1 00:00:00,000 --> 00:00:04,229 W. Curtis Preston: You found the backup wrap up your go-to podcast for all things 2 00:00:04,229 --> 00:00:06,659 backup recovery and cyber recovery. 3 00:00:07,125 --> 00:00:11,384 In this episode, we explore the crucial world of ransomware forensics with 4 00:00:11,384 --> 00:00:13,875 cybersecurity expert Mike Saylor. 5 00:00:14,204 --> 00:00:18,944 We cover why forensics is important during a cyber attack, the essential steps and 6 00:00:18,944 --> 00:00:23,865 tools you need to do the job, and we shed light on how organizations can prepare 7 00:00:23,865 --> 00:00:26,655 for and respond to ransomware incidents. 8 00:00:27,119 --> 00:00:30,689 From preserving critical evidence to navigating the complexities of 9 00:00:30,689 --> 00:00:35,579 mobile device forensics, this episode will explain how to use ransomware 10 00:00:35,579 --> 00:00:40,109 forensics to unravel cyber attacks and protect your valuable data. 11 00:00:40,829 --> 00:00:45,697 By the way, if you have no idea who I am, hi, I'm w Curtis Preston, AKA, Mr. 12 00:00:45,702 --> 00:00:45,810 Backup, 13 00:00:46,923 --> 00:00:51,573 and I've been passionate about backup and recovery and related topics ever since. 14 00:00:51,573 --> 00:00:55,953 I had to tell my boss that we had lost the production database 15 00:00:56,283 --> 00:00:58,023 and had no backup for it. 16 00:00:58,953 --> 00:01:00,573 I don't want that to happen to me. 17 00:01:00,573 --> 00:01:03,873 I don't want that to happen to you, and that's why I do this podcast. 18 00:01:03,873 --> 00:01:08,433 Here we turn Unappreciated backup admins into cyber recovery Heroes. 19 00:01:08,583 --> 00:01:10,803 This is the backup wrap up. 20 00:01:25,996 --> 00:01:26,926 Welcome to the show. 21 00:01:28,126 --> 00:01:32,116 Before I continue, if I could ask you to press that subscribe or follow 22 00:01:32,116 --> 00:01:34,216 button so that you'll continue to get. 23 00:01:34,561 --> 00:01:39,811 Our amazing content I am w Curtis Preston, AKA, Mr. 24 00:01:39,811 --> 00:01:45,201 Backup, and I have with me my power loss counselor Prassanna 25 00:01:45,401 --> 00:01:47,891 Malaiyandi, how's it going prasanna. 26 00:01:48,586 --> 00:01:52,696 Prasanna Malaiyandi: I'm doing well, Curtis, I know you, not so much, 27 00:01:52,876 --> 00:01:56,956 but hey, isn't solar and batteries and everything else supposed to 28 00:01:56,956 --> 00:01:58,481 solve all these issues for you? 29 00:01:59,746 --> 00:02:03,751 W. Curtis Preston: I, I was a, as you know, I've been working on behalf 30 00:02:03,751 --> 00:02:08,671 of this one customer and we've been conducting the first ever backup 31 00:02:08,671 --> 00:02:10,141 of some really important data. 32 00:02:10,651 --> 00:02:14,881 Um, and it's like 500 terabytes of data, and we're down to the, we're kind of down 33 00:02:14,881 --> 00:02:17,401 to the, I think the, the, the finish line. 34 00:02:18,556 --> 00:02:24,526 And, uh, I had, I'm running a bunch of backups and I had divvied the backups up 35 00:02:24,526 --> 00:02:30,346 into thousands of little policies because for many, many reasons, and some of those 36 00:02:30,346 --> 00:02:34,696 policies were still, even though they were backing up, only a single sub, sub 37 00:02:35,056 --> 00:02:40,876 subdirectory, they've been running for like 10 days when I lost power yesterday. 38 00:02:42,151 --> 00:02:43,591 When the customer lost power 39 00:02:44,371 --> 00:02:45,061 Prasanna Malaiyandi: Ouch. 40 00:02:45,541 --> 00:02:48,271 W. Curtis Preston: rebooting And there is no 41 00:02:48,481 --> 00:02:49,411 Prasanna Malaiyandi: my question for you 42 00:02:49,861 --> 00:02:53,251 is why is there no resume functionality for. 43 00:02:53,851 --> 00:02:57,361 W. Curtis Preston: there is in uh, so in this particular 44 00:02:57,361 --> 00:02:58,681 customer, we're using that backup. 45 00:02:58,686 --> 00:03:03,061 There is a resume functionality in that backup, but not for SMB. 46 00:03:03,946 --> 00:03:05,566 Our network based backup. 47 00:03:05,566 --> 00:03:07,606 So we're doing, we're backing up over s and b. 48 00:03:07,666 --> 00:03:12,166 Um, we, we tried s and b and NFS, uh, we're backing up over s and b 49 00:03:12,166 --> 00:03:13,756 and there's no resume functionality. 50 00:03:13,756 --> 00:03:16,876 So I will start over. 51 00:03:17,086 --> 00:03:23,596 Um, and we will have lost 10 days and this backup that is taking forever. 52 00:03:25,786 --> 00:03:26,506 Good times. 53 00:03:26,881 --> 00:03:28,591 Prasanna Malaiyandi: I am sorry Curtis, but 54 00:03:29,221 --> 00:03:29,581 in, 55 00:03:29,716 --> 00:03:30,051 W. Curtis Preston: That's all. 56 00:03:30,166 --> 00:03:31,456 That's all I needed to hear. 57 00:03:31,636 --> 00:03:32,806 Prasanna was somebody. 58 00:03:33,661 --> 00:03:34,261 Say there. 59 00:03:34,261 --> 00:03:34,801 Sorry. 60 00:03:38,581 --> 00:03:40,171 Oh, goodness gracious. 61 00:03:40,171 --> 00:03:43,291 But as I told you this morning, when I texted you, at least I found out 62 00:03:43,291 --> 00:03:45,271 that the reboot that was not my fault 63 00:03:45,991 --> 00:03:47,701 Prasanna Malaiyandi: Yes, it was not the server randomly 64 00:03:48,001 --> 00:03:49,561 W. Curtis Preston: was not, the server was not, 65 00:03:50,251 --> 00:03:50,641 yeah. 66 00:03:50,671 --> 00:03:53,646 Prasanna Malaiyandi: oh, I'll, I asked you first it was like, was it CrowdStrike? 67 00:03:54,341 --> 00:03:54,631 W. Curtis Preston: Yeah. 68 00:03:55,461 --> 00:03:55,751 Yeah. 69 00:03:56,446 --> 00:03:59,086 was not, it was not CrowdStrike. 70 00:03:59,146 --> 00:04:01,216 It is a window server, but it was not CrowdStrike. 71 00:04:01,246 --> 00:04:03,196 Uh, CrowdStrike is not running on the server. 72 00:04:03,286 --> 00:04:04,666 I did check that, by the way. 73 00:04:06,406 --> 00:04:11,506 But, uh, anyway, but speaking of the cyber world, we once again have 74 00:04:11,506 --> 00:04:16,846 our friend of the pod, Mike Sailor, uh, uh, joining with us today. 75 00:04:16,846 --> 00:04:17,686 How's it going, Mike? 76 00:04:18,796 --> 00:04:19,696 Mike Saylor: Afternoon, I'm well. 77 00:04:21,856 --> 00:04:24,676 W. Curtis Preston: So, uh, we're gonna, and, and for those of you 78 00:04:24,676 --> 00:04:28,336 that follow the show, you're gonna see a lot of mike, uh, over the next 79 00:04:28,426 --> 00:04:34,006 little bit, uh, because we're diving deep, diving deep into the world of 80 00:04:34,006 --> 00:04:37,546 responding to a ransomware attack. 81 00:04:37,966 --> 00:04:41,596 And today we're gonna talk about the forensics phase. 82 00:04:41,596 --> 00:04:43,486 So, uh, Mike. 83 00:04:43,996 --> 00:04:45,766 What, what do we mean when we say that? 84 00:04:45,766 --> 00:04:49,726 Why would we be doing forensics in the middle of a cyber attack? 85 00:04:52,126 --> 00:04:55,246 Mike Saylor: Well, uh, it's a great way to collect evidence in a, in a 86 00:04:55,246 --> 00:04:57,646 safe, uh, controlled environment. 87 00:04:58,246 --> 00:05:03,526 And so forensics creates a read-only image of, of your target. 88 00:05:03,586 --> 00:05:07,246 So whether it's a whole machine or a particular file or object, uh. 89 00:05:08,326 --> 00:05:11,326 We create an image of that that's read only so we can play with it 90 00:05:11,326 --> 00:05:14,446 and look at it and not have to worry about it executing more malware 91 00:05:14,446 --> 00:05:16,396 or trying to do what malware does. 92 00:05:16,936 --> 00:05:18,046 But, so there's one thing. 93 00:05:18,046 --> 00:05:19,966 So some, some safe analysis. 94 00:05:19,966 --> 00:05:21,286 We can build a sandbox. 95 00:05:21,286 --> 00:05:27,496 The other part of that is, uh, in that analysis, we, we can learn things about, 96 00:05:27,976 --> 00:05:31,696 um, you know, particular, uh, artifact. 97 00:05:31,696 --> 00:05:33,796 So if it's malware, uh. 98 00:05:34,531 --> 00:05:37,561 Uh, is there any metadata that would indicate, you know, the type 99 00:05:37,561 --> 00:05:39,241 of malware where it came from? 100 00:05:39,601 --> 00:05:44,431 Uh, is the signature or hash value of this malware similar to other, um, 101 00:05:45,271 --> 00:05:47,071 other cases using the same malware? 102 00:05:47,401 --> 00:05:52,141 But then if we expand that from just that object or artifact into the, like 103 00:05:52,146 --> 00:05:57,871 an entire system, uh, forensically without having to change, so. 104 00:05:58,651 --> 00:06:02,281 I guess fundamentally I'll add, uh, forensics allows us to interact 105 00:06:02,281 --> 00:06:05,251 with, with evidence without changing any of that metadata. 106 00:06:05,671 --> 00:06:09,241 So if you log into a machine to review what happened to this machine, you're 107 00:06:09,241 --> 00:06:12,241 also changing data in the machine. 