Forensic analysis is one of the least de veloped areas of computer security. Inve stigations are often handled by individu als withlittle more than a software cert ifications and very few investigators ha ve detailed knowledge of the inner worki ngs of the software and systems they ana lyze. A checklist of search terms and a copy of EnCase is often sufficient for c ases involving less knowledgeable defend ants, but what happens when a skilled at tacker plans for the eventuality of fore nsic analysis? This talk will discuss th e process and failings of forensic analy sis as it is commonly performed today. W e will present the details of techniques which can be used to undermine modern f orensic analysis. These techniques will be outlined through detailed samples imp lemented in a Linux rootkit along with i mprovements that could be made to the fo rensic process. Cris Neckar is currently a jobless bum b ut will be starting on Google's security team in May. Until recently he was a Se nior Application Security Consultant at Neohapsis Inc. where he specialized in a pplication assessment, vulnerability res earch, and exploit development. In this capacity Cris led penetration tests and whitebox assessments on high profile sof tware, web applications and embedded dev ices as well as forensic malware analysi s. Cris also spends his time performing and publishing research into new attack techniques. As an adjunct professor for DePaul University's College of Digital M edia in Chicago, Cris developed and teac hes one of the first graduate level cour ses on the technical details of applicat ion assessment and exploit development. As an Application Security Consultant at Neohapsis Inc., Greg specializes in app lication security assessment, internal a nd external penetration testing, as well as performing research on topics rangin g from kernel-level exploitation to web application vulnerabilities. Prior to jo ining Neohapsis, Greg developed a lightw eight security framework for mobile devi ces and implemented a secure boot and re -imaging infrastructure to enforce data integrity.