Raul Siles

Incident Response (IR) & Forensics / Respuesta ante incidentes & A. Forense

Whitepapers Tools Web Books

You have seen something suspicious in one of your systems and you think that perhaps it has been compromissed. You need to confirm if your guess is true or not. Then, you incident handling/management/investigation/response... methods, whatever you want to call them, should be applied and will help you manage the situation. In the worse case scenario, you have been hacked, so you should determine How, What, Who, When, Where, Why...; the forensic analysis techniques will answer all these!

Has visto algo sospechoso en uno de tus sistemas y piensas que quizás ha podido ser comprometido. Debes confirmar si tu sospecha es cierta o no. Entonces, tus métodos de manejo/gestión/investigación/respuesta ante incidentes, como quieras llamarlos, deben entrar en juego y ayudarte a resolver la situación. En el peor caso, el sistema fue vulnerado, por lo que deberías determinar Cómo, Qué, Quién, Cuándo, Dónde, Porqué...; para ello dispones de las técnicas de análisis forense!

Whitepapers / Artículos
Freeware Forensics Tools for UnixDerek ChengNovember, 2001
Windows Forensics: A Case Study, Part OneStephen BarishDecember, 2002
Windows Forensics: A Case Study, Part TwoStephen BarishMarch, 2003
Handbook of Forensic ServicesU.S. DoJ2003
Detailed Explanation of FAT Boot SectorMicrosoftDecember, 2003
Computer Security Incident Handling GuideNISTJanuary, 2004
Forensic Analysis of a Live Linux System, Pt. 1Mariusz BurdachMarch, 2004
Forensic Analysis of a Live Linux System, Pt. 2Mariusz BurdachApril, 2004
A Method for Forensic PreviewsTimothy E. WrightMarch, 2005
Web Browser Forensics, part 1Keith J. Jones, R. BelaniMarch 2005
Web Browser Forensics, part 2Keith J. Jones, R. BelaniMay 2005
Advanced Antiforensics: SELFPluf & RipeAugust, 2005
Process Dump and Binary ReconstructioniloAugust, 2005
Packet forensics using TCPD. Parker, M. SuesAugust 2005
Windows Memory Analysis ChallengeDFRWS2005
Tracing an E-mailRavenJanuary, 2006

Tools / Herramientas
dcflddNick HarbourEnhanced "dd"
TSK & AutopsyBrian CarrierThe Sleuth Kit & The Autopsy Forensic Browser: digital forensics tools
DFTTBrian CarrierDigital Forensics Tool Testing Images
AFFSimson L. GarfinkelAdvanced Forensic Format (AFF)
ExiftoolPhil HarveyRead and write meta information in image, audio and video files
TcpxtractNick HarbourTool for extracting files from network traffic based on file signatures
ForemostAfosi, CisrConsole program to recover files based on their headers/footers/structures

Analysis CDs
Helixe-fenseIncident Response & Computer Forensics Live CD
FCCU (d-fence)Christophe MonniezFCCU GNU/Linux Forensic Boot CD
F.I.R.E.Dirk LossForensic and Incident Response Environment on a bootable CD-ROM
Penguin SleuthErnest BacaPenguin Sleuth Bootable CD
RIPKent Robotti(R)ecovery (I)s (P)ossible Linux rescue CD

Windows
PascoThe Open Forensics GroupA tool for analyzing the Microsoft Windows index.dat file (Odessa)
GalletaThe Open Forensics GroupA tool for analyzing Internet Explorer cookies (Odessa)
RifiutiThe Open Forensics GroupA tool for investigating the Microsoft Windows recycle bin info2 file (Odessa)
Web HistorianRed CliffTool for reviewing websites stored in the history files of the most commonly used browsers
Unix utilsKarl M. SyringCommon GNU utilities to native Win32
FSPHarlan CarveyForensic Server Project: retrieve volatile data from compromised systems

Web
Open Source Digital ForensicsReference for the use of open source software in digital forensics and incident response
IACISThe International Association of Computer Investigative Specialists
HTCNHigh Tech Crime Network
Forensics.nl (www.forensix.org)Computer Forensics, Cybercrime and Steganography Resources
E-evidence infoThe Electronic Evidence Information Center
IH Windows 2000/XPIntrusion Discovery Windows 2000/XP - Cheat Sheet (SANS Institute)
IH LinuxIntrusion Discovery Linux - Cheat Sheet (SANS Institute)
Digital DetectiveForensic Computing Tools & Utilities
NSRLNational Software Reference Library (NIST)
Forensic-es.org Portal dedicado a la ciencia informática forense
Conferences

DFRWsDigital Forensic Research Workshop (DFRWS)
IMFInternational Conference on IT-Incident Management & IT-Forensics
Mailing lists

The Sleuth Kit InformerBi-monthly newsletter for The Sleuth Kit, Autopsy, and related tools (Brian Carrier)

Books / Libros
Incident Response and Computer Forensic, 2nd Ed.C. Prosise, K. Mandia, M. Pepe (McGraw-Hill)July 2003
Windows Forensics and Incident RecoveryHalan Harvey (Addison Wesley)July 2004
Forensic Discovery Dan Farmer, Wietse Venema (Addison Wesley)December 2004
File System Forensic Analysis Brian Carrier (Addison Wesley)March 2005
Real Digital Forensics: Computer Security and Incident ResponseK. Jones, R. Bejtlich, C. Rose (Addison Wesley)September 2005