Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 54 guests and 5 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Forensicsarrow Beginner to Security and Forensics
EH-Net
May 24, 2012, 08:07:26 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Beginner to Security and Forensics  (Read 7149 times)
0 Members and 1 Guest are viewing this topic.
darmour
Newbie
*
Offline Offline

Posts: 2


View Profile
« on: October 08, 2007, 02:40:00 PM »

I've been given some new roles within my job that require me to be able to perform digital forensics in case of an investigation.

My boss would like for me to gather and price out the tools required to perform all scenarios of digital forensics.  Right now all I have is a IDE and SATA write blocker and a copy of BackTrak 2 to play with.

Any suggestions would be greatly appreciated to include paid training.  I have looked at Encase as a possible software and training package.

Thank you,

-Damon
Logged
dean
Guest
« Reply #1 on: October 08, 2007, 04:29:37 PM »

Hi darmour,

Look at the HELIX Live CD. It is designed for forensic analysis. It does not automount any drives or touch the swap space in any way. This keeps the entire process forensically sound.

Also check out Brian Carrier's site: http://www.digital-evidence.org/

Another option is the Forensic Toolkit from AccessData. I use both Encase and FTK. Encase's training is very good but specific to their product, I have never taken it though. For training that is less vendor specific check out the SANS 508 Forensics, Investigation and Response Track: http://www.giac.org/certifications/security/gcfa.php It is a very, very good course.

You also might want to check into network forensic products too. Due to all the anti-forensic techniques (check out Metasploit's Timestomp, Slacker, Sam Juicer & Transmorgrify for a few examples) it's often easier to gather network traffic and data to build a case.

dean
Logged
darmour
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #2 on: October 10, 2007, 07:57:30 AM »

Thank you for the information.  I'll check into all those options.

Are there any specific hardware tools I should have in my possession for forensic activities?  I have a dedicated Dell PC for this tasks and the write blockers.  Anything else needed?

Thanks again!

-Damon
Logged
oleDB
Recruiters
Full Member
*
Offline Offline

Posts: 236



View Profile WWW
« Reply #3 on: October 11, 2007, 02:55:45 PM »

Buy and read these books cover to cover
http://www.bookpool.com/sm/0321525647

- http://www.digitalintelligence.com/
- Make sure to keep your dell forensic box in physically secure location and that your media is locked away.
- Depending on what your analyzing, specifically phones and pda's, you may need to buy more hardware for that
- Don't go cheap on storage. You might have to image a raid server one day.
- Download LiveView so you can investigate the image as an interactive VM
- Make sure to write out your forensic process in a document. This is very helpful, because you first you want it to be repeatable and accurate. Second, it helps in court when you have a standing procedure thats used over and over.
- Its common in forensics to use 2 or more tools like FTK and Encase. So you may consider getting both depending on your budget.
- You'll probably want to build a jumpbox full of tools that you can take with you on a moments notice. Many vendors sell these in a complete set.

I've taken the SANS Forensics training and its very good, however if you are going to be using Encase I would recommend getting their product specific training over SANS. Just my opinion, based on the fact that Encase is the mostly widely used product. Not the best, just the most common.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.289 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.