Claim Missing Document
Check
Articles

Found 2 Documents
Search

Enhancing Digital Forensics with Cyber Kill Chain and 5W1H: A Case Study on Phishing Attacks Erika Ramadhani; Toto Raharjo
IJoICT (International Journal on Information and Communication Technology) Vol. 11 No. 1 (2025): Vol. 11 No. 1 Jun 2025
Publisher : School of Computing, Telkom University

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.21108/ijoict.v11i1.8966

Abstract

This research has combined the Cyber Kill Chain (CKC) model and the 5W1 H for detection and control of cybercrime such as phishing for the automation of digital forensic investigation. The most vital challenge in digital forensics is its evidence handling complexity, the lack of a standard because of diversified kinds of tools, and the non-availability of automated tools that systematically present information. Therefore, it provides a web-based framework to automate the investigation by referring to the attack stages of the CKC and identifies the contextual allegories of the incident like who, what, when, where, why, and how through the rule of 5W1H. It includes the problem identification method, collecting and classifying the digital artifacts according to CKC stages, in-depth analysis with the 5W1H framework, and visualization of investigation results for further understanding. A case study of a phishing attack on the Kredivo application was used to evaluate the effectiveness of this approach, where the CKC stages from reconnaissance to actions on objectives were implemented to analyze artifacts such as activity logs and phishing data. The results show that the integration of CKC and 5W1H improves analysis accuracy, generates comprehensive visualizations of artifacts, and strengthens response to attacks. It is expected that this finding would mean a highly significant change in the productivity of forensic investigations by making it easier for analysts and preparing proper documentation education for the court.
Simulated Phishing Attack and Forensic Analysis Using the D4I Framework: A Case Study on Kredivo Muhammad Yusuf Halim; Toto Raharjo; Rosi Rahmadi Syahputra; Erika Ramadhani
Journal of Technology and Informatics (JoTI) Vol. 7 No. 2 (2025): Vol. 7 N. 2 (2025)
Publisher : Universitas Dinamika

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.37802/joti.v7i2.1086

Abstract

Phishing is a form of cyberattack where attackers deceive users into revealing sensitive information such as credentials or financial data, often through fake communication channels or websites. This threat is particularly critical in the financial technology (fintech) sector, where services rely heavily on digital transactions and user trust. This study presents a simulated phishing case targeting Kredivo users to evaluate the effectiveness of the Digital Forensics framework for Reviewing and Investigating cyber-attacks (D4I) in digital forensic analysis. The Cyber Kill Chain (CKC) model was employed to trace attacker behavior across seven phases, from weaponization to actions on objectives. Forensic data was acquired using MOBILedit Forensic Express from two smartphones, namely an iPhone 11 (iOS 15.8.1) and a Vivo Y21 (Android 8.1.0), which served as simulated evidence devices. Using the D4I framework, the investigation successfully identified and correlated key digital artifacts such as phishing links, OTP transmissions, and unauthorized access logs. These findings were organized into a visual chain of artifacts to reconstruct the full attack lifecycle. The results demonstrate that the D4I framework is effective in guiding structured forensic investigations and understanding attack patterns, supporting the enhancement of fintech security strategies.