informa
/
Risk
Commentary

IR/Forensic Favorites Get Streamlined

A couple of my favorite incident response and forensic tools were recently updated with some great new features to help streamline their use. The first two tools are from Mandiant and work hand-in-hand, Memoryze and Audit Viewer. If you've not used Memoryze yet, it deserves your attention. I've found it to be extremely useful in incident response situations dealing with malware.
A couple of my favorite incident response and forensic tools were recently updated with some great new features to help streamline their use. The first two tools are from Mandiant and work hand-in-hand, Memoryze and Audit Viewer. If you've not used Memoryze yet, it deserves your attention. I've found it to be extremely useful in incident response situations dealing with malware.For example, I received a call yesterday from someone who was browsing the Internet when the Windows Security Center notified him that the firewall was turned off because of Win32.Zafi.B. After scanning his system with McAfee VirusScan, one DLL was identified as being infected and the logs said the file was deleted even though it was still on the drive. I tried manually deleting the DLL and an EXE in the same directory but was denied with a message they were in use.

Analysis of the Windows Registry and current processes didn't turn up anything related to the two files, so I imaged the memory using Memoryze v1.3.0. On a separate machine, I used the new Memoryze Launcher included with Audit Viewer v1.0.0.8 to perform an audit of processes, handles, injected DLLs and hooks that may indicate a rootkit.

Sure enough. In the output of processes and handles, I found both the EXE and DLL in memory providing evidence that the machine was indeed infected. What I want to draw attention to is the easy-to-use interface the included Memoryze Launcher now provides. It allows you to specify the audits you want to run, set their different options and automatically loads the results in Audit Viewer when it is complete. Great job by Peter Silberman of Mandiant on this update to Audit Viewer.

F-Response, one of my other favorite tools, was also just given a nice GUI that also streamlines the process of connected to remote machines for analysis. Both the Enterprise and Consultant versions were updated with similar enhancements. Previously, I had to manually add hosts and their disk drives within the Microsoft iSCSI Initiator, but not anymore. It's now as easy as the click of a few buttons and the disks are ready for remote, read-only analysis.

The common theme in these updates seems to be enabling the investigator to do his or her job faster by getting to the data quicker without going through cumbersome steps that could lead to user error. This is incredibly important in the IR/forensics world. Take the tools for a spin and let me know what you think.

John H. Sawyer is a senior security engineer on the IT Security Team at the University of Florida. The views and opinions expressed in this blog are his own and do not represent the views and opinions of the UF IT Security Team or the University of Florida. When John's not fighting flaming, malware-infested machines or performing autopsies on blitzed boxes, he can usually be found hanging with his family, bouncing a baby on one knee and balancing a laptop on the other. Special to Dark Reading.

Recommended Reading:
Editors' Choice
Kirsten Powell, Senior Manager for Security & Risk Management at Adobe
Joshua Goldfarb, Director of Product Management at F5