Malware Can Hide, But It Must Run

It’s October, haunting season. However, in the forensics world, the hunting of evil never ends. And with Windows 10 expected to be the new normal, digital forensics and incident response (DFIR) professionals who lack the necessary (memory) hunting skills will pay the price.

Investigators who do not look at volatile memory are leaving evidence at the crime scene. RAM content holds evidence of user actions, as well as evil processes and furtive behaviors implemented by malicious code. It is this evidence that often proves to be the smoking gun that unravels the story of what happened on a system.

Although Microsoft is not expected to reach its Windows 10 rollout goal of one billion devices in the next two years, their glossiest OS to date currently makes up 22% of desktop systems according to netmarketshare.com.

Read More Continue reading Malware Can Hide, But It Must Run

Posted in Uncategorized

Breaking the Android Puzzle with Oxygen Forensic® Detective v. 9.0

Oxygen Forensics, the worldwide developer and provider of advanced forensic data examination tools for mobile devices and cloud services, announced today that it has added a Jet-Imager module to its Oxygen Forensic® Detective product that allows users to acquire data from Android devices faster saving experts critical time while solving law enforcement cases.

“With the new Jet-Imager module, experts using our products will be able to speed up data acquisition on Android devices which will save them minutes or maybe even hours in some cases and that directly translates to closing cases faster,” said Lee Reiber, Oxygen Forensics COO. “Oxygen Forensics will continue to seek ways to speed up the time it takes for forensics experts to do their job since budgets are always in the crosshairs and organizations are constantly looking for ways to save on overtime as well as solve cases more effectively”. Continue reading Breaking the Android Puzzle with Oxygen Forensic® Detective v. 9.0

Posted in Uncategorized

The “I’ve Been Hacked” Defence

by Yuri Gubanov, Oleg Afonin
(C) Belkasoft Research, 2016

Abstract
This article was inspired by an active discussion in one of the forensic listservs. Original post was asking on how to fight with an argument “This is not me, this is a malware”. The suspect was allegedly downloading and viewing illicit child photos and was denying that, explaining the fact of these photos’ presence by malicious software they presumably had.

I’ve Been Hacked
The “I’ve been hacked” tactic is the most common defense when it comes to crimes committed on or with computers. However obvious it might be, the burden of proof lies on you and not on the suspect. So how can you figure out whether or not the suspect’s computer has actually been subject to unauthorized activities?

Read More Continue reading The “I’ve Been Hacked” Defence

Posted in Uncategorized

Arsenal Recon Launches Breakthrough Microsoft Windows Hibernation Forensic Tool

Hibernation Recon Provides Digital Forensics Experts with Unprecedented Access to Hibernation Data

Arsenal Recon, digital forensics experts building powerful tools to improve the analysis of electronic evidence, announced the formal release of Hibernation Recon today. Hibernation Recon extracts valuable information from Microsoft Windows® XP, Vista, 7, 8, 8.1, and 10 hibernation files that other tools have failed to reveal for many years. Digital forensics experts armed with Hibernation Recon are now able to exploit not only the active contents of Windows hibernation files, but also massive volumes of information in the multiple levels of slack space within them. Continue reading Arsenal Recon Launches Breakthrough Microsoft Windows Hibernation Forensic Tool

Posted in Uncategorized

New Performance Enhancements in Magnet AXIOM Mean Faster Results

Processing Times Reduced Dramatically in AXIOM 1.0.6

By Jad Saliba, Founder and CTO at Magnet Forensics

Last week, we released Magnet AXIOM version 1.0.6. This update included a number of features and fixes, but one of the main goals was to address issues we, and our customers, had seen in processing times. And we did it! AXIOM Process times are now testing as being equal to, or slightly faster than, IEF.

Here’s how we did it… Continue reading New Performance Enhancements in Magnet AXIOM Mean Faster Results

Posted in Uncategorized

BlackBag® helps Saskatoon Police Service put a criminal behind bars

BlackBag® Technologies’ premiere digital forensic software, BlackLight® helped put a man, convicted of possessing 450 child pornography images, behind bars. Marcel Cole Beuker, whose trial was held in March of this year, claimed the images found on a hard drive connected to his iMac, were not his. It took three long years for the Saskatchewan Internet Child Exploitation (ICE) unit to bring him to justice, but their diligent work secured a conviction. Beuker received an 18-month sentence, plus 4 months for disobeying release conditions.

During the trial, BlackLight®’s .fseventsd feature was featured prominently. The ICE unit had their work cut out for them, as Beuker was an experienced programmer and very tech savvy. Using tools, including BlackLight®, they were able to show almost all of the communication originated from the accused’s system, and no other devices. Continue reading BlackBag® helps Saskatoon Police Service put a criminal behind bars

Posted in Uncategorized

Forensic Focus Forum Round-Up

Welcome to this month’s round-up of recent posts to the Forensic Focus forums.

Can you help honor_the_data work out this USB storage timestamp anomaly?

Forum members discuss iPhone 4S iTunes backup encryption.

Should you apply for ISO/IEC 17020 and 17025 if you’re a one-person organisation?

Which programming language should you learn if you’re a digital forensic examiner?

Do SSDs ‘shrink’ over time? Add your thoughts in the forum.

Forum members discuss detection of file-hollowing.

How would you bypass a PIN-locked SIM? Chime in on the forum.

Are we ready for Apple vs. the FBI round two?

Forum members discuss eSIM chip-off forensics.

How can we extract evidence from Virtual Assistants? Continue reading Forensic Focus Forum Round-Up

Posted in Uncategorized

Why False Positives Are Important

By Jamie McQuaid

Most forensic examiners are familiar with seeing false positives in their search or processing results. False positives will always be present in tools that conduct some form of data carving in their searching and/or processing.

I often get questions from forensic examiners (both new and experienced) on whether the data that IEF or AXIOM has found is valid. Without seeing the data myself, it’s quite difficult to determine the validity of the information so I’ll typically respond with several follow up questions trying to understand what the examiner is seeing. This helps me assess the likelihood of the data being either valid or a false positive. Continue reading Why False Positives Are Important

Posted in Uncategorized

Webinar: Challenges Mobile Devices Pose in Global Investigations

11 October
9:00AM ET / 2:00PM UK / 3:00PM CEST

Discussion Topics:

– To some extent, the ubiquity of mobile devices—and many people’s use of them as their primary digital interface—has come in the aftermath of the first wave of standards being set for e-discovery, data retention, and so on.
– What are a party’s duties of control, retention, production, and so on?
– In terms of data generated on or stored in mobile devices, where is the line drawn between what the corporate entity (presumably your client) is deemed responsible for as opposed to what the individual possessing the mobile device is responsible for? Is it primarily based on (a) physical possession; (b) legal title/ownership; (c) beneficial ownership/control; or (d) some other factor or combination?
– Enforcement procedures including parties, venue, noteworthy procedural requirements?

Panelists will include: Ian De Freitas, Partner, BLP, London; Tim Hickman, Counsel, White & Case, London; Kevin DeLong, Vice President of Mobile Investigations, AccessData

Register here Continue reading Webinar: Challenges Mobile Devices Pose in Global Investigations

Posted in Uncategorized