Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, April 7, 2012

Tools, Tips, and Reverse-Image Searches

Posted on 4:22 PM by Unknown

Last week must have been pretty quiet as folks prepared for the Easter weekend. I didn’t collect near as much material as usual.

That’s a good thing seeing as I’m still digging out the piles of linkage I’ve been buried under.

Submitted for your edification:

NoVirusThanks - Funny name, great tools and freeware utilities for sysadmins and incident responders alike.  I have a few other "elite go-to” sources that offer a spectacular range of utilities for my prime toolsets and I’ve had to add NoVirusThanks to my list.

  • Sysinternals Utilities - Microsoft SysInternals.
  • Nirsoft - Nir Sofer’s amazing collection of freeware tools and utilities.
  • woanware - Mark Woan’s collection of forensics and network security utilities.

There are lots of other great producers of quality freeware Windows tools and utilities both for system administration, incident response, and forensics, but these sites seem to pack the best of them into a single place.

Wireshark · Wireshark 1.6.7 Released - Mostly bugfixes but check out the full 1.6.7 release notes if you care. Then go download the latest version of Wireshark in your favorite flavor.

Just when I thought I covered the series in my last post, Girl, Unallocated slips in a new installment, #2.4 with some timeline/SIFT work.

  • Case Experience #2 - IP Theft Investigation Thought Process
  • Case Experience #2.1 - More About IP Theft Thought Process
  • Case Experience #2.2 - Let the Digging Begin
  • Case Experience #2.3 - Digging Into the Registry
  • Case Experience #2.4 - Exposing Kilroy with Log2Timeline

David Kravets from Wired’s Threat Level authored the post How Forensics Claims Facebook Ownership Contract Is 'Forged' that offers some certainly interesting items out of a forensic examination. I find value in reading publically released incident response and forensic analysis reports to pick up tips as well try to understand both the good, the great and especially the less than stellar (to then be avoided) in techniques used.

New Tools, Registry Findings - Windows Incident Response blog - Harlan Carvey passes on some new tips, tools, and registry bits of his own, one of which is the super-handy RegRipper Plugins maintenance tool from the super-cool Cheeky4n6Monkey. Read both Halan’s and Cheeky’s posts to get some idea if this tool would helpful.

Get out the Vote!

The Forensic 4cast Awards hosted by Forensic 4cast is open for voting through June 17th.

Take a look at the stellar nominees for each category and pass some love and kindness in support of the hard work these oft-unrecognized forensicators do day-in and day-out. Everybody likes some props now and then and here’s a way to show your appreciation for the top-shelf work done in the forensic community. Go and Meet the 2012 Nominees then cast a vote.

The humble GSD blog treads far below these giants but it was cool to see a kind link-back over in a recent SANS Digital Forensics Case Leads blog post. That’s some mighty fine company to be sandwiched amongst. I’m encouraged that some of these posts are as helpful to others as they are rewarding for me to share. Semper paratus, my friends.

Where’s That Image?

And here is how Claus finds new tools/techniques. Scary.

I was ripping though my RSS feed pile this past week and came across this post over at Boing Boing! That piqued my interest: Moon boxes and mystery men. I’m a sucker for old black-n-white techy photos of stuff from bygone era’s. Stuff like old space program photos, crazy industrial equipment, even the ads over at Phil Are Go!

Anyway.

While the question posed by Frank Munger was interesting, I was more curious if/where the photo had previously appeared on the WWW.

So I downloaded the “original” image, popped over to Google Images, clicked on the tiny blue camera in the search bar, uploaded the image I had downloaded and…bingo got the results. Of course, looking down a bit more on the page I found that Frank Munger had since found the answer he was seeking Y-12's moon-box mystery solved, although the Boing Boing didn’t update their story. That particular itch was now considered scratched, but that did lead me to look around for more reverse-image search tools.

There may be times when you find an image on a system or drive and want some more information about it. You could do a search on the file-name but those can be renamed. While you may not be able to draw many conclusions from an image search, it might give you some additional context for understanding.

Since the last time I went blogging about reverse-image-lookup tools on the web was quite a while ago, there are some new ones worth bookmarking.

Google Images - Check out these related links for more information on how to use this Google search feature: Search by Image · Inside Google Search and Search by Image - Google Images Help.

TinEye Reverse Image Search - One of the originals and still quite good. TinEye also offers some Plugins for major web-browsers.

Bing Images - While Bing does some great image searches based on terms, it doesn’t (yet) seem to support reverse-image searching.

Anyone know of any other reverse image search sites and/or tools worth recommending?

Cheers!

--Claus V.

Read More
Posted in forensics, graphics, Link Fest, security, utilities | No comments

Sunday, April 1, 2012

Forensic Linkfest - microwave-ready meals

Posted on 1:26 PM by Unknown

My “For-Sec” to-be-blogged pile is bustin out at the seams.

