case examples on investigative techniques and intelligence ......•use a vpn (tor) at all times...

27
BOGDAN CIINARU | BANGKOK | 10.09.2019 Case Examples on Investigative Techniques and Intelligence Gathering

Upload: others

Post on 05-Sep-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

BOGDAN CIINARU | BANGKOK | 10.09.2019

Case Examples on Investigative Techniques and

Intelligence Gathering

Page 2: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note
Page 3: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

• Use a VPN (TOR) at all times when online.• Search widely, ba ck up and reinforce your findings• Make a note/ take copies of ALL evidence collected at the time of identification

(date): Screenprints Hyperlinks Website copies (Static/ video capture).• Record EVERYTHING that you provide to websites (pseudonyms) for future

reference and recall.• Understand the market (language, terminology, options...)• Lot of luck needed

Page 4: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

• Consistency - Criminals adopt an identity and keep it!• Confirm one identity – run checks on “ username “ elsewhere• Where possible, also consider ‘alternative spellings’:‘Bogdan123’‘B0gdan123’‘Bogdan_123’ ....

User Names

Page 5: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

VPN – Virtual Privat Network

• Hide your IP address

• Change your IP address

• Mask your location

• Encrypt data transfers

• Access blocked websites

Page 6: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

• Consider both current and historical registration domain records• Applicable date ranges of these periods• New leads - names, email addresses, telephone numbers, addresses• Site options:

Domain Tools (domaintools.com)Whoisology (whoisology.com)Domain History (domainhistory.net)

Domain Records – GDPR!?

Page 7: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

Terms and Conditions/ Disclaimer Pages

Contact details (including indication of geography) Affiliate companies Parent companies Phrasing used elsewhere online (compare and link)

• Interrogate for further information on:

Page 8: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

Payment Methods

• Proceed through mock check-out process• Use fake information to ‘analyse’• Do not complete!• Appropriate:

Check-out process Account summary

Page 9: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

BaiduBingAskAOLExciteYahooDogpileMetacrawlerGigablast…

Search Engines on internet

Page 10: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

WebMii :http://webmii.com

Pipl : https://pipl.com/

Peoplesearch : https://www.pplesearch.com/

Search People

15

Page 11: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

UK OSINT SOCIAL MEDIA SEARCH tool

http://www.uk-osint.net/facebook.html

Page 12: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note
Page 13: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note
Page 14: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note
Page 15: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note
Page 16: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

Geolocation

- Google maps (GPS) maps.google.com

- Maps (historical)

- Geolocation (IP address)

- https://www.iplocation.net

- http://www.infosniper.net

- https://www.openstreetmap.org

Page 17: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

EMAIL

http://www.lettermelater.com

http://www.emkei.cz

http://www.anonymouse.com

http://www.yandex.com

Page 18: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

https://www.ip-adress.com/trace-email-

address#result

Email header analyzer

Page 19: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

IMAGES FROM BROWSERS

Google Imagesimages.Google.com

Bingbing.com/images

Yandex (Russia)images.yandex.com

Baidu (Chinese)stu.baidu.com

Page 20: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

METADATA /IMAGES

Verexif (On-line Resource)Removes Exif data from an image.http://www.verexif.com/

Onlineocr (On-line Resource)Performs text recognition from an image or PDf and converts to Document (e.g. Doc, xls)https://www.onlineocr.net/

Free OCR (On-line Resource)Performs text recognition from an image with characters.www.free-ocr.com

FotoForensics (On-line Resource)Returns metadata, and among other features, checks if an image has been manipulated.http://fotoforensics.com/

Page 21: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

Stolencamerafinder (On-line Resource)By the image serial checks the origin of the camera, and search were are other photos taken by the camera.http://www.stolencamerafinder.co.uk/

Getghiro (Application)Application environment for forensic image analysis.http://www.getghiro.org/

METADATA /IMAGES

Page 22: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

Display Video Frames

https://www.youtube.com/watch?v=K9qSsb_1iyA

http://i.ytimg.com/vi/K9qSsb_1iyA/0.jpghttp://i.ytimg.com/vi/K9qSsb_1iyA/1.jpghttp://i.ytimg.com/vi/K9qSsb_1iyA/2.jpghttp://i.ytimg.com/vi/K9qSsb_1iyA/3.jpg

Reverse Videohttps://inteltechniques.com/menu.html

Metadatahttps://citizenevidence.amnestyusa.org

VIDEO

Page 23: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

https://osintframework.com/

Page 24: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

https://github.com/jivoi/awesome-osint

Page 25: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

IntelTechniques :

https://inteltechniques.com/index.html

Page 26: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

https://www.paterva.com/web7/downloads.php

Page 27: Case Examples on Investigative Techniques and Intelligence ......•Use a VPN (TOR) at all times when online. • Search widely, ba ck up and reinforce your findings • Make a note

Thank you for your attention!

Bogdan CÎINARUTel.: +31611782482

[email protected]