SlideShare a Scribd company logo
The 3rd FIOS
(F-INSIGHT OPEN SEMINAR)
Resurrect the System and Services
: 죽은 서비스도 살리는 포렌식 기술
ykei
@ykx100
forensicinsight.org Page 2
목차
1. Cold or Hot Evidence
2. Resurrection
3. Chain of Custody
forensicinsight.org Page 3
Cold or Hot?
forensicinsight.org Page 4
Cold or Hot Evidence
Top Class Forensic Scientist
forensicinsight.org Page 5
Cold or Hot Evidence
One of Top Class Forensic Scientist
forensicinsight.org Page 6
Cold or Hot Evidence
Meet
The bruised body
One of Top Class Forensic Scientist
with breath
forensicinsight.org Page 7
Cold or Hot Evidence
U Remember?
Specialized at dead body
forensicinsight.org Page 8
Cold or Hot Evidence
forensicinsight.org Page 9
Cold or Hot Evidence
Now He got the cold body
as his wish
Is it fair?
forensicinsight.org Page 10
Cold or Hot Evidence
Digital Evidence?
forensicinsight.org Page 11
Cold or Hot Evidence
Have you ever like this?
forensicinsight.org Page 12
Cold or Hot Evidence
Same Cold EV.
forensicinsight.org Page 13
Cold or Hot Evidence
But,
Benefit of live forensics
 Short way to extract
 Quick response
 Seize the live data
forensicinsight.org Page 14
Cold or Hot Evidence
Increased size,
complexity of Data
Hard to find evidence
forensicinsight.org Page 15
Cold or Hot Evidence
Still, u
wanna kill
the hot &
take the
cold body
for analysis?
forensicinsight.org Page 16
Cold or Hot Evidence
Stop pulling the plug
forensicinsight.org Page 17
Cold or Hot Evidence
Boooooring… I know that, already
forensicinsight.org Page 18
Cold or Hot Evidence
Someone killing the hot body
 Mistake
 Wrong decision
 Bad Situation
forensicinsight.org Page 19
Cold or Hot Evidence
If someone give you the shit,
forensicinsight.org Page 20
Resurrection
forensicinsight.org Page 21
Resurrection
 Unified Log Monitor System
 Pulled the plug and Imaging the Disks
 Can you export the all log from DB?
 Where is the start point?
Here is shit…
forensicinsight.org Page 22
Resurrection
Resurrect System
forensicinsight.org Page 23
Resurrection
Virtual mount disk image files
forensicinsight.org Page 24
Resurrection
Check the Kernel version information
forensicinsight.org Page 25
Resurrection
Check Filesystem information
forensicinsight.org Page 26
Resurrection
Make the VM with mounted disk
forensicinsight.org Page 27
Resurrection
Now boot,
Meet the kernel panic
So I present this now :)
forensicinsight.org Page 28
Resurrection
Try to rescue boot [ linux rescue, chroot /mnt/sysimage ]
forensicinsight.org Page 29
Resurrection
Try to rescue boot [ linux rescue, chroot /mnt/sysimage ]
forensicinsight.org Page 30
Resurrection
Physical Driver to Virtual [ /etc/modprobe.conf ]
forensicinsight.org Page 31
Resurrection
Check disk order [ fdisk –l ]
forensicinsight.org Page 32
Resurrection
Check original mount point [ /etc/fstab ]
forensicinsight.org Page 33
Resurrection
Fix the raid bug [ /etc/grub.conf ]
forensicinsight.org Page 34
Resurrection
Grub information update [ grub-install ]
forensicinsight.org Page 35
Resurrection
Update Kernel information [ mkinitrd ]
forensicinsight.org Page 36
Resurrection
Still No Heartbeat of Service
forensicinsight.org Page 37
Resurrection
Resurrect Service
forensicinsight.org Page 38
Resurrection
Adjust network environment [ ifconfig ]
forensicinsight.org Page 39
Resurrection
Recovery DB files
forensicinsight.org Page 40
Resurrection
Recovery DB files
forensicinsight.org Page 41
Resurrection
May be It is not good idea…
forensicinsight.org Page 42
Resurrection
But, u can cheating the history :) [ history ]
forensicinsight.org Page 43
Resurrection
Now service is warmed
forensicinsight.org Page 44
Resurrection
Maybe, u need to PW recovery from DB
forensicinsight.org Page 45
Resurrection
But, Is resurrection break the chain?
forensicinsight.org Page 46
Chain of Custody
forensicinsight.org Page 47
Chain of Custody
No, Chain is fine
forensicinsight.org Page 48
Chain of Custody
When is preservation done,
CoC is Start.
forensicinsight.org Page 49
Chain of Custody
Don’t scared, Do hash
For Compatibility : MD5
For Security : SHA256(higher)
forensicinsight.org Page 50
Chain of Custody
But be prepared, always
 Guide
 Tools for your Environment
 Storage for backup
 And Hiring the Real Expert
Don’t deceived by crook
forensicinsight.org Page 51
Now, Cold or Hot?
forensicinsight.org Page 52
Conclusion
Virtual Technology is awesome
I can resurrect the cold media
Sometimes, It is very efficient method
forensicinsight.org Page 53
Conclusion
Please reconsidering the pull the plug
Do not send the shit to me
If you give me the shit,
I can over that, too.
forensicinsight.org Page 54
Conclusion
Hello, digital media necromancer!
Have u a question?

More Related Content

PPT
Presentation
ODP
Counter strike setup by vikas verma
PDF
Instalando rrd tool-no-centos-5-usando-yum
PDF
Backups are the BOMB!
PDF
Test Continuous
PPT
Project Panorama: vistas on validated information
PPT
Metadata, standaarden, interoperabiliteit, semantisch web en linked data
PDF
(120513) #fitalk windows 8 forensics
Presentation
Counter strike setup by vikas verma
Instalando rrd tool-no-centos-5-usando-yum
Backups are the BOMB!
Test Continuous
Project Panorama: vistas on validated information
Metadata, standaarden, interoperabiliteit, semantisch web en linked data
(120513) #fitalk windows 8 forensics

More from INSIGHT FORENSIC (20)

PDF
(160820) #fitalk fileless malware forensics
PDF
(150124) #fitalk advanced $usn jrnl forensics (korean)
PDF
(150124) #fitalk advanced $usn jrnl forensics (english)
PDF
(140118) #fitalk detection of anti-forensics artifacts using ioa fs
PDF
(140118) #fitalk 2013 e-discovery trend
PDF
(141031) #fitalk plaso 슈퍼 타임라인 분석 도구 활용 방안
PDF
(141031) #fitalk os x yosemite artifacts
PDF
(140716) #fitalk 전자금융사고에서의 디지털 포렌식
PDF
(140716) #fitalk digital evidence from android-based smartwatch
PDF
(140625) #fitalk sq lite 소개와 구조 분석
PDF
(140407) #fitalk d trace를 이용한 악성코드 동적 분석
PDF
(140625) #fitalk sq lite 삭제된 레코드 복구 기법
PDF
(130216) #fitalk reverse connection tool analysis
PDF
(130216) #fitalk potentially malicious ur ls
PDF
(130202) #fitalk trends in d forensics (jan, 2013)
PDF
(130202) #fitalk china threat
PDF
(130119) #fitalk sql server forensics
PDF
(130119) #fitalk apt, cyber espionage threat
PDF
(130119) #fitalk all about physical data recovery
PDF
(130105) #fitalk trends in d forensics (dec, 2012)
(160820) #fitalk fileless malware forensics
(150124) #fitalk advanced $usn jrnl forensics (korean)
(150124) #fitalk advanced $usn jrnl forensics (english)
(140118) #fitalk detection of anti-forensics artifacts using ioa fs
(140118) #fitalk 2013 e-discovery trend
(141031) #fitalk plaso 슈퍼 타임라인 분석 도구 활용 방안
(141031) #fitalk os x yosemite artifacts
(140716) #fitalk 전자금융사고에서의 디지털 포렌식
(140716) #fitalk digital evidence from android-based smartwatch
(140625) #fitalk sq lite 소개와 구조 분석
(140407) #fitalk d trace를 이용한 악성코드 동적 분석
(140625) #fitalk sq lite 삭제된 레코드 복구 기법
(130216) #fitalk reverse connection tool analysis
(130216) #fitalk potentially malicious ur ls
(130202) #fitalk trends in d forensics (jan, 2013)
(130202) #fitalk china threat
(130119) #fitalk sql server forensics
(130119) #fitalk apt, cyber espionage threat
(130119) #fitalk all about physical data recovery
(130105) #fitalk trends in d forensics (dec, 2012)
Ad

Recently uploaded (20)

PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Getting Started with Data Integration: FME Form 101
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Machine learning based COVID-19 study performance prediction
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
A comparative analysis of optical character recognition models for extracting...
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
A Presentation on Artificial Intelligence
PPTX
Big Data Technologies - Introduction.pptx
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Approach and Philosophy of On baking technology
SOPHOS-XG Firewall Administrator PPT.pptx
“AI and Expert System Decision Support & Business Intelligence Systems”
Getting Started with Data Integration: FME Form 101
Spectral efficient network and resource selection model in 5G networks
20250228 LYD VKU AI Blended-Learning.pptx
Machine learning based COVID-19 study performance prediction
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
gpt5_lecture_notes_comprehensive_20250812015547.pdf
Agricultural_Statistics_at_a_Glance_2022_0.pdf
A comparative analysis of optical character recognition models for extracting...
Group 1 Presentation -Planning and Decision Making .pptx
Mobile App Security Testing_ A Comprehensive Guide.pdf
Per capita expenditure prediction using model stacking based on satellite ima...
Advanced methodologies resolving dimensionality complications for autism neur...
Diabetes mellitus diagnosis method based random forest with bat algorithm
A Presentation on Artificial Intelligence
Big Data Technologies - Introduction.pptx
MIND Revenue Release Quarter 2 2025 Press Release
Building Integrated photovoltaic BIPV_UPV.pdf
Approach and Philosophy of On baking technology
Ad

(Fios#03) 5. 죽은 서비스도 살려내는 포렌식 기술