Unfortunately, I still haven’t been able to find the time to toss the meat on grill in a way that gives it justice…so as of now, that material is still slow-smoking.

In the meantime maybe you will find something noteworthy in the following links-of-note prepared for quick consumption.

NetWitness - Investigator Freeware - Version 9.7.5.4 released 03/16/12. I’ve used this NFAT tool successfully in the past, but had stopped looking for updated versions. So the other day when my one-year’s registration period had expired and I had to “re-enlist” I was advised an update was available. There are a number of free NFAT tools, and each provides its own slant. NetWitness Investigator Freeware version is a must-have tool for your assessment collection. Get the update!

MIR-ROR - This incident response toolset has now been updated to version 2.0: HolisticInfoSec: MIR-ROR 2.0 released. Sure you have to dump a few of the ingredients in the provided bowl before you bake, but it’s, well, a piece of cake. The result is a collection of tools that can speed up your assessment and information collection on a suspect system.

65 Open Source Replacements for Security Software - Datamation’s Cynthia Harvey has composed a knock-out list of great Open Source tools. I’m confident that anybody who regularly reads this blog will find something new or interesting in this list.

NAFT Release - Didier Stevens has released his Network Appliance Forensic Toolkit than can handle network appliances but also supports memory dumps of OS’s like Windows. Basically (for now) it extracts network packets from memory dumps or other devices via pattern recognition.

The Latest Version of Redline Finds Indicators of Compromise and More - Mandiant’s Redline tool has now been updated.

Brett Shavers has a number of new posts about progress in the WinFE building and toolsets.

  • Colin’s Write Protect Application- Windows Forensic Environment Blog
  • WinFE Script Updated - Windows Forensic Environment Blog

The Girl, Unallocated forensic blog has been a great source of how-to’s and advice on approaching investigations. This latest series is quite interesting.

  • Case Experience #2 - IP Theft Investigation Thought Process
  • Case Experience #2.1 - More About IP Theft Thought Process
  • Case Experience #2.2 - Let the Digging Begin
  • Case Experience #2.3 - Digging Into the Registry

Prefetch analysis posts are quite plentiful.

  • Prefetch Analysis, Revisited...Again... - Windows Incident Response blog
  • Second Look at Prefetch Files - Journey Into Incident Response blog

Corey Harrell also has a great in-depth timeline study based on Volume Shadow Copy data. Sharpen your Saw on this one!

  • Volume Shadow Copy Timeline- Journey Into Incident Response blog

We are all learning more and more as Chrome gains in popularity. SANS Computer Forensics and Incident Response blog’s “johnmmccash” has a great roundup of material in his Forensically mining new nuggets of Google Chrome post.

Finally, Security Ripcord blog’s Don C. Weber has a technical post on Hard Drive Acquisition Information Using faidds and makes some interesting observations in the process.

Cheers!

--Claus V.

Read More
Posted in Chrome/Chromium, forensics, Link Fest, malware tools, NFAT, security, software, utilities | No comments

Neat Portable File Encryption Program via the USAF!

Posted on 12:43 PM by Unknown

The other day I needed to transfer a file securely though the emails but didn’t want to deal with setting up a certificate-based method such as Comodo’s Secure Email or an OpenPGP email solution like Enigmail. I wanted to be able to keep this file in my web-based email account for access but didn’t want to leave it in the “free-n-clear” in case my account ever got hacked. Sure, I could have made an encrypted file volume in TrueCrypt and copied it up, but that seemed like overkill.

I just wanted to encrypt the file and decrypt it as needed without a lot of drama as needed when I found myself on a guest system.

I found a big selection of freeware tools to do this and while they all were quite full-featured, they all seemed to be a bit more expansive then the simple task I was looking for. Those that I explored included:

  • Chiave 2 - (AddictiveTips review)
  • SteadyCrypt - Java-based encrypting utility
  • AxCrypt - file encryption software by Axantum that compliments Dropbox, Live Mesh, SkyDrive and Box.net services.
  • Androsa FileProtector
  • File Encryption
  • BoxCryptor - offering on-the-fly encryption for cloud storage. (BoxCryptor Blog)
  • Encoding Decoding Free - (AddictiveTips review)
  • lazarcrypter - (AddictiveTips review)
  • along with a number of clever and tiny DOS-based Encryption & Encoding utilities.

Almost any of these almost fit the need I had, but I just didn’t feel the match was perfect. Plus I wasn’t really looking for something I might have to install on a guest system…especially if it might not be running Windows.

Finally I found exactly what I was looking for courtesy of the US Air Force Research Laboratory geeks.

Software Protection Initiative - Encryption Wizard Public. From the page.

Encryption Wizard (EW) is a simple, strong, Java file and folder encryptor for protection of sensitive information (FOUO, Privacy Act, CUI, etc.). EW encrypts all file types for data-at-rest and data-in-transit protection. Without installation or elevated privileges, EW runs on Windows, Mac, Linux, Solaris, and other computers with Sun Java. Behind its simple drag-n-drop interface, EW offers 128-bit AES encryption, SHA-256 hashing, searchable metadata, archives, compression, secure deleting, and PKI/CAC/PIV support. EW is GOTS - Government invented, owned, and supported software. Over 35,100 copies of EW protect a wide variety of data.

