Hiding Behind the Keyboard

Hiding Behind the Keyboard

Uncovering Covert Communication Methods with Forensic Analysis

1st Edition - March 11, 2016

Write a review

  • Authors: Brett Shavers, John Bair
  • Paperback ISBN: 9780128033401
  • eBook ISBN: 9780128033524

Purchase options

Purchase options
DRM-free (PDF, EPub, Mobi)
Sales tax will be calculated at check-out

Institutional Subscription

Free Global Shipping
No minimum order


Hiding Behind the Keyboard: Uncovering Covert Communication Methods with Forensic Analysis exposes the latest electronic covert communication techniques used by cybercriminals, along with the needed investigative methods for identifying them. The book shows how to use the Internet for legitimate covert communication, while giving investigators the information they need for detecting cybercriminals who attempt to hide their true identity. Intended for practitioners and investigators, the book offers concrete examples on how to communicate securely, serving as an ideal reference for those who truly need protection, as well as those who investigate cybercriminals.

Key Features

  • Covers high-level strategies, what they can achieve, and how to implement them
  • Shows discovery and mitigation methods using examples, court cases, and more
  • Explores how social media sites and gaming technologies can be used for illicit communications activities
  • Explores the currently in-use technologies such as TAILS and TOR that help with keeping anonymous online


Information Security practitioners and consultants, public and private sector cybercrime investigators, IT managers, attorneys, law enforcement officers, InfoSec students

Table of Contents

    • Foreword
    • Introduction
    • About the Authors
    • Acknowledgments
    • Chapter 1. Laying the Foundation of Covert Communications
      • Introduction
      • A Brief History of Covert Communication
      • Covert Communication Overload
      • Covert Communication Goals
      • Summary
    • Chapter 2. The Tor Browser
      • Introduction
      • History and Intended Use of The Onion Router
      • How The Onion Router Works
      • Forensic Analysis of The Onion Router
      • Tracking Criminals Using Tor
      • Used in Combination of Other Tools and Methods
      • Tails
      • Related Tor Tools and Applications
      • Summary
    • Chapter 3. Triaging Mobile Evidence
      • Logical Data
      • Physical Data
      • Examples of Logical and Physical Data
      • Wireless Carriers
      • Mobile Network Operators
      • Mobile Virtual Network Operator
      • Determining Target Number
      • Fonefinder.net
      • Number Portability Administration Center
      • Search.org
      • Subscriber Identity Module
      • Internal Hardware of a SIM
      • The SIM File System
      • SIM Sizes and Evolution
      • Typical Evidence
      • SIM Security—PIN and PUK
      • Triaging Devices
      • Devices Powered “On”
      • Devices Located “Off”
      • Manual Exams
      • Tools Available
      • Software Solutions
      • Chapter Summary Points
      • References for Manual Tools
    • Chapter 4. Mobile Extraction Issues
      • Flash Memory
      • Embedded Multimedia Card, Embedded Multichip Package, and Multichip Package
      • The Function of NAND
      • Encoding
      • Epochs
      • Cellebrite Physical Analyzer
      • User-Installed Applications
      • User-Enabled Security
      • Advanced Validation
      • References for Listed Tools
    • Chapter 5. Data Hiding
      • Introduction
      • What is Steganography
      • Hiding Data Behind Data
      • Steganalysis
      • Steganography Methods
      • Relevant Cases
      • Summary
    • Chapter 6. Cryptography and Encryption
      • Introduction
      • Brief History of Encryption and Cryptography
      • Basic Working Knowledge
      • Hardware
      • Public and Private Keys
      • The Key is the Key
      • So Tell Me Something I Can Do About This!
      • Back to Steganography
      • Summary
    • Chapter 7. Antiforensics
      • Introduction
      • The Easy and Very Effective Methods
      • The Best Methods Aren’t the Most Commonly Used Methods
      • Another Simple Method
      • File Signature Manipulation
      • Time Stamp Modifications
      • Decoy Storage Devices
      • Portable Apps
      • Hidden Operating Systems
      • Virtual Machines
      • Planning Against Antiforensics
      • Finding Communication Records on Hard Drives
      • When All Else Fails or Is Likely to Fail
      • Summary
    • Chapter 8. Electronic Intercepts
      • Introduction
      • Value of Electronically Intercepted Communications
      • Authority and Necessity
      • Technology
      • Technical Barriers
      • Finding Cell Phone Numbers
      • Summary
    • Chapter 9. Digital Identity
      • Introduction
      • Identity
      • Finding the Digital Identity
      • Summary
    • Chapter 10. Putting It All Together
      • Introduction
      • Collecting Real-Time Communications
      • Collecting Historical Communications
      • Turning Information Into Intelligence
      • The (Virtually) Impossible
      • Non-tech Communications
      • Putting the Case Together
      • Summary
    • Chapter 11. Closing Thoughts
      • Introduction
      • Privacy Expectations
      • Legal and Technical Considerations
      • Summary
    • Index

