Digital Forensics Now

Heather Charpentier & Alexis "Brigs" Brignoni

A podcast by digital forensics examiners for digital forensics examiners. Hear about the latest news in digital forensics and learn from researcher interviews with field memes sprinkled in.

read less
TechnologyTechnology

Episodes

Balancing Act: Trials, Training, and the Future of Digital Forensics
4d ago
Balancing Act: Trials, Training, and the Future of Digital Forensics
Send us a textRecognizing excellence is key in our community, and we spotlight the SANS Difference Maker Awards and Cellebrite Summit Digital Justice Awards. Discover why it’s crucial to nominate your peers and learn about the newly opened registration for IACIS 2025 training classes, featuring must-attend courses like Advanced Mobile Device Forensics. While highlighting a recent article by Brett Shavers, we stress the significance of continuous education and community acknowledgment in helping digital forensics professionals grow and excel.Our conversation delves into the technical challenges of iOS Telegram data analysis and the development of tools like Kathryn Hedley's Parse USBs script. We shed light on the importance of peer reviews and cognitive bias in forensics. This episode is a deep dive into the intricacies of digital forensics, education, and the community that drives it forward.Notes:SANS Difference Maker Awards https://www.sans.org/about/awards/difference-makers/Cellebrite Summit Digital Justice awardshttps://cellebrite.com/en/c2c-summit-digital-justice-awards/IACIS 2025 Traininghttps://iacis.com/training/Belkasoft - iOS Telegram Acquisition and Database Analysis https://belkasoft.com/ios-telegram-forensics-acquisition-and-database-analysisKathryn Hedley parseusbs scripthttps://www.khyrenz.com/post/automated-usb-artefact-parsing-from-the-registryhttps://github.com/khyrenz/parseusbsCracking OneDrives Personal Vault -Brian Maloneyhttps://malwaremaloney.blogspot.com/2024/09/cracking-onedrives-personal-vault.htmlhttps://github.com/Beercow/Personal-Vault-BEKBrett Shavers New Article - Today, today I ranthttps://www.linkedin.com/pulse/today-i-rant-dfir-training-brett-shavers--pij4c/Lionel Notari Logs of the Weekhttps://www.ios-unifiedlogs.com/unifiedlogoftheweek
AI as a Report Writing Tool: Accuracy Enhancing or Recollection Poisoning?
Aug 30 2024
AI as a Report Writing Tool: Accuracy Enhancing or Recollection Poisoning?
Send us a textWhat's the real impact of AI on law enforcement documentation? Can digital forensics tools truly revolutionize our investigative processes? These are just some of the provocative questions we tackle in our season two premiere of Digital Forensics Now! Join us as we celebrate our one-year anniversary with reflections on the past year, exciting updates, and plans for the future. The episode takes a deep dive into the ethical and practical implications of AI in law enforcement, sparked by a recent AP News article on police officers using AI chatbots for writing crime reports. We express our skepticism about AI's accuracy and discuss the vital need for human oversight. Examining AI’s influence on officers' recollection of events, this episode scrutinizes the potential pitfalls and ethical concerns associated with AI in policing. We also humorously critique some AI-generated descriptions of our podcast, shedding light on AI's current limitations and biases.Don't forget to vote for your favorite difference makers with the SANS Difference Maker Awards!In the latter part of the show, we shine a spotlight on Recuperabit, a forensic file system reconstruction tool, and Lionel Notari's invaluable contributions on iOS log files. We tackle the challenges of modifying third-party tools and discuss the broader ethical concerns of reverse engineering. As we wrap up, we celebrate our anniversary by announcing the winners of our prize draw and featuring the "Meme of the Week," which humorously highlights the financial struggles in our field. Tune in for an informative and engaging episode!Notes-Local Storage and Session Storage in Mozilla FireFox Part 1https://www.cclsolutionsgroup.com/post/local-storage-and-session-storage-in-mozilla-firefox-part-1SANS Difference Maker Awardshttps://www.sans.org/about/awards/difference-makers/Police officers are starting to use AI chatbots to write crime reports. Will they hold up in court?https://apnews.com/article/ai-writes-police-reports-axon-body-cameras-chatgpt-a24d1502b53faae4be0dac069243f418Magnet Forensics acquires Medex Forensicshttps://www.magnetforensics.com/news/magnet-forensics-acquires-medex-forensics-strengthening-video-evidence-integrity-with-detection-of-deepfakes-and-generative-ai/RecuperaBit Forensic File System Reconstructionhttps://www.forensicfocus.com/interviews/andrea-lazzarotto-digital-forensics-consultant-and-developer/https://github.com/Lazza/RecuperaBitThe Logs of the Weekhttps://www.ios-unifiedlogs.com/unifiedlogoftheweek
