Chapter 5 EnCase Concepts.

Slides:



Advertisements
Similar presentations
This workforce solution was funded by a grant awarded under Workforce Innovation in Regional Economic Development (WIRED) as implemented by the U.S. Department.
Advertisements

Guide to Computer Forensics and Investigations Fourth Edition
Guide to Computer Forensics and Investigations Fourth Edition
Guide to Computer Forensics and Investigations Third Edition
Hands-On Microsoft Windows Server 2003 Administration Chapter 6 Managing Printers, Publishing, Auditing, and Desk Resources.
 Temperature sensors are the devices which are used to measure the temperature of an object.  These sensors sense the temperature and generate output.
SOP Standard Operating Procedure This workforce solution was funded by a grant awarded under the President’s Community-Based Job Training Grants as implemented.
C ALCULATING M L/ HR FROM DOSAGE PER KG. 1 ST STEP First, calculate dose per minute. 3 mcg/kg/min x 95.9 kg = mcg/min.
Chapter 9 Computer Forensics Analysis and Validation Guide to Computer Forensics and Investigations Fourth Edition.
Chemical Safety BT 202 Biotechnology Techniques II.
Brush up on Math BCTC Nursing Student Resource Center Renee Felts, RN.
Health Technology Business & Industry Leadership Team Name:______________________________ Company:___________________________ Healthcare: check 1. Patient.
Unit 6 Review Flashcards Unit 6 Review Flashcards ALA: Pre-Algebra Unit 6 Integers.
Subtracting Integers ALA: Pre-Algebra Unit 6 Integers.
Guide to Computer Forensics and Investigations Fourth Edition
Developing a One-Stop Resource Center JoEllen Space, Director Online Programs Community College System of NH.
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Lecture #4 Data Acquisition September 8, 2008.
Unit 4 Review Flashcards Unit 4 Review Flashcards ALA: Pre-Algebra Unit 4 Ratios and Proportions.
Multi-State Advanced Manufacturing Consortium US DOL SPONSORED TAACCCT GRANT: TC23767 RELEASE DATE10/31/2013 VERSIONv 002 PAGE 4_2_c_ _v_002_desired_state_c_nc_registration4_2_c_ _v_002_desired_state_c_nc_registration.
Summer Working Connections Linux+ Virtual Labs Julie Hietschold Tuesday, July 14, 2015.
Greater Than > Less Than Review Greater Than > Less Than Review ALA: Pre-Algebra Unit 1 Whole Numbers.
Using Evaluation and Data To Support Continuous Improvement: Recognizing Key Turning Points COSGROVE & ASSOCIATES BRAGG & ASSOCIATES.
Massachusetts Community Colleges & Workforce Development m Transformation Agenda Transformation Agenda Summer Gathering August 20, 2014 Session 3C: Unveiling.
Exponent Flashcards ALA: Pre-Algebra Unit 6 Integers.
MCCWDTA OER Repository Implementation Barbara Treacy, Education Development Center August 20, 2014 This work is licensed under a Creative Commons 3.0 License.
Work Readiness Program Introduction. Objectives List reasons a person is considered a “Good Employee” List reasons a person is considered a “Good Employee”
Test Taking Skills. Strategies for Mental and Physical Preparation 1. Get plenty of sleep the night before 2. Eat a good breakfast 3. Arrive 5-10 minutes.
MCCWDTA Contextualized Curriculum Regional Meeting Planning for Implementation January 2013.
Summer Working Connections Linux+ Virtual Labs Julie Hietschold Friday, July 17, 2015.
Balancing Act What Reading Teachers Want Writing Teachers to Know and What Writing Teachers Want Reading Teachers to Know.
M ULTI -S TATE A DVANCED M ANUFACTURING C ONSORTIUM _v001_msamc_courseware_quality_ppt _v001_msamc_courseware_quality_ppt5 found in Resources.
Introduction to Medical Terminology. Knowledge how medical terms are built Lots of memorization of the various medical word components Once know the components.
Pumps. PUMP FAMILY TREE CENTRIFUGAL PUMP ADVANTAGES This type of pump is cheaper and requires less maintenance They will operate with a constant head.
Summer Working Connections Linux+ Virtual Labs Julie Hietschold Wednesday, July 15, 2015.
Summer Working Connections Linux+ Virtual Labs Julie Hietschold Thursday, July 16, 2015.
Hands-On Microsoft Windows Server 2008 Chapter 7 Configuring and Managing Data Storage.
Amy Kong Mathematics Faculty. Using Google Hangouts to Enhance Online Teaching.
Pumps. DIAPHRAGM PUMPS DIAPHRAGM PUMP DIAGRAM(cont’d)
Unit 7 Review Flashcards Unit 7 Review Flashcards ALA: Pre-Algebra Unit 7 Algebra.
SURP 2014 – SUMMER UNDERGRADUATE RESEARCH PROGRAM Connecticut Health & Life Sciences Career Initiative is 100% funded by a $12.1 million USDOL Trade Adjustment.
How Might We?. THE VISION: MoHealthWINs is a Transformative Process that Can Help Missouri Lead the Nation in Educational Attainment.
Summer Working Connections Linux+ Virtual Labs Julie Hietschold Monday, July 13, 2015.
This material is licensed under the Creative Commons Attribution 4.0 Unported License. To view a copy of this license, visit
Right Angle Trigonometry MoManufacturingWINs Precision Machining Technology ME 100 – Measurement, Materials & Safety.
MoManufacturingWINs Precision Machining Technology ME 100 – Measurement, Materials & Safety.
Advanced Computer Forensics
EnCase Computer Forensics
Planning your future in a digital world
Presentation on Conversions between English and Metric Systems
Petroleum Instrumentation NGT 160
Contact Jessica Stumpff at for questions
IHUM Statewide Marketing Update
Portland Cement Concrete
SEARCHING, VIEWING AND BOOKMARKING
Advanced Computer Forensics
Chapter 3: Compaction.
Advanced Computer Forensics
P&ID SYMBOLS.
Chapter 3 First Response.
Acing the Job Application
Rigging & Lifting COMPLETION TECHNICIAN Chain Hoist Chain sling Sling
Gas Compression and Flow Dynamics NGT 150
Chapter 10 Nitrogen Rejection Unit
Chapter 2: Soils Investigation
Horizontal Three-Phase Separator
“Information Technology” Certificate
CHFI & Digital Forensics [Part.1] - Basics & FTK Imager
PLACEHOLDER FOR YOUR LOGO
PLACEHOLDER FOR YOUR LOGO
Measuring Devices Technology Readiness Training
Presentation transcript:

Chapter 5 EnCase Concepts

Within EnCase You can: Acquire forensically sound data Search and find data even though a suspect may have tried to hide it or deleted it Transfer/share case analytics with others Produce and manipulate reports Analyze many different file formats and devices Manage large amounts of data

EnCase Evidence File Evidence extension Forensically Sound .E01 – legacy (v6) .Ex01 – current (v7) Stores data differently than v6 Specs on Guidance Software site Forensically Sound MD5 and SHA-1 – physical drive of volume Files as well One or the other, both or none CRC – after every block

EnCase Files - 1 Header Entered by the investigator Administrative information Segment size Number of segments Compressed or not, name, notes and passwords One header per evidence file Automatically compressed even if the evidence is not

EnCase Files - 2 CRC Works like MD5 and SHA-1 Takes less processing power so it is quicker, but there are many less options before a “collision” Most HDs have a CRC per sector. If they don’t match then there is an error (disk error) CRC is present after each data block in EnCase if not compressed If compressed the validation is within the compression/decompression process

EnCase Files - 3 Evidence File Format Exact bit-for-bit copy Information entered by the user is in the header Every byte of each data is verified with CRC Default size of data block is 64 sectors MD5 calculated by default Acquisition hash – physical drive or logical vol. Once created the file is marked read-only SHA-1 option – acquisition SHA-1 Validation of the original written to the last segment of the evidence file Provides a second level of verification

EnCase Automatically Verifies the CRC when evidence is added to a case Re-computes the hash value for the data Acquisition hash values stored in the evidence file and verification hashes which is computed when a file is added to a case Appears in the report Verification at any time Highlight drive or volume – Device->Hash

Ex01 and Lx01 Format Reconstructed how data is stored EV2 Header Data Compression GUID Signature Data Sector / entry / device info Link Record Size of data area Hash value Position of next link record Encryption / Compression flags Type of data CRC

Case File Text file with information specific to a case Pointers to evidence files or previewed devices Searches, keywords, hash and signature analysis results Case files created when EnCase is run Cannot be simultaneously accessed by more than one examiner Default location User Data – should create unique case related folders for all of the pertinent files created for a case.

Backup Scheduled Custom On Demand C:\Users\<username>\Documents\EnCase\CaseBack up (location- can be customized) BaseBackupDatabse.sqlite Case file, Primary EvidenceCache, Secondary EvidenceCache if used, dates/times/sizes of all files and everything in the case folder except: Export folder Temp folder Evidence files

Configuration Files - 1 Default installation settings Specific user settings Global user settings Older version made the user export these New version separates them from the updatable area Saved per user – AppData area for that particular user

Configuration Files - 2 Location Program Files – EnCase Installation C:\Program Files\EnCase7\Config Created by the installer and are NOT modified Remain the same forever User Data C:\Users|<username>\Documents\EnCase User-created files not EnCase version or install specific Backup user data (CaseBackup files, user keys, user created conditions, filters, templates, index, raw searches) User Application Data C:\Users|<username>\AppData\Roamine\EnCase\EnCase7-1 Configuration and user temp files that pertain to a specific user installation folder of EnCase Local.ini, viewers.ini, modification to filetypes.ini

Configuration Files - 3 Location Global Application Data C:\ProgramData\EnCase Contains the files that are for the configuration of EnCase regardless of user NAS Report Template Images Noise Files (for indexing) Shared Files Folder Pointed to a folder where shared files are kept EnScript modules Searches Conditions File types, text styles and keys

Device/Evidence Cache Stares the results of the EnCase Evidence Processor Performs processes Signature analysis Hash analysis Indexing Stores Cache based on GUID GUID associated with each device and/or evidence with the case Default C:\Users\<username>\Documents\EnCase\EvidenceCach e\<GUID of device> Created when evidence is added

Evidence Cache Folder Contains – results for a device Cache Index Evidence Processor \Users\<username>\Documents\EnCase\Evidence Cache\<Hash> (win7 up) \Documents and Settings\<username>\My Documents\EnCase\Evidence Cache\<Hash> Hashes CRC – 32 MD5 – 128 SHA-1 - 160

DOL Disclaimer and CCBY This workforce product was funded by a grant awarded by the U.S. Department of Labor’s Employment and Training Administration. The product was created by the grantee and does not necessarily reflect the official position of the U.S. Department of Labor. The Department of Labor makes no guarantees, warranties, or assurances of any kind, express or implied, with respect to such information, including any information on linked sites, and including, but not limited to accuracy of the information or its completeness, timeliness, usefulness, adequacy, continued availability or ownership. Except where otherwise noted, this work by Central Maine Community College is licensed under the Creative Commons Attribution 4.0 International License.