Tuesday, July 16, 2013

Results of the 4cast Awards Nominations

As previously announced, I was nominated for 'Digital Forensics Examiner of the Year' at the Forensics 4cast Awards. The awards ceremony was held last week during the DFIR summit, and I voted the winner in the category. I am very grateful for this award and recognition and hope to have another strong showing next year!

Monday, July 8, 2013

Interview on the Healthy Paranoia podcast

I was recently interviewed on the Healthy Paranoia podcast about memory forensics during DFIR as well as other related topics. It was a really fun time, and I hope to be on the show again in the future. Read about the interview and listen to the MP3 here:

http://packetpushers.net/healthy-paranoia-show-14-digital-forensics-and-incident-response-with-andrew-case/

Please contact me if you any feedback or comments about the show.

Thanks,
Andrew (@attrc)

Thursday, June 13, 2013

Final Week of Month of Volatility Plugins II is posted

We are writing as the final week of the second installment of the Month of Volatility Plugins is now posted. Volatility 2.3 is currently in beta, and the blog posts are focusing on new features in this version. 

This week's posts discussed a number of new and updated plugins used to analyze Mac systems. 

The first post demonstrated leveraging process cross-view analysis for Mac rootkit detection: 

http://volatility-labs.blogspot.com/2013/06/movp-ii-41-leveraging-process-cross.html 

The second post covered dumping, scanning, and searching process memory:

http://volatility-labs.blogspot.com/2013/06/movp-ii-42-dumping-scanning-and.html 

The third post discussed how to recover networking information:  

http://volatility-labs.blogspot.com/2013/06/movp-ii-43-recovering-mac-os-x-network.html 

The fourth post showed a number of artifacts in Mac kernel memory:  

http://volatility-labs.blogspot.com/2013/06/movp-ii-44-whats-in-your-mac-osx-kernel.html 

The fifth post analyzed the Rubilyn kernel rootkit and detected it in a number of ways:

http://volatility-labs.blogspot.com/2013/06/movp-ii-45-mac-volatility-vs-rubilyn.html 

We hope you have enjoyed this month's posts and will be trying 2.3 when its released!

Thanks,

Andrew (@attrc)

Wednesday, May 29, 2013

Second Week of Month of Volatility Plugins II is posted

We are writing as the second week of the second installment of the
Month of Volatility Plugins is now posted. Volatility 2.3 is currently
in beta, and the blog posts are focusing on new features in this
version. This week's posts discussed a number of new and updated
plugins used to analyze Windows systems.

The first post discussed recovering RSA Private Keys and SSL
Certificates from memory:

http://volatility-labs.blogspot.com/2013/05/movp-ii-21-rsa-private-keys-and.html

The second post discussed recovering information about unloaded kernel
modules from memory:

http://volatility-labs.blogspot.com/2013/05/movp-ii-22-unloaded-windows-kernel_22.html

The third post showed how to create timelines with in-memory data
using Volatility:

http://volatility-labs.blogspot.com/2013/05/movp-ii-23-creating-timelines-with.html

The fourth post demonstrated how to recover MFT entries and utilize
them during investigations:

http://volatility-labs.blogspot.com/2013/05/movp-ii-24-reconstructing-master-file.html

The last post highlighted a number of new and updated plugins that are
very useful during investigations:

http://volatility-labs.blogspot.com/2013/05/movp-ii-25-new-and-improved-windows.html

We hope you enjoy the posts, and the third week of posts will begin
tomorrow and cover a number of new plugins to help analyze Linux and
Android samples.

If you have any questions or comments please comment on an individual
blog post or reply to this email.

Thanks,
Andrew (@attrc)

First week of Month of Volatility Plugins II is posted

We are writing as the first week of the second installment of the
Month of Volatility Plugins is now posted. Volatility 2.3 is currently
in beta, and the blog posts are focusing on new features in this
version. This week's posts discussed a number of new address spaces we
have added to support new hardware architectures and file formats.

The first one is the MachO address space used to support Mac Memory Reader:

http://volatility-labs.blogspot.com/2013/05/movp-ii-11-mach-o-address-space.html

The second is an address space used to support VirtualBox:

http://volatility-labs.blogspot.com/2013/05/movp-ii-12-virtualbox-elf64-core-dumps.html

The third address space allows for analysis of VMware snapshot files
(.vmss and .vmsn):

http://volatility-labs.blogspot.com/2013/05/movp-ii-13-vmware-snapshot-and-saved.html

The fourth address space supports the hpak format of the HBGary Fast
Dump acquisition tool:

http://volatility-labs.blogspot.com/2013/05/movp-ii-14-new-hpak-address-space.html

The final address space discussed adds support for the ARM
architecture. This is leveraged by Volatility's Android support:

http://volatility-labs.blogspot.com/2013/05/movp-ii-15-arm-address-space-volatility.html

We hope you enjoy the posts, and the second installment of posts will
begin tomorrow and cover a number of new plugins to help analyzing
Windows samples.

If you have any questions or comments please comment on an individual
blog post or email the author.

Thanks,
Andrew (@attrc)

Tuesday, March 12, 2013

BSides New Orleans Speaker Lineup Published



We are writing to announce that the BSides New Orleans speaker lineup is now released. For those unaware, BSides New Orleans is a free, all day information security conference taking place on May 25th in New Orleans. We received so many strong submissions, from companies such as Google, Ernst & Young, Mad Security, and HP, that we have expanded the conference to 3 tracks for a total of 18 presentations. Complete information about the conference and speakers can be found here:


Between the strong lineup and the fact that the conference is New Orleans, we expect the seats to fill fast. If you want to attend (free), you must fill out the EventBrite form referenced on the wiki page. You only have to give your name and email for registration, and we promise not to spam you. If you have any questions about the event, please email bsidesnola [ @ ] gmail.com.

Thanks,
Andrew (@attrc)

Friday, February 15, 2013

Memory Forensics Talk at RSA!

On Wednesday of RSA I will be giving a talk titled:

"Memory Forensics: Defeating Disk Encryption, Skilled Attackers and Malware"

 This talk will focus on three key points:

1) Showcasing the power and usefulness of memory forensics
2) Distinguishing memory forensics from disk forensics
3) Highlighting why live forensics should not be used and instead analysts should switch to using offline memory forensics

Throughout the talk there will be many examples of powerful rootkits, techniques of advanced attackers, and looking at Android and software-based disk encryption.

If you are interested in the talk and plan on attending, please add it to your conference calendar:

https://ae.rsaconference.com/US13/connect/sessionDetail.ww?SESSION_ID=1885

If you have any questions about the talk or or want to meet up at RSA then please contact me or ping me on Twitter (@attrc).