<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-36666403</atom:id><lastBuildDate>Thu, 16 May 2013 10:31:22 +0000</lastBuildDate><category>data recovery</category><category>Guidance Software</category><category>Scott Burkeman</category><category>Hard disk data storage</category><category>CSITech</category><category>Research</category><category>write blocking</category><category>graduates</category><category>Adroit Photo Forensics</category><category>Digital Evidence Collection Kit</category><category>Computer Forensic Investigation</category><category>storage</category><category>privacy</category><category>graduate</category><category>stalking</category><category>cold boot attack</category><category>mobile telephone connection records</category><category>bitlocker</category><category>business continuity</category><category>cell phone forensics</category><category>file carving</category><category>Criminal Justice and Immigration Bill</category><category>Kaminsky</category><category>encryption</category><category>cyberstalking</category><category>George Chlapoutakis</category><category>McMurdie</category><category>validating</category><category>tactical</category><category>David Benford</category><category>dominik weber</category><category>computer forensics</category><category>Forensic 4cast</category><category>Lance Mueller</category><category>hotplug</category><category>computer forensics events</category><category>Greg Smith</category><category>Google history</category><category>Projects</category><category>clifford stoll</category><category>review</category><category>Challenges</category><category>security metrics</category><category>Appointments-UK</category><category>training</category><category>blogs</category><category>Graham Brown-Martin</category><category>reporting</category><category>future</category><category>cv</category><category>scalability</category><category>write blocker review</category><category>ntfs</category><category>Chris Pamplin</category><category>Images</category><category>Si Biles</category><category>FTK</category><category>computer forensics jobs</category><category>EnCase</category><category>PIN</category><category>document analysis</category><category>Cystinosis</category><category>Experience</category><category>craig ball</category><category>forensics</category><category>employment</category><category>David Sullivan</category><category>data recovery training</category><category>Jon Rowe</category><category>online</category><category>Google forensics</category><category>Nick Furneaux</category><category>interview</category><category>expet witness</category><category>ACPO Good Practice Guide</category><category>Lee Whitfield</category><category>computer forensics costs prices</category><category>forensic focus stats</category><category>computer forensics licensing</category><category>tagview</category><category>Russell May</category><category>Columnists</category><category>interviews</category><category>DOMEX</category><category>expert witness</category><category>EnScripts</category><category>geotags</category><category>simon biles</category><category>key recovery</category><category>feeds</category><category>e-fense Live Response</category><category>forensic software</category><category>cell site analysis</category><category>education</category><category>technology</category><category>forensic hardware</category><category>Bright Forensics</category><category>computer security</category><category>Simson Garfinkel</category><category>Nessus</category><category>Tableau</category><category>Zimmermann</category><category>digital evidence</category><category>push button</category><category>passwords</category><category>truecrypt</category><category>forums</category><category>Scott Moulton</category><category>Search Warrants</category><category>iso</category><category>Infosecurity</category><category>chris hargreaves</category><category>Students</category><category>Sam Raincock</category><category>Programming</category><category>telecoms</category><category>procedures</category><category>live forensics</category><category>computer forensics education</category><category>harassment</category><category>mobile forensics</category><category>Advanced Forensic Sessions</category><category>survey</category><category>Pinpoint Labs</category><category>write blockers</category><category>peer review</category><category>UK Register of Expert Witnesses</category><category>data protection</category><category>single sign on</category><category>forensic reports</category><category>terms of engagement</category><category>image</category><category>disaster recovery</category><category>SIM</category><category>Tony Sammes</category><category>recruitment</category><category>4N6 Investigation</category><category>hard disk reliability</category><category>holographic memory</category><category>wiebetech</category><category>sharing knowledge</category><category>Matthew Shannon</category><category>V200 SIM Dialer</category><category>sterilization</category><category>cuckoo's egg</category><category>games consoles</category><category>Cloud Computing</category><category>recruiters</category><category>cold boot</category><category>careers</category><category>Agile Risk Management</category><category>vulnerability scanners</category><category>dan gaskell</category><category>Stephen Mason</category><category>network forensics</category><category>copyright</category><category>certification</category><category>Helix 3 Enterprise</category><category>wiping</category><category>jobs</category><category>Diffie</category><category>Digital Safety Conference</category><category>twitter</category><category>Robert Botchek</category><category>computer forensics recruitment</category><category>Hoffmann</category><category>compliance</category><category>computer forensics training</category><category>sean mclinden</category><category>standards</category><category>X-Ways</category><category>global computer forensics</category><category>memory acquisition</category><category>metadata</category><category>F-Response</category><category>electronic signatures</category><category>Ben Levitan</category><category>computer forensics podcasts</category><category>Windows Search forensics</category><title>Forensic Focus Blog</title><description>Official blog of &lt;a href="http://www.forensicfocus.com"&gt;ForensicFocus.com&lt;/a&gt;</description><link>http://forensicfocus.blogspot.com/</link><managingEditor>noreply@blogger.com (Jamie)</managingEditor><generator>Blogger</generator><openSearch:totalResults>213</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="forensicfocusblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://www.forensicfocus.com/blog/feed.php" /><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.bloglines.com/sub/http://www.forensicfocus.com/blog/feed.php" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://fusion.google.com/add?feedurl=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2628553655948352670</guid><pubDate>Thu, 21 Feb 2013 17:31:00 +0000</pubDate><atom:updated>2013-02-21T09:31:01.919-08:00</atom:updated><title>Interview with Robert Bond, Product Marketing Manager, Guidance Software</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.forensicfocus.com/uploads/pro_news/1361466589.2398.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://www.forensicfocus.com/uploads/pro_news/1361466589.2398.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-weight: bold;"&gt;Robert, please tell us a little about yourself and your role at Guidance Software&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
I’m the new Product Marketing Manager of Forensic Solutions which includes &lt;a class="postlink" href="http://www.guidancesoftware.com/encase-forensic.htm" rel="nofollow" target="_blank" title="http://www.guidancesoftware.com/encase-forensic.htm"&gt;&lt;span style="font-weight: bold;"&gt;EnCase Forensic&lt;/span&gt;&lt;/a&gt;, &lt;a class="postlink" href="http://www.guidancesoftware.com/encase-portable.htm" rel="nofollow" target="_blank" title="http://www.guidancesoftware.com/encase-portable.htm"&gt;&lt;span style="font-weight: bold;"&gt;Encase Portable&lt;/span&gt;&lt;/a&gt; and &lt;a class="postlink" href="http://www.tableau.com/index.php?pageid=products" rel="nofollow" target="_blank" title="http://www.tableau.com/index.php?pageid=products"&gt;&lt;span style="font-weight: bold;"&gt;Tableau products&lt;/span&gt;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
I have been in marketing for over 15 years with technology brands like 
Hewlett Packard, Kodak, and most recently in e-Discovery with Ricoh 
Legal.&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;Version 7 of EnCase introduced 
significant changes, the reaction to some of which was mixed within the 
forensic community. What kind of feedback did you receive from users?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
For our customers who have been using EnCase, the new look of Version 7 
was a bit of a transition and took some adjustment. For new users 
however, the interface is similar to the look and feel of other popular 
programs so we’ve seen the learning curve for users new to the software 
become shorter.&lt;br /&gt;&lt;br /&gt;From a customer experience perspective, Guidance 
marketing and technical support has provided webinars and other tools to
 assist users in making a smooth transition. We believe their investment
 in getting comfortable with the new interface will increase their 
efficiency.&lt;br /&gt;
&lt;br /&gt;
Further, as we have upgraded the software culminating with Version 7.05;
 we are learning that the increased speed of processing data and several
 of the new features including prioritized processing are dramatically 
helping our customers increase their productivity...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.forensicfocus.com/c/aid=55/interviews/2013/robert-bond-product-marketing-manager-guidance-software/"&gt;Read more&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HA8YdBZQe80:r3JEmy8q-0o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HA8YdBZQe80:r3JEmy8q-0o:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HA8YdBZQe80:r3JEmy8q-0o:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=HA8YdBZQe80:r3JEmy8q-0o:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HA8YdBZQe80:r3JEmy8q-0o:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HA8YdBZQe80:r3JEmy8q-0o:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=HA8YdBZQe80:r3JEmy8q-0o:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HA8YdBZQe80:r3JEmy8q-0o:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HA8YdBZQe80:r3JEmy8q-0o:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HA8YdBZQe80:r3JEmy8q-0o:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HA8YdBZQe80:r3JEmy8q-0o:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2013/02/interview-with-robert-bond-product.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2672086549690919843</guid><pubDate>Wed, 30 Jan 2013 16:41:00 +0000</pubDate><atom:updated>2013-01-30T08:41:38.913-08:00</atom:updated><title>Internet Evidence Finder (IEF) review</title><description>&lt;a href="http://www.forensicfocus.com/uploads/pro_news/1359471421.9711.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://www.forensicfocus.com/uploads/pro_news/1359471421.9711.jpg" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Reviewed by BitHead (discussion thread &lt;a class="postlink" href="http://www.forensicfocus.com/Forums/viewtopic/t=10196/" rel="nofollow" target="_blank" title="http://www.forensicfocus.com/Forums/viewtopic/t=10196/"&gt;here&lt;/a&gt;).&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
When this review started at the beginning of August 2012, Internet 
Evidence Finder (IEF) was a project of Jad Saliba of JADSoftware.  At 
that time the version was 5.41.&lt;br /&gt;
&lt;br /&gt;
The interface was simple, and IEF was an easy to use tool that found a 
lot of artifacts and displayed them in an easy to follow report.&lt;br /&gt;
&lt;br /&gt;
In the middle of August I was contacted by Adam Belsher of JADSoftware 
and told there was going to be a few major changes coming to 
JADSoftware.  A week later Saliba announced “JADsoftware has a new 
identity, including a new company name – Magnet Forensics.”&lt;br /&gt;&lt;br /&gt;In 
his first blog post on the Magnet Forensics site, Saliba wrote, “A lot 
has changed since I launched JADsoftware and first developed Internet 
Evidence Finder (or IEF) while working as a police officer and forensic 
examiner. After a couple of years juggling both jobs, I realized IEF had
 enormous potential to help you perform better investigations, so I 
decided to dedicate myself to developing the software full-time. The 
growth the company has experienced since then has exceeded my highest 
expectations.”&lt;br /&gt;
&lt;br /&gt;
And there were a lot more changes than just the name...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.forensicfocus.com/c/aid=54/reviews/2013/internet-evidence-finder-ief/"&gt;Read more &lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=m1zRvSsBS3U:BP5TRXSPPQ4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=m1zRvSsBS3U:BP5TRXSPPQ4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=m1zRvSsBS3U:BP5TRXSPPQ4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=m1zRvSsBS3U:BP5TRXSPPQ4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=m1zRvSsBS3U:BP5TRXSPPQ4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=m1zRvSsBS3U:BP5TRXSPPQ4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=m1zRvSsBS3U:BP5TRXSPPQ4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=m1zRvSsBS3U:BP5TRXSPPQ4:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=m1zRvSsBS3U:BP5TRXSPPQ4:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=m1zRvSsBS3U:BP5TRXSPPQ4:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=m1zRvSsBS3U:BP5TRXSPPQ4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2013/01/internet-evidence-finder-ief-review.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2570216565712516945</guid><pubDate>Fri, 30 Nov 2012 14:19:00 +0000</pubDate><atom:updated>2012-11-30T06:19:06.477-08:00</atom:updated><title>Interview with Eddie Sheehy, CEO, Nuix</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.forensicfocus.com/uploads/pro_news/1354245679.7981.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://www.forensicfocus.com/uploads/pro_news/1354245679.7981.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-weight: bold;"&gt;Eddie, can you tell us something about your background and your current role as CEO of &lt;a class="postlink" href="http://www.nuix.com/" rel="nofollow" target="_blank" title="http://www.nuix.com/"&gt;Nuix&lt;/a&gt;?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
