Linux Forensics with Linux - CTF Walkthrough
DFIRScience
View ChannelAbout
Welcome to DFIRScience (https://DFIR.Science). This channel is devoted to research and development in cybersecurity, digital forensics, and incident response. DFIRScience is a mix of practical how-tos on various topics and keeps up on current news and research in digital forensic science, cybercrime investigation, and hacking. Schedule: * New tutorials every Tuesday Early, ad-free access for supporters: https://www.patreon.com/dfirscience Signup for the DFIRScience newsletter for the monthly schedule: http://eepurl.com/hG9inj π Subscribe for weekly videos β https://www.youtube.com/DFIRScience?sub_confirmation=1 πΈοΈ Website β https://DFIR.Science β€οΈ Support β https://www.patreon.com/dfirscience βοΈ Contact Us β https://bit.ly/DFIRSciContact π€ Code and data β https://github.com/dfirscience Social * https://www.twitter.com/DFIRScience * https://www.reddit.com/user/dfirscience * https://linkedin.com/dfirscience * https://facebook.com/dfirscience
Latest Posts
Video Description
Cyber5W released a mini Linux Forensics capture the flag (CTF) as part of the Magnet User Summit 2022. [https://lfmus22.cyber5w.net/] It is open until the end of the year. And while there are no prizes, it is an excellent way to practice investigating Linux systems. The scenario is an internal policy violation. Each system has some suspect user activities. However, the questions only somewhat related to the scenario. Thank you to our Members and Patrons, but especially to our Investigators, TheRantingGeek, Roman, and Alexis Brignoni! Thank you so much! Instead of processing the forensic images with a tool like Autopsy, we mount the images with ewfmount, mmls, and mount. This gives us direct access to the suspect data. Then we chroot into the suspect root directory to see a "native view" of the suspect data. This makes investigations much easier. 00:00 Cyber5W Linux Forensics CTF 00:15 CTF Case Scenario 00:44 How this walkthrough works 01:11 Download images and setup 02:40 Verify Expert Witness Format File E01 with ewfverify 06:05 Mount the suspect disk image with ewfmount and mount 08:16 Get disk partition offsets with mmls and bc 10:44 Mount the partition based on disk offset with mount 12:18 Access the suspect system directly with chroot 14:04 MATE Q1 15:54 MATE Q2 18:25 MATE Q3 19:56 MATE Q4 22:58 MATE Q5 23:43 MATE Q6 25:48 Switching to the Kubuntu image 28:36 KUBUNTU Q1 30:01 KUBUNTU Q2 32:19 KUBUNTU Q3 33:58 KUBUNTU Q4 37:43 KUBUNTU Q5 40:29 Clean up and conclusions π Full Digital Forensic Courses β https://learn.dfir.science Links: * Linux CTF: https://lfmus22.cyber5w.net/ * Tsurugi Linux (to follow exactly): https://tsurugi-linux.org/ Related books: * π₯π₯Practical Linux Forensics (https://amzn.to/3MMCjqY) * Digital Forensics with Open Source Tools (https://amzn.to/388dE1e) 010001000100011001010011011000110110100101100101011011100110001101100101 Get more Digital Forensic Science π Subscribe β https://bit.ly/2Ij9Ojc β€οΈ YT Member β https://bit.ly/DFIRSciMember β€οΈ Patreon β https://www.patreon.com/dfirscience πΈοΈ Blog β https://DFIR.Science π€ Code β https://github.com/DFIRScience π¦ Follow β https://www.twitter.com/DFIRScience π° DFIR Newsletter β https://bit.ly/DFIRNews 010100110111010101100010011100110110001101110010011010010110001001100101 Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License. Please link back to the original video. If you want to use this video for commercial purposes, please contact us first. We would love to see what you are doing.
Forensics Kit Essentials
AI-recommended products based on this video

10Gtek USB WiFi Adapter, for PC, AC600M USB WiFi Dongle 802.11ac Wireless Network Adapter with Dual Band 2.4GHz/5Ghz for Desktop Laptop Support Windows 10/8/7/XP, MAC OS, Linux etc

TP-Link USB WiFi Adapter for PC(TL-WN725N), N150 Wireless Network Adapter for Desktop - Nano Size WiFi Dongle for Windows 11/10/7/8/8.1/XP/ Mac OS 10.9-10.15 Linux Kernel 2.6.18-4.4.3, 2.4GHz Only

TP-Link USB to Ethernet Adapter (UE306) - Foldable USB 3.0 to Gigabit Ethernet LAN Laptop Network Adapter, Supports Nintendo Switch, Windows, Linux, Apple MacBook OS 10.11- OS 12, Surface

10.1 Inch Touch Portable Monitor IPS Screen 1366x768P 60Hz 400 Brightness 99% sRGB HDMI USB-C Monitors Switch for Xbox PS3/4/5 Laptop Compatible with Raspberry Pi, Mini Touch Screen

UGREEN USB to USB C Adapter & USB C to USB Adapter Combo 4-Pack, 10Gbps Type-C Converter, Car Charger Compatible with MacBook Pro, iPad Mac mini, iPhone 17/16, Galaxy, PC/Laptop, Hard Drive Enclosure

Elebase USB to USB C Adapter 4 Pack,USBC Female to A Male Car Charger,Type C Converter for iPhone 16 Pro Max,15 14 13 12 11 Plus,Apple Watch iWatch 10 9 8,Airpods,iPad Air Mini 6 7,Samsung Galaxy S25

Mcbazel Wii to HDMI Converter Output Video Audio Adapter for Wii (NTSC 480I, 480P, PAL 576I) -Support All Display Modes

ABLEWE RCA to HDMI,AV to HDMI Converter, 1080P Mini RCA Composite CVBS Video Audio Converter Adapter Supporting PAL/NTSC for TV/PC/ PS3/ STB/Xbox VHS/VCR/Blue-Ray DVD Players

USB C Hub, MacBook Pro Adapter USB C Dongle with 4K HDMI,Thunderbolt 3 100W Power Delivery Port,USB C 5Gbps Data Port,SD/TF Card Reader,2 USB 3.0 Ports Compatible for MacBook Pro Air 2022/2021/2020

SanDisk 64GB 2-Pack Ultra USB 3.0 Flash Drive (2x64GB) - SDCZ48-064G-GAM462, Black

Netac 64GB USB Stick USB 3.0 Flash Drive, Up to 90MB/s, Thumb Drive for Data Storage, Pen Drive with Swivel Design, Memory Stick for External Storage Data/Computer/PC/Laptop/Sound

RAOYI 5pcs 32GB USB 3.0 Flash Drive Memory Stick Fold Storage Thumb Stick Pen Drive U Disk Swivel Design (5 Mixed Colors: Black Red Blue Green Purple)

SanDisk Ultra Flair USB 3.0 64GB Flash Drive High Performance up to 150MB/s (SDCZ73-064G-G46)

Logitech M185 Wireless Mouse, 2.4GHz with USB Mini Receiver, 12-Month Battery Life, 1000 DPI Optical Tracking, Ambidextrous, Compatible with PC, Mac, Laptop - Black

Logitech G203 Wired Gaming Mouse, 8,000 DPI, Rainbow Optical Effect LIGHTSYNC RGB, 6 Programmable Buttons, On-Board Memory, Screen Mapping, PC/Mac Computer and Laptop Compatible - Black

Logitech G305 LIGHTSPEED Wireless Gaming Mouse, Hero 12K Sensor, 12,000 DPI, Lightweight, 6 Programmable Buttons, 250h Battery Life, On-Board Memory, PC/Mac - Black

Logitech G502 HERO High Performance Wired Gaming Mouse, HERO 25K Sensor, 25,600 DPI, RGB, Adjustable Weights, 11 Programmable Buttons, On-Board Memory, PC / Mac, Black

Dell UltraSharp 24 Monitor - U2424H

Dell UltraSharp U2723QE 27" 4K UHD WLED LCD Monitor - 16:9 - Black, Silver EPEAT

Dell UltraSharp U2725QE 27' 4K Thunderbolt-Hub-Monitor mit Bildwiederholfrequenz Von 120Hz