Bird Cameras and Forensic Insights from New Zealand
Aug 9 2024
Bird Cameras and Forensic Insights from New Zealand
Send us a text(THIS IS WHAT AN AI GENERATED DESCRIPTION WITH NO HUMAN CORRECTIONS WILL PROVIDE FOR YOU! SO NATURALLY WE HAD TO KEEP IT HAHA!)What happens when a digital forensics expert sets up a podcast studio in a cupboard under the stairs and a co-host becomes a modern-day Snow White with her Bird Buddy camera? You get a lively and engaging episode of the Digital Forensics Now podcast! Alexis Brignoni, aka Briggs, and Heather Charpentier kick off this special episode with humor and camaraderie, sharing personal anecdotes and giving shout outs to their devoted listeners like Adam and Kevin. Plus, we nod to fellow podcaster Justin Tolman for his enlightening episodes on forensic technology, including a riveting discussion on AI and legal standards with Brandon Epstein.Ever wondered how driving on the opposite side of the road or discovering local flavors like Vegemite could become part of a professional journey? This episode takes you on an entertaining trip to New Zealand, where Alexis recounts his experiences teaching at a New Zealand Customs event alongside experts like Jung Son and Mario Merendon. From navigating tiny light switches to marveling at Auckland’s architectural wonders, this chapter is filled with both professional insights and delightful cultural encounters. The rooftop bar with waist-high glass bumps offering views into the train station below is a highlight not to be missed!For our tech-savvy listeners, we dive deep into the world of digital forensics tools and training. We discuss the significance of volunteering for IACIS, troubleshoot  Magnet Axiom software, and outline upcoming training events like the SANS Community Learning Day in Miami. We also explore the practicalities of running Python scripts, showcasing a new tool called Mister Skinnylegs, caution against over-reliance on AI, and stress the importance of fundamental knowledge in digital forensics. From iOS tool updates and Metadata Forensics to sourcing forensic-related blogs, this episode is packed with valuable insights to enhance your forensic expertise.Notes:DFIRCON xLEAPPhttps://www.sans.org/mlp/dfircon-miami-agenda/CCL Solutions Group - Mister Skinnylegshttps://github.com/cclgroupltd/mister-skinnylegsiOS 17- The “Forever” Setting That Isn’t… Or Is It?https://smarterforensics.com/2024/08/ios-17-the-forever-setting-that-isnt-or-is-it/Identity Lookup Servicehttps://djangofaiola.blogspot.com/2024/08/identity-lookup-service.html
Due Diligence, Password Cracking & New Tool Features
Jul 12 2024
Due Diligence, Password Cracking & New Tool Features
Send us a textWelcome back to another episode of the Digital Forensics Now podcast! In this episode, we explore the critical need for continuous learning in the field, discuss fascinating forensic tools, showcase UFADE with its new chat capture feature, and engage in a spirited debate on the value of certifications. Get ready to expand your knowledge and stay at the forefront of this ever-evolving industry.We begin by discussing the intricacies of unconscious and conscious incompetence as outlined in Brett Shavers new article. The episode continues with a detailed demonstration of UFADE, created by Christian Peter highlighting its user-friendly interface and the new chat capture feature. The hosts walk you through the tool's capabilities, showcasing its accessibility and usefulness in digital forensics investigations. From breaking Windows logon passwords using a Raspberry Pi Zero W to exploring the distinction between exploratory and explanatory data analysis, this segment offers a wealth of knowledge and practical insights. We also touch on the value of certifications, sparking a lively debate that challenges conventional wisdom and invites listeners to question the true measure of expertise in the tech industry. Get ready to be engaged in this thought-provoking episode.Notes-DFIR Competence: Are you Truly Skilled or Just Fooling Yourself?https://www.dfir.training/blog/dfir-competence-are-you-truly-skilled-or-just-fooling-yourselfOxygen Forensics Call for Speakers at the 2024 International User Summithttps://oxygenforensics.com/en/call-for-speakers-user-summit/UFADE Updateshttps://github.com/prosch88/UFADEP4WNP1 Buildhttps://lush-seeder-8ab.notion.site/P4WNP1-Build-54ffcdbe7cdf4e74b47861e9bd80f857SANS Webcast Serieshttps://www.sans.org/webcasts/demystifying-data-conversion-binary-hexadecimal-decimal-ascii/Bitlocker on by Default Windows 11https://www.tomshardware.com/software/windows/windows-11-24h2-will-enable-bitlocker-encryption-for-everyone-happens-on-both-clean-installs-and-reinstallsChatGPT https://www.sciencedirect.com/science/article/pii/S2666281724001252?dgcid=author
Microsoft recall of Recall & all of the latest Digital Forensic News!
Jun 13 2024
Microsoft recall of Recall & all of the latest Digital Forensic News!
