Forenzika what is it - from stress to career

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
506
Reaction score
867
Deposit
0$
Forenzika - what it is and how to pronounce it properly
The impact in the word "forenza" is placed on the second syllable: foreZine. By ear - [FarEnzika], with a shock "e." The word is a calca with the English forensics, which goes back to the Latin forensis - "related to the forum." In ancient Rome, the forum was the place of judgment, and the forensic meant "judicial" - associated with the presentation of evidence in the public process. Forenzika in English - digital forensic or forensic computers, full form - forensic science, that is, "judicial science." More details - in our detailed analysis of the investigation of cyber attacks.



When borrowing in Russian, the word narrowed. The English forensics covers any forensic examination - from ballistics to toxicology. Russian "forenza" almost always means computer forensics: work with digital media, disk images, memory dumps and network traffic. "Digital forensics" and "computer forensics" are full of forensics synonyms, both correct. In vacancies and conferences, "forensic" is more common - more compact and familiar for the industry.

A simple analogy: a forensic specialist is a forensicist, only instead of fingerprints and casings he works with files, logs and metadata. As an expert at the crime scene, he fixes every evidence without violating its integrity, so the digital forensicsman removes the image of the disc bitwise so that no bytes change. The result is a conclusion that can be presented in court or used for internal investigation.

Computer foresee and forensic audit: what is the difference



The search for the word "forenzik" issues descriptions of investigations of hacker attacks, and the services of consulting companies for the verification of financial and economic activities. Two different worlds - to confuse them is not worth.



Computer Forensic (digital forensics) - work with digital media: removal of disk images, analysis of RAM dumps, recovery of deleted files, analysis of system logs. The goal is to find traces of the incident (attacks, leaks, internal fraud) and to record the evidence so that they will withstand the legal review.



Forenzik audit (forensic audit, forensic accounting) - financial investigation: search for asset withdrawal schemes, analysis of procurement chains, detection of fraudulent transactions. Tools here - accounting documents, bank statements, registers of counterparties. Consulting companies offer exactly such services: investigation of corporate fraud and corruption, examination for arbitration disputes.

General - the result must withstand legal verification. But the set of skills, tools and education of specialists are radical. Next, we will talk exclusively about computer forensics - digital forensics.

Stages of forensic investigation in practice
The digital investigation process is standardized. ISO/IEC 27037 describes the four phases of working with digital evidence: identification, collection, receipt (acquisition) and preservation. NIST adds analysis and presentation of results. In practice, investigating the incident goes through all these stages - but a live investigation is certainly less neat than the standard on paper.

Identification and collection of evidence
The first step is to determine which devices and media may contain relevant data. These are not only obvious laptops and servers, but also smartphones, USB drives, network equipment (router logs, DHCP records), cloud storage.

The order of collection is critical: volatile data - RAM contents, current network connections, ARP table cache - disappear when the device is switched off. Therefore, the RAM dump is removed first, before any other action. Pulled the cord out of the outlet ahead of time - lost everything that was in memory. Each device is documented: serial number, location, condition at the time of seizure, who and when seized.

Preserving data integrity
The challenge is to ensure that the evidence has not been changed. For this purpose, write-blockers (hardware devices that physically prohibit recording on the medium) and bit copying are used. The full image of the disk is removed, including unused space and slack space. Integrity is confirmed by hash amounts - if the SHA-256 image coincides with the SHA-256 of the original, the data is identical:




Bash:

dd if=/dev/sda of=/mnt/evidence/case001.img bs=4M status=progress
sha256sum /dev/sda > /mnt/evidence/case001_original.sha256
sha256sum /mnt/evidence/case001.img > /mnt/evidence/case001_image.sha256

The original medium after removing the image - in the safe. All further work is done only with a copy. The chain of custody (chain of custody) records who, when and why turned to the evidence. Without it, a competent lawyer will challenge the results of the examination in court - and will be right.

