
ããŒã¿ãªãŒã¯ã¯ã»ãŒæ¯æ¥çºçããŸãã
ããŒã¿æŒæŽ©ã€ã³ããã¯ã¹ã«ãããš
ã 2013幎以éã
4,762,376,960件ã
è¶
ããã¬ã³ãŒãã倱ããããçãŸããŸããã

æ倧ã®ããŒã¿ãªãŒã¯ã¯æ¬¡ã®å Žæã§çºçããŸããã
- JPã¢ãŒã¬ã³ãã§ã€ã¹
- ã¢ã¡ãªã«éè¡
- Hsbc
- TD Bank
- 察象
- ã¿ã³ãã©ãŒ
- ããŒã ãã
- ãã€ã¹ããŒã¹
- eBay
- Adobe System Inc
- iMesh
ãžã¥ãããŒãªãµãŒãã¯ã2019幎ãŸã§ã«ãµã€ããŒç¯çœªã«ãã被害ã¯2å
ãã«ãè¶
ãããšäºæž¬ããŠããŸãã ãããã£ãŠãæ³å»åŠåæã®éèŠã¯å¢ãç¶ããŸãã
ãœãããŠã§ã¢ããŒã«ã¯ã·ã¹ãã 管çè
ã®èŠªåã§ãããé©åãªããŒã«ã䜿çšããããšã§ãäœæ¥ãè¿
éãã€å¹ççã«è¡ãããšãã§ããŸãã
ã€ã³ã·ãã³ãã®èª¿æ»ã¯ç°¡åãªäœæ¥ã§ã¯ãããŸããã蚌æ ãå
¥æããçµæãæé€ããããã®èšç»ãç«ãŠãããã«ãã§ããã ãå€ãã®æ
å ±ãåéããå¿
èŠãããããã§ãã 以äžã§ã¯ãã€ã³ã·ãã³ãã調æ»ããããã®ããã€ãã®äŸ¿å©ãªããŒã«ã«ã€ããŠèª¬æããŸãã ãããã®ã»ãšãã©ã¯ç¡æã§ãïŒ
ããŒã«ãªã¹ãïŒ
- æ€æ»
- æå·åãã£ã¹ã¯æ€åºåš
- Wireshark
- ãã°ãããRAMãã£ããã£
- ãããã¯ãŒã¯ãã€ããŒ
- NMAP
- RAMãã£ããã£
- æ³å»åŠææ»å®
- ãã¡ãŠ
- Hashmyfiles
- USBæžã蟌ã¿ãããã«ãŒ
- 矀è¡ã®åå¿
- NFIããã¬ã€ã¶ãŒ
- Exiftool
- ããŒã«ãºãªãŒ
- SIFT
- ãã³ããžã©
- ãã©ãŠã¶å±¥æŽ
- ForensicUserInfo
- ããã¯ãã©ãã¯
- ãã©ãã£ã³
- ã¹ã«ãŒã¹ããã
- ã±ã€ã³
1.æ€æ»åæ€ã¯ãããŒããã©ã€ããšã¹ããŒããã©ã³ã®å¹æçãªæ³å»åŠèª¿æ»ã®ããã®ã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ãåãããªãŒãã³ãœãŒã¹ããã°ã©ã ã§ãã äœå人ãã®äººã
ãåæ€ã䜿çšããŠãå®éã«ã³ã³ãã¥ãŒã¿ãŒã«äœãèµ·ãã£ãããææ¡ããŠããŸãã

倧äŒæ¥ãšè»ã®å°é家ã¯ã圌ãã®ä»äºã«åºãåæ€ã䜿çšããŠããŸãã 以äžã¯ãåæ€ã®æ©èœã®äžéšã§ãã
- ã¡ãŒã«åæ;
- ãã¡ã€ã«ã¿ã€ãã®æ±ºå®ã
- ãã«ãã¡ãã£ã¢åç;
- ã¬ãžã¹ããªåæ;
- ã¡ã¢ãªã«ãŒãããåçãå埩ããŸãã
- JPEGãã¡ã€ã«ããäœçœ®æ
å ±ãšã«ã¡ã©æ
å ±ãæœåºããŸãã
- ãã©ãŠã¶ãããããã¯ãŒã¯ã¢ã¯ãã£ããã£ããŒã¿ãååŸããŸãã
- ã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ã§ã®ã·ã¹ãã ã€ãã³ãã®è¡šç€ºã
- æç³»ååæ;
- Androidããã€ã¹ããã®ããŒã¿æœåºïŒSMSãé話èšé²ãé£çµ¡å
ãªã©ã
ãã®ããŒã«ã䜿çšããŠãHTMLããã³XLS圢åŒã®ã¬ããŒããçæã§ããŸãã
2.æå·åãã£ã¹ã¯æ€åºåšEncrypted Disk Detectorã¯ãæå·åãããããŒããã©ã€ãã®åæã«åœ¹ç«ã¡ãŸãã ãã®ããã°ã©ã ã¯ãTrueCryptãPGPãBitlockerãSafebootã䜿çšããŠæå·åãããããŒãã£ã·ã§ã³ã§åäœããŸãã
3. WiresharkWiresharkã¯ããããã¯ãŒã¯ã§äœãèµ·ãã£ãŠããããç£èŠããã®ã«åœ¹ç«ã€ãããã¯ãŒã¯ãã±ãããã£ããã£ããã³åæããŒã«ã§ãã Wiresharkã¯ããããã¯ãŒã¯ã€ã³ã·ãã³ãã調æ»ãããšãã«åœ¹ç«ã¡ãŸãã
4.ãã°ãããRAMãã£ããã£ãã°ãããRAMãã£ããã£ã«ãããRAMã®ã¹ãããã·ã§ãããååŸããã¡ã¢ãªå
ã®ã¢ãŒãã£ãã¡ã¯ããåæã§ããŸãã ãã®ããã°ã©ã ã¯Windowsã§åäœããŸãã
5.ãããã¯ãŒã¯ãã€ããŒWindowsãLinuxãããã³MAC OS Xåãã®ãã®èå³æ·±ããããã¯ãŒã¯ãã©ã¬ã³ãžãã¯åæããŒã«ã«ããããã©ãã£ãã¯ã¢ãã©ã€ã¶ãŒãŸãã¯PCAPãã¡ã€ã«ã䜿çšããŠããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããã¹ãåãã»ãã·ã§ã³ã®æ€åºãããã³ããŒãã®æ€åºãå¯èœã«ãªããŸãã
Network Minerã¯ãæœåºãããã¢ãŒãã£ãã¡ã¯ããçŽæçãªã€ã³ã¿ãŒãã§ãŒã¹ã§è¡šç€ºããŸãã
6. NMAPNMAP ïŒNetwork MapperïŒã¯ããããã¯ãŒã¯ããã³æ
å ±ã»ãã¥ãªãã£ãç£æ»ããããã®æãäžè¬çãªããŒã«ã®1ã€ã§ãã NMAPã¯ãWindowsãLinuxãSolarisãMAC OSãHP-UXãªã©ãã»ãšãã©ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšäºææ§ããããŸãã ããã°ã©ã ã¯ãªãŒãã³ãœãŒã¹ãªã®ã§ãç¡æã§ãã
7. RAMãã£ããã£ãŒBelkasoftã®RAM Capturerã¯ãæ®çºæ§ã®ã³ã³ãã¥ãŒã¿ãŒã¡ã¢ãªããããŒã¿ããã³ãããç¡æã®ããŒã«ã§ãã ãã®ããã°ã©ã ã¯Windowsãšäºææ§ããããŸãã ã¡ã¢ãªãã³ãã«ã¯ãæå·åãããããªã¥ãŒã ã«ããé»åã¡ãŒã«ãŸãã¯ãœãŒã·ã£ã«ãããã¯ãŒã¯ã«å
¥ãããã®ãã¹ã¯ãŒããšããŒã¿ãå«ãŸããå ŽåããããŸãã
8.æ³å»åŠææ»å®Splunkã䜿çšããå Žåã
Forensic Investigatorã圹ç«ã¡ãŸãã ãã®Splunkã¢ããªã«ã¯å€ãã®æ©èœããããŸãã

- WHOIS / GeoIPã¯ãšãª
- ping;
- ããŒãã¹ãã£ããŒ
- ããããŒã³ã¬ã¯ã¿ãŒã
- URLããŒãµãŒ/ãã³ãŒããŒã
- XOR / HEX / Base64ã³ã³ããŒã¿ãŒ;
- SMBå
±æ/ NetBIOSã衚瀺ããŸãã
- ãŠã€ã«ã¹ããŒã¿ã«ã¹ãã£ã³ã
