in discovery Sept. 25 th , 2019 1 People. Partnership. Performance. - - PowerPoint PPT Presentation

in discovery
SMART_READER_LITE
LIVE PREVIEW

in discovery Sept. 25 th , 2019 1 People. Partnership. Performance. - - PowerPoint PPT Presentation

San Diego ACC Paralegal Institute Forensics strategies for emerging data sources in discovery Sept. 25 th , 2019 1 People. Partnership. Performance. epiqglobal.com Slack Overview Account Types Collection Method Channels vs Direct


slide-1
SLIDE 1
  • People. Partnership. Performance. epiqglobal.com

1

San Diego ACC Paralegal Institute Forensics strategies for emerging data sources in discovery

  • Sept. 25th, 2019
slide-2
SLIDE 2
  • People. Partnership. Performance. epiqglobal.com

2

Slack

  • Slack Overview
  • Account Types
  • Collection Method
  • Channels vs Direct Messages
  • Limitations
  • Processing / Review
  • Recap with step-by-step collection

instructions

slide-3
SLIDE 3
  • People. Partnership. Performance. epiqglobal.com

3

Slack Stats

  • Released in 2014
  • 3 million paid subscribers
  • 8 million daily users
  • More than 1,500 apps in

Slack directory

  • 5.1 billion corporate

valuation

slide-4
SLIDE 4
  • People. Partnership. Performance. epiqglobal.com

4

What is Slack?

slide-5
SLIDE 5
  • People. Partnership. Performance. epiqglobal.com

5

  • People. Partnership. Performance. epiqglobal.com

5

Public and Private Channels Direct and Multi- party Messages

slide-6
SLIDE 6
  • People. Partnership. Performance. epiqglobal.com

6

  • People. Partnership. Performance. epiqglobal.com

6

Free, Standard, and Plus accounts require the end users credentials to collect their account

slide-7
SLIDE 7
  • People. Partnership. Performance. epiqglobal.com

7

  • People. Partnership. Performance. epiqglobal.com

7

Enterprise accounts can be collected from an administrator login

slide-8
SLIDE 8
  • People. Partnership. Performance. epiqglobal.com

8

Free Slack Account Limitations

slide-9
SLIDE 9
  • People. Partnership. Performance. epiqglobal.com

9

Slack Export Features

  • The native export for Plus

and Enterprise accounts creates a JSON file

  • The JSON file includes a link

to the native but not the actual native file.

  • The JSON file format is not

easily rendered into a reviewable format.

slide-10
SLIDE 10
  • People. Partnership. Performance. epiqglobal.com

10 10

Slack Collections

  • Best Practice tools:
  • Capture Direct and Multi-party Messages
  • Selectively capture Public and Private Channels
  • Download and extract metadata from attachments
  • Retains the parent-child relationship with attachments
  • Generate a native file of the message conversation
  • Export is load ready for Relativity
slide-11
SLIDE 11
  • People. Partnership. Performance. epiqglobal.com

11 11

Slack Collection Recap

  • Is the client using Slack Enterprise or Free/Standard/Plus versions?
  • If Enterprise, we can collect the custodian’s direct messages and channels from an

administrator account.

  • If no, we need the custodian’s credentials.
  • Does the client have two-factor, SSO, or SAML authentication enabled?
  • Determine what Public channels need to be collected and from whom.
  • Determine if Direct Messages need to be collected and from whom.
  • Confirm if a date filter should be applied to the collection.
  • The collections typically takes 1-2 days to download with an additional day or so to

process and generate a load file.

slide-12
SLIDE 12
  • People. Partnership. Performance. epiqglobal.com

12

Mobile Devices

slide-13
SLIDE 13
  • People. Partnership. Performance. epiqglobal.com

13 13

Mobile

  • Corporate Policy and Mobile Device

Management Considerations

  • Overview of mobile devices

collections

  • Potential issues to consider with Apple

and Android devices

  • Reporting, review, and production of

mobile data

slide-14
SLIDE 14
  • People. Partnership. Performance. epiqglobal.com

14 14

mobile device preservation and collection

  • Mobile device data is:
  • Easily altered / spoliated
  • Challenging preserving and collecting

− Encryption − Third party messaging apps − Evolving and changing technology − Enterprise Mobile Device Management Software

  • Differs in format from traditional computer data collections
  • Constantly changing when connected to a cell tower or

Wi-Fi network

slide-15
SLIDE 15
  • Corporate Mobile Policies –

Universal Considerations

slide-16
SLIDE 16
  • People. Partnership. Performance. epiqglobal.com

16 16

BYOD

  • Bring Your Own Device (BYOD)
  • Increasing popularity
  • Users mix personal and business data

− Does a policy exist? − Does IT implement a Mobile Device Management software solution? − Does preservation of BYOD data exist? − Does device accessibility exist (for example, passcode management) − Has collection of intermixed data been addressed?

  • Third-party and affiliated parties such as board members
slide-17
SLIDE 17
  • People. Partnership. Performance. epiqglobal.com

17 17

BYOD

  • How do you address the privacy concerns to limit what is reviewed?
  • How do you address the intermingled data issues?

− Can you selectively export the requested conversations?

slide-18
SLIDE 18
  • People. Partnership. Performance. epiqglobal.com

18 18

Example BYOD collection method

  • Forensics consultant will collect the device using Cellebrite.
  • All collected data will be saved to an encrypted hard drive.
  • The consultant will open the collection in Cellebrite Physical Analyzer (PA).
  • The consultant will prepare a Cellebrite PA report of the requested SMS, MMS, and Chat (if

supported), along with technical device details such as the device IMEI and serial

  • number. The report will be made in two formats: Microsoft Excel and Cellebrite UFED Reader
  • format. The reports will be saved to two (2) separate collection drives.
  • The consultant will perform a QC check on the Cellebrite reports with counsel to ensure only

the identified data types and technical device information are included in the reports.

  • The consultant will take possession of the collection reports and start an electronic Chain of

Custody on the collection report drives.

  • The consultant will hand the original encrypted drive with the full collection data to the

custodian (or counsel) for retention.

  • Forensics consultant will only leave the collection site with the Cellebrite reports of identified

text message/chat thread data.

slide-19
SLIDE 19
  • People. Partnership. Performance. epiqglobal.com

19 19

MDM

  • Mobile Device Management Software
  • Used by organizations to control device use and security

− Allows security policy to be managed centrally − Allows remote wipe − May allow for passcode change (usually causes wipe) − Potential to inhibit the ability to collect data − AirWatch,MaaS360, MobiControl, XenMobile, others

slide-20
SLIDE 20
  • People. Partnership. Performance. epiqglobal.com

20 20

MDM

  • Examples of MDM restrictions
slide-21
SLIDE 21
  • Mobile Collections
slide-22
SLIDE 22
  • People. Partnership. Performance. epiqglobal.com

22 22

Mobile Device Collections

  • Mobile device must be isolated from cell towers and Wi-Fi (radio frequencies – RF)

to prevent changes/destruction (remote wiping)

  • Special faraday boxes can be used to

forensically maintain RF isolation

  • Airplane mode is a common method

for RF avoidance (use caution)

slide-23
SLIDE 23
  • People. Partnership. Performance. epiqglobal.com

23 23

Mobile Device Collection Tools

  • Tools currently available at Epiq:
  • Cellebrite
  • XRY
  • Blacklight*
  • Mobilyze*
  • Oxygen Forensics*
  • * Limited to iOS and certain logical Android collections

Across all products support for over 10,000 mobile devices

slide-24
SLIDE 24
  • People. Partnership. Performance. epiqglobal.com

24 24

Cellebrite Collection Method Overview

  • Industry standard in mobile collections,

application decoding, forensic analysis, and advanced reporting.

  • Apple iOS collections

− Advanced Logical Method 1 & 2

  • Android

− Physical (if supported) − Logical − File System (typically Android Backup)

slide-25
SLIDE 25
  • People. Partnership. Performance. epiqglobal.com

25 25

Collection Time

  • Phone sizes have increased 10x
  • ver the last five years with volume
  • f text and chat messages growing

at a similar rate. With the growth in device capacity, the time to collect a large phone is comparable to imaging a workstation at 3-5 hours.

slide-26
SLIDE 26
  • Mobile Collection Issues to

Consider

slide-27
SLIDE 27
  • People. Partnership. Performance. epiqglobal.com

27 27

Encryption Types

  • Encryption is becoming more

popular on mobile device hardware, software, and on the application level.

  • Hardware/File Based

− Blackberry, Android, and iOS

  • Software

− iTunes Backup Encryption

  • Application Level

− Messaging Apps: Signal and Wickr

slide-28
SLIDE 28

iTunes Backup Encryption

  • One-time password
  • It can be user initiated or implemented via

a MDM policy.

  • iTunes (installed version) does not support a

forgotten password feature for the backup encryption.

  • The device can be collected, however we

need the password to decrypt the image.

https://support.apple.com/en-us/HT205220

slide-29
SLIDE 29
  • People. Partnership. Performance. epiqglobal.com

29 29

iTunes Backup Encryption Removal

  • For iOS 11 and newer, a setting reset can be

performed to remove the password, but it also resets numerous other phone settings.

  • Once you apply the reset, it can not be undone. This

should only be used as a last resort.

