• Evidence ProjectForensics Tools Catalogue - https://www.dftoolscatalogue.eu
• NIST - Forensics Tools Catalogue - https://toolcatalog.nist.gov
• S&T partners and NIST - Computer Forensic Tool Testing (CFTT) - https://www.dhs.gov/science-and-technology/nist-cftt-reports
Interesting information
• Beyond the Veil of Surveillance: Private Sector Offensive Actors (PSOAs)
• Burn, drown, or smash your phone: Forensics can extract data anyway
• How law enforcement gets around your smartphone’s encryption
• Cellphone data used to solve murder case from 2 years ago, police say
• The Stingray: How Law Enforcement Can Track Your Every Move
• Police are tracking you and your license plates
• SCOTUS: Police Need Search Warrant to Ping cell Phones
• Motion to Suppress Aerial Surveillance Evidence in U.S. vs Muhammed Momtaz Alazhari
• Researchers Find Way to Steal Encrypted Data - NYT (2008)
• As UN Human Rights Chief Urges Stricter Rules, Snowden Calls for End to Spyware Trade (2021)
Comparison between Drive Badger (Open source platform) with other lawful interception platforms. Visit: Official online sheet complete and updated or PDF in our repo.
| Zero-day Exploit | Associated Spyware Vendor |
| CVE-2023-28205 and CVE-2023-28206 (Apple iOS) | Variston (BridgeHead) |
| CVE-2023-2033 (Google Chrome) | Intellexa/Cytrox (Predator) |
| CVE-2023-2136 (Google Chrome) | Intellexa/Cytrox (Predator) |
| CVE-2023-32409 (Apple iOS) | Variston (BridgeHead) |
| CVE-2023-3079 (Google Chrome) | Intellexa/Cytrox (Predator) |
| CVE-2023-41061 and CVE-2023-41064 (Apple iOS) | NSO Group (Pegasus) |
| CVE-2023-41991, CVE-2023-41992, and CVE-2023-41993 (Apple iOS) | Intellexa/Cytrox (Predator) |
| CVE-2023-5217 (Google Chrome) | Candiru (DevilsTongue) |
| CVE-2023-4211 (Arm Mali GPU) | Cy4Gate (Epeius) |
| CVE-2023-33063 (Qualcomm Adreno GPU) | Variston (BridgeHead) |
| CVE-2023-33106 and CVE-2023-33107 (Qualcomm Adreno GPU) | Cy4Gate (Epeius) |
| CVE-2023-42916 and CVE-2023-42917 (Apple iOS) | PARS Defense |
| CVE-2023-7024 (Google Chrome) | NSO Group (Pegasus) |
👷🛠️UNDER CONSTRUCTION🚧🏗
1.01 Forensic standards
Visit our repo tree: 2.FORENSIC
Standards
NIST — National Institute of Standards and Technology
Visit: https://www.nist.gov/standards
ISO/IEC — International Electrotechnical Commission
Visit: https://www.iso27001security.com
Official - Information security, cybersecurity and privacy protection — https://www.iso.org/standard/27001
- ISO/IEC 27000 — ISO27k overview & glossary
- ISO/IEC 27001 — formal ISMS specification
- ISO/IEC 27002 — infosec controls catalogue
- ISO/IEC 27003 — ISMS implementation guide
- ISO/IEC 27004 — infosec measurement [metrics]
- ISO/IEC 27005 — info[sec] risk management
- ISO/IEC 27006-n — ISMS & PIMS certification
- ISO/IEC 27007 — management system auditing
- ISO/IEC TS 27008 — security controls auditing
- ISO/IEC 27009 — sector variants of ISO27k
- ISO/IEC 27010 — for inter-org comms
- ISO/IEC 27011 — ISMS for telecoms
- ISO/IEC 27013 — ISMS & ITIL/service mgmt
- ISO/IEC 27014 — infosec governance
- ISO/IEC TR 27016 — infosec economics
- ISO/IEC 27017 — cloud security controls
- ISO/IEC 27018 — cloud privacy
- ISO/IEC 27019 — process control in energy industry
- ISO/IEC 27021 — competences for ISMS pro’s
- ISO/IEC TS 27022 — ISMS processes
- ISO/IEC 27031 — ICT element of business continuity
- ISO/IEC 27032 — Internet security
- ISO/IEC 27033-n — network security
- ISO/IEC 27034-n — application security
- ISO/IEC 27035-n — incident management
- ISO/IEC 27036-n — ICT supply chain & cloud
- ISO/IEC 27037 — digital evidence [eForensics]
- ISO/IEC 27038 — document redaction
- ISO/IEC 27039 — intrusion prevention
- ISO/IEC 27040 — storage security
- ISO/IEC 27041 — incident investigation assurance
- ISO/IEC 27042 — analysing digital evidence
- ISO/IEC 27043 — incident investigation
- ISO/IEC 27050-n — digital forensics
- ISO/IEC 27070 — virtual roots of trust
- ISO/IEC 27071 — trusted connections
- ISO/IEC 27099 — ISMS for PKI
- ISO/IEC TS 27100 — cybersecurity overview/concepts
- ISO/IEC 27102 — cyber-insurance
- ISO/IEC 27103 — ISMS for cybersecurity
- ISO/IEC TS 27110 — cybersecurity frameworks
- ISO/IEC 27400 — IoT security and privacy
- ISO/IEC TR 27550 — privacy engineering
- ISO/IEC 27553-n — mobile device biometrics
- ISO/IEC 27555 — deleting PII/personal data
- ISO/IEC 27556 — privacy preferences
- ISO/IEC 27557 — privacy risk management
- ISO/IEC 27559 — de-identification of personal data
- ISO/IEC TS 27560 — privacy consent record structure
- ISO/IEC TR 27563 — AI use case security & privacy
- ISO/IEC TS 27570 — smart city privacy
- ISO/IEC 27701 — managing privacy with an ISMS
- ISO 27799 — information security in healthcare
RFC
Best Current Practices (BCP)
- RFC 1918 / BCP 5: Address Allocation for Private Internets
- RFC 2350 / BCP 21: Expectations for Computer Security Incident Response
- RFC 2505 / BCP 30: Anti-Spam Recommendations for SMTP MTAs
- RFC 2644 / BCP 34: Changing the Default for Directed Broadcasts in Routers
- RFC 2827 / BCP 38: Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing
- RFC 3013 / BCP 46: Recommended Internet Service Provider Security Services and Procedures
- RFC 3227 / BCP 55: Guidelines for Evidence Collection and Archiving
- RFC 3360 / BCP 60: Inappropriate TCP Resets Considered Harmful
- RFC 3365 / BCP 61: Strong Security Requirements for Internet Engineering Task Force Standard Protocols
- RFC 4086 / BCP 106: Randomness Requirements for Security
