<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-36666403</atom:id><lastBuildDate>Thu, 17 May 2012 14:03:01 +0000</lastBuildDate><category>data recovery</category><category>Guidance Software</category><category>Scott Burkeman</category><category>Hard disk data storage</category><category>CSITech</category><category>Research</category><category>write blocking</category><category>graduates</category><category>Adroit Photo Forensics</category><category>Digital Evidence Collection Kit</category><category>Computer Forensic Investigation</category><category>storage</category><category>privacy</category><category>graduate</category><category>stalking</category><category>cold boot attack</category><category>mobile telephone connection records</category><category>bitlocker</category><category>business continuity</category><category>cell phone forensics</category><category>file carving</category><category>Criminal Justice and Immigration Bill</category><category>Kaminsky</category><category>encryption</category><category>cyberstalking</category><category>George Chlapoutakis</category><category>McMurdie</category><category>validating</category><category>tactical</category><category>David Benford</category><category>dominik weber</category><category>computer forensics</category><category>Forensic 4cast</category><category>Lance Mueller</category><category>hotplug</category><category>computer forensics events</category><category>Greg Smith</category><category>Google history</category><category>Projects</category><category>clifford stoll</category><category>review</category><category>Challenges</category><category>security metrics</category><category>Appointments-UK</category><category>training</category><category>blogs</category><category>Graham Brown-Martin</category><category>reporting</category><category>future</category><category>cv</category><category>scalability</category><category>write blocker review</category><category>ntfs</category><category>Chris Pamplin</category><category>Images</category><category>Si Biles</category><category>FTK</category><category>computer forensics jobs</category><category>EnCase</category><category>PIN</category><category>document analysis</category><category>Cystinosis</category><category>Experience</category><category>craig ball</category><category>forensics</category><category>employment</category><category>David Sullivan</category><category>data recovery training</category><category>Jon Rowe</category><category>online</category><category>Google forensics</category><category>Nick Furneaux</category><category>interview</category><category>expet witness</category><category>ACPO Good Practice Guide</category><category>Lee Whitfield</category><category>computer forensics costs prices</category><category>forensic focus stats</category><category>computer forensics licensing</category><category>tagview</category><category>Russell May</category><category>Columnists</category><category>interviews</category><category>DOMEX</category><category>expert witness</category><category>EnScripts</category><category>geotags</category><category>simon biles</category><category>key recovery</category><category>feeds</category><category>e-fense Live Response</category><category>forensic software</category><category>cell site analysis</category><category>education</category><category>technology</category><category>forensic hardware</category><category>Bright Forensics</category><category>computer security</category><category>Simson Garfinkel</category><category>Nessus</category><category>Tableau</category><category>Zimmermann</category><category>digital evidence</category><category>push button</category><category>passwords</category><category>truecrypt</category><category>forums</category><category>Scott Moulton</category><category>Search Warrants</category><category>iso</category><category>Infosecurity</category><category>chris hargreaves</category><category>Students</category><category>Sam Raincock</category><category>Programming</category><category>telecoms</category><category>procedures</category><category>live forensics</category><category>computer forensics education</category><category>harassment</category><category>mobile forensics</category><category>Advanced Forensic Sessions</category><category>survey</category><category>Pinpoint Labs</category><category>write blockers</category><category>peer review</category><category>UK Register of Expert Witnesses</category><category>data protection</category><category>single sign on</category><category>forensic reports</category><category>terms of engagement</category><category>image</category><category>disaster recovery</category><category>SIM</category><category>Tony Sammes</category><category>recruitment</category><category>4N6 Investigation</category><category>hard disk reliability</category><category>holographic memory</category><category>wiebetech</category><category>sharing knowledge</category><category>Matthew Shannon</category><category>V200 SIM Dialer</category><category>sterilization</category><category>cuckoo's egg</category><category>games consoles</category><category>Cloud Computing</category><category>recruiters</category><category>cold boot</category><category>careers</category><category>Agile Risk Management</category><category>vulnerability scanners</category><category>dan gaskell</category><category>Stephen Mason</category><category>network forensics</category><category>copyright</category><category>certification</category><category>Helix 3 Enterprise</category><category>wiping</category><category>jobs</category><category>Diffie</category><category>Digital Safety Conference</category><category>twitter</category><category>Robert Botchek</category><category>computer forensics recruitment</category><category>Hoffmann</category><category>compliance</category><category>computer forensics training</category><category>sean mclinden</category><category>standards</category><category>X-Ways</category><category>global computer forensics</category><category>memory acquisition</category><category>metadata</category><category>F-Response</category><category>electronic signatures</category><category>Ben Levitan</category><category>computer forensics podcasts</category><category>Windows Search forensics</category><title>Forensic Focus Blog</title><description>Official blog of &lt;a href="http://www.forensicfocus.com"&gt;ForensicFocus.com&lt;/a&gt;</description><link>http://forensicfocus.blogspot.com/</link><managingEditor>noreply@blogger.com (admin)</managingEditor><generator>Blogger</generator><openSearch:totalResults>186</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="forensicfocusblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://www.forensicfocus.com/blog/feed.php" /><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.bloglines.com/sub/http://www.forensicfocus.com/blog/feed.php" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://fusion.google.com/add?feedurl=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-4962882442522503830</guid><pubDate>Thu, 17 May 2012 14:03:00 +0000</pubDate><atom:updated>2012-05-17T07:03:01.190-07:00</atom:updated><title>Interview with John Patzakis, Founder and CEO of X1 Discovery</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.forensicfocus.com/uploads/pro_news/1337187562.2303.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://www.forensicfocus.com/uploads/pro_news/1337187562.2303.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-weight: bold;"&gt;John, the last time you were interviewed
 at Forensic Focus you were the Vice Chairman and Chief Legal Officer at
 Guidance Software. Now you're the founder and CEO of &lt;a class="postlink" href="http://www.x1discovery.com/" rel="nofollow" target="_blank" title="http://www.x1discovery.com"&gt;X1 Discovery&lt;/a&gt; - tell us about that move.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
I am proud to have been a co-founder and part of the senior team at 
Guidance Software for ten years. The early days at Guidance were 
exciting as we sowed new fields, just as we are doing now at X1 
Discovery. At Guidance, we first pioneered Windows-based forensics, 
which was the new paradigm and represented an order of magnitude 
improvement over Dos-based forensics. Then circa 2004, we introduced and
 championed the concept of enterprise in-house eDiscovery, a strategy 
that ended up being Guidance’s main force of growth leading to our IPO 
in 2006.&lt;br /&gt;&lt;br /&gt;So after leaving in 2009 and engaging in consulting 
projects through 2010 I began discussions with X1, an Idealab Company 
that I always thought had excellent search technology for both the 
desktop and the enterprise. At first the intent was to sit on the board 
as an investor but then I learned about the IP they were developing for 
social media, and I also became excited about the promise of X1’s 
enterprise server to be a very robust eDiscovery early case assessment 
and first pass review solution. So to make a long story short, the board
 at Idealab – which is our parent company -- offered to have me head up 
X1 Discovery as a spin-off to X1 Technologies, with ownership of all our
 intellectual property. It was a great opportunity and the Idealab board
 has been very supportive and enabled me to recruit some outstanding 
talent and assemble a great team.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;What does X1 Discovery do? What makes it
 different from the other eDiscovery companies which have entered the 
market in the past few years?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
At X1 Discovery we are pioneering the new fields of forensics and 
eDiscovery of social media and cloud-based data. I have always been 
interested in where the puck is going as opposed to where it is now, and
 we believe the X1 Discovery’s disruptive technology is already years 
ahead of the field. We accomplished this by leveraging our vision and 
industry experience to effectively build on the patented X1 Search 
Technology. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;Tell us more about your products, X1 Social Discovery and X1 Rapid Discovery.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
X1 Social Discovery, launched in October 2011, is basically like EnCase 
or FTK for social media and website collection. It is a desktop 
application specifically designed for computer investigators and legal 
professionals that we believe is the clear market leader in its class. 
