Quantcast
Channel: Forensic Focus Forums - Recent Topics
Browsing all 20110 articles
Browse latest View live

Mobile Phone Forensics: ios Hotspot Logs?

Just looking at my phone there are 3 ways for a device to connect to the 'hotspot' phone, WiFi, Bluetooth and via USB (assuming a computer wants to use the iPhone connection). Have you checked the...

View Article


General Discussion: Lost folders/files on OS HDD

Hi, The working image of HDD will obviously be in E01 file format. So, I would suggest you to use E01 file viewer.This type of tool provides you the facility to explore all the file ,which you are...

View Article


Mobile Phone Forensics: Nokia Lumia 610

Hi I JTAG'd a Nokia Lumia 520 (Win and ran into similar problems. I fired the BIN file into Recover My Files and selected recover drive. Recover my files mapped all partitions and I was able to get at...

View Article

Digital Forensics Job Vacancies: Cyber Crime Investigator - Bristol

Our client is looking for a Cyber Crime Investigator on the South West Regional Cyber Crime Unit you’ll be in pole position to support the effective investigation of the most serious types of internet...

View Article

Digital Forensics Job Vacancies: Forensic/ Incident Response Specialist - London

Our client is looking for a Forensic / Incident Response Specialist for their office in London Responsible for conducting and owning cyber forensic investigations in support of external hacking...

View Article


Forensic Software: [Tool] Autopsy 3.1 Released - Parallel Pipelines and Android

BasisTech wrote: It probably makes sense to get some more details on your environment in order to help you, but I would suggest continuing the conversation on the dedicated forum for Autopsy support....

View Article

General Discussion: Mailbox Collection from Office 365

There is a 'Litigation Hold' option in the Office365 Exchange settings under Administration. Hit that first.

View Article

General Discussion: Bootable Imaging distros

marcyu wrote: You're not reading properly - the live cd is read only (you can't write to it). The evidentiary disk is read only (you can't write to it) when using a hardware write blocker. You can't...

View Article


Mobile Phone Forensics: JPEG carving/identifying/recovering

Relying on 1 byte value here sounds like a big gamble. Why not use alternative techniques here like photo dna [http://en.wikipedia.org/wiki/PhotoDNA]?

View Article


Mobile Phone Forensics: Another tool?

Just learned about this ability today. Not sure how long it's been around but it may provide some usefulness prior to an exam, no? https://www.icloud.com/activationlock/

View Article

General Discussion: Zapper investigations (sales suppression software)

Hidden executable file, which can also reside on external media, leaving no traces in OS. It would simply modify database, but it has to be customised!! That's not a problem for any skilled programmer,...

View Article

General Discussion: Bootable Imaging distros

Using a bootable distro on a USB thumb drive or CD/ DVD can destroy the stored bitlocker key (if used) in the TPM chip. Better to drag the HDD out and use it on a write blocker. If a notebook, like a...

View Article

General Discussion: Lost folders/files on OS HDD

sn0wstorm wrote: Jaclaz, This is why I'm just as confused as you. In all my experience I have never encountered something like this. There is no prompt to 'initialize' the disk, the disk shows up in...

View Article


Mobile Phone Forensics: JPEG carving/identifying/recovering

impulse wrote: 1.7.4 is in beta. I have sent you a PM with a link so that you can test it now on the modified headers. Got it and replied. <img src="images/smiles/icon_smile.gif" alt="Smile"...

View Article

General Discussion: Bootable Imaging distros

thefuf wrote: And if another consultant successfully demonstrates design flaws in your tool that result in missing / corrupted evidence? It could be, but as I said it depends on how you weight the...

View Article


Mobile Phone Forensics: ios Hotspot Logs?

I have just completed adding a binary PList viewer to my new Forensic Browser for SQLite. Testing has shown that IOS devices often use Binary Plists embedded as blobs within sqlite databases - this...

View Article

Digital Forensics Job Vacancies: SAP Analyst Senior - Ernst & Young (EY) -...

SAP Analyst Senior - Forensic Technology and Discovery Services / Zürich Everyone has their favorite spot – somewhere to think things through, get to grips with exciting tasks and make a difference. At...

View Article


Mobile Phone Forensics: Nokia Lumia 610

Got the CommsBackup file which as you say does have messages so at lease I could use that to build up a picture of the SMS, although there must be a database viewer for it since the phone can interpret...

View Article

Mobile Phone Forensics: Turkcell Default PIN

No idea on the PIN, but could you use the PUK from here? https://www.turkcell.com.tr/yardim/yardim-araclari/puk-sorgulama

View Article

General Discussion: Bootable Imaging distros

jaclaz wrote: Which means (as said as I read it): I am holding back from doing something that I would like to do because I am afraid that it will have bad consequences, thus I will continue using the...

View Article
Browsing all 20110 articles
Browse latest View live