Top Banner
EnCase Direct Network Preview EnCase v7.06 and higher
21

Ecase direct servlet acess v1

Jan 11, 2017

Download

Education

Damir Delija
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Ecase direct servlet acess  v1

EnCase Direct Network Preview

EnCase v7.06 and higher

Page 2: Ecase direct servlet acess  v1

Direct Network Preview

• Direct Network Preview and Acquisition process was introduced in EnCase 7.06 as an option for powered on computers

• It allows the examiner to view the target computer through the EnCase for Windows interface and conduct an examination just as if working from an image.

• Direct Network Preview allows access of data on a target computer system while it is powered on, including • the contents of hard drives connected externally or internally,• removable media,• electronic memory.

• If there is disk encryption on the target system the mounted volumes may be imaged without having to obtain the authentication files or passphrase(s).

Page 3: Ecase direct servlet acess  v1

Direct Network Preview

EnCase ExaminerTarget machines with direct servlet

Page 4: Ecase direct servlet acess  v1

Preparation of the Examiner’s Computer

• A small command-line program must be run on the target computer to enable a connection from the examiner’s computer an servlet.

• Servlet contains an authentication key and authenticate access from the Encase computer system that created the servlet

Page 5: Ecase direct servlet acess  v1

Steps

• Generation encryption key pairs• two files public and private keys are generate

• Creating direct servelet with encryption keys

• Deploying servlets• as service or

• for one go as application

• Accesing remote machine

• Optional removing servlets

Page 6: Ecase direct servlet acess  v1

Generate Encryption Key – 1 step

• Generate Encryption Key – tools dropdown entry

Page 7: Ecase direct servlet acess  v1

Generate Encryption Key - 2 step

• Generation of the keypair

Page 8: Ecase direct servlet acess  v1

Generate Encryption Key – 3 step

• Provide user name and password for keypair• traditionaly user is Examiner

• Don’t forget username and password

Page 9: Ecase direct servlet acess  v1

Generate Encryption Key – 4 step

• Save public key • it is

<username>.PublicKey

Page 10: Ecase direct servlet acess  v1

Creation of the Direct Servlet

• Creation of the Direct Servlet requires encryption keys• In communication

• servlet takes public key,

• private key is used by EnCase

• Each OS needs different servlet code • for some OS there can be more than one servlet file

Page 11: Ecase direct servlet acess  v1

Creation of the Direct Servlet – step 1

• tools dropdown entry -> Create Direct Servlet

Page 12: Ecase direct servlet acess  v1

Creation of the Direct Servlet – step 2

• Choose encryption key• It is essential that public

keyfile is in default position in filesystem so EnCase can use it

• Keypair is defined by username used during key pair creation, • username passoword will

decrypt key files

Page 13: Ecase direct servlet acess  v1

Creation of the Direct Servlet – step 3

• Choose for wich platform you like to have servlets

• Choose in which folder to store servlets

Page 14: Ecase direct servlet acess  v1

Creation of the Direct Servlet – step 4

• Pressing on Finish will create servlets • Windows platform

• „G:\cases\DirectNWPriview\Servlets” folder

Page 15: Ecase direct servlet acess  v1

Windows servlets

• 32 i 64bit version of servlets

• can be in two forms• enstart.exe standalone program

• better for running from USB

• setup.msi as instaler• as a service on target machine

Page 16: Ecase direct servlet acess  v1

Configure the Target Computer System

• One servlet can be installed on many target machines • you can talk only with one servlet in one moment

• Start the servlet• you have to be local administrator

• from usb media - enstart.exe or

• install service setup.exe• option -h option for help

• record IP adress and chek if servlet is running and accessible

• For conecting from EnCase workstation • password, IP address, TCP port info is needed

Page 17: Ecase direct servlet acess  v1

Conneting to servlet – step 1

• Best to open new case for each direct servlet access

• In case select • Add Evidence -> Add Network Preview -> Add Direct Network Preview

Page 18: Ecase direct servlet acess  v1

Choose encryption key - step 2

Page 19: Ecase direct servlet acess  v1

Connect to the servlet – step 3• IP address or machine name with TCP port is needed

machine: COMPUTER19,

port: 4445

Page 20: Ecase direct servlet acess  v1

Choose devices to access on the remote machine

• It is same as other „add device” wizard menu

Page 21: Ecase direct servlet acess  v1

Do forensics

• It is on live remote machine

• At the end do not forget to stop/remove servlet from target machine