Tổng hợp nghiên cứu về Tội phạm
Blog Archive
-
▼
2011
(249)
-
▼
May
(31)
- [Hack Crack] Full SQL inject cheat sheet - DarkGh0...
- [Hack crack] Tổng hợp Google Dork 1
- [Hack crack] Tổng hợp Google Dork
- [Phân tích] Quá trình phát tán virus
- Demo RFI/LFI
- [TUT HACK] RFI/LFI và demo :))
- [Thống kê] Bạn quản lý password bằng cách nào?
- [Tool hack] Google password decrypter
- [Key] SQL Inject
- [Tool hack] Online SQL INJECTION
- [Tool hack] sql inject - Pangolin
- [Tool hack] Havij - SQL Inject
- [Mã nguồn] Worm Osama bin laden trên facebook
- [Lượm] Tổng hợp 100 trang download ebook miễn phí
- [LƯỢM] Bảo mật cho facebook của bạn
- [Vận may] Cơ hội trúng BitDefender bản quyền 1 năm...
- [Miễn phí bản quyền] NEW Avira Premium Security Su...
- [Miễn phí] Metasploit Framework 3.7.0 Released 2/5...
- AV-Test Product Review and Certification Report - ...
- [LƯỢM] Tổng hợp các ký tự đặc biệt
- [RAT] 10 "điểm nhấn" về Osama bin laden
- [RAT] You're a tool, a digital forensics tool.
- [Sopho] Lừa đảo qua mạng facebook lợi dụng tin osa...
- [Tài liệu] Tuyển tập các văn bản pháp luật về Hìn...
- [Phân tích] Điểm mới quy định về Tội phạm máy tính...
- [Ebook]CHFI - Computer hacking forensic investigator
- [Miễn phí bản quyền] 6 tháng F-Secure Internet Sec...
- [Miễn phí] 2011 Kaspersky Anti-rootkit utility TDS...
- [RAT] Bộ sưu tập câu hỏi Game show - Rung chuông v...
- [Miễn phí bản quyền] Avira Premium Security Suite ...
- [Miễn phí bản quyền] TuneUp Utilities 2010 -2/5/2011
-
▼
May
(31)
Powered by Blogger.
A common question I am asked or see posted on forums, user groups and social media sites is: "What is the best computer forensic tool?" It is usually posed by someone getting started in the field and is an understandable query for an individual who is unfamiliar with some of the granular technical details of the field and looking for direction on how to get their feet wet. In addition there are considerable marketing efforts by product developers to set their solution apart from the rest claiming to be the best, fastest, most reliable or somehow "court approved." (Chris Pogue recently touched upon the "court-approved" tool fallacy on his blog http://thedigitalstandard.blogspot.com/2010/08/court-approved.html.)
When this question is posed I try impress upon the person asking it that there are no forensic tools. There are only tools that forensic practitioners use in the course of gathering evidence and performing analysis.
I make this distinction because your thinking and approach are dangerousl and fundamentally flawed if they are tool-centric when performing collections, analysis and investigations. Tools simply assist the investigator by expediting a process or helping interpret the data. As investigators we cannot simply trust in a tool's resulting information without validation, verification and comparison to another method or tool's result. Our professional duty is to know how things that assist our job function work at a very technical level. This is not required in many other professions.
The UPS guy doesn't have to know the gritty details about fulcrum points, leverage or weight distribution to use the hand truck to get deliveries from the truck to the customer. He just needs to know how to put the boxes on the hand truck, deliver them and move on to the next delivery. The hand truck tool makes his job easier and he doesn't have to explain how it works. He knows that it is what he needs to get the job done.
We don't have that luxury in this field. We have to justify and potentially explain every aspect about how the tool works in a legal proceeding.
Digital forensics and computer investigations have a basis in scientific methodology that we need to accept and understand to perform our job and ultimately explain our findings. This requires a level of skepticism and objective thinking that is in direct conflict to having blind trust of the claims made by others, the manufacturer or by a developer as to the authenticity of the results produced.
Also, by simply asking for the "best tool" without adding the context of what you are trying to achieve, you miss the crucial point that forensic methodology is a process. Would you pop into Home Depot and ask the first orange-aproned employee, "What's the best tool to build my house?" You need to have a plan prior to picking up a hammer, screw driver and a wrench.
Instead it is important to be method-centric and frame your investigations. This requires you to use the best tool available — your brain. YOU are the best forensic tool for the job. Work to build confidence in your investigative methodology instead of the claims made by someone else or a marketing pitch about what is "best." It will be you, NOT the tool, called to testify. It is very difficult to put a dongle on the witness stand and get a sworn statement.
Source: http://computer-forensics.sans.org/blog/2010/09/16/tool-digital-forensics-tool/
When this question is posed I try impress upon the person asking it that there are no forensic tools. There are only tools that forensic practitioners use in the course of gathering evidence and performing analysis.
I make this distinction because your thinking and approach are dangerousl and fundamentally flawed if they are tool-centric when performing collections, analysis and investigations. Tools simply assist the investigator by expediting a process or helping interpret the data. As investigators we cannot simply trust in a tool's resulting information without validation, verification and comparison to another method or tool's result. Our professional duty is to know how things that assist our job function work at a very technical level. This is not required in many other professions.
The UPS guy doesn't have to know the gritty details about fulcrum points, leverage or weight distribution to use the hand truck to get deliveries from the truck to the customer. He just needs to know how to put the boxes on the hand truck, deliver them and move on to the next delivery. The hand truck tool makes his job easier and he doesn't have to explain how it works. He knows that it is what he needs to get the job done.
We don't have that luxury in this field. We have to justify and potentially explain every aspect about how the tool works in a legal proceeding.
Digital forensics and computer investigations have a basis in scientific methodology that we need to accept and understand to perform our job and ultimately explain our findings. This requires a level of skepticism and objective thinking that is in direct conflict to having blind trust of the claims made by others, the manufacturer or by a developer as to the authenticity of the results produced.
Also, by simply asking for the "best tool" without adding the context of what you are trying to achieve, you miss the crucial point that forensic methodology is a process. Would you pop into Home Depot and ask the first orange-aproned employee, "What's the best tool to build my house?" You need to have a plan prior to picking up a hammer, screw driver and a wrench.
Instead it is important to be method-centric and frame your investigations. This requires you to use the best tool available — your brain. YOU are the best forensic tool for the job. Work to build confidence in your investigative methodology instead of the claims made by someone else or a marketing pitch about what is "best." It will be you, NOT the tool, called to testify. It is very difficult to put a dongle on the witness stand and get a sworn statement.
Source: http://computer-forensics.sans.org/blog/2010/09/16/tool-digital-forensics-tool/
0 comments to "[RAT] You're a tool, a digital forensics tool."
Post a Comment