13.07.2015 Views

Cyber-Sleuthing: Using The Internet For ... - IADC Meetings

Cyber-Sleuthing: Using The Internet For ... - IADC Meetings

Cyber-Sleuthing: Using The Internet For ... - IADC Meetings

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Cyber</strong>-<strong>Sleuthing</strong>: <strong>Using</strong><strong>The</strong> <strong>Internet</strong> <strong>For</strong>Investigative PurposesInvestigating Sources Of False Or Defamatory <strong>Internet</strong> Information


<strong>Cyber</strong> <strong>Sleuthing</strong> RequiresTechnical-Investigative-LegalApproachesLegal Approaches:Blind Cease & DesistRequest Website RemovalJohn Doe Law SuitSubpoena<strong>Internet</strong> ProfilingEmail AddressesSocial MediaBoolean SearchesDeep Web SearchesHistorical Web SearchesCache Web SearchesDNS SearchesWhoIS Searches<strong>Cyber</strong> <strong>For</strong>ensicsOnline Sting OperationsIP TrapsWeb TrapsEmail SpoofingText SpoofingLegal Electronic Wire TapsMeta Data RecoverySocial Media Deep MappingData LeakagePrecise Geo-Location<strong>For</strong>ensic Recovery Of EvidenceStrategic/Subpoena Strategies


Types of Cases We See:<strong>Internet</strong> DefamationHacking & Intrusions<strong>Cyber</strong> Stalking/HarassmentExtortion/BlackMail<strong>Cyber</strong> Bullying<strong>Internet</strong> FraudGrey Market Diversion/TrademarkIntellectual Property <strong>The</strong>ft


AnonymityPeople are Willing To Do InPrivate…What <strong>The</strong>y Would NeverDare In Public


You Can Just Subpoena<strong>The</strong> Information Right?


Geographic Complexities


Congratulations You Just CaughtDonald Duck…..Name: Donald DuckAddress: Disney LandIP Address- Anonymous ProxyEmail Address: donaldduck@gmail.comEmail Set Up: Anonymous Proxy


<strong>Cyber</strong> Tracing RequiresDiligence-Patience-Know How


Introduction To <strong>Internet</strong>Profiling &Investigation Tools


Boolean Search


Meta Searcheshttp://www.thesearchenginelist.com/www.dogpile.comhttp://www.turboscout.com/http://monstercrawler.com/Ads Search, Craigslist, Amazon Ebay and many morehttp://www.adhuntr.com/http://global.ebay.com/search/http://claz.org/


Meta Search<strong>The</strong> Search Engine List


Email TracingTracing HeadersGmail TracingTraceroutesMyLife – www.mylife.comSpokeo – www.spokeo.comPeople Search www.peoplesearch.comIP Traps


Tracing Headers


IP Traps


Website TracingAdvanced WhoIs – Domain ToolHosting History – Registrar HistoryIP Traps Through Domains By ProxyWayBack Machine - web.archive.orgSite Dossier -http://www.sitedossier.com/site/NAMEOFSITE.comGoogle Analytics - http://sameid.net/


Website TracingHTML-PHP CodeExif DataPrivate MessagingHidden Document – WebsiteRipper


Website Tracing


Historical Websites


Social MediaFacebook MappingTwitter Mapping


Geolocating TweetsWho In Florida Tweeted Django


Phone TracingTinID, MyLife Spoke – www.tnid.us , mylife.com ,spokeo.comPrivate Phone Database – www.tracersinfo.comSkip Tracy- www.bellescamp.comSpy-Dialer –www.spydialer.comTriangulation Pings - Specialized


Phone Tracingwww.tnid.us


Cell-Triangulation1. Will Locate Cell Phones Location2. From 6 meters to 1500 ft.3. Works When Phone Turned Off813-555-21333122 Eastway Drive, NC


People TracingCredit HeadersPhonesFriends & FamilyBank AccountsJob Location/Workers


People TracingSocial Engineering PhoneWeb SearchSocial MediaSocial Engineering/IP Address


Maltego –Paterva.com


IP TracingWeb TrapsPhone TrapsEmail TrapsSocial Media TrapsEmail <strong>For</strong>ensicsPhone <strong>For</strong>ensicsLive Memory <strong>For</strong>ensicsLogsSubpoena


Traceroute’sOpus1.comCentralOps.net


Ip & Metadata withFoca


Wireless SSID, GEO &Mac TracingWigle.net


Ip TriangulationIP Trap62.12.14.5262.12.14.52


How To Get A Copy OfThis Slide PresentationBruce AndersonDirector Of Investigations(813) 315-8484bruce@cyberinvestigationservices.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!