Digital Forensics Practice Exam Review

Data Abstraction and Physical Storage Architecture

  • Data Abstraction Layers: The architectural hierarchy of data organization within a system identifies specific responsibilities for each layer:     * Physical Media Layer: The actual hardware (platters, flash cells) where bits are stored.     * Host Bus Adapter (HBA) Protocol Layer: The interface (SATA, SCSI, NVMe) through which the host communicates with the storage device.     * Block Device Layer: Provides a logical representation of the storage as a sequence of blocks.     * Filesystem Layer: Directly responsible for organizing block storage into files, directories, and managing associated metadata such as timestamps (atimeatime, mtimemtime, ctimectime) and permissions.

  • Sector Configurations (Advanced Format):     * Native 4K (4Kn4Kn): Characterized by having 4096 bytes4096\,bytes for both logical sectors and physical sectors.     * 512e512e: Uses 4096 byte4096\,byte physical sectors but emulates 512 byte512\,byte logical sectors for compatibility.

  • Solid-State Drive (SSD) Internals and Forensic Implications:     * Flash Translation Layer (FTL): A critical controller component performing several functions:         * Wear Leveling: Distributes write operations evenly across all flash cells to prevent premature failure of specific blocks.         * Garbage Collection: Reclaims flash pages marked invalid by the host to maintain write performance.         * Bad Block Management: Identifies failed cells and remaps the addressable space to spare cells.         * Over-provisioning: Maintains a reserve of spare capacity for background operations (e.g., swapping blocks during wear leveling).     * Forensic Significance of Over-provisioning: This area is inaccessible through standard host commands and may retain remnants of deleted data that were never subject to TRIMTRIM erasure.     * Logical vs. Physical Mapping: Modern SSD controllers implement proprietary wear-leveling algorithms that decouple Logical Block Addresses (LBAsLBAs) from actual physical locations on the storage medium. The SATA/SCSISATA/SCSI interface does NOT expose physical memory cells in their true sequential order.     * TRIMTRIM Command: Instructs the device to flag specified logical blocks as no longer in use, allowing the controller to proactively erase them.

  • SMART (Self-Monitoring, Analysis, and Reporting Technology): Provides historical and diagnostic data, including:     * Cumulative power-on hours and total power cycle counts.     * Number of sectors reallocated due to read/write errors.     * Evidence of recent ATA SECURITY ERASE UNITATA\,SECURITY\,ERASE\,UNIT command execution.     * Historical read/write error rates and temperature records.

Forensic Acquisition Tools and Methodologies

  • Standard Utility: dddd:     * conv=noerrorconv=noerror: Instructs the utility to continue the copying process after a read error occurs rather than aborting.     * conv=noerrorconv=noerror without syncsync: If a read error occurs, the output image becomes shorter than the source because error blocks are skipped without being replaced, causing a misalignment of all subsequent data.     * conv=noerror,syncconv=noerror,sync: Padds every input block with zeros when an error occurs, preserving the block alignment and total size of the image.

  • Enhanced Tool: dc3dddc3dd: Provides capabilities beyond standard dddd, including:     * Integrated hashing for multiple algorithms (e.g., MD5MD5, SHA−1SHA-1, SHA−256SHA-256, SHA−512SHA-512).     * Detailed activity logging with timestamps and specific error counts.     * On-the-fly hash verification during the acquisition process.     * Support for splitting output into multiple files of a designated size.

