To overcome the need for investigators to travel far and wide to gather evidence from infected computers after a cyberattack, a Kaspersky Lab expert has developed a simple tool that can remotely collect vital data without risk of its contamination or loss. Named BitScout, the tool can build a swiss-army knife for the remote forensic investigation of live systems and has been made freely available for all investigators to use.

 

In most cyberattacks, legitimate owners of compromised systems fall victim to unidentified perpetrators. Victims usually agree to cooperate and help security researchers find the infection vector or other details about the attackers.

 

However, it is a longstanding concern among forensic researchers that the need to travel long distances to collect crucial evidence such as malware samples from infected computers can result in expensive and delayed investigations.

The longer it takes for an attack to be understood, the longer it is before users are protected and perpetrators identified. However, the alternatives have either involved expensive tools and a knowledge of how to operate them, or the risk of contaminating or losing evidence by moving it between computers.

 

To solve the problem, Vitaly Kamluk, Director of Kaspersky Lab’s Global Research and Analysis Team in Asia Pacific (APAC) has created an open-source digital tool that can remotely collect key forensic materials, acquire full disk images via the network or locally attached storage, or simply remotely assist in malware incident handling.

 

Evidence data can be viewed and analyzed remotely or locally while the source data storage remains intact through reliable container-based isolation.

 

“The need to analyze security incidents as efficiently and swiftly as possible is increasingly important, as adversaries grow ever more advanced and stealthy. But speed at all costs is not the answer either – we need to ensure evidence is untainted so that investigations are trusted and results can be qualified for use in court if required. I couldn’t find a tool that allowed us to achieve all of this, freely and easily – so I decided to build one,” said Vitaly Kamluk.

 

Kaspersky Lab experts work closely with law enforcement agencies across the world to help in the technical analysis of cyber investigations. This gives them a unique insight into the challenges LEA personnel face when fighting modern cybercrime.

 

The cybersecurity landscape is now so complex and sophisticated that investigators need tools that can adapt and scale to the demands of the job. BitScout is a good example of this. It can be adjusted to the particular needs of an investigator, and improved and upgraded with additional features and custom software.

 

Most importantly it comes free of charge, based on open-source solutions and is fully transparent: instead of relying on third party tools with proprietary code, experts can use the Bitscout open-source code to build their own swiss-army knife for digital forensics.

 

The list of BitScout features includes:

●Disk image acquisition even with un-trained staff

●Training people on the go (shared view-only terminal session)

●Transferring complex pieces of data to your lab for deeper inspection

●Remote Yara or AV scanning of offline systems (essential against rootkits)

●Search and view registry keys (autoruns, services, plugged USB devices)

●Remote file carving (recovering deleted files)

●Remediation of the remote system if access is authorized by the owner

●Remote scanning of other network nodes (useful for remote incident response)

 

The tool is freely available at the GitHub code repository: https://github.com/vitaly-kamluk/bitscout

 

Read more on Securelist.com.


RECOMMENDED ARTICLE FOR TECHWORLD


 
DJI Develops Option for Pilots to Fly Without Internet Data Transfer
Techworld Date Posted: 16 August 2017 3:00 PM | 233 Views
DJI, the world's leader in civilian drones and aerial imaging technology, is developing a new local data mode that stops internet traffic to and from its flight control apps, in order to provide enhanced.... See More
 
DJI Develops Option for Pilots to Fly Without Internet Data Transfer
Techworld Date Posted: 3:00 PM | 233 Views
DJI, the world's leader in civilian drones and aerial imaging technology, is developing a new local data mode that stops internet traffic to and from its flight control apps, in order to provide enhanced...See More

 
Kaspersky Lab Moving Core Infrastructure from Russia to Switzerland; Opening First Transparency Center
Techworld Date Posted: 16 May 2018 3:56 PM | 506 Views
As part of its Global Transparency Initiative, Kaspersky Lab is adapting its infrastructure to move a number of core processes from Russia to Switzerland.. See More
 
Kaspersky Lab Moving Core Infrastructure from Russia to Switzerland; Opening First Transparency Center
Techworld Date Posted: 3:56 PM | 506 Views
As part of its Global Transparency Initiative, Kaspersky Lab is adapting its infrastructure to move a number of core processes from Russia to Switzerland.See More

PC Buyers Guide
Kaspersky Lab named a Champion in Canalys Leadership Matrix for APAC in Q1 2018
Techworld • By: PC Buyers Guide | Date Posted: 26 March 2018 4:16 PM | 315 Views
Kaspersky Lab has been positioned in the Champions quadrant of the Canalys Leadership Matrix for Asia Pacific in 2018. As a Champion, Kaspersky lab achieved the highest scores from its partners in 10 areas.... See More
PC Buyers Guide
Kaspersky Lab named a Champion in Canalys Leadership Matrix for APAC in Q1 2018
Techworld • By: PC Buyers Guide | Date Posted: 4:16 PM | 315 Views
Kaspersky Lab has been positioned in the Champions quadrant of the Canalys Leadership Matrix for Asia Pacific in 2018. As a Champion, Kaspersky lab achieved the highest scores from its partners in 10 areas...See More