Send us a textJoin us as we recount our recent travels to Argentina and the Techno Security & Digital Forensics conference. We'll share the highlights of our trips before diving into the core content.What could possibly go wrong with a feature designed for user convenience? We'll scrutinize Microsoft's controversial "Recall" feature, exploring its significant privacy concerns and implications for digital forensics. From unencrypted data to automatic opt-ins, we speculate on the potential user backlash. We'll also dive into the latest tech updates, including CCL Solutions Group's enhancements to the Rabbit Hole tool and how these advancements can revolutionize data analysis processes.Discover the capabilities of VFC from MD5 and the latest tools for examining data from platforms like Snapchat and Facebook. We'll introduce new and updated blogs, innovative Python scripts, and the latest additions to the LEAPPS in this packed episode. Stick around for an insightful discussion and a sneak peek at what's coming in future episodes.Notes- Rabbit Hole Updates and SQLite Blog/Cheatsheethttps://vimeo.com/948752153https://www.cclsolutionsgroup.com/post/time-travelling-with-sqlite-journals-and-walhttps://vimeo.com/953570512https://cdn.prod.website-files.com/5f02f2c93eab87a6ea84e2f3/665ed5e6ec5ef877d9d74dd2_sqlite-journal-cheatsheet.pdfCopilot+ Recall disaster & Forensic Applications of Microsoft Recall https://doublepulsar.com/recall-stealing-everything-youve-ever-typed-or-viewed-on-your-own-windows-pc-is-now-possible-da3e12e9465ehttps://cybercx.com.au/blog/forensic-applications-of-microsoft-recall/Rising Star Jeremy McBroomhttps://yeahihaveaquestion.com/Analysis of Browser Artefacts from File Sharing Serviceshttps://us5.campaign-archive.com/?u=a5a2a1131e612711f02b96e2c&id=9555c3f865https://github.com/cclgroupltd/ccl_chromium_readerSQLite Freelist Page Checkerhttps://github.com/SpyderForensics/SQLite_ForensicsForensics StartMe Pagehttps://start.me/p/q6mw4Q/forensics?locale=en
Android Security, Market Acquisitions, Research, Tools & More Tools!
May 16 2024
Android Security, Market Acquisitions, Research, Tools & More Tools!
Send us a textJoin us for an engaging session where we'll recap recent events and activities before diving into the latest research, cutting-edge tools, and exciting updates!Tune in as we explore groundbreaking research conducted by emerging stars in the DFIR community. We'll delve into the testing of data stored in iOS Unified Logs, focusing on driving and motion states—this is sure to be fascinating. Discover the newly documented multi-user/multi-account functionality, such as Samsung's Dual Messenger, uncovered by a newcomer to digital forensics. Stay informed about enhancements and new capabilities for tools like UFADE.We'll also ponder the implications of significant market acquisitions, such as Thoma Bravo's, and discuss their potential impact on the digital forensics field.Additionally, learn about Android's innovative anti-theft features designed to thwart device thieves, which will also have implications for forensic investigations.This episode is packed with insights you won't want to miss!Notes-iOS Unified Logs - Driving and Motion Stateshttps://www.ios-unifiedlogs.com/post/ios-unified-logs-drivingThoma Bravo Announces a Cash Offer to Acquire Cybersecurity Leader Darktracehttps://www.thomabravo.com/press-releases/thoma-bravo-announces-a-cash-offer-to-acquire-cybersecurity-leader-darktraceMagnet Onehttps://www.magnetforensics.com/products/magnet-one/UFADE Updateshttps://github.com/prosch88/UFADE/Android’s Theft Protection Features Keep Your Device and Data Safehttps://blog.google/products/android/android-theft-protection/CCL Updateshttps://github.com/cclgroupltd/ccl-segbBrian Hempsteads Work on the Session Applicationhttps://www.linkedin.com/posts/bhempstead_a-guide-for-session-app-sqlite-database-navigation-activity-7196877311659446272-zebuPhil Hagen YouTube Channelhttps://www.youtube.com/@PhilHagenVMware Fusion Pro: Now Available Free for Personal Usehttps://blogs.vmware.com/teamfusion/2024/05/fusion-pro-now-available-free-for-personal-use.htmlhttps://unexploredterritory.tech/074-newsflash-vmware-workstation-and-fusion-licensing-changes-did-i-hear-free/
From Disaster to Attainment: Crafting Digital Forensic Reports
Apr 11 2024
From Disaster to Attainment: Crafting Digital Forensic Reports
Send us a textNavigating the complexities of digital forensics can be daunting, but this week we've got your back with the exploration of Magnet Forensics' Axiom version 8, and its transformative Mobile View feature. As your hosts we're not just sharing tech updates; we're discussing the impact these tools have on our work and how they shape the narratives we construct. When it comes to the integrity of an investigation, the devil is in the details—and in the documentation. We delve into the craft of forensic reporting, dissecting why an analyst's narrative is just as critical as the raw data pulled from tools. From the subtleties of crafting a timeline to the nuances of articulating the relevance of each artifact, we've got the insights that will assist you on your report writing journey. Finally, join us for a celebration of the community spirit that fuels this field, illustrated by new blogs and newly supported artifacts in the LEAPPS. We also look at the growing significance of vehicle forensics in investigations. And because we all need a good chuckle, don't miss our 'meme of the week' segment. It's an episode brimming with expertise, but not without its moments of laughter because finding joy in our work is paramount. Come for the knowledge, stay for the camaraderie, and enhance your forensic acumen with us.Notes-Job Alert- Upcoming Openings at the New York State Policehttps://troopers.ny.gov/civilian-employmentCapture the FlagsHexordiahttps://www.hexordia.com/spring2024-weekly-ctf-challengeOxygenhttps://oxygenforensics.com/en/training/events/ctf-apr-19-2024/Belkasofthttps://belkasoft.com/belkactf6/infoMobile View and Copilot in Magnet Axiomhttps://www.magnetforensics.com/blog/bring-your-mobile-evidence-to-life-with-the-new-mobile-view-in-magnet-axiom/https://www.magnetforensics.com/blog/identify-deepfakes-and-quickly-surface-evidence-with-new-ai-tools-in-magnet-axiom/DeRR.p. Investigating Power Events on Samsung Deviceshttps://thebinaryhick.blog/2024/04/07/__trashed/Peer Review Checklisthttps://www.hexordia.com/blog-1-1/gc0vnvj80ogwx724ovu7avzwvjl742What's the Buz: Forensic Analysis of Buz for iOShttps://laurora4n6.wixsite.com/aurora4n6/post/what-s-the-buzWhat's New with the LEAPPS?https://www.stark4n6.com/2024/04/splitwise-on-ios.html
Apple Is At It Again, Changing Our Logicals!