X1 Social Discovery’s two core benefits are scalability and 
defensibility. It can collect tens of thousands of social media items in
 a few hours and up to millions in a few days, and then instantly search
 and filter those items with the patented X1 fast-as-you-type indexed 
search. X1 Social Discovery is very defensible as we are establishing a 
chain of custody with case management, evidence segregation, logging, 
and MD5 hashing of all collected items. Also, social media sites are 
accessed read-only, which is important as visiting a live Facebook page 
can easily cause changes to the page and its metadata. Finally, we 
collect all available metadata on social media sites. A Facebook item 
alone has over two dozen unique metadata fields and we preserve and 
collect all of them.&lt;br /&gt;
&lt;br /&gt;
Our other product, X1 Rapid Discovery is a proven, and now with the 
release of version 4, a truly cloud-deployable, eDiscovery and 
enterprise search solution that enables users to quickly identify, 
search, and collect distributed data wherever it resides in the IaaS 
cloud or within the enterprise. Just this past week we were the first 
eDiscovery company accepted into the Amazon Web Services (AWS) Solution 
Provider program. Importantly, its a non-appliance software solution 
that is very easy to install and configure. So in addition to the cloud,
 X1 Rapid Discovery is quickly deployed in the field on the 
investigator’s own hardware to collect data from servers and/or to 
index, cull and search through up to terabytes of collected data...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.forensicfocus.com/c/aid=44/interviews/2012/john-patzakis-founder-and-ceo-of-x1-discovery/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-4962882442522503830?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=7LQCK20bxJQ:MnLTVgRi3pU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=7LQCK20bxJQ:MnLTVgRi3pU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=7LQCK20bxJQ:MnLTVgRi3pU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=7LQCK20bxJQ:MnLTVgRi3pU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=7LQCK20bxJQ:MnLTVgRi3pU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=7LQCK20bxJQ:MnLTVgRi3pU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=7LQCK20bxJQ:MnLTVgRi3pU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=7LQCK20bxJQ:MnLTVgRi3pU:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=7LQCK20bxJQ:MnLTVgRi3pU:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=7LQCK20bxJQ:MnLTVgRi3pU:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=7LQCK20bxJQ:MnLTVgRi3pU:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/05/interview-with-john-patzakis-founder.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-808137412104427824</guid><pubDate>Tue, 15 May 2012 11:52:00 +0000</pubDate><atom:updated>2012-05-15T04:52:19.255-07:00</atom:updated><title>Interview with Noreen Tehrani, Applied Trauma Psychologist, NTA</title><description>&lt;a href="http://www.forensicfocus.com/uploads/pro_news/1337077523.4267.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://www.forensicfocus.com/uploads/pro_news/1337077523.4267.jpg" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Can you tell us something about your background and why you decided to work in the field of applied trauma psychology?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
I have had a very mixed career; I have worked in medical research, as a 
retail operations director, property development, Head of a counselling 
service and running my own company.  I think that the fact that I have 
had lots of experience doing different things has been really helpful to
 me.  Although I love research, at heart I am a practitioner and enjoy 
working with people and organisations to help them to have happy and 
healthy lives.&lt;br /&gt;
&lt;br /&gt;
I don’t think that I set out to be an applied trauma psychologist – it 
was just that the work was interesting and I could see that it helped 
people deal with difficult issues.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Tell us more about applied trauma psychology - what does your work involve and who do you aim to help?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
I work with lots of different organisations and kinds of people.  My 
main areas of expertise are in psychological trauma, bullying and 
harassment and psychological rehabilitation.  I have worked with victims
 of major incidents such as 9/11 and the 7/7 bombings as well as natural
 disasters, transport deaths, rapes and other crimes.  My goal is to 
help organisations prepare for crisis and disasters by training and 
preparing their employees and when a crisis occurs to help the 
organisation to deal with it to limit the damage caused to the 
workforce.  I have developed a number of psychological tools which help 
people to recover from stress, burnout and psychological trauma.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;What experience have you had working with digital forensics professionals?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
The first time I worked with digital forensic professionals was around 
ten years ago.  A commercial forensics organisation had taken over some 
work on Operation Ore and the young forensic examiners were having 
problems in dealing with the impact of the images they were assessing.  I
 later became involved in supporting other forensic examiners who were 
working in Eastern Europe where they felt that they were in very 
threatening working environments with little support.  More recently I 
have become more involved with law enforcement officers working with 
child abuse. This is a really interesting area of work and I find that 
the people involved in this work are really dedicated and keen to push 
the boundaries of their knowledge of computer forensics to the limits.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;What are the short and long term effects
 of working with the kind of disturbing material which digital forensics
 examiners often encounter in their work?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
I think that it is relatively easy to see that some people will never be
 able to deal with the distressing images, sounds and dialogue that are 
part of the examiners world.  Some people fail within the first few days
 of being exposed to the material.  However, perhaps more difficult is 
the slow grinding down of the digital examiner's resilience which can 
happen over months or years.  People who have handled this kind of work 
may suddenly find that they are unable to deal with it any more.  I 
think that most people have a “shelf-life” for dealing with the most 
distressing material and need to take a break.  The initial reaction to 
distressing material is the shock and disgust it causes, the fact that 
people will do things that most of us could never imagine. This is 
particularly distressing when the victim is a child.  The real problems 
relate to the trauma reactions that this shock can create.  The way our 
brains work is to try to protect us from anything that could cause harm.
  The common response to a traumatic exposure is to a) try to avoid 
further exposure b) become hyper alert or aroused to the material or 
thoughts about the material and c) to have dreams, flashbacks or 
constant thoughts about the exposure.  People can also become irritable,
 detached and start using “self-medication” (caffeine, alcohol, drugs – 
prescribed and otherwise) to handle their symptoms.  Often relationships
 suffer as normal loving relationships are affected by the impact of the
 material...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.forensicfocus.com/c/aid=43/interviews/2012/noreen-tehrani-applied-trauma-psychologist-nta/"&gt;Read more &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-808137412104427824?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=iCQk1d8f9-8:7VgDtQlpQ3g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=iCQk1d8f9-8:7VgDtQlpQ3g:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=iCQk1d8f9-8:7VgDtQlpQ3g:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=iCQk1d8f9-8:7VgDtQlpQ3g:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=iCQk1d8f9-8:7VgDtQlpQ3g:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=iCQk1d8f9-8:7VgDtQlpQ3g:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=iCQk1d8f9-8:7VgDtQlpQ3g:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=iCQk1d8f9-8:7VgDtQlpQ3g:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=iCQk1d8f9-8:7VgDtQlpQ3g:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=iCQk1d8f9-8:7VgDtQlpQ3g:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=iCQk1d8f9-8:7VgDtQlpQ3g:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/05/interview-with-noreen-tehrani-applied.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-7346314892789713684</guid><pubDate>Wed, 18 Apr 2012 10:17:00 +0000</pubDate><atom:updated>2012-04-18T03:17:27.313-07:00</atom:updated><title>Interview with Keith Cottenden, Forensic Services Director, CY4OR</title><description>&lt;a href="http://www.forensicfocus.com/uploads/pro_news/1334742720.3287.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://www.forensicfocus.com/uploads/pro_news/1334742720.3287.jpg" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Can you tell us something about your background and how you became involved in digital forensics?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
I spent 22 years in the Royal Air Force Police specialising as a Counter
 Intelligence and Information Technology Security investigator; 
supporting criminal and security investigations by the examination of 
recovered computer media, using recognised forensic techniques. I have 
over twenty years experience of carrying out computer audits and 
investigating incidents of computer misuse, virus attacks, hacking and 
loss &amp;amp; theft of data. I have been in the private sector, 
specialising in digital forensics, for the last 8 years and have worked 
on behalf of law enforcement agencies, solicitors and corporate clients 
on a variety of UK based and international cases.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What services does &lt;a class="postlink" href="http://www.cy4or.co.uk/" rel="nofollow" target="_blank" title="http://www.cy4or.co.uk"&gt;CY4OR&lt;/a&gt; offer?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
CY4OR is recognised as an industry leader in the investigation of 
serious and complex crime, and civil litigation cases.  We have 
extensive experience in conducting investigation on a broad range of 
digital media including computers, mobile devices and audio and visual 
analysis.  We compliment our forensic offering with full eDisclosure, 
cell site analysis, data recovery, data destruction, vulnerability 
assessment and penetration testing services. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;What is your own role?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
I am responsible for directing all investigation and consultancy 
services; accountable to the board for all operational and technical 
aspects of the business.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;Tell us more about CY4OR's growing focus
 on eDisclosure and eDiscovery. How important have those services become
 compared to "traditional" computer forensics?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
eDisclosure was a natural progression from digital forensics for CY4OR. 
 Both disciplines involve handling data in a manner that ensures 
preservation and interpretation.  We have moved with the industry and as
 litigation and regulatory pressures are now a fact of life for many 
organisations, as well as dealing with an ever increasing amount of 
electronic data, edisclosure is now becoming the norm in many cases...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.forensicfocus.com/c/aid=42/interviews/2012/keith-cottenden-forensic-services-director-cy4or/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-7346314892789713684?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9nYFEd0sEls:No1VKOUzZ6I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9nYFEd0sEls:No1VKOUzZ6I:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9nYFEd0sEls:No1VKOUzZ6I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=9nYFEd0sEls:No1VKOUzZ6I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9nYFEd0sEls:No1VKOUzZ6I:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9nYFEd0sEls:No1VKOUzZ6I:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=9nYFEd0sEls:No1VKOUzZ6I:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9nYFEd0sEls:No1VKOUzZ6I:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9nYFEd0sEls:No1VKOUzZ6I:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9nYFEd0sEls:No1VKOUzZ6I:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=9nYFEd0sEls:No1VKOUzZ6I:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/04/interview-with-keith-cottenden-forensic.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2686262440749954994</guid><pubDate>Fri, 13 Apr 2012 10:17:00 +0000</pubDate><atom:updated>2012-04-13T03:17:22.674-07:00</atom:updated><title>Exploded Car for Digital Forensics Students Tutorial</title><description>University forensics students sift through exploded car to find digital data for use in mock trial (YouTube Video)&lt;br /&gt;
&lt;br /&gt;
&lt;iframe allowfullscreen="" frameborder="0" height="315" src="http://www.youtube.com/embed/x4oRotwAukY" width="560"&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-2686262440749954994?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NqNafQExksI:S7ciAcgaHIk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NqNafQExksI:S7ciAcgaHIk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NqNafQExksI:S7ciAcgaHIk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=NqNafQExksI:S7ciAcgaHIk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NqNafQExksI:S7ciAcgaHIk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NqNafQExksI:S7ciAcgaHIk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=NqNafQExksI:S7ciAcgaHIk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NqNafQExksI:S7ciAcgaHIk:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NqNafQExksI:S7ciAcgaHIk:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NqNafQExksI:S7ciAcgaHIk:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=NqNafQExksI:S7ciAcgaHIk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/04/exploded-car-for-digital-forensics.html</link><author>noreply@blogger.com (admin)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://img.youtube.com/vi/x4oRotwAukY/default.jpg" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-9018439243930138166</guid><pubDate>Tue, 03 Apr 2012 11:08:00 +0000</pubDate><atom:updated>2012-04-03T04:08:25.342-07:00</atom:updated><title>Overcoming Potential Legal Challenges to the Authentication of Social Media Evidence</title><description>Social media evidence is highly relevant to most legal disputes and 
broadly discoverable, but challenges lie in evidentiary authentication 
without best practices technology and processes. This whitepaper 
examines these challenges faced by eDiscovery practitioners and 
investigators and illustrates best practices for collection, 
preservation, search and production of social media data. Also 
highlighted in this paper are examples of numerous unique metadata 
fields for individual social media items that provide important 
information to establish authenticity, if properly collected and 
preserved...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2012/04/02/overcoming-potential-legal-challenges-to-the-authentication-of-social-media-evidence/"&gt;Read more &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-9018439243930138166?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=-6ZU4NAksnI:xhwtkhc0-m4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=-6ZU4NAksnI:xhwtkhc0-m4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=-6ZU4NAksnI:xhwtkhc0-m4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=-6ZU4NAksnI:xhwtkhc0-m4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=-6ZU4NAksnI:xhwtkhc0-m4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=-6ZU4NAksnI:xhwtkhc0-m4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=-6ZU4NAksnI:xhwtkhc0-m4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=-6ZU4NAksnI:xhwtkhc0-m4:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=-6ZU4NAksnI:xhwtkhc0-m4:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=-6ZU4NAksnI:xhwtkhc0-m4:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=-6ZU4NAksnI:xhwtkhc0-m4:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/04/overcoming-potential-legal-challenges.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-7129191187194634940</guid><pubDate>Wed, 29 Feb 2012 23:34:00 +0000</pubDate><atom:updated>2012-02-29T15:34:28.725-08:00</atom:updated><title>viaForensics releases 10 Android YAFFS2 images</title><description>The YAFFS2 file system is widely used in Android devices, but to date 
has not been supported by the leading open source forensic toolkit, The 
Sleuth Kit, commonly known as TSK. viaForensics has undertaken 
development to integrate YAFFS2 file system support in TSK and while the
 YAFFS2 analysis tools are still in development has created and verified
 multiple YAFFS2 images for educational purposes...&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://viaforensics.com/products/tools/sleuth-kit-yaffs2/" rel="nofollow" target="_blank" title="http://viaforensics.com/products/tools/sleuth-kit-yaffs2/"&gt;More (viaforensics)&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-7129191187194634940?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SuW_cNF_rEY:kS9wfUp1Qg0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SuW_cNF_rEY:kS9wfUp1Qg0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SuW_cNF_rEY:kS9wfUp1Qg0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=SuW_cNF_rEY:kS9wfUp1Qg0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SuW_cNF_rEY:kS9wfUp1Qg0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SuW_cNF_rEY:kS9wfUp1Qg0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=SuW_cNF_rEY:kS9wfUp1Qg0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SuW_cNF_rEY:kS9wfUp1Qg0:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SuW_cNF_rEY:kS9wfUp1Qg0:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SuW_cNF_rEY:kS9wfUp1Qg0:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SuW_cNF_rEY:kS9wfUp1Qg0:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/02/viaforensics-releases-10-android-yaffs2.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-5145149360388912408</guid><pubDate>Fri, 24 Feb 2012 15:39:00 +0000</pubDate><atom:updated>2012-02-24T07:39:28.210-08:00</atom:updated><title>What is it like being a digital forensics investigator?</title><description>A little bit of fun before the weekend... &lt;br /&gt;
&lt;br /&gt;
Thanks to everyone who entered the "&lt;a href="http://www.forensicfocus.com/Forums/viewtopic/t=8752/"&gt;What is it like being a digital forensics investigator?&lt;/a&gt;" competition and congratulations to Infern0 for 
the winning entry - &lt;a href="http://www.forensicfocus.com/DF_Multimedia/page=watch/id=77/"&gt;watch the video here&lt;/a&gt;!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-5145149360388912408?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xiXdQ7Gsb_A:MLuUfL72VaQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xiXdQ7Gsb_A:MLuUfL72VaQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xiXdQ7Gsb_A:MLuUfL72VaQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=xiXdQ7Gsb_A:MLuUfL72VaQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xiXdQ7Gsb_A:MLuUfL72VaQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xiXdQ7Gsb_A:MLuUfL72VaQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=xiXdQ7Gsb_A:MLuUfL72VaQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xiXdQ7Gsb_A:MLuUfL72VaQ:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xiXdQ7Gsb_A:MLuUfL72VaQ:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xiXdQ7Gsb_A:MLuUfL72VaQ:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xiXdQ7Gsb_A:MLuUfL72VaQ:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/02/what-is-it-like-being-digital-forensics.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-3554198173947454546</guid><pubDate>Wed, 22 Feb 2012 11:07:00 +0000</pubDate><atom:updated>2012-02-22T03:07:37.500-08:00</atom:updated><title>Another Judge Rules Encryption Passphrase not Testimonial Under Fifth Amendment Analysis</title><description>&lt;i&gt;Posted by &lt;a href="http://articles.forensicfocus.com/author/barristerharri/" rel="author" title="Posts by barristerharri"&gt;barristerharri&lt;/a&gt; &lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
I previously discussed, on a bar association section blog in 2007 and 
2009, the case of In re Boucher, where a U.S. judge for the District of 
Vermont ruled that requiring a criminal defendant to produce an 
unencrypted version of his laptop’s hard-drive, which was believed to 
contain child pornography, did not constitute compelled testimonial 
communication. The circuit court appeal in Boucher was dropped, but a 
new case has surfaced in the U.S. Court for the District of Colorado, 
United States v. Fricosu.  There, a bank fraud defendant’s home was 
searched pursuant to a warrant, and a computer seized which held 
encrypted files. Further, Defendant provided evidence indicating her 
ownership computer, that she knew it was encrypted, and that it 
contained inculpatory evidence...&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2012/02/09/another-judge-rules-encryption-passphrase-not-testimonial-under-fifth-amendment-analysis/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2012/02/09/another-judge-rules-encryption-passphrase-not-testimonial-under-fifth-amendment-analysis/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-3554198173947454546?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Tl3m6plpVqo:AWhu2gWkFCY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Tl3m6plpVqo:AWhu2gWkFCY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Tl3m6plpVqo:AWhu2gWkFCY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=Tl3m6plpVqo:AWhu2gWkFCY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Tl3m6plpVqo:AWhu2gWkFCY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Tl3m6plpVqo:AWhu2gWkFCY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=Tl3m6plpVqo:AWhu2gWkFCY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Tl3m6plpVqo:AWhu2gWkFCY:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Tl3m6plpVqo:AWhu2gWkFCY:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Tl3m6plpVqo:AWhu2gWkFCY:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=Tl3m6plpVqo:AWhu2gWkFCY:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/02/another-judge-rules-encryption.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-6373484346765930086</guid><pubDate>Tue, 21 Feb 2012 13:12:00 +0000</pubDate><atom:updated>2012-02-21T05:12:03.393-08:00</atom:updated><title>Interview with Yuri Gubanov, Founder of Belkasoft</title><description>&lt;a href="http://2.bp.blogspot.com/-nkbAh2Fv6Ck/T0OYDIxiBPI/AAAAAAAAAHI/pA092U5YtTE/s1600/yuri-gubanov-200x200.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-nkbAh2Fv6Ck/T0OYDIxiBPI/AAAAAAAAAHI/pA092U5YtTE/s1600/yuri-gubanov-200x200.jpg" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Yuri is the founder of Belkasoft, an 
independent software vendor specializing in computer forensics and 
system software for the Windows and Mac OS platforms.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Yuri, can you tell us something about your background and who you are?&lt;br /&gt;
&lt;br /&gt;
I have a degree in mathematics and software engineering. I graduated 
with honors from St-Petersburg State University, Mathematical and 
Mechanical faculty. This is one of the oldest and best universities in 