PCBG Contributing Writer
The Race to 64-bit
Techworld • By: PCBG Contributing Writer | Date Posted: 3 March 2018 8:47 AM | 131 Views
When you install an OS, sometimes the installer would say something along the lines of “Your architecture does not support this operating system” and would prompt you to install another. See More
PCBG Contributing Writer
The Race to 64-bit
Techworld • By: PCBG Contributing Writer | Date Posted: 8:47 AM | 131 Views
When you install an OS, sometimes the installer would say something along the lines of “Your architecture does not support this operating system” and would prompt you to install anotherSee More

 
SAP Launches Youth Enablement Program in Southeast Asia
Techworld Date Posted: 16 September 2017 9:43 AM | 192 Views
SAP SE (NYSE: SAP) today announces the launch of its flagship program for young talents, SAP's Young Professional Program (YPP), in Southeast Asia. Developed by the SAP Training and Development Institute (SAP TDI), this.... See More
 
SAP Launches Youth Enablement Program in Southeast Asia
Techworld Date Posted: 9:43 AM | 192 Views
SAP SE (NYSE: SAP) today announces the launch of its flagship program for young talents, SAP's Young Professional Program (YPP), in Southeast Asia. Developed by the SAP Training and Development Institute (SAP TDI), this...See More

 
ASUS Republic of Gamers Announces Strix XG27VQ
Techworld Date Posted: 23 August 2017 1:10 PM | 211 Views
ROG Strix XG27VQ is a Full HD display with an ultrafast 144Hz refresh rate and features ASUS-exclusive Extreme Low Motion Blur and Adaptive-Sync (FreeSyncTM) technologies for gameplay without tearing and stuttering. Its gaming-inspired design.... See More
 
ASUS Republic of Gamers Announces Strix XG27VQ
Techworld Date Posted: 1:10 PM | 211 Views
ROG Strix XG27VQ is a Full HD display with an ultrafast 144Hz refresh rate and features ASUS-exclusive Extreme Low Motion Blur and Adaptive-Sync (FreeSyncTM) technologies for gameplay without tearing and stuttering. Its gaming-inspired design...See More

 
SILVERSTONE TECHNOLOGY LAUNCHES 2018 PRODUCT LINE
Techworld Date Posted: 4 May 2018 3:22 PM | 341 Views
SilverStone Technology Co., Ltd. (SST), one of the biggest designers and manufacturers of computer parts and accessories in the world introduces their 2018 product line in the Philippines with a Launch Party for its.... See More
 
SILVERSTONE TECHNOLOGY LAUNCHES 2018 PRODUCT LINE
Techworld Date Posted: 3:22 PM | 341 Views
SilverStone Technology Co., Ltd. (SST), one of the biggest designers and manufacturers of computer parts and accessories in the world introduces their 2018 product line in the Philippines with a Launch Party for its...See More

 
TRIAL and ERROR: Kaspersky Lab Unearths iOS Cryptomining Attacks, Careless Mistakes by Roaming Mantis
Techworld Date Posted: 24 September 2018 4:57 PM | 119 Views
Just five months after Kaspersky Lab’s first report on the DNS hijacking operation to infect Android smartphones in Asia, the attack dubbed ‘Roaming Mantis’ remains highly active, exploring new tricks and techniques to extend.... See More
 
TRIAL and ERROR: Kaspersky Lab Unearths iOS Cryptomining Attacks, Careless Mistakes by Roaming Mantis
Techworld Date Posted: 4:57 PM | 119 Views
Just five months after Kaspersky Lab’s first report on the DNS hijacking operation to infect Android smartphones in Asia, the attack dubbed ‘Roaming Mantis’ remains highly active, exploring new tricks and techniques to extend...See More

 
Say Goodbye to Dead Spots at Home and Say Hello to Google WiFi! PLDT Teams Up with Google to Give You the Strongest and Seamless Connections at Home
Techworld Date Posted: 25 October 2018 2:32 PM | 136 Views
Nothing ruins an online experience like an interrupted connection. Whether you’re streaming the final episode of your favorite series, uploading an important file to make a deadline or video calling with your bestfriend abroad,.... See More
 
Say Goodbye to Dead Spots at Home and Say Hello to Google WiFi! PLDT Teams Up with Google to Give You the Strongest and Seamless Connections at Home
Techworld Date Posted: 2:32 PM | 136 Views
Nothing ruins an online experience like an interrupted connection. Whether you’re streaming the final episode of your favorite series, uploading an important file to make a deadline or video calling with your bestfriend abroad,...See More

 
Philippine Robotics Team Awarded to Compete Globally
Techworld Date Posted: 24 August 2018 4:33 PM | 135 Views
Various schools across the country will represent the Philippines at the World Robotics Olympiad 2018 (WRO 2018) happening on November 15 to 19 in Chiang Mai, Thailand, after being proclaimed as winners of the.... See More
 
Philippine Robotics Team Awarded to Compete Globally
Techworld Date Posted: 4:33 PM | 135 Views
Various schools across the country will represent the Philippines at the World Robotics Olympiad 2018 (WRO 2018) happening on November 15 to 19 in Chiang Mai, Thailand, after being proclaimed as winners of the...See More


Power by

Download Free AZ | Free Wordpress Themes