Mar 29 2024
Apple Is At It Again, Changing Our Logicals!
Send us a textIn mobile forensics, with each update brings new challenges and opportunities. Join us as we dissect the latest iOS 17.4 impacts, including the nuances of SQLite databases and the advent of write-ahead logs in Advanced Logical extractions. Our episode is brimming with insights that could change the way you approach data extraction and parsing. The forensic landscape is ever-evolving, and this episode isn't shy about the hurdles we face, or the workarounds that keep us ahead. Discover how matching forensic work environments with devices' native operating systems and utilizing tools like Christian Perter's  and Lionel Notari's for Logical and Unified Log extraction can streamline your investigative processes. Building a personal brand in digital forensics isn't just about notoriety; it's about cultivating a reputation that commands respect and opens doors. This episode celebrates those who contribute to the community, from the creation of new parsers to the latest features in FTK 8, and how these actions bolster not just your standing but the entire field. We explore the unique journeys that shape our professional identities and share laughter over common forensics foibles. It's an episode that champions growth, community, and the personal touch that makes all the difference in a technical world.Notes-A Gift From Apple:https://www.msab.com/blog/apple-deleted-data-itunes-backups/UFADE Universal Forensic Apple Device Extractor:https://github.com/prosch88/UFADEiOS Unified Logs tool:https://www.ios-unifiedlogs.com/blogFTK LevelDB Support:https://www.exterro.com/ftk-product-downloadsWhat's New with the LEAPPS?https://github.com/abrignoni
Is Support on Life Support?
Mar 15 2024
Is Support on Life Support?
Send us a textUnlock the secrets of advanced forensic analysis with us! We reveal essential training classes that every digital sleuth needs to stay ahead in an ever-changing tech landscape. Sign-on to be enlightened by experts in the captivating world of data structures through Hexordia's class and IACIS's comprehensive course.  But it's not all about the classes; we're also sending a must-read book your way to sharpen that detective wit you pride yourself on. Get ready to explore the controversial yet fascinating realm of facial recognition with our introduction of Exponent Faces, a  X-Ways Forensics X-Tension. Whether it's identifying suspects or navigating the ethical minefields of biometric data, we're weighing in with all the expertise you could hope for. Finally, journey with us as we dissect the pivotal role of soft skills and community support for forensic examiners, you'll find this episode is not just about the tech—it's about the people behind the screens who make justice possible. Join us, where knowledge is power and staying updated is as crucial as the evidence itself.Notes:IACIS Advanced Mobile Device Forensicshttps://www.iacis.com/training/amdf-advanced-mobile-device-forensics/DFIR Investigative Mindset-Brett ShaversBook release March 22, 2024- 1/2 price for one week!Facial Recognition in DFIRhttps://www.apiforensics.com/blogs/announcing-exponent-faces.asphttps://abcnews.go.com/Business/controversy-illuminates-rise-facial-recognition-private-sector/story?id=96116545Google Chrome Platform Notification Analysishttps://www.sans.org/blog/google-chrome-platform-notification-analysis/The Digital Forensic Practitioner Survey (DFPulse2024)https://bit.ly/dfpulseWhat's New with the LEAPPs?https://github.com/abrignoni
Don't Strive to be Mediocre!
Mar 1 2024
Don't Strive to be Mediocre!
Send us a textEmbark on a journey through both history and the cutting-edge world of digital forensics with us as we pay homage to the brilliant Dr. Gladys West, whose work underpins the GPS technology we take for granted today. In celebration of Black History Month, we draw inspiration from Dr. Martin Luther King Jr., discussing how we can all contribute to the fight against enduring societal challenges. Our conversation is a testament to the power of empathy and action in fostering societal change, spotlighting the often overlooked breadth of achievements by historical figures like Dr. West and Dr. King.Unravel the complexities of iOS location and  Unified Log analysis through our educational talk on the recent breakthroughs highlighted by experts like Ian Whiffin and Lionel Notari. Discover the new feature from Magnet Axiom. The Animated Map Routes feature provides an additional facet for courtroom presentation. We wrap up with a deep appreciation for the significance of training and expertise in digital forensics, engaging with the thoughts presented by Shafik Punja in his 'Bullshit Hunting: Digital Forensics Edition' article. The discussion traverses the critical role of proper forensic training and tools, the ethical responsibilities that accompany our work, and the profound impact that our industry has on legal outcomes and lives. Notes-The Cyber Social Hub- Daily Digital Investigator Episodeshttps://podcast.cybersocialhub.com/Belkasoft's Free Android Forensics Classhttps://belkasoft.com/android-forensics-trainingApple Maps - Visited Location?https://www.doubleblak.com/blogPost.php?k=mapssynciOS Unified Logs - WiFi and AirPlane Modehttps://www.ios-unifiedlogs.com/post/ios-unified-logs-wifi-and-airplane-modeAnimated Map Routes in Magnet Axiomhttps://www.youtube.com/watch?v=fyPrJKLhD9k8 Log Files You Can Collect from iOS and Android Deviceshttps://www.magnetforensics.com/blog/8-log-files-you-can-collect-from-ios-and-android-devices/Candidate Examiner's and Training Programshttps://www.bullshithunting.com/p/bullshit-hunting-digital-forensicsSources of Error in Digital Forensicshttps://www.sciencedirect.com/science/article/pii/S2666281724000027
The Future: Talking to Your Digital Forensic Tools?
Feb 16 2024
The Future: Talking to Your Digital Forensic Tools?
Send us a textDiscover the intersection of digital innovation and forensic expertise as we celebrate and honor the incredible legacy of computing pioneer Mark Dean during Black History Month. With a salute to unsung heroes like Johann, who fuel the open-source tools we rely on, this episode is a tribute to the collaborative spirit that propels digital forensics forward.Peek behind the curtain of the Photos SQLite database with insights from the Forensic Scooter blog, uncovering the depths of data crucial to forensic investigations. We explore how metadata comparison can reveal content manipulation, the importance of distinguishing between cloud and device media origins, and the crafty skills required to validate findings in a world where AI is becoming a pivotal tool. This episode isn't just about the tools we use; it's about the critical thinking and validation skills necessary to ensure AI assists rather than misleads.Fasten your seatbelt as we navigate the evolving landscape of vehicle forensics and tackle the challenges posed by encryption in new vehicle modules. Reflect on how data from vehicle systems can be leveraged in accident reconstruction and criminal investigations, emphasizing the need to stay ahead of technological advancements. Wrapping up, we delve into the latest from the LEAPPs framework and the implications of Android's multi-user support, underscoring the episode's commitment to sharing knowledge that keeps the digital forensics community at the cutting edge.Notes-Black History Month Notable Contributor to Digital Forensics-Mark Deanhttps://web.eecs.utk.edu/~markdean/Device Set-up – Transferring data to new iPhone & Effects to Photos.sqlitehttps://theforensicscooter.com/2024/02/04/device-setup-transferring-data-to-new-iphone-effects-to-photos-sqlite/Dissecting the Android WiFiConfigStore.xml for Forensic Analysishttps://blog.digital-forensics.it/2024/02/dissecting-android-wificonfigstorexml.htmlAI Generated Imageryhttps://us5.campaign-archive.com/?u=a5a2a1131e612711f02b96e2c&id=81d1b025e7Magnet Idea Lab-Project Goosehttps://magnetidealab.com/projects/project-goose/Vehicle ForensicsHow to access logical files in a QNX partition-   https://www.youtube.com/watch?v=8SAZthXjT5sThe LEAPPShttps://github.com/abrignoni
All About The Latest CTFs, CFPs, C2C, & All The News For You To See
Feb 2 2024
All About The Latest CTFs, CFPs, C2C, & All The News For You To See
Send us a textEmbark on an enlightening path as we meld the celebration of Black History Month with the dynamism of mobile forensics. This episode is a tribute not only to the past but a clarion call for the future, as we honor Annie Easley, the trailblazing NASA computer scientist, while also navigating the rapidly evolving landscape of digital investigation tools. As your guides, we unravel the intricacies of open-source forensics tools, and the necessity of test devices, ensuring your knowledge remains at the forefront of technological advancements.With a constant eye on professional growth, we're excited to share information about upcoming conferences, training and opportunities to sharpen your digital forensic skills. We share our experiences, opening doors for you to learn and grow right beside us. Our conversation takes a stimulating turn as we discuss the Rabbit R1, a new AI gadget that promises to redefine app interaction and its implications for data privacy. As we dissect the nuances of AI in fingerprint analysis, we invite you to journey with us through the maze of modern forensics, where even the uniqueness of fingerprints is called into question.As we wrap up, our passion for the subject matter shines through with the introduction of cutting-edge features in mobile forensics updates, and the vital role of resource management in our field. We laugh over the meme of the week but also reflect on the serious undertones it brings to the prioritization of forensic cases. Closing the session, we express our heartfelt gratitude for the engagement and support that fuels our podcast, leaving you with an anticipation for deeper discussions and discoveries in the episodes to come. Join us, and together, let's shape the narrative of digital forensics and its rich connection to history and innovation.Notes-Honoring Annie Easley-Black History Month Feb 2024https://elective.collegeboard.org/annie-easley-computer-science-pioneerTesting and Validationhttps://www.hexordia.com/blog-1-1/unlock-rooting-pixel6ahttps://blog.d204n6.com/2020/08/setting-up-testing-lab-of-ios-and.htmlParaben Forensic Innovation Conferencehttps://pfic-conference.com/Free Android Training from Belkasofthttps://belkasoft.com/android-forensics-trainingCellebrite Case to Closure Summit and Awards https://global-c2c-summit-2024.cventevents.com/event/ec371a30-107d-4ce4-8bad-44e331148339/summaryhttps://cellebrite.com/en/c2c-summit-digital-justice-awards/Magnet Virtual Summit/Capture the Flaghttps://magnetvirtualsummit.com/https://magnetvirtualsummit.com/capture-the-flag/Rabbit R1https://www.theverge.com/2024/1/9/24030667/rabbit-r1-ai-action-model-price-release-dateAI- Fingerprints Unique or Maybe Not?https://www.cnn.com/2024/01/12/world/fingerprints-ai-based-study-scn/index.htmlLayoffs Due to AIhttps://www.theverge.com/2024/1/14/24038397/google-layoffs-just-the-beginningHidden Gem in iOS 17https://www.linkedin.com/posts/luca-cadonici-41299b4b_ios-ipados-passcode-activity-7152770642168160257-VJ7CAndroid Auto Rebootshttps://www.bleepingcomputer.com/news/security/grapheneos-frequent-android-auto-reboots-block-firmware-exploits/The LEAPPShttps://github.com/abrignoni
Insights, Insots, Inseyets!