the second largest city in Russia, famous for its white nights in June 
when you can even read at night being outside...&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://www.forensicfocus.com/c/aid=32/interviews/2012/yuri-gubanov-founder-belkasoft/" rel="nofollow" target="_blank" title="http://www.forensicfocus.com/c/aid=32/interviews/2012/yuri-gubanov-founder-belkasoft/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-6373484346765930086?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HRqRr0bin8I:YB_Mhd758V0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HRqRr0bin8I:YB_Mhd758V0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HRqRr0bin8I:YB_Mhd758V0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=HRqRr0bin8I:YB_Mhd758V0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HRqRr0bin8I:YB_Mhd758V0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HRqRr0bin8I:YB_Mhd758V0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=HRqRr0bin8I:YB_Mhd758V0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HRqRr0bin8I:YB_Mhd758V0:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HRqRr0bin8I:YB_Mhd758V0:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HRqRr0bin8I:YB_Mhd758V0:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=HRqRr0bin8I:YB_Mhd758V0:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/02/interview-with-yuri-gubanov-founder-of.html</link><author>noreply@blogger.com (admin)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-nkbAh2Fv6Ck/T0OYDIxiBPI/AAAAAAAAAHI/pA092U5YtTE/s72-c/yuri-gubanov-200x200.jpg" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-5628149764124747450</guid><pubDate>Mon, 13 Feb 2012 11:28:00 +0000</pubDate><atom:updated>2012-02-13T03:28:08.089-08:00</atom:updated><title>Forensic Focus site redesign</title><description>A short advance warning that I'm planning to make some changes to the site design this evening. There won't be any major changes, just a refresh to give what I hope will be a cleaner, more professional look with somewhat less clutter than we have at the moment.&lt;br /&gt;&lt;br /&gt;As a result of the above, expect the site to be offline for a few hours starting at around 7PM GMT (I'll try and keep downtime to a minimum).&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;Jamie&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-5628149764124747450?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=CL0ZGiturfk:hD5itAqLsH0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=CL0ZGiturfk:hD5itAqLsH0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=CL0ZGiturfk:hD5itAqLsH0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=CL0ZGiturfk:hD5itAqLsH0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=CL0ZGiturfk:hD5itAqLsH0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=CL0ZGiturfk:hD5itAqLsH0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=CL0ZGiturfk:hD5itAqLsH0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=CL0ZGiturfk:hD5itAqLsH0:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=CL0ZGiturfk:hD5itAqLsH0:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=CL0ZGiturfk:hD5itAqLsH0:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=CL0ZGiturfk:hD5itAqLsH0:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/02/forensic-focus-site-redesign.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-5883448360522872715</guid><pubDate>Tue, 24 Jan 2012 12:18:00 +0000</pubDate><atom:updated>2012-01-24T04:18:53.850-08:00</atom:updated><title>Harry Onderwater</title><description>A few days ago the Dutch forensics community - indeed, the wider forensics community - lost one of its founding fathers, Harry Onderwater.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://1.bp.blogspot.com/-OVo9iL3NhZM/Tx6gvKAM9-I/AAAAAAAAAFg/FxvPXQvoIIE/s1600/harry.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-OVo9iL3NhZM/Tx6gvKAM9-I/AAAAAAAAAFg/FxvPXQvoIIE/s1600/harry.jpg" /&gt;&lt;/a&gt;Having worked for many years for the Dutch police in Amsterdam, Harry then moved to the Centrale Recherche Informatie Dienst (&lt;span id="lblTitle"&gt;National Criminal Intelligence Service) where he became one of the first investigators in the newly emerging field of computer crime, building a reputation for excellence not just in the Netherlands but also further afield throughout Europe and the USA. Later in his career he became Corporate Security Manager at KPMG in the Netherlands where he also played a leading role in digital forensics.&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;It is difficult to describe Harry without resorting to cliché, but he truly was a larger than life character. Behind his imposing physical presence - which must surely have worked to his advantage in his many years on the force - lay a consummate professional and gentleman. Kind hearted, generous and possessing a wonderful sense of humour, Harry was always a joy to deal with. To the vast majority of those who met Harry through work, there is little doubt he will be remembered first and foremost as a friend rather than a colleague.&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;On a personal note, I would like to offer my sincere condolences to Harry's family and close friends. He has left us all too soon and will be deeply missed.&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;Bedankt, Harry, voor alles.&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;Jamie&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-5883448360522872715?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=ET9KKGGyRiU:YwSdgjfF004:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=ET9KKGGyRiU:YwSdgjfF004:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/01/harry-onderwater.html</link><author>noreply@blogger.com (admin)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-OVo9iL3NhZM/Tx6gvKAM9-I/AAAAAAAAAFg/FxvPXQvoIIE/s72-c/harry.jpg" height="72" width="72" /><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-7403047671448154593</guid><pubDate>Tue, 29 Nov 2011 16:01:00 +0000</pubDate><atom:updated>2011-11-29T08:01:40.137-08:00</atom:updated><title>Forensic Toolkit v3 Tips and Tricks ― Not on a Budget</title><description>by Sean L. Harrington&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-style: italic;"&gt;"A couple of weeks ago, Brian Glass 
posted a very helpful comment, Forensic Toolkit v3 Tips and Tricks — on a
 Budget.  His comment focused on how to “get close to SSD performance on
 the cheap” and he discussed the practice of partitioning a large hard 
drive, but using only the outer sectors of the platter, and frequent 
defragmentation.  In my comment, today, I want to encourage readers to 
adopt Glass’ advice, and, if you have the budget, to consider a few 
other enhancements to improve performance..."&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2011/11/23/forensic-toolkit-v3-tips-and-tricks-%E2%80%95-not-on-a-budget/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2011/11/23/forensic-toolkit-v3-tips-and-tricks-%E2%80%95-not-on-a-budget/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-7403047671448154593?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=pLLzBuKDzhc:PCi4Ydmxjf0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=pLLzBuKDzhc:PCi4Ydmxjf0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/11/forensic-toolkit-v3-tips-and-tricks-not.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-4805731595649540964</guid><pubDate>Tue, 29 Nov 2011 16:01:00 +0000</pubDate><atom:updated>2011-11-29T08:01:19.664-08:00</atom:updated><title>Is your client an attorney? Be aware of possible constraints (Part 2)</title><description>by Sean L. Harrington&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-style: italic;"&gt;"In my first post several weeks ago, I 
discussed some of the special obligations that digital forensics 
investigators may have while in the employ of a lawyer. I elaborated 
briefly on the duty to zealously guard the attorney-client privilege, to
 correctly apply the work product doctrine, and to conduct 
investigations in a way that does not compromise the integrity of the 
case or the rights, privileges, or immunities of the retaining party. In
 this second part of the series, I will explore another important factor
 for consideration by examiners: the legality of investigative 
techniques..."&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2011/11/22/is-your-client-an-attorney-be-aware-of-possible-constraints-on-your-investigation-part-2-of-a-multi-part-series/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2011/11/22/is-your-client-an-attorney-be-aware-of-possible-constraints-on-your-investigation-part-2-of-a-multi-part-series/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-4805731595649540964?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=nuaIp9beTqE:NpTCitw5CYM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=nuaIp9beTqE:NpTCitw5CYM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/11/is-your-client-attorney-be-aware-of.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-1146106822009451141</guid><pubDate>Tue, 29 Nov 2011 16:00:00 +0000</pubDate><atom:updated>2011-11-29T08:00:56.984-08:00</atom:updated><title>iPhone Tracking – from a forensic point of view</title><description>Posted by 4rensiker&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-style: italic;"&gt;"iPhoneTracking is sexy! Every mobile 
forensic suite, at least the ones dealing with iPhones, are providing it
 proudly. iPhoneTracking also has been a hot topic in the media all 
around the globe. People stated that there is a way to display every 
step of an iPhone user ever since the device got bought. Hmm...sounds 
great for all kind of investigations! Let’s see..."&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2011/11/20/iphone-tracking-from-a-forensic-point-of-view/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2011/11/20/iphone-tracking-from-a-forensic-point-of-view/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-1146106822009451141?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=_VqQHiw5Gd8:rNEfbZLM4FI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=_VqQHiw5Gd8:rNEfbZLM4FI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/11/iphone-tracking-from-forensic-point-of.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-5114270280613497869</guid><pubDate>Tue, 29 Nov 2011 16:00:00 +0000</pubDate><atom:updated>2011-11-29T08:00:35.371-08:00</atom:updated><title>Android Forensics Study of Password and Pattern Lock Protection</title><description>Posted by Oxygen Software&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-style: italic;"&gt;"Let’s see what Pattern Lock is, how to
 access, determine or even get rid of it? We’ll also speak about 
Password Lock Protection and find out what it has in common with Pattern
 Lock. And finally we’ll try to understand how these locks are related 
to forensic investigation process. Generally pattern lock is a set of 
gestures that phone user performs to unlock his smartphone when he needs
 to use it. It seems to be complicated, but actually it is not..."&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2011/11/18/android-forensics-study-of-password-and-pattern-lock-protection/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2011/11/18/android-forensics-study-of-password-and-pattern-lock-protection/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-5114270280613497869?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=pzvRLDeSAng:8XpcUHjYpXo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=pzvRLDeSAng:8XpcUHjYpXo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/11/android-forensics-study-of-password-and.html</link><author>noreply@blogger.com (admin)</author><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-8663633981843469801</guid><pubDate>Tue, 29 Nov 2011 15:59:00 +0000</pubDate><atom:updated>2011-11-29T08:00:04.971-08:00</atom:updated><title>Skype in eDiscovery</title><description>by Stuart Clarke, 7Safe&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-style: italic;"&gt;"The EDRM (Electronic Discovery 
Reference Model) is a widely accepted workflow, which guides those 
involved in eDiscovery. Typically, the identification and collection 
phases see email and common office documents harvested, but as 
technology moves forward is this enough? Many of us are experiencing a 
rise in audio discovery projects using solutions including phonetics and
 speech to text. In time this is likely to move onto rich media, in 
particular video. As a forensic analyst, I know only too well the 
variety of different data sources which are overlooked in electronic 
disclosure exercises, yet I appreciate the strong argument of 
proportionality. Nevertheless, it is relatively straightforward to 
circumvent some proportionality claims with the appropriate skill sets 
and techniques. Throughout this article I will discuss proof of concept 
solutions dealing with Skype in eDiscovery..."&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2011/11/09/skype-in-ediscovery/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2011/11/09/skype-in-ediscovery/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-8663633981843469801?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=djgw-IRNGko:_HjDWOi3AeI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=djgw-IRNGko:_HjDWOi3AeI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/11/skype-in-ediscovery.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-1322486998535877758</guid><pubDate>Tue, 29 Nov 2011 15:59:00 +0000</pubDate><atom:updated>2011-11-29T07:59:31.863-08:00</atom:updated><title>Forensic Toolkit v3 Tips and Tricks – On a budget</title><description>Posted by Brian K. Glass&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-style: italic;"&gt;"While researching FTK 3X and Oracle, 
you just recently discovered that the best configuration of your Oracle 
database would be on a solid state drive (SSD). Solid state drives give 
the maximum level of performance to Oracle databases and in turn speed 
up your FTK 3X responsiveness. You are a conscientious analyst and 
decide to try reinstalling your database on a SSD. You approach your 
boss, who is not a techno geek, and ask him to purchase a 256GB high 
performance SSD..."&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2011/11/06/forensic-toolkit-v3-tips-and-tricks-on-a-budget/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2011/11/06/forensic-toolkit-v3-tips-and-tricks-on-a-budget/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-1322486998535877758?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=SNe9B8FEwLA:hvx9bEDn3yg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=SNe9B8FEwLA:hvx9bEDn3yg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/11/forensic-toolkit-v3-tips-and-tricks-on.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2601029190217035185</guid><pubDate>Tue, 29 Nov 2011 15:58:00 +0000</pubDate><atom:updated>2011-11-29T07:58:48.201-08:00</atom:updated><title>Anonymous, what does it mean?</title><description>Posted by forens245&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-style: italic;"&gt;"Anonymous, a word which 
Merriam-Webster describes as: of unknown authorship or origin, not named
 or identified, or lacking individuality, distinction, or 
recognizability. There are some in this world that wish to remain 
anonymous, not named or identified. Sure I am one of these people, but I
 have my reasons. With the work that I do, clinging to my anonymity is 
how I keep myself safe, out of harm’s way. There are many people that 
would like to see me hang for what I’ve uncovered about them..."&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2011/11/01/anonymous/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-2601029190217035185?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=UNrD5id9Z5E:e03s0FfbA1U:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=UNrD5id9Z5E:e03s0FfbA1U:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/11/anonymous-what-does-it-mean.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-8591696364600822950</guid><pubDate>Fri, 07 Oct 2011 15:28:00 +0000</pubDate><atom:updated>2011-10-07T08:28:34.256-07:00</atom:updated><title>YouDetect – Implementing the principles of statistical classifiers and cluster analysis for the purposes of classifying illegally acquired multimedia files</title><description>&lt;div&gt;

&lt;div align="center" style="text-align: left;"&gt;
&lt;strong&gt;Author: Jonathan Murphy, 7Safe&lt;/strong&gt;&lt;/div&gt;
&lt;div align="center" style="text-align: left;"&gt;
&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;strong&gt;&lt;/strong&gt;Whilst all instances of the illegal acquisition of 
multimedia are not known, it is not possible to gain a complete loss 
value, but a loss of $12.5 billion has been suggested by the IPI. 