108 00:06:12,241 --> 00:06:15,751 You're, you're, you're, you're stepping on evidence potentially, 109 00:06:15,781 --> 00:06:16,441 or changing. 110 00:06:16,951 --> 00:06:20,041 W. Curtis Preston: what's the, there, there's a thing in science, the 111 00:06:20,041 --> 00:06:22,051 observational effect for something. 112 00:06:22,051 --> 00:06:23,311 There's a, there's a word for that. 113 00:06:24,151 --> 00:06:24,391 Mike Saylor: Yep. 114 00:06:24,391 --> 00:06:26,011 So once you interact with, with 115 00:06:26,011 --> 00:06:26,881 it, it changes, 116 00:06:27,571 --> 00:06:27,781 Right. 117 00:06:27,781 --> 00:06:29,791 So observation, simple observation. 118 00:06:29,791 --> 00:06:32,881 Sometimes, uh, uh, muddies the water. 119 00:06:33,361 --> 00:06:37,711 So creating forensic image of, of whatever it is, allows you to play 120 00:06:37,711 --> 00:06:40,561 with it and, and interact with it without changing the fundamental 121 00:06:40,561 --> 00:06:42,361 evidence of any attributes or metadata. 122 00:06:42,481 --> 00:06:42,541 It. 123 00:06:43,111 --> 00:06:47,041 So if I, if if a machine as an example, uh, since we're talking about incident 124 00:06:47,046 --> 00:06:51,811 response, if a machine is infected or, or we suggest something or we suspect 125 00:06:51,811 --> 00:06:56,551 something happened, compromised, uh, employee downloaded a bunch of data on 126 00:06:56,551 --> 00:07:01,231 their last day, whatever, whatever our suspicion is that led us to this machine, 127 00:07:01,231 --> 00:07:06,061 if we do a forensic image of that, a couple of things, uh, are important, 128 00:07:06,211 --> 00:07:10,081 uh, about that one, we can review all that stuff without changing anything. 129 00:07:10,081 --> 00:07:10,711 So if we. 130 00:07:11,221 --> 00:07:14,611 If we need to hand it over to legal counsel or it goes to court 131 00:07:14,611 --> 00:07:16,321 prosecution, any of that stuff. 132 00:07:16,681 --> 00:07:17,881 It, it is in the state. 133 00:07:17,881 --> 00:07:21,721 It was, uh, whenever that event happened. 134 00:07:22,351 --> 00:07:26,191 The other thing that allows us to do is determine attributes 135 00:07:26,251 --> 00:07:27,691 of certain activities. 136 00:07:27,691 --> 00:07:31,921 So if it's malware, ransomware, as an example, how did it get on this machine? 137 00:07:31,921 --> 00:07:33,181 What did the log files say? 138 00:07:33,181 --> 00:07:34,831 What is the, uh. 139 00:07:35,446 --> 00:07:36,556 What network was it on? 140 00:07:36,556 --> 00:07:37,996 Was it attached to a wifi? 141 00:07:38,026 --> 00:07:38,806 Where did it go? 142 00:07:38,806 --> 00:07:42,646 What connections did it make from this machine to other machines? 143 00:07:42,916 --> 00:07:45,916 There's a lot of good stuff, uh, that you're able to dig into. 144 00:07:46,066 --> 00:07:48,256 Uh, if you have the right tools and you know where to look. 145 00:07:48,621 --> 00:07:53,031 Prasanna Malaiyandi: So when you say forensic image, what exactly do you mean? 146 00:07:53,451 --> 00:07:53,781 Right. 147 00:07:53,781 --> 00:07:56,901 Is it just like, 'cause I know we've talked, especially on this 148 00:07:56,901 --> 00:08:00,861 podcast previously about like snapshots and backups and everything 149 00:08:00,861 --> 00:08:04,371 else, but that's sort of like copying the data out sometimes. 150 00:08:04,371 --> 00:08:06,141 Like if you're doing an image-based copy. 151 00:08:06,786 --> 00:08:09,456 Of like a virtual machine, you get a virt, uh, duplicate 152 00:08:09,456 --> 00:08:10,866 copy of that virtual machine. 153 00:08:11,166 --> 00:08:14,286 Is there something different when you talk about forensic image that 154 00:08:14,286 --> 00:08:19,176 goes beyond just sort of taking a copy of like a virtual machine? 155 00:08:20,711 --> 00:08:22,871 Mike Saylor: There's a couple of things that, that make the term 156 00:08:22,871 --> 00:08:24,851 forensic imaging a little different. 157 00:08:24,851 --> 00:08:28,541 One forensic, the forensic part of that term is really just the 158 00:08:28,541 --> 00:08:33,671 discipline, understanding how to approach and, and conduct, uh, a 159 00:08:33,676 --> 00:08:39,101 forensic imaging, um, in a, in that, in that approved manner, you've got 160 00:08:39,101 --> 00:08:39,521 a formal 161 00:08:39,556 --> 00:08:41,056 Prasanna Malaiyandi: you don't change things right, like you 162 00:08:41,056 --> 00:08:42,076 were talking about previously. 163 00:08:42,796 --> 00:08:43,576 Mike Saylor: It's consistent. 164 00:08:43,906 --> 00:08:47,866 So if it goes to court as a forensic expert, I can say I did this the 165 00:08:47,866 --> 00:08:49,186 way that I've done all of them. 166 00:08:49,246 --> 00:08:52,876 And there's this documented formal process that's, you know, approved and 167 00:08:52,876 --> 00:08:56,386 and known by industry and accepted in court cases and that kind of thing. 168 00:08:56,391 --> 00:08:59,416 So there's the discipline of forensics that lends itself 169 00:08:59,416 --> 00:09:01,066 to the forensic imaging term. 170 00:09:01,576 --> 00:09:04,186 Uh, more specifically it's called forensic acquisition. 171 00:09:04,936 --> 00:09:08,446 Uh, so we're acquiring the data and the way that we're acquiring 172 00:09:08,446 --> 00:09:09,736 it is through a forensic. 173 00:09:10,051 --> 00:09:12,361 Least sound imaging process. 174 00:09:13,021 --> 00:09:19,441 Now, another, another term, uh, that, and, and this goes back to just normal, like 175 00:09:19,501 --> 00:09:23,521 investigative processes is best evidence. 176 00:09:24,301 --> 00:09:29,256 And so for example, if, if, uh, I'm working on a MacBook Pro that's 177 00:09:29,256 --> 00:09:31,621 got a, an integrated storage DR. 178 00:09:31,681 --> 00:09:35,341 Drive and it's encrypted and there's just, they. 179 00:09:35,911 --> 00:09:38,611 And I, and I'm time constrained or resource constrained, or the 180 00:09:38,611 --> 00:09:42,421 building's on fire or whatever it is, I'm not gonna be able to do a a, a 181 00:09:42,421 --> 00:09:44,941 sound forensic image of that laptop. 182 00:09:45,451 --> 00:09:49,711 What would be better and more timely and possibly as valuable? 183 00:09:50,431 --> 00:09:52,681 Best evidence would be an iTunes backup. 184 00:09:53,201 --> 00:09:53,421 Prasanna Malaiyandi: Hmm. 185 00:09:54,031 --> 00:09:56,791 Mike Saylor: Let's do an iTunes backup before this building burns down, and I run 186 00:09:56,791 --> 00:10:00,961 outta time, and that is the best evidence I had the ability to get at that moment. 187 00:10:01,561 --> 00:10:04,921 You mentioned snapshots or even other backups? 188 00:10:05,011 --> 00:10:09,631 Um, we, we, back in the day when, when we were doing a lot of email forensics, 189 00:10:09,631 --> 00:10:13,801 we were, we would do two, we would do the local PST file and then the, the 190 00:10:13,801 --> 00:10:15,841 backup, uh, from the exchange server. 191 00:10:16,851 --> 00:10:17,141 W. Curtis Preston: Yeah. 192 00:10:17,191 --> 00:10:19,201 Mike Saylor: there's, those are good evidence, one or the other. 193 00:10:19,516 --> 00:10:23,146 W. Curtis Preston: It probably falls, uh, Mike, it probably falls in, you 194 00:10:23,146 --> 00:10:25,126 know, a lot of stuff we talk about here. 195 00:10:25,126 --> 00:10:26,511 We talk about good, better, best, right? 196 00:10:27,196 --> 00:10:30,796 So, you know, good, you know, not good is nothing. 197 00:10:31,036 --> 00:10:31,336 Right. 198 00:10:31,336 --> 00:10:33,256 Good is something right. 199 00:10:33,256 --> 00:10:37,426 So like, you know, said like the PST files, uh, maybe an iTunes backup, maybe 200 00:10:37,666 --> 00:10:41,236 any kind of backup that would help prove the, the whatever it is, the thing that 201 00:10:41,236 --> 00:10:43,876 you're trying to prove or investigate the thing you're trying to investigate. 202 00:10:44,356 --> 00:10:48,106 The next level, I would think would be an image of the hard drive, like 203 00:10:48,106 --> 00:10:49,516 a full image of the hard drive. 204 00:10:49,516 --> 00:10:52,996 The next level beyond that would be the full image of the hard drive plus. 205 00:10:53,356 --> 00:10:57,616 The, the image of the memory at the time of the system running right. 206 00:10:58,156 --> 00:10:58,816 Um, 207 00:10:59,746 --> 00:10:59,896 Mike Saylor: And 208 00:10:59,896 --> 00:11:03,466 so that, that discipline, that discipline lends itself to your 209 00:11:03,466 --> 00:11:08,956 understanding as a forensics expert of, of how to approach this situation. 210 00:11:09,286 --> 00:11:12,556 If the computer's on, yeah, I can do a memory dump of that if it's 211 00:11:12,561 --> 00:11:14,956 not on, well, it's not even probable 212 00:11:15,046 --> 00:11:20,056 unless, you know, the virtual, the, uh, like the, the drive, uh, storage 213 00:11:20,056 --> 00:11:24,106 drive cache, uh, but also understanding the, the fundamentals of the device. 214 00:11:24,111 --> 00:11:26,206 Your, your target is, I mean, is it a. 215 00:11:26,836 --> 00:11:28,306 Can I take the hard drive out of this? 216 00:11:28,311 --> 00:11:28,996 Is it sd? 217 00:11:28,996 --> 00:11:30,526 Is it, you know, mechanical? 218 00:11:30,526 --> 00:11:32,656 Is it flash, is it integrated? 219 00:11:33,136 --> 00:11:36,316 Um, all of those things are important. 220 00:11:36,646 --> 00:11:41,656 Uh, one thing I'll just add real quick to best e evidence, it's also, uh, and 221 00:11:41,656 --> 00:11:45,286 I, I alluded to this in my example of the, the house is on fire, what have 222 00:11:45,286 --> 00:11:47,836 you, but it's also, uh, logistics. 223 00:11:48,136 --> 00:11:53,296 So if, if, if the, if the case is in, you know, in Europe. 224 00:11:53,941 --> 00:11:57,661 The likelihood that we're gonna timely be able to get a forensic image of 225 00:11:57,661 --> 00:12:00,301 that device is, uh, is pretty limited. 226 00:12:00,361 --> 00:12:02,881 You know, they, we, I've either gotta send somebody there or 227 00:12:02,881 --> 00:12:04,051 they've gotta ship it to me. 228 00:12:04,561 --> 00:12:06,781 Uh, and in both cases you've got some logistics. 229 00:12:06,781 --> 00:12:10,771 So if it's a virtual environment, just take a snapshot, upload it through 230 00:12:10,771 --> 00:12:13,801 a cloud, make it available to me, I can pull it down or work on it. 231 00:12:14,161 --> 00:12:17,371 Um, and so those are also acceptable alternatives. 232 00:12:17,586 --> 00:12:20,826 W. Curtis Preston: don't, those don't, those snapshots in a virtual 233 00:12:20,826 --> 00:12:26,466 environment that they usually contain, uh, the memory image, right. 234 00:12:27,481 --> 00:12:28,591 Mike Saylor: From the virtual environment, 235 00:12:28,591 --> 00:12:29,461 they typically do your 236 00:12:29,586 --> 00:12:29,826 W. Curtis Preston: Yeah. 237 00:12:29,896 --> 00:12:30,186 Yeah. 238 00:12:30,661 --> 00:12:30,871 Mike Saylor: Yep. 239 00:12:31,076 --> 00:12:31,296 Yep. 240 00:12:31,666 --> 00:12:33,976 Prasanna Malaiyandi: So as you're describing all of this, Mike, I was 241 00:12:33,976 --> 00:12:37,456 just thinking this is something that's like way outside the scope of like 242 00:12:37,456 --> 00:12:40,696 what a normal IT person does, right? 243 00:12:40,696 --> 00:12:43,066 Just even thinking about like how do I even approach this? 244 00:12:43,071 --> 00:12:47,116 Maybe you might get some of this from like the secure, like a security person, 245 00:12:47,116 --> 00:12:49,156 but just like an IT generalist probably. 246 00:12:49,546 --> 00:12:51,346 Isn't thinking about things in this way, right? 247 00:12:51,346 --> 00:12:54,376 They're probably thinking about how do I quickly recover my 248 00:12:54,376 --> 00:12:56,896 machine if it was down right? 249 00:12:56,896 --> 00:12:59,566 How do I get people back up and running? 250 00:12:59,566 --> 00:13:03,226 Not necessarily how do I preserve evidence to figure out what went on? 251 00:13:03,996 --> 00:13:04,356 Mike Saylor: Yep. 252 00:13:04,836 --> 00:13:08,196 And it's, uh, I, I've seen it implemented just as normal standard 253 00:13:08,196 --> 00:13:12,396 operating procedure in some, some environments, uh, where every 254 00:13:12,396 --> 00:13:14,226 employee that leaves, they do an image 255 00:13:14,226 --> 00:13:16,656 of that laptop so that they can preserve that. 256 00:13:16,661 --> 00:13:19,776 They then they, uh, rebuild the machine and put it out. 257 00:13:20,386 --> 00:13:21,376 Uh, redistribute it. 258 00:13:21,436 --> 00:13:26,026 Uh, so that if, and that, and that's, uh, for, for it to become more efficient. 259 00:13:26,026 --> 00:13:29,656 So they're not, they don't have this, this laptop on a shelf somewhere for some, 260 00:13:29,716 --> 00:13:33,286 you know, 34, 5 days until management decides they don't need anything. 261 00:13:33,886 --> 00:13:36,976 The day that they, they separate, they get that laptop back, they 262 00:13:36,976 --> 00:13:40,816 image it takes a couple of hours, uh, they're then able to rebuild it. 263 00:13:40,816 --> 00:13:44,656 So by the end of the same day, they're able to re redistribute that image 264 00:13:44,686 --> 00:13:48,316 or that that laptop and then preserve that image on, on a server somewhere. 265 00:13:49,111 --> 00:13:50,216 In case it's needed in the future. 266 00:13:50,656 --> 00:13:52,306 W. Curtis Preston: Yeah, it's, it's a very different. 267 00:13:52,681 --> 00:13:56,011 Um, like, like you said, broan, it's a very different discipline than 268 00:13:56,011 --> 00:14:00,241 backup and recovery, even though it's kind of a backup, it's just a backup 269 00:14:00,631 --> 00:14:02,701 done for a very different purpose. 270 00:14:02,761 --> 00:14:03,811 It's just like archive. 271 00:14:03,841 --> 00:14:07,591 Archive is kind of like a backup but done for a very different purpose. 272 00:14:07,591 --> 00:14:07,891 Right. 273 00:14:07,891 --> 00:14:11,281 This is, this is kind of like an archive. 274 00:14:11,791 --> 00:14:16,651 'cause you're, you're basically making a one time copy of the drive, 275 00:14:16,981 --> 00:14:20,461 um, for the, for the purposes of. 276 00:14:21,331 --> 00:14:24,781 Other things, you're not doing it generally, you're not doing it. 277 00:14:25,171 --> 00:14:29,791 Um, that the, the departing employee defense thing, uh, Mike, maybe one 278 00:14:29,791 --> 00:14:32,281 of those where there's dual purposes, you may need that image later 279 00:14:32,281 --> 00:14:36,811 because you accuse the, the, the, um, the employee of doing something. 280 00:14:37,081 --> 00:14:39,961 You may need that image later when you find out, oh crap. 281 00:14:40,201 --> 00:14:40,831 The, uh, 282 00:14:41,361 --> 00:14:42,346 Prasanna Malaiyandi: They had a file. 283 00:14:42,631 --> 00:14:44,731 W. Curtis Preston: he was the only guy working on the empty squad 284 00:14:44,731 --> 00:14:47,071 project, and it's only on its laptop. 285 00:14:47,281 --> 00:14:49,411 Well, first off, that was an it fail, but. 286 00:14:49,631 --> 00:14:53,981 That may be a reason to use your use, use your forensic image for something else. 287 00:14:54,161 --> 00:14:59,261 But in this case, primarily what we're talking about, right, is we're 288 00:14:59,261 --> 00:15:00,851 in the midst of a cyber attack. 289 00:15:01,181 --> 00:15:04,541 We're going to get, you know, I, I like your term best evidence. 290 00:15:04,541 --> 00:15:09,671 We're gonna get the best copy that we can of the environment that we believe is, 291 00:15:09,671 --> 00:15:14,831 is, uh, subject to this attack so that we can use that for multiple purposes. 292 00:15:15,791 --> 00:15:16,691 You talked about. 293 00:15:17,356 --> 00:15:18,346 I like that first one. 294 00:15:18,346 --> 00:15:22,726 You talked about taking that image and putting it into, when you first said it, 295 00:15:22,726 --> 00:15:24,166 I, I didn't understand what you meant. 296 00:15:24,166 --> 00:15:27,496 You said you, you said something like, it allows you to interact 297 00:15:27,496 --> 00:15:30,976 with it in a, in a safe environment or a controlled environment. 298 00:15:30,976 --> 00:15:32,686 I was like, whatcha talking about controlled environment? 299 00:15:32,686 --> 00:15:34,126 We're in the midst of a cyber attack here. 300 00:15:34,426 --> 00:15:38,176 But you're talking about taking that image and moving it to a different 301 00:15:38,176 --> 00:15:43,996 environment where you have more control over the, over, over, the network. 302 00:15:43,996 --> 00:15:45,196 Is that that what you meant? 303 00:15:46,611 --> 00:15:49,506 Mike Saylor: OO over the, over the image that you're, 304 00:15:49,716 --> 00:15:50,586 you're playing with. 305 00:15:51,186 --> 00:15:55,296 But, but forensics tools also allow you to, to rebuild an environment. 306 00:15:55,296 --> 00:15:55,986 So if I image. 307 00:15:56,196 --> 00:16:01,446 You know, four net networked PCs, then I can, I can load all of those 308 00:16:01,446 --> 00:16:08,316 images into one case in my forensics tool and view all of the data across 309 00:16:08,316 --> 00:16:11,136 all of those images concurrently. 310 00:16:11,706 --> 00:16:13,176 I don't have to treat them as individually. 311 00:16:13,176 --> 00:16:14,586 It becomes one big data set. 312 00:16:15,366 --> 00:16:20,361 And the other thing I'll add too is that, um, you know, fundamentally, uh. 313 00:16:21,451 --> 00:16:23,641 And that is consistent today. 314 00:16:23,641 --> 00:16:27,721 Even the, some of the tools that forensics, uh, practitioners use 315 00:16:27,721 --> 00:16:31,831 are, uh, the, the fundamental capabilities are based on traditional 316 00:16:31,831 --> 00:16:34,021 system tools like DD and the Linux 317 00:16:34,021 --> 00:16:38,491 Unix environment, uh, ghost and, and SIS tools in the Windows environment. 