  • Consider downloading an iCloud backup as an

alternative method to getting to the data on the encrypted device.

slide-30
SLIDE 30
  • People. Partnership. Performance. epiqglobal.com

30 30

Apple iOS collection issues

  • The new iPhones support 512 GB of storage making the

collection times longer than most custodian’s will want to be without their device.

  • iTunes Backup Encryption
  • MDM client software restricting what applications can

be backed up.

slide-31
SLIDE 31
  • People. Partnership. Performance. epiqglobal.com

31 31

Apple iCloud collection issues

  • Apple’s iCloud infrastructure underwent massive changes in

2018.

  • The iCloud changes significantly affected the ability for the

entire industry to collect iCloud backups starting late September 2018 when the backup was iOS 11 or 12, and 2FA was enabled.

  • As of one month ago, there is a solution in place to allow

iCloud downloads. At this moment in time, this is solution is currently unavailable.

slide-32
SLIDE 32
  • People. Partnership. Performance. epiqglobal.com

32 32

  • People. Partnership. Performance. epiqglobal.com

Android collection issues

  • Strong encryption and hardware security measures on

newer devices.

  • Android Security Patch Updates
  • In many cases, you can only collect a logical extraction

because of the Android security patch updates. In order to collect third-party apps or deleted text messages, you need a physical extraction.

  • Advanced extraction methods (Custom Boot Loaders,

JTAG, Chip Off, etc) are available through Epiq and trusted third party vendors, but not always supported on the newest Android devices. These methods may render the device permanently unusable.

slide-33
SLIDE 33
  • People. Partnership. Performance. epiqglobal.com

33 33

Recovery of deleted messages

  • Deleted SMS/MMS/Third Party Chats can be recovered in some

instances

  • With iOS 11 and the new security feature in Android device, it is

becoming less common to recover significant volumes of deleted text messages.

slide-34
SLIDE 34
  • Mobile Review and Production
slide-35
SLIDE 35
  • People. Partnership. Performance. epiqglobal.com

35 35

Mobile Reporting & Review Options

  • Cellebrite Excel Report contains:
  • Contacts,
  • Call logs,
  • Calendars
  • Internet history
  • Messaging
  • Recorded voicemails
  • User location information
  • Documents
  • Media (pictures & video)
  • Notes
  • And more…
slide-36
SLIDE 36
  • People. Partnership. Performance. epiqglobal.com

36 36

Text message review in Excel

  • Does not support complex searches and

tagging

  • Cannot be produced in a granular

format

  • Cannot easily be redacted
  • Does not keep the parent child

relationship if processed

  • Easy to create
  • Simple to review and filter

Pro’s Con’s

slide-37
SLIDE 37
  • People. Partnership. Performance. epiqglobal.com

37 37

Mobile Chat Analyzer

  • Developed in-house to address the complexities of mobile data review.
  • Creates a granular records for each item that can be searched, reviewed, and

produced.

  • Creates a native image for each record and extracts the searchable text.
  • Threads conversations
  • Retains the parent child relationship
slide-38
SLIDE 38
  • People. Partnership. Performance. epiqglobal.com

38 38

New DOJ Text Message Specifications

TXT-PARTICIPANTS List of participant names and/or telephone numbers. TXT-BODY Body of text messages, notes, chats, or calendar items. Do not populate for emails. TXT-STATUS Indicates whether text was Sent or Read on the device. TXT-THREAD-GROUP Populate with the DOCID of the first text in the chat conversation to allow the entire chat conversation to be

grouped as a family. (Sort each device by Chat Number and then by Row Number to assign TXT-THREAD-GROUP identifier.) This is NOT the BEGATTACH field or Relativity Group Identifier.

TXT-SMSC Short Message Service Center (handles SMS text messages on behalf of phone service provider) TXT-STARREDMESSAGE Notes whether the message was flagged. TXT-DELETED Indicates whether a chat, instant message, or file was deleted from the mobile device and recovered by Cellebrite. TXT-READDATE Date and time the chat, text message, or instant message was opened to read. Format: MM/DD/YYYY HH:MM:SS

(Use 24-hour times, e.g., 13:32:00 for 1:32 pm); AM, PM, time zone, or day of the week indicators cannot be included.

TXT-TIMESTAMP Timestamp of item. Equivalent to DateRecieved afor incoming items or to SateSent for outgoing items. In

MM/DD/YYYY HH:MM:SS in 24-hour format that does not include AM, PM, time zone, or day of the week indicators.