- RFC 4107 / BCP 107: Guidelines for Cryptographic Key Management
- RFC 5068 / BCP 134: Email Submission Operations: Access and Accountability Requirements
- RFC 5358 / BCP 140: Preventing Use of Recursive Nameservers in Reflector Attacks
- RFC 5406 / BCP 146: Guidelines for Specifying the Use of IPsec Version 2
Standards
- RFC 2142: Mailbox Names for Common Services, Roles and Functions
- RFC 2246: The TLS Protocol Version 1.0
- RFC 2554: SMTP Service Extension for Authentication
- RFC 3168: The Addition of Explicit Congestion Notification (ECN) to IP
- RFC 3207: SMTP Service Extension for Secure SMTP over Transport Layer Security
- RFC 3369: Cryptographic Message Syntax (CMS)
- RFC 3370: Cryptographic Message Syntax (CMS) Algorithms
- RFC 3834: Recommendations for Automatic Responses to Electronic Mail
- RFC 4033: DNS Security Introduction and Requirements
- RFC 4034: Resource Records for the DNS Security Extensions
- RFC 4035: Protocol Modifications for the DNS Security Extensions
- RFC 4051: Additional XML Security Uniform Resource Identifiers (URIs)
- RFC 4055: Additional Algorithms and Identifiers for RSA Cryptography for use in the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile
- RFC 4056: Use of the RSASSA-PSS Signature Algorithm in Cryptographic Message Syntax (CMS)
- RFC 4109: Algorithms for Internet Key Exchange version 1 (IKEv1)
- RFC 4217: Securing FTP with TLS
- RFC 4250: The Secure Shell (SSH) Protocol Assigned Numbers
- RFC 4251: The Secure Shell (SSH) Protocol Architecture
- RFC 4252: The Secure Shell (SSH) Authentication Protocol
- RFC 4253: The Secure Shell (SSH) Transport Layer Protocol
- RFC 4254: The Secure Shell (SSH) Connection Protocol
- RFC 4255: Using DNS to Securely Publish Secure Shell (SSH) Key Fingerprints
- RFC 4256: Generic Message Exchange Authentication for the Secure Shell Protocol (SSH)
- RFC 4301: Security Architecture for the Internet Protocol
- RFC 4302: IP Authentication Header
- RFC 4303: IP Encapsulating Security Payload (ESP)
- RFC 4308: Cryptographic Suites for IPsec
- RFC 4344: The Secure Shell (SSH) Transport Layer Encryption Modes
- RFC 4346: The Transport Layer Security (TLS) Protocol Version 1.1
- RFC 4359: The Use of RSA/SHA-1 Signatures within Encapsulating Security Payload (ESP) and Authentication Header (AH)
- RFC 4366: Transport Layer Security (TLS) Extensions
- RFC 4513: Lightweight Directory Access Protocol (LDAP): Authentication Methods and Security Mechanisms
- RFC 4871: DomainKeys Identified Mail (DKIM) Signatures
- RFC 4959: IMAP Extension for Simple Authentication and Security Layer (SASL) Initial Client Response
- RFC 4985: Internet X.509 Public Key Infrastructure Subject Alternative Name for Expression of Service Name
- RFC 5070: The Incident Object Description Exchange Format
- RFC 5321: Simple Mail Transfer Protocol
- RFC 5322: Internet Message Format
- RFC 5901: Extensions to the IODEF-Document Class for Reporting Phishing
- RFC 6045: Real-time Inter-network Defense (RID)
- RFC 6409: Message Submission for Mail
- RFC 6528: Defending against Sequence Number Attacks
Informational
- RFC 1281: Guidelines for the Secure Operation of the Internet
- RFC 1321: The MD5 Message-Digest Algorithm
- RFC 1470: Tools for Monitoring and Debugging TCP/IP Internets and Interconnected Devices
- RFC 1750: Randomness Recommendations for Security
- RFC 2076: Common Internet Message Headers
- RFC 2196: Site Security Handbook
- RFC 2411: IP Security Document Roadmap
- RFC 2504: Users Security Handbook
- RFC 2577: FTP Security Considerations
- RFC 2979: Behavior of and Requirements for Internet Firewalls
- RFC 3067: TERENA's Incident Object Description and Exchange Format Requirements
- RFC 3098: How to Advertise Responsibly Using E-Mail and Newsgroups or — how NOT to $$$$$ MAKE ENEMIES FAST! $$$$$
- RFC 3164: The BSD syslog Protocol
- RFC 3174: US Secure Hash Algorithm 1 (SHA1)
- RFC 3330: Special-Use IPv4 Addresses
- RFC 3511: Benchmarking Methodology for Firewall Performance
- RFC 3631: Security Mechanisms for the Internet
- RFC 3833: Threat Analysis of the Domain Name System (DNS)
- RFC 3871: Operational Security Requirements for Large Internet Service Provider (ISP) IP Network Infrastructure
- RFC 3964: Security Considerations for 6to4
- RFC 4096: Policy-Mandated Labels Such as "Adv:" in Email Subject Headers Considered Ineffective At Best
- RFC 4270: Attacks on Cryptographic Hashes in Internet Protocols
- RFC 4272: BGP Security Vulnerabilities Analysis
- RFC 4381: Analysis of the Security of BGP/MPLS IP Virtual Private Networks (VPNs)
- RFC 4641: DNSSEC Operational Practices
- RFC 4686: Analysis of Threats Motivating DomainKeys Identified Mail (DKIM)
- RFC 4766: Intrusion Detection Message Exchange Requirements
- RFC 4772: Security Implications of Using the Data Encryption Standard (DES)
- RFC 4778: Current Operational Security Practices in Internet Service Provider Environments
- RFC 4890: Recommendations for Filtering ICMPv6 Messages in Firewalls
- RFC 4891: Using IPsec to Secure IPv6-in-IPv4 Tunnels
- RFC 4942: IPv6 Transition/Coexistence Security Considerations
- RFC 4986: Requirements Related to DNS Security (DNSSEC) Trust Anchor Rollover
- RFC 4949: Internet Security Glossary, Version 2
- RFC 6092: Recommended Simple Security Capabilities in Customer Premises Equipment (CPE) for Providing Residential IPv6 Internet Service
- RFC 6274: Security Assessment of the Internet Protocol Version 4
- RFC 6305: I'm Being Attacked by PRISONER.IANA.ORG!
- RFC 6471: Overview of Best Email DNS-Based List (DNSBL) Operational Practices
- RFC 6480: An Infrastructure to Support Secure Internet Routing
- RFC 6561: Recommendations for the Remediation of Bots in ISP Networks
- RFC 7123: Security Implications of IPv6 on IPv4 Networks
Experimental / Historic
- RFC 4406: Sender ID: Authenticating E-Mail
- RFC 4408: Sender Policy Framework (SPF) for Authorizing Use of Domains in E-Mail, Version 1
- RFC 4765: The Intrusion Detection Message Exchange Format (IDMEF)
- RFC 4767: The Intrusion Detection Exchange Protocol (IDXP)
- RFC 6541: DomainKeys Identified Mail (DKIM) Authorized Third-Party Signatures
- RFC 6587: Transmission of Syslog Messages over TCP
1.02 Forensic certs & training
1.03 Online forensic tools
• Message Header Analyzer — https://mha.azurewebsites.net
• Message Header Analyzer — https://github.com/microsoft/MHA
• PhishTank — https://phishtank.org
• Simple Email Reputation — https://emailrep.io
• Have I Been Pwned — https://haveibeenpwned.com
• DeHashed — https://www.dehashed.com
• Whois — https://www.iana.org/whois
• ViewDNS — https://viewdns.info
• WhoisMyDNS — https://whoismydns.com
• NSLookup — https://www.nslookup.io
• My-Addr — https://my-addr.com
• Malpedia — https://malpedia.caad.fkie.fraunhofer.de
• CVE Details — https://www.cvedetails.com
• Exploit Database — https://www.exploit-db.com
• FileInfo — https://fileinfo.co
• xCyclopedia — https://strontic.github.io/xcyclopedia
• The Windows Binary Index — https://winbindex.m417z.com
• Palo Alto Applipedia — https://applipedia.paloaltonetworks.com
• Windows Securitiy Logs — https://www.ultimatewindowssecurity.com/securitylog/encyclopedia
• Internet Archive - WayBackMachine - https://web.archive.org
• Archive web content — https://archive.ph
• Internet Archive — https://archive.org
• HTTrack — https://www.httrack.com
• IPVOID — https://www.ipvoid.com
• AbuseIPDB — https://www.abuseipdb.com
• Grabify IP Logger — https://grabify.link/
• IP Logger — https://iplogger.org
• IP Tracker — https://iplogger.org/ip-tracker
• IP location — https://www.iplocation.net
• Location Tracker — https://iplogger.org/location-tracker
• URL Checker — https://iplogger.org/url_checker
• MAC Address Lookup — https://iplogger.org/mac-checker
• MAC Vendor — https://macvendors.com
• IP API
— ip-api — https://ip-api.com
— ipify — https://www.ipify.org
— ipapi — https://ipapi.co
— vpnapi — https://vpnapi.io
— ipapi — https://ipapi.com
• Virus Total — https://www.virustotal.com
• Hybrid Analysis — https://hybrid-analysis.com
• AlienVault OTX — https://otx.alienvault.com/
• IBM X-Force Exchange — https://exchange.xforce.ibmcloud.com
• Cisco Talos — https://talosintelligence.com/reputation_center
• Maltiverse — https://maltiverse.com/collection
• GreyNoise — https://www.greynoise.io
• SANS Internet Storm Center — https://isc.sans.edu
• Intelligence X — https://intelx.io
• MetaDefender Cloud — https://metadefender.opswat.com
• RiskIQ Community Edition — https://community.riskiq.com/home
• Pulsedive — https://pulsedive.com
• Valhalla YARA Rules — https://valhalla.nextron-systems.com
• Binvis — https://binvis.io
• JoeSandbox — https://www.joesandbox.com
• ANY.RUN — https://any.run
• urlscan.io — https://urlscan.io
• Verexif - https://www.verexif.com/en/
• Any Run — https://app.any.run
• The ZMap Project — https://zmap.io
• Name OSINT — https://namechk.com
• Reverse Shell Generator — https://www.revshells.com
• Rainbow Tables (Hashes) — https://hashes.com/en/decrypt/hash
• Breach Directory - https://breachdirectory.org
• MD5 Decrypt - https://md5decrypt.net/en/Sha1
• File Signatures ("Magic Numbers") — https://en.wikipedia.org/wiki/Magic_number_(programming)
• List of File Signatures — https://en.wikipedia.org/wiki/List_of_file_signatures
• CyberChef — https://gchq.github.io/CyberChef
• explainshell — https://explainshell.com
• Epoch Converter — https://www.epochconverter.com
For OSINT tools visit our repository: https://www.dftoolscatalogue.eu
NIST - https://toolcatalog.nist.gov
S&T partners and NIST - Computer Forensic Tool Testing (CFTT) - https://www.dhs.gov/science-and-technology/nist-cftt-reports
- The Sleuth Kit (TSK)(GitHub)
- Autopsy
- ImHex
- Hashcat
- John the Ripper
- Drive Badger — Covert Data Exfiltration Operations
- Making Maps for Investigators
- Offensive Google framework
- Bitlocker Key Finder
- SIFT
- RegRipper
- No More Ransom
- MS Sysinternals
- WinFE
Image and video upscaling programs
• ImageJ
• Upscalers - https://github.com/hollowaykeanho/Upscaler
| Encryption: | Seize the encrypted files and decrypt them using a password or key and the appropriate decryption software. |
| Virtualization: | Seize the virtual image file and open it with the correct password. OR Log into the virtual machine and seize the data while the virtual machine is turned on and in an unencrypted state. |
| Relational Database: | Seize all the files containing records. Obtain a copy of the database software and rebuild the database. OR Log into the database while it is live and employ the application used to create and manage the database as a search tool. Download the data using the method allowed by the application, either in the form of printouts or data files. |
Encryption workarounds:
- Find the key.
- Guess the key.
- Compel the key.
- Exploit a flaw in the encryption software.
- Access plaintext while the device is in use.
- Locate another plaintext copy.
1.05 Cryptography
Visit our repo tree: 3.DOCUMENTS/Encryption
Encryption workarounds:
- Find the key.
- Guess the key.
- Compel the key.
- Exploit a flaw in the encryption software.
- Access plaintext while the device is in use.
- Locate another plaintext copy.
Read the thread Brute Force Attacks
.Visit our repo tree: 3.DOCUMENTS/Cryptanalysis
1.06 Memory analysis
• Volatility
https://www.volatilityfoundation.org/releases
• Linux Memory Extractor (LiME)
https://github.com/504ensicsLabs/LiME
• Cobalt Strike in memory
https://andreafortuna.org/2020/11/22/how-to-detect-cobalt-strike-activity-in-memory-forensics/
https://www.cellebritelearningcenter.com/mod/page/view.php?id=11903
https://www.fletc.gov/jtag-chipoff-smartphones-training-program
https://www.gillware.com/phone-data-recovery-services/jtag-chip-off-forensics
https://www.gillware.com/phone-data-recovery-services/chip-off-forensics-services
https://octoplusbox.com
https://medusabox.com
https://www.riffbox.org
https://easy-jtag.com
https://z3x-team.com
1.07 Cryptocurrencies analysis
https://github.com/OffcierCia/On-Chain-Investigations-Tools-List
https://github.com/aaarghhh/awesome_osint_criypto_web3_stuff
https://blocksherlock.com/home/blockchain-explorers
https://tronscan.org
https://etherscan.io
https://algoexplorer.io
https://explorer.solana.com
https://stellar.expert
https://snowtrace.io
https://flowscan.org
https://polygonscan.com
https://github.com/demining/CryptoDeepTools
https://github.com/demining/bitcoindigger
https://github.com/demining/Dao-Exploit
https://github.com/immunefi-team/Web3-Security-Library/blob/main/Tools/README.md#blockchain-analysis
https://chainalysis.com
https://elliptic.co
https://ciphertrace.com
https://coinmetrics.io
https://www.whitestream.io
https://ciphertrace.com
https://elementus.io
https://trmlabs.com
https://bitok.org/investigations
👷🛠️UNDER CONSTRUCTION🚧🏗
2.01 Police hacking
Visit our repo tree: 4.POLICE_HACKING
• MITRE ATT&CK — ICS Techniques
https://attack.mitre.org/techniques/ics
• MITRE ATT&CK — Mobile Techniques
https://attack.mitre.org/techniques/mobile/
• MITRE ATT&CK — Enterprise Techniques
https://attack.mitre.org/techniques/enterprise/
∙ Rootme — https://www.root-me.org
∙ Vulnhub — https://www.vulnhub.com
∙ Hacker101 — https://www.hacker101.com
∙ Crackmes — https://crackmes.one
∙ Attack Defense — https://attackdefense.com
∙ Omerta Digital (FBI Honey Pot?)
https://www.omertadigital.com/
∙ Case: ANON (also stylized as AN0M or ΛNØM)
https://en.wikipedia.org/wiki/ANOM
https://www.vice.com/en/article/n7b4gg/anom-phone-arcaneos-fbi-backdoor
∙ Case: EncroChat
https://en.wikipedia.org/wiki/EncroChat
https://eucrim.eu/news/germany-federal-court-of-justice-confirms-use-of-evidence-in-encrochat-cases
https://xperylab.medium.com/the-dark-phones-encrochat-criminals-are-building-their-own-communication-system-474f3aeef759
∙ Case: Pegasus Spyware (NSO Group)
https://theintercept.com/2021/07/27/pegasus-nso-spyware-security
∙ Case: Verint
https://wikileaks.org/spyfiles/docs/VERINT_2012_AvneTurn_en.html
https://www.reddit.com/r/InfoSecNews/comments/sxxzju/leaktheanalyst_group_leak_critical_data_from/
∙ Case: Phantom Secure
https://en.wikipedia.org/wiki/Phantom_Secure
https://www.vice.com/en/article/v7m4pj/the-network-vincent-ramos-phantom-secure
∙ Case: Sky Global
https://en.wikipedia.org/wiki/Shutdown_of_Sky_Global
∙ Case: Bundestrojaner
https://en.wikipedia.org/wiki/Bundestrojaner
∙ Case: Magic Lantern
https://en.wikipedia.org/wiki/Magic_Lantern_(software)
https://github.com/bibanon/bibanon/blob/0b84bb23794c91c238a5601403898b61b5d193fc/Encyclopedia/History/Events/Pifts.md?plain=1#L125
∙ Case: Cryptophon
https://en.wikipedia.org/wiki/Tron_(hacker)#Cryptophon
∙ Planting Tiny Spy Chips in Hardware Can Cost as Little as $200
https://www.wired.com/story/plant-spy-chips-hardware-supermicro-cheap-proof-of-concept
∙ Installation of beacon implants
https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa-upgrade-factory-show-cisco-router-getting-implant
∙ The tricky issue of spyware with a badge: meet ‘policeware’
https://arstechnica.com/information-technology/2007/07/will-security-firms-avoid-detecting-government-spyware
∙ Analisi della normativa e della giurisprudenza sul captatore informatico e la spiegazione del Caso Exodus
https://www.dirittoconsenso.it/2021/11/11/captatore-informatico-trojan-di-stato
∙ LightEater Demo: Stealing GPG keys/emails in Tails via remote firmware infection
https://www.youtube.com/watch?v=sNYsfUNegEA
∙ KeyGrabber Forensic Keylogger
https://www.youtube.com/watch?v=6JJo8qCYE8M
2.02 Law Enforcement Agency (LEA)
*First of all, consult court cases to see how laws are (mis)applied.