EW comes in two, fully-compatible and interoperable editions, EW-Public and EW-Govt. Anyone can download and use EW-Public. Designed for US Federal Government (and contractor) computers, EW-Govt is accredited by the Army and Air Force for NIPRNet and SIPRNet. EW is free to users.

It was a piece of cake to use.

I downloaded the latest version (EW-Public) v3.3.1

I unzipped the archive (included 2.09 MB PDF user guide, 1.21 MB “jar” application, and 2kB text file for getting started).

I ran the EW-Public-3.3.1 “jar” file and got a cool splash logo followed by the application.

I selected the file I needed to encrypt and drag/dropped in on the application window.

I hit the “Encrypt” button and provided/confirmed a “passphrase.” (note it will provide you feedback on the strength as you go.)

Hit the “next” button and decided if I wanted to keep the original file after encryption or delete it. Your choice. Added it. Done.

Note, it does not randomize or otherwise change the file name itself, so you may want to do so if the file name makes it more interesting to snooping eyes.

To decrypt, launch the app, drag the encrypted file onto the application,choose the “Decrypt” button, pass your passphrase and you are good.

It is a breeze to use, is 100% portable, and is very fast. If you are afraid the system you are working on doesn’t have Java for some bizarre reason, keep a copy of jPortable along side this jar file application.

If you want to encrypt many files at once, drag them all and then encrypt and it will create a “many-in-one” compressed/encrypted file. Sweet!

The PDF User Guide v3.3.x is very detailed and well worth reading if you are interesting in using this tool.

Yes, I know using a US military/govt developed tool for encryption may not appeal to the tinfoil-hat wearing crowd, but on the other hand if you need a fast, easy to use file-encryption tool, this is a great choice. It’s good enough for me and has my full confidence.

Bonus Find:

Software Protection Initiative - Lightweight Portable Security - The same team that developed the encryption tool above also has a public version of a secure ISO-based live-CD linux build that also includes Encryption Wizard - Public. Download the ISO and you burn it to a CD (or create a bootable USB drive from the included “install to USB” tool in Windows on the root of the ISO/CD) and use this distro to securely run on a system.  It’s light-weight and no frills. There is also a “deluxe” version that includes OpenOffice and AdobeReader which are stripped out of the “lite” version.

It’s a nice lite little distro for special needs usage and was an unexpectedly pleasant find.

Cheers!

--Claus V.

Read More
Posted in boot-cd's, security, utilities | No comments

No Foolin! Free Download Gold.

Posted on 11:38 AM by Unknown

Lots of good freeware downloads these past several weeks.

Get panning.

Update for Windows Live Essentials 2011 now available - Windows Experience Blog. Trying to find out exactly what gets updated in these releases is always challenging. Comments on this page report issues with Live Mesh after the upgrade. read these comments if you rely on it before updating. Blaine points us to this page, Windows Live Essentials 2011 release notes that still isn’t great but is better than nothing.

Thesycon USB Descriptor Dumper - displays USB descriptors of any USB device.

sCheckbook - DonationCoder.com - bare-bones check-register application. No bells or whistles. Just the simple basics to record check information and keep a running tab. Others apps are out there with lots more features, but if you are training a young adult in the habits, this could be a simple place to start.

Universal USB Installer – USB Pen Drive Linux - “Live” Linux Booting USB creator tool. Select a distro, go though the steps, and it will load and configure your USB device with the ability to boot a system from that distro. See the link to see all the supported distros. It’s a very comprehensive collection.

Digital Lagniappe’s Photo Collage - Screen saver that tosses images from folders onto your desktop. I’ve been using SE-ScreenSavers for a long time, but this new screensaver is very nice. Options are light but enough to get the job done. It’s a pleasant change.

Audacity 2.0 - My favorite, go-to audio editor got a major version bump lately. I really like the performance and though I have only just started to feel like I have mastered the basics, I’m excited about this new version. For a rundown of the major new features: Audacity 2.0 Update Brings Lots Of Bug Fixes & New Features post addictivetips.com, Six years of betas later, Audacity 2.0 debuts post betanews.com. Also, don’t forget that Wavosaur free audio editor with VST and ASIO support is alike and kicking also.

Oracle VM VirtualBox - Updated to v 4.1.10. Changelog – Oracle VM VirtualBox, and Forum discussion on the 4.1.10 release. First go round I had trouble installing the updated VirtualBox Extension Pack for 4.1.10 and it kept bombing out part way though. VB quickly identified the issue and updated the pack and the new one went on smoothly. You should always download and install the matching Extension Pack when you update the main VirtualBox application. Head over to the Downloads page and grab both.

