Mobile Phone Forensics: ios Hotspot Logs?
Just looking at my phone there are 3 ways for a device to connect to the 'hotspot' phone, WiFi, Bluetooth and via USB (assuming a computer wants to use the iPhone connection). Have you checked the...
View ArticleGeneral Discussion: Lost folders/files on OS HDD
Hi, The working image of HDD will obviously be in E01 file format. So, I would suggest you to use E01 file viewer.This type of tool provides you the facility to explore all the file ,which you are...
View ArticleMobile Phone Forensics: Nokia Lumia 610
Hi I JTAG'd a Nokia Lumia 520 (Win and ran into similar problems. I fired the BIN file into Recover My Files and selected recover drive. Recover my files mapped all partitions and I was able to get at...
View ArticleDigital Forensics Job Vacancies: Cyber Crime Investigator - Bristol
Our client is looking for a Cyber Crime Investigator on the South West Regional Cyber Crime Unit you’ll be in pole position to support the effective investigation of the most serious types of internet...
View ArticleDigital Forensics Job Vacancies: Forensic/ Incident Response Specialist - London
Our client is looking for a Forensic / Incident Response Specialist for their office in London Responsible for conducting and owning cyber forensic investigations in support of external hacking...
View ArticleForensic Software: [Tool] Autopsy 3.1 Released - Parallel Pipelines and Android
BasisTech wrote: It probably makes sense to get some more details on your environment in order to help you, but I would suggest continuing the conversation on the dedicated forum for Autopsy support....
View ArticleGeneral Discussion: Mailbox Collection from Office 365
There is a 'Litigation Hold' option in the Office365 Exchange settings under Administration. Hit that first.
View ArticleGeneral Discussion: Bootable Imaging distros
marcyu wrote: You're not reading properly - the live cd is read only (you can't write to it). The evidentiary disk is read only (you can't write to it) when using a hardware write blocker. You can't...
View ArticleMobile Phone Forensics: JPEG carving/identifying/recovering
Relying on 1 byte value here sounds like a big gamble. Why not use alternative techniques here like photo dna [http://en.wikipedia.org/wiki/PhotoDNA]?
View ArticleMobile Phone Forensics: Another tool?
Just learned about this ability today. Not sure how long it's been around but it may provide some usefulness prior to an exam, no? https://www.icloud.com/activationlock/
View ArticleGeneral Discussion: Zapper investigations (sales suppression software)
Hidden executable file, which can also reside on external media, leaving no traces in OS. It would simply modify database, but it has to be customised!! That's not a problem for any skilled programmer,...
View ArticleGeneral Discussion: Bootable Imaging distros
Using a bootable distro on a USB thumb drive or CD/ DVD can destroy the stored bitlocker key (if used) in the TPM chip. Better to drag the HDD out and use it on a write blocker. If a notebook, like a...
View ArticleGeneral Discussion: Lost folders/files on OS HDD
sn0wstorm wrote: Jaclaz, This is why I'm just as confused as you. In all my experience I have never encountered something like this. There is no prompt to 'initialize' the disk, the disk shows up in...
View ArticleMobile Phone Forensics: JPEG carving/identifying/recovering
impulse wrote: 1.7.4 is in beta. I have sent you a PM with a link so that you can test it now on the modified headers. Got it and replied. <img src="images/smiles/icon_smile.gif" alt="Smile"...
View ArticleGeneral Discussion: Bootable Imaging distros
thefuf wrote: And if another consultant successfully demonstrates design flaws in your tool that result in missing / corrupted evidence? It could be, but as I said it depends on how you weight the...
View ArticleMobile Phone Forensics: ios Hotspot Logs?
I have just completed adding a binary PList viewer to my new Forensic Browser for SQLite. Testing has shown that IOS devices often use Binary Plists embedded as blobs within sqlite databases - this...
View ArticleDigital Forensics Job Vacancies: SAP Analyst Senior - Ernst & Young (EY) -...
SAP Analyst Senior - Forensic Technology and Discovery Services / Zürich Everyone has their favorite spot – somewhere to think things through, get to grips with exciting tasks and make a difference. At...
View ArticleMobile Phone Forensics: Nokia Lumia 610
Got the CommsBackup file which as you say does have messages so at lease I could use that to build up a picture of the SMS, although there must be a database viewer for it since the phone can interpret...
View ArticleMobile Phone Forensics: Turkcell Default PIN
No idea on the PIN, but could you use the PUK from here? https://www.turkcell.com.tr/yardim/yardim-araclari/puk-sorgulama
View ArticleGeneral Discussion: Bootable Imaging distros
jaclaz wrote: Which means (as said as I read it): I am holding back from doing something that I would like to do because I am afraid that it will have bad consequences, thus I will continue using the...
View Article