∙ UN — Library of Resources — https://www.unodc.org/e4j/en/resdb/index.html∙ UN — https://www.unodc.org/elearning/en/courses/course-catalogue.html ∙ Budapest Convention — Cybercrime — https://www.coe.int/en/web/cybercrime/the-budapest-convention
∙ Octopus Project — https://coe.int/en/web/cybercrime/octopus-project
∙ Five Eyes — https://en.wikipedia.org/wiki/Five_Eyes
∙ Cybercrime — https://www.coe.int/cybercrime
∙ GLACY+ — https://coe.int/en/web/cybercrime/glacyplus
∙ iPROCEEDS-2 — https://coe.int/en/web/cybercrime/iproceeds-2
∙ Octopus Project — https://coe.int/en/web/cybercrime/octopus-project
∙ CyberSouth — https://coe.int/en/web/cybercrime/cybersouth
∙ CyberEast — https://coe.int/en/web/cybercrime/cybereast
- Council of Europe – Cybercrime Digest and Cybercrime@CoE Update: a bi-weekly selection of news relevant to the current areas of interest to the Cybercrime Programme Office of CoE (C-PROC) and a quarterly review of the work carried out by the Cybercrime Convention Committee (T-CY).
- Council of Europe – Cybercrime Newsletter: subscribe to receive the latest updates on the topic.
- CERT-EU: access quarterly Threat Landscape Reports and monthly Cyber Security Briefs from the Computer Emergency Response Team for the EU institutions, bodies and agencies.
- CEPOL – Publications: find the latest documents on trainings for law enforcement officials including the European Law Enforcement Research Bulletin.
- ENISA Newsroom: follow the most recent news on cybersecurity.
- ENISA Publications: sort the latest publications on cybersecurity by topic (and download copies).
- EUROJUST Newsletter: news from the European Union Agency for Criminal Justice Cooperation.
- European Commission’s DG HOME Newsletter: spotlight on Schengen and borders, internal security and relevant European funds.
- Europol – Email alerts: ranging from news to upcoming publications and vacancies, choose what alerts to receive.
- Organisation for Security and Co-operation in Europe (OSCE) Newsletter: hand-picked updates and in-depth information bundles on OSCE activities, with possibility to choose countries of interest.
- SIRIUS project publications: co-implemented by Europol and Eurojust, in close partnership with the European Judicial Network, the SIRIUS project is a central reference point in the EU for knowledge sharing on cross-border access to electronic evidence and allows to download, among other publications, the yearly EU Digital Evidence Situation Report.
∙ US — Federal Rules — Criminal Procedure — Rule 41 — Search and Seizure — Link
| On a Network in a Single District |
On a Network in Multiple Districts | On a Network with Data Stored Internationally | Unknown Where the Data is Stored (Cloud) |
| Search under Rule 41; consider noting in affidavit the possibility of other locations | Multiple search warrants for each district with data or §2703 Warrant served on service provider | Use legal process required in country hosting the data, or consider accessing data remotely with a search warrant under Rule 41 | Search under Rule 41 for subject computers, and concurrently search under §2703 served on service provider |
∙ UK — Crime, justice and law — Law and practice — Link
∙ UK — Public General Acts — Investigatory Powers Act 2016 — Link
∙ GE — German Criminal Code (Strafgesetzbuch — StGB) — Link
∙ GE — German Code of Criminal Procedure (Strafprozeßordnung — StPO) — Link
∙ US Federal Cases — https://pacer.uscourts.gov/find-case
∙ EUR-Lex https://eur-lex.europa.eu/homepage.html
∙ EU Common Portal of Case Law — https://network-presidents.eu/cpcl
∙ casetext (Thomson Reuters) - https://casetext.com
∙ UNODC — Case Law Database — https://sherloc.unodc.org/cld/v3/sherloc/cldb/index.html?lng=en
∙ UNODC — Cyber Organized Crime — https://www.unodc.org/e4j/en/cybercrime/module-13/additional-teaching-tools.html
∙ Council of Europe - COE Cybercrime - https://www.coe.int/en/web/cybercrime
∙ Council of Europe - Octopus Cybercrime Community - Materials - https://www.coe.int/en/web/octopus/training
∙ US Dod - Computer Crime and Intellectual Property Section (CCIPS) - https://www.justice.gov/criminal/criminal-ccips
∙ US FBI - Internet Crime Complaint Center (IC3) - https://www.ic3.gov
∙ Computer Crime Research Center - https://www.crime-research.org
| Countries | Five Eyes | Nine Eyes | Fourteen Eyes | Other |
| United Kingdom | ✔️ | ✔️ | ✔️ | |
| United States | ✔️ | ✔️ | ✔️ | |
| Australia | ✔️ | ✔️ | ✔️ | |
| Canada | ✔️ | ✔️ | ✔️ | |
| New Zealand | ✔️ | ✔️ | ✔️ | |
| Denmark | ✔️ | ✔️ | ||
| Netherlands | ✔️ | ✔️ | ||
| France | ✔️ | ✔️ | ||
| Norway | ✔️ | |||
| Germany | ✔️ | |||
| Belgium | ✔️ | |||
| Spain | ✔️ | |||
| Sweden | ✔️ | |||
| Italy | ✔️ | |||
| Israel | ✔️ | |||
| Japan | ✔️ | |||
| Singapore | ✔️ | |||
| South Korea | ✔️ |
"Apart from these methods of cooperation, there are a number of equally secretive bilateral and multilateral agreements in other regions of the globe – such as the Club of Berne (an intelligence-sharing arrangement among the EU intelligence services) and the Shanghai Cooperation Organizations (an affiliation among the People’s Republic of China (‘China’), India, Kazakhstan, Kyrgyzstan, Pakistan, the Russian Federation (‘Russia’), Tajikistan and Uzbekistan) – together with intelligence exchange arrangements within a group of states comprising Russia, Iraq, Iran and Syria to facilitate the fight against the Islamic State."