9. FAWFAW ïŒForensics Acquisition of WebsitesïŒã¯ããããªã調æ»ã®ããã«WebããŒãžããŒã¿ãåéããããã«äœ¿çšãããŸãã ããŒã«ã«ã¯ä»¥äžãå®è£
ãããŠããŸãã
- éšåçãŸãã¯å®å
šãªããŒãžã®ä¿åã
- ãã¹ãŠã®ã¿ã€ãã®ç»åãä¿åããŸãã
- WebããŒãžã®ãœãŒã¹HTMLã³ãŒãã®ä¿åã
- Wiresharkã§åäœããŸãã
10. HashMyFilesHashMyFilesã¯ãMD5ãšSHA1ã®ããã·ã¥ãèšç®ããã®ã«åœ¹ç«ã¡ãŸãã ãã®ããŒã«ã¯ãã»ãšãã©ãã¹ãŠã®ææ°ããŒãžã§ã³ã®Windowsã§åäœããŸãã
11. USBæžã蟌ã¿ãããã«ãŒæçŽãã¡ã¿ããŒã¿ããŸãã¯ã¿ã€ã ã¹ã¿ã³ããæ®ããã«ãUSBãã©ã€ãã®å
容ãé²èŠ§ããŸãã
USBæžã蟌ã¿ãããã«ãŒã¯ãWindowsã¬ãžã¹ããªã䜿çšããŠãUSBããã€ã¹ãžã®æžã蟌ã¿ãé²ããŸãã
12.矀è¡ã®åå¿Crowd Strikeããã®
å¿çã¯ãã€ã³ã·ãã³ã察å¿ãšã»ãã¥ãªãã£ã«é¢ããã·ã¹ãã æ
å ±ãåéããããã«èšèšãããWindowsã¢ããªã±ãŒã·ã§ã³ã§ãã CRConvertã䜿çšããŠãçµæãXMLãCSVãTSVãŸãã¯HTML圢åŒã§è¡šç€ºã§ããŸãã ãã®ããã°ã©ã ã¯ãXP以éã®ãã¹ãŠã®32ãããããã³64ãããããŒãžã§ã³ã®Windowsã§å®è¡ãããŸãã
Crowd Strikeã«ã¯ãä»ã«ãåªãã調æ»ããŒã«ããããŸãã
- Tortillaã䜿çšãããšãTORãä»ããŠTCP / IPããã³DNSãã©ãã£ãã¯ãå¿åã§ã«ãŒãã£ã³ã°ã§ããŸãã
- Shellshock Scanner-ãããã¯ãŒã¯ã§shellshockã®è匱æ§ã確èªããŸãã
- ããŒãããªãŒãã¹ãã£ããŒ-OpenSSLã®ããŒãããªãŒãã®è匱æ§ã«ã€ããŠãããã¯ãŒã¯ã確èªããŸãã
13. NFIããã¬ã€ã¶ãŒDefraserã¯ãæ
å ±ã¹ããªãŒã ã§ãã«ãã¡ãã£ã¢ãã¡ã€ã«ãŸãã¯ãã®ãã©ã°ã¡ã³ããèŠã€ããã®ã«åœ¹ç«ã€ç 究ããŒã«ã§ãã
14. ExifToolExifToolã䜿çšãããšãEXIFãGPSãIPTCãXMPãJFIFãGeoTIFFãPhotoshop IRBãFlashPixãªã©ãå«ãããŸããŸãªçš®é¡ã®ãã¡ã€ã«ã®ã¡ã¿ããŒã¿ã®èªã¿åããæžã蟌ã¿ãç·šéãã§ããŸãã
15.ããŒã«ãºãªãŒToolsleyã¯ã12ãè¶
ãã䟿å©ãªèª¿æ»ããŒã«ãæäŸããŠããŸãã
- ãã¡ã€ã«ã®ããžã¿ã«çœ²åã®æ€èšŒã
- ãã¡ã€ã«åœ¢åŒã®èå¥ã
- ãã¡ã€ã«ã®ããã·ã¥ãšãã§ãã¯ã
- ãã€ããªãã¡ã€ã«ã€ã³ã¹ãã¯ã¿ãŒã
- ããã¹ãæå·å;
- ããŒã¿URIãžã§ãã¬ãŒã¿ãŒã
- ãã¹ã¯ãŒããžã§ãã¬ãŒã¿ã
16. SIFTSIFT ïŒSANS調æ»ãã©ã¬ã³ãžãã¯ããŒã«ãããïŒã¯ãUbuntu 14.04ã§èªç±ã«å©çšã§ããã¯ãŒã¯ã¹ããŒã·ã§ã³ã§ãã SIFTã¯äŸ¿å©ãªåæããŒã«ã®ã³ã¬ã¯ã·ã§ã³ã§ãããæã人æ°ã®ãããªãŒãã³ãœãŒã¹ã®ã€ã³ã·ãã³ã察å¿ãã©ãããã©ãŒã ã®1ã€ã§ãã