Extracting and analysis
Here begins the main work. The expert digs into the file system, Windows registry, event logs, file metadata, browser artifacts, USB connection history, Prefetch files, $MFT table.



It is necessary to take into account the techniques of anti-forensic - purposeful destruction of traces of the attackers. In the terminology of MITRE ATT&CK it is a technique Indicator Removal (T1070) with subtechnics: Clear Windows Event Logs (T1070.001), Clear Linux or Mac System Logs (T1070.002), Timestomp (T1070.006) - replacement of time labels of files. Separately - Disable or Modify Tools (T1562.001), when the attacker disables logging and protective equipment.



The task of the forensic is to recognize the traces of these techniques. The purified Event Log is an artifact in itself: the recording of EventID 1102 (Log was cleared) says no less than deleted events. Substituted time tags are detected by matching $MFT timestamps to $STANDARD_INFORMATION - if the $SI date is newer than the $FN date, it is a sign of timestomping. The attacker thought that he had noticed the traces, but in fact he left a red flag.



According to OWASP (A09:2021 - Security Logging and Monitoring Failures), the absence or incorrect setting of the logging is one of the key security problems: without logs, the investigation of the incident turns into a blind job.

Documentation and presentation of results
Each step of the investigation is recorded: what tools were used, what parameters were set, what results were obtained. The conclusion is made in a form that is clear to non-specialists - judges, management of the company, investigators. For criminal cases in Russia this is the opinion of the expert on the article. 204 of the Code of Criminal Procedure of the Russian Federation, for corporate investigations - a technical report with conclusions and recommendations.

Computer Foresight Tools
Windows Artifacts and Network Forensics
Eric Zimmerman Tools - a set of free utilities for parsing Windows-artifacts: MFTECmd (parsing $MFT), PECmd (Prefetch), Registry Explorer (register), EvtxECmd (Event Logs), ShellBags Explorer, Timeline Explorer. In Russian DFIR-teams - the actual standard. Free, fast, with good documentation.



Wireshark - network traffic analyzer with graphical interface. In forensics, it is used to parse pcap files obtained from IDS/IPS or when intercepting traffic. Filtering by protocols, restoring TCP sessions, extracting files from the network stream - everything is out of the box.



Belkasoft X - a commercial tool for extracting and analyzing data from computers, mobile devices and cloud services. Supports timeline analysis and geolocation, works with encrypted data.

NIST supports Computer Forensics Tool Testing (CFTT) program, which tests and validates forensic tools. There is also available National Software Reference Library (NSRL) - a database of hashes of known software, allowing to filter system files during analysis and focus on unique objects.

Books on forensics - what really worth reading



The lists of books on digital forensics are from the article to the article - the same titles, often without explanation, why to open them at all. Below is only what is applicable in practice, with an explanation of who and when to take.



N.N. Fedotov "Forenzika - computer forensics" - the only fundamental book in Russian. Written available, covers legal and technical aspects. Some of the tools are outdated, but the legal and methodological basis is still relevant. It is worth starting with it - at least to understand how forensics is arranged in the Russian legal field.



Brian Carrier "File System Forensic Analysis" - detailed analysis of FAT, NTFS, Ext, UFS file systems at the data structure level. The author is the creator of The Sleuth Kit. The book is heavy, but if you want to understand what exactly happens when you recover a deleted file and why slack space can contain scraps of old data - without it anywhere.



Michael Hale Ligh and co-authors of "The Art of Memory Forensics" - analysis of Windows, GNU/Linux and macOS memory dumps. Linked to the Volatility Framework. One of the few forensic books where the theory is backed by practical examples with real malware samples. It is a must for those who want to work with forensic memorys.



Harlan Carvey "Windows Registry Forensics" - a narrow topic, but for investigations on Windows critical. The registry stores data about connected USB devices, the latest open files, auto-run programs, network connections. The book teaches these data to extract and interpret.



Laura Chappell "The Official Wireshark Certified Network Analyst Study Guide" - for those who need a network forensic. Covers traffic analysis from basic filters to the analysis of malicious communications.

