Citation preview

Page 1: CNS 320 Week1 Lab

1

CNS 320 COMPUTER FORENSICS & INCIDENT RESPONSE

Week 3 – LAB #1

Copyright © 2012, John McCash. This work may be copied, modified, displayed and distributed under conditions set forth in the Creative Commons Attribution-Noncommercial License. To view a copy of this license, visit http://creativecommons.org/licenses/by-nc/2.0/ or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.

Page 2: CNS 320 Week1 Lab

Lab #1: Part 1Physical Imaging W/Helix Edit the SIFT Windows VM and add

another 60GB HD to it. This will simulate a blank disk onto which we will shortly be imaging it.

Change the CDROM drive for the SIFT Windows VM to point to the Helix3 iso file. This will simulate booting it from a CDROM

In the VM options, enable Shared Folders, and share out the drives from the host so you can access files stored there 2

Page 3: CNS 320 Week1 Lab

Edit the SIFT Windows VM

Page 4: CNS 320 Week1 Lab

Click the Add Button

Page 5: CNS 320 Week1 Lab

Select Hard Disk

Page 6: CNS 320 Week1 Lab

Create a New Virtual Disk

Page 7: CNS 320 Week1 Lab

SCSI (Recommended)

Page 8: CNS 320 Week1 Lab

Set Size to 60GB. Other Settings Default

Page 9: CNS 320 Week1 Lab

Default .vmdk Filename

Page 10: CNS 320 Week1 Lab

60GB Drive Now Added

Page 11: CNS 320 Week1 Lab

Now Select the CDROM Drive

Page 12: CNS 320 Week1 Lab

Select ‘Use ISO image file’ and browse to your Helix file

Page 13: CNS 320 Week1 Lab

Go to the Options Tab & Select Shared Folders

Page 14: CNS 320 Week1 Lab

Select ‘Always Enabled’, ‘Map as Network Drive’, and Click Add

Page 15: CNS 320 Week1 Lab

Adding a Shared Folder

Page 16: CNS 320 Week1 Lab

Add Each Drive Separately (Same Procedure for Each)

Page 17: CNS 320 Week1 Lab

Enable

Page 18: CNS 320 Week1 Lab

Shares All Added

Page 19: CNS 320 Week1 Lab

Inside the VM, Your Newly Mapped Folders Will Now Show Up Under Z:\

Page 20: CNS 320 Week1 Lab

VMware Mouse Problem

When Booted from CDROM, VMware detects USB mouse, by default, as USB device rather than mouse Result: You can’t click Fix: With VM shut down, edit .vmx file &

add (or modify) these lines: usb:0.deviceType="mouse“ usb:0.present="FALSE“ mouse.vusb.enable="FALSE"

20

Page 21: CNS 320 Week1 Lab

Open .vmx File in Notepad

Page 22: CNS 320 Week1 Lab

Find These Values

Page 23: CNS 320 Week1 Lab

Replace with these & Save

Page 24: CNS 320 Week1 Lab

To Make Booting into BIOS Easier

Page 25: CNS 320 Week1 Lab

Lab #1: Part 1Physical Imaging W/Helix (1)

Boot the Windows SIFT Kit In VMware Player, hit F2 quickly (this is

difficult with the default settings, see previous slide)

In VMware Workstation, which is on the DePaul Lab systems, you can just click VM -> Power -> Power On to BIOS

Change the boot order to put the CDROM first

25

Page 26: CNS 320 Week1 Lab

In VMware Player, Hit F2

Page 27: CNS 320 Week1 Lab

BIOS Settings

Page 28: CNS 320 Week1 Lab

Right-Arrow Three Times to Tab Over Down-Arrow Twice to Select CDROM

Page 29: CNS 320 Week1 Lab

‘+’ Twice to Move CDROM to Top, F10 to Save & Exit

Page 30: CNS 320 Week1 Lab

Once Helix3 boots, go to Applications->System Tools->Partition Editor

In the upper right, select your new 60GB disk

Device->Set Disklabel Click create Right-click on the unallocated space, click

new, and format the result as fat32 Hit Apply Right click on the new filesystem->mount

on /media/sdc Your newly added disk is now mounted

read/write

Lab #1: Part 1Physical Imaging W/Helix (2)

30

Page 31: CNS 320 Week1 Lab

Helix Boot ScreenHit Enter to Boot into Helix Environment

Page 32: CNS 320 Week1 Lab

Run the Partition Editor

Page 33: CNS 320 Week1 Lab

Select /dev/sdc(Your newly added 60GB Virtual Disk)

Page 34: CNS 320 Week1 Lab

Set Disklabel

Page 35: CNS 320 Week1 Lab

Hit Create to write an MBR Partition Table to the New Disk

Page 36: CNS 320 Week1 Lab

Be Sure You Haven’t Selected /dev/sda or /dev/sdb (That would be bad…)