ISO Toolkit 5.0 - Tweaking with Vishal - This is a nice do-it-all tool to work with ISO files. Wish I had been able to include it in my Mostly ISO burning post a while back. A more detailed review can be found at this freewaregenius post.

If ISO Toolkit is too “geeky” then consider CD Manipulator MOD instead to manage your ISO file and disk-burning needs. The pictures speak for themselves. More details on the features over at this addictivetips post: CD Manipulator: Read/ Write & Master CDs, Create Easy Duplicates.

Greenshot remains my current screen-shot utility of choice. Though not perfect, it runs stably on XP and Windows 7 and contains enough editing and markup extras to make it more than adequate for my screen capture needs. That said, I saw two more screen-shot tools that you might be interested in: aeroshot and livecapture. This post has more details on the former if you are interested: Live Capture: All-In-One Screenshot Tool With 12 Different Modes by AddictiveTips. Their 5 Best Free Screen Capture Software For Windows post is a good place for a pros/cons review of several of these screencapture tools so you can find one that fits your particular needs.

And yesh. Time to update Flash again.

Game on with Adobe Flash 11.2 and AIR 3.2 - BetaNews

Adobe Flash Player APSB12-07 - 28 March 2012 - SANS ISC Diary

New, easier-to-update Flash designed to snuff out malware attacks - ArsTechnica

What’s my Flash Player version? Where’s the latest Flash update? -Ed Bott

Current Version Downloads via FileHippo

  • Flash Player 11.2.202.228 (IE) 64-bit - Download
  • Flash Player 11.2.202.228 (IE) - Download
  • Flash Player 11.2.202.228 (Non-IE) 64-bit - Download
  • Flash Player 11.2.202.228 (Non-IE) - Download

Keeping these updated has been challenging but this new version now gives you options for it to automatically check for and apply updates, notify you of updates (but do nothing else), or to not bother checking for updates. Choose wisely!

Cheers!

--Claus V.

Read More
Posted in boot-cd's, Link Fest, software, utilities, virtualization | No comments

Saturday, March 10, 2012

Backup Material

Posted on 7:03 PM by Unknown

It has been quite a while since I specifically visited the subject of Sync & Backup Tools (freeware).

Since then there have been lots of new tools and applications developed so I thought I would return with a link-dump of sorts.

Generally, my own personal backup strategy remains a bit pragmatic. Wish I could be much more organized like ComptuerZen’s Scott Hanselman.

  • On Losing Data and a Family Backup Strategy - Scott Hanselman
  • A basic non-cloud-based personal backup strategy - Scott Hanselman
  • BACKUP YOUR CRAP: Missing Operating System, Backups, Disk Images, Home Servers, BootRec, BootMgr, RebuildBCD, FixBoot and Problems, Plural - Scott Hanselman

Here then are a few simple routines I use for different purposes, followed by a list-of-lists of various freeware backup programs.

Collections to USB

I have a few “production” folders on my main system that contain a deep collection of portable applications, how-to documents, reference materials, common third-party browser plugin updates, and incident response checklists and guides. These are replicated to a number of USB sticks and portable USB hard-drives for use in the field.

For this type of situation, what I need more is a synchronization program rather than a true “backup” application.

The one I always reach for is DSYNCHRONIZE from Dimo’s Tools. It has lots of options and is quite fast. AddictiveTips blog has recent post going over its finer points: Perform Real Time Sync, Backup Large Storage Mediums With DSynchronize.

This is the easiest by far type of “backup” process I have. I’m just replicating the master set of folders and files onto the USB sticks as needed and DSynchronize cleans up the changes I make in the main folders to the replicated spawn quite nicely.

“My Documents” to USB HDD Storage

The next set of things I have to back up are the “My Documents” folder for myself and the girls, as well as related personal files and folders.

This is where things get a bit more complicated.

I have a few USB hard-disk drives for backup duties. Each one is formatted into two partitions. The first partition is usually just around 100 MB or less. The second volume is the remaining GB’s.

I format the first partition NFTS and load it with a few critical portable software applications; most important of which is TrueCrypt.

The idea behind this first volume is that in the event I ever have to grab-n-get with the drive, all the tools I need to restore data from the drive to another system are on the drive itself. No hunting around.

I then use TrueCrypt to create an encrypted partition out of that second volume. The first partition is relatively tiny as it only needs to keep a few tools in the clear and helps keep me from being tempted with putting any important docs in the free and clear there. The second volume is fully encrypted and that’s where all the good stuff stays. I also put a copy of my portable backup application on it as well.

I then just need to attach the USB device to my system(s), allow it to find the first partition, run TrueCrypt and mount the second volume and attach to it. Then I can run my backup tool and put the backup files into the encrypted volume.

For the backup program itself, I’ve come to rely upon Back4Sure by Ulrich Krebs.

