RAM Forensic Analysis

by Eliézer Pereira

1 Goal

The purpose of this article is show how to perform a RAM memory forensic analysis, presenting some examples of information that can be retrieved and analyzed to help identify indications of security incidents as well as fraud and other illegal practices through information systems.

2 Good Practices and Techniques for Computer Forensic Analysis

2.1 NIST 800-86

The National Institute of Standards and Technology (NIST) is known worldwide for the publication of documents that bring well detailed and well comprehensive technology standards.

Document 800-86 – Guide to Integrating Forensic Techniques into Incident Response has a number of recommendations for proceeding with forensic analysis of security incidents, from data collection to the preparation of a final report.

Read More Continue reading RAM Forensic Analysis

Posted in Uncategorized

Job Vacancy: Lecturer In Digital Forensics (2 Posts)

School of Cranfield Defence and Security

Lecturer in Digital Forensics (2 posts)

Permanent

Lecturer Salary: £41,153 to £45,872 per annum (with additional performance related pay up to £57,340 per annum)

Location: Shrivenham, Oxfordshire, SN6 8LA

Here at Cranfield, we can offer you the opportunity and resources to really develop your career. Cranfield Defence and Security (CDS) provides unique educational opportunities to the defence and security sectors of both public and private sector organisations.

Cranfield Forensic Institute (CFI) provides a Centre of Excellence for the application of science and technology to law enforcement particularly, through forensic science and engineering. The Digital Forensics Unit is part of the Cranfield Forensic Institute and is in a fast moving academic and practical arena, with sought after expertise and considerable credentials in the area of forensic computing. The MSc in Digital Forensics run by the Digital Forensics Unit was the first Digital Forensics course to gain full certification from GCHQ.

Read More Continue reading Job Vacancy: Lecturer In Digital Forensics (2 Posts)

Posted in Uncategorized

Remote Forensics Of Windows 10 Mobile Devices

by Oleg Afonin, Elcomsoft

Microsoft has developed Windows 10 as the one OS for all types of devices from servers to wearables. Desktops, laptops, two-in-ones, tablets and smartphones can (and do) run a version of Windows 10. There are countless forensic tools for acquiring evidence from the desktop version of Windows 10, much less for Windows-powered smartphones.

Forensic analysis of Windows 10 Mobile devices can be complicated due to the exotic status of such devices. Due to full-disk encryption, on-device access may not be an option. However, Microsoft collects enormous amounts of information from its users. This information is then stored in the user’s Microsoft Account. Some bits of data are fully accessible to the user, while access to some other bits (such as mobile backups) is restricted.

Read More Continue reading Remote Forensics Of Windows 10 Mobile Devices

Posted in Uncategorized

Laminar Flow Cabinet from HddSurgery

HddSurgery Ltd. is a global leader in providing professional data recovery and computer forensic hardware tools since 2009.

Our mission is to find optimal solutions for common mechanical problems with hard drives, such as broken heads, head stiction and jammed spindle.

Beside the tools which solve these problems, our company provides assistive data recovery tools like Workbench, Platter stand, Head holder and Unlock key.

This year we introduced the most sophisticated product from our company – HDDS Horizontal Laminar Flow Cabinet M. Continue reading Laminar Flow Cabinet from HddSurgery

Posted in Uncategorized

Interview With Cesar Leon, Head Of Support Team, Oxygen Forensics

Cesar, you’re Head of the Support Team at Oxygen. Tell us about your role – what does your day-to-day job look like?

Hey! My role right now is to help my team supporting our software to our end users all over the world, to the best of our abilities. Whether that be with helping with technical issues, or commercial issues, I help my team with whatever questions or concerns they need.

My day to day really varies, as one day it can be all research into why a particular problem is occurring with the software, or another day helping our Sales Team complete a huge order. I’m a jack of all trades for the company, and every day brings new challenges and tasks.

Read More Continue reading Interview With Cesar Leon, Head Of Support Team, Oxygen Forensics

Posted in Uncategorized

Webinar: Information Overload: Navigating In Today’s Regulatory Environment

Webinar: Information Overload: Navigating Information Risk, Investigations & Privacy in Today’s Regulatory Environment (…and Staying Compliant)

http://bit.ly/2szneQS

June 27th
Information Risk and Compliance in the Information Age

July 11th
Managing Internal Investigations Swamped With Data

July 25th
It’s No Secret: What New Data Protection Regulations Mean for Risk Management

All webinars will be held at 8:00 AM PT /11:00 AM ET / 4:00 PM UK Continue reading Webinar: Information Overload: Navigating In Today’s Regulatory Environment

Posted in Uncategorized

ADF Solutions Partners With Belkasoft To Provide Mobile Computing Analysis

ADF Solutions and Belkasoft, both leading providers of digital forensic tools, today joined in a partnership that will allow ADF Solutions to license core Belkasoft technology into its field forensic and triage solutions to analyze mobile computing devices. This additional capability will be offered as an add-on to current ADF users, including field investigators, military operatives, and border agents.

“ADF is the leading provider of field forensic and triage solutions for computers and storage media, and this partnership extends our mobile computing technology to a new group of users.” said Yuri Gubanov, CEO of Belkasoft. Continue reading ADF Solutions Partners With Belkasoft To Provide Mobile Computing Analysis

Posted in Uncategorized