±Forensic Focus Partners

Become an advertising partner

±Your Account


Forgotten password/username?

Site Members:

New Today: 0 Overall: 33968
New Yesterday: 6 Visitors: 150

±Follow Forensic Focus

Forensic Focus Facebook PageForensic Focus on TwitterForensic Focus LinkedIn GroupForensic Focus YouTube Channel

RSS feeds: News Forums Articles

±Latest Articles

RSS Feed Widget

±Latest Webinars





Helix 3 Enterprise

Helix 3 Enterprise
Reviewed by Jonathan Krause of Forensic Control.

Helix 3 Enterprise (H3E) is e-fense’s flagship investigation suite pitched at a similar level as EnCase Enterprise or Access Data Enterprise. It’s aimed at organisations which need to be able to carry out incident response, forensics and e-discovery functions over networks. H3E facilitates centralised incident response, imaging of drives and volatile data and also enables scans and searches of a user’s internet history and documents on any computer which has had the H3E Agent pre-installed on it. The integrity of data in transit and within the H3E database is ensured through 256-bit AES encryption.   more ...


Write Blocker Review

One of the write blockers tested
Reviewed by David Kovar of NetCerto, Inc.


Digital evidence needs to come from somewhere, right? It doesn’t appear, “forensically sound”, from out of the blue. And the phrase “forensically sound” is key – the evidence needs to be acquired in a manner that ensures that the process doesn’t modify the evidence in any manner. There are exceptions to this – cell phones and live acquisitions come to mind – but even then, the process should be minimally invasive.

The key to this acquisition process is the ubiquitous write blocker, probably the most important tool in any acquisition kit. A write blocker was my first forensics hardware purchase and I keep my collection of write blockers up to date religiously.   more ...


Digital Safety Conference, London, 19th June

Graham Brown-Martin, Digital Safety Conference
Reviewed by Jan Collie.

Cyberstalking is the new urban terror – the message rang home loud and clear at the Digital Safety Conference in London last week (Friday).

For although, in Cyberspace, no-one hears you scream, increasing numbers of people are getting off on imagining it.

The evils of instant communication – texting, live chat, social networking – were laid out in lurid detail before delegates meeting in a brick-lined space known as The Brewery, near the city’s Barbican.

Tales of horror: physical threats and psychological manipulation, poured out. The family pursued relentlessly via emails, bulletin board postings and websites dedicated to damaging their names for more than five years. The teenager who suffered Post Traumatic Stress Syndrome following a campaign of anonymous texts. The Information Age exposed in all its gory.   more ...


e-fense Live Response

e-fense Live Response
Product Information

Vendor: e-fense®
Product: Live Response®
Version: 2009 Release 3
Price: $499.95 (16GB version)

e-fense is best known for the Helix3 Incident Response and bootable Live CD. Helix3, created by forensic specialist Drew Fahey, was a donation-ware Linux LiveCD distribution designed specifically for digital forensics and based on the popular Knoppix and then Ubuntu distributions. It contained many forensic and security related tools designed to aid in the recovery and analysis of digital evidence in live and post-mortem (powered off) computer examinations. There were tools to analyze Windows and Linux file systems like Ext2/Ext3, and even the less common Reiser FS, JFS and XFS.   more ...


MacLockPick II

MacLockPick II
Reviewed by Austin W. Troxell, MSc, CISSP of Cyber Investigation Services.


In today's computing environment of tera-byte hard drives and encrypted file systems, the practice of 'pull the plug, image at the lab' is becoming impractical, if not risky. To address these and other challenges, live acquisition is gaining in popularity. Indeed, every digital forensics examiner should become proficient in the techniques of what has come to be the latest buzz-phrase in the industry: “field triage.”


To meet the needs of non-technical first-responders such as law-enforcement, parole officers, private investigators, etc., SubRosaSoft (subrosasoft.com/OSXSoftware/index.php) has introduced MacLockPick II, a USB stick loaded with a suite of acquisition and reporting utilities that will extract pertinent data from Apple Macintosh, Windows (XP and Vista) and Linux systems.   more ...