30
Damir Delija, Dr.Sc.E.E. Davorka Foit, mag.ing.inf. et comm.techn. 22. October 2013, LTEC Prague EnCase Forensic Digital Forensic Tool

LTEC 2013 - EnCase v7.08.01 presentation

Embed Size (px)

DESCRIPTION

LTEC 2013 - EnCase v7.08.01 presentation supposed to be workshop but machines were missing so it was turned into live presentation

Citation preview

Page 1: LTEC 2013 - EnCase v7.08.01 presentation

Damir Delija, Dr.Sc.E.E.

Davorka Foit, mag.ing.inf. et comm.techn.

22. October 2013, LTEC Prague

EnCase Forensic

Digital Forensic Tool

Page 2: LTEC 2013 - EnCase v7.08.01 presentation

2

EnCase Forensic

Leading digital forensics tool• www.guidancesoftware.com

Accepted as a standard tool in the

judiciary

A large number of court rulings and

procedures in which EnCase was used

It is not necessary to be a computer

expert to carry out a standard

investigation with EnCase

EnCase Forensic – Digital Forensic Tool

Page 3: LTEC 2013 - EnCase v7.08.01 presentation

3

Goal

The goal is to provide EnCase Forensic

hands-on in real usage scenario

Scenario:• There is a search warrent which defines what has to be

done and how

• EnCase Forensic will be used

• Evidence is real

EnCase Forensic – Digital Forensic Tool

Page 4: LTEC 2013 - EnCase v7.08.01 presentation

4

EnCase – main screen

EnCase Forensic – Digital Forensic Tool

Page 5: LTEC 2013 - EnCase v7.08.01 presentation

5

Writeblocker enabling

EnCase Forensic – Digital Forensic Tool

Page 6: LTEC 2013 - EnCase v7.08.01 presentation

6

Disk adding

EnCase Forensic – Digital Forensic Tool

Page 7: LTEC 2013 - EnCase v7.08.01 presentation

7

Disk view - writeBlocked

EnCase Forensic – Digital Forensic Tool

Page 8: LTEC 2013 - EnCase v7.08.01 presentation

8

Aquisition – creating disk

image

EnCase Forensic – Digital Forensic Tool

Page 9: LTEC 2013 - EnCase v7.08.01 presentation

9

Forensic disk image

EnCase Forensic – Digital Forensic Tool

Page 10: LTEC 2013 - EnCase v7.08.01 presentation

10

EnCase case folder

structure

EnCase Forensic – Digital Forensic Tool

Page 11: LTEC 2013 - EnCase v7.08.01 presentation

11

Evidence processor –

automatic processing

EnCase Forensic – Digital Forensic Tool

Page 12: LTEC 2013 - EnCase v7.08.01 presentation

12

Main case screen

EnCase Forensic – Digital Forensic Tool

Page 13: LTEC 2013 - EnCase v7.08.01 presentation

13

Disk view – Tree table view

EnCase Forensic – Digital Forensic Tool

Page 14: LTEC 2013 - EnCase v7.08.01 presentation

14

Images – Gallery view

EnCase Forensic – Digital Forensic Tool

Page 15: LTEC 2013 - EnCase v7.08.01 presentation

15

Evidence processor –

automatic processing

EnCase Forensic – Digital Forensic Tool

Page 16: LTEC 2013 - EnCase v7.08.01 presentation

16

Images found

EnCase Forensic – Digital Forensic Tool

Page 17: LTEC 2013 - EnCase v7.08.01 presentation

17

Image tagging – table view

EnCase Forensic – Digital Forensic Tool

Page 18: LTEC 2013 - EnCase v7.08.01 presentation

18

Tagging of found evidence:

which tag to use

EnCase Forensic – Digital Forensic Tool

Page 19: LTEC 2013 - EnCase v7.08.01 presentation

19

Timeline view

EnCase Forensic – Digital Forensic Tool

Page 20: LTEC 2013 - EnCase v7.08.01 presentation

20

Bookmarking of found

evidence

EnCase Forensic – Digital Forensic Tool

Page 21: LTEC 2013 - EnCase v7.08.01 presentation

21

Preliminary report

EnCase Forensic – Digital Forensic Tool

Page 22: LTEC 2013 - EnCase v7.08.01 presentation

22

Raw search

EnCase Forensic – Digital Forensic Tool

Page 23: LTEC 2013 - EnCase v7.08.01 presentation

23

Search – keyword definition

EnCase Forensic – Digital Forensic Tool

Page 24: LTEC 2013 - EnCase v7.08.01 presentation

24

Search results

EnCase Forensic – Digital Forensic Tool

Page 25: LTEC 2013 - EnCase v7.08.01 presentation

25

Conditions- metadata

search

EnCase Forensic – Digital Forensic Tool

Page 26: LTEC 2013 - EnCase v7.08.01 presentation

26

Index search

EnCase Forensic – Digital Forensic Tool

Page 27: LTEC 2013 - EnCase v7.08.01 presentation

27

Search results consolidated

EnCase Forensic – Digital Forensic Tool

Page 28: LTEC 2013 - EnCase v7.08.01 presentation

28

Reporting

EnCase Forensic – Digital Forensic Tool

Page 29: LTEC 2013 - EnCase v7.08.01 presentation

29

Case backup and archive

EnCase Forensic – Digital Forensic Tool

Page 30: LTEC 2013 - EnCase v7.08.01 presentation

30

Questions

EnCase Forensic – Digital Forensic Tool

[email protected]

[email protected]