Kind of evidence gathered by agents RCS Modules Kind of evidence gathered by agents Is the “tool” of the agent used to gather certain type of evidence Pictures, files, keystrokes, messages, etc. What is a module? One shot modules need to be triggered everytime agent must gather a specific kind of evidence Always-on modules are activated by actions and are working until disabled by an anoter action Types of modules Not all modules are available in every platform and some of them are depending on Desktop or Mobile application Agents manage modules in a best efford form, so will gather the information requested only if its possible Platforms and availability
RCS Modules Desktop When an action starts one of this modules, only one unit of this kind of evidences will be gathered. Agent should activate them as many times as evidence units needs If an action starts one of these modules, it will work until another action stops it Thses are security modules that must be used after conulting with HT support service
RCS One-shot Modules Example: Taking a screenshot every 10 seconds When agent starts working after 10 sec 1st screenshot 2nd screenshot 3rd screenshot …
Example: Taking pictures when Skype starts and stops RCS One-shot Modules Example: Taking pictures when Skype starts and stops When skype.exe stops When skype.exe starts
RCS On-Off Modules Example: Mouse module based on active process When that window is not active When a window with *HSNC* in title is activ
RCS Modules Desktop: Takes a picutere with webcam if available. LED of webcam will blink Mobile: Takes a picture with front and rear camera of the device Camera Quality: Indicates level of JPEG compression of the evidence Camera Settings
RCS Modules Desktop: Processor, Memory, Disks, OS, Application list, … Mobile: Model, Manufaturer, IMEI, IMSI, App list, ... Device Desktop: In Windows and Linux platforms, gather information of Bitcoins, Litecoins, ... accounts in the computer Money Desktop: Gathers wifi hotspots around. Mobile: Gathers Wifi hotspots around GSM cell info and/or GPS Position
RCS Modules Desktop: Takes a copy of whole screeen or on-focus window Mobile: Takes a copy of device whole screen Screenshot Desktop & Mobile: gathers contacts from different applications like mail, chats, Facebooks, phone agenda, etc. Agenda Desktop & Mobile: shows when every application starts or stops Applications
RCS Modules Desktop & Mobile: Presents dates and schedules Calendar Desktop: Records calls on supported applications Mobile: Captures audio* and call information from GSM and apps. Call Desktop & Mobile: Captures every piece of conversation on supported apps as single evidence Chat
RCS Modules Desktop & mobile: gathers text copied to clipboard Clipboard Desktop: Captures path (and content) of files opened by target matching filters of module settings. Files
RCS Modules Desktop & Mobile: Gathers what is typed in keyboard Keylogger Desktop: Captures email messages Mobile: Captures email, SMS and MMS messages. Messages
RCS Modules Microphone Desktop & Mobile: Records surrounding voices Desktop: Takes a picture around every mouse click Mouse Desktop & Mobile: Captures every possible password stored by user Password
RCS Modules Desktop & Mobile: Copy every URL accessed by device browser URL Mobile: Makes a third party call to specified number Conference Mobile: Calls specified number for realtime listening Livemic
RCS Modules Desktop & Mobile: Disable agent functionalities in order to prevent being detected URL