17.ãã³ããžã©Dumpzillaã䜿çšããŠãFirefoxãIceweaselãSeamonkeyã®ãã©ãŠã¶ãŒããé¢å¿ã®ãããã¹ãŠã®æ
å ±ãååŸããŸãã
18.ãã©ãŠã¶ã®å±¥æŽFoxtonã«ã¯2ã€ã®èå³æ·±ãããŒã«ããããŸãã
- Windowsçšã®ãã©ãŠã¶ãŒå±¥æŽïŒChromeãFirefoxãIEãããã³EdgeïŒã®ä¿åã
- ãã©ãŠã¶ã®å±¥æŽã衚瀺ããŸãã ææ°ã®ãã©ãŠã¶ã§ã¯ãã¢ã¯ã·ã§ã³ã®å±¥æŽãæœåºããŠåæã§ããŸãã çµæã¯ã€ã³ã¿ã©ã¯ãã£ããªãã£ãŒãã«è¡šç€ºãããå±¥æŽããŒã¿ããã£ã«ã¿ãªã³ã°ã§ããŸãã
19. ForensicUserInfoForensicUserInfoã䜿çšãããšã次ã®æ
å ±ãæœåºã§ããŸãã
- RID
- LM / NTããã·ã¥ã
- ãã¹ã¯ãŒãã®å€æŽãã¢ã«ãŠã³ãã®æå¹æéã
- ãã°ã€ã³æ°ãè©Šè¡å€±æã®æ¥ä»ã
- ã°ã«ãŒã
- ãããã¡ã€ã«ãã¹ã
20.ããã¯ãã©ãã¯Backtrackã¯ãè匱æ§ããã§ãã¯ããããã®æãäžè¬çãªãã©ãããã©ãŒã ã®1ã€ã§ãããæ³å»åŠåææ©èœãå®è£
ããŠããŸãã
21.ãã©ãã£ã³PALADIN Forensic Suiteã¯ãäžçã§æã人æ°ã®ããLinuxçšã®ãã©ã¬ã³ãžãã¯ããŒã«ãããã§ãããUbuntuããŒã¹ã®ä¿®æ£Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã§ã32ãããããã³64ãããããŒãžã§ã³ã§å©çšã§ããŸãã

Paladinã«ã¯100ãè¶
ããããŒã«ãå«ãŸããŠããã29ã®ã«ããŽãªã«ã°ã«ãŒãåãããŠããŸãã ã€ã³ã·ãã³ãã調æ»ããããã«å¿
èŠãªããšã¯ã»ãŒãã¹ãŠã§ãã Autospyã¯ææ°ããŒãžã§ã³-Paladin 6ã«å«ãŸããŠããŸãã
22.ã¹ã«ãŒã¹ãããSleuth Kitã¯ãè«çãã©ã€ããšãã¡ã€ã«ã·ã¹ãã ã調ã¹ãŠåæããããŒã¿ãèŠã€ããããã«èšèšãããã³ãã³ãã©ã€ã³ããŒã«ãããã§ãã
23.ã±ã€ã³CAINEïŒComputer Aided Investigate EnvironmentïŒã¯ãã¢ã¯ã·ã§ã³ã«é¢ããåæã調æ»ãããã³ã¬ããŒãã®ããã®80以äžã®ããŒã«ãåããå®å
šãªãšãã¹ããŒããã©ãããã©ãŒã ãæäŸããLinuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã§ãã

äžèšã®ããŒã«ãã€ã³ã·ãã³ãã®åŠçãšèª¿æ»ã®è¿
éåã«åœ¹ç«ã€ããšãé¡ã£ãŠããŸãã
äŒçµ±çã«ãç§ãã¡ã¯HOSTING.cafeã調ã¹ãŠä»®æ³ãµãŒããŒãŸãã¯å
±æãã¹ãã£ã³ã°ãéžæããããšã«èå³ããããã¹ãŠã®äººãæåŸ
ããŸãã ãã¹ãã£ã³ã°æ¥è
ã®ã¬ãã¥ãŒã¯POISK.hostingã§åéãããŸã ã