TinyApps recommended Back4Sure some time ago and that was good enough for me to check it out. I’ve become very pleased with it’s ease of use and reliability.  If I had to go with a second, Create Synchronicity might be a close second also recommended by TinyApps: Backup to drive label instead of drive letter.

Whole System Backup

This is kinda cheating, but once in blue-moon I will also use ImageX to create a full-disk image of my primary system and dump the image file into one of those TrueCrypt volumes as well.

This takes lots longer but is a good option for a catastrophic system failure.

Although I could use one of the more regular data backups to get another system going again, this allows me to hunt down and extract any bits-n-pieces of data that get scattered sometimes in weird places if the need ever arises.

List of Backup/Sync Tools

Here below is a list of additional freeware backup tools, programs, utilities and the like. Some are quite new and others are quite old. They are not really listed in any particular order. Take some time and click around. Sometimes the trick is finding one that has the right balance of ease-of-use with options needed for a particular job. Like me, you may find that using a combo of tools for different purposes may be the best solution.

These first ones are more in the class of focused file set backups. Though some could probably handle a system-wide backup job, they mostly would be better suited for backing up a specific subset of files/folders from a system rather than the whole enchilada.

  • DSYNCHRONIZE - Dimo’s Tools
  • Back4Sure by Ulrich Krebs
  • Create Synchronicity
  • Areca Backup - Official Website
  • FreeFileSync
  • Toucan - PortableApps.com - Portable software for USB, portable and cloud drives
  • Personal-Backup - Rathlev
  • Cobian Backup
  • AceBackup
  • Comodo Backup,
  • 2BrightSparks - SyncBackSE
  • FBackup
  • PureSync - Synchronize and backup files and folders
  • Hinx Software Backup Easy
  • Handy Backup Software 7.0 - Back up Windows PC and Servers
  • Dmailer Backup - Free backup software - Online storage service |Windows & Mac
  • Everyday Auto Backup
  • Zback homepage - portable backup and synchronize tool for Windows
  • Freebyte Backup
  • ICE Mirror
  • Ocster Backup: Freeware Windows Edition - Free Backup Software for Windows (AddictiveTips review)
  • DFIncBackup - Freeware incremental backup - (AddictiveTips review)

These next ones are more of the specialty enchilada menu-fare. These will cover more of a whole-drive backup rather than limited file/folder sets. That said, they still primarily run within the existing Windows system so should be familiar and dependable for geeks and grannies alike.

  • Paragon Backup & Recovery Free Edition
  • Macrium Reflect FREE Edition
  • EASEUS Todo Backup
  • GFI BackUp Freeware - (AddictiveTips review)
  • Redo Backup and Recovery
  • DriveImage XML Backup Software
  • Carbon Copy Cloner - Features
  • XXCLONE, A New Way of Cloning the Windows System Disk- (AddictiveTips review)

Finally, we can step off the well tread path and go to more geeky options that are system-backup and imaging tools for the tech-crowd.

  • ImageX -GSD Blog posts tagged “ImageX”
  • Clonezilla
  • OSFClone - Open source utility to create and clone forensic disk images
  • Disk2vhd
  • Device Image
  • Partition Saving
  • Partimage
  • G4L
  • g4u - Harddisk Image Cloning for PCs
  • Miray Software - HDClone
  • Clone Maxx
  • Seagate Technology - DiscWizard
  • Seagate Technology - MaxBlast 5

I suppose if you were super-geeky or a forensicator, you could also use any of the various tools you probably are aware of for making sector-based drive images. However for personal “backups” I prefer to use file-based backup methods as having a forensically sound exact duplicate of my drive isn’t as critical as having the files I need available for easy restore or off-loading.

More information:

  • Best Free Backup Program - Gizmo’s Freeware
  • Best file and folder synchronization freeware for Windows 7 - The Windows Club
  • Free Disk Image and Cloning Utilities - thefreecountry.com

Back it up,

Encrypt it if it’s personal (or even it it isn’t),

Cheers.

--Claus V.

Read More
Posted in boot-cd's, Link Fest, Linux, Microsoft, organization, software, troubleshooting, utilities | No comments

Incident Response Toolsets and Checklists

Posted on 11:56 AM by Unknown

A few months ago I was reading this Digital Forensics Case Leads: ReFS, Ex01, and DFIROnline post and came across the following bit under the Tools section:

Michael Ahrendt recently released an interesting looking "Automated Triage Utility," written in the AutoIT scripting language. It is a GUI-driven data collection utility designed for live system response. In this regard, it reminds me a lot of Monty McDougal's Windows Forensic Toolchest. They differ in UI and programming language, but aim at the same objective.

I hopped over to take a look at Michael’s Automated Triage Utility and it is pretty cool. You do have some "light” building work to do to seed the structure Michael provides with some extra applications but in total it provides a responder a great set of information logs and evidence collection.

While one-click incident assessments are no substitute to a detailed and focused analysis and pick-apart, these toolsets and first-responses may be of significant benefit getting some assessment data to determine scope of impact and breadth incident. With the core data collected an analyst or response team can then plan out additional responses.