(Ref.: WATT, Eliza. State Sponsored Cyber Surveillance: The Right to Privacy of Communications and International Law. Edward Elgar Publishing, 2021.)
2.03 Liability for Contents
- How to start your own ISP
- Where are torrents permitted?
- UK ISP Court Orders
- Web Sheriff
- A new bill could punish web platforms for using end-to-end encryption
- French court rules that Steam’s ban on reselling used games is contrary to European law
- MEPs approve sweeping changes to copyright law
- The Legalities of Linking
- COPYRIGHT LIABILITY FOR LINKING AND EMBEDDING — Klaris Law (.PDF)
- EU court says linking to copyrighted material isn't illegal
- IP Address is Not Enough to Identify Pirate, US Court of Appeals Rules — (.PDF)
- New EU Piracy Watchlist Targets Key Pirate Sites and Cloudflare — (.PDF)
- Domain Registrar Can be Held Liable for Pirate Site, Court Rules
- Reporting When Pirate Releases Hit The Internet is Apparently Illegal Now
- Swiss Copyright Law: Downloading Stays Legal, No Site Blocking
- List of websites blocked in the United Kingdom
- Major US ISPs Refuse to Discuss Repeat Infringer Policies
- Who Watches the Watchmen: Exploring Complaints on the Web
- British ISPs throw in the towel, give up sending out toothless copyright infringement warnings
2.04 Tor Fingerprint
∙ TOR Fingerprinting — https://blog.torproject.org/browser-fingerprinting-introduction-and-challenges-ahead
∙ Attacks on Tor — https://github.com/Attacks-on-Tor/Attacks-on-Tor
∙ EFF Test — https://coveryourtracks.eff.org/learn
2.06 Supply Chain Attack
• https://reproducible-builds.org
• https://github.com/SAP/risk-explorer-for-software-supply-chains
• https://github.com/ossillate-inc/packj
2.07 APT & Cybercriminal Campagin Collections
• https://github.com/CyberMonitor/APT_CyberCriminal_Campagin_Collections
2.08 Man In The Middle (MitM)
• https://github.com/frostbits-security/MITM-cheatsheet
• https://github.com/andreafortuna/MITMInjector
• https://github.com/KoreLogicSecurity/wmkick
• https://github.com/jakev/mitm-helper-wifi
• https://github.com/jakev/mitm-helper-vpn
2.09 Network Analysis (SIGINT)
• Snort — https://github.com/snort3
• Wireshark — https://www.wireshark.org
• NMAP — https://nmap.org
Live System Based
Security Onion Network Security Toolkit
2.10 Metadata
∙ ExifTool — https://github.com/exiftool/exiftool
∙ PhotoDNA — https://anishathalye.com/inverting-photodna
∙ Geo-tags — https://tool.geoimgr.com
2.12 Social Engineeringg (HUMINT)
- Social Engineering Fundamentals, Part I: Hacker Tactics, SecurityFocus
- Social Engineering Fundamentals, Part II: Combat Strategies, SecurityFocus
- Awesome Social Engineering — GitHub
- Social Engineer Toolkit — GitHub
${\color{Yellow}\textbf{PHONE SNIFFING}}$
• DEFCON Safe Mode - Cooper Quintin - Detecting Fake 4G Base Stations in Real-Time
https://www.youtube.com/watch?v=siCk4pGGcqA
• SRLabs - Warn you about threats like fake base stations (IMSI Catchers)
https://github.com/srlabs/snoopsnitch
• Android IMSI-Catcher Detector (suspended)
https://github.com/CellularPrivacy/Android-IMSI-Catcher-Detector
• Telecom Exploits - Signalling System 7 (SS7)
https://github.com/SigPloiter/SigPloit
• Telecom Exploits - HLR Lookups
https://github.com/SigPloiter/HLR-Lookups
Useful Websites
— OpenCellID — Link
— Cell Tower Locator (Cell2GPS) — Link
— Cell Phone Trackers — Link
— International Numbering Plans — Link
— GSM World Coverage Map and GSM Country List — Link
— Imei Info — https://www.imei.info
— GSMArena Phones Ref.- https://www.gsmarena.com
— Phonescoop Phones Ref.- https://www.phonescoop.com
— Cell Towers — https://opencellid.org
Information & Explanations
— IMSI-catcher — Link
— GSM frequency bands — Link
— List of software-defined radios — Link
Useful Apps
— Mobile Software
— AIMSICD — Link
— SnoopSnitch — Link
— Desktop Software
— GsmEvil 2 — Link
— IMSI-catcher — Link
Equipment
GSM 900 / GSM 1800 MHz are used in most parts of the world: Europe, Asia, Australia, Middle East, Africa. GSM 850 / GSM 1900 MHz are used in the United States, Canada, Mexico and most countries of S. America.