318 00:16:38,731 --> 00:16:42,721 I mean, that's, those are tools we used, you know, 20 years ago to to do imaging. 319 00:16:43,261 --> 00:16:48,181 Um, and then today, so today a lot of the forensics imaging tools, 320 00:16:48,331 --> 00:16:52,291 some of them are available free, uh, because they want you to then use 321 00:16:52,291 --> 00:16:55,261 their, their expensive analysis tool. 322 00:16:55,951 --> 00:17:03,691 Um, but to your point about, uh, the, the normal IT or ops person not being familiar 323 00:17:03,691 --> 00:17:07,141 with forensics, I think they are, again, to your comment about the, from the, from 324 00:17:07,141 --> 00:17:09,571 a backup perspective or cloning or a. 325 00:17:10,066 --> 00:17:13,191 Uh, you know, imaging, you know, I, I've, I've created a, i, I 326 00:17:13,196 --> 00:17:15,796 built a laptop and this is the way I want all my laptops to be. 327 00:17:15,796 --> 00:17:19,966 So I made this golden image, but then I'm gonna apply on every laptop we build 328 00:17:19,966 --> 00:17:24,976 and distribute same, same principle and some of the same fundamental tools. 329 00:17:25,336 --> 00:17:25,936 Um, 330 00:17:26,791 --> 00:17:27,301 W. Curtis Preston: I like, 331 00:17:27,496 --> 00:17:27,646 Mike Saylor: I think. 332 00:17:28,201 --> 00:17:30,661 W. Curtis Preston: I like the comment that you talked about and you, you 333 00:17:30,661 --> 00:17:36,091 reminded me because when you make that forensic image with some exceptions, 334 00:17:36,091 --> 00:17:42,481 that that image is really just an image of a hard drive that can be mounted and 335 00:17:42,481 --> 00:17:47,731 accessed without actually running the operating system of that hard drive. 336 00:17:47,731 --> 00:17:48,691 So if you can get. 337 00:17:49,201 --> 00:17:52,411 You know, obviously if it's encrypted, if it, you know, there's some scenarios 338 00:17:52,411 --> 00:17:56,431 where this doesn't work, but in many cases you're talking about putting 339 00:17:56,431 --> 00:18:01,441 those forensic images into a case in a forensic, uh, what would you call that? 340 00:18:01,441 --> 00:18:03,031 A discovery tool? 341 00:18:03,031 --> 00:18:03,511 What would you call it? 342 00:18:03,511 --> 00:18:06,991 Forensic analysis tool, right? 343 00:18:07,771 --> 00:18:09,331 Mike Saylor: Processing and analysis are 344 00:18:09,331 --> 00:18:10,261 the next couple of. 345 00:18:11,251 --> 00:18:14,101 W. Curtis Preston: And you can interact with those images and you can look at 346 00:18:14,101 --> 00:18:16,231 the files that are on those images. 347 00:18:16,816 --> 00:18:20,986 Without actually doing further risk by actually running those 348 00:18:20,986 --> 00:18:23,596 images as a, as a machine. 349 00:18:24,166 --> 00:18:27,796 Prasanna Malaiyandi: Or I think in addition, you could also, like, 350 00:18:27,826 --> 00:18:30,706 uh, Mike was saying you could run those images if you wanted to 351 00:18:30,706 --> 00:18:33,706 say, for instance, understand the interactions between those four network 352 00:18:34,036 --> 00:18:35,146 W. Curtis Preston: You Yeah. 353 00:18:35,236 --> 00:18:36,016 Prasanna Malaiyandi: talking about in a 354 00:18:36,021 --> 00:18:37,006 safe manner, right? 355 00:18:37,276 --> 00:18:37,666 W. Curtis Preston: yeah, you, 356 00:18:37,666 --> 00:18:38,296 can. 357 00:18:38,476 --> 00:18:41,176 I'm just saying you don't have to necessarily, depending 358 00:18:41,176 --> 00:18:42,556 on what you're, uh, and it 359 00:18:42,616 --> 00:18:43,546 Prasanna Malaiyandi: Trying to accomplish, 360 00:18:43,651 --> 00:18:45,661 W. Curtis Preston: occur to me until he was talking about putting them in 361 00:18:45,666 --> 00:18:48,211 a case in that, um, analysis tool. 362 00:18:49,066 --> 00:18:53,446 Mike Saylor: So imagine, imagine as an IT ops person, uh, you've got an issue 363 00:18:53,446 --> 00:18:58,186 with a, uh, a workstation and you've gotta go and, and interact with this. 364 00:18:58,186 --> 00:19:02,296 But be careful not to change anything while you're also searching for whatever 365 00:19:02,296 --> 00:19:07,156 it might be, a hash value, uh, reviewing logs to determine what happened in a 366 00:19:07,156 --> 00:19:12,286 period of time, uh, and then correlating those log entries to well, alright, 367 00:19:12,286 --> 00:19:14,206 so this, the log says this happened. 368 00:19:14,566 --> 00:19:19,396 Now let me go look in the, in all the file structure and do some, you know, power 369 00:19:19,396 --> 00:19:23,656 shell or whatever searches you're gonna do to see what correlates to that log entry. 370 00:19:24,046 --> 00:19:26,206 Imagine how much time that would take you 371 00:19:27,336 --> 00:19:27,696 W. Curtis Preston: Right. 372 00:19:27,856 --> 00:19:31,906 Mike Saylor: with forensics, I'm just going to image the whole machine and, 373 00:19:31,911 --> 00:19:35,356 and one thing I'll make clear too, there are different types of forensic imaging. 374 00:19:35,776 --> 00:19:37,636 There is whole disc imaging. 375 00:19:38,386 --> 00:19:39,796 And then there's targeted imaging. 376 00:19:39,886 --> 00:19:44,236 So maybe, uh, and this is important in like cloud and, and multi-tenant 377 00:19:44,236 --> 00:19:50,026 environments where I just want one VM or one piece of the vm because that's 378 00:19:50,026 --> 00:19:54,226 what my, my warrant allows me, or the scope of my investigation allows me. 379 00:19:54,231 --> 00:20:00,256 I can't go outside of that or shouldn't, but if, uh, if I do a, 380 00:20:00,256 --> 00:20:05,326 a bit for bit, you know, first bit to last bit physical image of a, of 381 00:20:05,326 --> 00:20:07,666 a drive or a of a, of a device, I. 382 00:20:07,966 --> 00:20:15,676 Um, the next step in forensics, uh, the forensics process is processing. 383 00:20:15,676 --> 00:20:16,966 It's also called indexing. 384 00:20:17,476 --> 00:20:23,236 So I'm using my forensic software to analyze every bit of data from start 385 00:20:23,236 --> 00:20:25,186 to finish, even the empty space. 386 00:20:25,486 --> 00:20:28,486 And it indexes that into, well, it creates an index. 387 00:20:28,816 --> 00:20:32,746 So for example, in, in my forensics tool, if I'm looking for the 388 00:20:32,746 --> 00:20:34,396 occurrence of the word apple. 389 00:20:35,326 --> 00:20:39,556 As I type the word apple, my results automatically in real time updates. 390 00:20:39,556 --> 00:20:46,276 So when I type the letter A, I've got 7 million results, and as I finish typing 391 00:20:46,276 --> 00:20:53,776 that word, it tells me specific to Apple, not just how many occurrences, 392 00:20:53,781 --> 00:20:55,516 but where in the entire dataset. 393 00:20:55,516 --> 00:20:58,366 I could have one computer, I could have a hundred, as long as they're 394 00:20:58,366 --> 00:21:02,356 part of the same case, it will give me results across all of the different 395 00:21:02,356 --> 00:21:04,066 data sets that I selected That. 396 00:21:04,591 --> 00:21:11,461 Query to hit, and then I can apply more, uh, criteria like, uh, the word 397 00:21:11,461 --> 00:21:18,031 apple specific to metadata related to a specific SID uh, or user, uh, within a 398 00:21:18,031 --> 00:21:22,531 period of time on a particular piece of evidence related to some other attribute. 399 00:21:22,681 --> 00:21:25,321 And so now you can see the power of that in real time. 400 00:21:25,321 --> 00:21:27,391 They call that a live or an index search. 401 00:21:27,391 --> 00:21:29,911 You can also do a live search while indexing is happening, 402 00:21:29,916 --> 00:21:30,991 but it slows stuff down. 403 00:21:31,501 --> 00:21:31,651 But I. 404 00:21:33,286 --> 00:21:37,336 It'll, it could take, depending on the size of the device, the, the storage. 405 00:21:37,426 --> 00:21:39,946 Uh, it could take a couple of hours to do the imaging. 406 00:21:40,276 --> 00:21:44,326 It could take another couple of hours to do the indexing and processing, 407 00:21:44,806 --> 00:21:48,046 but you could be doing other stuff while the machine's doing its thing. 408 00:21:48,076 --> 00:21:52,816 And then when you sit down to do your investigation, it's almost in real time. 409 00:21:53,416 --> 00:21:57,346 And it, some of the forensics tools now will do timelines for you. 410 00:21:57,616 --> 00:22:01,216 Uh, they'll extrapolate all the media images and, and I mean, you can, 411 00:22:01,366 --> 00:22:04,996 every, every attribute of data you can think of, you can search on and 412 00:22:04,996 --> 00:22:06,946 create, you know, complex queries on. 413 00:22:07,441 --> 00:22:07,651 W. Curtis Preston: So, 414 00:22:07,651 --> 00:22:13,921 let's, let's, let's talk about, um, some of the things that you, you know, again, 415 00:22:13,921 --> 00:22:15,601 talking about good, better, best, right? 