Elcomsoft Phone Breaker 6.0 Decrypts FileVault 2, Downloads iCloud Photos

ElcomSoft Co. Ltd. releases a major update to Elcomsoft Phone Breaker, the company’s mobile forensic tool for logical and over-the-air acquisition of mobile devices. Version 6.0 adds support for decrypting FileVault 2 volumes by downloading the Recovery Key from iCloud. In addition, the new release adds the ability to download existing and recently deleted photos and media files from iCloud Photos. Other changes include the updated Keychain Explorer and the ability to cache online authentication credentials for streamlined subsequent logins into iCloud, Windows Phone and BlackBerry 10. Continue reading Elcomsoft Phone Breaker 6.0 Decrypts FileVault 2, Downloads iCloud Photos

Posted in Uncategorized

Exploring Magnet AXIOM’s Examiner-Created File System and Registry Artifacts

We’re excited to introduce you to Jessica Hyde, our new Director, Forensics. Jessica will be contributing to the Magnet Forensics blog with insights on the digital forensics industry and in-depth looks at our products and product features.

Her inaugural blog explores the ability to add an artifact from the File System or Registry Explorers and provides how-tos for you to create your own.

Read More Continue reading Exploring Magnet AXIOM’s Examiner-Created File System and Registry Artifacts

Posted in Uncategorized

Interview With Shahar Tal, Director Of The Research Group, Cellebrite

Shahar, you are the Director of the Research Group at Cellebrite. Tell us a bit about your role. What does a day in your life look like?

In my role, I am responsible for Cellebrite’s research efforts to provide extraction-enabling solutions for all devices of interest. This core role within the company helps define what our products and services can do. Our unmatched research is one of our strongest differentiators, creating high expectations among our customers and colleagues. My job is to ensure that we continue developing unique capabilities to match these expectations. Luckily, I have several research teams made up of top talent that are dedicated to the task in each different research domain. They deserve a lot of the credit for the technical breakthroughs achieved at Cellebrite.

Read More Continue reading Interview With Shahar Tal, Director Of The Research Group, Cellebrite

Posted in Uncategorized

MacQuisition™ 2016 R1 is Now Available

BlackBag® Technologies is excited to announce the release of MacQuisition™ 2016 R1, our 3-in-1 solution for live data acquisition, targeted data collection, and forensic imaging. Our customers around the globe depend on our software’s reliability to securely image hundreds of Macs. MacQuisition™ is the only forensic solution that runs within a native OS X boot environment, making it uniquely versatile.

With changes in Apple’s hardware and software comes improvement to MacQuisition™. MacQuisition™ now supports imaging RAM in the Macintosh 10.11 operating system. When MacQuisition™ is used on a live Mac OS X system, it will detect the operating system version to ensure it is a supported version and warn the user if the version is not supported for RAM imaging.

Improvements have also been made to the ‘Comments’ section, the ‘MacQuisition™ Updater’ application, and user interface consistency. Continue reading MacQuisition™ 2016 R1 is Now Available

Posted in Uncategorized

Q&A: Chuck Cobb, Magnet Forensics’ New VP Of Training

We all know the forensics industry needs to be credible and reliable to have its necessary impact in the courtroom. Magnet Forensics recently launched an expanded training program and its first certification – the Magnet Certified Forensic Examiner (MCFE). To build an industry-leading training program, Magnet Forensics brought Chuck Cobb on board as Vice President, Training. We took a minute to sit down with Chuck and learn what it takes to build a top notch training and certification program.

Read more Continue reading Q&A: Chuck Cobb, Magnet Forensics’ New VP Of Training

Posted in Uncategorized

Turkish Journalist Jailed for Terrorism Was Framed, Forensic Report Shows

Turkish investigative journalist Barış Pehlivan spent 19 months in jail, accused of terrorism based on documents found on his work computer. But when digital forensics experts examined his PC, they discovered that those files were put there by someone who removed the hard drive from the case, copied the documents, and then reinstalled the hard drive. Continue reading Turkish Journalist Jailed for Terrorism Was Framed, Forensic Report Shows

Posted in Uncategorized

Review: Oxygen Forensic Complete Training

Reviewed by Brad Robin

Introduction

This review will be based solely on the Oxygen Forensic Complete Training class that occurred in Lafayette, Louisiana between April 19-21, 2016.

Coming into this class my knowledge of the Oxygen Forensic Detective program was very limited. I still remember calling a friend the first time I used the program and asking “Where are the pictures and videos?’ Now don’t get me wrong I have a vast knowledge of the digital forensics community and programs, however you will find that all programs are created different and the GUI interfaces can be quite tricky until you learn each. This is why I am an advocate of being trained on the software you actually use in your day to day investigations.

Read More Continue reading Review: Oxygen Forensic Complete Training

Posted in Uncategorized

Forensic Focus Forum Round-Up

Welcome to this month’s round-up of recent posts to the Forensic Focus forums.

What would you do if you came across a setup that seemed to have very few lines of possible enquiry? Add your thoughts in the forum.

Can you recommend software that can image a damaged drive by skipping over bad sectors? Chime in on the forum.

Can you help this forum member identify an unknown file system?

Forensic Focus is now running Twitter chats under the hashtag #dftalk – add your suggestions for topics here.

How did volume shadow copies work in Windows XP? Add your answer in the forum.

Forum members discuss how to estimate the age of victims in cases of IIOC.

Which methods and tools do you use for case management?

Forum members discuss cell tower data interpretation.

Can you recommend an open source tool to recover Facebook chats?

Do you use a mini-PC for acquiring images? Add your recommendations to the thread. Continue reading Forensic Focus Forum Round-Up

Posted in Uncategorized