Friday, March 19, 2021

Feeling kinda blue (team)

Hello all! It took me much longer than I had planned to post again, but life has a way of keeping one busy. Between extra crazy hours at work, spending two weeks in bed "enjoying" the Covid-19 experience and otherwise just being busy as heck, I'm finally back to write a little.

In my last post, I said that I felt like it was unlikely I'd work in a digital forensics or any other security role ever again. I just didn't feel like I had a real chance to do anything in the field again. However, thanks to a lot of encouragement from a good friend, I'm studying and hoping to land a job as a entry level SOC analyst. The work seems very interesting to me and I believe it's something I would love.

Just like my earlier days getting into digital forensics, the ol' budget is pretty much nothing, so I'm actively searching out free and low cost training opportunities. The best source I've found for information on free and low cost training is on the DFIR Diva site. Along with her training information pages, Elan has so much more on the site that helps security noobs and veterans as well. I nominated her site for the DFIR Resource of the Year Forensic 4:cast Award and I hope you will too. There are so many great resources out there, but I think this one deserves recognition for it's fantastic wealth of information for those new or returning to the field.

One fantastic training I attended last month was the SOC Core Skills course taught by John Strand. This is a 16 hour (4 hours per day, 4 days) class that teaches entry level folks the basics they need to work in a SOC. It includes both lecture and labs. From the course info page, here's what the class teaches:

  1. Core networking skills
  2. Live Windows Forensics
  3. Live Linux Forensics
  4. Memory Forensics
  5. Active Directory Analysis
  6. Network Threat Hunting
  7. Basics of Vulnerability Management
  8. The Incident Response Process

The class is "pay what you can", so there is no reason for anyone to say they can't afford it. I was very impressed with the quality of the training. A Windows virtual machine is used in the course and it has all the lab materials. The lab materials are frequently updated.

Another opportunity I'm taking advantage of is the community version of Rangeforce. This free version of the site includes 20 course modules covering such things as Splunk, Docker, regular expressions, Kubernetes and so much more. This is an incredible resource and I'm learning a lot from it. The modules are taught in virtual machines so you can do hands on learning. I absolutely love this site and encourage you to give it a look.

I'm also training on the TryHackMe site. Like Rangeforce, there is free and paid training available and it too uses virtual machines in the browser to perform the labs. I'm having a lot of fun with this site too. I'm enrolled in the free Cyber Defense path which includes modules like Intro to Networking, Network Services, Active Directory Basics and more.

I've spent a little time on LetsDefend.IO This site simulates working in a SOC environment and does it pretty well. I've worked through the free exercises and plan to subscribe soon so that I can do more.

Finally, a great video resource I've found is the YouTube channel of Gerald Auger called Simply Cyber. He does a lot of great videos on getting into Cyber Security.

So that's all I've got for now. My progress through all of this is pretty slow, given my work schedule. When I have free time, I spend a lot of it working through this excellent training and look forward to finding more. Hope you all are well and thanks for reading!

Saturday, October 10, 2020

Where the heck have I been?

In the unlikely chance that someone will read this, I thought I'd just say hello and talk about what I've been doing since my last post nearly two years ago. Since then, I've disappeared from and then reappeared on social media and got a new job.

I'm currently in a job completely unrelated to anything I've ever done before. I'm working for a national home improvement store chain in the electrical department. I've learned so much about home electrical wiring and everything that goes with it and I'm really enjoying it. The hours are pretty crazy, but the work is usually enjoyable. After almost 4 years of retirement, I needed to get off my butt and do something productive again.

With all that said, I've recently started re-engaging with the DFIR world. This is because I missed learning cool new things and then experimenting with them on my own. From the first time I ever learned about digital forensics, I've been fascinated by it and all the different things that fall under the DFIR umbrella.

More importantly, I've missed the people. I made a lot of good friends over the years and I've lost touch with them for the most part, which I truly hate. So I've started trying to get back in touch with old friends and hope they're interested in being back in touch with me.