416 00:22:16,291 --> 00:22:21,691 So if you're in the midst of a cyber attack, what. 417 00:22:22,681 --> 00:22:27,271 Are the things that you really have to make sure you don't 418 00:22:27,271 --> 00:22:29,221 lose, if at all possible? 419 00:22:29,371 --> 00:22:31,291 I'm thinking number one would be logs. 420 00:22:31,771 --> 00:22:36,781 Uh, obviously what we, what we want is a, is a forensic image of every 421 00:22:36,781 --> 00:22:41,581 machine that we think is, is, suspect that it, that it looks like it might 422 00:22:41,581 --> 00:22:43,471 have be involved in this attack. 423 00:22:43,711 --> 00:22:44,791 That's what we want. 424 00:22:45,391 --> 00:22:49,651 Is there, is there things that we should grab, like logs? 425 00:22:50,266 --> 00:22:55,156 Um, like the, the first thing that we grab to make sure that we, we get that. 426 00:22:55,246 --> 00:22:58,546 Um, is there stuff like that besides the logs? 427 00:22:59,596 --> 00:23:03,436 Mike Saylor: Certainly, and, and, and it, it may change from situation to situation, 428 00:23:03,436 --> 00:23:08,296 but preserving logs is paramount because one, as you guys probably know, a lot 429 00:23:08,296 --> 00:23:12,496 of environments don't have good log settings, so they're overwritten, uh, 430 00:23:12,556 --> 00:23:14,746 usually based off volume, not by. 431 00:23:15,236 --> 00:23:15,956 Age. 432 00:23:16,016 --> 00:23:19,706 And so in a cyber attack, you can imagine the volume of logs 433 00:23:19,706 --> 00:23:21,416 is gonna go up exponentially. 434 00:23:21,716 --> 00:23:25,976 So the likelihood that the, uh, the initial, the initialization of 435 00:23:25,976 --> 00:23:29,456 that attack, the logs related to that are preserved is, is small. 436 00:23:29,516 --> 00:23:33,026 If you don't catch it and preserve those, those, those logs timely. 437 00:23:33,506 --> 00:23:38,066 And we want every log we want firewall, router, switch, nas. 438 00:23:38,791 --> 00:23:43,411 Uh, everything you can think of from external to, you know, from the, from 439 00:23:43,411 --> 00:23:47,311 your perimeter all the way into these, uh, potentially compromised machines. 440 00:23:47,311 --> 00:23:53,791 We want all those logs, uh, even exchange, uh, or Office 365, all that stuff. 441 00:23:54,181 --> 00:23:59,761 Just you need, you need a, a log, uh, log preservation archiving, 442 00:23:59,821 --> 00:24:03,871 SOP that just says, when bad stuff happens, here's everything we need to 443 00:24:03,871 --> 00:24:05,701 preserve and where we're gonna put it. 444 00:24:06,091 --> 00:24:09,931 Which is also something to think about because if your network's compromised and 445 00:24:09,936 --> 00:24:13,051 you're gonna consolidate all these logs into a network location, well, bad guys 446 00:24:13,051 --> 00:24:16,441 could just, well, I'll just wait until they're done and delete all of that. 447 00:24:16,981 --> 00:24:18,511 Um, so there's, 448 00:24:18,511 --> 00:24:19,891 W. Curtis Preston: everything all in one place. 449 00:24:19,981 --> 00:24:21,421 Now let me blow that place up. 450 00:24:22,591 --> 00:24:24,211 Mike Saylor: Bad guys are lazy, I'm telling you. 451 00:24:24,661 --> 00:24:30,211 Um, but then also depending on, like, there's a, there was a big credit union 452 00:24:30,211 --> 00:24:35,911 hack, uh, compromised recently, and it was determined that the source of 453 00:24:35,911 --> 00:24:37,681 that attack came from a mobile phone. 454 00:24:38,311 --> 00:24:41,401 It was a, a network user that interacted with a. 455 00:24:42,031 --> 00:24:44,221 Uh, it was either a website or an email. 456 00:24:44,341 --> 00:24:48,781 Uh, is a, it was a, a no click malware that infected the phone. 457 00:24:48,841 --> 00:24:52,561 And then because the phone was on the production network, it was able to spread. 458 00:24:53,071 --> 00:24:57,331 Uh, who would've thought to go back and get an image of that phone 459 00:24:57,691 --> 00:24:57,931 Prasanna Malaiyandi: Yeah, 460 00:24:58,141 --> 00:24:58,921 Mike Saylor: or that tablet? 461 00:24:59,701 --> 00:25:01,681 Uh, so it does, it does. 462 00:25:02,371 --> 00:25:05,581 There are some nuances based on what the situation is, but 463 00:25:06,331 --> 00:25:09,751 fundamentally, you're right, Curtis, uh, preserving the logs is very 464 00:25:10,126 --> 00:25:12,406 W. Curtis Preston: Is there anything that's just beyond that? 465 00:25:14,311 --> 00:25:18,001 Mike Saylor: So you can go to your ISP 'cause they, they typically have some 466 00:25:18,001 --> 00:25:24,571 data, uh, depending on the, the service that you, uh, you subscribe to, uh, and 467 00:25:24,571 --> 00:25:30,031 your, your ISPs, uh, operating procedures, a lot of times they'll drop, they'll drop 468 00:25:30,031 --> 00:25:32,281 known bad traffic before it gets to you. 469 00:25:32,896 --> 00:25:34,756 Well then bad guys are just figuring that out. 470 00:25:34,756 --> 00:25:37,276 We're gonna try this, this, this, this, this, and this. 471 00:25:37,606 --> 00:25:41,836 Until we find the, the, the secret sauce or the recipe or, you know, whatever 472 00:25:41,836 --> 00:25:45,226 it is, that allows me to finally talk to the target, the victim network. 473 00:25:45,826 --> 00:25:51,496 Uh, and so the ISP may have some log data that predates, uh, the actual attack. 474 00:25:51,501 --> 00:25:55,756 And that could be important 'cause you'll see bad guys change IP addresses and, and 475 00:25:55,761 --> 00:25:57,586 uh, and hosts and all that good stuff. 476 00:25:57,646 --> 00:26:00,376 Uh, so that, that's, that's valuable information too, to. 477 00:26:01,036 --> 00:26:03,736 Uh, potentially block future attacks. 478 00:26:04,186 --> 00:26:10,816 Um, the other, the other areas to consider too, um, is, is who do you outsource 479 00:26:10,816 --> 00:26:12,856 or rely on from a service perspective? 480 00:26:12,856 --> 00:26:16,036 If you outsource, you know, your firewall management, uh, if you 481 00:26:16,036 --> 00:26:19,366 outsource your backups, if you outsource, if you have cloud environments 482 00:26:19,366 --> 00:26:23,506 and, uh, you have, uh, service providers that help you with those. 483 00:26:23,881 --> 00:26:27,811 Uh, if you have an it, if you have an MSP that helps, you know, does your, your 484 00:26:27,811 --> 00:26:31,921 help desk and some other, those, uh, some of those other services, that's gotta 485 00:26:31,921 --> 00:26:33,661 be part of your incident response plan. 486 00:26:33,781 --> 00:26:35,161 You know, not just preserving logs. 487 00:26:35,166 --> 00:26:38,431 And sometimes you may have to call those, those partners and service 488 00:26:38,431 --> 00:26:40,261 providers to get those logs archived. 489 00:26:40,261 --> 00:26:44,161 But again, you know, part of incident response is having all that figured out 490 00:26:44,161 --> 00:26:46,291 today, uh, before bad stuff happens. 491 00:26:46,291 --> 00:26:48,451 So you've got a, a good, a good playbook to 492 00:26:48,451 --> 00:26:49,291 run to run. 493 00:26:49,846 --> 00:26:51,346 Prasanna Malaiyandi: Is there, a recommendation? 494 00:26:51,346 --> 00:26:54,586 So I know you've talked about how logs are super important in all of this. 495 00:26:55,096 --> 00:26:59,236 Is there a recommendation on how long, I know you talked about sometimes people 496 00:26:59,236 --> 00:27:04,247 do more volume-based than date-based for keeping logs, but is there sort of like. 497 00:27:05,326 --> 00:27:08,656 A recommended practice in terms of how long they should keep their logs. 498 00:27:08,656 --> 00:27:11,956 'cause speaking from the privacy side, which I'm very interested in, right, 499 00:27:11,956 --> 00:27:16,096 there's sort of the downside of keeping too much data for too long, right? 500 00:27:16,366 --> 00:27:20,056 Versus uh, not having enough data so you can do these incident 501 00:27:20,056 --> 00:27:21,766 responses and where's that balance? 502 00:27:22,411 --> 00:27:24,391 Mike Saylor: There's a couple of parts to my answer there, and 503 00:27:24,391 --> 00:27:30,751 the first, the fundamental, uh, response is making sure your logs 504 00:27:30,751 --> 00:27:33,871 are configured, uh, appropriately. 505 00:27:34,591 --> 00:27:37,801 So our, we, we call that the value of your log data. 506 00:27:37,951 --> 00:27:40,831 So what's the value of the information your logs are collecting? 507 00:27:41,911 --> 00:27:44,401 Um, and that value could be business related. 508 00:27:44,401 --> 00:27:47,671 So when we review a log, we, we always ask, why are you logging that? 509 00:27:47,671 --> 00:27:49,561 Well, because we use it for X, Y, and Z. 510 00:27:49,591 --> 00:27:50,041 Okay? 511 00:27:50,161 --> 00:27:53,581 Uh, but if it's, if it's just a, I don't know, someone set, set it up 512 00:27:53,581 --> 00:27:55,531 that way, I'm not sure why we do that. 513 00:27:55,981 --> 00:28:00,571 Uh, so let's, let's have a conversation about in improving the value of your logs. 514 00:28:00,631 --> 00:28:03,661 So there's one thing, and that could reduce the size of logs, it 515 00:28:03,661 --> 00:28:06,601 could expand the size of logs, but nonetheless, it's more valuable. 