4 ms·
"Think about it, if I ask you to hand over your laptop for say, an hour, during which I have completely free reign over it, can you tell me everything I've done
by likeowned 12y ago
"Think about it, if I ask you to hand over your laptop for say, an hour, during which I have completely free reign over it, can you tell me everything I've done during that hour and all the backdoors installed, if any?"
Yes, I can. Read up on modern digital forensics. Everything you do on a machine leaves a trace and there are ways to recover those traces and put together exactly what you did. That is exactly what Incident Response/Digital Forensics Firms do. An IR firm would never tell you to just reimage a machine when you're dealing with an advanced attacker. They'd want to go through, use the tools they have to identify exactly what happened on the machine and what other machines were compromised before they even started talking remediation. Wiping the one machine that you got an alert on would do absolutely nothing to solve the problem.
- noinsight 12y agoGranted I'm not an expert, but I'm not confident that you could tell everything, at least not in the default configuration of desktop OSes without special auditing in place. Some stuff, sure. > An IR firm would never tell you to just reimage a machine when you're dealing with an advanced attacker. They'd want to go through, use the tools they have to identify exactly what happened on the machine Yes, I was talking more in the run-of-the-mill case sense, not regarding thorough forensic investigations. If you're actually going to investigate the incident deeper, you should at least get memory dumps, process dumps and an image of the machine and such. In my experience though, at most companies the SOP is just monitoring standard antivirus stuff and then when an infection comes up, it either gets automatically cleaned or someone goes over and fixes it with a manual scan or whatever. Which is completely inadequate.
- scintill76 12y agoI'll admit to a fairly casual acquaintance with digital forensics, but I disagree, if for no other reason than you didn't really address all the possibilities of the scenario given. I'd be happy to hear if I am in turn missing something. Forensic analysts are good at tracing activities done from within a system, and/or by entities that don't know a lot about forensics or don't have system privileges to cover their tracks. I read noinsight's scenario as involving physical access by a skilled attacker. If one shut down the laptop, pulled out the hard drive, mounted it on another system, modified a single sector of a document that doesn't exist anywhere else (and the laptop owner isn't perceptive enough to notice the change), preserved file metadata, and placed the drive back in the laptop, what would digital forensics be able to tell you? Only the details of the system being shut down, I'd guess. Maybe if they paid tens of thousands of dollars to a specialized lab, they could find faint magnetic traces of the former contents of the changed sector, but I'm not sure that's in the scope of what you meant. If all that was done was read the drive, there'd be even less chance of determining what was read. As mentioned, the attacker might compromise the BIOS or firmware, and while that would be detectable, I think only the highest-end IR firms would look for it, let alone have the resources to identify subtle changes. Even working within the system, I'd say many attackers can remove traces such that many investigators won't find them, by doing things like deleting created logs, restoring file metadata to its original state, and writing over the erased evidence multiple times. (This perhaps assumes root access and a consumer-grade OS in default configuration.) It might lead to a suspicious state where the system has been running for hours with no artifacts that would routinely be left, but the investigator might not be able to determine much of what was done. It might be as simple as using a browser the investigators don't check: http://www.cbsnews.com/news/casey-anthony-detectives-overlooked-google-search-for-fool-proof-suffocation-methods-sheriff-says/ http://www.cbsnews.com/news/casey-anthony-detectives-overloo...
- al2o3cr 12y ago"Read up on modern digital forensics. Everything you do on a machine leaves a trace and there are ways to recover those traces and put together exactly what you did." As a followup, both you and GP should read up on digital forensics from someplace OTHER than their marketing material...