TXT-LOCATION GPS information associated with chats, text messages, or instant messages. TXT-MESSAGENUMBER Similar to RowNumber. Individual identifier for message. TXT-CHATNUMBER Chat number, identifies chat groups. TXT-ROWNUMBER Row number.

slide-39
SLIDE 39
  • People. Partnership. Performance. epiqglobal.com

39

Office 365

slide-40
SLIDE 40
  • People. Partnership. Performance. epiqglobal.com

40 40

O365 Office Capabilities

  • Presentations
  • Office On-line
  • Business

Platform

  • Project

Management

  • Small Business

Apps

  • File Storage &

Collaboration

  • Outlook: Email,

Calendar, Contacts & Tasks

  • Chat &

Conferencing

slide-41
SLIDE 41
  • People. Partnership. Performance. epiqglobal.com

41 41

O365 eDiscovery Features Licensing

slide-42
SLIDE 42
  • People. Partnership. Performance. epiqglobal.com

42 42

eDiscovery Search

Exchange:

Sent Date

SharePoint:

Modified Date

slide-43
SLIDE 43
  • People. Partnership. Performance. epiqglobal.com

43 43

eDiscovery Search - Sources

SharePoint Online/OneDrive:

Exact URL Required *** S&CC will take erroneous URLs and not report an immediate error

Exchange Online:

Select Mailbox by typing user alias

slide-44
SLIDE 44
  • People. Partnership. Performance. epiqglobal.com

44 44

eDiscovery Export

Options:

  • Unindexed/Unsearchable Items handling
  • Container consistency
  • Deduplication (***Never Use)
  • Versioning
  • Compressed ZIP or Native
slide-45
SLIDE 45
  • People. Partnership. Performance. epiqglobal.com

45 45

O365 Index

Unindexed/Unsearchable Items

  • Unindexed/unsearchable items are flagged as unable to be fully indexed
  • Does NOT mean the item was not searched at all
  • An item with a positive hit could also be exported as unindexed/unsearchable
  • Items are typically unsupported files, images, PDFs that were scanned, encrypted items,

etc.

  • Low likelihood of being responsive; historical statistics put positive hit rates at less than 20%

(per Microsoft) if the data is exported and searched downstream

  • Standard practice is to export unindexed items however clients can choose to ignore these

items if they understand and accept the limitations of the Microsoft O365 index

slide-46
SLIDE 46
  • People. Partnership. Performance. epiqglobal.com

46 46

SharePoint/OneDrive Long File Paths

  • Paths longer than 260 characters will be shortened by truncating filename upon S&CC

export

  • If the full path name is still too long after shortening the file name, the item is moved from its

current location to the parent folder and process repeated until pathname is under the 260-character limit.

  • If a truncated full path name already exists, a version number will be added to the end of

the filename

  • For this reason, best practice is to export to ZIP file rather than native
slide-47
SLIDE 47
  • People. Partnership. Performance. epiqglobal.com

47 47

Export Limits

From Microsoft:

  • You can export a maximum of 2 TB of data from a single Content Search. If

the search results are larger than 2 TB, consider using date ranges or other types of filters to decrease the total size of the search results.

  • Your organization can export a maximum of 2 TB of data during a single

day.

  • You can have a maximum of 10 exports running at the same time within

your organization.

  • A single user can run a maximum of three exports at the same time.
slide-48
SLIDE 48
  • People. Partnership. Performance. epiqglobal.com

48 48

Office 365: Teams

Each “Team” has

  • Team Conversations (messages stored in

dedicated EXO mailbox associated to a Team)

  • 1:N Chats (1:1 / group messages stored in

users EXO mailboxes)

  • Files (SharePoint document library)
  • Mailbox
  • Office 365 Group
  • Calendar
  • Wiki
  • Document versioning is turned on by default

Chat oriented collaboration tool with social media influence

  • Browser App
  • Desktop App
  • Mobile App
slide-49
SLIDE 49
  • People. Partnership. Performance. epiqglobal.com

49 49

Office 365: OneDrive

. . .

File storage tool similar to Dropbox, Box.com, Google Drive

  • Designed to replace “My Documents” folder and “Home

Share” on File Server.

  • For all intents and purposes: It’s a SharePoint site
  • Access via the web or local copy on user’s device
slide-50
SLIDE 50
  • People. Partnership. Performance. epiqglobal.com

50 50

Office 365: OneDrive

Metadata Concerns:

  • Document creation timestamps will reflect date and time the file was first

synced by the local file system. The same document will have different creation dates in different sync points.

  • For cases where creation times are substantial, collection from many sync

points, including duplicates, could be a requirement.

  • If OneDrive locations are out of sync, documents can be missed during

collection if single sync point is collected.

slide-51
SLIDE 51
  • People. Partnership. Performance. epiqglobal.com

51 51

SharePoint/OneDrive: Versioning

SharePoint Export folder SharePoint User Interface

  • Last 100 versions saved on default for OneDrive unless on legal hold
  • Version 101 overwrites version 1, etc.
slide-52
SLIDE 52
  • People. Partnership. Performance. epiqglobal.com

52

  • People. Partnership. Performance. epiqglobal.com

52

Questions