Detecting steganogr...
 
Notifications
Clear all

Detecting steganography?

6 Posts
6 Users
0 Reactions
1,040 Views
SilesianMan
(@silesianman)
Active Member
Joined: 16 years ago
Posts: 15
Topic starter  

Hi,
what are you using to detect steganography of the acquired data you are analyzing?

I know there was the StegAlyzer software but it is not available anymore.
Do you have any recommendations?

Thank you,
Karol


   
Quote
(@dandaman_24)
Estimable Member
Joined: 11 years ago
Posts: 172
 

Have a little read if this PDF.

https://www.sans.org/reading-room/whitepapers/stenganography/steganalysis-detecting-hidden-information-computer-forensic-analysis-1014


   
ReplyQuote
(@vootz)
Eminent Member
Joined: 20 years ago
Posts: 27
 

Karol,

WetStone Technologies has their Stego Suite software. May want to check that out.

Thanks,
Mike


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Hi,
what are you using to detect steganography of the acquired data you are analyzing?

At the moment, nothing…there's not yet been any reason to suspect that stego has been used.

However, if I were conducting an investigation and found that a stego tool was installed on a system, or if there were indications that such a tool had been used, I might consider the need. But to this point, with the DFIR work I've been doing (ranging from "is this box infected/compromised" to full-on targeted threat), there hasn't been any reason to suspect that stego was used.


   
ReplyQuote
MDCR
 MDCR
(@mdcr)
Reputable Member
Joined: 15 years ago
Posts: 376
 

Hi,
what are you using to detect steganography of the acquired data you are analyzing?

At the moment, nothing…there's not yet been any reason to suspect that stego has been used.

Same here.

As for Stego, it's either plaintext or encrypted. Plaintext would be easy and encryption compresses really badly - so that's a hint.


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

I know there was the StegAlyzer software but it is not available anymore.

Isn't it? ?
http//www.sarc-wv.com/products/stegalyzeras/learn_more.aspx

jaclaz


   
ReplyQuote
Share: