Top Banner
No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society of Forensic Computer Examiners
16

No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.

Dec 17, 2015

Download

Documents

Phoebe Lynch
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.

No Nonsense File Collection

Presented by:

Pinpoint Labs

Presenter:

Jon Rowe, CCE, ISFCECertified Computer Examiner

Members:  The International Society of Forensic Computer Examiners

Page 2: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.

Session Objectives

Understanding ESI Collection MethodsTypical ESI Collection Mistakes Improve Vendor SelectionAvoid Client System ModificationsCommon Problems with Existing MethodsDemonstrate Automated Job Process Using One Click Collect

Page 3: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.

Custodial Collections:3 Common ESI Collection Methods

‘Drag and drop’•Alters file timestamps and metadata•No Chain of Custody•Missed search results

Hard drive imaging/cloning•Chain of Custody•Retains file timestamps and metadata•Required for most forensic exams

Remote collection•Creates forensic image or active files only•Can be remotely scripted•Custodians may perform “self collection”

Using the ‘drag and drop’ collection method is common, however, there are several related risks.

Page 4: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.
Page 5: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.
Page 6: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.
Page 7: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.
Page 8: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.
Page 9: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.
Page 10: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.
Page 11: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.
Page 12: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.

ESI Active File Collection

Page 13: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.
Page 14: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.

Incomplete File Collections8 Common Reasons Evidence is Missed

Many active file collection processes don’t:

1) Hash verify file contents2) Copy files in paths greater than 255 characters3) Log files in use4) Easily apply settings across multiple jobs5) Handle Unicode filenames6) Handle network drops or extended outage7) Effectively resume interrupted file copies8) Identify all custodian systems and data sources

Page 15: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.

Custodial Collections:Potential Data Sources

Hard drivesServersBackup mediaEmail serversOther hard drives and email servers in organizationOutside recipients (hard drives, servers, backups)Laptop computersHome computersUSB drives, CD’s DVD’sCell phones, smart phones, PDA’sGPS

Page 16: No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.

Court Recognized Sources:

Sources ranked from most accessible to least accessible for purposes of e-evidence discovery:

Active, online data [on HDD or active network servers]Near-line data [on removable media, optical disks/mag tape]Offline storage/archives [on offline removable media] Backup tapes [not organized for retrieval of individual files] Erased, fragmented, or damaged data [tagged for deletion, but may still exist]