Jan 19 2024
Insights, Insots, Inseyets!
Send us a textGet ready to navigate the complexities of digital forensics with the latest industry insights, as we shine a light on Cellebrite's recent rebranding journey. From the quirky 'EYE' twist in their new product names to the strategic significance behind the move, we've got it all covered in a dynamic discussion that promises to clarify and critique the changes afoot. Plus, we'll dive into how Cellebrite is contributing to the tireless work of child protection organizations, aligning tech advancements with noble missions.We will guide you through our thoughts relating to advertising effectiveness in the forensics domain, and why the quality work of forensic professionals trumps any single tool on the market. The art of communication from businesses about their products and the role of technology in boosting company progression is key.       The conversation turns to the exciting potential of recent password recovery innovations from Arsenal Recon's Password Sledgehammer and new support for location based and messaging applications in the LEAPPs!As we wrap up, the discussion turns to the thrilling possibilities of Android device analysis and the ever-evolving policies of giants like Google. We're not just talking about the next big thing; we're living it, breathing it, and sharing our experiences with you. So plug in, turn up the volume, and prepare for an episode that’s as informative as it is engaging.Notes:Operation Find Them All-https://abcnews-go-com.cdn.ampproject.org/c/s/abcnews.go.com/amp/Business/wireStory/cellebrite-donates-ai-investigative-tools-nonprofits-find-missing-106321858Magnet Forensics Acquires High Peaks Cyber-https://forensicfocus.com/news/magnet-forensics-acquires-high-peaks-cyber-further-bolstering-the-magnet-graykey-labs-research-team/Arsenal Password Sledgehammer-https://arsenalrecon.com/products/arsenal-image-mounter/downloadsLife360 Stark4N6-https://www.stark4n6.com/Analysis of Android Settings During a Forensic Investigation-https://blog.digital-forensics.it/2024/01/analysis-of-android-settings-during.htmlGoogle Location Data News!-https://www.forbes.com/sites/cyrusfarivar/2023/12/14/google-just-killed-geofence-warrants-police-location-data/?sh=245f8f422c86https://www.washingtonpost.com/technology/2023/12/14/google-maps-location-history/
New Year, New Tools, New Ways of Thinking!
Jan 5 2024
New Year, New Tools, New Ways of Thinking!
Send us a textEver found yourself piecing together a complex jigsaw puzzle of digital evidence? That's precisely the journey we invite you to embark on in our latest episode packed with tools, tales, and tech. We're not just talking shop; we're handing you the magnifying glass to examine the intricacies of JSON files with JSON CRACK, and introducing a  python tool to automate investigations involving Google Drive File Stream artifacts, DriveFS-sleuth.This episode is a testament to the craft of digital forensics, featuring a blog from Mattia at Zena Forensics that aides in answering the question, "Has the user ever used the XYZ application?".  As we unpack the nuances of reverse engineering and celebrate the updates to Hexordia's Evanole, we're reminded that the heart of digital forensics beats to the rhythm of relentless inquiry and meticulous method. We delve into the advanced research and exploitation methodologies With Magnet GrayKey Labs and converse about the importance of these capabilities as well as validation. This is coupled with a live demonstration involving SEGB files and the data that can be overlooked without research and the validation of multiple tools.Raise your glasses—here's to the exuberant spirit of learning and the relentless pursuit of truth that defines our community.  So, are you ready to elevate your understanding of the digital landscape and smash those New Year's resolutions? Join us, and let's make 2024 a year of 4K clarity—in forensics and beyond!Notes:JSON Crack-https://jsoncrack.com/DriveFS Sleuth — Your Ultimate Google Drive File Stream Investigator!https://amgedwageh.medium.com/drivefs-sleuth-investigating-google-drive-file-streams-disk-artifacts-0b5ea637c980https://github.com/AmgdGocha/DriveFS-SleuthAdvanced Research and Exploitation Methodologies With Magnet GRAYKEY Labshttps://www.magnetforensics.com/blog/advanced-research-and-exploitation-methodologies-with-magnet-graykey-labs/Has the user ever used the XYZ application?https://blog.digital-forensics.it/2023/12/has-user-ever-used-xyz-application-aka.htmlEvanole New Year Reveal! https://www.hexordia.com/evanolece
Christmas Miracle: Android Memory Forensics. Doing what we didn't know was possible.
