Peering Through The Cloud

by Shahaf Rozanski

With there now being more mobile phones on the planet than people and smartphones set to achieve saturation in just 10 years, unlocking the data held on them has increasingly needed to be used as vital evidence for police forces. However as apps – and the data held within them – have moved into the cloud, police forces have struggled to follow this data into the ether. Law enforcement agencies could in fact be missing out on critical evidence if they don’t have technology in place to extract and analyse this evidence.

What makes it so valuable is that an increasingly large proportion of information now accessed on a modern device – whether that be via Gmail, Dropbox or WhatsApp – is actually stored in the cloud, not on the device itself.

Read More Continue reading Peering Through The Cloud

Posted in Uncategorized

Interview with Syed Naqvi, Senior Lecturer in Cyber Security and Forensics, Birm

Syed, you’re a Senior Lecturer in Cyber Security and Forensics at Birmingham City University. Tell us a bit about your role: what does a typical day look like for you?

The role of a university academic has tremendously grown in recent years. We are no… Continue reading Interview with Syed Naqvi, Senior Lecturer in Cyber Security and Forensics, Birm

Posted in Uncategorized

Call for participants: Survey of digital forensic investigation professionals

Enter a draw to win £300/€400 by sharing your perspective!

Spend five minutes answering seven quick questions on your preferred investigative methodologies and be entered in a prize draw to win one of two £300/€400 Mastercard giftcards. You will also receive a copy of the global report once completed.

As the bulk of investigative activity moved from paper to digital documents, keyword searching became the primary tool for identifying relevant evidence in a data set. However, keywords can be imprecise. A search may miss important items or return too many irrelevant results. As data volumes grow, investigators must trawl through ever increasing numbers of search results to find the information they seek. Enter this global survey to help us answer; is keyword search becoming obsolete in the age of digital investigation? Do data visualisations provide a viable primary alternative for investigators? Continue reading Call for participants: Survey of digital forensic investigation professionals

Posted in Uncategorized

Apple challenges ‘chilling’ demand to decrypt San Bernardino shooter’s iPhone

Apple has hit back after a US federal magistrate ordered the company to help the FBI unlock the iPhone of one of the San Bernardino shooters, with chief executive Tim Cook describing the demand as “chilling”.

The court order focuses on Apple’s security feature that slows down anyone trying to use “brute force” to gain access to an iPhone by guessing its passcode. In a letter published on the company’s website, Cook responded saying Apple would oppose the order and calling for public debate.

Read More (The Guardian) Continue reading Apple challenges ‘chilling’ demand to decrypt San Bernardino shooter’s iPhone

Posted in Uncategorized

Forensic Focus Forum Round-Up

Welcome to this month’s round-up of recent posts to the Forensic Focus forums.

Forum members give their advice on investigating the contents of a DVR security camera system.

Do you use password breakers in your investigations?

Forum members discuss magnetic force microscopy.

How would you go about demonstrating that a given file has or has not been viewed?

Have you ever accidentally wiped data from a device during an investigation?

What software do you use for CDR analysis?

Can you recommend a tool for data collection from social media profiles?

Forum member aeforensics shares a list of DFIR educational resources. Continue reading Forensic Focus Forum Round-Up

Posted in Uncategorized

Using Large Dictionaries for Password Cracking in a Network Environment

Passware has recently released a new version of its flagship product – Passware Kit Forensic 2016.1, which supports shared dictionaries. What does this mean for corporations and forensic investigators?

Large custom wordlists and even memory image files can be used by Passware Kit as dictionaries to recover a password. Such files are often stored on network-shared drives, while the password recovery process is launched on different workstations.

Passware customers no longer have to copy large dictionary files to local computers running Passware Kit or Passware Kit Agents. The dictionary should be compiled first with Passware Kit into its *.dic format, and can afterwards be stored on a network drive. A customer has to specify the location of the dictionary folder in the Passware Kit settings once — the program would import the dictionaries automatically from the location specified. For distributed password recovery processes, these dictionaries will also be shared among the Passware Kit Agents. Continue reading Using Large Dictionaries for Password Cracking in a Network Environment

Posted in Uncategorized