The Most/Recent Articles

Showing posts with label triforce. Show all posts
Showing posts with label triforce. Show all posts

Daily Blog #693: Patent Powered

SANS Webcast and PFIC Slides/Labs

SANS Webcast and PFIC Slides/Labs by David Cowen - Hacking Exposed Computer Forensics Blog


Hello Reader,
        If you attended my session at PFIC hopefully you already took these labs with you, if not I'll be linking them down below. For those of who attended my SANS webcast today I hope you found it useful! Now you can try it yourself.

If you didn't attend either I'll explain what's contained within. I presented on how to do USN Journal Analysis using the free version of our tool Triforce ANJP to:
  • Recover the names of wiped files
  • Prove what was uploaded and downloaded from Dropbox
  • Show what attachments were accessed from Outlook 2007 and greater
and more analysis tips. Hopefully you'll find it helpful!

Link to SANS webcast:
https://www.sans.org/webcasts/hands-on-usn-journal-analysis-99177

First here are the slides from today's webcast:
https://mega.co.nz/#!WgwhmKYb!JhwWvGLlug9T0yCU6dlR29S23fx0up2M_LL3Aml6q24

Link to download the sample evidence to do the labs from today's webcast:
https://mega.co.nz/#!3pwmDLzZ!IFUw9rBm2-0Kryu_ASBxKIcFnQSdCNQl7uRyG4DpHvQ

Download Triforce ANJP here:

Link N/A



Triforce at Blackhat Arsenal

Triforce at Blackhat Arsenal by David Cowen - Hacking Exposed Computer Forensics Blog

Hello Reader,
          It's been a bit I know, I've enjoyed my brief time off from blogging which coincided with a lot of work! I am heading to Blackhat today and I am excited to say that I will be at Blackhat Arsenal on Wednesday 8/6/14 showing Triforce ANJP Commercial edition from 10:00am-12:30am. If you are going to be there I hope you come by and say hi if nothing else. We are working a lot of new features that I'll be demoing such as:

  • Support for Carved USN Journal Entries
  • Support for forensic images
  • Support for journals over 400gb in size
  • Faster processing
  • More signatures!
For those current license holders we will be sending you this version this month as we finish our internal testing!

Want to know more? Click here to see our listing for Arsenal: https://www.blackhat.com/us-14/arsenal.html#Cowen



Daily Blog #359: Carving USN Records

Carving USN Records by David Cowen - Hacking Exposed Computer Forensics Blog


Hello Reader,
           Today I want to talk about something I find very exciting. You know how much we enjoy USN journals but as with all the best artifacts its limited in scope as to amount of time the journal goes back. We previously found joy in the fact that USN Journals are included in the Volume Shadow Copies meaning we could recover much more data about what happened in the past, but now we can get even more!

I was under the misconception in the past that USN Journals like the $logfile was a circular log, meaning the data at the beginning of the journal would be overwritten when the space allocated ran out. This belief though did not line up with what we saw in the journal itself, we just kept seeing blocks of 0's assigned and no overwritten records. After talking to Troy Larson though I now understand that this behavior is due to the fact that the journal is not circular but rather pages are allocated and deallocated as the journal grows.

Why is this exciting? This means that old records are not overwritten just deallocated and hanging out in the unallocated space in the partition. That means we can carve for these records and recover much more USN Journal data. USN Journal data when carved is especially useful as a record contains everything you need to know within (timestamp, file reference number, filename, etc...) nothing leading up to or proceeding a record will detract from the value of carving even a single record.

Currently I know X-ways Forensics supports carving these entries and we will be coming out with carving signatures for you to use as well. This is great news and will lead to even more great evidence! As we move forward with the commercial version of the Triforce you should expect to see this carving functionality built in as well.

Also Read: Daily Blog #358

Daily Blog #345: Extracting USN Journals in X-ways Forensics

Extracting USN Journals in X-ways Forensics

Hello Reader,
       Today we have a guest post from Blazer Catzen, of Catzen forensics,  who was nice enough to write up the procedure necessary to extract out USN Journals with X-ways forensics in a way that makes the file more accessible with other tools. Let me explain what I mean by more accessible, X-ways correctly places no timestamps on a file that has none when an alternate data stream is exported. ADS have no timestamp attribute so applying one is artificial and applying one is something they allow the user to do. This is handy as the win32 api really wants to have a timestamp when it is opening a file and many tools will fail if it does not have one. So here is Blazer's writeup on how to do it:

Extracting USN Journals in X-ways Forensics

Xways comes with license for WinHex

Process as follows
1 locate USN$J and note that it has children (the dots along the bottom)

Extracting USN Journals in X-ways Forensics

2 Go into the “child”, in this case the ADS

Extracting USN Journals in X-ways Forensics

And select recover copy

Extracting USN Journals in X-ways Forensics

NOTE Output ADS as files check box

Extracting USN Journals in X-ways Forensics


And as you so aptly noted … no dates… tunneling did give a created date but no modified and anjp (WinAPI wants both….. so picky)

Extracting USN Journals in X-ways Forensics


Close XWF – Open WInHex – Open $J and file- save as ….

Extracting USN Journals in X-ways Forensics


 And now your new file will have dates

Extracting USN Journals in X-ways Forensics

And will open up with other programs that rely on the win32 api to open file handles, such as Triforce.

Also Read: Daily Blog #344

Daily Blog #340: The leap from beta to final, Triforce updates

The leap from beta to final, Triforce updates

Hello Reader,
          If you are still running a Triforce beta, I would highly suggest you move over to the production version. We've fixed a lot of bugs and added lots of features. It's your choice free or paid, of course think the paid version is well worth the money! Curious as to what all is waiting for you? Here is an update:

You can grab a copy of the free or paid version at:
LINK N/A

Report Filtering (Please read user manual for more information)

Exporting and importing filters

The leap from beta to final, Triforce updates

Unexpected crashes using filtering options
Added filtering logic

The leap from beta to final, Triforce updates

Additional Unicode Support

Filter with Unicode Strings

The leap from beta to final, Triforce updates

Export to Unicode File Name

The leap from beta to final, Triforce updates


Signatures

Signature Corrections
User can create a file list to search the MFT (Paid Version Only)

The leap from beta to final, Triforce updates

GUI

Various GUI bugs
Report Record Count in Report View

The leap from beta to final, Triforce updates

Also to those users who've moved over the paid version we have our first signature update going out to you tonight!

Also Read: Daily Blog #339

Daily Blog #338: Triforce ANJP Free Edition

Triforce ANJP Free Edition by David Cowen - Hacking Exposed Computer Forensics Blog

Hello Reader,
    I think its important to keep promises whenever you can. If you remember when we first started talking about the Triforce products we stated we always wanted to keep a free version available. Today we announce that free version to all of you. While in a perfect world you would get a license of our awesome commercial product, we don't want to withhold good evidence from anyone. The free version of Triforce ANJP will fully parse out the $MFT, $Logfile and USNJrnl to text and sqlite databases just like the commercial version. The only difference comes in its ability to use signatures, both provided by us and ones you create yourself, and advanced reporting.

You can download your own free for life copy here:  

LINK N/A

We are here to support you in your investigations and make sure you always have the best evidence we can help you get. You will see that the license states not for commercial use, which we think is fair for those of you using our tools to generate a profit from your services.

Moving forward we will strive to make the core of the parser the same as the commercial version so the free version will stay up to date and hopefully bug free.

Also Read: Daily Blog #337