Dec 15 2023
Christmas Miracle: Android Memory Forensics. Doing what we didn't know was possible.
Send us a textEver thought about the thin line between privacy and morality? Well, join us, , as we deep-dive into the ethical complexities surrounding this issue in today’s digital age. We bring to you exciting updates from a recent workshop in Panama, where enlightening exchanges with digital forensics experts from all over the world were had.Our exploration takes us through the workings of XRY and XRY Pro, as well as RAMDCoder, a game-changer in analyzing memory dumps from Android devices. We'll show you just how to navigate this tool, offering a glimpse into the future with the upcoming updates that promise to revolutionize device profiling. Intriguing, isn't it? Get ready as we take on mobile device  forensics, focusing on the Samsung Galaxy S21 Ultra, and the treasure trove of data within its RAM. Learn from our experiences, including how we recovered from missing a crucial step in the extraction process. Oooops user error strikes again!As we wrap up, we'll discuss phishing attacks and the crucial role organizations play in preventing them. We believe in the power of research and validation, especially in the digital forensics field. We’ll also share insights from Jessica Hyde of Hexordia, underscoring the importance of peer-reviewed research in our field. Get a good laugh as we humorously compare Apple to Darth Vader, highlighting the challenges they present for forensic examiners. SEGB for the WIN! This is an episode that you will not want to miss!Notes:Chat encryption: A moral responsibility or a moral abdication?https://arstechnica.com/tech-policy/2023/12/meta-defies-fbi-opposition-to-encryption-brings-e2ee-to-facebook-messenger/What makes epoch timestamps tick?https://www.cclsolutionsgroup.com/post/what-makes-epoch-timestamps-tickCheatSheet: https://assets-global.website-files.com/5f02f2c93eab87a6ea84e2f3/656da27da36e0c5cd1715d8a_EpochCheatsheet.pdfMSAB XRY:https://www.msab.com/BrowserState.db last_visited_time?https://doubleblak.com/beta/browserstateSEGB Parsers!https://github.com/cclgroupltd/ccl-segb
What To Expect When You Are Expecting a Digital Forensics Class, Two Hardware Solutions, One Neat Tool Capability For Windows, and a Partridge in a Pear Tree.
Dec 1 2023
What To Expect When You Are Expecting a Digital Forensics Class, Two Hardware Solutions, One Neat Tool Capability For Windows, and a Partridge in a Pear Tree.
Send us a textGet ready to journey into the world of digital forensics as we share our insights on the crucial art of utilizing a diverse range of tools. A single tool just won't cut it, and reliance on just one could cause you to miss out on important finds. We also give our listeners the floor, inviting you to voice your thoughts on the IACIS Advanced Mobile Device Forensics class, and the topics you'd love to see covered. How do you feel about forensic extraction tools? We dissect unique features of tools like duplicators, TX1, and Atrio, and dive into latest updates from OpenText and ArcPoint Forensics. These updates have made it possible to create Android and iOS backups using duplicators, a game changer in the field. With Atrio, we open up an intriguing discussion about their forensic triaging and AI capabilities. We discuss the role of AI in identifying CSAM and brainstorm ways to enhance the tooling. We share our own learning experiences from various classes, highlighting the absolute necessity of continual learning and outside research in this ever-evolving field.  We also explore the features and potential of Arsenal, a digital forensics tool which aids in mounting and virtualizing E01 images. The unique capabilities provided by Arsenal to bypass the password to a Windows logon screen and access DPAPI-protected data is a must try! Whether you're a seasoned expert or just dipping your toes in the water, this episode is sure to pique your interest in the vast world of digital forensics.Notes-IACIS Advanced Mobile Device Forensics (AMDF)https://iacis.com/training/amdf-advanced-mobile-device-forensics/OpenText Duplicator Updatehttps://www.youtube.com/watch?v=L3qGa7H6NBsArcPoint Forensicshttps://www.arcpointforensics.com/DFIR Diva-https://dfirdiva.com/Arsenal Recon-https://arsenalrecon.com/Hexordia Mobile Data Structure-Virtual Live Training-https://academy.cyber5w.com/courses/hexordia-mobile-data-structures-dec-2023
Vendor Transparency, Mobile Device Extractions, & Brigs Learns the Difference Between Validation and Verification
Nov 17 2023
Vendor Transparency, Mobile Device Extractions, & Brigs Learns the Difference Between Validation and Verification
Send us a text We are back with a mind-boggling conversation about our experiences, and the ever-evolving face of digital forensics. We're going to share some personal anecdotes, enlighten you about the changing UNIX epoch timestamp, and even discuss how we cope with the advancing age in this fast-paced world.In the digital world, knowledge is power. We will reveal an amazing cheat sheet from Cellebrite that will simplify your understanding of extractions and the data that they yield. We’ll also delve into the concept of tool transparency, highlighting the pros and cons that come with it. We’ll help you understand why it's crucial to be informed about known bugs in a tool, and navigate the complex process of bug reporting. We’re going to discuss why it's essential to have multiple tools in your arsenal for data validation, and how manual validation is a must when it relates to key evidence.As we wrap up, we'll talk about the implementation of ALEAPP and iLEAPP in Paraben and its capabilities to choose artifacts to report on. To add some levity, we'll also share a humorous meme that perfectly captures the essence of the repercussions of failing to validate your digital data. So, prepare to embark on a journey that’s bound to make you rethink everything you know about data extraction and tooling analysis.Notes-Scholarship Reminders-https://www.iacis.com/will-docken-scholarship/-https://www.iacis.com/womens-scholarship/-https://www.magnetforensics.com/blog/2023-magnet-forensics-scholarship-program-apply-today/Cellebrite Data Extraction CheatSheet-https://www.linkedin.com/posts/heather-mahalik-cellebrite_data-extraction-cheatsheet-activity-7125138491805462528-l5-5/-https://cellebrite.com/en/episode-23-i-beg-to-dfir-data-extractions-explained-ffs-afu-bfu-advanced-logical-digital-forensics-webinar/Paraben-https://paraben.com
Digital Forensics, Moot Court, and New Tool. Come Down the RabbitHole ™ with Us!
