The Wisdom of the Heap: Mesh It up by Weaving Data Structures

In this short presentation, Trufflepig Forensics’ Aaron Hartel and Christian Müller present some early stage research about the volatility of data in memory as data structures change version to version.

Session Chair: We’re now going over … Continue reading The Wisdom of the Heap: Mesh It up by Weaving Data Structures

Memory Forensic Analysis of a Programmable Logic Controller in Industrial Control Systems

Winner of the Best Student Paper Award at DFRWS-EU 2022! Muhammad Haris Rais describes a step-wise approach to analyze the memory of specific PLCs, and subsequently find a generic framework applicable to all PLCs. By following a methodology that… Continue reading Memory Forensic Analysis of a Programmable Logic Controller in Industrial Control Systems

Frontline Managed Services’ Kyle Campbell on DFIR & E-Discovery Skills & Pathways

Christa: Electronic discovery, or e-discovery, has always required some digital forensic skills as litigators prepare to present electronic data at trial. However, as technology evolves, likewise, the skills needed to identify, collect and anal… Continue reading Frontline Managed Services’ Kyle Campbell on DFIR & E-Discovery Skills & Pathways

PEM: Remote Forensic Acquisition of PLC Memory in Industrial Control Systems

https://youtu.be/_pPxk5eTH_Y

Winner of the Best Paper Award at DFRWS-EU 2022, Nauman Zubair proposes a new memory acquisition framework to remotely acquire a programmable logic controller (PLC)’s volatile memory while the PLC is controlling a phys… Continue reading PEM: Remote Forensic Acquisition of PLC Memory in Industrial Control Systems

Defining Atomicity (and Integrity) for Snapshots of Storage in Forensic Computing

In this video from DFRWS-EU 2022, Jenny Ottmann revisits the discussion on quality criteria for “forensically sound” acquisition of such storage and proposes a new way to capture the intent to acquire an instantaneous snapshot from a single targe… Continue reading Defining Atomicity (and Integrity) for Snapshots of Storage in Forensic Computing

Introducing 2 Forensic Focus Podcast Co-Hosts: Simon Biles and Alex Desmond

Christa: Welcome to the Forensic Focus podcast. I’m your host, Christa Miller. And this week we’re switching it up a little bit. We’re introducing some new co-hosts: Simon Biles and Alex Desmond. Simon’s an IT and digital fore… Continue reading Introducing 2 Forensic Focus Podcast Co-Hosts: Simon Biles and Alex Desmond

Extraction and Analysis of Retrievable Memory Artifacts From Windows Telegram Desktop Application

In this video from DFRWS-EU 2022, Pedro Fernandez-Alvarez describes research focused on the Telegram Desktop client, in particular the client process contents in a Windows system’s RAM.

Session Chair: We are now in the topic of memory f… Continue reading Extraction and Analysis of Retrievable Memory Artifacts From Windows Telegram Desktop Application

Bridging the Gap: Standardizing Representation of Inferences in Diverse Digital Forensic Contexts

Session Chair: So the next speaker is Timothy. It’s going to be online, so Timothy, are you ready?

Timothy: Hi, everyone. So I’m Timothy Bollé, I’m a PhD student at the University of Lausanne. And today I will … Read m… Continue reading Bridging the Gap: Standardizing Representation of Inferences in Diverse Digital Forensic Contexts

Cellebrite’s Monica Harris on Achieving Balance in Corporate Investigations and E-Discovery

Christa: Digital forensics in enterprises increasingly overlaps corporate investigations, e-discovery and incident response, with the result that enterprises themselves must balance data acquisition and retention with employee privacy and cyber… Continue reading Cellebrite’s Monica Harris on Achieving Balance in Corporate Investigations and E-Discovery