While I don't know if it's likely I'll ever work in any DFIR related job again, I still want to stay engaged with it. I love it and it's good for the brain to keep learning. That's why I've signed up for some free training courses and am working through them at the moment.

The courses I'm currently taking are both from Basis Technology. One is an introductory course called Intro to DFIR: The Divide and Conquer Process. The other Basis Tech course I'm taking is Autopsy Basics and Hands On. Both courses are online. I'm learning new investigative concepts, as well as being reminded of things I used to know and had forgotten about. I'm grateful to Basis for making these courses available.

My current plan, such as it is, is to continue these courses just to get my mind active on the subject(s) of DFIR. I've already started realizing just how much I've forgotten and how much has changed over the last few years. I'm excited to be thinking about these topics again. 

I reopened this blog in hopes it will prompt me to continue learning and writing about what I've learned. I always enjoyed writing and have missed doing it on a regular basis.

Be well and I'll be back with another post soon.

Tuesday, December 4, 2018

DFIR Training

Hello all! Back again, though not as soon as I had thought. Anyway, today I want to tell those who haven't already heard about the training offered by Brett Shavers. His courses have recently moved to a new home at https://www.patreon.com/DFIRtraining. This is where you will find all his current courses, as well as new courses as they come out. All courses are bundled and available for a monthly subscription.

I reviewed his old WinFE course four years ago. You can read it HERE, although that course is no longer active. I have also had access to his older X-Ways Forensics course and learned a lot from it.

While I haven't taken any of his newest training, the courses I've seen were great. The material itself is very well prepared and presented. The video and audio quality is also good, with items on screen easy to see and understand.

DFIR training is usually very expensive, as we all know. Brett is offering some high quality training at a fraction of the cost of many other courses. I plan to become one of his Patreon supporters soon and experience his newest offerings.

Brett also started a DFIR oriented social network at https://social.dfir.training/. There are currently three groups on the site. One group is for DFIR Book Giveaways. Group members have the opportunity to win DFIR related books on a monthly basis. The other two groups are a SANS FOR 508 study group and a WinFE group.

Kudos to Brett for all he's doing with these sites. I encourage you to support him on his Patreon page and take part in some good DFIR training.

Tuesday, August 28, 2018

Life Update, a little Object ID research and More

It's been just over two years since I retired from the police department. As a retiree, I've enjoyed a lot of time with my wife, kids and grandkids, spent a lot of hours on my tractor, taken many walks in the woods and generally enjoyed life. As much as I've enjoyed my time off, I've realized I'm too young to be "really" retired.

While trying to figure out what I want to be when (if) I grow up, the field of digital forensics is always at the top of my list. I've missed the fun of learning cool new things and I miss solving cases. I often think back to my first case and how much I enjoyed doing that investigation. Finding what was on the computer and being able to report how and when it got there was so cool. Doing my own testing to find how artifacts were created and using that testing to help me tie the illegal materials in question to a certain user account, eventually getting a conviction was something I'll never forget.

I know that getting into forensics in the private sector won't be easy for me. I've accepted the possibility that it may never happen, but I'm going to give it a try. I know I have much to learn and catch up on. But honestly, learning the material is at least half the fun, right?
-------------------------

Speaking of learning, I watched the Forensic Lunch Test Kitchen with David Cowen a few days ago. In the video, he demonstrated the difference between Windows 7 and Windows 10 when it comes to the creation of an Object ID for a file. I recreated the test he did here and got the same results of course. But I started thinking about what may or may not change those results.

I wondered what might happen if I created the file as David did and then copied it to another location on the disk. I created a file called Never-opened.txt in my Documents folder. It was automatically given an object ID as expected from the earlier test. Next, I copied the file to another folder and used fsutil once again to check for an object ID for the copied file. In this case, no object ID was assigned.

Finally, I cut the file from it's original location and pasted it to another folder. the object ID traveled with the file to its new location. I went back and opened the copied file and as expected, a new object ID was created for it.  This testing all occurred on a Windows 10 Home system.

