February 20, 2018
Alan Orlikoski
Twitter: @alanorlikoski
LinkedIn: https://www.linkedin.com/in/alan-orlikoski-5a2b07/
Using Open Source Tools to Solve New DFIR Challenges
1
1
My Backstory
2
New Challenges
What is Live Response (LR)
DFIR and LR for Everyone
Take Advantage of the Cloud
Automation Everywhere
Discussion Points
3
System Diversity
New Challenges
Doing More with Less
Cross Platform Tooling
4
5
What is Live Response?
Collecting and Analyzing a subset of data to quickly determine the validity and severity of a suspected malicious event
6
What is Collected?
Clear Text
Binary Data
7
Live Response Process
Collect Data
Process Data
Analyze Data
Live Response vs Cold Disk/Disk Image
Live Response:
Small collection of critical artifacts
Cold Disk/Disk Image:
Block copy of the full file structure
DFIR and LR For Everyone
CyLR, CDQR Forensics - Virtual Machine (CCF-VM)
9
Logical Workflow (simple concept)
10
IR Analyst
Compromised System
CCF-VM
1) Initiate artifact collection
2) Collection direct to server
3) Perform analysis
Collect with CyLR
The Process
View with TimeSketch
Process with CDQR
11
Collect: CyLR
Collects forensic artifacts from hosts
12
Factors in Artifact Collection
Minimize impact on target host
Windows API
13
CyLR: Default Collection Artifact List
Windows
Mac and Linux
14
CyLR: Default Collection Demo
CyLR: Custom Collection Demo
Process: CDQR
Parses raw data from bits and bytes to words and numbers. Provides a fast, easy to use interface for Plaso.
17
CDQR Parsers
18
Investigate: CSV Reports
Create one SuperTimeline
Data is parsed into a maximum of 16 special reports
Special reports group similar data together and include additional parsing to speed up analysis
19
CDQR Special Reports
Example: Event Log Report.csv
CDQR: CDQR to CSV Reports
CDQR: CDQR to ElasticSearch
Investigate: ELK +T
Elasticsearch: Search and analytics engine
Kibana: Visualization engine for Elasticsearch data
TimeSketch: Investigative Tool that provides easy access to data as well as multi-user support and investigative aids
24
CDQR
Kibana and TimeSketch
25
TimeSketch
26
Kibana
27
Easy Access
Simple Setup
Relatively low cost
Strong authentication methods
Multiple methods to optimize access
Take Advantage of the Cloud
28
Preparing for GCP Build
29
Build CCF-VM in Cloud
30
Create GCP Data Bucket
Copy CCF-VM_3.0.tar.gz to GCP Bucket
Create GCP image
Create new CCF-VM instance (AND LOG IN)
In house 24/7/365 SOC is expensive
SaaS is expensive
Alert volume too high
Automation is the answer
Automation Everywhere
31
Data Enrichment
Automation Activities
Reduce Training
Rapid Response
32
Managing Risk
Silent Failures
Infinite Loops (runaway processes)
Proprietary solutions
Automation Pitfalls
33
Q&A