Forensic Focus - Computer Forensics, Computer Forensic Training, Digital Forensics
LoginRegisterForumsPapersEducationGraduate RecruitmentReviewsInterviewsNewsletterJobsEventsBlog
Search Forensic Focus
Custom Search
Graduate Recruitment

computer forensics graduate jobs

Join, Subscribe, Share

Join newsletter

Join LinkedIn group

Follow on Twitter

Subscribe to news

Subscribe to forums

Subscribe to blog

Subscribe to tweets

Members' blogs

External feeds

Bookmark & share: Bookmark and Share

Main Menu
MY ACCOUNT
COMMUNITY
EMPLOYMENT
EDUCATION
RESOURCES
MISC
Computer Forensics Newsletter
Newsletter

You must be a
registered user
to receive our newsletter

Register Now!
Forensic Focus

Forensic Focus

Copy and paste the text below to insert the button displayed above on your site. Thanks for your support!

Computer Forensics Survey
Which of the following do you usually use for imaging evidence?




Results :: Polls

Votes: 34417
Comments: 0


MacLockPick II

reviewed by Austin W. Troxell, MSc, CISSP of Cyber Investigation Services


Introduction

In today's computing environment of tera-byte hard drives and encrypted file systems, the practice of 'pull the plug, image at the lab' is becoming impractical, if not risky. To address these and other challenges, live acquisition is gaining in popularity. Indeed, every digital forensics examiner should become proficient in the techniques of what has come to be the latest buzz-phrase in the industry: “field triage.”


Overview/Features

To meet the needs of non-technical first-responders such as law-enforcement, parole officers, private investigators, etc., SubRosaSoft (subrosasoft.com/OSXSoftware/index.php) has introduced MacLockPick II, a USB stick loaded with a suite of acquisition and reporting utilities that will extract pertinent data from Apple Macintosh, Windows (XP and Vista) and Linux systems.

The MacLockPick II (MLP) arrived packed in a round can with an accompanying CD that features a 17-minute instruction video in Quicktime, MP4 format. The MLP itself is a mini-USB stick with a non-ferrous metal shell that extends to the end of the USB contacts (see photos). With the extended metal case, there is no need for a “connector protector” to fumble with or misplace. However, the cladding does make the MLP a little more difficult to insert in a USB port than a regular flash drive.


What's in the box

MacLockPick


In Action

Before the MLP can be used to extract data, it must be “authenticated.” This is a relatively straightforward process of executing an application on the MLP, emailing the resultant file to SubRosaSoft and copying the attachment from the return email to the MLP. My request was answered by the vendor in less than 4 hours – on a Saturday night!

Once the MacLockPick is inserted in a USB port, the device is auto-mounted and auto-executes the acquisition program. Very little user-intervention is required. As data is being collected, an animated progress screen lets the user know that the program is working and a caption reports on which particular items are being extracted at the time. A message indicates when the acquisition process has completed. (NB: The MLP shows up as “UT165 USB2 Flash Storage” in the Windows Registry. It is important to document this “change” if the PC is to be seized and imaged later.)

The collected information is stored on the MLP. Optionally, a different external device may be selected as the storage media for data and reports. The data may also be copied or moved from the MLP once back at the lab.

Not surprisingly (considering its name), MacLockPick acquisition from a Macbook was a breeze. Data-collection was easy and fast!

Running the MLP against my Windows XP Home desktop, was unsuccessful. Because I have disabled Auto-Run/Auto-Play on my system, the MLP was not able to self-execute. When I manually invoked the acquisition executable, I received a message after a few seconds that the program completed successfully. Examination of the output folder showed that no data had been been extracted. SubRosaSoft is working on repeating and resolving this issue. I have been very favorably impressed with SubRosaSoft's prompt replies to all of my emails.

Subsequent tests on other PCs that still had Auto-Run/Auto-Play enabled were successful, although in one instance it took 90 minutes to extract data from the Windows Registry of a laptop running XP.

I was unable to extract data with the MLP from a Fedora 10 Linux system. According to SubRosaSoft, the MacLocPick was tested successfully on Ubuntu and SUSE Linux systems.