— SDR
— RTL-SDR (65MHz-2.3GHz) — Link
— Antenna
— Antenna — Link
Equipment
— Catching IMSI Catchers — Link
GSM Sniffing Install/Setup Guide
Install
$ sudo apt install python3-numpy python3-scipy python3-scapy gr-gsm $ git clone https://github.com/Oros42/IMSI-catcher && cd IMSI-catcher $ sudo grgsm_livemon && python3 simple_IMSI-catcher.py --sniff
GSM Install Error? Try this!
$ sudo apt-get install -y \ cmake \ autoconf \ libtool \ pkg-config \ build-essential \ docutils \ libcppunit-dev \ swig \ doxygen \ liblog4cpp5-dev \ gnuradio-dev \ gr-osmosdr \ libosmocore-dev \ liborc-0.4-dev \ swig $ gnuradio-config-info -v
Tips
$ sudo grgsm_scanner -l # List your SDR connected. $ sudo grgsm_scanner # Scan for cell towers near you. $ sudo grgsm_livemon # Live radio scanning.
${\color{Green}\textbf{BRUTE FORCE ATTACKS}}$
Brute Force Attacks
The speed at which your password is cracked depends on the entropy of your password and the power of the computer.
Computer programs used for brute force attacks can check anywhere from 10,000 to 1 billion passwords per second. A Pentium 100 can try 10.000 passwords a second. A supercomputer can try 1.000.000.000 per second.
Complex sheet:
Simplified sheet:
Types of brute force attacks
Simple Brute Force Attack
The attacker relies on trying out commonly used, weak passwords such as 123456, qwerty, admin, changeme, qazwsxedc etc.
Dictionary attack
Software that can make thousands of guesses every second using dictionary databases, hence the name of the attack.
Hybrid Brute Force Attack
A hybrid attack is utilized once the attacker already knows the username of its prey.
Reverse Brute Force Attack
A reverse brute force attack requires the attacker to know the password beforehand and then attempt to guess the username.
Credential stuffing
Hackers can get entire databases of stolen login credentials and then try to apply them to the account they’re trying to access. This kind of attack can be especially devastating if the attacked user reuses passwords across multiple accounts.
Rainbow Table Attack
A rainbow table attack is a method of password cracking that employs rainbow tables to break the password hashes in a database. Websites or apps don’t store passwords in plain text; instead, they encrypt passwords with hashes. Once the password is used for logging in, it is immediately converted to a hash. The next time the user logs in using their passwords, the server checks whether the password matches the previously created hash. If the two hashes match, the user is then authenticated. The tables used to store password hashes are known as rainbow tables.
Multi Factor Authenticator (MFA) or Two-factor Authenticator (2FA)
Set up MFA whenever possible, It's an extra layer of security that requires additional steps to verify the user's identity.
Encryption workarounds:
- Find the key.
- Guess the key.
- Compel the key.
- Exploit a flaw in the encryption software.
- Access plaintext while the device is in use.
- Locate another plaintext copy.
Sites of Interest
- https://www.cve.org
- https://www.cvedetails.com
- https://www.openwall.com
- https://www.lkrg.org
- https://www.attack.mitre.org
- https://www.exterro.com
- https://www.forensicfocus.com
- https://www.forensicscijournal.com
- https://www.hackthebox.com
- https://www.hackerone
- https://www.hackread.com
- https://www.htcia.org
- https://www.osforensics.com
- https://www.magnetforensics.com
- FTK Lite
- SSAC Publications
- Botnets as a Vehicle for Online Crime — CERT
- Security Audit
- SANS Institute
- Internet Storm Center — SANS Institute
- COAST Hotlist: Computer Security, Law and Privacy — CERIAS, Purdue University
General Publications
• CVE Alerting Platform
https://github.com/opencve/opencve
• The Hacker News — Newsletter
https://thehackernews.com/#email-outer
• Forensic Focus — Newsletter
https://www.forensicfocus.com
• SANS Institute — Newsletter
https://www.sans.org>
• Google Scholar — Alerts
osgeolive-doc-readthedocs-io-en-stable
https://scholar.google.com/scholar_alerts?view_op=list_alerts&hl=en-US
• Secure List
https://securelist.com
• Debian Security Announce
https://lists.debian.org/debian-security-announce
• Wired News
https://www.wired.com
• ZDnet
https://www.zdnet.com
• Cert Coordination Center
https://www.cert.org
• DoD Instructions Cybersecurity
https://www.esd.whs.mil/dd/
• Computer World
https://computerworld.com
• InfoWorld
https://www.infoworld.com
• InformationWeek
https://www.informationweek.com
• Sophos
https://sophos.com
• TechWorld
https://www.techworld.com
• Infosec Institute
https://resources.infosecinstitute.com
• Government Executive Magazine
https://govexec.com
• E Security Planet
https://www.esecurityplanet.com
• Help Net Security
https://www.helpnetsecurity.com
• Information Security Magazine
https://searchsecurity.techtarget.com
• Network World Fusion
https://www.nwfusion.com
• Federal Computer Week Security News
https://fcw.com/Home.aspx
• Government Computer News IT Security
https://gcn.com/Home.aspx
• IA Technology Analysis Center
https://iac.dtic.mil/csiac
• Overseas Security Advisory Council
https://www.osac.gov
• SANS Internet Storm Center
https://isc.sans.edu
• Search Security
https://searchsecurity.techtarget.com
• News Factor
https://www.newsfactor.com
• Security Focus
https://www.securityfocus.com/news
• New Scientist
https://www.newscientist.com/section/news
• Silicon Valley
https://www.siliconvalley.com
• USA Today
https://www.usatoday.com/tech
• Reuters
https://www.reuters.com/news/technology
• TechWeb
https://www.techweb.com
Forensic Publications
• Make a Google Scholar search from an interesting subject that you want to follow up on.