You should not try to read everything at the same time. Fedotov - for the context. Carrier or "Art of Memory Forensics" is then more interesting depending on whether the disk or memory foresico is more interesting. The rest as needed.

Vacancies in forensics and profession of forensic specialist
Sober picture: Forensica is not a mass market for vacancies. Positions are significantly less than in pentest or SOC monitoring. But specialists are needed, and demand is growing: IBM X-Force records the growth of attacks using valid credentials by 71% year on year, and according to CrowdStrike, cloud intrusions grew by 26%. More incidents - more investigations.



In Russia, the profession of forensic specialist is realized in several types of organizations:



DFIR teams of vendors and integrators - investigation of incidents for customers. The widest range of tasks and cases.
Expert units of law enforcement agencies - forensic examination in criminal cases. Specialized education and admissions are required.
Internal IB departments of large companies - investigation of leaks and insider threats. It is often combined with the role of incident responder.
Consulting is a forensic audit, but it's closer to accounting than to a technical computer forensic.
Interviews ask: experience with FTK Imager or Autopsy, understanding of NTFS and Ext4 file systems, skills with Volatility, knowledge of Windows artifacts (Prefetch, Amcache, ShellBags, Event Logs). For senior positions - experience with EnCase or X-Ways Forensics, knowledge of the standards of chain of custody, the ability to draw up opinions for the court.

According to IBM, the Bureau of Labor Statistics forecasts a 31% rise in vacancies in forensic computers by 2029. The Russian market is proportionally more modest, but the trend is similar. Do not expect "easy entry" - forensica requires deep technical knowledge, perseverance and attention to detail.

Forenzika for beginners: where to start
Step-by-step plan for those who want to enter digital forensics.



1. Deal with the basics of the OS. Forenzik works with artifacts of operating systems: NTFS file system (MFT, $LogFile transaction log), Windows registry, Event Log. For GNU/Linux - structure /var/log, inode-based file systems, journalctl. Without this foundation, tools are useless - like a microscope without knowledge of biology.



2. Put the tools and try your hands. Install Autopsy, download test images with CFREDS (Computer Forensic Reference Data Sets) or Digital Corpora. Try to find deleted files, build timeline, analyze web artifacts. Free, you only need a computer and time.



3. Learn memory analysis. Ready-made RAM dumps for training are available on the Volatility website. Install Volatility 3, try to extract a list of processes, network connections, identify a suspicious process. The skill of memory forensics is what distinguishes a beginner from an advanced specialist.



4. Learn Windows artifacts. Install Eric Zimmerman Tools, disassemble $MFT, Prefetch, and ShellBags on test images. Most of the investigations in practice are Windows, knowledge of these artifacts is critical.



5. Read writeups of real incidents. The publications of the DFIR-teams give an idea of how the investigations look from the beginning to the end: which artifacts were key, what techniques the anti-forenzika used the attacker, how the conclusions were drawn up.



6. Consider the certification. GIAC GCFE (Certified Forensic Examiner) is one of the most respected certifications in the industry. CHFI (Computer Hacking Forensic Investigator) from EC-Council is a more affordable option. Certification does not replace experience, but helps to pass the HR filter.



7. Practice on CTF tasks. Forenzik-taski on CTF-platforms is a way to stuff your hand in the analysis of artifacts, analysis of pcap files and memory dumps in conditions close to real.



The path from "I want to forensica" to the first work task - a minimum of six months-year with a systematic approach. Skills accumulate through practice, not through reading.



One thing rarely said out loud: Forenzika is not about the heroic investigation of one big incident. It's routine. Image removal, waiting to copy terabyte discs, same type of parsing of artifacts, multi-hour timeline analysis. Romantics in the profession exactly as much as in the work of a detective from real life - a little. But every tenth case gives a find for which everything is worth doing: a deleted file that is not completely lost; a cleaned log in which one record is left; a timestamp that does not beat the rest.
 
Top Bottom