With this blog post I am pleased to announce the publication of a new ERNW White Paper about our incident analysis and digital forensics framework. It is available on our website.
Due to the increasing number and impact of computer security incidents, it has become essential to develop and implement efficient measures for their investigation. However, comprehensive forensic analyses are time-consuming, and this time is often not available to security analysts during computer security incidents. As a result, automated tools are increasingly being used. These tools, however, often cover only a limited scope of the necessary analyses and typically require deep technical expertise to be used effectively.
Last week I gave a talk at #TROOPERS26: Integrating Incident Analysis and Digital Forensics Tooling for Automated Compromise Detection. I discussed the challenges of incident analysis, such as increasing storage capacities and the lack of integration between tools. I presented a modular framework that integrates established forensic and analysis tools using a decision-tree-based control mechanism. A workflow was designed to control the execution of 14 integrated analysis tools in order to reproduce the manual analysis process usually performed by analysts. Moreover, the framework is capable of identifying whether a system has been compromised and compiles a analyst-oriented report. Together with the audience we took a look at the report in a live demonstration. The evaluation results of the framework were promising as it was able to identify all compromised systems. However, a significant number of false positive classifications were also observed. To improve the framework possible future extensions include functionality such as recovering already deleted files to detect missed Indicators of Compromise. Additionally, our team want to integrate artificial intelligence in the workflow to help in data processing and make more decisions automatically. The slides will be published next week on the conference website. I will add the link in this blog post when they become available. A more detailed description of the content of the talk can be found in the following sections. Looking forward to #TROOPERS27!
In a recent incident response project, we had the chance to virtually look over
the attackers’ shoulder and observe their activities. The attackers used the
Remote Desktop Protocol (RDP) for lateral movement within the compromized
environment and beyond (MITRE techniques
T1570,
T1021). As a matter of fact,
RDP creates cache files that contain tiles of the transferred screen recording
data. While this fact is well-known and there are existing tools, we found it
worth reporting because of two different aspects:
For the realization and introduction of autonomous vehicles, the safe interaction of functions, systems and services as well as their monitoring over the entire product life cycle is essential. An exclusive security-by-design approach is no longer sufficient and must be continuously supported by feedback obtained from in-the-wild operation. This is where the recently successfully completed joint project BMBF UNCOVER comes into play, which targets the requirements of the standards ISO/SAE 21434 (Road vehicles – Cybersecurity engineering) and ISO 21448 (Road vehicles – Safety of the intended functionality (SOTIF)).
I’m happy to announce the publication of the paper
Windows memory forensics: Identification of (malicious) modifications in memory-mapped image files
at this years DFRWS USA, and the release of the corresponding
volatility plugin.
With this research came also an update to the Ptenum family (affecting
especially the ptemalfind plugin), which makes the plugins reliable in
identifying modified pages despite memory combining, so make sure to grab the
newest version from the Github repository.
The IMF Conference is the International Conference on IT Security Incident
Management & IT Forensics. This year it took place from May 23 to 24 in Munich.
The schedule lists
a lot of interesting talks.
One of the talks was my presentation on a paper about Ceph forensics, based on
my Master Thesis:
The concept of Software Defined Storage (SDS) has become very popular over the
last few years. It is used in public, private, and hybrid clouds to store
enterprise, private, and other kinds of data. Ceph is an
open-source software that implements an SDS stack.
I’m happy to announce the
release of several plugins for
Volatility 3 that allow you to dig deeper into the memory analysis. One of those
plugins is PteMalfind, which is essentially an improved version of malfind.
Another one is PteResolve which, similarly to the WinDBG command !pte,
allows you to inspect Page Table Entry (PTE) information for e.g., a given
virtual address. In this blog post we will have a closer look at these and more
plugins, and the PteEnumerator base class and what you can do with it. The
memory dump used for this blog post is available
here. Some of
the injection tools used in this blog post can be gathered from
here.
I recently stumbled upon a strange behavior in my Firefox: I visited an
HTTPS-enabled website that I had visited before and saw that my Firefox
connected insecurely via HTTP. I found that strange because nowadays, most
websites set the
HSTS
header, which is supposed to force the browser to connect via HTTPS. I checked
whether this website set the HSTS header – and it did. This means my Firefox was
ignoring/forgetting about the HSTS header right after my visit.
I am glad to announce the release of the ERNW whitepaper 71 containing
information about quarantine file formats of different AV software vendors. It
is available
here.
Anti-Virus Software
I took quarantine files from real-life incidents and created some in a lab
environment. Afterwards I tried to identify metadata, like timestamps, path
names, malware names, and the actual malicious file in the quarantine files. One
goal was to use this information to support our incident analyses: Using the
results, we can now easily create timelines showing information about
quarantined files, extract the detected malware, and sometimes even find
information about processes that created the malicious files.
The use of Internet of Things devices is continuously increasing: People buy devices, such as smart assistants, to make their lives more comfortable or fitness trackers to assess sports activities. According to the Pew Research Center [1], every fifth American wears a device to track their fitness. In Germany, the number increases likewise. The increasing number of fitness trackers in use can also be seen in criminal proceedings, as there exist more and more cases where these devices provide evidence.