Of course, use of these tools on a live system may have an impact of their own on that system. If possible it might be best to first try to capture both system and memory images if possible to preserve volatile system state information. That said, if the threat is significant enough and risk of critical data loss high, then it might be wise to isolate the system from the network immediately if your response protocol allows. Detailed documentation of response actions and tools run will also help in the post-mortem.

Here are some other related tools and resources that came to my mind after looking at the Automated Triage Utility Toolset.

RegRipper - Harlan Carvey’s Perl-based toolset for picking apart critical registry locations and data for a forensic response. Addition of additional community-based scripts extends the features wonderfully.

RegExtract - Mark Woan’s own take of RegRipper that uses a Windows binary with other 70 plugins to assess system information.

BinPack -Godai Group - a portable application storehouse with over 100 security tools for security assessment and pen-testing.

MIR-ROR - CodePlex project from Russ McRee and Troy Larson. MIR-ROR = Motile Incident Response - Responde Objectively, Remediate. Customized CLI script that uses Windows Sysinternals tools and others to do live-system captures. More info here at HolisticInfoSec’s Toolsmith: (PDF) June 2009 - MIR-ROR: Motile Incident Response - Respond Objectively, Remediate.

Confessor - CodePlex project built from the concepts of MIR-ROR. This allows remote intel gathering on a host of systems in an AD environment. Pretty cool stuff. More info here at HolisticInfoSec’s Toolsmith: (PDF) November 2010- Confessor & MOLE

Registry Decoder Digital Forensics Software - registrydecoder & regdecoderlive - Automated, live acquisition of registry files - via Google Project Hosting. Some of the previous tools listed work on Windows Registry hives that have already been collected. This one is a bit different in that it can be used against live registry files as well as historical ones. More info here at HolisticInfoSec’s Toolsmith: (PDF) December 2011 - Registry Decoder

MANDIANT: Intelligent Information Security has an outstanding collection of free software for incident response and malware analysis. In particular, their Redline utility does some super-awesome host triaging work. See also: IOC Finder

Security Database IT Watching - Evidence Collector - Not supported from some time, but still a very clever and useful “command and control center” tool that leverages other applications in collecting information from systems being assessed.

OSForensics - PassMark Software’s tool can be used to build a portable version to do extensive system information and analysis.

ESET Sysinspector - Neat tool to collect details on a running system, then perform heuristic analysis for risk level labeling of captured components. Makes it easy to begin a top-down assessment of a system.

Nigilant32 - Agile Risk Management LLC. Tiny tool to create a report snapshot of critical live-system processes, services, accounts, tasks, ports, and so on, as well as file-system review tool and active memory imaging support.

rapier - First Responders Info Gathering Tool - Google Project Hosting - RAPIER stands for Rapid Assessment & Potential Incident Examination Report tool. It doesn’t appear to be active since early 2008 but there may be some good material left in this tool. Check the “Downloads” page for some additional PDF and presentation material regarding the toolset. Based on the Intel (R) RPIER project. Added to post list 04-21-12

Response Checklists

Of course, just because you got some tools in your box doesn’t mean that you should just run rough-shod onto a system that is the target of some evilness. Hopefully you and/or your organization has a well-documented incident response framework already in place to guide and shape your response activities in a meaningful and effective way.

Here is a collection of some good ones you may want to consider.

Information and Security Cheat Sheet and Checklist References - Lenny Zeltser. Serious collection of cheat sheets and checklists for IT security response pros. Look carefully at the bottom of the page as Lenny offers some additional cheat sheets form others as well.

KnowYourEnemy.eu - Checklists galore!

Incident Response Checklist (PDF) - via Digi4nsic.com

Procedure for Windows Incident Response (PDF) - via Digi4nsic.com

Request for Forensic Examination (PDF) - via Digi4nsic.com

Computer Security Incident Handling Guide (PDF) - NIST

An Incident Handling Process for Small and Medium Businesses - SANS Institute. Page 39 in particular has a good “Checklist for incident response capability”

Malware Detection Checklist - GoogleDocs - Instrument developed by Harlan Carvey and posted in this DFIROnline: Detecting Malware in an Acquired Image in Windows Incident Response blog post.

His work was expanded a bit in these posts:

  • Linkz 4 Exploits to Malware - Journey Into Incident Response
  • Malware Detection Checklist - Sketchymoose’s blog

Cheat Sheets - Packet Life - For the network incident response crew.

More resources:

Simple Malware Research Tools - ISC Diary. Some fresh tools from the SANS gang.

Can we believe our eyes? Another story - Microsoft Malware Protection Center

Malware Analysis Blog - Great new blog (to me) covering malware review and study.

PXE Boot Server in a Malware Lab - Malware Analysis Blog

Using Free Windows XP Mode as a VMWare Virtual Machine - Lenny Zeltser on Information Security blog

US-CERT: United States Computer Emergency Readiness Team - 2011 GFIRST 2011 Conference papers and materials. So much goodness!

