diff --git a/docs/approximate_matching.md b/docs/approximate_matching.md index 2f04e6701..c6d987f50 100644 --- a/docs/approximate_matching.md +++ b/docs/approximate_matching.md @@ -1,6 +1,6 @@ --- tags: - - No Category + - Articles that need to be expanded --- *Approximate matching* is a term used in computer forensics to mean that two objects have similar contents but are not identically the same. It @@ -8,16 +8,12 @@ replaced the previously used terms *similarity* and *fuzzy hashing.* The following two paragraphs are clearly similar but not identical: - **We the People** of the United States, in Order to form a more perfect Union, establish Justice, insure domestic Tranquility, provide for the common defence, promote the general Welfare, and secure the Blessings of Liberty to ourselves and our Posterity, do ordain and establish this Constitution for the United States of America. - - - **We the People** of the United States, in Order to form a more perfect Union, establish Justice, insure domestic Tranquility, provide for the common defense, promote the general Welfare, and secure the Blessings of @@ -28,11 +24,11 @@ Constitution for the United States of America. In forensics there are several kinds of similarity that are of interest: -1. Binary Similarity -2. Textual Similarity -3. Visual Similarity -4. Audible Similarity -5. Algorithmic (code) Similarity +1. Binary Similarity +2. Textual Similarity +3. Visual Similarity +4. Audible Similarity +5. Algorithmic (code) Similarity ### Binary Similarity @@ -44,8 +40,8 @@ have the commutative property. That is, BS(a,b) may not equal BS(b,a). There are several applications for a binary similarity function: -1. Determining that a master object is embedded in the target object. -2. Determining if the target object is derived from the target object. +1. Determining that a master object is embedded in the target object. +2. Determining if the target object is derived from the target object. The leading similarity systems in use are are: diff --git a/docs/assets/images/EF_adn.png b/docs/assets/images/EF_adn.png deleted file mode 100644 index 2f2200b81..000000000 Binary files a/docs/assets/images/EF_adn.png and /dev/null differ diff --git a/docs/assets/images/Ef_iccid.png b/docs/assets/images/Ef_iccid.png deleted file mode 100644 index 85dede7c0..000000000 Binary files a/docs/assets/images/Ef_iccid.png and /dev/null differ diff --git a/docs/assets/images/Ef_imsi.png b/docs/assets/images/Ef_imsi.png deleted file mode 100644 index 166b3e75e..000000000 Binary files a/docs/assets/images/Ef_imsi.png and /dev/null differ diff --git a/docs/assets/images/Ef_loci.png b/docs/assets/images/Ef_loci.png deleted file mode 100644 index 6b968efa8..000000000 Binary files a/docs/assets/images/Ef_loci.png and /dev/null differ diff --git a/docs/assets/images/Plmnsel.png b/docs/assets/images/Plmnsel.png deleted file mode 100644 index 3373dc7b2..000000000 Binary files a/docs/assets/images/Plmnsel.png and /dev/null differ diff --git a/docs/assets/images/Simcon.png b/docs/assets/images/Simcon.png deleted file mode 100644 index febe9787e..000000000 Binary files a/docs/assets/images/Simcon.png and /dev/null differ diff --git a/docs/assets/images/What_you_need.jpg b/docs/assets/images/What_you_need.jpg deleted file mode 100644 index f4ea80b3f..000000000 Binary files a/docs/assets/images/What_you_need.jpg and /dev/null differ diff --git a/docs/ewftools.md b/docs/ewftools.md index 3bf89c807..f76777965 100644 --- a/docs/ewftools.md +++ b/docs/ewftools.md @@ -1,5 +1,6 @@ --- tags: - - No Category + - Redirect --- -1. REDIRECT [Libewf](libewf.md) \ No newline at end of file + +_See: [libewf](libewf.md)_ diff --git a/docs/logical_volume_manager.md b/docs/logical_volume_manager.md index cfe8c5446..7c413aacb 100644 --- a/docs/logical_volume_manager.md +++ b/docs/logical_volume_manager.md @@ -1,6 +1,6 @@ --- tags: - - No Category + - Redirect --- -1. REDIRECT [Linux Logical Volume Manager - (lvm)](linux_logical_volume_manager_(lvm).md) \ No newline at end of file + +_See: [Linux Logical Volume Manager (lvm)](linux_logical_volume_manager_(lvm).md)_ diff --git a/docs/md5deep.md b/docs/md5deep.md index 7a9eb628a..de9d69eda 100644 --- a/docs/md5deep.md +++ b/docs/md5deep.md @@ -1,6 +1,6 @@ --- tags: - - No Category + - Tools --- **md5deep** is a suite of cross platform tools to compute and audit [hashes](hashing.md) for any number @@ -139,4 +139,4 @@ Here is an example: ## External Links * [Official website](https://md5deep.sourceforge.net/) -* [Wikipedia entry on md5deep](https://en.wikipedia.org/wiki/Md5deep) +* [Wikipedia: md5deep](https://en.wikipedia.org/wiki/Md5deep) diff --git a/docs/mobile_phone.md b/docs/mobile_phone.md index 0ff367692..c28182d71 100644 --- a/docs/mobile_phone.md +++ b/docs/mobile_phone.md @@ -1,5 +1,6 @@ --- tags: - - No Category + - Redirect --- -1. REDIRECT [Cell phones](cell_phones.md) \ No newline at end of file + +_See: [Cell phones](cell_phones.md)_ diff --git a/docs/mobile_phones.md b/docs/mobile_phones.md index 57e5f190f..c28182d71 100644 --- a/docs/mobile_phones.md +++ b/docs/mobile_phones.md @@ -1,5 +1,6 @@ --- tags: - - No Category + - Redirect --- -1. REDIRECT [Cell_phones](cell_phones.md) \ No newline at end of file + +_See: [Cell phones](cell_phones.md)_ diff --git a/docs/nickfile_format.md b/docs/nickfile_format.md index bbf4ce7e1..6a40a35db 100644 --- a/docs/nickfile_format.md +++ b/docs/nickfile_format.md @@ -1,5 +1,6 @@ --- tags: - - No Category + - Redirect --- -1. REDIRECT [Nickfile (nk2)](nickfile_(nk2).md) \ No newline at end of file + +_See: [Nickfile (nk2)](nickfile_(nk2).md)_ diff --git a/docs/nist.md b/docs/nist.md index 2a21cf0c7..476420c28 100644 --- a/docs/nist.md +++ b/docs/nist.md @@ -1,6 +1,6 @@ --- tags: - - No Category + - Redirect --- -1. REDIRECT [National Institute of Standards and - Technology](national_institute_of_standards_and_technology.md) \ No newline at end of file + +_See: [National Institute of Standards and Technology](national_institute_of_standards_and_technology.md)_ diff --git a/docs/ntfs.md b/docs/ntfs.md index ffb50b8fd..9617bf54a 100644 --- a/docs/ntfs.md +++ b/docs/ntfs.md @@ -1,6 +1,6 @@ --- tags: - - No Category + - Redirect --- -1. REDIRECT [New Technology File System - (ntfs)](new_technology_file_system_(ntfs).md) \ No newline at end of file + +_See: [New Technology File System (ntfs)](new_technology_file_system_(ntfs).md)_ diff --git a/docs/nuix.md b/docs/nuix.md index ad6217a5f..1e6db1acf 100644 --- a/docs/nuix.md +++ b/docs/nuix.md @@ -1,5 +1,6 @@ --- tags: - - No Category + - Redirect --- -1. REDIRECT [Nuix Pty Ltd](nuix_pty_ltd.md) \ No newline at end of file + +_See: [Nuix Pty Ltd](nuix_pty_ltd.md)_ diff --git a/docs/other_resources.md b/docs/other_resources.md deleted file mode 100644 index b8f27e91f..000000000 --- a/docs/other_resources.md +++ /dev/null @@ -1,6 +0,0 @@ ---- -tags: - - No Category ---- -1. REDIRECT [Educational Resources for Teaching Computer - Forensics](educational_resources_for_teaching_computer_forensics.md) \ No newline at end of file diff --git a/docs/physical_memory.md b/docs/physical_memory.md index b436ca73d..7d992eec0 100644 --- a/docs/physical_memory.md +++ b/docs/physical_memory.md @@ -1,7 +1,7 @@ --- tags: - - Hardware - - Memory + - Hardware + - Memory --- **Physical memory** is the **Random Access Memory**, or **RAM**, used by the computer. By [imaging](tools_memory_imaging.md) the physical @@ -13,4 +13,4 @@ operating system and of the programs running on the computer. - [Tools:Memory Imaging](tools_memory_imaging.md) - [Memory Imaging](memory_imaging.md) -- [Memory analysis](memory_analysis.md) \ No newline at end of file +- [Memory analysis](memory_analysis.md) diff --git a/docs/property_list.md b/docs/property_list.md index 41edb81c2..a4232364b 100644 --- a/docs/property_list.md +++ b/docs/property_list.md @@ -1,5 +1,6 @@ --- tags: - - No Category + - Redirect --- -1. REDIRECT [Property list (plist)](property_list_(plist).md) \ No newline at end of file + +_See: [Property list (plist)](property_list_(plist).md)_ diff --git a/docs/ram.md b/docs/ram.md index 441f3e4c9..05ef7e37a 100644 --- a/docs/ram.md +++ b/docs/ram.md @@ -1,5 +1,6 @@ --- tags: - - No Category + - Redirect --- -1. REDIRECT [Physical memory](physical_memory.md) \ No newline at end of file + +_See: [Physical memory](physical_memory.md)_ diff --git a/docs/real_cases.md b/docs/real_cases.md index c6b1967f7..f2316bf59 100644 --- a/docs/real_cases.md +++ b/docs/real_cases.md @@ -1,6 +1,6 @@ --- tags: - - No Category + - Redirect --- -1. REDIRECT [Famous Cases Involving Digital - Forensics](famous_cases_involving_digital_forensics.md) \ No newline at end of file + +_See: [Famous Cases Involving Digital Forensics](famous_cases_involving_digital_forensics.md)_ diff --git a/docs/rim_blackberry.md b/docs/rim_blackberry.md index 92e7efd1a..aec244ca0 100644 --- a/docs/rim_blackberry.md +++ b/docs/rim_blackberry.md @@ -1,5 +1,6 @@ --- tags: - - No Category + - Redirect --- -1. REDIRECT [BlackBerry](blackberry.md) \ No newline at end of file + +_See: [BlackBerry](blackberry.md)_ diff --git a/docs/sha1deep.md b/docs/sha1deep.md index a44c24bbf..699814287 100644 --- a/docs/sha1deep.md +++ b/docs/sha1deep.md @@ -1,5 +1,6 @@ --- tags: - - No Category + - Redirect --- -1. REDIRECT [md5deep](md5deep.md) \ No newline at end of file + +_See: [md5deep](md5deep.md)_ diff --git a/docs/sim_forensics.md b/docs/sim_forensics.md index 0d78142f0..bbc109dc8 100644 --- a/docs/sim_forensics.md +++ b/docs/sim_forensics.md @@ -1,215 +1,6 @@ --- tags: - - Articles that need to be expanded - - Mobile + - Redirect --- -*Under Construction* -The [SIM Card](sim_cards.md) is the basic memory device inside of -many mobile phones in use today. This small piece of hardware has been -key to solving many cases in the world of [SIM Card -Forensics](sim_card_forensics.md). However, without the proper -knowledge of the SIM card's filesystem, the user will be missing out on -all the valuable information the SIM Card holds. - -## Getting Started - - - - -This is a list of items to get you started on reading SIM Cards and -their information: - -1. [Windows](windows.md) operating system -2. [SIMCon](simcon.md)[1](https://www.simcon.no/) - - Program used to read SIM Cards -3. SIM Cards -4. SIM Card Reader - -## Quick Guide for SIMCon - -1. Make sure the SIM Card Reader with SIM Card is connected -2. Open [SIMCon](simcon.md) -3. Click File \> Read SIM or Click - simcon in the upper left corner of [SIMCon](simcon.md) - -4. Click