After talking with David, I've got a few other things I want to test as well. I'll post more when that's been done.
-------------------------

Finally, Brett Shavers wrote an excellent post on his blog How to start a digital forensic lab in your police department. The experiences he talked about were very similar to mine. He's absolutely right that you can make it happen, but it takes a lot of work and commitment to get it done. I was fortunate to have a chief who was very receptive to my ideas and helped me make it happen.

I wrote several grants to get funding for software and hardware. In addition to Federal grants, I was able to obtain funding from two different local foundations and one corporation. I like writing anyway, so getting to write a grant narrative explaining what I wanted and why was an enjoyable part of the process

Brett also talked about training. Like he mentioned, I paid my own way through some of my training (SANS FOR 508, 526 (old version) and 558 (old network forensics course). However, being in law enforcement, I also had the opportunity to attend training put on by the National White Collar Crime Center (NW3C). I took the NW3C BDRA and IDRA courses and those gave me an excellent introduction to the world of forensics prior to my SANS course attendance. If you are in in law enforcement, make sure you take advantage of the courses available to you for free through the NW3C.

-------------------------

That's it for now. I hope to start posting a little more often as time allows. Be well!

Friday, June 30, 2017

DFIR Reminiscing

Hello all. I have a new, mostly non-forensics blog that I occasionally post to. I just posted yesterday on a topic that I thought would be interesting to readers of this blog as well. The post is about fun/cool stuff I've acquired over the last few years from conferences and friends. Instead of re-posting it here, just take a look at the post on my Mental Field Trip blog.

Thursday, February 2, 2017

2017 Forensic 4:cast Awards Nominations are Open!

Just in case anyone still stops by this blog, I wanted to post that nominations are now open for the 2017 Forensic 4:cast Awards. Click HERE to go and nominate your favorites. I think the 4:cast Awards are a very good thing for the DFIR community and encourage you to participate. Thanks to the great Lee Whitfield for continuing to run the awards program every year. Your efforts do not go unappreciated.

Regarding my last post way back in July, I was unable to attend ArchC0n 2016 due to illness. I'm really sorry to have missed it, especially since I learned recently that this was the final ArchC0n. Congratulations and thanks to Paul Jaramillo and crew for what was an excellent conference.

Since my retirement, I haven't been especially active in the world of forensics. I did work one case for the local sheriff's office that involved a Raspberry Pi. That was my first Linux related investigation and it was pretty interesting. When I get some time and my thoughts together, I'll try to post about it as it was fun working something different than a Windows case.

Till the next time, take care and don't forget to head over to the Forensic 4:cast website and nominate your favorites for an award.


Friday, July 29, 2016

ArchC0n 2016

 Hello Dear Readers. I hav returned to the blogosphere (I hate that term) to remind you of a great security conference coming up. ArchC0n 2016 will be held August 26 at the Hyatt Regency in St. Louis.

This will be the third annual ArchC0n and once again it looks like it's going to be a great one. I've attended the previous events and had a great experience with each. I cannot recommend this conference enough.

 I like to call ArchC0n the "little con that could" because, for a new conference, they've consistently come up with great speakers and workshops. This year looks to be no different in that respect. Malware is one of  my favorite subjects and there will be plenty of info on that topic presented by Harlan Carvey and Andrew Pease. I've attended several of Harlan's talks over the last few years and can tell you he's an entertaining speaker.

Likewise, I've previously attended talks by Kyle Maxwell, Andrew Hay, Robert M Lee and Scott Roberts. Each of them is someone I look up to in the field and I'm excited to hear them speak again. You can view the full list of speakers and trainers HERE. The program schedule can be found HERE.

I'm planning to attend ArchC0n 2016 and I hope to see you there too. It's a great conference and it's one that I hope will continue to be an annual event for a very long time to come. Follow the ArchC0n Twitter account for news.