  • Infected! Using the Oregon SIRT Malware Toolkit to Safely Determine Source, Vector, and Duration of a Malware Infection (PDF) - John Ritchie, Senior Security Analyst, State of Oregon Enterprise, Security Office
  • Cyber Incident Management: A Process-Driven Approach with an Integrated, Train-in-Place, Cyber Drill and Exercise Capability (PDF) - Christopher Fogle, Partner, Delta Risk LLC & Brian Zaas, Director, Enterprise Solutions, Avineon, Inc.
  • Sniper Forensics: One Shot, One Kill (PDF) - Christopher E. Pogue, Senior Security Analyst, Trustwave

Cheers!

--Claus V.

Read More
Posted in cheat sheets, forensics, Link Fest, malware tools, security, utilities | No comments

Rain-Delay Linkfest

Posted on 10:14 AM by Unknown

After an exceptional season of drought here in Texas, it looks like things are starting to change. We are facing at least five days of rain; heavy downpours mixed with long periods of light grey drizzles.

Planned yard-work long since abandoned.

Perfect weather for emptying the “to-be-blogged” hopper.

System Security

Time for new Flash updates. These are for the mainstream 11.1.x line of Flash builds. If you are running the 11.2.x line of beta Flash, I figure you are keeping up with those already.

Flash vulnerability exploited to deliver malware - Help Net Security has some good details about a threat that was patched as well as how it was flagged and described by security researcher Mila Parkour. While this Adobe rushes out critical Flash update post over at Ars Technica has some more details about “…the vulnerability, discovered by Tavis Ormandy and Fermin Serna of Google's security team, affects Flash players on Windows, Mac OS X, Linux, and Solaris operating systems, as well as Google Chrome and Android.”

I use these links from File Hippo for my Flash updating needs. Whatever source you prefer to use go get’em.

  • Download Flash Player 11.1.102.63 (IE) - FileHippo.com
  • Download Flash Player 11.1.102.63 (Non-IE) - FileHippo.com

PSI 3.0 Beta Launch -Secunia is rebuilding their Personal Software Inspector tool to now not only find and notify you about missing security updates and patches needed for applications and plug-ins on your system, but also make it easier to apply those found patches and updates in-application rather than hunting them out yourself. It is still a work in progress but should provide a good tool to help in the process.

Microsoft Security Bulletin Advance Notification for March 2012 - Microsoft Security TechCenter. MS Windows updates coming soon to a system near you!

Getting Inside the evil

I’ve really been enjoying Troy Hunt’s writings, both current and browsing through the archive material. These two posts were exceptionally eye-opening. Troy does an excellent job showing the process by which these scams work. Get out the notepad.

  • Scamming the scammers – catching the virus call centre scammers red-handed - Troy Hunt
  • Anatomy of a virus call centre scam - Troy Hunt

Introducing Adobe SWF Investigator - Adobe Developer Connection. New beta tool making the rounds on various security sites. Based on the Adobe AIR platform, it will help with SWF analysis from both static and dynamic angles.

Examining VSCs with GUI Tools - Journey Into Incident Response blog. Corey Harrell does a great job in showing methods to work with Volume Shadow Copies containers.

Browser Things

Password Generation - The Chromium Projects. We’ve touched on passwords here at GSD quite recently. This new component of Chrome development is pretty interesting. Having the built-in-browser ability to quickly and easily generate complex passwords is pretty cool. I hope some form of this feature matures into the mainstream builds.

Speaking of Chrome, for the longest time I have been using a portable build of Chromium (DEV builds)coupled with an updater application from Caschys Blog. Once a week or so I hit the updater and it finds and downloads/installs the newest version available from the source repositories. Unfortunately I wasn’t paying attention to what (or what not) was actually happening. When I recently saw the latest DEV build level in a RSS feed, I finally went back and checked what my Chrome DEV build was and it was WAY behind. Seriously WAY WAY behind. Bother. So now I am using this Google Chrome Portable page and scrolling down the the portable DEV build link. Updating is just a matter of downloading the file, and pointing it to the exiting location and overwriting it. If you are porting over your profile and extensions over from a previous portable version, the location they go into turned out to be quite different from the earlier portable DEV build I had been using.

It is now located in this folder location: “ …\GoogleChromePortableDev\Data\profile\Default”

Once I had my Chrome profile ported out of the old DEV version and into the new one, the difference in the builds was significant.

Mozilla’s Collusion tells who’s tracking you - Mozilla Links. Worth a look.

2-step verification - Google Apps Help. Google has a optional 2-step verification option to enhance the security of your account login process. FYI.