Nov 2 2023
Digital Forensics, Moot Court, and New Tool. Come Down the RabbitHole ™ with Us!
Send us a textCurious about how digital forensics can unlock the secrets held by your tech devices? Join us as we shine a light on RabbitHole, an ingenious tool devised by Alex Caithness of CCL Solutions Group. This episode is sure to be a revelation, as we delve into this unique amalgamation of data format viewers. The plot thickens as we, act as your guides, to dissect the complexities of the RabbitHole - reparse feature, the free form report builder, and the remarkable ability to extract data from various sources. We step away from the tech talk for a moment to underline the crucial role of Moot Court in nurturing digital forensics examiners. We debate the need for a supportive environment that allows mistakes, honing professionals in the field. We discuss the highlights of what qualities are needed to shape a great witness and throw light on two free cybersecurity courses related to expert witness testimony.Don't miss our discussion on the new additions to iLEAPP! Media events from the knowledgeC database and connecting Discord attachments to message threads. Finally we discuss  changes to Shellbag artifacts that were implemented in Windows 11 updates as outlined by 13Cubed, and the meme of the week!So, are you ready to tumble down this fascinating digital RabbitHole with us?Notes:CCL Solutions-RabbitHole-https://www.cclsolutionsgroup.com/forensic-products/rabbitholeCourtroom Testimony Trainings-CYBRARY.IT- https://cybrary.it/course/dfir-investigations-and-witness-testimonyNW3C-DF501 Expert Witness Testimony - Digital Forensic Examiners- https://www.nw3c.org/UI/CourseCatalog.htmlConnecting Discord Attachments to Message Threads-https://bluecrewforensics.com/2023/10/30/connecting-discord-attachments-threads-sdwebimage-library/13 Cubed: An Important Change to ShellBags - Windows 11 2023 Update!https://www.youtube.com/watch?v=M1nyMIu1Y18&t=4sShellbags Explorer by Eric Zimmermanhttps://ericzimmerman.github.io/#!index.md
New iOS Geolocation Artifacts, iOS Location Shenanigans, Time Zones, Do You Realm?, and The Meme Of The Week!
Oct 18 2023
New iOS Geolocation Artifacts, iOS Location Shenanigans, Time Zones, Do You Realm?, and The Meme Of The Week!
Send us a textEver wondered how to make the most of data analysis tools like iOS Spotlight Store DB and Realm Databases? We're here to share our experiences, tips, and favorite resources to help you elevate your data extraction skills. Join us, as we discuss the amazing work of Yogesh Khatri, the creator of a game-changing parser and as we guide you through the vast world of data extraction and analysis techniques.We begin our journey with iOS Spotlight Store DB, revealing the treasures hidden within and how to use Yogesh's parser to uncover its secrets. We then navigate through Realm Databases, sharing our encounters with data stores and tools for parsing extracted data. We also share our personal workflow process, granting you a peek into our data analysis strategies. But we're not done yet. Our adventure takes a detour towards Google Maps Geolocation Artifacts, where we highlight the amazing work of The Binary Hick and his research of the audio files and geolocation points related to navigation.Finally, we explore the nuanced art of analyzing timestamps and locations in images, revealing a fascinating intersection of data and intent. We share how we use Python scripts, manual offsets, and more to make data time-zone aware. Wrapping up our discussion, we emphasize the vitality of research in data analysis and the role of code in automation. So, buckle up for a thrilling ride into the mesmerizing world of data extraction and analysis. You'll come out the other side armed with fresh insights and new tools at your disposal.Notes:iOS Spotlight store.db:https://github.com/ydkhatri/spotlight_parserRealm Databases:https://www.mongodb.com/docs/realm/studio/The Binary Hick-Finding Phones with Google Maps:https://thebinaryhick.blog/2023/10/17/finding-phones-with-google-maps-part-1-android/iOS Media Adjustments:https://www.doubleblak.com/blogPosts.php?id=23