516 00:28:07,321 --> 00:28:12,061 And that's both from a, like a, a, a detection perspective, 517 00:28:12,541 --> 00:28:13,891 uh, but also incident response. 518 00:28:13,891 --> 00:28:16,771 So, uh, logs are important for a lot of reasons. 519 00:28:17,221 --> 00:28:21,661 Uh, and then some regulatory, um, situations. 520 00:28:21,661 --> 00:28:22,021 Logs are 521 00:28:22,021 --> 00:28:24,571 required simply because of the business you're in, like 522 00:28:24,576 --> 00:28:26,671 financial, the financial sector. 523 00:28:26,671 --> 00:28:29,401 So making sure your logs are valuable is step one. 524 00:28:30,031 --> 00:28:31,771 Uh, and that could then dictate. 525 00:28:32,311 --> 00:28:36,061 How long you keep them based on the, the resulting log 526 00:28:36,061 --> 00:28:36,571 size. 527 00:28:37,321 --> 00:28:41,611 But ideally, you want, you want whatever that host is. 528 00:28:43,006 --> 00:28:47,446 Creating the logs, you want something else to collect that log from the host. 529 00:28:47,446 --> 00:28:50,626 So if the host is impacted, you're not worried about the logs on the host. 530 00:28:50,626 --> 00:28:51,466 They've already been sent 531 00:28:51,466 --> 00:28:54,106 somewhere else, like a SIS log server. 532 00:28:54,556 --> 00:28:58,696 Um, that, I mean, sis log servers are Kiwi servers, I think they used to be called. 533 00:28:59,056 --> 00:29:00,586 Uh, you can do some cool stuff with those. 534 00:29:00,591 --> 00:29:03,166 You can write rules and have 'em, you know, email you or 535 00:29:03,226 --> 00:29:04,426 paid you back in the day. 536 00:29:04,816 --> 00:29:10,846 Uh, but good, better, best, best would be let's have all the. 537 00:29:11,146 --> 00:29:11,206 the. 538 00:29:11,776 --> 00:29:16,756 The, the good log sources, the good data sources, let's ingest those into 539 00:29:16,756 --> 00:29:18,856 a true sim like security incident, 540 00:29:18,856 --> 00:29:23,566 event management platform that can run analytics 24 hours a day and do some 541 00:29:23,566 --> 00:29:28,306 better, cooler, more effective stuff, while also giving us good visibility 542 00:29:28,306 --> 00:29:32,326 across the environment, both east and west and, you know, uh, within the environment, 543 00:29:32,326 --> 00:29:33,676 north, south, in and out of the 544 00:29:33,711 --> 00:29:34,031 environment. 545 00:29:34,396 --> 00:29:36,946 W. Curtis Preston: and also by doing that, you. 546 00:29:37,546 --> 00:29:42,226 Um, you know, if you, if you did it right, I would think you would also provide a 547 00:29:42,226 --> 00:29:48,256 separation so that those logs are not as easily accessible by the bad guys, right. 548 00:29:48,706 --> 00:29:49,576 Um, right. 549 00:29:49,576 --> 00:29:51,226 having having them all in one place. 550 00:29:51,376 --> 00:29:53,836 I like the idea of having a, a Sims o tool. 551 00:29:54,251 --> 00:29:58,871 Look at it, um, and look at these logs on a regular basis to say, Hey, 552 00:29:58,871 --> 00:29:59,921 there's something going on here. 553 00:29:59,921 --> 00:30:01,091 You might want to take a look. 554 00:30:01,091 --> 00:30:01,301 Right. 555 00:30:01,301 --> 00:30:05,201 It'd be nice to be notified of, of something suspicious. 556 00:30:05,621 --> 00:30:11,291 Um, you know, versus that, and this is, I I think one of the recurring themes that 557 00:30:11,296 --> 00:30:16,781 we're we're going here is there are things that you really need to do in advance. 558 00:30:18,346 --> 00:30:22,006 So, you know, la last call we talked about assume breach, right? 559 00:30:22,156 --> 00:30:24,316 At some point you're going to be breached. 560 00:30:24,316 --> 00:30:26,116 You need to be prepared for that. 561 00:30:26,566 --> 00:30:31,036 And so one of the things that we're talking about is be prepared to do 562 00:30:31,036 --> 00:30:36,706 forensic images, be but be prepared, uh, to, to separate these logs, right? 563 00:30:36,946 --> 00:30:39,406 You know, like you talked about, like having a Syslog server, 564 00:30:39,586 --> 00:30:41,206 having a centralized log. 565 00:30:41,986 --> 00:30:43,726 Uh, management system. 566 00:30:43,996 --> 00:30:48,496 And then I do like the idea of, of that, you know, the best would be putting 567 00:30:48,496 --> 00:30:52,816 that into an actual, uh, like a sim sort tool that's gonna actually analyze that. 568 00:30:53,536 --> 00:30:54,076 Um. 569 00:30:54,631 --> 00:30:58,261 So let's go back to the, to the, to the, to the imaging. 570 00:30:58,261 --> 00:31:02,011 I, I, I completely agree with you that the tool, many of the tools, they're 571 00:31:02,011 --> 00:31:07,291 using the same techniques that we used back in the day to do what we used 572 00:31:07,291 --> 00:31:10,531 to call bare metal recovery, right. 573 00:31:10,621 --> 00:31:14,371 Um, a hundred years ago, before everything was virtualized, the idea 574 00:31:14,371 --> 00:31:19,501 of being able to restore a server from bare metal was a thing that we tried 575 00:31:19,501 --> 00:31:22,891 to do, uh, and that required an image. 576 00:31:23,176 --> 00:31:23,596 Right. 577 00:31:23,686 --> 00:31:26,566 That's when we talk about forensic imaging, all we're talking about 578 00:31:26,566 --> 00:31:30,406 essentially is, you know, an image that's typically a, a level 579 00:31:30,406 --> 00:31:32,566 below the file system, right? 580 00:31:32,566 --> 00:31:37,216 This isn't just a, a file system backup, which is generally all we take now. 581 00:31:37,546 --> 00:31:39,316 Uh, well, I'll, I'll back that up. 582 00:31:39,526 --> 00:31:44,896 In the virtualized world, we also take, um, images, we, we've, we've figured out 583 00:31:44,896 --> 00:31:47,356 how to do backups at the image level. 584 00:31:48,091 --> 00:31:51,631 While being able to do file level recovery, which is a beautiful thing. 585 00:31:51,841 --> 00:31:52,261 Right. 586 00:31:52,411 --> 00:31:58,291 Um, and so I would think that having this is yet another advantage of having 587 00:31:58,296 --> 00:32:02,701 a fully virtualized environment is forensic imaging, I think is a lot easier 588 00:32:02,706 --> 00:32:04,501 to do in the, in the virtual world. 589 00:32:05,491 --> 00:32:11,371 Um, what are the, some of the tools that you run into out there are, there are, 590 00:32:11,461 --> 00:32:14,581 are there really common ones that you see or is it just all over the board? 591 00:32:16,126 --> 00:32:19,546 Mike Saylor: So there's, there are common ones depending on what 592 00:32:19,551 --> 00:32:22,696 the, um, the source device is. 593 00:32:23,231 --> 00:32:23,471 W. Curtis Preston: Right. 594 00:32:23,761 --> 00:32:27,121 Mike Saylor: So if you're talking and, and really today there's, there's 595 00:32:27,121 --> 00:32:30,591 two, there's two forensic disciplines. 596 00:32:30,831 --> 00:32:35,451 There's traditional forensics, which really continues to follow 597 00:32:35,451 --> 00:32:40,131 and is very rigid on forensic, um, process and principles. 598 00:32:40,161 --> 00:32:41,871 Like you, you don't touch the data. 599 00:32:41,871 --> 00:32:43,101 If it's off, you leave it off. 600 00:32:43,101 --> 00:32:44,781 If it's on you leave it on, 601 00:32:45,291 --> 00:32:47,751 um, you handle it in a certain way. 602 00:32:47,901 --> 00:32:49,611 W. Curtis Preston: And, and that's pro, sorry to interrupt you, but 603 00:32:49,611 --> 00:32:55,911 that's probably more focused on like lawsuits and things like that, right? 604 00:32:56,181 --> 00:32:58,701 Is that, am I correct that particular discipline? 605 00:33:00,051 --> 00:33:04,191 Mike Saylor: It, it well that, that discipline is focused on traditional 606 00:33:04,191 --> 00:33:06,411 computers like laptop servers, 607 00:33:06,411 --> 00:33:08,781 workstations, things that have hard drives, 608 00:33:09,096 --> 00:33:09,576 W. Curtis Preston: Okay. 609 00:33:10,311 --> 00:33:12,411 Mike Saylor: and Linux, Unix, 610 00:33:12,771 --> 00:33:15,171 Mac and Windows operating systems. 611 00:33:16,011 --> 00:33:16,551 Um. 612 00:33:17,976 --> 00:33:22,326 So that, that, that traditional forensics, the, the procedures that 613 00:33:22,326 --> 00:33:29,466 you follow are possible because of that traditional hardware. 614 00:33:30,726 --> 00:33:37,206 When you, when you compare that then to a mobile device like an iPhone, you cannot 615 00:33:37,211 --> 00:33:39,216 image an iPhone when it's turned off. 616 00:33:40,056 --> 00:33:45,366 You cannot image an iPhone in some cases by itself, iPhones and some, some of 617 00:33:45,366 --> 00:33:49,656 these mobile devices, smartphones, they have to be mounted in order to be imaged. 