General Discussion: Security Changes Registry Keys
EvaMendis wrote: So,I suggest you to use one of the following tools to track the changes in the registry. ... Have you actually checked and verified that those tools do detect/record changes in...
View ArticleGeneral Discussion: Zapper investigations (sales suppression software)
Does anyone have any information on investigating restoraunt or other sales supression software (aka zappers) that they could share? I realize the evidence an investigator would find would be...
View ArticleMobile Phone Forensics: manually deleted images
Some more notes re-checking FFE2 => application_segment_flashpix so this is another specific standard on top of JPEG, also see: http://www.sno.phy.queensu.ca/~phil/exiftool/TagNames/FlashPix.html...
View ArticleMobile Phone Forensics: Nokia 108
polar wrote: alex101 wrote: The option you have linked to is a JTAG cable. Use this cable with ATF (or other flasher box of your choice). You can then decode the resultant file with the forensic tool...
View ArticleMobile Phone Forensics: Does Last Access Time Stamp Update
hsteward wrote: I understand fat doesn't update the last accessed time Says who? Terry
View ArticleGeneral Discussion: graphics card memory
wQuant wrote: If you allow some speculation, there might be substantial evidence inside such a bit coin miner GPU RAM and perhaps even the keys to otherwise inaccessible wallets of interest. I am not...
View ArticleServices Required: SEEKING SUB-CONTRACTOR FOR COMPUTER & DIGITAL FORENSICS
Hi....please contact me off list, tom.devine@usdia.org We are New England based but can cover parts of NY....
View ArticleMobile Phone Forensics: Nokia 108
polar wrote: The 108 cable has USB too.You are right, my bad <img src="images/smiles/icon_redface.gif" alt="Embarassed" title="Embarassed" /> , the 108 has both, I was referring to "the JTAG...
View ArticleGeneral Discussion: Lost folders/files on OS HDD
You need to start with the partition table and manually walk it and subsequent boot sectors to find out what is going on. If you can't follow the pointers from partition to boot to NTFS MFT (or what...
View ArticleMobile Phone Forensics: manually deleted images
jamie wrote: Topic split to http://www.forensicfocus.com/Forums/viewtopic/t=12209/ as requested FYI there is some content in the thread that is related to the question from the OP, bottom line more...
View ArticleMobile Phone Forensics: JPEG carving/identifying/recovering
Apparently we got our own thread <img src="images/smiles/icon_wink.gif" alt="Wink" title="Wink" /> jaclaz wrote: If I get it right this, translated into English means "repetitions of FF value...
View ArticleMobile Phone Forensics: Are You Guys Following This Circus Sideshow? (Hernandez)
Hernandez lawyer never read cell phone search warrant (BostonGlobe) Amusing quotes from the linked article: "Before he departed, Collins said, he noted that the battery was out of the phone and the...
View ArticleEmployment and Career Issues: Moved from UK to Melbourne - Entry Level Job...
There are quite a number of firms operating forensic practices in Melbourne. The Big 4 accounting firms all have forensic practices in Melbourne as do most of the mid-tier advisory firms. A good place...
View ArticleGeneral Discussion: Who did delete a file
Hello.. Its correct every particular operating system has its own way of deleting files just you need to know ... Thanks Post more so that we could get informative knowledge..
View ArticleDigital Forensics Job Vacancies: eDiscovery Project Manager - €65-75K -...
My client, a leading, global forensic technology company, is looking for ED Project Managers to join their team in Stuttgart, Germany. contact ht@warnerscott.com for more information
View ArticleGeneral Discussion: Lost folders/files on OS HDD
sn0wstorm wrote: Yes the disk does show up in Disk Manager as a single volume and at the correct size, however because it isn't given a drive letter it doesn't show up in 'My Computer' and other tools...
View ArticleMobile Phone Forensics: manually deleted images
jaclaz wrote: Hope that now the relevant parts are easily accessible/readable. Thanks jaclaz!
View ArticleMobile Phone Forensics: JPEG carving/identifying/recovering
jaclaz wrote: Well, I am not the analyst, nor the one that writes a tool, I am simply someone passing by and trying to understand - since at first sight I notice something that seems to me "just not...
View ArticleMobile Phone Forensics: ios Hotspot Logs?
Hi Adam, Cellebrite extraction device and the physical analyzer software (to do advanced logicals). No Physical extractions available unfortunantly
View Article