Page 37: CNS 320 Week1 Lab

Right-click on the Unpartitioned Space, and Hit New

Page 38: CNS 320 Week1 Lab

Change Type for New Partition from Default ext2 to fat32, and Hit Add

Page 39: CNS 320 Week1 Lab

Right-click on New Partition, Select Format to fat32, and Hit Apply

Page 40: CNS 320 Week1 Lab

Right-click on New Filesystem, Select Mount on /media/sdc1

Page 41: CNS 320 Week1 Lab

Run Applications->Forensics & IR->Linen Hit spacebar to begin imaging, then select sda

using the left & right arrows Type /media/sdc1/image_drive_1 as the path for

the image files No alternate path is necessary Case number can be anything. Use 1 Use your name for examiner name Evidence number: ‘1’, ‘C:’ for description Current date, no notes, compress, hash, no

password Total sectors is the default, max file size 2000 The rest are defaults

Lab #1: Part 1Physical Imaging W/Helix (3)

41

Page 42: CNS 320 Week1 Lab

Start the Linen Imaging Application

Page 43: CNS 320 Week1 Lab

Once Linen StartsAll Physical & Logical Disks Are Listed

Page 44: CNS 320 Week1 Lab

Hit Spacebar to Begin Acquisition

Page 45: CNS 320 Week1 Lab

Use Right-arrow to select sda

Page 46: CNS 320 Week1 Lab

Hit Enter, and Type Your Image File Path: /media/sdc1/test_image

Page 47: CNS 320 Week1 Lab

Hit Enter (No Alternate Path is Necessary)

Page 48: CNS 320 Week1 Lab

Enter Case Number (if desired) and Hit Enter

Page 49: CNS 320 Week1 Lab

Enter Examiner Name (Mandatory) and Hit Enter

Page 50: CNS 320 Week1 Lab

Enter Evidence Number (if desired) and Hit Enter

Page 51: CNS 320 Week1 Lab

Enter Description (Mandatory) and Hit Enter

Page 52: CNS 320 Week1 Lab

Current Date Should Populate by Default. Hit Enter

Page 53: CNS 320 Week1 Lab

Notes not RequiredHit Enter

Page 54: CNS 320 Week1 Lab

Enable CompressionHit Enter

Page 55: CNS 320 Week1 Lab

Enable HashingHit Enter

Page 56: CNS 320 Week1 Lab

No PasswordHit Enter

Page 57: CNS 320 Week1 Lab

Total Sectors Automatically Calculated Hit Enter

Page 58: CNS 320 Week1 Lab

Set Max Image Segment Size to 2000 Hit Enter

Page 59: CNS 320 Week1 Lab

Leave Block Size DefaultHit Enter

Page 60: CNS 320 Week1 Lab

Leave Error Granularity DefaultHit Enter to Begin Imaging

Page 61: CNS 320 Week1 Lab

This will work, but it would take a while

61

Page 62: CNS 320 Week1 Lab

Here’s what it looks like completed

62

Page 63: CNS 320 Week1 Lab

Close the Linen window, (cancelling) Then quit out of Helix

Page 64: CNS 320 Week1 Lab

And Restart

Page 65: CNS 320 Week1 Lab

Hit EnterVM will reboot into Windows

Page 66: CNS 320 Week1 Lab
Page 67: CNS 320 Week1 Lab

Login to SANSForensics408with password: forensics

Page 68: CNS 320 Week1 Lab

Windows wants to be activatedHit Cancel

Page 69: CNS 320 Week1 Lab

Close the Software Counterfeiting nag box

Page 70: CNS 320 Week1 Lab

Close the Security essentials nag box too

Page 71: CNS 320 Week1 Lab
Page 72: CNS 320 Week1 Lab

Select your virtual DCROM drive in VMware, and ‘connect’ it

Browse to IR\RAM\Winen and execute winen.exe

Lab #1: Part 2Memory Imaging: Helix/Winen

72

Page 73: CNS 320 Week1 Lab

Enter Parameters as Before

Page 74: CNS 320 Week1 Lab

Lab #1: Part 3Memory Imaging: FTK Imager

Run FTK Imager (desktop icon) Select ‘Capture Memory’ Enter Parameters

Image Path Image Filename

Click ‘Capture Memory’

Page 75: CNS 320 Week1 Lab

Run FTK Imager (desktop icon)Select ‘Capture Memory’

Page 76: CNS 320 Week1 Lab

Enter Parameters

Page 77: CNS 320 Week1 Lab

Click ‘Capture Memory’

Page 78: CNS 320 Week1 Lab

Lab #1: Part 4Logical Disk Imaging: FTK Imager

Run FTK Imager (desktop icon) Select ‘Create Disk Image’

‘Logical Drive’ <Next> Source Drive: C:\ <Finish>

Add Destination Image Type: E01 <Next> Enter Parameters (all values optional) Image Destination Folder: Image Filename:

Windows_SIFT_Kit_First_Logical_Volume Image Fragment Size: 2000 Compression: 9

Click Start

Page 79: CNS 320 Week1 Lab

Run FTK Imager (desktop icon)Select ‘Create Disk Image’

Page 80: CNS 320 Week1 Lab

Select Source: Logical DriveHit Next

Page 81: CNS 320 Week1 Lab

Select Source Drive: C:\Hit Finish

Page 82: CNS 320 Week1 Lab

Add Image Destination, Select E01Hit Next

Page 83: CNS 320 Week1 Lab

Enter ParametersHit Next

Page 84: CNS 320 Week1 Lab

Enter Folder, Filename, Fragment Size, & Compression, Hit Finish

Page 85: CNS 320 Week1 Lab

Hit Start

Page 86: CNS 320 Week1 Lab
Page 87: CNS 320 Week1 Lab

87

Questions?