Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 46 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Forensicsarrow DFRWS Challenge 2011
EH-Net
May 25, 2013, 03:47:34 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: DFRWS Challenge 2011  (Read 6418 times)
0 Members and 1 Guest are viewing this topic.
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« on: May 20, 2011, 02:05:09 PM »

For those into foresics:

http://www.dfrws.org/2011/challenge/

Quote
Scenario 1: Suspicious Death

Donald Norby was found dead in his home with a single bullet to the head. It is unclear whether this is a suicide or homicide. The largest question revolves around the victim's potential connections to an organized criminal group called KRYPTIX. You have been asked to perform a forensic examination of Norby’s Android device found at the scene in order to determine his activities and, possibly, who he communicated with prior to his death. Your ultimate goal is to determine whether he killed himself or was murdered and provide any further leads to the investigator.

The device was acquired using what the agent considered to be industry best practices. The device flash storage as well as removable media was collected. See the case specific logs for more information.

I always do these challenges, most of the times just to stay focused. I rarely submit results though. Anyhow, for those looking for challenges or to just get sample data to work with, there are two scenarios there.

*fires up FTK + EnCase* (yes I use both simultaneously to replicate results.
Logged

sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #1 on: May 23, 2011, 10:16:10 AM »

The Quick and the Dead - Android Forensics using nothing but FTK ... Dirty primer, I was bored

http://www.infiltrated.net/droidphorensix/
Logged

lorddicranius
Sr. Member
****
Offline Offline

Posts: 447



View Profile WWW
« Reply #2 on: May 23, 2011, 01:38:37 PM »

I'm not a forensics guy, but that was really fun/interesting to watch Smiley
Logged

GSEC, eCPPT, Sec+
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #3 on: May 23, 2011, 02:33:43 PM »

I chose to do it with FTK because I didn't want to recompile my kernel for yffs2. Also, Encase was being a PITA trying to read the images.
Logged

R3B005t
Newbie
*
Offline Offline

Posts: 43


View Profile
« Reply #4 on: May 24, 2011, 09:11:08 AM »

Sil what version of FTK are you using? Have you gotten your hands on the latest release?  Just wondering what your impressions are..  BTW I love the forensic challenges, hard to stay on top of all of em  Grin
Logged
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #5 on: May 24, 2011, 10:03:40 AM »

I hate the latest versions of both FTK and EnCase. I swap between 1.81.6 and 1.50 (laptop has older, too lazy to upgrade) About to do the entire thing in Linux in a bit.
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.072 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.