Oxygen Forensics Announces Training Schedule For 3-Day Complete Course

Oxygen Forensics, the worldwide developer and provider of advanced forensic data examination tools for mobile devices and cloud services, invites forensic experts to join a new 3-day training course called Oxygen Forensic Complete.

Students attending an Oxygen Forensic training course will obtain a start to finish education on the use of Oxygen Forensic® Detective. The course introduces advanced methods of smart device collections and data analysis. Students will examine, collect and analyze data from iOS, Android, and Windows devices. Students will work to obtain physical images, understand file system formats, storage methods and evidence locations. Students also receive training and instruction on cloud storage and extraction techniques. Continue reading Oxygen Forensics Announces Training Schedule For 3-Day Complete Course

Posted in Uncategorized

Collecting Evidence From Google Accounts Gets Easier

ElcomSoft Co. Ltd. updates Elcomsoft Cloud eXplorer, a digital forensic tool for remotely acquiring information from Google accounts. In its first major update, the tool gains Gmail acquisition support via Google’s proprietary API, adds printable reports for a wide range of data categories, and extracts information on who requested access to the Google account being investigated.

Elcomsoft Cloud Explorer is an all-in-one solution for acquiring and analyzing information collected and stored by Google in the user’s Google Account. The tool offers forensic specialists access to users’ search history, up to 6 years of detailed location history, contacts, email communications, Chrome browsing history, notes, messages, and much more. Featuring selective access and blazing fast acquisition, Elcomsoft Cloud Explorer is world’s most advanced tool for Google forensics. Continue reading Collecting Evidence From Google Accounts Gets Easier

Posted in Uncategorized

BlackBag’s BlackLight 2016 R2 Now Available

We’re pleased to announce this year’s second major release of BlackLight, BlackBag’s comprehensive Windows, Android, iPhone/iPad and Mac forensic analysis software!

BlackLight, for those not already familiar with it, quickly analyzes computer volumes and mobile devices. It sheds light on user actions and now even includes analysis of memory images. BlackLight allows for easy searching, filtering and otherwise sifting through large data sets. It can logically acquire Android and iPhone/iPad devices, runs on Windows and Mac OS X, and can analyze data from all four major platforms within one interface.

BlackLight 2016 R2 features numerous improvements to make casework easier, including the following:
• Improved Offline Maps – vastly improved offline maps, based on OpenStreetMap *detailed below*
• Additional Email Parsing and Analysis – multiple Outlook formats and more *detailed below*
• New Data Ingestion User Interface – easier and more intuitive to add evidence to a case *detailed below*
• Tear-Off ‘File Content Viewer’ – simultaneously view multiple copies of the ‘File Content Viewer’ *detailed below*

Plus:
• Secondary Column Sorting – add a secondary sort by Shift-clicking a second column header
• Column Reordering – easily customize which columns are displayed, and in what order
• File Entropy – available as a sortable column for display in the ‘Browser’ and ‘File Filter’ views, also available as an individual file filter
• Updated ‘Media’ view – allows for more options in sorting through visual media files (OS thumbs, pictures, videos, or all combined)
• Improved Exporting of Contacts Data to Tab-Delimited and CSV Files – all fields of contact data are now included in exports
• Search Results Begin Displaying Before Search Is Complete – helps aid decisions about whether to allow the search to play out, or whether to pause and revise search criteria

Check out our latest blog release to view more details on how to use these new features, or attend our free webinar on August 3rd at 9am PDT. Click here to register! Continue reading BlackBag’s BlackLight 2016 R2 Now Available

Posted in Uncategorized

BlackBag Technologies Is Excited To Announce EFT Courses In Fall 2016

In addition to software, BlackBag also develops and delivers expert forensic training and certification programs, designed to meet the needs of law enforcement, military and private sector examiners. Taught by an elite team with considerable law enforcement and digital forensics experience, the courses are tailored to address realistic, multi-platform scenarios simulating the daily challenges of digital evidence.

In August and September, we will be holding an Essential Forensic Techniques I and Essential Forensic Techniques II (EFT I & II) at our headquarters in San Jose, CA. In October we will be holding an EFT I in Waterloo, Ontario and an EFT II in Mississauga, Ontario in Canada. Plus many more in the United Kingdom and the Netherlands! Continue reading BlackBag Technologies Is Excited To Announce EFT Courses In Fall 2016

Posted in Uncategorized

Oxygen Forensics Adds Pokémon Go! Data Parsing

Oxygen Forensics, the worldwide developer and provider of advanced forensic data examination tools for mobile devices and cloud services, announced today the release of Oxygen Forensic Detective 8.5.1 which supports data parsing from popular mobile app Pokémon Go!

“Over the past week and a half, Pokémon Go! is the most popular search query on Google, and that simply means that mobile users are playing the game in droves,” said Lee Reiber, Oxygen Forensics COO. “The reason forensic experts are interested in the app is that it has already caused accidents and law enforcement personnel need the tools to access Pokémon Go! data to determine whether the app being played contributed to any kind of accidents in specific situations.” Continue reading Oxygen Forensics Adds Pokémon Go! Data Parsing

Posted in Uncategorized

Cellebrite Introduces UFED Touch2 Platform

Cellebrite unveils UFED Touch2, the latest addition to the company’s industry-leading UFED Series family of mobile forensic solutions. With enhanced speed, usability, and portability, UFED Touch2 is a comprehensive mobile forensic solution that allows law enforcement, military, and intelligence agencies to extract evidentiary data in a forensically sound manner. The Touch2 can extract mobile device content up to three times faster than the UFED Touch, enabling investigators and examiners to accelerate investigations. Continue reading Cellebrite Introduces UFED Touch2 Platform

Posted in Uncategorized

Hiding Data from Forensic Imagers – Using the Service Area of a Hard Disk Drive

By Todd G. Shipley and Bryan Door

Kaspersky Labs® recently released their research regarding the compromise of hard disk drive firmware. This has confirmed our long standing suspicion that data hiding techniques using a hard disk drives Service Area could be used for malicious purposes. Kaspersky Labs® identified a group of attackers, dubbed the Equation Group, reportedly having close ties to the groups responsible for writing Stuxnet and Flame.

The “Equation Group” is reported to have run the most advanced hacking operation ever uncovered (Goodin 2015). This group is reported to have used firmware update techniques to create a “secret storage vault” to store data in the firmware of the compromised hard drives. Thus allowing the storage of data including the malware itself allowing the ability to survive standard format and wiping operations.

Read More Continue reading Hiding Data from Forensic Imagers – Using the Service Area of a Hard Disk Drive

Posted in Uncategorized

Join The Forensic Focus Twitter Chat, Wednesday 20th June: Education & Training

Join @ForensicFocus on Twitter at 3pm EST / 12pm PST / 7pm GMT (8pm BST in the UK) Wednesday 20th June for an in-depth chat on the topic of digital forensics education and training.

What do you wish you’d learned in training? Can someone succeed as a … Continue reading Join The Forensic Focus Twitter Chat, Wednesday 20th June: Education & Training

Posted in Uncategorized