  • Recovery Tool: GNU ddrescueGNU\,ddrescue:     * Primary Use Case: Acquiring data from physically failing drives containing bad sectors.     * Methodology: Uses a mapfile (or logfile) to track progress. A typical command sequence is ddrescue −n /dev/sda case.dd case.mapddrescue\,-n\,/dev/sda\,case.dd\,case.map.     * Retry Logic: If sectors remain failed (-$ symbol in the mapfile), the examiner should use ddrescue\,-d\,-r\,3\,/dev/sda\,case.dd\,case.maptoperformdirectdiscaccessandretryfailedsectorsthreetimes.</p></li><li><p><strong>AcquisitionStandardsandIntegrity</strong>:    ∗<strong>MinimumHashStandard</strong>:to perform direct disc access and retry failed sectors three times.</p></li><li><p><strong>Acquisition Standards and Integrity</strong>:     * <strong>Minimum Hash Standard</strong>:SHA-256iscurrentlyrecommendedastheminimumcryptographichashstandardfornewforensicacquisitions.    ∗<strong>Pseudo−physicalAcquisition</strong>:AtermbyCaseydescribingblock−levelimaging.Itis"pseudo"becausenotallphysicalareas(suchasreallocatedsectorsorHostProtectedAreas(is currently recommended as the minimum cryptographic hash standard for new forensic acquisitions.     * <strong>Pseudo-physical Acquisition</strong>: A term by Casey describing block-level imaging. It is "pseudo" because not all physical areas (such as reallocated sectors or Host Protected Areas (HPA))areaccessiblethroughthestandard)) are accessible through the standardHBAinterface.</p></li></ul><h3id="78264a98−8855−4c5b−a126−2abf98886bdf"data−toc−id="78264a98−8855−4c5b−a126−2abf98886bdf"collapsed="false"seolevelmigrated="true">EvidenceContainerFormats</h3><ul><li><p><strong>ExpertWitnessFormat(interface.</p></li></ul><h3 id="78264a98-8855-4c5b-a126-2abf98886bdf" data-toc-id="78264a98-8855-4c5b-a126-2abf98886bdf" collapsed="false" seolevelmigrated="true">Evidence Container Formats</h3><ul><li><p><strong>Expert Witness Format (E01//EWF)</strong>:Anindustry−standardcontainerthatprovides:    ∗<strong>Built−inCompression</strong>:Reducingthestoragerequirementsfortheimage.    ∗<strong>EmbeddedMetadata</strong>:Storesexaminername,casenumber,andnoteswithintheheader.    ∗<strong>Chunk−levelIntegrity</strong>:Employs)</strong>: An industry-standard container that provides:     * <strong>Built-in Compression</strong>: Reducing the storage requirements for the image.     * <strong>Embedded Metadata</strong>: Stores examiner name, case number, and notes within the header.     * <strong>Chunk-level Integrity</strong>: EmploysCRC32checksumsembeddedwithineachcompresseddatachunkforfine−grainedverification.    ∗<strong>AutomaticSplitting</strong>:Automaticallyhandlesthecreationofsequentiallynumberedsegments.</p></li></ul><h3id="3fe98127−a223−4cdd−9979−bec0e8060cfe"data−toc−id="3fe98127−a223−4cdd−9979−bec0e8060cfe"collapsed="false"seolevelmigrated="true">StoragePartitioningandLogicalVolumes</h3><ul><li><p><strong>MasterBootRecord(checksums embedded within each compressed data chunk for fine-grained verification.     * <strong>Automatic Splitting</strong>: Automatically handles the creation of sequentially numbered segments.</p></li></ul><h3 id="3fe98127-a223-4cdd-9979-bec0e8060cfe" data-toc-id="3fe98127-a223-4cdd-9979-bec0e8060cfe" collapsed="false" seolevelmigrated="true">Storage Partitioning and Logical Volumes</h3><ul><li><p><strong>Master Boot Record (MBR)</strong>:    ∗<strong>Size</strong>:Occupiesthefirst)</strong>:     * <strong>Size</strong>: Occupies the first512\,bytesectorofadisk.    ∗<strong>PartitionTable</strong>:Reservedsizeofsector of a disk.     * <strong>Partition Table</strong>: Reserved size of64\,byteswithinthewithin theMBR.    ∗<strong>TypeCodes</strong>:Thecode.     * <strong>Type Codes</strong>: The code0x83identifiesaLinuxnativefilesystem(e.g.,identifies a Linux native filesystem (e.g.,ext2,,ext3,,ext4).    ∗<strong>DeviceNaming(Linux)</strong>:Logicalpartitions(insideanextendedpartition)typicallystartnumberingat).     * <strong>Device Naming (Linux)</strong>: Logical partitions (inside an extended partition) typically start numbering at/dev/sdb5,regardlessofthenumberofprimarypartitions.</p></li><li><p><strong>GUIDPartitionTable(, regardless of the number of primary partitions.</p></li><li><p><strong>GUID Partition Table (GPT)</strong>:Partofthe)</strong>: Part of theUEFIspecification,providingimprovementsoverspecification, providing improvements overMBR:    ∗Removesthe:     * Removes the2\,TiBper−diskcapacityceiling.    ∗Supportsmorethanfourprimarypartitionsnatively.    ∗Includesaprimaryper-disk capacity ceiling.     * Supports more than four primary partitions natively.     * Includes a primaryGPTheaderatheader atLBA\,1.    ∗Featuresaredundantbackuppartitiontableatthephysicalendofthedisk.    ∗Uses.     * Features a redundant backup partition table at the physical end of the disk.     * UsesCRC32checksumsfortheheaderandpartitionentryarray.</p></li><li><p><strong>LogicalVolumeManagement(checksums for the header and partition entry array.</p></li><li><p><strong>Logical Volume Management (LVM)</strong>:Layersorganizedfromlowest(physical)tohighest(filesystem−ready):    1.<strong>PhysicalVolume()</strong>: Layers organized from lowest (physical) to highest (filesystem-ready):     1. <strong>Physical Volume (PV)</strong>:Therawdiskpartitions.    2.<strong>VolumeGroup()</strong>: The raw disk partitions.     2. <strong>Volume Group (VG)</strong>:Apoolofspacefromoneormore)</strong>: A pool of space from one or morePVs.    3.<strong>LogicalVolume(.     3. <strong>Logical Volume (LV)</strong>:Thevirtualpartitionpresentedtothefilesystem.</p></li><li><p><strong>LinuxRAID()</strong>: The virtual partition presented to the filesystem.</p></li><li><p><strong>Linux RAID (md)</strong>:    ∗<strong>RAID1</strong>:Faulttoleranceviamirroring(eachdiskisacompletecopy).    ∗<strong>RAID5</strong>:Usesdistributedparity;survivesthelossofexactlyonememberdisk.Minimumofthreedisksusuallyrequired.    ∗<strong>Management</strong>:Metadataisstoredinasuperblockoneachmemberdisk;thetool)</strong>:     * <strong>RAID 1</strong>: Fault tolerance via mirroring (each disk is a complete copy).     * <strong>RAID 5</strong>: Uses distributed parity; survives the loss of exactly one member disk. Minimum of three disks usually required.     * <strong>Management</strong>: Metadata is stored in a superblock on each member disk; the toolmdadmisusedforreassembly.</p></li></ul><h3id="ec1fed82−8e94−45a3−b793−439b76006033"data−toc−id="ec1fed82−8e94−45a3−b793−439b76006033"collapsed="false"seolevelmigrated="true">DataDiscoveryandAdvancedAnalysisTools</h3><ul><li><p><strong>is used for reassembly.</p></li></ul><h3 id="ec1fed82-8e94-45a3-b793-439b76006033" data-toc-id="ec1fed82-8e94-45a3-b793-439b76006033" collapsed="false" seolevelmigrated="true">Data Discovery and Advanced Analysis Tools</h3><ul><li><p><strong>bulk_extractor</strong>:    ∗<strong>ScanningMethodology</strong>:Readstheentireimageasaflatbytestream,ignoringfilesystemstructuresentirely.Thisallowsittofinddataindeletedregionsandswappartitions.    ∗<strong>RecursiveDecompression</strong>:Capableofscanningcontentinside</strong>:     * <strong>Scanning Methodology</strong>: Reads the entire image as a flat byte stream, ignoring filesystem structures entirely. This allows it to find data in deleted regions and swap partitions.     * <strong>Recursive Decompression</strong>: Capable of scanning content insideZIP,,GZIP,and, andBASE64containers.    ∗<strong>ParallelProcessing</strong>:Dividesimagesintofixed−sizepages.Defaultiscontainers.     * <strong>Parallel Processing</strong>: Divides images into fixed-size pages. Default is16\,MiBpageswithapages with a4\,MiBoverlapmargintoensureartifactsspanningaboundaryarenotmissed.    ∗<strong>ForensicPaths</strong>:Apathlikeoverlap margin to ensure artifacts spanning a boundary are not missed.     * <strong>Forensic Paths</strong>: A path like2097152-ZIP-4096-BASE64-128meanstheartifactisatbytemeans the artifact is at byte128ofaof aBASE64blob,whichisatoffsetblob, which is at offset4096withinawithin aZIParchivestartingatimagebytearchive starting at image byte2,097,152.    ∗<strong>StopLists</strong>:Usedtofilternoise.Amechanicalstoplistsuppressesfeaturesfoundinareferenceimage(e.g.,acleanOSinstall)tofocusonuser−specificdata.</p></li><li><p><strong>.     * <strong>Stop Lists</strong>: Used to filter noise. A mechanical stop list suppresses features found in a reference image (e.g., a clean OS install) to focus on user-specific data.</p></li><li><p><strong>sdhash(ApproximateMatching)</strong>:    ∗<strong>Function</strong>:Producesasimilarityscoreonacontinuousscale((Approximate Matching)</strong>:     * <strong>Function</strong>: Produces a similarity score on a continuous scale (0-100)ratherthanabinary(yes/no)match.    ∗<strong>FeatureSelection</strong>:Selects) rather than a binary (yes/no) match.     * <strong>Feature Selection</strong>: Selects64\,bytesequencesbasedonanentropy−basedmeasureofstatisticalimprobability.    ∗<strong>BloomFilters</strong>:UsesbitwiseoverlapbetweenBloomfilterstoestimatesharedbyte−levelfeatures.Adigestforasequences based on an entropy-based measure of statistical improbability.     * <strong>Bloom Filters</strong>: Uses bitwise overlap between Bloom filters to estimate shared byte-level features. A digest for a1\,GBfiletypicallyconsistsofanorderedsequenceoffile typically consists of an ordered sequence of256\,byteBloomfilters,totalingapproximatelyBloom filters, totaling approximately500\,KB.</p></li><li><p><strong>EntropyAnalysis</strong>:    ∗<strong>ShannonEntropyScale</strong>:Rangesfrom.</p></li><li><p><strong>Entropy Analysis</strong>:     * <strong>Shannon Entropy Scale</strong>: Ranges from0toto8.0\,bits/byte.    ∗<strong>Interpretations</strong>:Highentropy(.     * <strong>Interpretations</strong>: High entropy (7.9+)indicatessignificantrandomness,whichisconsistentwithencryption,compression,ordeliberaterandomfill.Entropyalonecannotdistinguishbetweenthesesources.    ∗<strong>Validation</strong>:The) indicates significant randomness, which is consistent with encryption, compression, or deliberate random fill. Entropy alone cannot distinguish between these sources.     * <strong>Validation</strong>: TheChi-squaredistributionisoftenusedalongsideentropytotestforrandomness.</p></li></ul><h3id="de661a53−3165−4fc3−b0ba−567377451172"data−toc−id="de661a53−3165−4fc3−b0ba−567377451172"collapsed="false"seolevelmigrated="true">TheSleuthKit(distribution is often used alongside entropy to test for randomness.</p></li></ul><h3 id="de661a53-3165-4fc3-b0ba-567377451172" data-toc-id="de661a53-3165-4fc3-b0ba-567377451172" collapsed="false" seolevelmigrated="true">The Sleuth Kit (TSK)andFileRecovery</h3><ul><li><p><strong>CommandSequenceforDeletedFiles</strong>:    ∗Identifydeletedfilesusing) and File Recovery</h3><ul><li><p><strong>Command Sequence for Deleted Files</strong>:     * Identify deleted files usingfls.Anasterisk(. An asterisk ()denotesadeletedentry(e.g.,) denotes a deleted entry (e.g.,r/r\,\,13: termination_notice.docx).    ∗<strong>InspectMetadata</strong>:Use).     * <strong>Inspect Metadata</strong>: Useistat\,-o\,[offset]\,image.dd\,13.    ∗<strong>RecoverContent</strong>:Use.     * <strong>Recover Content</strong>: Useicat\,-o\,[offset]\,image.dd\,13\,>\,recovery.docx.    ∗<strong>Limitation</strong>:Recoverydependsonwhetherthedatablockshavebeenoverwritten(allocationstatus)andifthefilesystemisfragmented.</p></li><li><p><strong>.     * <strong>Limitation</strong>: Recovery depends on whether the data blocks have been overwritten (allocation status) and if the filesystem is fragmented.</p></li><li><p><strong>mmlsvsvsfdisk</strong>:</strong>:mmlsdisplaysunallocatedinter−partitiongapsandalignmentregions,whichdisplays unallocated inter-partition gaps and alignment regions, whichfdisk\,-loftenignores.</p></li></ul><h3id="8881ded9−4dec−45c7−83ca−853da8c7ecbd"data−toc−id="8881ded9−4dec−45c7−83ca−853da8c7ecbd"collapsed="false"seolevelmigrated="true">Anti−ForensicsandTimelineAnalysis</h3><ul><li><p><strong>Timestomping</strong>:Thedeliberatemodificationoftimestamps(often ignores.</p></li></ul><h3 id="8881ded9-4dec-45c7-83ca-853da8c7ecbd" data-toc-id="8881ded9-4dec-45c7-83ca-853da8c7ecbd" collapsed="false" seolevelmigrated="true">Anti-Forensics and Timeline Analysis</h3><ul><li><p><strong>Timestomping</strong>: The deliberate modification of timestamps (MACtimes)tohideactivity.Iffourunrelatedfilesacrossdifferentdirectoriesshareidenticaltimes) to hide activity. If four unrelated files across different directories share identicalm/a/ctimestampstothesecond(e.g.,timestamps to the second (e.g.,Mon\,Jan\,15\,2024\,03:47:12), it strongly suggests the use of anti-forensic tools.

  • Verification: A legitimate alternative explanation (like a system-wide update or bulk copy) must be ruled out by checking installer logs or system activity records.

Questions & Discussion

  • Q: How do you confirm a block's allocation status?

  • A: Analyze the metadata structures (like the bitmap in ext4ororMFTininNTFS$$) to see if the bit corresponding to that block is set to allocated or free.

  • Q: What is the risk of a stop list based on an HR directory?

  • A: If an attacker uses an internal email address to exfiltrate data, a stop list containing all company addresses would suppress that evidence, leading to a false negative.