Freeware of Note

usboblivion - Google Project Hosting. Anti-forensics-like tool to purge USB history of USB-connected drives from Windows registry. Question: does use of the tool leave any tracks of its own behind? Spotted via this Addictive Tips blog post: Delete Record Of Previously Connected USB Devices Using USBOblivion

Rufus - Create bootable USB drives - Really neat and slick bootable USB creator tool. More details on these reboot.pro pages: Rufus and Rufus (introduction topic).

NTFS Permissions Reporter - Cjwdev - offered in both free and $ versions. Windows already has built-in methods to look at NTFS permissions but this is a nice GUI tool that some might find more useful at providing a wider-view on the permissions. Spotted via this Addictive Tips blog post: NTFS Permissions Reporter: View Access Permissions Applied On Folders.

regshot - Via SourceForge. Another tool to do before and after registry diff’ing. More details at this CybernetNews post: Monitor Registry Changes in Windows.

File Extension Monitor - NoVirusThanks - free/portable tool that allows real-time monitoring and logging of files created in the system. Great to run during setup files or to trace droppers/activity. Spotted via this Addictive Tips blog post: Monitor File Creation Activity Across Disk Volumes With File Extension Monitor.

HijackThis was my #1 go-to malware busting tool in the very early days of my IT career. I would use it slice-n-dice auto-run entries and bring back law-and-order to a malware-hijacked system. Over the years as my knowledge and skillset grew and tools matured, I’ve come to rely much more now on the Sysinternals Utilities. A one-two punch with Autoruns and Process Explorer coupled with the all-seeing-eye of Process Monitor typically provides me the hammer needed to bust into a hijacked system. So it was with fondness that I read this HijackThis now open source post at The H Security. I really hope that this move now gives new life and capability to this classic tool.

Peeking at NAFT - Didier Stevens is going crazy teasing us with a new project; a new forensic toolkit he is developing the “Network Appliance Forensic Toolkit (NAFT)”. Ooohhh!

Ezvid - Free Movie Maker and Slideshow Creator For YouTube. Spotted via this Addictive Tips blog post: Create Image & Video Slideshows With Narration Using ezvid.

Microsoft Research Cliplets - Neat project from MS Research that takes a digital video short, and allows you to isolate just a section of the motion. When exported the result is a static image with a section of movement. It’s a cool effect.

Multi-Image Fusion - This Microsoft Research project appears to be aiming as the next generation of Microsoft Image Composite Editor, or ICE. They have a 305-image composite on the page as a teaser. I love ICE but sometimes when I have a complex series of images and try to drag/drop them into ICE, it cannot stich non-sequential images into a composite. Related: Hugin - Panorama photo stitcher

For Sysadmins

BETA: PowerShell v3 Technical Guide (CTP2) - Kurt Shintaku's Blog

Service overview and network port requirements for the Windows Server system - Microsoft Support Article ID 832017.

[Review] God's Jury: The Inquisition, IT & Privacy - ReadWriteWeb. Curt Hopkins has a book review. What is really fascinating to me is how new technology can make the evils of dark history past relevant and accessible again with the dizzying pace (again) of information aggregation. Amazon has a Kindle version that will soon be making an appearance here in the Valca home.

Network Stuff

Nmap 5.61TEST5 released with 43 new scripts,improved OS & version detection, and more available for download - ISC Diary

Wireshark and Pcap-ng - Wireshark blog - news that Wireshark 1.8.0 will have two new features: concurrent capture from multiple interfaces and packet annotation. These changes appear to rely on pcap-ng file formats. Hopefully applications that rely on the pcap format will adjust and add compatibility for the pcap-ng format but if not, be sure you save your captures in a format that can be imported (or exported into) a file format compatible with your NFA tools.

Detecting sniffers with HSD - Hexacorn blog. Free tools and techniques for detecting the presence of network sniffing activity.

Tony Fortunato over at the LoveMyTool community blog has a video showing Using Pathtest for Performance Measurement. PathTest is a free tool to test network bandwidth capacity between two endpoints using packet-flooding techniques. This is a serious tool so use carefully and during non-production hours unless you (and your customers) really, really know what you are doing and why you need to do so. Cool tool!

Cheers!

--Claus V.

Read More
Posted in anti-virus software, books, boot-cd's, browsers, Chrome/Chromium, Firefox, forensics, Gmail, Google, graphics, Link Fest, malware tools, Microsoft, networking, NFAT, security, utilities | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Network Capture Tools and Utilities
    At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
  • It just has to be bigger on the inside…
      Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
  • Mostly Minor Network Notes
    Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
  • Windows Live Mail error 0x80041161
    Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
  • FireCAT 1.5 “Plus” Add-On Collection
    In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ▼  November (8)
      • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
      • ForSec Linkfest - 2013 DST Fallback Edition
      • CryptoLocker Ransomware Info & Free Prevention Sol...
      • Linkfest for the SysAdmins
      • Microsoft Security Essentials/Defender & PowerShell
      • Miscellaneous TrueCrypt linkage
      • PowerShell 4.0 and a tiny “gotcha”
      • New Software Updates + VMware Tools Update fix
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile