Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 79 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Forensicsarrow DFRWS Challenge 2011
EH-Net
May 26, 2012, 06:00:35 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: DFRWS Challenge 2011  (Read 4171 times)
0 Members and 1 Guest are viewing this topic.
sil
Hero Member
*****
Offline Offline

Posts: 536



View Profile WWW
« on: May 20, 2011, 02:05:09 PM »

For those into foresics:

http://www.dfrws.org/2011/challenge/

Quote
Scenario 1: Suspicious Death

Donald Norby was found dead in his home with a single bullet to the head. It is unclear whether this is a suicide or homicide. The largest question revolves around the victim's potential connections to an organized criminal group called KRYPTIX. You have been asked to perform a forensic examination of Norby’s Android device found at the scene in order to determine his activities and, possibly, who he communicated with prior to his death. Your ultimate goal is to determine whether he killed himself or was murdered and provide any further leads to the investigator.

The device was acquired using what the agent considered to be industry best practices. The device flash storage as well as removable media was collected. See the case specific logs for more information.

I always do these challenges, most of the times just to stay focused. I rarely submit results though. Anyhow, for those looking for challenges or to just get sample data to work with, there are two scenarios there.

*fires up FTK + EnCase* (yes I use both simultaneously to replicate results.
Logged

sil
Hero Member
*****
Offline Offline

Posts: 536



View Profile WWW
« Reply #1 on: May 23, 2011, 10:16:10 AM »

The Quick and the Dead - Android Forensics using nothing but FTK ... Dirty primer, I was bored

http://www.infiltrated.net/droidphorensix/
Logged

lorddicranius
Sr. Member
****
Offline Offline

Posts: 396



View Profile WWW
« Reply #2 on: May 23, 2011, 01:38:37 PM »

I'm not a forensics guy, but that was really fun/interesting to watch Smiley
Logged

sil
Hero Member
*****
Offline Offline

Posts: 536



View Profile WWW
« Reply #3 on: May 23, 2011, 02:33:43 PM »

I chose to do it with FTK because I didn't want to recompile my kernel for yffs2. Also, Encase was being a PITA trying to read the images.
Logged

R3B005t
Newbie
*
Offline Offline

Posts: 43


View Profile
« Reply #4 on: May 24, 2011, 09:11:08 AM »

Sil what version of FTK are you using? Have you gotten your hands on the latest release?  Just wondering what your impressions are..  BTW I love the forensic challenges, hard to stay on top of all of em  Grin
Logged
sil
Hero Member
*****
Offline Offline

Posts: 536



View Profile WWW
« Reply #5 on: May 24, 2011, 10:03:40 AM »

I hate the latest versions of both FTK and EnCase. I swap between 1.81.6 and 1.50 (laptop has older, too lazy to upgrade) About to do the entire thing in Linux in a bit.
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.186 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.