Skip to content

Open source cyber forensics challenge for middle and high school students interested in STEM

License

Notifications You must be signed in to change notification settings

secforks/cyber-forensics-challenge

Repository files navigation

Cyber Forensics Challenge

Designed as a introduction into cyber forensic investigations for middle and high school students interested in STEM. This activity employes the PBED process:

  • Plan
  • Brief
  • Execute
  • De-brief

Teams of 4-5 students will be established and receive the in-brief (CFC-InBriefing.pptx). In-brief will explain the importance of evidence collection, cateloging, and integrity. Finally, the challenge scenario will be outlined. Teams will have 15 minutes to properly handle, log, and analyze the evidence package.

Requirements

  • Small laptop or Chromebook (Chromebook requires Developer Mode) as seized evidence
  • Small laptop or Chromebook as investigators system (Advanced Challenge)
  • USB write blocker (Advanced Challenge)
  • Media card reader (Advanced Challenge)
  • Camera (Advanced Challenge)
  • Clothing to include
    • polo
    • pants w/ belt
    • vest
    • headgear
    • t-shirt
  • USB drives x2
  • SD card
  • Pen that can hold a piece of paper
  • LED penlight with batteries
  • strips of paper with passwords

Chromebook setup

  1. Power on chromebook and press ESC + Refresh (F3) + Power button
  2. Once recovery mode screen is up, press Ctrl + Alt + D, then Enter
  3. Press Ctrl + Alt + D again to start Developer Mode
  4. Login to the chromebook
  5. Press Ctrl + Alt + T
  6. Type "shell"
  7. Type "cd ~/Downloads"
  8. Type "wget https://github.com/jknyght9/CyberForensicsChallenge/blob/master/cfc-chromebook-setup1.sh"
  9. Type "sudo sh cfc-chromebook-setup1.sh"
  10. Once the installation is finished enter "pete" as the user
  11. Enter the login password in "CFC-Forms_answers"
  12. Login to the Ubuntu Linux system
  13. Open a terminal
  14. Type "sudo sh ~/Downloads/cfc-guest-setup2.sh"
  15. Go through the VeraCrypt installation process
  16. Type "history -c" to remove all history
  17. Enter Ctrl + Alt + L to lock the screen

Challenge Setup

  1. Copy all items in "SD card" folder onto blank SD card
  2. Copy all items in "USB Drive 1" folder onto blank USB drive
  3. Copy all items in "USB Drive 2" folder onto blank USB drive
  4. Copy the veracrypt file from the "TC Volume" onto the laptop
  5. Copy the laptop login onto a piece of paper
  6. Copy half of the veracrypt volume password on one piece of paper and write on the other side "1"
  7. Copy the other half of the veracrypt volume password on another piece of paper and write on the other side "2"
  8. Choose other items that maybe found on a person
  9. Place items into various places of the clothing
  10. Give teams a blank version of the challenge form
  11. Give judges a black form of the judge form
  12. Fill out a chain of custody form with a simulated case number, date/time seized, location, case officer, and first line of the chain of custody form
  13. Place all simulated evidence and chain of custody form in a bag or box
  14. Begin challenge

Basic Challenge

Multiple systems and write-blockers can be expensive. The basic challenge allows students to analyze evidence on the seized system. Evidence photographs are also not required. Students are required to wear latex gloves while handling the evidence.

Advanced Challenge

This challenge requires two laptops: one as seized evidence and the other as an investigators system. Challenge also requires a USB write-blocker (https://www.amazon.com/CRU-Inc-31300-0192-0000-WiebeTech-WriteBlocker/dp/B002DH1P0W), SD media card reader, and a digital camera. Students are required to log and photograph all evidence. Analysis of USB drives and SD cards must be completed on the investigator system with write blockers. Students are required to wear latex gloves while handling the evidence.

Password for CFC-Forms_answers.xlsx file is available by emailing me at [email protected]

About

Open source cyber forensics challenge for middle and high school students interested in STEM

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Languages