BitLocker: What’s New in Windows 10 November Update, And How To Break It

BitLocker is a popular full-disk encryption scheme employed in all versions of Windows (but not in every edition) since Windows Vista. BitLocker is used to protect stationary and removable volumes against outside attacks. Since Windows 8, BitLocker is activated by default on compatible devices if the administrative account logs in with Microsoft Account credentials. BitLocker protection is extremely robust, becoming a real roadblock for digital forensics.

Various forensic techniques exist allowing experts to overcome BitLocker protection. Capturing a memory dump of a computer while the encrypted volume is mounted is one of the most frequently used venues of attack. However, acquiring BitLocker-encrypted volumes may become significantly more difficult with the release of Windows 10 November Update. In this article, we’ll explore existing methods of recovering BitLocker volumes, look at what has changed with November Update, and review the remaining acquisition paths.

Read More Continue reading BitLocker: What’s New in Windows 10 November Update, And How To Break It

Posted in Uncategorized

SuperImager® Plus Desktop Pro Gen-2 Forensic Lab units – Dual-Boot Linux/Win 7

MediaClone, Inc. is proud to announce the release of the 2016 new generation of SuperImager® Plus Desktop Pro Gen-2 Forensic units–“Heavy Duty” multiple Forensic Imaging and a Network Loader units, with dual boot Linux OS and Windows 7 Pro, and with PCIE 3.0 Expansion slots.

User can perform simultaneous, in parallel, multiple Forensic Imaging with 3 hash authentication MD5, SHA-1, SHA-2 and encryption on the fly from 4 SAS/SATA drives to 4 SAS/SATA drives (4:4) and from 3 USB3.0 drives to 3 USB3.0 drives (3:3) in 7 separate sessions. Upload 8 SAS/SATA drives to the network with 8 separate sessions.

The unit basic specifications:

Ports: 8 SAS/SATA, 6 USB3.0, 1GbE, HDMI ports
Processor: i7 SKYLAKE
Bus: PCIE 3.0
Memory: 16GB
Internal Storage: 256GB
OS: Dual Boot with Linux and Windows 7 Pro Continue reading SuperImager® Plus Desktop Pro Gen-2 Forensic Lab units – Dual-Boot Linux/Win 7

Posted in Uncategorized

ESR Restores Access to Windows 10 Accounts, Adds Microsoft Account Support

ElcomSoft Co. Ltd. updates Elcomsoft System Recovery, a tool for IT security specialists and forensic examiners to unlock access to user’s Windows accounts. The tool enables recovering or instantly resetting Windows account passwords. The new release adds support for Windows 8, 8.1, 10. In addition to recovering local passwords, the updated release adds the ability to unlock Windows logins protected with the new Microsoft Account, and allows exporting hashed passwords to enable offline attacks to recover plain-text passwords to the user’s Microsoft Account. Access to information available in the cloud authenticated with Microsoft Account can be invaluable during forensic investigations.

The new release comes ready to use, and includes a custom boot image based on a customized Windows PE environment. ElcomSoft customizations include many additional drivers to support the widest range of hardware configurations including last-generation chipsets. Continue reading ESR Restores Access to Windows 10 Accounts, Adds Microsoft Account Support

Posted in Uncategorized

Forensic Focus Forum Round-Up

Welcome to this month’s round-up of recent posts to the Forensic Focus forums.

Forum members debate the Apple vs. FBI case; add your thoughts to the thread.

What do you think of the ISO accreditation requirement posited by the UK Home Office?

What software do you use for partition recovery? Chime in on the forum.

Forum members discuss what happens to devices after they cannot be processed.

Does posting about digital forensics methods on an open forum make life easier for criminals? Join the debate.

Do you use SSDs to store your images? Why/why not?

Forum members discuss how to recover data from a fingerprint-locked Samsung Galaxy S6 Edge.

How do you deal with deleted partitions in examinations? Share your thoughts on the forum.

Can you recommend some further reading for a student who wants to expand their knowledge? Continue reading Forensic Focus Forum Round-Up

Posted in Uncategorized

Is Keyword Search Becoming Obsolete In Forensic Digital Investigation?

by James Billingsley

Keyword searching is the primary tool investigators use to identify relevant evidence in a data set. However, poorly chosen keywords can miss important items or return too many irrelevant results. As data volumes grow, investigators must find better ways to focus on the items of interest within very large data sets. Expert forensic technician and investigator James Billingsley explains how visualising communication networks, timelines, maps and links between data sources can rapidly establish key players, their locations and their involvement in a matter of interest – all supported by forensic artefacts required for provenance.

Before the advent of computing, investigators who sought evidentiary documents that were relevant to their case faced the painstaking task of sifting through all the available pieces of paper and handwritten notes until only the significant ones remained.

Read More Continue reading Is Keyword Search Becoming Obsolete In Forensic Digital Investigation?

Posted in Uncategorized

BlackLight 2016 R1 – The Examiner’s Windows, Mac, iPhone and Android Solution

BlackLight 2016 R1 represents much more than new features and bug fixes. Our vision for BlackLight has always been a cost-effective forensic solution for law enforcement that just works.

A solution that:
– Analyzes 90% of your caseload (Windows, Mac,… Continue reading BlackLight 2016 R1 – The Examiner’s Windows, Mac, iPhone and Android Solution

Posted in Uncategorized