General Discussion: OSINT - are there any gurus in the house?
To JHowell, Thank you very much for taking the time to provide all your answers. You are correct on the name. I just looked at the book I have from Mr Bazzell "Open Source Intelligence Techniques" and...
View ArticleGeneral Discussion: Windows 7 MBR system unable to view Windows 8 GPT HDD
Right….. so after downloading and installing the hotfix mentioned in the Microsoft KB article that you linked to jaclaz I have run fsutil again over the same image file once again mounted with a cache...
View ArticleMobile Phone Forensics: Student help : Android Anti forensic literature
Kashif, Have a look at this post: http://www.forensicfocus.com/Forums/viewtopic/t=11524/ Android phones with encrypted containers already exist. Regards MPF
View ArticleClassifieds: Logicube Forensic Falcon (FASTEST) Imager for sale (20GB pm)
Good morning Folks, In addition to the FTK Dongles for sale in the other thread. I also have a Logicube Forensic Falcon (Its an extremely fast imager) with speeds than can achieve 20 GB per min*....
View ArticleMobile Phone Forensics: using adb to extract android
So... the statement "not entirely true", is false, ergo my statement is true. <img src="images/smiles/icon_mrgreen.gif" alt="Mr. Green" title="Mr. Green" /> Zergling wrote: jhup wrote: How can...
View ArticleForensic Software: .hash files not recognized by FTK or IEF
We have just installed FTK 5.1. I am trying to use my library of hash values to help in my cases. These are all hash sets of notable images from various LE agencies and are all in the .hash format. The...
View ArticleGeneral Discussion: facebook
Good afternoon, The contact details in this article may help with filing a legal application for disclosure of registration and user specified details:...
View ArticleForensic Software: EnCase Hash conversion
I too am having an issue with this. Were you able to successfully export the .hash file as a .txt file? I exported the hash file using EnCase v7, and it gave me an output of several bin files, but none...
View ArticleForensic Software: EnScript v7 - issues with getting MD5 hash value - HELP?
Thank you for your reply! I've now had an answer via the Guidance software forum. The method has to be entry.HashValue().GetString() for it to work with the other two images. The previous method was...
View ArticleForensic Software: Multiple EnCase Dongles v7
You only need one dongle per computer. The EnCase installer installs the dongle driver and associated license manager software.
View ArticleEducation and Training: need help on University project on image file search
I did some search but somehow i still not able to find any clue about it. the Image find that my lecturer want us to find evidence shown that the someone use tightvnc this remote software to remote the...
View ArticleServices Required: photoshop forensics / ELA advice needed please
Hi Jimmy. If you message it to me I can have a look at it for you. DaveB
View ArticleGeneral Discussion: Windows 7 MBR system unable to view Windows 8 GPT HDD
Well, there you go, we can but work around these things! Will no doubt have an effect on data recovery methodology as well…... That's very clever/sneaky of the drive
View ArticleEmployment and Career Issues: Masters Degree it is then, but from whom?
Although I haven't done the course I would highly recommend the university of Glamorgan, the staff and students over there are doing some very interesting work, particularly around data recovery and...
View ArticleMobile Phone Forensics: LogMeIn Ignition
It's not any hash that I'm familiar with. Did this come out of Logmein Ignition? What's the relationship between Logmein and this?
View ArticleForensic Software: Show File Path In EnCase Report
Hello, How exactly are you creating the report in EnCase? Adam
View ArticleGeneral Discussion: Cloud Forensics - Artifacts?
research1 wrote: Understood. No simple answer. Has anyone created any advice / documentation / research on how to approach cloud examinations and common artifacts/setups to look out for? You should...
View ArticleGeneral Discussion: FTK Imager stalling --
Below is brief description of BadDrive Adapter. We have similar product for USB for reading bad USB drives/sticks via usual SATA interfase, i.e. host interface SATA, device interface USB2.0. --- EPOS...
View ArticleMobile Phone Forensics: Student help : Android Anti forensic literature
Bundle of thanks MobilePhoneForensic I already posted a reply there. Basically I want to do research in some area which has some commercial significance. Blackphone and Boeing black are using...
View ArticleForensic Software: .hash files not recognized by FTK or IEF
Thank you. Luckily I have access to a machine with EnCase v6. I was able to export them and their sitting in IEF now. FTK seems a little slower than it should on the import, but hopefully they will be...
View Article