[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | | Home]

How do I do hard drive forensics?

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 24
Thread images: 6

How do I do hard drive forensics?
>>
>>62435895
You open up the HDD cover and use a magnet to remove the encryption. Then you reformat the drive with easier to read FAT32.
>>
>>62435895
buy a lot of hardware and software products
>>
>>62435925
>open the cover

I don't have a positive pressure clean room.
>>
>>62435895
run
# dd if=/dev/random of=/dev/sda
>>
>>62436005
it worked thanks
>>
>>62436005
I'm not trying to put a pedo in jail.
>>
>>62436055
good to know :^)
>>
>>62435939
Install a window fan.
>>
File: 1465189990053.gif (302KB, 500x500px) Image search: [iqdb] [SauceNao] [Google]
1465189990053.gif
302KB, 500x500px
>>62435895
Depends on what you're trying to do.
Recovery? Forensic analysis?
>>
>>62435895
Use a LiveCD that supports forensics.
>>
>>62436900
I don't know what's in it.

I just know there was a bunch of corporate data written on it.
>>
File: IMG_1375.jpg (164KB, 1200x630px) Image search: [iqdb] [SauceNao] [Google]
IMG_1375.jpg
164KB, 1200x630px
>>62437182
That's hardly informative. Is it busted or not?
>>
>>62437312
Not busted, but wiped.
>>
>>62437320
For future reference, this is known as forensic analysis. What happens next largely depends on two factors: if the wipe was up to NIST standards (STFW for "Guttman Wipe") or simply formatted.

I'd use photorec to take a quick look around if you want to do this casually, or you can take the official route of making a proper forensic image.

Choice is yours, really.
>>
>>62435895
install gentoo
>>
>>62437377
Thanks, anon.
>>
File: ziNh454.jpg (452KB, 1000x709px) Image search: [iqdb] [SauceNao] [Google]
ziNh454.jpg
452KB, 1000x709px
>>62437398
Think nothing of it. A bit of knowledge and usable experience here can be nice when applied properly. What a pity it doesn't happen more often.
>>
>>62435895
what ya do, is put the HDD under the microscope and read the data.
>>
>>62437513
Another interested anon here. What is the "official" route? Just clone onto another disk?
>>
File: narcosa.jpg (341KB, 1376x930px) Image search: [iqdb] [SauceNao] [Google]
narcosa.jpg
341KB, 1376x930px
>>62437565
In a sense. In forensic acquisition, it is absolutely imperative that the contents of the disk do not become modified while in acquisition, transit or storage. While most would rely on a copy of software like Encase to verify this, I would assume hash sums and a block-for-block copy of the disk may be sufficient.

While working with these forensic images, take great care to throw them through a loopback set as read only- it would be like a detective fudging a crucial piece of evidence in a case!
>>
>>62435895
You need a really good microscope. Preferably an electron microscope to see all the little electrons
>>
>>62435895
The tools off kali worked well. I forget the name of the one I used, but it was able to scan a block device for regex strings (SSN, CCN, etc) :^)
>>
>>62437530
I think u mean telescope
Thread posts: 24
Thread images: 6


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]
Please support this website by donating Bitcoins to 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
If a post contains copyrighted or illegal content, please click on that post's [Report] button and fill out a post removal request
All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site. This means that 4Archive shows an archive of their content. If you need information for a Poster - contact them.