Notifications
Clear all

Exchange Forensics

5 Posts
2 Users
0 Reactions
890 Views
RolfGutmann
(@rolfgutmann)
Noble Member
Joined: 10 years ago
Posts: 1185
Topic starter  

For a HX server investigation we are looking for the best tool to find deleted emails and contacts. As we do not have full access as no dedicated server was in use the case is difficult.

Who has advice for fast finding evidence on a HX? Shall we also take Splunk into consideration?

Please help! Thank you.


   
Quote
MDCR
 MDCR
(@mdcr)
Reputable Member
Joined: 15 years ago
Posts: 376
 

Shall we also take Splunk into consideration?

Why, as in using that overpriced piece of s**t for an investigation?

The only reason you buy a Siem system is because you want a ISO 12001 cert. I've been offered Arcsite, Splunk, RSA and similar s**t but i went with fast hardware + NoSql/Shared nothing databases instead. For performance and analytics they run in circles around Siem systems.

You don't do forensics in a Siem system.

Ask yourself, what kind of data is this? What do you NEED to be able to do your job? Do not listen to salespeople, they generally dont give a crap about your needs, and will lie straight to your face about their products being able to deliver magical unicorns and rainbows.

Is it a standard VM? Then ask if they can download the VM and send it. Then do recovery/carving on that.


   
ReplyQuote
RolfGutmann
(@rolfgutmann)
Noble Member
Joined: 10 years ago
Posts: 1185
Topic starter  

Thank you!

Fully agree that Splunk is overprized s**t, we just have it internally.

They refuse to send the VM image and we are under time pressure. A 'Internationales Rechtshilfegesuch in Strafsachen' takes too long time.

In an ongoing investigation (neartime crime) its about speed only.

I search for a script 'asking the eXchange server to answer everything possible' withing the sync communication.


   
ReplyQuote
MDCR
 MDCR
(@mdcr)
Reputable Member
Joined: 15 years ago
Posts: 376
 

Given the time constrains, all you are left with is to access remotely and gather info.

Try looking for artifacts left in the exchange log, example

https://serverfault.com/questions/570084/exchange-server-email-logs-location

https://technet.microsoft.com/en-us/library/bb124926(v=exchg.160).aspx

If IIS and message tracking is enabled, you can find more under \\servername\exchangeserver.log

https://social.technet.microsoft.com/Forums/lync/en-US/8b53984e-2b8d-4b82-b279-99086970a8a6/microsoft-server-exchange-email-logs?forum=exchangesvradminlegacy


   
ReplyQuote
RolfGutmann
(@rolfgutmann)
Noble Member
Joined: 10 years ago
Posts: 1185
Topic starter  

Tack!


   
ReplyQuote
Share: