Ever thought about the thin line between privacy and morality? Well, join us, , as we deep-dive into the ethical complexities surrounding this issue in today’s digital age. We bring to you exciting updates from a recent workshop in Panama, where enlightening exchanges with digital forensics experts from all over the world were had.
Our exploration takes us through the workings of XRY and XRY Pro, as well as RAMDCoder, a game-changer in analyzing memory dumps from Android devices. We'll show you just how to navigate this tool, offering a glimpse into the future with the upcoming updates that promise to revolutionize device profiling. Intriguing, isn't it? Get ready as we take on mobile device forensics, focusing on the Samsung Galaxy S21 Ultra, and the treasure trove of data within its RAM. Learn from our experiences, including how we recovered from missing a crucial step in the extraction process. Oooops user error strikes again!
As we wrap up, we'll discuss phishing attacks and the crucial role organizations play in preventing them. We believe in the power of research and validation, especially in the digital forensics field. We’ll also share insights from Jessica Hyde of Hexordia, underscoring the importance of peer-reviewed research in our field. Get a good laugh as we humorously compare Apple to Darth Vader, highlighting the challenges they present for forensic examiners. SEGB for the WIN! This is an episode that you will not want to miss!
Notes:
Chat encryption: A moral responsibility or a moral abdication?
https://arstechnica.com/tech-policy/2023/12/meta-defies-fbi-opposition-to-encryption-brings-e2ee-to-facebook-messenger/
What makes epoch timestamps tick?
https://www.cclsolutionsgroup.com/post/what-makes-epoch-timestamps-tick
CheatSheet: https://assets-global.website-files.com/5f02f2c93eab87a6ea84e2f3/656da27da36e0c5cd1715d8a_EpochCheatsheet.pdf
MSAB XRY:
https://www.msab.com/
BrowserState.db last_visited_time?
https://doubleblak.com/beta/browserstate
SEGB Parsers!
https://github.com/cclgroupltd/ccl-segb
Thursday, December 14, 2023
Thursday, November 30, 2023
What To Expect When You Are Expecting in a Digital Forensics Class, Two Hardware Solutions, One Neat Tool Capability For Windows, and a Partridge in a Pear Tree.
Get ready to journey into the world of digital forensics as we share our insights on the crucial art of utilizing a diverse range of tools. A single tool just won't cut it, and reliance on just one could cause you to miss out on important finds. We also give our listeners the floor, inviting you to voice your thoughts on the IACIS Advanced Mobile Device Forensics class, and the topics you'd love to see covered.
How do you feel about forensic extraction tools? We dissect unique features of tools like duplicators, TX1, and Atrio, and dive into latest updates from OpenText and ArcPoint Forensics. These updates have made it possible to create Android and iOS backups using duplicators, a game changer in the field. With Atrio, we open up an intriguing discussion about their forensic triaging and AI capabilities. We discuss the role of AI in identifying CSAM and brainstorm ways to enhance the tooling.
We share our own learning experiences from various classes, highlighting the absolute necessity of continual learning and outside research in this ever-evolving field. We also explore the features and potential of Arsenal, a digital forensics tool which aids in mounting and virtualizing E01 images. The unique capabilities provided by Arsenal to bypass the password to a Windows logon screen and access DPAPI-protected data is a must try! Whether you're a seasoned expert or just dipping your toes in the water, this episode is sure to pique your interest in the vast world of digital forensics.
Notes-
IACIS Advanced Mobile Device Forensics (AMDF)
https://iacis.com/training/amdf-advanced-mobile-device-forensics/
OpenText Duplicator Update
https://www.youtube.com/watch?v=L3qGa7H6NBs
ArcPoint Forensics
https://www.arcpointforensics.com/
DFIR Diva-
https://dfirdiva.com/
Arsenal Recon-
https://arsenalrecon.com/
Hexordia Mobile Data Structure-Virtual Live Training-
https://academy.cyber5w.com/courses/hexordia-mobile-data-structures-dec-2023
How do you feel about forensic extraction tools? We dissect unique features of tools like duplicators, TX1, and Atrio, and dive into latest updates from OpenText and ArcPoint Forensics. These updates have made it possible to create Android and iOS backups using duplicators, a game changer in the field. With Atrio, we open up an intriguing discussion about their forensic triaging and AI capabilities. We discuss the role of AI in identifying CSAM and brainstorm ways to enhance the tooling.
We share our own learning experiences from various classes, highlighting the absolute necessity of continual learning and outside research in this ever-evolving field. We also explore the features and potential of Arsenal, a digital forensics tool which aids in mounting and virtualizing E01 images. The unique capabilities provided by Arsenal to bypass the password to a Windows logon screen and access DPAPI-protected data is a must try! Whether you're a seasoned expert or just dipping your toes in the water, this episode is sure to pique your interest in the vast world of digital forensics.
Notes-
IACIS Advanced Mobile Device Forensics (AMDF)
https://iacis.com/training/amdf-advanced-mobile-device-forensics/
OpenText Duplicator Update
https://www.youtube.com/watch?v=L3qGa7H6NBs
ArcPoint Forensics
https://www.arcpointforensics.com/
DFIR Diva-
https://dfirdiva.com/
Arsenal Recon-
https://arsenalrecon.com/
Hexordia Mobile Data Structure-Virtual Live Training-
https://academy.cyber5w.com/courses/hexordia-mobile-data-structures-dec-2023
Thursday, November 16, 2023
Vendor Transparency, Mobile Device Extractions, & Brigs Learns the Difference Between Validation and Verification
We are back with a mind-boggling conversation about our experiences, and the ever-evolving face of digital forensics. We're going to share some personal anecdotes, enlighten you about the changing UNIX epoch timestamp, and even discuss how we cope with the advancing age in this fast-paced world.
In the digital world, knowledge is power. We will reveal an amazing cheat sheet from Cellebrite that will simplify your understanding of extractions and the data that they yield. We’ll also delve into the concept of tool transparency, highlighting the pros and cons that come with it. We’ll help you understand why it's crucial to be informed about known bugs in a tool, and navigate the complex process of bug reporting. We’re going to discuss why it's essential to have multiple tools in your arsenal for data validation, and how manual validation is a must when it relates to key evidence.
As we wrap up, we'll talk about the implementation of ALEAPP and iLEAPP in Paraben and its capabilities to choose artifacts to report on. To add some levity, we'll also share a humorous meme that perfectly captures the essence of the repercussions of failing to validate your digital data. So, prepare to embark on a journey that’s bound to make you rethink everything you know about data extraction and tooling analysis.
Notes-
Scholarship Reminders
-https://www.iacis.com/will-docken-scholarship/
-https://www.iacis.com/womens-scholarship/
-https://www.magnetforensics.com/blog/2023-magnet-forensics-scholarship-program-apply-today/
Cellebrite Data Extraction CheatSheet
-https://www.linkedin.com/posts/heather-mahalik-cellebrite_data-extraction-cheatsheet-activity-7125138491805462528-l5-5/
-https://cellebrite.com/en/episode-23-i-beg-to-dfir-data-extractions-explained-ffs-afu-bfu-advanced-logical-digital-forensics-webinar/
Paraben
-https://paraben.com
In the digital world, knowledge is power. We will reveal an amazing cheat sheet from Cellebrite that will simplify your understanding of extractions and the data that they yield. We’ll also delve into the concept of tool transparency, highlighting the pros and cons that come with it. We’ll help you understand why it's crucial to be informed about known bugs in a tool, and navigate the complex process of bug reporting. We’re going to discuss why it's essential to have multiple tools in your arsenal for data validation, and how manual validation is a must when it relates to key evidence.
As we wrap up, we'll talk about the implementation of ALEAPP and iLEAPP in Paraben and its capabilities to choose artifacts to report on. To add some levity, we'll also share a humorous meme that perfectly captures the essence of the repercussions of failing to validate your digital data. So, prepare to embark on a journey that’s bound to make you rethink everything you know about data extraction and tooling analysis.
Notes-
Scholarship Reminders
-https://www.iacis.com/will-docken-scholarship/
-https://www.iacis.com/womens-scholarship/
-https://www.magnetforensics.com/blog/2023-magnet-forensics-scholarship-program-apply-today/
Cellebrite Data Extraction CheatSheet
-https://www.linkedin.com/posts/heather-mahalik-cellebrite_data-extraction-cheatsheet-activity-7125138491805462528-l5-5/
-https://cellebrite.com/en/episode-23-i-beg-to-dfir-data-extractions-explained-ffs-afu-bfu-advanced-logical-digital-forensics-webinar/
Paraben
-https://paraben.com
Thursday, November 2, 2023
Digital Forensics, Moot Court, and New Tool. Come Down the RabbitHole ™ with Us!
Curious about how digital forensics can unlock the secrets held by your tech devices? Join us as we shine a light on RabbitHole, an ingenious tool devised by Alex Caithness of CCL Solutions Group. This episode is sure to be a revelation, as we delve into this unique amalgamation of data format viewers. The plot thickens as we, act as your guides, to dissect the complexities of the RabbitHole - reparse feature, the free form report builder, and the remarkable ability to extract data from various sources.
We step away from the tech talk for a moment to underline the crucial role of Moot Court in nurturing digital forensics examiners. We debate the need for a supportive environment that allows mistakes, honing professionals in the field. We discuss the highlights of what qualities are needed to shape a great witness and throw light on two free cybersecurity courses related to expert witness testimony.
Don't miss our discussion on the new additions to iLEAPP! Media events from the knowledgeC database and connecting Discord attachments to message threads.
Finally we discuss changes to Shellbag artifacts that were implemented in Windows 11 updates as outlined by 13Cubed, and the meme of the week!
So, are you ready to tumble down this fascinating digital RabbitHole with us?
Notes:
CCL Solutions-RabbitHole-
https://www.cclsolutionsgroup.com/forensic-products/rabbithole
Courtroom Testimony Trainings-
CYBRARY.IT-https://cybrary.it/course/dfir-investigations-and-witness-testimony
NW3C-DF501 Expert Witness Testimony - Digital Forensic Examiners- https://www.nw3c.org/UI/CourseCatalog.html
Connecting Discord Attachments to Message Threads-
https://bluecrewforensics.com/2023/10/30/connecting-discord-attachments-threads-sdwebimage-library/
13 Cubed: An Important Change to ShellBags - Windows 11 2023 Update!
https://www.youtube.com/watch?v=M1nyMIu1Y18&t=4s
Shellbags Explorer by Eric Zimmerman
https://ericzimmerman.github.io/#!index.md
We step away from the tech talk for a moment to underline the crucial role of Moot Court in nurturing digital forensics examiners. We debate the need for a supportive environment that allows mistakes, honing professionals in the field. We discuss the highlights of what qualities are needed to shape a great witness and throw light on two free cybersecurity courses related to expert witness testimony.
Don't miss our discussion on the new additions to iLEAPP! Media events from the knowledgeC database and connecting Discord attachments to message threads.
Finally we discuss changes to Shellbag artifacts that were implemented in Windows 11 updates as outlined by 13Cubed, and the meme of the week!
So, are you ready to tumble down this fascinating digital RabbitHole with us?
Notes:
CCL Solutions-RabbitHole-
https://www.cclsolutionsgroup.com/forensic-products/rabbithole
Courtroom Testimony Trainings-
CYBRARY.IT-https://cybrary.it/course/dfir-investigations-and-witness-testimony
NW3C-DF501 Expert Witness Testimony - Digital Forensic Examiners- https://www.nw3c.org/UI/CourseCatalog.html
Connecting Discord Attachments to Message Threads-
https://bluecrewforensics.com/2023/10/30/connecting-discord-attachments-threads-sdwebimage-library/
13 Cubed: An Important Change to ShellBags - Windows 11 2023 Update!
https://www.youtube.com/watch?v=M1nyMIu1Y18&t=4s
Shellbags Explorer by Eric Zimmerman
https://ericzimmerman.github.io/#!index.md
Wednesday, October 18, 2023
New iOS Geolocation Artifacts, iOS Location Shenanigans, Time Zones, Do You Realm?, and The Meme Of The Week!
Ever wondered how to make the most of data analysis tools like iOS Spotlight Store DB and Realm Databases? We're here to share our experiences, tips, and favorite resources to help you elevate your data extraction skills. Join us, as we discuss the amazing work of Yogesh Khatri, the creator of a game-changing parser and as we guide you through the vast world of data extraction and analysis techniques.
We begin our journey with iOS Spotlight Store DB, revealing the treasures hidden within and how to use Yogesh's parser to uncover its secrets. We then navigate through Realm Databases, sharing our encounters with data stores and tools for parsing extracted data. We also share our personal workflow process, granting you a peek into our data analysis strategies. But we're not done yet. Our adventure takes a detour towards Google Maps Geolocation Artifacts, where we highlight the amazing work of The Binary Hick and his research of the audio files and geolocation points related to navigation.
Finally, we explore the nuanced art of analyzing timestamps and locations in images, revealing a fascinating intersection of data and intent. We share how we use Python scripts, manual offsets, and more to make data time-zone aware. Wrapping up our discussion, we emphasize the vitality of research in data analysis and the role of code in automation. So, buckle up for a thrilling ride into the mesmerizing world of data extraction and analysis. You'll come out the other side armed with fresh insights and new tools at your disposal.
Notes:
iOS Spotlight store.db:
https://github.com/ydkhatri/spotlight_parser
Realm Databases:
https://www.mongodb.com/docs/realm/studio/
The Binary Hick-Finding Phones with Google Maps:
https://thebinaryhick.blog/2023/10/17/finding-phones-with-google-maps-part-1-android/
iOS Media Adjustments:
https://www.doubleblak.com/blogPosts.php?id=23
We begin our journey with iOS Spotlight Store DB, revealing the treasures hidden within and how to use Yogesh's parser to uncover its secrets. We then navigate through Realm Databases, sharing our encounters with data stores and tools for parsing extracted data. We also share our personal workflow process, granting you a peek into our data analysis strategies. But we're not done yet. Our adventure takes a detour towards Google Maps Geolocation Artifacts, where we highlight the amazing work of The Binary Hick and his research of the audio files and geolocation points related to navigation.
Finally, we explore the nuanced art of analyzing timestamps and locations in images, revealing a fascinating intersection of data and intent. We share how we use Python scripts, manual offsets, and more to make data time-zone aware. Wrapping up our discussion, we emphasize the vitality of research in data analysis and the role of code in automation. So, buckle up for a thrilling ride into the mesmerizing world of data extraction and analysis. You'll come out the other side armed with fresh insights and new tools at your disposal.
Notes:
iOS Spotlight store.db:
https://github.com/ydkhatri/spotlight_parser
Realm Databases:
https://www.mongodb.com/docs/realm/studio/
The Binary Hick-Finding Phones with Google Maps:
https://thebinaryhick.blog/2023/10/17/finding-phones-with-google-maps-part-1-android/
iOS Media Adjustments:
https://www.doubleblak.com/blogPosts.php?id=23
Thursday, October 5, 2023
FTK Mobile, Cellphone Forensics Tool Comparisons, and New Open Source Artifacts. Competition is Heating Up in the Mobile Forensics Space.
Ready for the breakdown of the newest player in the mobile forensics field, FTK 8? This latest release includes a facelift, enhanced mobile support, and a plethora of supportive features for mobile devices. From app-specific mobile artifacts like Discord, Facebook, Kik, Snapchat, WhatsApp, to calls, conversations, contacts, MMS, and SMS, FTK 8 is geared up. Plus, its Smart View tab provides new mini and super timeline features as well as enhancements to their multimedia view.
Our chat extends beyond the merits of FTK 8 to the realm of portable cases and the case review aspect of all digital forensic tools. Uncover how the right network setup can boost review speed and why understanding the limitations of portable cases is crucial for examiners and stakeholders alike. We also discuss how focusing on artifact-based reviews, can enhance efficiency. But that's not it! We also delve into the importance of data validation and why a user-friendly interface is key for people reviewing and examining cases.
Interested in hearing about comparative analysis? Tune in for an in-depth discussion about comparing the capabilities of one forensic tool to another and the possible outcomes of such a competitive assessment.
New to iLEAPP? We've got you covered! Together, we unearth new artifacts like the last car connection and voicemail artifacts, even recently deleted (trashed) voicemail - critical elements that will revolutionize your review process. Understanding the significance of analyzing torrent data encoded in Bencode, linking media on a device to files used to acquire that media, is another key takeaway from our conversation. To wrap things up, we express our heartfelt gratitude to you, our listeners and thank you for joining us on this fascinating journey into the world of digital forensics.
Notes-
FTK 8
https://www.exterro.com/ftk-8-0
iOS 15 Image Forensics Analysis and Tools Comparison Project
https://blog.digital-forensics.it/2023/09/ios-15-image-forensics-analysis-and.html
LEAPPS
https://github.com/abrignoni
Our chat extends beyond the merits of FTK 8 to the realm of portable cases and the case review aspect of all digital forensic tools. Uncover how the right network setup can boost review speed and why understanding the limitations of portable cases is crucial for examiners and stakeholders alike. We also discuss how focusing on artifact-based reviews, can enhance efficiency. But that's not it! We also delve into the importance of data validation and why a user-friendly interface is key for people reviewing and examining cases.
Interested in hearing about comparative analysis? Tune in for an in-depth discussion about comparing the capabilities of one forensic tool to another and the possible outcomes of such a competitive assessment.
New to iLEAPP? We've got you covered! Together, we unearth new artifacts like the last car connection and voicemail artifacts, even recently deleted (trashed) voicemail - critical elements that will revolutionize your review process. Understanding the significance of analyzing torrent data encoded in Bencode, linking media on a device to files used to acquire that media, is another key takeaway from our conversation. To wrap things up, we express our heartfelt gratitude to you, our listeners and thank you for joining us on this fascinating journey into the world of digital forensics.
Notes-
FTK 8
https://www.exterro.com/ftk-8-0
iOS 15 Image Forensics Analysis and Tools Comparison Project
https://blog.digital-forensics.it/2023/09/ios-15-image-forensics-analysis-and.html
LEAPPS
https://github.com/abrignoni
Thursday, September 21, 2023
Navigating the Digital Forensics Maze: Insightful Discussions and Valuable Resources
Stay tuned as we navigate the mesmerizing maze of digital forensics, sharing insights that you wouldn't want to miss! We kick-start this thrilling journey with a sneak-peek into the Regional Computer Forensics Lab in Boston. The fun doesn't stop here as we also delve into the exhilarating Cellebrite Capture the Flag challenge and touch upon the awe-inspiring Difference Makers Awards.
We then turn to the indispensable resources for those wishing to take on the digital forensics world. From the empowering IACIS Women in Law Enforcement Scholarship to the unique Magnet Forensics Scholarship, we've got you covered. Don't miss our take on the complimentary Belkasoft iOS Forensics Course and DFIR Artifact Museum. Plus, we'll guide you through using the intriguing Eric Zimmerman's SQLECmd and Timeline Explorer.
Finally, we discuss the invaluable act of giving back to the digital forensics community. We share the secrets of adjusting to corporate culture, continuing education, and the pivotal role of mentoring. We even touch upon the remarkable Digital Forensics Intern Program by Notre Dame. So, tune in as we unravel the complex world of digital forensics. What's more? We've got some valuable advice for newbies waiting at the end. Get ready to embark on this digital journey with us!
Notes:
Difference Makers Awards 2023: https://www.sans.org/about/awards/difference-makers/
IACIS Scholarship: https://www.iacis.com/will-docken-scholarship/
IACIS Women's Scholarship: https://www.iacis.com/womens-scholarship/
Magnet Scholarship: https://www.magnetforensics.com/blog/2023-magnet-forensics-scholarship-program-apply-today
Belkasoft iOS Free Training: https://belkasoft.com/ios-forensics-training
Eric Zimmerman's SQLECmd: https://ericzimmerman.github.io/#!index.md
DFIR Artifact Museum: https://github.com/AndrewRathbun/DFIRArtifactMuseum
J & L Forensics Blog: https://jnl4n6.com/2023/09/13/new-to-cyber-preston-mcnair/
We then turn to the indispensable resources for those wishing to take on the digital forensics world. From the empowering IACIS Women in Law Enforcement Scholarship to the unique Magnet Forensics Scholarship, we've got you covered. Don't miss our take on the complimentary Belkasoft iOS Forensics Course and DFIR Artifact Museum. Plus, we'll guide you through using the intriguing Eric Zimmerman's SQLECmd and Timeline Explorer.
Finally, we discuss the invaluable act of giving back to the digital forensics community. We share the secrets of adjusting to corporate culture, continuing education, and the pivotal role of mentoring. We even touch upon the remarkable Digital Forensics Intern Program by Notre Dame. So, tune in as we unravel the complex world of digital forensics. What's more? We've got some valuable advice for newbies waiting at the end. Get ready to embark on this digital journey with us!
Notes:
Difference Makers Awards 2023: https://www.sans.org/about/awards/difference-makers/
IACIS Scholarship: https://www.iacis.com/will-docken-scholarship/
IACIS Women's Scholarship: https://www.iacis.com/womens-scholarship/
Magnet Scholarship: https://www.magnetforensics.com/blog/2023-magnet-forensics-scholarship-program-apply-today
Belkasoft iOS Free Training: https://belkasoft.com/ios-forensics-training
Eric Zimmerman's SQLECmd: https://ericzimmerman.github.io/#!index.md
DFIR Artifact Museum: https://github.com/AndrewRathbun/DFIRArtifactMuseum
J & L Forensics Blog: https://jnl4n6.com/2023/09/13/new-to-cyber-preston-mcnair/
Subscribe to:
Posts (Atom)
-
We come back from a busy conference stretch and go hands-on with new digital forensics tools that speed up real workflows across vehicle, ...
-
Apple devices are constantly recording user activity, yet few forensic examiners are making use of the vast amount of data these systems q...
-
We kick off this episode with highlights from the Techno Security Conference, our 80s-themed outfits, packed LEAPP labs, AI panel discussi...