• Search paramters example:
police hacking intext:ilegal intext:abusive intext:law
• You could set keywords alerts: https://scholar.google.com/scholar_alerts?view_op=list_alerts
• Science Direct — Forensic Science International: Digital Investigation
https://www.sciencedirect.com/journal/forensic-science-international-digital-investigation
• Science Direct — Computer Law & Security Review
https://www.sciencedirect.com/journal/computer-law-and-security-review
• Forensic Science — Application of science to criminal and civil laws
https://www.forensicscijournal.com
• University of London - SAS Open Journals - Digital Evidence and Electronic Signature Law Review
https://journals.sas.ac.uk/deeslr/
• IEEE Intelligence and Security Informatics (IEEE-ISI)
https://ieee-isi.org
• USENIX Conferences
https://www.usenix.org/conferences
• International Journal of Intelligence and CounterIntelligence
https://www.tandfonline.com/journals/ujic20
• Information Security Journal: A Global Perspective
https://www.tandfonline.com/journals/uiss20
• Policing and Society — An International Journal of Research and Policy
https://www.tandfonline.com/journals/gpas20
• Police Practice and Research — An International Journal
https://www.tandfonline.com/journals/gppr20
• Journal of Applied Security Research
https://www.tandfonline.com/journals/wasr20
• Information Systems Security
https://www.tandfonline.com/journals/uiss19
• Journal of Computer Information Systems
https://www.tandfonline.com/journals/ucis20
• Australian Journal of Forensic Sciences
https://www.tandfonline.com/journals/tajf20
• Advancing Technology, Research and Collaboration
https://www.acm.org/conferences
• The APWG Symposium on Electronic Crime Research (APWG eCrime)
https://ecrimeresearch.org
• Communications in Computer and Information Science — Springer
https://www.springer.com/series/7899
Intelligence, Conflict, and Warfare Publications
• Taylor & Francis - Intelligence and National Security - Open access articles
https://www.tandfonline.com/action/showOpenAccess?journalCode=fint20
• The Journal of Intelligence, Conflict, and Warfare
https://journals.lib.sfu.ca/index.php/jicw/issue/archive
• CIA.gov - Center for the study of intelligence
https://www.cia.gov/resources/csi/studies-in-intelligence
• DCAF - Geneva Centre for Security Sector Governance
https://www.dcaf.ch/resources?type=publications
• E-International Relations - Open access scholarly books
https://www.e-ir.info/publications
• Springer Open
https://www.springeropen.com
• RIEAS
https://rieas.gr
Law Publications
• Necessary and Proportionate - https://www.necessaryandproportionate.org
• Privacy International - https://www.privacyinternational.org
• EFF - https://www.eff.org
• EPIC - https://epic.org/issues/surveillance-oversight
• Citizenlab - https://citizenlab.ca
• Bugged Planet - http://buggedplanet.info • BBW - https://bigbrotherwatch.org.uk
• Bad Internet Bills - https://www.badinternetbills.com
• Software Freedom Law Center - https://softwarefreedom.org
• UN Internet Governance Forum - https://www.intgovforum.org
• The IT Law Wiki - https://itlaw.fandom.com
• Computer Crime Research Center - https://www.crime-research.org
• Internet Crime Complaint Center (IC3) - https://www.ic3.gov/Home/AnnualReports
• ETSI - https://www.etsi.org/committees
• The Bureau of Investigative Journalism - https://www.thebureauinvestigates.com
https://www.fbi.gov
https://www.justice.gov/news
https://www.justice.gov/criminal/cybercrime
https://www.coe.int/en/web/cybercrime
https://www.sherloc.unodc.org
https://www.enisa.europa.eu
https://csrc.nist.gov
https://openyls.law.yale.edu
https://scholarship.law.duke.edu
https://law.utexas.edu/transnational/foreign-law-translations
https://www.computerweekly.com
https://www.vice.com/en/section/tech
https://copsincyberspace.wordpress.com
YouTube Conferences
https://www.youtube.com/@BlackHatOfficialYThttps://www.youtube.com/@DEFCONConference
https://www.youtube.com/@mediacccde
https://www.youtube.com/@DFRWS
https://www.youtube.com/@SANSForensics
https://www.youtube.com/@SANSOffensiveOperations
https://www.youtube.com/@RSAConference
https://www.youtube.com/@USENIXEnigmaConference
https://www.youtube.com/@DebConfVideos
https://www.youtube.com/@hitbsecconf
https://www.youtube.com/@44contv
https://www.youtube.com/@OffensiveCon
https://www.youtube.com/@secwestnet
https://www.youtube.com/@EkopartyConference
https://www.youtube.com/@reconmtl
https://www.youtube.com/@TROOPERScon
https://www.youtube.com/@MCH2022NL
https://www.youtube.com/@ntalOutlaw
https://www.youtube.com/@Seytonic
https://www.youtube.com/@DoingFedTime
https://www.youtube.com/@UsenixOrg
Others
• Computer Incident Response Center for Civil Society - https://www.civicert.org
https://eforensicsmag.com
https://0x00sec.org
https://csrc.nist.gov/projects
https://www.cisa.gov/news-events/cybersecurity-advisories
https://www.nsa.gov/Press-Room/Press-Releases-Statements
https://www.nsa.gov/ia/mitigation_guidance/security_configuration_guides/index.shtml
https://malware.lu
https://securelist.com
https://oval.mitre.org
https://www.w3.org/Security/Faq/www-security-faq.html
https://www.nowsecure.com
https://www.htcia.org
https://www.reddit.com/r/InfoSecNews
https://www.reddit.com/r/digitalforensics
https://www.reddit.com/r/computerforensics
https://www.reddit.com/r/antiforensics
https://www.reddit.com/r/Smartphoneforensics
https://github.com/yeahhub/Hacking-Security-Ebooks
https://github.com/InfoSecIITR/reading-material