I joined &lt;a class="postlink" href="http://www.nuix.com/" rel="nofollow" target="_blank" title="http://www.nuix.com/"&gt;&lt;span style="font-weight: bold;"&gt;Nuix&lt;/span&gt;&lt;/a&gt;
 as CEO in 2006 after working for quite a few high-growth finance and 
technology businesses. What I loved about Nuix was the precise detail 
the software could expose about the information it indexed. Having that 
degree of detail at scale could make a huge difference to the way an 
investigation played out.&lt;br /&gt;
&lt;br /&gt;
After about a year with Nuix, it became clear to me we couldn’t take on 
Access Data and Guidance directly –they owned the forensic investigation
 market. So we expanded into eDiscovery, and later information 
governance, as a way of growing the business. In 2011, having reached a 
more tenable scale, we decided to go back into investigations. That has 
been one of the most satisfying aspects of my time at Nuix.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What products and solutions does Nuix offer?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Nuix offers &lt;a class="postlink" href="http://www.nuix.com/Products" rel="nofollow" target="_blank" title="http://www.nuix.com/Products"&gt;&lt;span style="font-weight: bold;"&gt;products&lt;/span&gt;&lt;/a&gt; and &lt;a class="postlink" href="http://www.nuix.com/Solutions" rel="nofollow" target="_blank" title="http://www.nuix.com/Solutions"&gt;&lt;span style="font-weight: bold;"&gt;solutions&lt;/span&gt;&lt;/a&gt;
 for forensic investigation, eDiscovery and information governance. 
There’s a fair amount of overlap between those categories, for instance 
our Enterprise Collection Center technology for gathering evidence in 
the field is used by investigators and for eDiscovery and our processing
 engine underpins all three verticals.&lt;br /&gt;
&lt;br /&gt;
Indeed, at the heart of these products is our patent pending 
unstructured data indexing engine. The Nuix engine has unique load 
balancing, fault tolerance and intelligent processing technologies that 
enable it to process huge volumes of unstructured data at high speed and
 with forensic certainty...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.forensicfocus.com/c/aid=53/interviews/2012/eddie-sheehy-ceo-nuix/"&gt;Read more &lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=oHlsKxjABg0:mtUACmltRi4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=oHlsKxjABg0:mtUACmltRi4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=oHlsKxjABg0:mtUACmltRi4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=oHlsKxjABg0:mtUACmltRi4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=oHlsKxjABg0:mtUACmltRi4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=oHlsKxjABg0:mtUACmltRi4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=oHlsKxjABg0:mtUACmltRi4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=oHlsKxjABg0:mtUACmltRi4:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=oHlsKxjABg0:mtUACmltRi4:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=oHlsKxjABg0:mtUACmltRi4:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=oHlsKxjABg0:mtUACmltRi4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/11/interview-with-eddie-sheehy-ceo-nuix.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-3781622214377434139</guid><pubDate>Wed, 14 Nov 2012 15:28:00 +0000</pubDate><atom:updated>2012-11-14T07:28:14.988-08:00</atom:updated><title>Interview with Jonathan Krause, Managing Director, First Response</title><description>&lt;a href="http://www.forensicfocus.com/uploads/pro_news/1352892722.4486.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://www.forensicfocus.com/uploads/pro_news/1352892722.4486.jpg" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Jonathan, we last interviewed you back in 2008, what have you been doing since then?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
In early 2008 I started Forensic Control after four years as a computer 
forensic employee. It began as a vehicle for my contract work but soon 
developed into a business in its own right, becoming relatively well 
known – albeit within the fairly small world of computer forensics! I 
moved further and further away from my roots in public sector work, and 
found myself really enjoying the faster pace and challenges in the 
corporate world; there was no going back for me. During this time I was 
fortunate enough to work on some very interesting cases including the 
Deepwater Horizon oil spill and the estate of Elvis Presley.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;You recently became the Managing Director of &lt;a class="postlink" href="http://first-response.co.uk/" rel="nofollow" target="_blank" title="http://first-response.co.uk"&gt;First Response&lt;/a&gt;. Tell us more about the company and your involvement.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
First Response was set up in January 2012, and at present is being run 
alongside Forensic Control. There are three joint owners of the company;
 myself, John Douglas and Bill Lindley. John (the Operations Director), 
Bill (the Chairman) and I bring together over 30 years’ experience of 
working in the industry. We decided to bring the forensic operations of 
our separate companies under one roof which was a natural progression 
for each of our companies. We think we complement each other very well! 
There’s some more background on First Response in the recent Forensic 
Focus &lt;a class="postlink" href="http://www.forensicfocus.com/News/article/sid=1956/" rel="nofollow" target="_blank" title="http://www.forensicfocus.com/News/article/sid=1956/"&gt;news item&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
I’ve known Bill and John professionally and socially for years; as well 
as offering what we believe is a first-class service, we enjoy our work 
and enjoy working with each other – for me, this is of fundamental 
importance.&lt;br /&gt;
&lt;br /&gt;
In terms of my involvement, I’m a typical managing director/CEO though 
with a very much hands-on role. You’re as likely to find me imaging an 
unusual server configuration, analysing the content and reporting back 
to the client as much as dealing with the behind scenes management.&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;Can you give us some recent examples of cases First Response has worked on?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Sure. I think First Response’s main strength is in having both a great 
technical depth and an ability to communicate complex matters in a way 
that an average lawyer or director can easily understand and then act 
on. This helps our clients tremendously as it did in the two examples of
 cases I'll outline...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.forensicfocus.com/c/aid=52/interviews/2012/jonathan-krause-managing-director-first-response/"&gt;Read more &lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_KHxwE0OhQU:EN7LWtJjfN0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_KHxwE0OhQU:EN7LWtJjfN0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_KHxwE0OhQU:EN7LWtJjfN0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=_KHxwE0OhQU:EN7LWtJjfN0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_KHxwE0OhQU:EN7LWtJjfN0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_KHxwE0OhQU:EN7LWtJjfN0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=_KHxwE0OhQU:EN7LWtJjfN0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_KHxwE0OhQU:EN7LWtJjfN0:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_KHxwE0OhQU:EN7LWtJjfN0:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_KHxwE0OhQU:EN7LWtJjfN0:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_KHxwE0OhQU:EN7LWtJjfN0:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/11/interview-with-jonathan-krause-managing.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-9104117494182032622</guid><pubDate>Thu, 01 Nov 2012 16:12:00 +0000</pubDate><atom:updated>2012-11-01T09:12:14.112-07:00</atom:updated><title>Webinar (online now): Pitfalls of Interpreting Forensic Artifacts in the Windows Registry</title><description>The webinar "Pitfalls of Interpreting Forensic Artifacts in the Windows Registry" is now online &lt;a class="postlink" href="http://www.forensicfocus.com/c/aid=51/webinars/2012/some-pitfalls-of-interpreting-forensic-artifacts-in-the-windows-registry/" rel="nofollow" target="_blank" title="http://www.forensicfocus.com/c/aid=51/webinars/2012/some-pitfalls-of-interpreting-forensic-artifacts-in-the-windows-registry/"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
If you encounter any difficulties viewing the above page, the webinar is also available on YouTube &lt;a class="postlink" href="http://youtu.be/MC9AlUPvgRU" rel="nofollow" target="_blank" title="http://youtu.be/MC9AlUPvgRU"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
In this webinar, Jacky Fox, student at UCD School of Computer Science 
and Informatics, presents the results of her dissertation on Windows 
Registry reporting. Jacky will be available in &lt;a class="postlink" href="http://www.forensicfocus.com/Forums/viewtopic/t=9881/" rel="nofollow" target="_blank" title="http://www.forensicfocus.com/Forums/viewtopic/t=9881/"&gt;this forum thread&lt;/a&gt; for about an hour to answer any questions.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=s7Kpr_Rdw3k:cfkV75VtM_g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=s7Kpr_Rdw3k:cfkV75VtM_g:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=s7Kpr_Rdw3k:cfkV75VtM_g:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=s7Kpr_Rdw3k:cfkV75VtM_g:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=s7Kpr_Rdw3k:cfkV75VtM_g:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=s7Kpr_Rdw3k:cfkV75VtM_g:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=s7Kpr_Rdw3k:cfkV75VtM_g:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=s7Kpr_Rdw3k:cfkV75VtM_g:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=s7Kpr_Rdw3k:cfkV75VtM_g:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=s7Kpr_Rdw3k:cfkV75VtM_g:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=s7Kpr_Rdw3k:cfkV75VtM_g:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/11/webinar-online-now-pitfalls-of.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2657324951539095877</guid><pubDate>Tue, 30 Oct 2012 15:22:00 +0000</pubDate><atom:updated>2012-10-30T08:22:44.517-07:00</atom:updated><title>Guidance Software Releases EnCase® Forensic v7.05</title><description>Guidance Software Inc. has announced the release of &lt;a class="postlink" href="http://www.guidancesoftware.com/encase-forensic.htm" rel="nofollow" target="_blank" title="http://www.guidancesoftware.com/encase-forensic.htm"&gt;&lt;span style="font-weight: bold;"&gt;EnCase® Forensic version 7.05&lt;/span&gt;&lt;/a&gt;.
 This latest version of the industry-standard forensics software 
features key enhancements that enable investigators to work with data 
sets earlier and faster in order to both begin and close cases faster 
than ever before. Speed enhancements in the EnCase Forensic v7.05 
evidence processor have reduced significantly the processing time for 
both small and large data sets. Digital investigators can now rapidly 
process evidence files of virtually unlimited size, dramatically 
reducing case backlogs. With EnCase Forensic v7.05, investigators can 
uncover evidence up to nine times faster than previous versions using 
the greatly enhanced evidence processor...    &lt;br /&gt;&lt;br /&gt;EnCase Forensic 
v7.05 also improves investigative efficiency by automating common 
investigation tasks and significantly reducing manual efforts. 
Prioritized processing lets users process an early subset of evidence 
and make it available more quickly for analysis by investigators. They 
can also choose to continue or to stop processing remaining evidence. 
Enhancements to the analytic capabilities of the product’s built-in Case
 Analyzer offer forensic examiners deeper insight into computer systems 
through higher-level reports on metadata and the ability to compare 
potentially related artifacts side-by-side. Examiners can establish 
hyperlinks to original documents and images within reports. In addition,
 the results of a keyword search can be viewed and analyzed while that 
search is ongoing...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.forensicfocus.com/News/article/sid=1952/"&gt;Read more &lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Yu0XlvU2fGc:6lRUCdzJFOg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Yu0XlvU2fGc:6lRUCdzJFOg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Yu0XlvU2fGc:6lRUCdzJFOg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=Yu0XlvU2fGc:6lRUCdzJFOg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Yu0XlvU2fGc:6lRUCdzJFOg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Yu0XlvU2fGc:6lRUCdzJFOg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=Yu0XlvU2fGc:6lRUCdzJFOg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Yu0XlvU2fGc:6lRUCdzJFOg:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Yu0XlvU2fGc:6lRUCdzJFOg:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Yu0XlvU2fGc:6lRUCdzJFOg:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Yu0XlvU2fGc:6lRUCdzJFOg:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/10/guidance-software-releases-encase.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-6204751859568065653</guid><pubDate>Mon, 29 Oct 2012 15:29:00 +0000</pubDate><atom:updated>2012-10-29T08:29:45.626-07:00</atom:updated><title>Webinar: Pitfalls of Interpreting Forensic Artifacts in the Windows Registry</title><description>In this webinar, Jacky Fox, student at UCD School of Computer Science 