Continued response as a means of protecting the media companies and the 
income they receive from legal sales continues as copyright enforcement 
attempts to eradicate illegal downloading. This is forcing those who 
support the legal downloading material to invent new and more creative 
means to adapt technology to achieve an end to their means. ‘YouTube 
Downloader’ (YTD) is a proof of concept which allows the user to 
download videos (of any nature) from a number of video streaming 
websites simply by entering the URL of the video they wish to download. 
Whilst the application is specifically named after the website, 
YouTube.com, videos from many other websites can be acquired in this 
manner. The software allows the user to convert this video to a variety 
of multimedia formats including .mp3 and .avi. The individual can then 
view on these files on any supporting media device or computer. In the 
case of copyrighted material, the individual who uploaded the material 
to YouTube in the first instance, as well as the individual who then 
‘reproduced’ the material by extracting the video file have infringed on
 copyright law. As of September 2011, YTD has received approximately 85 
million downloads via software download website, ‘CNET.com’ making it 
the most commonly used tool of its type by a significant margin. Yet, 
for something which significantly assists and supports illegal 
downloading and multimedia piracy so significantly, little has been done
 to develop a suitable response...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2011/10/07/youdetect-implementing-the-principles-of-statistical-classifiers-and-cluster-analysis-for-the-purposes-of-classifying-illegally-acquired-multimedia-files-i/"&gt;Read more &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-8591696364600822950?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=1ch_BaEbyBE:y8Kb3CU_r0M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=1ch_BaEbyBE:y8Kb3CU_r0M:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/10/youdetect-implementing-principles-of.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-6214501929797589238</guid><pubDate>Fri, 07 Oct 2011 08:38:00 +0000</pubDate><atom:updated>2011-10-07T01:38:12.504-07:00</atom:updated><title>Advice for Digital Forensics Job Seekers</title><description>&lt;i&gt;by Joe Alonzo&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
You see the job advertisements posted 
on the web everyday, Digital Forensics Analyst, Internet Investigator, 
Computer Forensic Associate.  You hit the Apply Now button, often never 
hearing back from said company.&lt;br /&gt;
&lt;br /&gt;
Your background may consist of computer 
programming/IT, network security or possibly even a background in law 
enforcement.  You ask yourself, “How do I get the attention of this 
organization and get them to hire me?”&lt;br /&gt;
&lt;br /&gt;
Working for the leader in 
Computer Forensics and eDiscovery recruiting and seeing all the good and
 bad candidates have done, I can give you some great insight on how to 
get your dream job...&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2011/10/07/advice-for-digital-forensics-job-seekers/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2011/10/07/advice-for-digital-forensics-job-seekers/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-6214501929797589238?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=nHF3geT9tHI:qSChrlYyOJY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=nHF3geT9tHI:qSChrlYyOJY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/10/advice-for-digital-forensics-job.html</link><author>noreply@blogger.com (admin)</author><thr:total>3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-4072655358153339268</guid><pubDate>Tue, 04 Oct 2011 11:56:00 +0000</pubDate><atom:updated>2011-10-04T04:56:49.901-07:00</atom:updated><title>Forensic Toolkit v3 Tips and Tricks – Re-indexing a case</title><description>&lt;i&gt;by Brian K.Glass&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This is the first in a series of articles that will cover topics concerning AccessData&amp;nbsp;Forensic Toolkit (FTK)&amp;nbsp;version 3.&lt;br /&gt;
&lt;br /&gt;

So you’ve created a case in FTK 3.X / Oracle and added 20 forensic 
images of seized computers and assorted media which previously had been 
successfully processed and indexed. You’ve worked on this case for 
weeks, painstakingly searching and bookmarking thousands of keywords 
provided by Inspector R. Runner who has been investigating the Acme 
Corporation.&lt;br /&gt;
&lt;br /&gt;

Monday morning you come to work and fire up your FTK cluster, open 
your case, go to Indexed Search, type in the keywords Wile E. Coyote and
 Ka-Blam!! You get an error message saying a Search Request Error has 
occurred (Figure 1.) What happened, it was working fine on Friday?&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2011/09/30/forensic-toolkit-v3-tips-and-tricks-re-indexing-a-case/"&gt;Read more &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-4072655358153339268?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=4MVSENb1W2U:Usvl2BioUb8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=4MVSENb1W2U:Usvl2BioUb8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/10/forensic-toolkit-v3-tips-and-tricks-re.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2574137225521712991</guid><pubDate>Thu, 29 Sep 2011 12:30:00 +0000</pubDate><atom:updated>2011-09-29T05:33:53.637-07:00</atom:updated><title>Is your client an attorney? Be aware of possible constraints on your investigation. (Part 1 of a multi-part series)</title><description>&lt;i&gt;by Sean L. Harrington&lt;/i&gt; &lt;br /&gt;
&lt;br /&gt;
Significant legal and ethical challenges confront digital forensics 
investigators, for which some may not be well prepared.&amp;nbsp;Just as many 
lawyers may be confounded by technology in dealing with digital 
forensics matters, many digital forensics experts lack formal legal 
training, and are uninformed about their special obligations in the 
employ of a lawyer. These obligations include zealously guarding the 
attorney-client privilege, applying the work product doctrine, 
developing reports, exhibits, and testimony (that are both admissible 
and understandable to a lay jury or judge), and conducting their work in
 a way that does not compromise the integrity of the case or the rights,
 privileges, or immunities of the retaining party.&lt;br /&gt;
In certain situations, such as where digital forensics examiners serve as special masters (&lt;i&gt;see &lt;/i&gt;Fed.R.Civ.P. 53) or third-party neutrals (&lt;i&gt;see&lt;/i&gt; Model Rules of Prof’l Conduct R. 2.4 cmt. 1), they are regarded as officers of the court.&lt;br /&gt;
&lt;br /&gt;
The use of a third-party neutral has significant advantages. &lt;i&gt;&lt;i&gt;See, e.g.&lt;/i&gt;, &lt;/i&gt;Craig Ball,&lt;i&gt; &lt;i&gt;Neutral Examiners&lt;/i&gt;,&lt;/i&gt;
 Forensic Focus, 
http://www.forensicfocus.com/index.php?name=Content&amp;amp;pid=346. &amp;nbsp;First,
 as an officer of the court, the expert is subject to the court’s 
inherent powers, thereby providing an extra measure of accountability 
for misconduct (&lt;i&gt;e.g.,&lt;/i&gt; confidentiality breaches).&amp;nbsp; Second, a 
third-party neutral is ostensibly impartial, which impartiality 
presumptively aids in the fact-finding process and administration of 