Product details

  • No. of pages: 254
  • Language: English
  • Copyright: © Syngress 2016
  • Published: March 11, 2016
  • Imprint: Syngress
  • Paperback ISBN: 9780128033401
  • eBook ISBN: 9780128033524

About the Authors

Brett Shavers

Brett Shavers is a former law enforcement officer of a municipal police department. He has been an investigator assigned to state and federal task forces. Besides working many specialty positions, Brett was the first digital forensics examiner at his police department, attended over 2000 hours of forensic training courses across the country, collected more than a few certifications along the way, and set up the department’s first digital forensics lab in a small, cluttered storage closet.

Affiliations and Expertise

Digital Forensics Practitioner, expert witness, and Adjunct Instructor, University of Washington Digital Forensics program

John Bair

John Bair is currently employed as a detective with the Tacoma Police Department. He has been commissioned as a law enforcement officer since May 1989. During his assignment in the homicide unit he began specializing in Cell Phone Forensics.

In 2006 John created the current forensic lab that focuses on mobile evidence related to violent crimes. His case experience shortly thereafter gained the attention of Mobile Forensics Incorporated (MFI) where he was hired and spent several years serving as a contract instructor. MFI soon merged with AccessData to become the only training vendor for their mobile forensics core. This relationship fostered direct contact with engineers who assist in criminal cases which need anomalies and exploits addressed within their forensics products.

July 2013 he was hired as a contract instructor by Fox Valley Technical College to assist in training for the Department Of Justice - Amber Alert Program. His expertize with mobile forensics is being utilized to structure a digital evidence module for investigators responding to scenes where children had been abducted. The program promotes how to prevent mobile evidence contamination and how to triage live devices under exigent circumstances.

Within in Pierce County, he began a mobile forensics training program for Superior Court Prosecutors and Judicial Officers which is currently in its fourth year. The program stresses the technical origins of the warrant language, what to check for, validation of evidence and how to present this dynamic content in court.

In December 2013, Detective Bair gave a presentation to the University Of Washington Tacoma (UWT) Institute of Technology which provided an outline to merge digital solutions between the Tacoma Police Department and UWT. The relationship will focus on building a digital forensic lab that will be modeled after the Marshall University Forensic Science Center in West Virginia. The lab proposal also includes the ability to conduct advanced destructive forensics which will be a one of kind facility on the west coast. Based upon the proposal to create a combined lab, John created a mobile forensic course and began part time lecturing at UWT in April 2014. The course covers legal concepts, logical, physical searching methods and manual “carving”. John authored his own student and lab manuals for these courses. In March 2015, John started an intern program within the lab at the Tacoma Police which involved students from this program. In late August 2015, one of the interns was able to use advance python writing to assist with parsing over 3300 deleted messages in a homicide that took place earlier that year.

John Bair has instructed at various federal labs within the United States (Secret Service, ICE). He has presented on mobile evidence as a guest speaker at Paraben’s Innovative Conference, Washington State Association of Prosecuting Attorney’s (WAPA) Summit, and the Computer Technology Investigations Network Digital Forensics Conference. Recently he spoke at the 16th Annual Conference on Information Technology Education / 4th Annual Research in IT Conference in Chicago Illinois. These conferences are sponsored by the ACM Special Interest Group for Information Technology Education (SIGITE). John and two other professors from the University Of Washington – Tacoma (UWT) recently co-authored a paper regarding the current Mobile Forensic Program.

John has over 42 certifications related to digital evidence training. The following reflect the most significant related to mobile forensics: Mobile Forensics Certified Examiner (MFCE), Cellebrite Certified Mobile Examiner (CCME), Cellebrite Certified Physical Analyst (CCPA), Cellebrite Certified Logical Operator (CCLO), AccessData Certified Examiner (ACE), Cellebrite Mobile Forensics Fundamentals (CMFF), AccessData Mobile Examiner (AME), and Cellebrite Certified Task Instructor.

John is also the co-owner of the forensics expert services firm, NAND Forensics (www.nandforensics.com).

Affiliations and Expertise

MFCE, CCME, CCPA, CCLO, AME, Lecturer - Digital Mobile Forensics, University of Washington (Tacoma)

Ratings and Reviews

Write a review

There are currently no reviews for "Hiding Behind the Keyboard"