618 00:33:50,046 --> 00:33:53,406 Well, you've already violated the traditional forensic principles 619 00:33:53,406 --> 00:33:54,846 of do not modify the data. 620 00:33:55,296 --> 00:34:00,486 Well, I've just mount You had to mount it in order to, to get access to the device. 621 00:34:01,086 --> 00:34:05,046 So a lot of, when, when mobile forensics first came out years 622 00:34:05,046 --> 00:34:09,156 ago, the, the discipline, it was, uh, it was, it was, uh. 623 00:34:09,726 --> 00:34:14,016 Argued very heavily that it shouldn't be called forensics because it doesn't 624 00:34:14,016 --> 00:34:15,366 follow the traditional forensic 625 00:34:15,516 --> 00:34:16,296 W. Curtis Preston: Oh, interesting. 626 00:34:17,286 --> 00:34:21,666 Mike Saylor: Um, however, going back to best evidence when mobile 627 00:34:21,666 --> 00:34:23,316 data made its way to court. 628 00:34:23,751 --> 00:34:26,721 And opposing counsel started to argue, well, it didn't 629 00:34:26,721 --> 00:34:28,161 follow forensics principles. 630 00:34:28,166 --> 00:34:32,151 We were able then to fall back to, well, best evidence, this is the only 631 00:34:32,151 --> 00:34:33,921 way to get data out of this phone. 632 00:34:34,461 --> 00:34:39,081 And so the what you, what you do to make up the difference is good note taking. 633 00:34:39,411 --> 00:34:43,251 I did this on this data time, so when you see that in the mobile device 634 00:34:43,251 --> 00:34:47,151 evidence, you know, that was me and I was diligent in taking those notes. 635 00:34:47,331 --> 00:34:49,281 So, to, to answer your question. 636 00:34:50,451 --> 00:34:53,961 Traditional forensics has its own tool set, and there are 637 00:34:53,991 --> 00:34:56,751 industry leaders, uh, access data. 638 00:34:57,111 --> 00:34:58,911 Uh, I can't remember the name of their company. 639 00:34:58,916 --> 00:35:01,881 It was just acquired, uh, maybe in the last year or two. 640 00:35:02,481 --> 00:35:06,411 Uh, but Access Data was the name of the company, and the product was 641 00:35:06,411 --> 00:35:08,961 called Forensics Toolkit or FTK. 642 00:35:10,076 --> 00:35:14,391 And FTK was most heavily used by law enforcement because of the, of 643 00:35:14,391 --> 00:35:18,591 the, of Access data's willingness to customize and let them do things 644 00:35:18,596 --> 00:35:22,701 that they needed to do to support, you know, law enforcement activities. 645 00:35:23,211 --> 00:35:23,511 Well, that 646 00:35:23,766 --> 00:35:25,596 Prasanna Malaiyandi: comp, oh, sorry. 647 00:35:25,596 --> 00:35:28,506 I was just gonna chime in, Mike, that that company is now owned by Xero, 648 00:35:29,346 --> 00:35:29,766 Mike Saylor: ero Yep. 649 00:35:30,066 --> 00:35:31,086 Prasanna Malaiyandi: which does e-discovery. 650 00:35:32,391 --> 00:35:35,061 Mike Saylor: And, and that was a, a brilliant move on their part. 651 00:35:35,481 --> 00:35:42,081 Uh, the other competitor is, is guidance software and they make, um, their 652 00:35:42,081 --> 00:35:46,251 own, um, their own forensics tools. 653 00:35:46,341 --> 00:35:52,791 Uh, and interestingly enough, uh, guidance software is most heavily used by law firms 654 00:35:52,851 --> 00:35:57,471 and, uh, legal, uh, legal specializations. 655 00:35:58,041 --> 00:35:59,031 And even though. 656 00:35:59,916 --> 00:36:02,646 FTK is more heavily deployed around the world. 657 00:36:02,976 --> 00:36:08,196 Uh, guidance is the one that set the standard for how forensic imaging, 658 00:36:08,316 --> 00:36:12,636 uh, formats, uh, were, were expected. 659 00:36:12,636 --> 00:36:14,466 They call it the EO one format. 660 00:36:15,126 --> 00:36:15,336 Um. 661 00:36:16,866 --> 00:36:21,186 And, and guidance software's, tools called nk, E-N-C-A-S-E. 662 00:36:21,846 --> 00:36:25,896 And so NK or, or, and that's where the e comes from in the, in the, 663 00:36:25,961 --> 00:36:27,846 in the file extension, EO one. 664 00:36:28,296 --> 00:36:32,316 But most forensic software today, the imagers will, you, you've 665 00:36:32,316 --> 00:36:36,546 got the option to, to select what format you want your image in. 666 00:36:36,546 --> 00:36:39,426 It could be dd, it could be raw, it could be E oh one. 667 00:36:39,996 --> 00:36:44,256 Uh, and then on the flip side of that, so I could, I could make an image with FTK. 668 00:36:44,541 --> 00:36:48,351 And not have a problem importing and analyzing that image in NK, 669 00:36:48,471 --> 00:36:49,911 as an example, or vice versa. 670 00:36:50,361 --> 00:36:51,351 So that's traditional. 671 00:36:51,411 --> 00:36:57,501 Well, then you get to mobile forensics and the, the, the, the field of, of 672 00:36:57,501 --> 00:37:00,051 vendors and tools out there just blew up. 673 00:37:00,051 --> 00:37:03,321 There's, you know, black bag and oxygen and paraben and 674 00:37:03,321 --> 00:37:04,821 cellebrite, which you probably 675 00:37:05,181 --> 00:37:05,751 hear a lot. 676 00:37:06,031 --> 00:37:06,321 Prasanna Malaiyandi: Yeah. 677 00:37:06,996 --> 00:37:09,726 Mike Saylor: As far as getting into stuff, and they're, they're probably on the 678 00:37:09,726 --> 00:37:13,056 leading edge of, of, uh, mobile forensics. 679 00:37:13,146 --> 00:37:17,496 Um, they're, they're always able to do whatever the next best thing is, 680 00:37:18,156 --> 00:37:19,806 uh, and all of these things. 681 00:37:20,106 --> 00:37:23,316 Now, traditional forensics, the pricing is pretty similar. 682 00:37:24,216 --> 00:37:28,116 The licensing models are pretty similar when you get into mobile forensics. 683 00:37:28,821 --> 00:37:30,321 It can be very specific. 684 00:37:30,321 --> 00:37:34,851 Like I just want a tool that tells me that extracts all the chat messages and media. 685 00:37:34,881 --> 00:37:35,781 That's all I want. 686 00:37:35,961 --> 00:37:38,121 Very low cost, but that's all it does. 687 00:37:38,691 --> 00:37:42,051 Then you've got tools that, like Cellebrite that run the gamut 688 00:37:42,081 --> 00:37:45,141 and they have access to every phone, all the way back to the, 689 00:37:45,561 --> 00:37:47,601 the car phones of the eighties. 690 00:37:48,051 --> 00:37:52,551 Uh, and, and, and other stuff like, I need data out of a Nest thermostat 691 00:37:52,611 --> 00:37:55,071 or a wireless, uh, microwave. 692 00:37:55,101 --> 00:37:57,471 You know, there's it, the, the, 693 00:37:57,476 --> 00:37:58,131 scope. 694 00:37:59,091 --> 00:38:03,981 Capabilities, uh, vary widely as well as the the price and licensing. 695 00:38:04,086 --> 00:38:06,576 W. Curtis Preston: Yeah, I know my employer uses Cellebrite quite a bit. 696 00:38:07,116 --> 00:38:09,306 when, when when grabbing, uh, images from phones. 697 00:38:09,876 --> 00:38:10,476 Um. 698 00:38:10,491 --> 00:38:13,281 Mike Saylor: you can, you can get trained and certified in, in all 699 00:38:13,286 --> 00:38:17,511 of those tools like paraben and Cellebrite, uh, certified in that thing. 700 00:38:17,751 --> 00:38:22,881 Um, but much like other disciplines in it, you kind of become a one trick pony. 701 00:38:23,061 --> 00:38:23,901 Like that's all I can do. 702 00:38:24,996 --> 00:38:27,126 Uh, and the same with traditional forensics. 703 00:38:27,126 --> 00:38:28,776 They have certifications for that. 704 00:38:29,226 --> 00:38:34,416 Um, but to become a general forensics practitioner, man, it's, it's 705 00:38:34,416 --> 00:38:39,366 like, uh, it, it's like a lot of different, um, like trades type 706 00:38:39,866 --> 00:38:40,086 Prasanna Malaiyandi: Yes, 707 00:38:40,156 --> 00:38:40,546 W. Curtis Preston: Yeah, 708 00:38:40,566 --> 00:38:41,016 Mike Saylor: job. 709 00:38:41,136 --> 00:38:42,816 You've just gotta, you've gotta live it for 710 00:38:42,816 --> 00:38:43,656 a period of time to 711 00:38:43,656 --> 00:38:44,106 really. 712 00:38:44,901 --> 00:38:47,271 Prasanna Malaiyandi: so basically people like me who get all their 713 00:38:47,271 --> 00:38:50,451 knowledge from YouTube will not succeed in doing forensics. 714 00:38:52,336 --> 00:38:54,136 W. Curtis Preston: You might succeed, but you might have trouble if 715 00:38:54,141 --> 00:38:56,446 you're in some sort of court of law. 716 00:38:56,446 --> 00:38:56,536 Right. 717 00:38:56,536 --> 00:38:57,016 Um. 718 00:38:57,201 --> 00:39:01,191 Mike Saylor: A YouTube video long enough to to give you the 719 00:39:01,191 --> 00:39:03,891 exposure you need for just one 720 00:39:04,176 --> 00:39:06,936 W. Curtis Preston: Yeah, so, so it sounds like, you know, like, like the 721 00:39:06,936 --> 00:39:10,391 other things we've been talking about, this is yet another discipline where. 722 00:39:11,211 --> 00:39:15,471 If you're in the midst of the fire, this is why going back to the previous 723 00:39:15,471 --> 00:39:20,961 episode, you need to, in advance of the fire, get a relationship with a company, 724 00:39:21,531 --> 00:39:23,901 perhaps via your cyber insurance carrier. 