justice. Third, the third-party neutral is aptly situated to resolve 
discovery disputes, including issues of confidentiality, relevance, and 
privilege, and, if necessary, obtain court intervention or &lt;i&gt;in camera&lt;/i&gt; review to resolve such disputes.&lt;br /&gt;
&lt;br /&gt;
But if the examiner is not appointed by the court, but rather is 
retained by a party to an adversarial proceeding, he or she is 
nevertheless obliged to ferret out the truth...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2011/09/24/is-your-client-an-attorney-be-aware-of-possible-constraints-on-your-investigation-part-1-of-a-multi-part-series/"&gt;Read more &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-2574137225521712991?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=ikTazH9zlGk:OXBV6-OTUOY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=ikTazH9zlGk:OXBV6-OTUOY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/09/is-your-client-attorney-be-aware-of.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-9134504120950719296</guid><pubDate>Thu, 22 Sep 2011 17:09:00 +0000</pubDate><atom:updated>2011-09-22T10:09:42.159-07:00</atom:updated><title>Publishing articles at Forensic Focus</title><description>Forensic Focus is always keen to publish articles, papers or blog posts 
of interest to the digital forensics community. Articles are published 
not only &lt;a class="postlink" href="http://articles.forensicfocus.com/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/"&gt;online&lt;/a&gt;
 but also included in the monthly newsletter (sent to over 12,00 
subscribers) and promoted via our homepage/RSS feed, Twitter, LinkedIn 
and Facebook accounts.&lt;br /&gt;
&lt;br /&gt;
This is an excellent way of raising your profile or promoting your blog 
and items for publication are welcome from anyone working or studying in
 the field.&lt;br /&gt;
&lt;br /&gt;
To register as an author and start publishing at Forensic Focus, please use the form at &lt;a class="postlink" href="http://articles.forensicfocus.com/contact/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/contact/"&gt;http://articles.forensicfocus.com/contact/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-9134504120950719296?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=JzrLJhSimHU:k82HbMJtsDk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=JzrLJhSimHU:k82HbMJtsDk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/09/publishing-articles-at-forensic-focus.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2554488566135674937</guid><pubDate>Mon, 19 Sep 2011 13:03:00 +0000</pubDate><atom:updated>2011-09-19T06:03:38.897-07:00</atom:updated><title>What is “good enough” information security?</title><description>&lt;i&gt;by Simon Biles&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;

I have, occasionally in the past, mentored people in (on?) 
Information Security – once for money (this is not a revenue stream that
 I’ve mastered by any stretch of the imagination!), but more often than 
not, informally and infrequently. What there is in common with most 
people who are keen, but still a bit wet behind the ears, is an 
idealistic world view where Information Security, as a totality, can be 
obtained. It sometimes seems a bit like kicking a puppy to have to break
 it to people that, irregardless of how long, how much money and how 
much technology you throw at something, it will still have 
vulnerabilities and risks. Even the proverbial “unplug it, stick it in a
 safe and throw away the key” is still vulnerable. I’ve seen “Oceans 11″
 – I know what can happen to a safe.&lt;br /&gt;
&lt;br /&gt;

The reality is what we do for a living is to make security “good 
enough” – we are risk managers, risk mitigators, risk avoidance and risk
 acceptance professionals. We know what can happen, and then we decide 
if spending £x on it is worth it. Where we go wrong, inevitably, is that
 we sometimes have absolutely &lt;em&gt;no idea&lt;/em&gt; about the value of the 
asset that we are protecting. How can you determine if a countermeasure 
or control is appropriate if you don’t know this figure? The real 
problem is that very often the business has no real idea either...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2011/09/19/what-is-good-enough-information-security/"&gt;Read more &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-2554488566135674937?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=hJxyH0V0Tz8:MqJY4mjcvZQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=hJxyH0V0Tz8:MqJY4mjcvZQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/09/what-is-good-enough-information.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-1836510284438143775</guid><pubDate>Wed, 24 Aug 2011 13:20:00 +0000</pubDate><atom:updated>2011-08-24T06:22:09.877-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">mobile forensics</category><title>Obtaining Information from Mobile Devices in Criminal Investigations</title><description>&lt;p style="font-style: italic;"&gt;by David W. Bennett&lt;/p&gt;&lt;p&gt;Mobile device forensics is the process of recovering digital evidence  from a mobile device under forensically sound conditions and utilizing  acceptable methods. Forensically sound is a term used in the digital  forensics community to justify the use of a particular technology or  methodology. Many practitioners use the term to describe the  capabilities of a piece of software or forensic analysis approach  (McKemmish, 3). Mobile devices vary in design and manufacturer. They are  continually evolving as existing technologies progress and new  technologies are introduced. It is important for forensics investigators  to develop an understanding of the working components of a mobile  device and the appropriate tasks to perform when they deal with them on a  forensic basis. Knowledge of the various types of mobile devices and  the features they possess is an important aspect of gathering  information for a case since usage logs and other important data can  potentially be acquired using forensics toolkits. &lt;/p&gt; &lt;p&gt;Mobile device forensics has expanded significantly over the past few  years. Older model mobile phones could store a limited amount of data  that could be easily obtained by the forensics investigator. With the  development of the smartphone, a significant amount of information can  still be retrieved from the device by a forensics expert; however the  techniques to gather this information have become increasingly  complicated...&lt;/p&gt;&lt;p&gt;Read more at &lt;a href="http://articles.forensicfocus.com/2011/08/22/the-challenges-facing-computer-forensics-investigators-in-obtaining-information-from-mobile-devices-for-use-in-criminal-investigations/"&gt;http://articles.forensicfocus.com/2011/08/22/the-challenges-facing-computer-forensics-investigators-in-obtaining-information-from-mobile-devices-for-use-in-criminal-investigations/&lt;/a&gt;
&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-1836510284438143775?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=nqupH5E00G4:eRDzN8f3PlU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=nqupH5E00G4:eRDzN8f3PlU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/08/obtaining-information-from-mobile.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item></channel></rss>

