A Deeper Look at Magnet AXIOM’s Improved Hashing

By Jamie McQuaid, Forensic Consultant at Magnet Forensics

One of the most obvious benefits of Magnet AXIOM is the access to the entire file system, as well as the hundreds of artifact types that the Magnet Forensics parsing and carving engine finds. To accommodate the larger data set and expanded access, we’ve improved the hashing functionality as well.

If you are more familiar with IEF, then you know there are a few options to hash pictures or whitelist non-relevant files. However, since IEF only reports on the artifacts it finds, some features like hashing were limited to artifacts and any file that was not an artifact wouldn’t be included.

To get started using AXIOM’s advanced hashing functionality, the first thing you’ll want to do is to load your hash lists into AXIOM and, depending on the type of hash list you’re loading, you’ll have a few options available. Continue reading A Deeper Look at Magnet AXIOM’s Improved Hashing

Posted in Uncategorized

Oxygen Forensic® Detective extracts data from the most popular dating app!

Oxygen Forensics releases a maintenance version of Oxygen Forensic® Detective.

The new version adds bypassing of the screen lock and complete device image extraction from the new LG Android smartphones and support for 200+ Android OS devices.

Oxygen Forensic® Detective v. 9.0.2 offers data parsing from Plenty Of Fish – the world’s largest online dating service and updates support for other popular apps.

It also adds extraction of the information about Dropbox and video calls made in the latest WhatsApp application versions.

All registered customers may download the new version immediately from their personal customer area. Continue reading Oxygen Forensic® Detective extracts data from the most popular dating app!

Posted in Uncategorized

Magnet Forensics Launches New Training Curriculum and AXIOM Certification

The training team at Magnet Forensics has opened registration for a new AXIOM certification, and unveiled two new courses, launching in 2017: AXIOM Examinations and IEF Examinations.

Magnet Certified Forensics Examiner (MCFE) – AXIOM

Our newest MCFE certification is now open for registration! You can save your seat now for the MCFE – AXIOM certification exams that will begin in 2017.

The Magnet Forensics certification program is designed to validate expert-level competence for forensics professionals. The MCFE – AXIOM will authenticate your knowledge and expertise of Magnet AXIOM, our digital investigation platform. This certification covers all areas of functionality in AXIOM – acquisition and extraction, analysis and examination, and sharing and reporting. Continue reading Magnet Forensics Launches New Training Curriculum and AXIOM Certification

Posted in Uncategorized

Apple Silently Uploads Call Logs to iCloud, ElcomSoft Enables Acquisition

Apple cloud services, releases tool to extract iPhone call logs from iCloud. According to ElcomSoft, Apple automatically uploads iPhone call logs to Apple’s remote servers. Call logs can be stored on Apple servers for months, and there is no option for the end user to disable this sync without disabling iCloud entirely on their device. ElcomSoft updates Elcomsoft Phone Breaker 6.20 to give it the ability to download call logs made with iPhones running iOS 9 and newer directly from the cloud regardless of whether or not the device is locked and whether or not the passcode is known. Continue reading Apple Silently Uploads Call Logs to iCloud, ElcomSoft Enables Acquisition

Posted in Uncategorized

New Release Available of Leading Media Exploitation Tool: Triage-G2

ADF Solutions, a leading provider of digital forensic and media exploitation tools, has released Triage-G2®, the latest evolution of ADF’s award-winning media exploitation tool. Triage-G2 is deployed by special forces, military and intelligence agencies worldwide and has a proven track record of supporting site exploitation missions, including media exploitation (DOMEX/MEDEX) and biometric identity operations. Continue reading New Release Available of Leading Media Exploitation Tool: Triage-G2

Posted in Uncategorized

Forensic Focus Forum Round-Up

Welcome to this month’s round-up of recent posts to the Forensic Focus forums.

Forum members discuss how they manage their inventory.

Do you have any tips to help giandega acquire a Western Digital 1TB hard disk?

Is the date-time counter on video footage reliable? Add your thoughts on the forum.

How would you find out who deleted some files from a machine?

Why are InstallDate and InstallTime showing differently on this Windows OS?

Forum members discuss network acquisition.

How can we counter anti-forensic measures on mobile devices?

Add your recommendations for file carving software here.

Which software provides the best extraction results for social media applications? Chime in on the forum.

At what point do you report illegal activity to law enforcement when working on a civil case? Continue reading Forensic Focus Forum Round-Up

Posted in Uncategorized

Magnet AXIOM Now Supports Pebble Watch, LINE for Android, RAR Artifacts & More

Magnet AXIOM version 1.0.7 is now available.

This new version includes support for Pebble Watch for iOS and Android. Examiners can now access the Pebble Watch artifacts to recover information held by those apps, including notification time stamps, ca… Continue reading Magnet AXIOM Now Supports Pebble Watch, LINE for Android, RAR Artifacts & More

Posted in Uncategorized

Forensic Implications of iOS Lockdown (Pairing) Records

In recent versions of iOS, successful acquisition of a locked device is no longer a given. Multiple protection layers and Apple’s new policy on handling government requests make forensic experts look elsewhere when investigating Apple smartphones.

In this publication, we’ll discuss acquisition approach to an iOS device under these specific circumstances:

1. Runs iOS 8.x through 10.x
2. When seized, the device was powered on but locked with a passcode and/or Touch ID
3. Device was never powered off or rebooted since it was seized
4. Does not have a jailbreak installed and may not allow installing a jailbreak
5. Investigators have access to one or more computers to which the iOS device was synced (iTunes) or trusted (by confirming the “Trust this PC” pop-up on the device) in the past

Read More Continue reading Forensic Implications of iOS Lockdown (Pairing) Records

Posted in Uncategorized

The Growth of Digital Evidence Backlogs and Making Them a Thing of the Past

By Adam Belsher, CEO Magnet Forensics

A recent report by the United Kingdom’s police oversight body, Her Majesty’s Inspectorate of Constabulary (HMIC), highlights a key issue that law enforcement agencies across the globe are facing: there is an overwhelming amount of digital evidence piling up.

This shouldn’t come as a surprise given the proliferation of smartphones, tablets, drives, computers, and other connected devices. Some estimates show that there will be 6.1 billion smartphones alone in the world by 2020.

Unfortunately, these devices not only make our lives more convenient, they have also helped to enable criminals. It’s easy to imagine that almost every criminal case could involve some form of digital evidence. Continue reading The Growth of Digital Evidence Backlogs and Making Them a Thing of the Past

Posted in Uncategorized