General Discussion: safely removing external HDD fails due to System $extend.
williamsonn wrote: jaclaz: Do yo mean that I have to enable Write Cache in each PC I will plug the HDD on, and also to always use the software USB Safely remove, and so the HDD will always be safely...
View ArticleGeneral Discussion: How to know exact hour & minute you visited a website?
Well to start with which browser are you using? More for my own curiosity, why are you trying to find this? The methods you described so far seem far from forensic.
View ArticleDigital Forensics Job Vacancies: IntaForensics - Senior Computer Analyst -...
IntaForensics have been operational since 2006 as a specialist service provider of digital forensics services. Our client base includes several large and small Police forces for whom we provide...
View ArticleDigital Forensics Job Vacancies: IntaForensics - Computer Forensic Analyst -...
IntaForensics have been operational since 2006 as a specialist service provider of digital forensics services. Our client base includes several large and small Police forces for whom we provide...
View ArticleGeneral Discussion: ExFAT vs FAT32 (deeper mechanics)
I finally got that beta out last week. So for those that want to check the ExFAT functionality, check out: www.isobuster.com/news/isobuster_3.2_beta_release_notes Usually after 2-4 weeks I release the...
View ArticleGeneral Discussion: Windows Media Player: User Hive Entries and Link Files.
I am a digital forensics student conducting a research project on the Windows artifacts left behind by using QuickTime Player. I'm using the Windows 7 OS in Bootcamp. I have located the xml document...
View ArticleGeneral Discussion: Twitter Profile capture
If you're willing to pay for it, X1 Social Discovery does a very nice job of capturing twitter content and allows for keyword searching, geo-mapping, and can create various report types. The nice part...
View ArticleGeneral Discussion: Forensic Artifacts in Facebook Apps
Hey all, First time posting. I know how to find forensic artifacts from normal Facebook activities (IM, wall posts, etc) but how would I find artifacts from Facebook apps such as Farmville or other...
View ArticleMobile Phone Forensics: Recovery from (very) damaged SIM
Is it possible to recover the data from a SIM card that was broken in pieces? The investigator has tried "reassembling" all the pieces together on a piece of Scotch Tape, and using a SIM reader to try...
View ArticleDigital Forensics Job Vacancies: Mobile Forensic Analyst - Warwickshire -...
Our Client is looking for for a Mobile Forensic Analyst to join their expanding team. They are looking for someone with excellent EnCase and FTK skills, backed by a good range of other forensic tools...
View ArticleDigital Forensics Job Vacancies: Computer Forensic Investigator,...
Thank you for your responses! This position is now now closed to new applications
View ArticleEducation and Training: Dissertation Ideas
EricZimmerman wrote: ? I fail to see the connection. Its not complicated in the least, nor is it any kind of demand or ultimatum. All I asked was to pass on my contact info. Most likely I already know...
View ArticleMobile Phone Forensics: Missing smartphone files
Hi, Do you have iTunes installed? If not install iTunes (or reinstall iTunes) To acquire an iPhone (or iPad) in EnCase 7 iTunes is required to be installed, but during acquisition NOT running. Regards
View ArticleGeneral Discussion: accessing hidden partitions
mikebentzen wrote: I have two disks. They're both bootable and run Linux. When I physically mount the disks, I can see scsi devices get added. /dev/sdb and /dev/sdc. However the partitions are not...
View ArticleGeneral Discussion: Working with mounted EDB archives
Be sure that the account you're using to run the exchange cmdlet has administrative access to the share you are exporting the PSTs to, else it won't work.
View ArticleMobile Phone Forensics: Recovery from (very) damaged SIM
Thanks guys, but I've been able to get the opinion of 2 people to which I have sent the pictures of the SIM and they both told me that it was unrecoverable.
View ArticleMobile Phone Forensics: qcc notes
I wrote about Forensic CaseNotes back in 2007 and the work of John Douglas: http://trewmte.blogspot.co.uk/2007/01/forensic-casenotes.html John, the links you originally gave are out of date. Perhaps...
View ArticleMobile Phone Forensics: Faraday / shield pro's and con's
bigjon this FF links has discussions on some pros and cons: http://www.forensicfocus.com/Forums/viewtopic/t=9890/ Do you fancy putting together a pros and cons list or table?
View ArticleMobile Phone Forensics: viaForensics AFLogical
I was wondering if anyone out there could provide me with some comments on this software. At present I only have a cellebrite, but I'm looking to expand. If you have experience with this and can...
View Article