Thursday, December 8, 2011

SUPER Timeline creation (from SANS)

I'm making a push for more forensics at work.  One avenue I'm trying to open up is the investigation of laptops/computers of former employees.  And, to that end, one of the tools I'll be making heavy use of is the timeline.  I'm pretty adept at creating timelines with SIFT, but Log2Timeline was not in existence when I took my GCIH.

This article is an excellent primer on using Log2Timeline to create a SUPER timeline in SIFT, using many inputs from an acquired image.

(Edit 1/20/12) Rob Lee has added another article on  Log2Timeline to the SANS Forensics blog, this article talking about log2timeline and log2timeline-sift.  Plus, there are some good examples at the end of the article.

(Edit 1/28/12) Rob has added yet another article...releasing a template that colorizes output from Log2Timeline.  I haven't given this a whirl, but I will after I create my next timeline.

Older articles:
How to Create a Filesystem and Registry Timeline


I've created this post so I know where to reference the original article, as I'm sure I'll forget.

Tuesday, November 29, 2011

Google Talk Spam on my Android phone

For the first time, I have received, what I believe to be, SPAM through Google Talk on my Android phone.  I don't use Google Talk, at all, so I'm 100% positive that this is spam.  Upon looking at the notification in the notification bar, I see:

crazieannaxx3@aol.com wants to chat with you.  Will you accept?

This is a vector I haven't seen before, and if anyone has more information, I'd love to hear more.

Monday, November 28, 2011

Apple IOS interim STIG guidance (and a mobile device draft STIG)

I happened to be checking disa.mil today and I noticed a couple of updates:

Windows 7 benchmarks were updated on November 9th.
Apple IOS interim guidance was released November 17th.
A draft for the General Mobile Device (non-Enterprise Activated) was added November 21st.

From the Apple interim guidance memo:

When approved by the Component CIO, the guide may be used to configure Apple iOS devices for limited deployment, pilots, and demonstrations.

Regarding the General Mobile Device (non-Enterprise Activated) STIG, I noticed the following:

The STIG requirements apply to a smartphone or tablet that does not connect to the DoD
network or a DoD email system, and does not store or process sensitive or classified DoD
information.
This is as of today's date.

Wednesday, November 23, 2011

Holiday Incident Response

I wrote about this a couple of years ago, and one of the links in the post that links to the SANS posts is one of my all time favorite reads.  It's that time of the year again.  Incident Responders and Forensicators will be visiting family and friends (or have guests themselves) and invariably, the question will come up:  "Can you take a look at my laptop/computer/etc.?  There's something wrong."

It never fails.  (Disclaimer...I've already been asked by my parents.)

Education of our families and friends will go a long way in preventing the question from arising next year, or the next holiday, or next week.  High on my list of education topics are automatic updates, anti-virus, and social engineering (in no particular order.)

Here's hoping you have a relaxing holiday, good times, and quick work (if you have to.)

Friday, November 18, 2011

DISA.mil back up, but limited

As of this morning (when I checked - 11/18/2011) DISA.mil appears to be back up.  However, it appears that there is still some limited functionality.  From the banner on iase.disa.mil:

Parts of the IASE NIPR site are temporarily unavailable. We apologize for any inconvenience.
For STIG content, please go to AKO/DKO (AKO/DKO account required).

I'll keep checking on more functionality.

Tuesday, November 15, 2011

DISA.mil down (inlcuding iase.disa.mil)

I use DISA.mil for much of my guidance while testing systems and analyzing data from testing trips.  It appears that DISA.mil is down.  I noticed it yesterday while looking for STIGs, and now SANS has a post on it.  The comments allude to a web server being down in the SAN.

Here's the SANS post.

I'll try to post again when it is back up.

Edit (11/17/2011):  As of 8:30 this morning, the site is still down.

Edit (11/18/2011):  Parts of the site appear to be back up, but in limited capacity.

Thursday, October 27, 2011

2012 DISA FSO Release Schedule for STIGs

While looking for a STIG today, I saw that DISA released the schedule for updated STIGs in 2012.  Those dates are:
  • First Quarter:  27 January 2012
  • Second Quarter 27 April 2012
  • Third Quarter:  27 July 2012
  • Fourth Quarter:  26 October 2012

I probably will not get a chance to write up what gets released this quarter due to travel, but I did see that the Gold Disk has been released.  The files are in the PKI-protected area of DISA.

SANS Incident Detction and Log Management Summit

I just received an email about this summit today, and it looks like a great couple of days' worth of events.  Due to politics in the office, and likely my travel schedule, it appears I will not be able to attend.  The event is being held December 7 and 8, 2011 in Washington D.C.

Here's a link to the summit.

I look forward to reading write-ups and recaps of the event.

Monday, October 10, 2011

A link to a post on getting into the field

As I am continuously trying to land a job in IR and Forensics full time, I look for any clues or tips on breaking into the field.  The other day, I saw this article, linked to the Forensic Focus site and thought it would benefit others looking to get into the field.

Good luck.

Advide for Digital Forensics Job Seekers

Monday, October 3, 2011

Betfair accounts hacked

I haven't seen this story making the rounds in the security community.  Interestingly, I got this story from a mailing list for a card forum.  Apparently, 2.28 million"encrypted payment card account numbers and other details" were stolen OVER 18 MONTHS AGO.  Betfair just recently notified their clients.  Allegedly, 3.16 million "account user names with encrypted security questions" and 89,744 "account usernames with bank details" were also taken.

An article with more information is here.

Sure, it's good to hear that some information was encrypted.  However, a lot can happen in 18 months.  If someone has a link to an article with more technical information, I would love to see it.