{"id":732,"date":"2020-08-27T21:28:49","date_gmt":"2020-08-27T20:28:49","guid":{"rendered":"https:\/\/cybercop-training.ch\/?p=732"},"modified":"2020-09-07T21:25:14","modified_gmt":"2020-09-07T20:25:14","slug":"disk-forensics-p1","status":"publish","type":"post","link":"https:\/\/cybercop-training.ch\/?p=732","title":{"rendered":"Disk Forensics P1"},"content":{"rendered":"<p dir=\"ltr\">Disk forensics techniques are used to acquire the disk image, process this image to find artifacts of interest including deleted ones.<\/p>\n<p dir=\"ltr\">In this lab, a disk image file \u201cevidence.img\u201d is provided in the home directory of the root user (\/root\/). Interact with the image using <a href=\"https:\/\/github.com\/sleuthkit\/sleuthkit\" target=\"_blank\" rel=\"noopener noreferrer\"><b>The Sleuth Kit<\/b><\/a>\u00a0and answer the following questions:<\/p>\n<ol>\n<li>\n<blockquote><p>What is the image format type of the image?<\/p><\/blockquote>\n<\/li>\n<li>\n<blockquote><p>Which file system type is used in the image?<\/p><\/blockquote>\n<\/li>\n<li>\n<blockquote><p>Which directory was mounted most recently from the disk whose image is provided to us?<\/p><\/blockquote>\n<\/li>\n<li>\n<blockquote><p>List the names of the directories present on the image.<\/p><\/blockquote>\n<\/li>\n<li>\n<blockquote><p>What is the name of the file present in the notes directory?<\/p><\/blockquote>\n<\/li>\n<li>\n<blockquote><p>Retrieve the flag kept inside the flag.txt file.<\/p><\/blockquote>\n<\/li>\n<\/ol>\n<p>Let&#8217;s check which file types are possible<\/p>\n<p><code>img_stat -i list<\/code><\/p>\n<p><a href=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-736\" src=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_1.png\" alt=\"\" width=\"1009\" height=\"879\" srcset=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_1.png 1009w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_1-300x261.png 300w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_1-768x669.png 768w\" sizes=\"auto, (max-width: 1009px) 100vw, 1009px\" \/><\/a><\/p>\n<p><code>img_stat -t evidence.img<\/code><\/p>\n<p><a href=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-738\" src=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_2.png\" alt=\"\" width=\"730\" height=\"295\" srcset=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_2.png 730w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_2-300x121.png 300w\" sizes=\"auto, (max-width: 730px) 100vw, 730px\" \/><\/a><\/p>\n<blockquote><p><strong>Answer 1: raw<\/strong><\/p><\/blockquote>\n<p>To answer question 2 let&#8217;s list the supported file types first<\/p>\n<p><code>fsstat -i raw -f list<\/code><\/p>\n<p><a href=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-741\" src=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_3.png\" alt=\"\" width=\"672\" height=\"726\" srcset=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_3.png 672w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_3-278x300.png 278w\" sizes=\"auto, (max-width: 672px) 100vw, 672px\" \/><\/a><\/p>\n<p><code>fsstat -i raw -t evidence.img<\/code><\/p>\n<p><a href=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_4.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-742\" src=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_4.png\" alt=\"\" width=\"803\" height=\"227\" srcset=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_4.png 803w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_4-300x85.png 300w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_4-768x217.png 768w\" sizes=\"auto, (max-width: 803px) 100vw, 803px\" \/><\/a><\/p>\n<blockquote><p><strong>Answer 2: ext4<\/strong><\/p><\/blockquote>\n<p>I&#8217;ll go ahead to get the directory that was mounted most recently<\/p>\n<p><code>fsstat -i raw -f ext4 evidence.img<\/code><\/p>\n<p><a href=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_5.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-743\" src=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_5.png\" alt=\"\" width=\"912\" height=\"647\" srcset=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_5.png 912w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_5-300x213.png 300w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_5-768x545.png 768w\" sizes=\"auto, (max-width: 912px) 100vw, 912px\" \/><\/a><\/p>\n<blockquote><p>answer: \/mnt\/disk0<\/p><\/blockquote>\n<p>To list the names of the directories that are being present in the image I&#8217;ll use the following command:<\/p>\n<p><code>fls -i raw -f ext4 evidence.img<\/code><\/p>\n<p><a href=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_6.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-744\" src=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_6.png\" alt=\"\" width=\"816\" height=\"257\" srcset=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_6.png 816w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_6-300x94.png 300w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_6-768x242.png 768w\" sizes=\"auto, (max-width: 816px) 100vw, 816px\" \/><\/a><\/p>\n<blockquote><p>Answer 4: notes, photos, videos<\/p><\/blockquote>\n<p>To get the name of a specific file in the notes directory I use the following command:<\/p>\n<p><code>fls -i raw -f ext4 evidence.img <strong>12<\/strong><\/code><\/p>\n<p><a href=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_7.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-746\" src=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_7.png\" alt=\"\" width=\"851\" height=\"120\" srcset=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_7.png 851w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_7-300x42.png 300w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_7-768x108.png 768w\" sizes=\"auto, (max-width: 851px) 100vw, 851px\" \/><\/a><\/p>\n<blockquote><p>Answer 5: flag.txt<\/p><\/blockquote>\n<p>Now I need to find a way to see what&#8217;s stored inside the file flag.txt<\/p>\n<p><code>icat -i raw -f ext4 evidence.img <strong>16<\/strong> &gt;flag.txt<\/code><\/p>\n<p><a href=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_8.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-747\" src=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_8-1024x238.png\" alt=\"\" width=\"1024\" height=\"238\" srcset=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_8-1024x238.png 1024w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_8-300x70.png 300w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_8-768x178.png 768w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/08\/sleuth_8.png 1093w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/p>\n<blockquote><p>Answer 6: baa82c37e53e2886a8a1379f4e3c2999<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\"><p>Disk forensics techniques are used to acquire the disk image, process this image to find artifacts of interest including deleted ones. In this lab, a <a class=\"mh-excerpt-more\" href=\"https:\/\/cybercop-training.ch\/?p=732\" title=\"Disk Forensics P1\">[&#8230;]<\/a><\/p>\n<\/div>","protected":false},"author":2,"featured_media":735,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,16],"tags":[],"class_list":["post-732","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-forensic","category-linux"],"_links":{"self":[{"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=\/wp\/v2\/posts\/732","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=732"}],"version-history":[{"count":6,"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=\/wp\/v2\/posts\/732\/revisions"}],"predecessor-version":[{"id":748,"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=\/wp\/v2\/posts\/732\/revisions\/748"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=\/wp\/v2\/media\/735"}],"wp:attachment":[{"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=732"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=732"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=732"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}