Digital Forensic Investigational Tool For Volatile Browser Based Data Analysis

by W.Chirath De Alwis, School of Computing, Asia Pacific Institute of Information Technology, Colombo, Sri Lanka

Cyber security threats on sensitive resources have increased recently and it has increased the need for digital forensic analysis tools. D… Continue reading Digital Forensic Investigational Tool For Volatile Browser Based Data Analysis

Posted in Uncategorized

Comprehensive Forensic Chat Examination with Belkasoft

Call logs, SMSes, emails, social networks communications and, of course, chats in instant messengers can give you a lot of important information in a course of a forensic investigation. Let’s see how one single chat product can be examined from different aspects, each of which gives one more – unique! – part of puzzle.

In our case, the suspect had Skype installed on his laptop and mobile device which were seized and investigated with Belkasoft Evidence Center 2017.

First part of the analysis is easy: chats are extracted from existing main.db, a SQLite database where Skype stores its history logs. Continue reading Comprehensive Forensic Chat Examination with Belkasoft

Posted in Uncategorized

Forensic Focus Forum Round-Up

Welcome to this month’s round-up of recent posts to the Forensic Focus forums.

Forum members discuss how to extract data from a device with a faulty USB connection.

What is the most forensically sound way to acquire RAM on a PC? Add your thoughts in the forum.

Is it possible to tell whether data has already been extracted from a phone?

Do you have any recommendations for good digital forensics books?

How would you show evidence that someone had tried to access a Windows shared drive? Chime in on the forum.

Can you help giandega forensically analyse a Garmin Navigator?

Forum members discuss how to bypass iPhone 5 & 6 encrypted backups.

Renfantino is looking for a way to extract data from a CCTV system – can you help?

Can you recommend some software to brute force EFS decryption? Continue reading Forensic Focus Forum Round-Up

Posted in Uncategorized

Oxygen Forensics and Passware Team Up to Provide Extraction of iOS Photo Stream

Oxygen Forensics, the worldwide developer and provider of advanced forensic data examination tools for mobile devices and cloud services, announced today that it is teaming with Passware Inc. to provide customers the ability for instant extraction of iOS Photo Stream files.

“We’ve been working with Passware Inc. since 2013, and we’re very pleased to join forces again to show our customers the distinct advantage of combining data extraction with decryption as they work hard to solve crimes and other mysteries that only mobile devices can tell,” said Lee Reiber, Oxygen Forensics COO. “Law enforcement and eDiscovery professionals will great benefit in time savings with both Oxygen Forensic Detective and Passware Kit Forensic harmoniously working side by side.” Continue reading Oxygen Forensics and Passware Team Up to Provide Extraction of iOS Photo Stream

Posted in Uncategorized

Elcomsoft Extracts iPhone Calls, Contacts, Calendars and Web Browsing Activities

ElcomSoft Co. Ltd. updates Elcomsoft Phone Breaker, the company’s mobile acquisition tool. Version 6.30 gains the ability to extract information about the user’s recent Web browsing activities, notes and calendars from the cloud. In contrast with cloud backups, this information along with call logs and contacts is available with little or no delay, enabling near real-time access to essential user activity data. This can be essential for the law enforcement and forensic experts who may need urgent access to the most recent data that has not become part of a cloud backup. Continue reading Elcomsoft Extracts iPhone Calls, Contacts, Calendars and Web Browsing Activities

Posted in Uncategorized

The Ugly Side of Two-Factor Authentication

by ElcomSoft

Two-factor authentication is great when it comes to securing access to someone’s account. It’s not so great when it gets in the way of accessing your account. However, in emergency situations things can turn completely ugly. In this article we’ll discuss steps you can do to minimize the negative consequences of using two-factor authentication if you lose access to your trusted device and your trusted phone number. In order to keep the size of this text reasonable we’ll only talk about Apple’s implementation, namely Two-Step Verification and Two-Factor Authentication.

Two-Factor Authentication in Emergencies

What’s an emergency? For the purpose of this article, we’ll look at a common scenario of a traveler going abroad with an iPhone. The iPhone goes missing or gets stolen.

Read More Continue reading The Ugly Side of Two-Factor Authentication

Posted in Uncategorized

BlackBag’s Forensic Certification Courses Scheduled for 2017

BlackBag®’s EFT I and II are now open for registration for 2017. Sign up now to reserve your spot!

ESSENTIAL FORENSIC TECHNIQUES I (EFT I)
SAN JOSE, CA – FEB 6, 2017
STAFFORD, UK – FEB 20, 2017
LARGO, FL – MAY 1, 2017

ESSENTIAL FORENSIC TECHNIQUES II (EFT II)
SAN JOSE, CA – FEB 13, 2017
STAFFORD, UK – FEB 27, 2017
LARGO, FL – MAY 8, 2017

Each course is one week long taught by industry-leading experts in a professional training setting. Please click on the corresponding course for more information or to register. If you are unsure if you are qualified to take the EFT II course take our placement exam. Continue reading BlackBag’s Forensic Certification Courses Scheduled for 2017

Posted in Uncategorized

New Federal Rule of Evidence to Impact Computer Forensics and eDiscovery

by John Patzakis, X1

A key amendment to US Federal Rule of Evidence 902, in the form of new subsection (14), will go into effect on December 1, 2017. This amendment will significantly impact eDiscovery and computer forensics software and its use by establishing that electronic data recovered “by a process of digital identification” is to be self-authenticating, thereby not routinely necessitating the trial testimony of a forensic or technical expert where best practices are employed, as certified through a written affidavit by a “qualified person.”

Notably, the accompanying official Advisory Committee notes specifically reference the importance of both generating “hash values” and verifying them post-collection as a means to meet this standard for self-authentication. This digital identification and verification process can only be achieved with purpose-built computer forensics or eDiscovery collection and preservation tools.

Read More Continue reading New Federal Rule of Evidence to Impact Computer Forensics and eDiscovery

Posted in Uncategorized