CS 493/593: Digital Forensics
Location: FAB 10 (TR 09:00 - 10:40)
Instructor: D. Kevin McGrath
- PDX username: dmcgrath
- Office hours:
- Location: FAB 120-15
- Times:
- Wednesday: Code Party! 18:00 - 22:00 (FAB 86-01)
- Whenever you see me in my office with the door open.
Syllabus
Recorded Lectures
All of these are raw recordings, and have not been edited.
- Week 1 - Lecture 1: no recording
- Week 1 - Lecture 2: no recording
- Week 2 - Lecture 1
- Week 2 - Lecture 2
- Week 3 - Lecture 1
- Week 3 - Lecture 2
- Week 4 - Lecture 1
- Week 4 - Lecture 2
- Week 5 - Lecture 1
- Week 5 - Lecture 2
- Week 6 - Lecture 1
- Week 6 - Lecture 2: no class due to illness
- Week 7 - Lecture 1
- Week 7 - Lecture 2: no recording
- Week 8 - Lecture 1: no recording
- Week 8 - Lecture 2: no recording
- Week 9 - Lecture 1: no recording
- Week 9 - Lecture 2: no recording
- Week 10 - Lecture 1: no recording
- Week 10 - Lecture 2: no recording
Lecture Content
- Background Reference – supplemental concepts (NTFS internals, 802.11 endianness, TCP in timeline context, legal constraints overview)
- Digital Forensics Concepts
- Privacy Law and beyond Fourth Amendment
- Structure of the legal system
- The Fourth Amendment in an E-World
- E-Discovery and Evidence
- Decision-Makers: Judges and Juries
- SSH Tunnel for Windows RDP
- tmux config
- Forensic Imaging of Storage Media
- Windows Forensic Investigations: Guidelines and Methodology
- File Systems
- The Sleuth Kit
- File Carving
- Timeline Analysis – methodology, timestamp sources, anti-forensics, multi-source correlation
- Digital Forensics vs. Incident Response – goals, timelines, evidence standards, the speed/preservation tension, when to use each
- Incident Response – NIST SP 800-61r3 and SANS PICERL frameworks, all IR phases, evidence preservation, tabletop exercises
- Adversary Models: MITRE ATT&CK and Related Frameworks – ATT&CK, Kill Chain, Diamond Model, D3FEND, ENGAGE, UKC
- APT Groups – definitions, naming conventions (Mandiant/CrowdStrike/Microsoft/MITRE), active groups by nation-state, common TTPs
- Malware Triage – static analysis, VirusTotal multi-engine scanning, sandboxed dynamic analysis, IOC extraction, online sandbox platforms
- Networking Fundamentals
- tcpdump
- Wireshark
- Network Forensics: Acquisition, Analysis, and Detection
- Network Log Forensics – DHCP, DNS, firewall/NAT, proxy, VPN, RADIUS, NetFlow, Suricata EVE, SMTP, SSH
- Unix Text Processing: sed and awk – substitution, in-place editing, validation, and pipeline patterns
- Working with SQLite – CLI, schema inspection, timestamp conversion, browser and OS artifact databases, Python integration, deleted row recovery
- Digital Archiving and Digital Forensics – preservation vs. forensics, abandoned/binary file formats, format identification (PRONOM/siegfried), flux imaging, emulation, and old software
Slides
Homework
Each homework will build on the previous assignment. These aren’t your typical “write answers to questions” type assignments, but rather are intended to be more hands-on. We will be adding to, modifying, or otherwise doing something to the VM environment to enable us to do something else. The first assignment will be to get the VM environment set up and configured. Subsequent assignments will build on this.
Submission
All work will be submitted via MarkDown documents within an internal gitlab repo. You will be using this repo for the rest of the term. This repo exists on the CECS intranet. You will need to add myself to this repo as Developer. Grades and feedback will be done via a merge request from.
Assignments
Other stuff
- Deprecated Linux network commands – a list of deprecated Linux networking commands and their replacements
- Useful SANS resources
- Software configuration – not required, but possibly useful information on environment setup
- Powershell profile – powershell profile from the Software Configuration page
- Technical Writing – if unfamiliar with markdown or LaTeX, this page will help
- VM Setup on Windows
- Kali configuration
Useful links for learning
- The Art of Packet Crafting with Scapy
- Markdown
- The C Book
- The GNU
makemanual (PDF) - Managing projects with
make(PDF) - The
chmodcalculator - The Python tutor
- The Linux Command Line (direct PDF download)
- Adventures with the Linux Command Line (PDF)
- The Linux Development Platform
- gdb tutorial
- gef manual
- pwndbg