Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Cloud Forensics - Bsides Colombia 2015
Search
ShieldNow
September 05, 2015
Technology
0
540
Cloud Forensics - Bsides Colombia 2015
ShieldNow
September 05, 2015
Tweet
Share
More Decks by ShieldNow
See All by ShieldNow
GPG
shieldnow
0
600
Guía TCPDump
shieldnow
0
580
Netcat
shieldnow
0
520
Other Decks in Technology
See All in Technology
今日から使える AWS Step Functions 小技集 / AWS Step Functions Tips
kinunori
1
110
設計に疎いエンジニアでも始めやすいアーキテクチャドキュメント
phaya72
27
19k
プロダクト開発と社内データ活用での、BI×AIの現在地 / Data_Findy
sansan_randd
1
830
AWS 環境で GitLab Self-managed を試してみた/aws-gitlab-self-managed
emiki
0
150
AIの個性を理解し、指揮する
shoota
3
630
よくわからない人向けの IAM Identity Center とちょっとした落とし穴
kazzpapa3
1
110
어떤 개발자가 되고 싶은가?
arawn
1
440
ピープルウエア x スタートアップ
operando
2
3.4k
Boxを“使われる場”にする統制と自動化の仕組み
demaecan
0
200
窓口業務を生成AIにおまかせ!Bedrock Agent Coreで実現する自治体AIエージェント!
rayofhopejp
0
180
SREのキャリアから経営に近づく - Enterprise Risk Managementを基に -
shonansurvivors
1
740
CloudComposerによる大規模ETL 「制御と実行の分離」の実践
leveragestech
0
190
Featured
See All Featured
RailsConf 2023
tenderlove
30
1.3k
Principles of Awesome APIs and How to Build Them.
keavy
127
17k
Learning to Love Humans: Emotional Interface Design
aarron
274
41k
Six Lessons from altMBA
skipperchong
29
4k
The Language of Interfaces
destraynor
162
25k
Intergalactic Javascript Robots from Outer Space
tanoku
273
27k
Templates, Plugins, & Blocks: Oh My! Creating the theme that thinks of everything
marktimemedia
31
2.6k
I Don’t Have Time: Getting Over the Fear to Launch Your Podcast
jcasabona
34
2.5k
Visualizing Your Data: Incorporating Mongo into Loggly Infrastructure
mongodb
48
9.7k
Improving Core Web Vitals using Speculation Rules API
sergeychernyshev
21
1.2k
Why You Should Never Use an ORM
jnunemaker
PRO
60
9.6k
[Rails World 2023 - Day 1 Closing Keynote] - The Magic of Rails
eileencodes
37
2.6k
Transcript
Open Source Cloud Forensics B-Sides | Septiembre 2015
Methodology Collection Examination Analysis Reporting
Problem 1 • Physical Access • Host Contamination • Response
Time • Technical Expertise
Problem 2 • Size of Resources • Chain of custody
• Tools • Technical Expertise
Problem 3 Rackspace • Where is the data stored? •
Acquisition - Size of Resources • Chain of custody? • Live Forensics? • Legal Considerations?
Traditional Way Snapshot of VM Snapshot of storage volumes http://blogs.msdn.com/b/azuresecurity/archive/2015/08/14/azure-forensics-for-the-security-responder-how-i-learned-to-stop-worrying-and-love-the-cloud.aspx
Puppet The Master
The Master /etc/puppet/manifests/site.pp
The Master allowscp chrootpath = /home/ user=strigoi:033:000110: /etc/rssh.conf
Strigois (Puppet-Nodes) /etc/puppet/puppet.conf
Strigois (Puppet-Nodes) /etc/puppet/puppet.conf
The Master artefacto-worm1-105233.tar.xz artefacto-worm2-11.tar.xz artefacto-worm3-2846.tar.xz artefacto-worm4-106736.tar.xz artefacto-worm5-5413.tar.xz /home/strigoi/
The Master 2cf0de7966fcc238b12f42df621a6beee55dba17b39be620cd147295afebc0c9a6bd58a0270cfb160edd16fbf46e253 793e5eed943d57a2db1881d72e0c9d5c4 /tmp/artefacto/auth.log d13254e9a6d6d12af1765b099d14e3c8742b731c98993ded94783883946a84a3b7c46f2e587a58ab6965c313125d 77e039ec05e80c51e803a11d5d456005ed8c /tmp/artefacto/dataw 582939b8399b80852ea83500dd1ac244b2a3332212085777207e8166e0673f19b00623c903edb91f729626491f52 7e575b9f7b6157e07d2473da07a46952bff5
/tmp/artefacto/swap.swap 3f73d4a9591f5ba47c65a739ec8c0bf0c3a8f41bef778479374b4588af7e7009ba12a4405d9937925b7825e6f51974 ac28f628f6bfcfea58bf1994aa04f5d785 /tmp/artefacto/memorydump.lime 06f9deb3034b5cf649c7aa3e07430417a868e64e80930564a29f52d64d1d3e6a9edf651698f97f204c1777bc748e9b 653d39c7fd1c9521592332019c04a67cad /tmp/artefacto/messages 37ec32ee176380e81a2ce7e25eb30f662b5097d7a2fcd54af0960d29a14e01a03aac63202c906db0192a8c8cd4f6d f2a033d11c0c3879b8b4d3a8b85512babdc /tmp/artefacto/netdump.pcap /home/strigoi/artefacto-strigoiname-uptimeinsec.tar.xz
The Master auth.log: Auth OS log dataw: arp, netstat (udp/tcp),
ps, host info swap.swap: Swap Memory Dump memorydump.lime: Physical Memory Dump messages: Message OS Log netdump.pcap: 1000 network packets hash-f: Integrity hash (SHA512) /home/strigoi/artefacto-strigoiname-uptimeinsec.tar.xz
Incident Response Team ShieldNow Cloud VM VM VM Public Cloud
Host Info Network Packets Network Info OS/APP Logs Memory Dump Integrity Hash Forensic Analysis Solution
Solution VM VM VM Public / Private / Hybrid Cloud
Linux VM • Open Source Puppet • Volatility • Yara • Snort • The Sleuth Kit® (TSK) • log2timeline • Wireshark • Cryptcat • dc3dd • Foremost • netcat
Future Work Public / Private / Hybrid Cloud • Windows
Forensics Puppet + Sysinternals + PowerShell • Timestamping (thanks to Fernando Quintero @nonroot) • Automated Analysis • Web Front-End • Digital Chain of Custody • Automated Report
Learn Forensics Public / Private / Hybrid Cloud
Learn Forensics Public / Private / Hybrid Cloud • Windows
Forensics Puppet + Sysinternals + PowerShell • Automated Analysis • Web Front-End • Digital Chain of Custody • Automated Report
Learn Puppet Public / Private / Hybrid Cloud • Windows
Forensics Puppet + Sysinternals + PowerShell • Automated Analysis • Web Front-End • Digital Chain of Custody • Automated Report
Obey the Master!!! Thanks for your attention