OK when the next dialog box pops up - - **Note**, some SIM cards are locked. This is where the PIN needs - to be entered if known. - - If the PIN is unknown, the SIM cannot be read. -5. Click OK again when the next dialog box pops up - -## Definitions - -### MF - -- Only **one** MF -- The Master File (MF) -- Root of the SIM Card file system -- Equivalent to the root directory or "/" in the Linux filesystem - -### DF - -- Dedicated Files (DF) -- Equivalent to a folder in a Windows/Linux filesystem -- Usually three DF's - - DF_GSM / DF_DCS1800 / DF_TELECOM - -#### DF_DCS1800 / DF_GSM - -- Contains network related information -- Specifying data in DF_GSM writes only to DF_GSM on the SIM -- The SIM is expected to mirror GSM and DCS1800 - -#### DF_TELECOM - -- Contains the service related information - -### EF - -- Elementary Files (EF) -- Holds one to many records -- Represent the leaf node of the filesystem -- EF's sit below the DF's in the filesystem hierarchy - -### PLMN - -- Public Land Mobile Network - - A PLMN is a network that is established and operated by an - administration or by a recognized operating agency (ROA) for the - specific purpose of providing land mobile telecommunications - services to the public. - [2](https://en.wikipedia.org/wiki/Public_land_mobile_network) - -### LAI - -- Location Area Identity - - Each location area of a public land mobile network (PLMN) has its - own unique identifier which is known as Location Area Identity - (LAI). [3](https://en.wikipedia.org/wiki/Location_Area_Identity) - -## Filesystem - -### EF_ICCID - -This displays the ID or Card Identity of the SIM Card, this can also be -found on the SIM card itself. - - - - - - - - - - - - - ----- - -### DF_GSM - -#### EF_IMSI - -- International Mobile Subscriber Identity - (IMSI)[4](https://en.wikipedia.org/wiki/IMSI) -- 310 - 260 - 653235860 -- MCC - MNC - MSIN - - MCC[5](https://en.wikipedia.org/wiki/List_of_mobile_country_codes) (3 - Digits) - - Mobile Country Code - - MNC[6](https://en.wikipedia.org/wiki/Mobile_Network_Code) (2 Digits - EU / 3 Digits NA) - - Mobile Network Code - - MSIN[7](https://en.wikipedia.org/wiki/MSIN) (Remaining Digits) - - Mobile Subscription Identification Number - - Within the network's customer base - -
- - -
- - - - - - - - - - ----- - -#### EF_PLMNSEL - -- List of all PLMN's - [Sim_Filesystem#PLMN](sim_forensics.md#plmn) - -
- - -
- - - - - - - - - - ----- - -#### EF_LOCI - -- Location Information - - Contains Location Area Identity - [Sim_Filesystem#LAI](sim_forensics.md#lai) - - LAI Network Code - [Sim_Filesystem#PLMN](sim_forensics.md#plmn) / - [Sim_Filesystem#LAI](sim_forensics.md#lai) - -
- - -
- - - - - - - - - - ----- - -### DF_TELECOM - -#### EF_ADN - -EF_adn.png - - - - - - - - - - - ----- +_See: [SIM Card Forensics](sim_card_forensics.md)_ diff --git a/docs/simcon_help.md b/docs/simcon_help.md index 7ab1f0106..74611078a 100644 --- a/docs/simcon_help.md +++ b/docs/simcon_help.md @@ -1,5 +1,6 @@ --- tags: - - No Category + - Redirect --- -1. REDIRECT [SIM_Forensics](sim_forensics.md) \ No newline at end of file + +_See: [SIMCon](simcon.md)_ diff --git a/docs/similarity_functions.md b/docs/similarity_functions.md index 13b693be4..4f9a8f5b8 100644 --- a/docs/similarity_functions.md +++ b/docs/similarity_functions.md @@ -1,5 +1,6 @@ --- tags: - - No Category + - Redirect --- -1. REDIRECT [Approximate Matching](approximate_matching.md) \ No newline at end of file + +_See: [Approximate Matching](approximate_matching.md)_