and Informatics, presents the results of her dissertation on Windows 
Registry reporting - focusing on automating correlation and 
interpretation. After the webinar Jacky will be available in the 
Forensic Focus webinars forum to answer any questions.&lt;br /&gt;
&lt;br /&gt;
Date: Thursday, November 1st 2012&lt;br /&gt;
Time: 12PM (midday) EDT US / 4PM GMT UK / 5PM CET Europe&lt;br /&gt;
Duration: 20 mins&lt;br /&gt;
&lt;br /&gt;
There is no need to register for this webinar, simply visit &lt;a class="postlink" href="http://www.forensicfocus.com/webinars" rel="nofollow" target="_blank" title="http://www.forensicfocus.com/webinars"&gt;http://www.forensicfocus.com/webinars&lt;/a&gt; at the above time (the webinar has been pre-recorded and will be archived for viewing later if you are unable to attend)&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=8R6NaDhxoOs:yQ3pM1rbbfk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=8R6NaDhxoOs:yQ3pM1rbbfk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=8R6NaDhxoOs:yQ3pM1rbbfk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=8R6NaDhxoOs:yQ3pM1rbbfk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=8R6NaDhxoOs:yQ3pM1rbbfk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=8R6NaDhxoOs:yQ3pM1rbbfk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=8R6NaDhxoOs:yQ3pM1rbbfk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=8R6NaDhxoOs:yQ3pM1rbbfk:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=8R6NaDhxoOs:yQ3pM1rbbfk:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=8R6NaDhxoOs:yQ3pM1rbbfk:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=8R6NaDhxoOs:yQ3pM1rbbfk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/10/webinar-pitfalls-of-interpreting.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-7515474306935364411</guid><pubDate>Tue, 09 Oct 2012 08:42:00 +0000</pubDate><atom:updated>2012-10-09T01:42:18.789-07:00</atom:updated><title>Interview with Lindy Sheppard, F3 (First Forensic Forum) Secretary</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.forensicfocus.com/uploads/pro_news/thumb_1349698318.2955.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://www.forensicfocus.com/uploads/pro_news/thumb_1349698318.2955.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-weight: bold;"&gt;Lindy, tell us something about the cases you have been involved in.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
I have been involved in quite a variety of cases, from counter terrorism
 to the importation of drugs, fraud, missing children and sadly, far too
 often, the abuse of children. Working alongside Tony Sammes has meant 
that I have been involved in many high profile and often ground breaking
 cases. It has always been good to see the outcome of a trial in the 
news and feel a sense of satisfaction at a job well done. Although not 
working on the technical side of the industry I have been the link 
between Tony and the case officer and/or OIC in far more cases than I 
can number - I do know that I have handled well in excess of 600 
exhibits...&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://www.forensicfocus.com/c/aid=50/interviews/2012/lindy-sheppard-f3-first-forensic-forum-secretary/" rel="nofollow" target="_blank" title="http://www.forensicfocus.com/c/aid=50/interviews/2012/lindy-sheppard-f3-first-forensic-forum-secretary/"&gt;Read more&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=49Y5izzTjbQ:bOJ0LE7fsGQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=49Y5izzTjbQ:bOJ0LE7fsGQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=49Y5izzTjbQ:bOJ0LE7fsGQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=49Y5izzTjbQ:bOJ0LE7fsGQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=49Y5izzTjbQ:bOJ0LE7fsGQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=49Y5izzTjbQ:bOJ0LE7fsGQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=49Y5izzTjbQ:bOJ0LE7fsGQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=49Y5izzTjbQ:bOJ0LE7fsGQ:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=49Y5izzTjbQ:bOJ0LE7fsGQ:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=49Y5izzTjbQ:bOJ0LE7fsGQ:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=49Y5izzTjbQ:bOJ0LE7fsGQ:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/10/interview-with-lindy-sheppard-f3-first.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-6925887519351573335</guid><pubDate>Thu, 13 Sep 2012 15:24:00 +0000</pubDate><atom:updated>2012-09-13T08:24:19.607-07:00</atom:updated><title>Interview with Philip Anderson, Senior Lecturer at Northumbria University</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.forensicfocus.com/uploads/pro_news/thumb_1347543907.5897.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://www.forensicfocus.com/uploads/pro_news/thumb_1347543907.5897.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-weight: bold;"&gt;Philip, can you tell us something about your background and why you decided to teach digital forensics?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
I graduated from Northumbria University with a BSc (Hons) in Business 
Information Technology in 1997 and gained an MSc in Distance Education 
with Athabasca University, Canada by distance learning in 2008.&lt;br /&gt;
&lt;br /&gt;
After I graduated I started working at Northumbria University in a 
number of different IT Support/Developer roles for different departments
 within Northumbria University before becoming a Lecturer in 2001. I 
started teaching programming and also web design and development 
modules. It was in 2004 and 2005 alongside colleagues that we developed 
the undergraduate Computer Forensic degree. Once validated and in its 
first year I naturally changed to teach computer forensic modules (and 
more) as the degree progressed.&lt;br /&gt;&lt;br /&gt;I have over seven years’ 
extensive teaching experience involving Guidance Software (i.e. EnCase) 
in taught computer forensic modules. I have also successfully worked in 
the field, on a number of different forensic examinations of digital 
media for external clients, involving examination, analysis and 
production of extensive reports.&lt;br /&gt;
&lt;br /&gt;
I was appointed a European Network and Information Security Agency 
(ENISA) expert in 2010 for two years for identifying emerging and future
 ICT risks in the area of Information Security Risk Assessment and 
Management. I also served as a Special Constable with Durham 
Constabulary for over 14 years.&lt;br /&gt;
&lt;br /&gt;
For me, the reason I chose and enjoy teaching digital forensics is my 
computing background and the application of that knowledge in 
conjunction with strong investigative skills...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.forensicfocus.com/c/aid=47/interviews/2012/philip-anderson-northumbria-university/"&gt;Read more&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=bdDmyOjIQLg:oG0a81VUSs0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=bdDmyOjIQLg:oG0a81VUSs0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=bdDmyOjIQLg:oG0a81VUSs0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=bdDmyOjIQLg:oG0a81VUSs0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=bdDmyOjIQLg:oG0a81VUSs0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=bdDmyOjIQLg:oG0a81VUSs0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=bdDmyOjIQLg:oG0a81VUSs0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=bdDmyOjIQLg:oG0a81VUSs0:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=bdDmyOjIQLg:oG0a81VUSs0:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=bdDmyOjIQLg:oG0a81VUSs0:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=bdDmyOjIQLg:oG0a81VUSs0:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/09/interview-with-philip-anderson-senior.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-356282390581284643</guid><pubDate>Wed, 29 Aug 2012 15:58:00 +0000</pubDate><atom:updated>2012-08-29T08:58:09.902-07:00</atom:updated><title>Windows 8 Forensics webinar - alternative URL</title><description>Sincere apologies to anyone having difficulty connecting to the 
Meetingburner service to view the Windows 8 Forensics presentation - 
please try the following URL on YouTube instead:&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://youtu.be/uhCooEz9FQs" rel="nofollow" target="_blank" title="http://youtu.be/uhCooEz9FQs"&gt;http://youtu.be/uhCooEz9FQs&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Josh is available in the webinars forum to answer any questions. Please go &lt;a class="postlink" href="http://www.forensicfocus.com/Forums/viewtopic/t=9604/" rel="nofollow" target="_blank" title="http://www.forensicfocus.com/Forums/viewtopic/t=9604/"&gt;here&lt;/a&gt; if you would like to join in the discussion.&lt;br /&gt;
&lt;br /&gt;
Additionally, a PDF with slides from the presentation can be downloaded &lt;a class="postlink" href="http://www.forensicfocus.com/downloads/windows-8-forensics-josh-brunty.pdf" rel="nofollow" target="_blank" title="http://www.forensicfocus.com/downloads/windows-8-forensics-josh-brunty.pdf"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
I will get these gremlins out of the system soon, I promise!&lt;br /&gt;
&lt;br /&gt;
Jamie&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Ouwdtq75tK0:2ZPamtlWgyY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Ouwdtq75tK0:2ZPamtlWgyY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Ouwdtq75tK0:2ZPamtlWgyY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=Ouwdtq75tK0:2ZPamtlWgyY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Ouwdtq75tK0:2ZPamtlWgyY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Ouwdtq75tK0:2ZPamtlWgyY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=Ouwdtq75tK0:2ZPamtlWgyY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Ouwdtq75tK0:2ZPamtlWgyY:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Ouwdtq75tK0:2ZPamtlWgyY:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Ouwdtq75tK0:2ZPamtlWgyY:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Ouwdtq75tK0:2ZPamtlWgyY:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/08/windows-8-forensics-webinar-alternative.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-4738226296958635827</guid><pubDate>Tue, 28 Aug 2012 13:22:00 +0000</pubDate><atom:updated>2012-08-28T06:22:07.434-07:00</atom:updated><title>JADsoftware - The Company Behind IEF - Re-Launches As Magnet Forensics Inc.</title><description>JADsoftware, the company behind the industry-leading digital forensics 
product Internet Evidence Finder (IEF), announced on Monday that they 
have re-launched the company under a new name - &lt;a class="postlink" href="http://www.magnetforensics.com/" rel="nofollow" target="_blank" title="http://www.magnetforensics.com"&gt;&lt;span style="font-weight: bold;"&gt;Magnet Forensics Inc.&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
“A lot has changed since I launched JADsoftware and first developed IEF 
while working as a police officer and forensic examiner,” said Jad 
Saliba, Founder and Chief Technology officer of Magnet Forensics.&lt;br /&gt;
&lt;br /&gt;
“After a couple years juggling both jobs, I realized that IEF had 
tremendous potential to help forensics professionals perform better 
investigations, so I decided to dedicate myself to developing the 
software full-time,” Saliba explained.  “We now have a team of talented 
individuals who are working around the clock to take IEF to the next 
level.  The time felt right to transition to a name that better reflects
 what we do, which is help our customers get to key Internet evidence as
 quickly and easily as possible, among a proliferation of online data.”&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.forensicfocus.com/News/article/sid=1927/"&gt;Read more &lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=OTPbpEPmZto:RTKLcYGLjkI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=OTPbpEPmZto:RTKLcYGLjkI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=OTPbpEPmZto:RTKLcYGLjkI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=OTPbpEPmZto:RTKLcYGLjkI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=OTPbpEPmZto:RTKLcYGLjkI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=OTPbpEPmZto:RTKLcYGLjkI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=OTPbpEPmZto:RTKLcYGLjkI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=OTPbpEPmZto:RTKLcYGLjkI:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=OTPbpEPmZto:RTKLcYGLjkI:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=OTPbpEPmZto:RTKLcYGLjkI:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=OTPbpEPmZto:RTKLcYGLjkI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/08/jadsoftware-company-behind-ief-re.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-7381450282383599448</guid><pubDate>Mon, 27 Aug 2012 16:15:00 +0000</pubDate><atom:updated>2012-08-27T09:15:35.362-07:00</atom:updated><title>Computer Analysts and Experts – Making the Most of GPS Evidence</title><description>&lt;i&gt;by Professor David Last&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
The many companies that sell software for computer forensics have 
developed products for analysing satellite navigators. Police high tech 
crime units and independent laboratories now use this software on an 
industrial scale. Computer technicians conduct the analyses. This is 
home territory for them, since the biggest component of a vehicle 
satellite navigator is a computer, often running the Linux operating 
system, and with access via a USB connection or an SD card. The analysis
 software extracts addresses which it plots using tools such as Google 
Maps. Specialists extract similar data from satnavs built into vehicles.&lt;br /&gt;
&lt;br /&gt;

But many investigating officers find the results disappointing: “it’s
 just a list of addresses!” Unlike CCTV, ANPR and witness evidence, 
there are rarely times or dates to fit into a chronology. And anyway, 
the addresses are simply destinations for planning routes. The defence 
will point out that no-one can say who entered them, or at what time on 
what date, or whether a route was planned to them, or whether the satnav
 ever went there, let alone in a specific vehicle driven by a their 
client!&lt;br /&gt;
&lt;br /&gt;

Another problem is that the investigating officer may simply not be 
able to understand the data provided. What are all these addresses? Were
 they recorded by the device itself or input by a user? Was that 
inputting an intentional action? The sense of frustration is enhanced by
 the quality of reports generated by much commercial software. The best 
packages provide at least some explanation of the data they contain, the
 worst none at all. The technicians who conduct the analyses often have 
neither the time nor the training to help. This leaves the officer with 
the prospect of presenting and defending poorly understood data in 
court. Some just give up!&lt;br /&gt;
&lt;br /&gt;

But the addresses may at least have intelligence value...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2012/08/27/computer-analysts-and-experts-making-the-most-of-gps-evidence/"&gt;Read more&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_inID1hEKsU:KNZ8JTgVY5k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_inID1hEKsU:KNZ8JTgVY5k:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_inID1hEKsU:KNZ8JTgVY5k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=_inID1hEKsU:KNZ8JTgVY5k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_inID1hEKsU:KNZ8JTgVY5k:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_inID1hEKsU:KNZ8JTgVY5k:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=_inID1hEKsU:KNZ8JTgVY5k:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_inID1hEKsU:KNZ8JTgVY5k:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_inID1hEKsU:KNZ8JTgVY5k:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_inID1hEKsU:KNZ8JTgVY5k:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_inID1hEKsU:KNZ8JTgVY5k:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/08/computer-analysts-and-experts-making.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-3592533132043695249</guid><pubDate>Fri, 24 Aug 2012 11:29:00 +0000</pubDate><atom:updated>2012-08-24T04:29:39.772-07:00</atom:updated><title>Generating computer forensic supertimelines under Linux: A comprehensive guide for Windows-based disk images</title><description>When the authors first published this paper, their intentions were to
 develop a comprehensive guide to digital forensic timelines in order to
 consolidate the many fragmented sources of information concerning this 
topic.&amp;nbsp; What they discovered, however, was that quality references were 
often challenging to find among various books, papers, periodicals, 
filesystem specifications and source code.&lt;br /&gt;
&lt;br /&gt;

While conducting their research, they found that practical tool-based
 solutions existed for generating digital forensic timelines, though 
they each had specific limitations.&amp;nbsp; Thus, efforts were undertaken by 
the authors to provide an alternative timeline generation framework.&amp;nbsp; 
Although some in the community had already proposed the use and 
generation of supertimelines, all too often important data sources were 
being left out.&amp;nbsp; In order to rectify this, it became necessary to couple
 additional tools in order to provide maximum evidentiary extraction...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2012/08/22/generating-computer-forensic-supertimelines-under-linux-a-comprehensive-guide-for-windows-based-disk-images/"&gt;Read more &lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1XzEBwGeETk:HvuDD339EOo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1XzEBwGeETk:HvuDD339EOo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1XzEBwGeETk:HvuDD339EOo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=1XzEBwGeETk:HvuDD339EOo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1XzEBwGeETk:HvuDD339EOo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1XzEBwGeETk:HvuDD339EOo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=1XzEBwGeETk:HvuDD339EOo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1XzEBwGeETk:HvuDD339EOo:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1XzEBwGeETk:HvuDD339EOo:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1XzEBwGeETk:HvuDD339EOo:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1XzEBwGeETk:HvuDD339EOo:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/08/generating-computer-forensic.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-6201181260016383662</guid><pubDate>Wed, 22 Aug 2012 14:35:00 +0000</pubDate><atom:updated>2012-08-22T07:35:13.403-07:00</atom:updated><title>Webinar: Windows 8 Forensics - A First Look</title><description>Take a first look at Windows 8 forensics in a webinar presented by Josh 
Brunty, Assistant Professor of Digital Forensics at Marshall University.
 Learn about the changes in Windows 8 which forensic examiners should be
 aware of before this new OS is released to the public in October. After
 the webinar Josh will be available in the Forensic Focus forums to 
answer any questions.&lt;br /&gt;
&lt;br /&gt;
Date: Wednesday, August 29 2012&lt;br /&gt;
Time: 11AM EDT US / 4PM BST UK / 15:00 GMT&lt;br /&gt;
Duration: 35 mins&lt;br /&gt;
&lt;br /&gt;
Register today at &lt;a class="postlink" href="http://forensicfocus.enterthemeeting.com/m/JXI8IWVX" rel="nofollow" target="_blank" title="http://forensicfocus.enterthemeeting.com/m/JXI8IWVX"&gt;http://forensicfocus.enterthemeeting.com/m/JXI8IWVX&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Please share this invitation with any friends or colleagues who might also be interested, thank you.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JsDk9cZe3Mk:KggTm7OqKD0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JsDk9cZe3Mk:KggTm7OqKD0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JsDk9cZe3Mk:KggTm7OqKD0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=JsDk9cZe3Mk:KggTm7OqKD0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JsDk9cZe3Mk:KggTm7OqKD0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JsDk9cZe3Mk:KggTm7OqKD0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=JsDk9cZe3Mk:KggTm7OqKD0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JsDk9cZe3Mk:KggTm7OqKD0:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JsDk9cZe3Mk:KggTm7OqKD0:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JsDk9cZe3Mk:KggTm7OqKD0:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JsDk9cZe3Mk:KggTm7OqKD0:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/08/webinar-windows-8-forensics-first-look.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-8998300233704222394</guid><pubDate>Fri, 17 Aug 2012 12:57:00 +0000</pubDate><atom:updated>2012-08-17T05:57:40.032-07:00</atom:updated><title>Apple phones are AES-tough, says forensics expert</title><description>Monday's &lt;span style="font-style: italic;"&gt;&lt;a class="postlink" href="http://www.technologyreview.com/news/428477/the-iphone-has-passed-a-key-security-threshold/" rel="nofollow" target="_blank" title="http://www.technologyreview.com/news/428477/the-iphone-has-passed-a-key-security-threshold/"&gt;Technology Review&lt;/a&gt;&lt;/span&gt;
 carries a glowing tribute to Apple iPhone security according to its 
author, Simson Garfinkel, a contributing editor who works in computer 
forensics and is highly regarded as a leader in digital forensics. He 
says Apple has passed a threshold “Today the Apple iPhone 4S and iPad 3 
are trustworthy mobile computing systems that can be used for mobile 
payments, e-commerce, and the delivery of high-quality paid 
programming,” thanks to Apple’s heavy investment in iPhone security. 
That is where “threshold” comes in. Apple has crossed it. Even law 
enforcement cannot perform forensic examinations of Apple devices seized
 from criminals, he said...&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://phys.org/news/2012-08-apple-aes-tough-forensics-expert.html" rel="nofollow" target="_blank" title="http://phys.org/news/2012-08-apple-aes-tough-forensics-expert.html"&gt;Read more (Phys.org)&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mDXYy0TGCpw:4K-0MRDpk0o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mDXYy0TGCpw:4K-0MRDpk0o:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mDXYy0TGCpw:4K-0MRDpk0o:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=mDXYy0TGCpw:4K-0MRDpk0o:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mDXYy0TGCpw:4K-0MRDpk0o:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mDXYy0TGCpw:4K-0MRDpk0o:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=mDXYy0TGCpw:4K-0MRDpk0o:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mDXYy0TGCpw:4K-0MRDpk0o:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mDXYy0TGCpw:4K-0MRDpk0o:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mDXYy0TGCpw:4K-0MRDpk0o:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mDXYy0TGCpw:4K-0MRDpk0o:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/08/apple-phones-are-aes-tough-says.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-7929992834295385052</guid><pubDate>Thu, 16 Aug 2012 11:21:00 +0000</pubDate><atom:updated>2012-08-16T04:21:39.578-07:00</atom:updated><title>Researchers Show How to Crack Android Encryption</title><description>As forensic examiners, some of the last things we want to hear are 
"encryption" and "enabled" in the same sentence, however that's what has
 been happening with the current line of Android devices. Starting with 
Android 3.0, devices have been shipping with the ability for the user to
 enable full device encryption. Fortunately for the forensic community, 
there are individuals steadfast to find a way to break that encryption -
 and have already proven how to do so. Two such researchers - Thomas 
Cannon and Seyton Bradford - have demonstrated successful brute force 
attacks against Android encryption. Thomas detailed their findings at 
DEF CON 2012 in his presentation &lt;a class="postlink" href="https://viaforensics.com/mobile-security-category/droid-gaining-access-android-user-data.html" rel="nofollow" target="_blank" title="https://viaforensics.com/mobile-security-category/droid-gaining-access-android-user-data.html"&gt;"Into the Droid - Gaining Access to User Data"&lt;/a&gt;...    &lt;br /&gt;&lt;br /&gt;He
 discusses that the encryption uses standard Linux dm-crypt, 
incorporated in Android devices running version 3.0 and newer, and uses 
the same password to encrypt and decrypt data as is used to unlock or 
log in to the device. So while the encryption is generally considered 
strong, users default to using short or easy-to-type passwords and pins 
to protect their device and enable the encryption...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.forensicfocus.com/News/article/sid=1921/"&gt;Read more &lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=MmUmSk8b-r8:kaYI_9b8fKA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=MmUmSk8b-r8:kaYI_9b8fKA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=MmUmSk8b-r8:kaYI_9b8fKA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=MmUmSk8b-r8:kaYI_9b8fKA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=MmUmSk8b-r8:kaYI_9b8fKA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=MmUmSk8b-r8:kaYI_9b8fKA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=MmUmSk8b-r8:kaYI_9b8fKA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=MmUmSk8b-r8:kaYI_9b8fKA:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=MmUmSk8b-r8:kaYI_9b8fKA:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=MmUmSk8b-r8:kaYI_9b8fKA:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=MmUmSk8b-r8:kaYI_9b8fKA:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/08/researchers-show-how-to-crack-android.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-739387591239774172</guid><pubDate>Fri, 10 Aug 2012 15:53:00 +0000</pubDate><atom:updated>2012-08-10T08:53:27.956-07:00</atom:updated><title>Forensic Examination of FrostWire version 5</title><description>As digital forensic practitioners, we are faced regularly with users 
utilizing the internet to swop and download copyrighted and contraband 
material. Peer to peer (P2P) applications are commonly used for this 
purpose, and like any software application, they are ever changing and 
ever evolving. This paper will discuss how the P2P software application,
 FrostWire v.5, functions and what artifacts can be found and examined 
for forensic purposes. The software application mentioned is one of the 
more popular P2P applications...&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2012/07/19/forensic-examination-of-frostwire-version-5/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2012/07/19/forensic-examination-of-frostwire-version-5/"&gt;Read more&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=kDeC25-2pCY:kBW7iJekOMk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=kDeC25-2pCY:kBW7iJekOMk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=kDeC25-2pCY:kBW7iJekOMk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=kDeC25-2pCY:kBW7iJekOMk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=kDeC25-2pCY:kBW7iJekOMk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=kDeC25-2pCY:kBW7iJekOMk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=kDeC25-2pCY:kBW7iJekOMk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=kDeC25-2pCY:kBW7iJekOMk:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=kDeC25-2pCY:kBW7iJekOMk:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=kDeC25-2pCY:kBW7iJekOMk:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=kDeC25-2pCY:kBW7iJekOMk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/08/forensic-examination-of-frostwire.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-236819036316151548</guid><pubDate>Wed, 01 Aug 2012 13:07:00 +0000</pubDate><atom:updated>2012-08-01T06:08:25.834-07:00</atom:updated><title>Book Review: Mastering Windows Network Forensics &amp; Investigations</title><description>&lt;i&gt;by Chad Tilbury&lt;/i&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Mastering Windows Network Forensics and Investigations&lt;/i&gt;&amp;nbsp;fills
 an interesting niche not well addressed in the pantheon of digital 
forensics resources.&amp;nbsp; The material is well suited for beginning and 
intermediate forensic examiners looking to better understand network 
artifacts and go beyond single-system forensics.&amp;nbsp; I highly recommend it 
for system administrators looking for a different perspective on network
 security or those interested in designing networks to be 
forensics-friendly.&amp;nbsp; That said, the topics covered do not fit within the
 classical definition of network forensics.&amp;nbsp; A more apt title might be&amp;nbsp;&lt;i&gt;Mastering Incident Response Forensics and Investigations&lt;/i&gt;.&lt;br /&gt;
&lt;br /&gt;
This is the first book I have read in the Sybex Mastering series, and
 I was impressed with the writing, research, and editing.&amp;nbsp; The authors 
blended dense material with relevant examples and insightful and 
engaging text boxes.&amp;nbsp; Some of my favorite “side” topics were:&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;“Cross-platform Forensic Artifacts”&lt;/li&gt;
&lt;li&gt;“Registry Research”, illustrating the use of Procmon for application footprinting&lt;/li&gt;
&lt;li&gt;“Time is of the Essence”, explaining fast forensics using event logs and the registry&lt;/li&gt;
&lt;/ul&gt;
The book begins with four chapters familiarizing the reader with Windows
 networking. &amp;nbsp;While this may slow down those hungry for forensics 
topics, they are replete with information.&amp;nbsp; Windows domains, hacking 
methodology, and Windows credentials are all described in these early 
chapters. &amp;nbsp;Amazingly, this is the first forensics book I have read 
containing a discussion of the NTDS.DIT Active Directory database file, 
perhaps the most dangerous file in the enterprise. &amp;nbsp;While there were 
probably too many pages spent on password sniffing and cracking, I 
recognize it is beneficial to understand the risks and I commend the 
authors for also mentioning pass the hash and token stealing attacks.&amp;nbsp; 
It would have been valuable to see these same attacks identified later 
in the book via Windows registry and log artifacts...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2012/07/24/book-review-mastering-windows-network-forensics-investigations/"&gt;Read more &lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JATkT0p4E9c:ayM7pDvDt60:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JATkT0p4E9c:ayM7pDvDt60:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JATkT0p4E9c:ayM7pDvDt60:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=JATkT0p4E9c:ayM7pDvDt60:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JATkT0p4E9c:ayM7pDvDt60:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JATkT0p4E9c:ayM7pDvDt60:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=JATkT0p4E9c:ayM7pDvDt60:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JATkT0p4E9c:ayM7pDvDt60:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JATkT0p4E9c:ayM7pDvDt60:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JATkT0p4E9c:ayM7pDvDt60:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JATkT0p4E9c:ayM7pDvDt60:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/08/book-review-mastering-windows-network.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-9189253206617350996</guid><pubDate>Thu, 26 Jul 2012 15:52:00 +0000</pubDate><atom:updated>2012-07-26T08:52:47.653-07:00</atom:updated><title>Introduction to Penetration Testing – Part 3a – Active Reconnaissance</title><description>&lt;i&gt;by Si Biles, Thinking Security &lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Apologies in advance, this is a bit of a connective blog entry – this
 is a big topic, and it needs some scene setting, basic understanding 
and several weeks worth to get the most out of it.&lt;br /&gt;
&lt;br /&gt;

We live in a connected world now – my other half was showing me a 
washing machine with a WiFi connection and an associated iPhone App that
 would allow you remote control of and reporting about your intimate 
garments spin cycle ! I wonder if that is really necessary to be honest,
 as even if it has finished, knowing &lt;em&gt;that&lt;/em&gt; while I’m in the office and the washing machine is at home is a complete waste of electrons.&lt;br /&gt;
&lt;br /&gt;

The network, and the connected nature of things is what allows us as 
penetration testers to attempt to compromise the security of a company 
without going anywhere near it. There are other aspects to full scale 
penetration testing as I’ve alluded to before – with social engineering 
and physical attack ( lock picking, not baseball bat ) parts of such a 
scope – but a majority of the work is computer and network based.&lt;br /&gt;
&lt;br /&gt;

To that end, a good understanding and working knowledge of networking
 is pretty much a job pre-requisite. So, rather than giving you a lesson
 myself, I’ll give you a quick and dirty set of online references – this
 won’t make you an expert by any stretch of the imagination, but 
hopefully it will get us through the rest of this section without too 
much head scratching.&lt;sup&gt;1&lt;/sup&gt;&lt;br /&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/OSI_model" target="_blank"&gt;The OSI Model&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/Internet_protocol_suite" target="_blank"&gt;Internet Protocol (IP)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/Transmission_Control_Protocol" target="_blank"&gt;Transmission Control Protocol (TCP)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/User_Datagram_Protocol" target="_blank"&gt;User Datagram Protocol (UDP)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
I would apologise for the laziness on my part, however I subscribe to &lt;a href="http://en.wikipedia.org/wiki/Larry_Wall" target="_blank"&gt;Larry Wall’s&lt;/a&gt;&amp;nbsp;school
 of thought that it is a virtue – if someone else has done it well 
enough already, why spend time re-inventing the wheel. The corollary of 
that is, if you find that there isn’t a good explanation of something in
 that set that you’d like to understand better – add a comment on the 
bottom of this post and we’ll bring it up to scratch ( perhaps both here
 and at Wikipedia &lt;img alt=";-)" class="wp-smiley" src="http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif?m=1129645325g" /&gt;  ).&lt;br /&gt;
&lt;br /&gt;

So seing as you all now fully understand TCP/IP packet structure and know your URG from your SYN …&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2012/07/17/introduction-to-penetration-testing-part-3a-active-reconnaissance/"&gt;Read more &lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NXn_wQqH20E:7rM0qyvoJbM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NXn_wQqH20E:7rM0qyvoJbM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NXn_wQqH20E:7rM0qyvoJbM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=NXn_wQqH20E:7rM0qyvoJbM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NXn_wQqH20E:7rM0qyvoJbM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NXn_wQqH20E:7rM0qyvoJbM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=NXn_wQqH20E:7rM0qyvoJbM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NXn_wQqH20E:7rM0qyvoJbM:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NXn_wQqH20E:7rM0qyvoJbM:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NXn_wQqH20E:7rM0qyvoJbM:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NXn_wQqH20E:7rM0qyvoJbM:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/07/introduction-to-penetration-testing_26.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2211107273872672540</guid><pubDate>Tue, 24 Jul 2012 14:08:00 +0000</pubDate><atom:updated>2012-07-24T07:08:00.163-07:00</atom:updated><title>Authenticating Internet Web Pages as Evidence: a New Approach</title><description>By John Patzakis&amp;nbsp;[1] and Brent Botta&amp;nbsp;[2]&lt;br /&gt;
&lt;br /&gt;

Previously, in Forensic Focus, we addressed the issue of evidentiary authentication of social media data (see previous entries &lt;strong&gt;&lt;a href="http://articles.forensicfocus.com/2012/04/02/overcoming-potential-legal-challenges-to-the-authentication-of-social-media-evidence/" title="Overcoming Potential Legal Challenges to the Authentication of Social Media Evidence"&gt;here&lt;/a&gt;&lt;/strong&gt; and &lt;strong&gt;&lt;a href="http://articles.forensicfocus.com/2012/04/25/key-twitter-and-facebook-metadata-fields-forensic-investigators-need-to-be-aware-of/" title=" Key Twitter and Facebook Metadata Fields Forensic Investigators Need to be Aware of"&gt;here&lt;/a&gt;&lt;/strong&gt;).
 General Internet site data available through standard web browsing, 
instead of social media data provided by APIs or user credentials, 
presents slightly different but just as compelling challenges, which are
 outlined below. To help address these unique challenges, we are 
introducing and outlining a specified technical process to authenticate 
collected “live” web pages for investigative and judicial purposes.[3] 
We are not asserting that this process must be adopted as a universal 
standard and recognize that there may be other valid means authenticate 
website evidence. However, we believe that the technical protocols 
outlined below can be a very effective means to properly authenticate 
and verify evidence collected from websites while at the same time 
facilitating an automated and scalable digital investigation workflow.&lt;br /&gt;
&lt;br /&gt;

&lt;strong&gt;Legal Authentication Requirements&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The Internet provides torrential amounts of evidence potentially 
relevant to litigation matters, with courts routinely facing proffers of
 data preserved from various websites. This evidence must be 
authenticated in all cases, and the authentication standard is no 
different for website data or chat room evidence than for any other. 
Under US Federal Rule of Evidence 901(a), “The requirement of 
authentication … is satisfied by evidence sufficient to support a 
finding that the matter in question is what its proponent claims.” 
United States v. Simpson, 152 F.3d 1241, 1249 (10th Cir. 1998).&lt;br /&gt;
&lt;br /&gt;

Ideally, a proponent of the evidence can rely on uncontroverted 
direct testimony from the creator of the web page in question. In many 
cases, however, that option is not available. In such situations, the 
testimony of the viewer/collector of the Internet evidence “in 
combination with &lt;strong&gt;circumstantial indicia&lt;/strong&gt; of authenticity
 (such as the dates and web addresses), would support a finding” that 
the website documents are what the proponent asserts. Perfect 10, Inc. 
v. Cybernet Ventures, Inc. (C.D.Cal.2002) 213 F.Supp.2d 1146, 1154. 
(emphasis added) (See also, Lorraine v. Markel American Insurance 
Company, 241 F.R.D. 534, 546 (D.Md. May 4, 2007) (citing Perfect 10, and
 referencing MD5 hash values as an additional element of potential 
“circumstantial indicia” for authentication of electronic evidence)...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2012/07/13/authenticating-internet-web-pages-as-evidence-a-new-approach/"&gt;Read more &lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=EYdwfmR0U2U:Yi5hncC0nvM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=EYdwfmR0U2U:Yi5hncC0nvM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=EYdwfmR0U2U:Yi5hncC0nvM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=EYdwfmR0U2U:Yi5hncC0nvM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=EYdwfmR0U2U:Yi5hncC0nvM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=EYdwfmR0U2U:Yi5hncC0nvM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=EYdwfmR0U2U:Yi5hncC0nvM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=EYdwfmR0U2U:Yi5hncC0nvM:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=EYdwfmR0U2U:Yi5hncC0nvM:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=EYdwfmR0U2U:Yi5hncC0nvM:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=EYdwfmR0U2U:Yi5hncC0nvM:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/07/authenticating-internet-web-pages-as.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-6277102102889010104</guid><pubDate>Thu, 19 Jul 2012 15:24:00 +0000</pubDate><atom:updated>2012-07-19T08:24:13.238-07:00</atom:updated><title>"Finding Evidence in an Online World" webinar recording and PDF now available</title><description>A recording of this week's webinar "Finding Evidence in an Online World -
 Trends and Challenges in Digital Forensics" is now available &lt;a class="postlink" href="http://www.forensicfocus.com/DF_Multimedia/page=watch/id=79/d=1/" rel="nofollow" target="_blank" title="http://www.forensicfocus.com/DF_Multimedia/page=watch/id=79/d=1/"&gt;here&lt;/a&gt; and on YouTube &lt;a class="postlink" href="http://www.youtube.com/watch?v=dUpSsoCbChw" rel="nofollow" target="_blank" title="http://www.youtube.com/watch?v=dUpSsoCbChw"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Sincere thanks to Jad Saliba for agreeing to re-record the presentation 
yesterday as a result of the audio issues we experienced during the live
 version. Also, a number of people requested a PDF version of the slides
 and Jad has kindly made that available &lt;a class="postlink" href="http://www.forensicfocus.com/downloads/jad-saliba-finding-evidence-in-an-online-world.zip" rel="nofollow" target="_blank" title="http://www.forensicfocus.com/downloads/jad-saliba-finding-evidence-in-an-online-world.zip"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
A free trial of IEF (the software used in the presentation)  is available at &lt;a class="postlink" href="http://www.jadsoftware.com/trial" rel="nofollow" target="_blank" title="http://www.jadsoftware.com/trial"&gt;http://www.jadsoftware.com/trial&lt;/a&gt; and for details of a 10% discount available until August 1st 2012 please contact &lt;a href="mailto:sales@jadsoftware.com"&gt;sales@jadsoftware.com&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=F9bz105Zh64:vSH5NDBXJ_E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=F9bz105Zh64:vSH5NDBXJ_E:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=F9bz105Zh64:vSH5NDBXJ_E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=F9bz105Zh64:vSH5NDBXJ_E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=F9bz105Zh64:vSH5NDBXJ_E:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=F9bz105Zh64:vSH5NDBXJ_E:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=F9bz105Zh64:vSH5NDBXJ_E:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=F9bz105Zh64:vSH5NDBXJ_E:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=F9bz105Zh64:vSH5NDBXJ_E:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=F9bz105Zh64:vSH5NDBXJ_E:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=F9bz105Zh64:vSH5NDBXJ_E:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/07/finding-evidence-in-online-world.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-6022815431863131753</guid><pubDate>Sat, 14 Jul 2012 19:20:00 +0000</pubDate><atom:updated>2012-07-14T12:22:20.964-07:00</atom:updated><title>Retrieving Digital Evidence: Methods, Techniques and Issues</title><description>&lt;i&gt;by Yuri Gubanov&amp;nbsp;&lt;a href="mailto:yug@belkasoft.com"&gt;yug@belkasoft.com&lt;/a&gt;&lt;br /&gt;
Belkasoft Ltd.&amp;nbsp;&lt;a href="http://belkasoft.com/"&gt;http://belkasoft.com&lt;/a&gt; &lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
This article describes the various types of digital forensic evidence 
available on users’ PC and laptop computers, and discusses methods of 
retrieving such evidence.&lt;br /&gt;
&lt;br /&gt;
A recent&amp;nbsp;&lt;a href="http://www-scf.usc.edu/%7Euscsec/images/DigitalEvidence&amp;amp;ComputerForensicsversion1.2USC.pdf" target="_blank"&gt;research conducted by Berkeley scientists&lt;/a&gt;&amp;nbsp;concluded
 that up to 93% of all information never leaves the digital domain. This
 means that the majority of information is being created, modified and 
consumed entirely in digital form. Most spreadsheets and databases never
 make it on paper, and most digital snapshots never get printed. There 
are many activities such as chats and social networking that are 
specific to digital and are even unimaginable outside of the virtual 
realm.&lt;br /&gt;
&lt;br /&gt;
Most such activities leave definite traces, allowing investigators to 
obtain essential evidence, solve criminal cases and prevent crimes. This
 article discusses the many types of digital evidence produced by a 
typical computer user, criminal or not, and demonstrates methods and 
techniques available to extract that evidence out of the original PC and
 into the hands of a forensic investigator...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2012/07/11/retrieving-digital-evidence-methods-techniques-and-issues/"&gt;Read more &lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=krkzfeMbxeU:LkEMeAic8hI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=krkzfeMbxeU:LkEMeAic8hI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=krkzfeMbxeU:LkEMeAic8hI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=krkzfeMbxeU:LkEMeAic8hI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=krkzfeMbxeU:LkEMeAic8hI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=krkzfeMbxeU:LkEMeAic8hI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=krkzfeMbxeU:LkEMeAic8hI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=krkzfeMbxeU:LkEMeAic8hI:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=krkzfeMbxeU:LkEMeAic8hI:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=krkzfeMbxeU:LkEMeAic8hI:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=krkzfeMbxeU:LkEMeAic8hI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/07/retrieving-digital-evidence-methods.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-3815550640807754259</guid><pubDate>Fri, 13 Jul 2012 16:41:00 +0000</pubDate><atom:updated>2012-07-14T12:24:27.743-07:00</atom:updated><title>Parallels hard drive image converting for analysis</title><description>&lt;div id="entry-author-info-heading"&gt;
&lt;i&gt;by zoltanszabodfw&lt;/i&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
The other day, talking to one of the analysts in Dallas, a question 
emerged about analyzing Parallels’ virtual machine hard drives.&amp;nbsp; To my 
surprise, I did not find many help on this issue on-line and did not 
find tools that would interpret the file system in Parallels’ hard drive
 images.&amp;nbsp; The simplest way I wanted to approach this issue is by 
converting the hard drive image to something simpler like a dd image.&amp;nbsp; I
 found a very nice article on how to convert to a plain hard drive image
 using Parallels Image Tool that comes with Parallels Desktop( &lt;a href="http://digfor.blogspot.com/2009/08/mounting-parallels-hdd-and-hds-files.html"&gt;http://digfor.blogspot.com/2009/08/mounting-parallels-hdd-and-hds-files.html&lt;/a&gt;),
 but I had no access to a Mac and wanted to see if there is a way to do 
this on Windows.&amp;nbsp; There was VMware vCenter Converter ( free software – &lt;a href="http://www.vmware.com/products/converter"&gt;http://www.vmware.com/products/converter&lt;/a&gt; ), but it did not by giving a message the it could not recognized it.&amp;nbsp; I also found an interesting tool MakeVM – &lt;a href="http://www.sysdevsoftware.com/soft/makevm.php"&gt;http://www.sysdevsoftware.com/soft/makevm.php&lt;/a&gt;
 that looked very promising, but the demo version would not convert an 
image size larger than 2GB.&amp;nbsp; So, I wanted to look further into other 
options.&amp;nbsp; This article is about the findings of that “journey”.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Parallels Workstation comes with a few command line tools for basic 
drive manipulation like prl_disk_tool or prl_conver, but the best 
converter, I found, is the latest Open Source project QEMU.&lt;br /&gt;
&lt;a href="http://lassauge.free.fr/qemu/release/Qemu-1.0.1-windows.zip"&gt;Qemu-1.0.1-windows.zip&lt;/a&gt; &lt;b&gt;- &lt;/b&gt;&lt;a href="http://lassauge.free.fr/qemu/"&gt;http://lassauge.free.fr/qemu/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
One of the utilities in QEMU is qemu-img where the help file reveals 
the value of this simple utility, when it comes to converting image 
types.&amp;nbsp; The latest version just added the parallels’ image format 
support.&amp;nbsp; &lt;span style="color: red;"&gt;“Supported formats: blkdebug 
blkverify bochs cloop cow dmg nbd parallels qcow qco w2 qed host_device 
file raw sheepdog vdi vmdk vpc vvfat”&lt;/span&gt;&lt;br /&gt;
&lt;span style="color: red;"&gt;&amp;nbsp; &lt;/span&gt;&lt;br /&gt;
Step 1. I have downloaded Parallels Workstation trail version to 
create a virtual machine for testing and to make sure my findings will 
be applicable to the latest version of Parallels.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Parallels Workstation Build 6.0.13976&lt;/i&gt;&lt;br /&gt;
&lt;i&gt; ( Revision 769982; June 8, 2012 )&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Step 2. Created a virtual machine ( Windows 2008 Server ) with a 20GB hard drive.&lt;br /&gt;
Step 3. Used qemu-img utility to convert the image into a raw image&lt;br /&gt;
&lt;span style="color: red;"&gt;&lt;i&gt;qemu-img.exe convert -f parallels -O 
raw “Windows Server 
2008-0.hdd.copy.0.{5fbaabe3-6958-40ff-92a7-860e329aab41}.hds” 
f:\temp\otput.dd&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;
Step 4. Opened the image in FTK Imager to analyze the data&lt;br /&gt;
&lt;br /&gt;
&lt;div class="wp-caption alignnone" id="attachment_1692" style="width: 310px;"&gt;
&lt;a href="http://forensicfocus.files.wordpress.com/2012/07/one2.png"&gt;&lt;img alt="" class="size-medium wp-image-1692 " height="168" src="http://forensicfocus.files.wordpress.com/2012/07/one2.png?w=300&amp;amp;h=168" title="Converted image in FTK Imager" width="300" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;div class="wp-caption-text"&gt;
Parallels converted hard drive image in FTK Imager&lt;/div&gt;
&lt;div class="wp-caption-text"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="wp-caption-text"&gt;
&lt;a href="http://articles.forensicfocus.com/2012/07/05/parallels-hard-drive-image-converting-for-analysis/"&gt;Read more &lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ARdWCHiP2M0:z4n0zZjZu0M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ARdWCHiP2M0:z4n0zZjZu0M:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ARdWCHiP2M0:z4n0zZjZu0M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=ARdWCHiP2M0:z4n0zZjZu0M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ARdWCHiP2M0:z4n0zZjZu0M:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ARdWCHiP2M0:z4n0zZjZu0M:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=ARdWCHiP2M0:z4n0zZjZu0M:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ARdWCHiP2M0:z4n0zZjZu0M:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ARdWCHiP2M0:z4n0zZjZu0M:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ARdWCHiP2M0:z4n0zZjZu0M:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ARdWCHiP2M0:z4n0zZjZu0M:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/07/parallels-hard-drive-image-converting.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-660550266090367045</guid><pubDate>Wed, 11 Jul 2012 10:27:00 +0000</pubDate><atom:updated>2012-07-11T03:27:53.466-07:00</atom:updated><title>Introduction to Penetration Testing – Part 2 – The Discovery Phase – Passive Reconnaissance</title><description>&lt;a href="http://upload.wikimedia.org/wikipedia/commons/thumb/f/f5/Fernglas%28alt%29.JPG/300px-Fernglas%28alt%29.JPG" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://upload.wikimedia.org/wikipedia/commons/thumb/f/f5/Fernglas%28alt%29.JPG/300px-Fernglas%28alt%29.JPG" /&gt;&lt;/a&gt;&lt;em&gt;&lt;em&gt;by Si Biles ( @si_biles ), consultant for&amp;nbsp;&lt;a href="http://www.thinking-security.co.uk/" target="_blank" title="Thinking Security"&gt;Thinking Security&lt;/a&gt;&lt;/em&gt;&lt;/em&gt; &lt;br /&gt;
&lt;br /&gt;
PenTest, like forensics, is almost as much an art as it is a science –
 you can only be taught so far, technical techniques and tools are all 
very well, but you really need a mind that can think sideways and 
approach a task from as many angles as possible. The ex-LE forensicators
 have this skill in spades – the data that is potentially available 
during an investigation includes interviews, statements, crime scene 
photos and all matter of collected evidence – in the commercial world 
there is less available, but still I’m confident that you’ll all have 
your sources. PenTest is much the same, the more that we can know about a
 potential target before we even fire up NMap&lt;sup&gt;1&lt;/sup&gt;, the further we will get.&lt;br /&gt;
&lt;br /&gt;

The title of this segment is “Passive Reconnaissance” – that’s not to
 say that you don’t have to do anything during this phase and that it 
all comes to you – it’s about obtaining information which is already in 
the public domain – not necessarily deliberately – and is related to the
 target.&lt;sup&gt;2&lt;/sup&gt;&lt;br /&gt;
&lt;br /&gt;

There isn’t really anything, at this stage, that we &lt;em&gt;aren’t&lt;/em&gt; interested in – collect all the information you can – we can whittle it down to pertinent facts as we go along&lt;sup&gt;3&lt;/sup&gt;.&lt;br /&gt;
&lt;br /&gt;

Right then – where to start ? Well, let’s start to build a picture of our target. Let’s have a look at their domain:&lt;br /&gt;
&lt;br /&gt;

&lt;code&gt;si$ whois google.co.uk&lt;br /&gt;
Domain name:&lt;br /&gt;
google.co.uk&lt;br /&gt;
Registrant:&lt;br /&gt;
Google Inc.&lt;br /&gt;
Registrant type:&lt;br /&gt;
Unknown&lt;br /&gt;
Registrant's address:&lt;br /&gt;
1600 Amphitheatre Parkway&lt;br /&gt;
Mountain View&lt;br /&gt;
CA&lt;br /&gt;
94043&lt;br /&gt;
United States&lt;br /&gt;
Registrar:&lt;br /&gt;
Markmonitor Inc. t/a Markmonitor [Tag = MARKMONITOR]&lt;br /&gt;
URL: http://www.markmonitor.com&lt;br /&gt;
Relevant dates:&lt;br /&gt;
Registered on: 14-Feb-1999&lt;br /&gt;
Expiry date: 14-Feb-2013&lt;br /&gt;
Last updated: 10-Feb-2011&lt;br /&gt;
Registration status:&lt;br /&gt;
Registered until expiry date.&lt;br /&gt;
Name servers:&lt;br /&gt;
ns1.google.com&lt;br /&gt;
ns2.google.com&lt;br /&gt;
ns3.google.com&lt;br /&gt;
ns4.google.com&lt;br /&gt;
WHOIS lookup made at 23:20:53 03-Jul-2012&lt;br /&gt;
--&lt;/code&gt;&lt;br /&gt;

Ok, so we have a home address for our company – this example isn’t 
the most detailed, but you can often glean names, e-mail addresses and 
phone numbers from a &lt;code&gt;whois&lt;/code&gt; lookup. It’s good if you can get
 an e-mail address – these will start to give you an idea of what the 
common format is that is&amp;nbsp;used within the company – e.g. first initial 
last name (sbiles) or first name.last name (simon.biles) or if there is a
 complicator (simon.biles100) [incidentally these are all real addresses
 at various organisations I've worked at]. Remember this, it will come 
in useful later.&lt;br /&gt;
&lt;br /&gt;

If we have a look at the website of our target itself, it is most 
likely that there will be good information there too – names, addresses,
 phone-numbers and e-mails are all good. Also, look out for support 
contact details, FTP site details and logins for example, social 
networking links etc. All of this is grist to the mill – potential 
routes of later attack, sources for social engineering, logins to 
systems that will get you past the first line of defence. Take a note of
 product names as well, these are often used as “guest” login details 
for FTP sites too – “producttrial” as both the username and password for
 example – for sales staff to use with customers. If you are planning a 
social engineering phase, it can be&amp;nbsp;beneficial&amp;nbsp; to take copies of 
web-pages ( faking a login page ), logos ( faking business cards and 
documents ) and other official looking documents and marketing material –
 I personally dislike performing social engineering, it’s often the 
easiest way to get into somewhere – if you are going to do it, make sure
 that you agree with your client in advance that there will be no 
repercussions for any member of staff that you succeed in manipulating, 
and that anonymity will be preserved – it could be an unlucky ring of 
the phone that costs someone their job otherwise.&lt;br /&gt;
&lt;br /&gt;

Where next ? Google. Google is your friend – it is one of the most 
amazing tools available, not only having a huge index of things that are
 current, but also cached copies of things that might not be so current.
 Googling well is a skill, not unlike that of writing search queries for
 Forensic searches – just Google is a lot faster than EnCase or FTK over
 a &lt;span style="color: black;"&gt;&lt;strong&gt;much&lt;/strong&gt; bigger data set...&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="color: black;"&gt;&lt;a href="http://articles.forensicfocus.com/2012/07/03/introduction-to-penetration-testing-part-2-the-discovery-phase-passive-reconnaissance/"&gt;Read more &lt;/a&gt;&lt;/span&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9-HA-xP8jvU:7w1lCChgl_A:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9-HA-xP8jvU:7w1lCChgl_A:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9-HA-xP8jvU:7w1lCChgl_A:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=9-HA-xP8jvU:7w1lCChgl_A:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9-HA-xP8jvU:7w1lCChgl_A:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9-HA-xP8jvU:7w1lCChgl_A:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=9-HA-xP8jvU:7w1lCChgl_A:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9-HA-xP8jvU:7w1lCChgl_A:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9-HA-xP8jvU:7w1lCChgl_A:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9-HA-xP8jvU:7w1lCChgl_A:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9-HA-xP8jvU:7w1lCChgl_A:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/07/introduction-to-penetration-testing.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-4769994394503975894</guid><pubDate>Thu, 05 Jul 2012 12:37:00 +0000</pubDate><atom:updated>2012-07-05T05:37:35.530-07:00</atom:updated><title>Interview with John H. Riley, Bloomsburg University of Pennsylvania</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.forensicfocus.com/uploads/pro_news/1341316881.1748.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://www.forensicfocus.com/uploads/pro_news/1341316881.1748.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-weight: bold;"&gt;John, can you tell us something about your background and why you decided to teach digital forensics?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
First, thanks for the opportunity to discuss our program. We're really 
proud of what we've accomplished here and believe we're contributing to 
the digital forensics community. I started as a mathematician (Ph.D., 
University of Connecticut, 1980) and then began to teach computer 
science as well as mathematics in the 1980s. I wrote two programming 
textbooks (Pascal, for the old timers). About six or seven years ago, my
 department was investigating majors that would be good for students. We
 decided upon computer forensics. It is an interesting, useful field of 
study that has worked really well for us and our students.&lt;br /&gt;&lt;br /&gt;On the
 intellectual side, I find the whole issue of what information can be 
found and how it can be used to build a story quite fascinating. "Story"
 here means a narrative that shows what happened, in a rigorous sense (a
 la a mathematician's proof). As a professor, it's really fun to work 
with digital forensics students. Our curriculum has a lot of hands on 
work so we see our students really digging into things. The ultimate 
reward is seeing them graduate and begin work. I must note that I've had
 really great colleagues, particularly Scott Inch, to work with. I also 
am grateful to the larger forensics community for their help.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;What digital forensic courses are currently offered by Bloomsburg University?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Introduction to Digital Forensics, File Systems 1 and 2, Digital 
Forensics Software, Advanced Topics in Digital Forensics, Small Devices 
Forensics, UNIX/Linux for Digital Forensics.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;Tell us more about course structure and 
content. What core knowledge and key skills should students gain by the 
end of their studies?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
The first five courses listed above (along with some computer science 
and other courses) form the backbone of our major. They cover the 
artifacts that can be found on a computer (and how they come to be), how
 the artifacts can be extracted in a forensically sound manner and how 
they can be linked together and presented or reported. As an example, 
students know why a deleted file may or may not be able to be recovered,
 how to use a tool like EnCase or FTK (or even a hex editor) to recover 
it, how it might be related to a link file or a registry entry, how to 
ensure its integrity after extraction using a hash function and how to 
include it in a report. We stress the importance of knowing how the 
computer is organizing files and generating artifacts so that what a 
tool produces is understood. Our graduates are prepared to defend their 
results. We also put this work in context. It's not just finding a 
deleted file, it's finding evidence which may change a person's life. So
 beyond knowledge and skills, we foster a sense of responsibility and 
integrity...&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Read more at&amp;nbsp;&lt;a href="http://www.forensicfocus.com/c/aid=46/interviews/2012/john-h-riley-bloomsburg-university-of-pennsylvania/"&gt;http://www.forensicfocus.com/c/aid=46/interviews/2012/john-h-riley-bloomsburg-university-of-pennsylvania/&lt;/a&gt; &lt;/i&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=v1hasBtHocg:w6W3UdKeQFs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=v1hasBtHocg:w6W3UdKeQFs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=v1hasBtHocg:w6W3UdKeQFs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=v1hasBtHocg:w6W3UdKeQFs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=v1hasBtHocg:w6W3UdKeQFs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=v1hasBtHocg:w6W3UdKeQFs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=v1hasBtHocg:w6W3UdKeQFs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=v1hasBtHocg:w6W3UdKeQFs:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=v1hasBtHocg:w6W3UdKeQFs:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=v1hasBtHocg:w6W3UdKeQFs:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=v1hasBtHocg:w6W3UdKeQFs:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/07/interview-with-john-h-riley-bloomsburg.html</link><author>noreply@blogger.com (Jamie)</author><thr:total>0</thr:total></item></channel></rss>
