Max

8 responses to “Beat EnCase File Signature Analysis on a Windows System”

  1. I guess if you think about it, what else can encase do ya no?

  2. Now why would you want to do anything on this website unless you were a criminal!?

    minelab excalibur 1000

  3. The best way to detect file types with high accuracy is to develop additional methods for creating comparable signatures/hashes of files and confirming the results with mini interpreters. This is how we see past tricks like the simple addition of “MZ” at the beginning of a file.

  4. Excalibur ii 1000, I’ll answer…

    For sensitive company information, we create a Truecrypt block volume on a device, create a hidden volume within that, with the datasets recorded being truecrypt containers with hidden volumes.

    Being that we send analysis data to “hostile” countries (Such as China, Vietnam, America) where data interception by those governments is high – using this method to encrypt TB’s of data on a HDD is valuable indeed.

    We have, over the past 12 monhts, “lost” 30-35 disks in international mail-handling system – luckily, those who have stolen these will not recover anything! This keeps our IP safe….

    We aren’t doing anything illegal – (except for Veitnam, where any disk encryption is illegal) but we’ve never had any issues with “lost” disks there..

  5. This is a great response Chris and the reasons you have given are very solid. Thank you for commenting on this topic.

  6. There is one thing I did not see mentioned (maybe I missed it). This makes that file unusable until you correct the bytes that you changed. So, you need to mask the header to hide, but unmask to use, then mask again to hide.

    I wonder why anyone would go through this hassle when you can hide data within a Truecrypt volume, or heck, even a hidden Truecrypt volume. That is a much easier solution, and investigators cannot do anything about it without the password.

    By the way, EnCase has progressed 2 major versions beyond that hacked version in your screen shots.

  7. Yes, depending on what type of file and the type of data and the type of OS accessing the data performing this type of data manipulation can render the file useless.

    There are plenty of articles throughout the rest of the site on using TrueCrypt as well. You are very correct in saying that if someone has data that they feel they need to hide or mask then they probably aren’t going to do something tedious like this, but this is not the point of the article.

    Yes, EnCase is into the version 6 series which I use as well, in fact I use all versions of EnCase going back to 3. This method exists throughout.

  8. Chris Ford, you should not have replied to excalibur ii 1000

    excalibur ii 1000 is a spamming bot, I have seen this kind of spam before, if you read again the one line sentence (it is usually a one line sentence), it is written in an ambigous way so that it can be posted at any blog, but that is not what gives it away, what gives “excalibur ii 1000″ is:

    1) Nickname is “excalibur ii 1000″, a commercial product

    2) “excalibur ii 1000″ has a signature link to, you guessed it “excalibur ii 1000″

    3) “excalibur ii 1000″ also links to his minelabexcalibur selling “excalibur ii 1000″

    I have no problem with people using their URL at all, but this is not a human being, this is a bot, whom obviously does not read the blog. I have seen spam like this a dozen times before, the traits are: always generic replies, one line sentence, a signature linking to a commercial product.

Leave a Reply

Archives