Sinisterly
Computer Forensics - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: General (https://sinister.ly/Forum-General)
+--- Forum: The Lounge (https://sinister.ly/Forum-The-Lounge)
+--- Thread: Computer Forensics (/Thread-Computer-Forensics)

Pages: 1 2


RE: Computer Forensics - Magnetron - 05-29-2019

(05-28-2019, 04:38 PM)Sartux Wrote:
(05-21-2019, 06:29 AM)Magnetron Wrote: Forensics can still be useful in the event of a crash or accidentally deleting your own stuff, however.
I recovered a video that took me 16 hours to edit one time. Another time, the piece of shit Windows Disk Manager deleted all 8 partitions on a 2TB drive. One partition in particular was very difficult to recover but I did it. And the ultimate: a 250GB USB stick failed and the filesystem was corrupted so I had no choice but to recover everything by hand, a process which took 6 months. Every repair shop told me it would be impossible, every tech forum on the internet said the same. I offered $10,000 to anyone who could do it and nobody took the offer. I did the impossible.

Forensics is pretty fucking useful.
That's damn impressive. Good work.

Do you mind me asking what tools you used?

I mainly used X-Ways Forensics (Winhex) coupled with a bunch of other apps to assist me such as TestDisk to help identify partition metadata and a bunch more smaller apps and scripts for miscellaneous stuff that came along the way. Putting fragmented files back together may rank as the most annoying task ever in data recovery.


RE: Computer Forensics - urgodfather - 06-24-2019

TestDisk is by far one of the best I have used for file/partition recovery provided it wasn't written over. For extensive Data Recovery, there is no "one tool fits all." For example, let's say you have a mechanical drive that is failing or has failed. Here is the most important thing to do that so many IT Specialists overlook. If it mounts, CLONE IT! Don't just jump in to Data Recovery on it! Think like you're driving down the road on a flat tire. The more you drive on it, the more damage. There are plenty of cloning utilities out there. Some will work well in one case but not the other. It varies. Once you get a clone, NOW you reconstruct it. Again, different tools for different circumstances. It never hurts to make backup clones too. This way you have viable restore points if you decide to manually reconstruct. So, let's say it doesn't mount... now what? This is crossing into hardware (occationally software) hacking, and also applies to thumbsticks, ssd's, etc. You will need to RE the circuitry and identify the problem. It could be a bad chip, crystal, resistor, or even full on mechanical failure. Familiarize yourself with it. Then look for viable workarounds. Repair whats needed, then RAW clone it to a donor for reconstruction. You may have to dive even deeper into byte level reconstruction. Having the right tools is everything. Soldering tools, Forensic tools, Oscilators, Programmers, Null Modem cables, THESE ARE ALL YOUR FRIENDS.


RE: Computer Forensics - Tivoli - 08-21-2020

Glad to see such themes, good stuff.
Memory forensics is the way, the law enforcement would go if your system is encrypted.
There are methods exists, which allow them to image your memory and grab the encryption keys, which could decrypt your data.
Even if you have unbreakable password, all encryption keys are resides in memory. If your encrypted PC is powered on when the guests have come, then you're in trouble.


RE: Computer Forensics - taylostolo - 08-21-2020

(08-21-2020, 09:37 PM)Tivoli Wrote: Glad to see such themes, good stuff.
Memory forensics is the way, the law enforcement would go if your system is encrypted.
There are methods exists, which allow them to image your memory and grab the encryption keys, which could decrypt your data.
Even if you have unbreakable password, all encryption keys are resides in memory. If your encrypted PC is powered on when the guests have come, then you're in trouble.
dont wake the dead their sleeping.


RE: Computer Forensics - Tivoli - 08-21-2020

(08-21-2020, 09:55 PM)taylostolo Wrote:
(08-21-2020, 09:37 PM)Tivoli Wrote: Glad to see such themes, good stuff.
Memory forensics is the way, the law enforcement would go if your system is encrypted.
There are methods exists, which allow them to image your memory and grab the encryption keys, which could decrypt your data.
Even if you have unbreakable password, all encryption keys are resides in memory. If your encrypted PC is powered on when the guests have come, then you're in trouble.
don't wake the dead their sleeping.

I'm sorry, but I think people should know about such attack vector. If theme is exhausted, there is no need to discuss it, but this information people should be aware of.
Give me your OS memory dump, and we will try to find out who you are :-)


RE: Computer Forensics - taylostolo - 08-22-2020

(08-21-2020, 10:15 PM)Tivoli Wrote:
(08-21-2020, 09:55 PM)taylostolo Wrote:
(08-21-2020, 09:37 PM)Tivoli Wrote: Glad to see such themes, good stuff.
Memory forensics is the way, the law enforcement would go if your system is encrypted.
There are methods exists, which allow them to image your memory and grab the encryption keys, which could decrypt your data.
Even if you have unbreakable password, all encryption keys are resides in memory. If your encrypted PC is powered on when the guests have come, then you're in trouble.
don't wake the dead their sleeping.

I'm sorry, but I think people should know about such attack vector. If theme is exhausted, there is no need to discuss it, but this information people should be aware of.
Give me your OS memory dump, and we will try to find out who you are :-)
yes people should know about mem forensics so make a new post and type your heart away...
im quite alright whe it comes to the dump im a very private person and my signature gives you all the info you need im the librarian so relax your inner keyboard warrior. Sleepy