diff --git a/STIX_for_digital_forensics/Email_Harassment/email_harassment.jpg b/STIX_for_digital_forensics/Email_Harassment/email_harassment.jpg new file mode 100644 index 0000000..42ad033 Binary files /dev/null and b/STIX_for_digital_forensics/Email_Harassment/email_harassment.jpg differ diff --git a/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.jpg b/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.jpg new file mode 100644 index 0000000..bdfd4c4 Binary files /dev/null and b/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.jpg differ diff --git a/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.pdf b/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.pdf index 58b8a71..8dd098a 100644 Binary files a/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.pdf and b/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.pdf differ diff --git a/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.svg b/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.svg index 1b6dbb7..6f5d9c6 100644 --- a/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.svg +++ b/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.svg @@ -2,8 +2,8 @@ + xmlns:v="http://schemas.microsoft.com/visio/2003/SVGExtensions/" width="32.5in" height="32in" viewBox="0 0 2340 2304" + xml:space="preserve" color-interpolation-filters="sRGB" class="st27"> @@ -12,28 +12,33 @@ @@ -41,18 +46,18 @@ - - - @@ -64,1619 +69,1626 @@ Page-1 - + + Rectangle.1201 + + + + + + Sheet.1 identity: Frank Xu - - - identity: Frank Xu - + + + identity: Frank Xu + Sheet.2 identity: administrator - - - identity: administrator - + + + identity: administrator + Rectangle.1067 x-investigator: Frank Xu - - - x-investigator: + + x-investigator:Frank Xu - + Dynamic connector.1001 attributed-to - - - - attributed-to - + + + + attributed-to + Rectangle.1002 x-crime-case: Illegal Rhino Images Possession - - - x-crime-case:Illegal Rhino Images Possession - + + + x-crime-case:Illegal Rhino Images Possession + Sheet.1003 file: Rhino Hunt.pdf - - - file: Rhino Hunt.pdf - + + + file: Rhino Hunt.pdf + Sheet.1004 file: rhino.log - - - file: rhino.log - + + + file: rhino.log + Sheet.1005 file: rhino2.log - - - file: rhino2.log - + + + file: rhino2.log + Sheet.1006 file: rhino3.log - - - file: rhino3.log - + + + file: rhino3.log + Dynamic connector.1007 case_file_refs - - - - case_file_refs - + + + + case_file_refs + Dynamic connector.1008 case_file_refs - - - - case_file_refs - + + + + case_file_refs + Dynamic connector.1009 case_file_refs - - - - case_file_refs - + + + + case_file_refs + Dynamic connector.1010 case_file_refs - - - - case_file_refs - + + + + case_file_refs + Rectangle.1011 x-image: rhino usb image - - - x-image:rhino usb image - + + + x-image:rhino usb image + Dynamic connector.1012 investigates - - - - investigates - + + + + investigates + Rectangle.1014 x-investigator: administrator - - - x-investigator: + + x-investigator:administrator - + Dynamic connector.1015 attributed-to - - - - attributed-to - + + + + attributed-to + Dynamic connector.1016 captures-evidence-in - - - - captures-evidence-in - + + + + captures-evidence-in + Dynamic connector.1017 captures-evidence-in - - - - captures-evidence-in - + + + + captures-evidence-in + Dynamic connector.1018 captures-evidence-in - - - - captures-evidence-in - + + + + captures-evidence-in + Dynamic connector.1019 acquired_by_ref - - - - acquired_by_ref - + + + + acquired_by_ref + Dynamic connector.1020 evidence-of - - - - evidence-of - + + + + evidence-of + Rectangle.1021 x-action: Delete Images - - - x-action:Delete Images - + + + x-action:Delete Images + Rectangle.4 x-secondary-storage-: USB - - - x-secondary-storage-:USB - + + + x-secondary-storage-:USB + Dynamic connector.1023 image-of - - - - image-of - + + + + image-of + Dynamic connector.1024 action_refs - - - - action_refs - + + + + action_refs + Rectangle.1001 indicator: Delete images indicator - - - indicator:Delete images indicator - + + + indicator:Delete images indicator + Rectangle.1027 observed-data: Deleted images - - - observed-data: + + observed-data:Deleted images - + Dynamic connector.1028 indicated-by - - - - indicated- + + + indicated-by - + Rectangle.1006 x-timeline - - - x-timeline - + + + x-timeline + Dynamic connector.1031 reconstructed_by_ref - - - - reconstructed_by_ref - + + + + reconstructed_by_ref + Dynamic connector.1032 based-on - - - - based-on - + + + + based-on + Rectangle.1075 file: f0106393.jpg - - - file:f0106393.jpg - + + + file:f0106393.jpg + Dynamic connector.1035 object_refs - - - - object_refs - + + + + object_refs + Rectangle.1098 x-investigation-tool: PhotoRec7.1 - - - x-investigation-tool:PhotoRec7.1 - + + + x-investigation-tool:PhotoRec7.1 + Rectangle.1039 file: f0106409.jpg - - - file:f0106409.jpg - + + + file:f0106409.jpg + Dynamic connector.1043 object_refs - - - - object_refs - + + + + object_refs + Rectangle.1044 file: f0106865.gif" - - - file:f0106865.gif" - + + + file:f0106865.gif" + Dynamic connector.1047 object_refs - - - - object_refs - + + + + object_refs + Rectangle.1049 file: f0106889.gif - - - file:f0106889.gif - + + + file:f0106889.gif + Dynamic connector.1051 object_refs - - - - object_refs - + + + + object_refs + Sheet.1054 artifact: I “hid” the photos - - - artifact:I “hid” the photos - + + + artifact:I “hid” the photos + Rectangle.1055 file: F0335017.doc - - - file:F0335017.doc - + + + file:F0335017.doc + Dynamic connector.1056 content_ref - - - - content_ref - + + + + content_ref + Rectangle.1059 observed-data: Deleted doc - - - observed-data: + + observed-data:Deleted doc - + Dynamic connector.1060 object_refs - - - - object_refs - + + + + object_refs + Rectangle.1061 Indicator: Delete doc indicator - - - Indicator:Delete doc indicator - + + + Indicator:Delete doc indicator + Dynamic connector.1062 based-on - - - - based-on - + + + + based-on + Rectangle.1063 x-action: Delete .doc - - - x-action:Delete .doc - + + + x-action:Delete .doc + Dynamic connector.1064 action_refs - - - - action_refs - + + + + action_refs + Dynamic connector.1065 indicated-by - - - - indicated- + + + indicated-by - + Rectangle.1067 file: F0105065.jpg - - - file:F0105065.jpg - + + + file:F0105065.jpg + Rectangle.1068 Indicator: steganographic tool, images indicator - - - Indicator:steganographic tool, images indicator - + + + Indicator:steganographic tool, images indicator + Rectangle.1069 artifact: jphide - - - artifact:jphide - + + + artifact:jphide + Rectangle.1070 x-investigation-tool: stegdetect - - - x-investigation-tool:stegdetect - + + + x-investigation-tool:stegdetect + Dynamic connector.1071 inputs_refs - - - - inputs_refs - + + + + inputs_refs + Dynamic connector.1072 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Rectangle.1073 observed-data: steg tool and images - - - observed-data:steg tool + + observed-data:steg tool and images - + Dynamic connector.1074 object_refs - - - - object_refs - + + + + object_refs + Dynamic connector.1075 based-on - - - - based-on - + + + + based-on + Dynamic connector.1076 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1077 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1078 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1079 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1080 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1081 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1082 imputs_refs - - - - imputs_refs - + + + + imputs_refs + Rectangle.1083 x-action: Hide Images - - - x-action:Hide Images - + + + x-action:Hide Images + Dynamic connector.1084 targets_refs - - - - targets_refs - + + + + targets_refs + Dynamic connector.1085 targets_refs - - - - targets_refs - + + + + targets_refs + Dynamic connector.1086 targets_refs - - - - targets_refs - + + + + targets_refs + Dynamic connector.1087 indicated-by - - - - indicated- + + + indicated-by - + Dynamic connector.1088 action_refs - - - - action_refs - + + + + action_refs + Sheet.1089 artifact: password-gator - - - artifact:password-gator - + + + artifact:password-gator + Dynamic connector.1090 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Rectangle.1091 x-investigation-tool: jpseek - - - x-investigation-tool:jpseek - + + + x-investigation-tool:jpseek + Dynamic connector.1092 inputs_refs - - - - inputs_refs - + + + + inputs_refs + Dynamic connector.1093 inputs_refs - - - - inputs_refs - + + + + inputs_refs + Rectangle.1094 file: r065.jpg - - - file:r065.jpg - + + + file:r065.jpg + Dynamic connector.1095 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1096 object_refs - - - - object_refs - + + + + object_refs + Dynamic connector.1097 object_refs - - - - object_refs - + + + + object_refs + Rectangle.1098 file: F0104249.jpg - - - file:F0104249.jpg - - Dynamic connector.1099 - outputs_refs - - - - - outputs_refs - + + + file:F0104249.jpg + Rectangle.1100 artifact: jphide - - - artifact:jphide - + + + artifact:jphide + Sheet.1101 artifact: password-gumbo - - - artifact:password-gumbo - + + + artifact:password-gumbo + Rectangle.1102 x-investigation-tool: stegdetect - - - x-investigation-tool:stegdetect - + + + x-investigation-tool:stegdetect + Dynamic connector.1103 inputs_refs - - - - inputs_refs - + + + + inputs_refs + Dynamic connector.1104 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1105 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Rectangle.1106 file: r249.jpg - - - file:r249.jpg - + + + file:r249.jpg + Rectangle.1107 x-investigation-tool: jpseek - - - x-investigation-tool:jpseek - + + + x-investigation-tool:jpseek + Dynamic connector.1108 inputs_refs - - - - inputs_refs - + + + + inputs_refs + Dynamic connector.1109 inputs_refs - - - - inputs_refs - + + + + inputs_refs + Dynamic connector.1110 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1111 object_refs - - - - object_refs - + + + + object_refs + Dynamic connector.1112 object_refs - - - - object_refs - + + + + object_refs + Dynamic connector.1113 object_refs - - - - object_refs - + + + + object_refs + Rectangle.1114 url: 137.30.120.40 - - - url:137.30.120.40 - + + + url:137.30.120.40 + Rectangle.1115 url: 137.30.122.253 - - - url:137.30.122.253 - + + + url:137.30.122.253 + Rectangle.1116 file: rhino1.jpg - - - file:rhino1.jpg - + + + file:rhino1.jpg + Rectangle.1117 network-traffic: rhino1.jpg - - - network-traffic:rhino1.jpg - + + + network-traffic:rhino1.jpg + Dynamic connector.1118 src_ref - - - - src_ref - + + + + src_ref + Dynamic connector.1119 dst_ref - - - - dst_ref - + + + + dst_ref + Rectangle.1120 x-investigation-tool: Wireshark - - - x-investigation-tool:Wireshark - + + + x-investigation-tool:Wireshark + Dynamic connector.1121 inputs_refs - - - - inputs_refs - + + + + inputs_refs + Dynamic connector.1122 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1123 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Rectangle.1124 observed-data: network images FTP - - - observed-data: + + observed-data:network images FTP - + Dynamic connector.1125 object_refs - - - - object_refs - + + + + object_refs + Dynamic connector.1126 object_refs - - - - object_refs - + + + + object_refs + Rectangle.1127 indicator: upload indicator - - - indicator:upload indicator - + + + indicator:upload indicator + Dynamic connector.1128 based-on - - - - based-on - + + + + based-on + Rectangle.1129 x-action: upload Images - - - x-action:upload Images - + + + x-action:upload Images + Dynamic connector.1130 targets_refs - - - - targets_refs - + + + + targets_refs + Dynamic connector.1131 indicated-by - - - - indicated- + + + indicated-by - + Dynamic connector.1132 action_refs - - - - action_refs - + + + + action_refs + Rectangle.1133 network-traffic: rhino3.jpg - - - network-traffic:rhino3.jpg - + + + network-traffic:rhino3.jpg + Dynamic connector.1134 des_ref - - - - des_ref - + + + + des_ref + Dynamic connector.1135 src_ref - - - - src_ref - + + + + src_ref + Rectangle.1137 file: rhino3.jpg - - - file:rhino3.jpg - + + + file:rhino3.jpg + Dynamic connector.1138 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1139 object_refs - - - - object_refs - + + + + object_refs + Dynamic connector.1140 object_refs - - - - object_refs - + + + + object_refs + Rectangle.1141 network-traffic: contraband.zip - - - network-traffic:contraband.zip - + + + network-traffic:contraband.zip + Dynamic connector.1142 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Rectangle.1143 file: contraband.zip - - - file:contraband.zip - + + + file:contraband.zip + Rectangle.1144 file: rhino2.jpg - - - file:rhino2.jpg - + + + file:rhino2.jpg + Sheet.1145 artifact: password.monkey - - - artifact:password.monkey - + + + artifact:password.monkey + Rectangle.1146 x-investigation-tool: fcrackzip - - - x-investigation-tool:fcrackzip - + + + x-investigation-tool:fcrackzip + Dynamic connector.1147 inputs_ref - - - - inputs_ref - + + + + inputs_ref + Dynamic connector.1148 outputs_ref - - - - outputs_ref - + + + + outputs_ref + Dynamic connector.1149 extensions.archive-ext.contains_refs - - - - extensions.archive-ext.contains_refs - + + + + extensions.archive-ext.contains_refs + Dynamic connector.1150 extensions.archive-ext.contains_refs - - - - extensions.archive-ext.contains_refs - + + + + extensions.archive-ext.contains_refs + Dynamic connector.1151 src_ref - - - - src_ref - + + + + src_ref + Dynamic connector.1152 des_ref - - - - des_ref - + + + + des_ref + Dynamic connector.1153 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1154 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1155 - + - + Dynamic connector.1156 object_refs - - - - object_refs - + + + + object_refs + Dynamic connector.1157 object_refs - - - - object_refs - + + + + object_refs + Dynamic connector.1158 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Rectangle.1159 url: 137.30.123.234 - - - url:137.30.123.234 - + + + url:137.30.123.234 + Rectangle.1160 url: 137.30.120.37 - - - url:137.30.120.37 - + + + url:137.30.120.37 + Rectangle.1161 network-traffic: rhino4.jpg - - - network-traffic:rhino4.jpg - + + + network-traffic:rhino4.jpg + Rectangle.1162 file: rhino4.jpg - - - file:rhino4.jpg - + + + file:rhino4.jpg + Dynamic connector.1163 src_ref - - - - src_ref - + + + + src_ref + Dynamic connector.1164 dst_ref - - - - dst_ref - + + + + dst_ref + Rectangle.1165 x-investigation-tool: Wireshark - - - x-investigation-tool:Wireshark - + + + x-investigation-tool:Wireshark + Dynamic connector.1166 inputs_refs - - - - inputs_refs - + + + + inputs_refs + Dynamic connector.1167 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1168 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Rectangle.1169 observed-data: http download images - - - observed-data:http download images - + + + observed-data:http download images + Dynamic connector.1170 object_refs - - - - object_refs - + + + + object_refs + Dynamic connector.1171 object_refs - - - - object_refs - + + + + object_refs + Rectangle.1172 Indicator: download image pattern - - - Indicator:download image pattern - + + + Indicator:download image pattern + Dynamic connector.1173 based-on - - - - based-on - + + + + based-on + Dynamic connector.1174 targets_refs - - - - targets_refs - + + + + targets_refs + Dynamic connector.1175 targets_refs - - - - targets_refs - + + + + targets_refs + Dynamic connector.1176 targets_refs - - - - targets_refs - + + + + targets_refs + Dynamic connector.1177 targets_refs - - - - targets_refs - + + + + targets_refs + Dynamic connector.1178 targets_refs - - - - targets_refs - + + + + targets_refs + Rectangle.1179 x-action: Download Images - - - x-action:Download Images - + + + x-action:Download Images + Dynamic connector.1180 action_refs - - - - action_refs - + + + + action_refs + Dynamic connector.1181 indicated-by - - - - indicated- + + + indicated-by - + Rectangle.1182 network-traffic: rhino5.gif - - - network-traffic:rhino5.gif - + + + network-traffic:rhino5.gif + Dynamic connector.1183 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1184 src_ref - - - - src_ref - + + + + src_ref + Dynamic connector.1185 det_ref - - - - det_ref - + + + + det_ref + Rectangle.1186 file: rhino5.gif - - - file:rhino5.gif - + + + file:rhino5.gif + Dynamic connector.1187 outputs_refs - - - - outputs_refs - + + + + outputs_refs + Dynamic connector.1188 object_refs - - - - object_refs - + + + + object_refs + Dynamic connector.1189 object_refs - - - - object_refs - + + + + object_refs + Dynamic connector.1190 targets_refs - - - - targets_refs - + + + + targets_refs + Dynamic connector.1191 targets_refs - - - - targets_refs - + + + + targets_refs + Dynamic connector.1192 reconstructed_from_ref - - - - reconstructed_from_ref - + + + + reconstructed_from_ref + Dynamic connector.1197 object_refs - - - - object_refs - + + + + object_refs + Dynamic connector.1198 object_refs - - - - object_refs - + + + + object_refs + + Dynamic connector.1200 + outputs_refs + + + + + outputs_refs + @@ -1687,32 +1699,32 @@ - + - - + + Note.1193 [file:extensions.auxiliary-ext.status='recovered' and file:ex... - + - - - - - [file:extensions.auxiliary-ext.status='recovered' and file:extensions.auxiliary-ext.content_tags[0]='rhino'] - + + + + + [file:extensions.auxiliary-ext.status='recovered' and file:extensions.auxiliary-ext.content_tags[0]='rhino'] + Sheet.1194 - + - + @@ -1726,38 +1738,79 @@ - + Note.1195 //"jphide tool used for hidding images"+"two passwords found"... - + - - - - - //"jphide tool used for hidding images"+"two passwords found" + "two jpgs are decoded from other images"[artifact:payload_bin MATCHES 'anBoaWRl' and file:extensions.auxiliary-ext.status='decoded' and exists artifact--01b778f5-e334-52a5-a49d-f9b2de330be9 and exists artifact--5bb67aa9-d849-465d-a433-114063836965] - + + + + + //"jphide tool used for hidding images"+"two passwords found" + "two jpgs are decoded from other images"[artifact:payload_bin MATCHES 'anBoaWRl' and file:extensions.auxiliary-ext.status='decoded' and file:extensions.auxiliary-ext.content_tags[0]='rhino' and exists artifact--01b778f5-e334-52a5-a49d-f9b2de330be9 and exists artifact--5bb67aa9-d849-465d-a433-114063836965] + Sheet.1196 - + + + + + + + + + + + + + + + + + + + + Note.1202 + grouping-1 + + + + + + + grouping-1 + + Sheet.1203 + + + + diff --git a/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.vsdx b/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.vsdx index cd6f40b..97a5f93 100644 Binary files a/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.vsdx and b/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.vsdx differ