725 00:39:24,111 --> 00:39:28,161 Get a relationship with a company that does know this stuff cold so 726 00:39:28,161 --> 00:39:30,801 that they know how, they know what they need to take an image of. 727 00:39:30,951 --> 00:39:33,981 They know how to take that image and they, they know how to do it in such a 728 00:39:33,981 --> 00:39:38,871 way that they get the evidence that they need, uh, without changing the evidence. 729 00:39:39,186 --> 00:39:43,446 And they also know how to manipulate and look at that evidence without, 730 00:39:43,956 --> 00:39:46,956 uh, you know, making the fire worse. 731 00:39:47,106 --> 00:39:48,096 Um, does that sound 732 00:39:48,096 --> 00:39:49,506 like a good summary there? 733 00:39:50,206 --> 00:39:50,426 Mike Saylor: it 734 00:39:50,431 --> 00:39:50,821 does. 735 00:39:50,821 --> 00:39:55,261 And if I could add one more thing that would just enhance the value 736 00:39:55,261 --> 00:39:56,521 of everything you just said. 737 00:39:57,126 --> 00:40:00,936 Is every organization needs to sit through what's called a business impact 738 00:40:00,936 --> 00:40:06,336 analysis and figure out where all those key critical, you know, secret sauce, 739 00:40:06,366 --> 00:40:11,646 jewels of the company are so that when something bad happens, we know 740 00:40:11,651 --> 00:40:13,476 what the bad guys are probably after. 741 00:40:13,481 --> 00:40:16,716 Or at least we know the specifics around all that stuff so that 742 00:40:16,716 --> 00:40:19,926 we're not having to figure it out on, on, your worst day. 743 00:40:20,286 --> 00:40:24,336 Um, and then I think there are a couple of things that, that. 744 00:40:24,651 --> 00:40:29,631 Organizations can document as far as like good first steps in, in helping 745 00:40:29,781 --> 00:40:31,821 preserve evidence in an incident response. 746 00:40:31,821 --> 00:40:34,401 Preserving logs are critical. 747 00:40:34,731 --> 00:40:42,021 Um, but being trained on some forensic acquisition tools like the FTK, uh, 748 00:40:42,021 --> 00:40:47,586 imager, which is free, and having a maybe a small inventory of extra drives that 749 00:40:47,591 --> 00:40:49,761 you can, you can preserve evidence to. 750 00:40:50,181 --> 00:40:54,081 Uh, that stuff, you can write a procedure and it's no different than 751 00:40:54,141 --> 00:40:56,091 like a backup or recovery procedure. 752 00:40:56,091 --> 00:41:00,021 It's just do these things and maybe there might be some decision trees here and 753 00:41:00,021 --> 00:41:04,311 there, but I've written, I've written several, like incident response forensics 754 00:41:04,341 --> 00:41:08,391 kit procedures and, and toolkits for, for clients around the world so that 755 00:41:08,391 --> 00:41:10,821 they can preserve that evidence before I, 756 00:41:11,121 --> 00:41:13,371 before I, you know, it takes me to get there. 757 00:41:13,401 --> 00:41:15,291 Prasanna Malaiyandi: was, The last thing you want, right, Mike? 758 00:41:15,291 --> 00:41:19,131 Based on what you said is like an IT person freaking out that this has 759 00:41:19,131 --> 00:41:22,581 hit and being like, oh, I just need to recover my machines and going 760 00:41:22,581 --> 00:41:24,321 and formatting the drives and then 761 00:41:24,321 --> 00:41:25,041 just starting over. 762 00:41:25,041 --> 00:41:25,371 Right. 763 00:41:25,401 --> 00:41:27,561 That's like literally the last thing that you want. 764 00:41:28,911 --> 00:41:30,951 Mike Saylor: That's right, because now you don't know how it happened. 765 00:41:31,251 --> 00:41:32,901 W. Curtis Preston: So I, I like what you're talking about, Mike. 766 00:41:33,021 --> 00:41:35,451 There's nothing wrong with, with learning some of that stuff, 767 00:41:35,451 --> 00:41:40,221 learning what you can do to support a forensic team that's coming in. 768 00:41:40,821 --> 00:41:43,791 I, I, I do wanna just emphasize, learn, right? 769 00:41:43,791 --> 00:41:46,581 Make sure you're learning it from somebody who says, okay, I. 770 00:41:46,956 --> 00:41:48,516 We're, we're gonna be your team. 771 00:41:48,516 --> 00:41:49,266 We're gonna come in. 772 00:41:49,326 --> 00:41:53,976 Here's what you can learn how to do on your own to support us. 773 00:41:54,276 --> 00:41:54,666 Right? 774 00:41:54,726 --> 00:41:56,226 And here's what not to do. 775 00:41:56,586 --> 00:41:57,006 Right. 776 00:41:57,006 --> 00:41:59,646 Please don't just go shut all the machines down, for example. 777 00:41:59,646 --> 00:42:01,596 We want to get it for, you know, we wanna see if we can get an 778 00:42:01,596 --> 00:42:03,246 image of that memory right. 779 00:42:03,306 --> 00:42:07,416 Um, because that's, that was what I would think would be the first step is literally 780 00:42:07,416 --> 00:42:08,916 just going, powering everything off. 781 00:42:08,916 --> 00:42:09,246 Right. 782 00:42:09,726 --> 00:42:09,947 Mike Saylor: It depends. 783 00:42:10,461 --> 00:42:11,306 If it's, if it's 784 00:42:11,311 --> 00:42:13,371 ransomware, call the plug. 785 00:42:14,436 --> 00:42:17,226 W. Curtis Preston: Uh, and so you have those conversations in advance. 786 00:42:17,226 --> 00:42:20,736 Figure out what it is that you should be doing, uh, to support that team and then 787 00:42:20,736 --> 00:42:22,686 get that team in as quickly as possible. 788 00:42:22,986 --> 00:42:27,756 Well, um, uh, I think, I think we beat this topic to death enough. 789 00:42:28,026 --> 00:42:30,396 Uh, thanks again for, uh, your help, Mike. 790 00:42:31,671 --> 00:42:33,831 Mike Saylor: Certainly, and there are, there are some intro courses 791 00:42:33,831 --> 00:42:38,811 to forensics, uh, that are part of, uh, continuing education programs. 792 00:42:39,336 --> 00:42:40,866 Uh, or degree programs. 793 00:42:40,896 --> 00:42:46,386 Uh, I teach, uh, intro to Forensics, uh, and investigations for UT San Antonio. 794 00:42:46,926 --> 00:42:49,866 Uh, it's a, it's a 700 page textbook. 795 00:42:50,376 --> 00:42:54,246 Uh, but there, there's some parts of this that are more related to 796 00:42:54,251 --> 00:42:58,326 law enforcement and criminal justice degrees that we don't focus so much on. 797 00:42:58,326 --> 00:43:02,526 But it's a great, uh, great insight into some of the elements of 798 00:43:02,526 --> 00:43:04,146 forensics that are important to know. 799 00:43:04,206 --> 00:43:05,136 If you do wanna. 800 00:43:05,751 --> 00:43:09,261 Run a, you know, clone a drive or, or do an image to preserve data 801 00:43:09,261 --> 00:43:10,971 and, and how that data can be used. 802 00:43:11,796 --> 00:43:12,306 W. Curtis Preston: I like it. 803 00:43:12,396 --> 00:43:14,136 Well, thanks, uh, thanks for coming on 804 00:43:15,021 --> 00:43:16,311 Mike Saylor: Certainly anytime I. 805 00:43:16,956 --> 00:43:19,476 W. Curtis Preston: and Prasanna, thanks again for, you know, consoling me 806 00:43:19,476 --> 00:43:23,016 in the midst of my power attack and also asking great questions as usual. 807 00:43:23,541 --> 00:43:26,961 Prasanna Malaiyandi: I try and, yeah, hopefully they realize maybe they 808 00:43:26,961 --> 00:43:29,331 should think about battery backups, 809 00:43:29,871 --> 00:43:31,791 W. Curtis Preston: Well, they had it, it just, it was, the power 810 00:43:31,791 --> 00:43:35,751 outage was long enough that it exceeded the, uh, the backups. 811 00:43:35,846 --> 00:43:37,221 Prasanna Malaiyandi: they just need to expand it. 812 00:43:37,671 --> 00:43:38,781 Mike Saylor: They didn't consider 813 00:43:38,901 --> 00:43:40,041 how long of a battery 814 00:43:40,041 --> 00:43:40,581 they needed. 815 00:43:40,581 --> 00:43:40,821 W. Curtis Preston: Yeah. 816 00:43:41,031 --> 00:43:44,031 apparently, apparently longer than four hours. 817 00:43:44,451 --> 00:43:45,831 Uh, anyway. 818 00:43:45,921 --> 00:43:46,281 All right. 819 00:43:46,281 --> 00:43:47,931 Well, thanks to the listeners. 820 00:43:47,961 --> 00:43:49,461 Uh, we'd be nothing without you. 821 00:43:49,641 --> 00:43:50,446 That is a wrap. 822 00:43:53,326 --> 00:43:58,036 The backup wrap up is written, recorded and produced by me w Curtis Preston. 823 00:43:58,606 --> 00:44:00,076 If you need backup or Dr. 824 00:44:00,076 --> 00:44:03,706 Consulting content generation or expert witness work, 825 00:44:04,006 --> 00:44:05,956 check out backup central.com. 826 00:44:06,706 --> 00:44:09,826 You can also find links from my O'Reilly Books on the same website. 827 00:44:10,486 --> 00:44:14,566 Remember, this is an independent podcast and any opinions that you 828 00:44:14,566 --> 00:44:16,486 hear are those of the speaker. 829 00:44:16,551 --> 00:44:18,411 And not necessarily an employer. 830 00:44:19,311 --> 00:44:20,031 Thanks for listening.