What I Retrieved

Here is a list of the most notable data that I recovered from the various test systems:

- Windows Clipboard
- Bookmarks from Internet Explorer, Firefox, and Apple Safari
- Browsing History
- Cookies
- Auto-fill entries
- System Information
- Network Information, including ARP entries and Statistics
- Interface information (MAC & IP info)
- Running processes
- Windows Registry – Full Tree (Classes Root), file associations
- Apple Key Chain extraction

(A more complete description of what the MacLockPick can recover is available here.)

The retrieved information is stored in a separate database file for each case. The MLP Reader application presents this data in a sortable table that may be exported to a text file for searching and reporting.

I was quite surprised with the amount and quality of information that the MLP recovered from the test systems. In fact, the MacLockPick recovered a good bit of data that I mistakenly thought my “privacy-protection” software had wiped from my PC!


Screen-shot of Data Reader (click image to view full size)


What I Liked

When it worked, auto-execution was smooth and returns a LOT of information. Report output is clean and easy-to-read. The MLP is small and designed to be carried on a key-chain. The metal shell makes the MLP very rugged. As previously mentioned, the reinforced USB connector requires some extra effort to insert the device into a USB port. That's not a complaint - I'll take ruggedness over easy-to-insert any day for a product that will spend most of its time being jangled in someone's pocket along with keys and loose change.


What I Didn't Like

If the MLP doesn't auto-start, it doesn't work. Windows acquisition can be quite slow. I'm not convinced that a user in the field would want to wait an hour and a half while the MacLockPick extracts data. As to the how-to CD that comes with the MLP, although informative, the audio track was annoyingly choppy (duplicated on various Windows systems). This may be just a minor irritation to some, but for the price (see below) and considering the non-technical audience for this product, I feel it one worth addressing.


The Price

At $495 USD, I felt the MacLockPick II is a bit pricey, although the cost is very close to what is offered by competing vendors. Considering the hefty price-tag of most products that are aimed at the digital forensics market, the MacLockPick II may actually be a bargain.


The Verdict

Most systems encountered in the field run either XP or Vista. The failure of MacLockPick II to consistently extract information from Windows PCs in a timely manner is a significant shortcoming. If a user encounters a PC that has Auto-Run disabled, there should be a “Click Me” workaround on the MLP that will assist them.

In its current version, the MacLockPick II still needs a little work. In addition to resolving the Auto-Run issue, I'd like future revisions to have a graphics extractor to allow a system to be quickly scanned for its image content and the results summarized in a collection of thumbnails. If SubRosaSoft can solve the performance issues mentioned above, the MLP could be a very useful tool for first-responders. Until then, prospective customers may wish to evaluate other products.

- Austin W. Troxell, MSc, CISSP


This review can be discussed here.




--

Cyber Investigation Services serves the Anderson, Greenville and Spartanburg area of Upstate South Carolina offering Computer and Mobile Device Forensics, Electronically-Stored Information (ESI) Discovery, Data Recovery, Escrow Agent / Special Master for litigation support and Secure Data Destruction.


Universities/Colleges

computer forensics education choices COURSE DIRECTORY

User Info

Welcome Anonymous

Nickname

Membership:
Latest: IvanZ
New Today: 8
New Yesterday: 18
Overall: 13164

People Online:
Members: 4
Visitors: 24
Bots: 7
Staff: 0
Staff Online:

No staff members are online!
Latest Jobs

e-Discovery Manager - London, Europe - iConect, Clearwell
Last post by RaviBans01 in Computer Forensics Job Vacancies on Feb 04, 2010 at 18:22:04

CYBER FORENSIC INVESTIGATORS - LONDON £40k - £65k + Bens
Last post by emma in Computer Forensics Job Vacancies on Jan 25, 2010 at 12:22:12

INTELLIGENCE ANALYST - LONDON - up to £50k
Last post by emma in Computer Forensics Job Vacancies on Jan 25, 2010 at 12:02:28

Computer Forensic Investigator - Phoenix, Arizona (USA)
Last post by DDDR in Computer Forensics Job Vacancies on Jan 22, 2010 at 18:05:29

Forensics, Pent Testing, IDS, Malware, C&A - Washington DC
Last post by jhup in Computer Forensics Job Vacancies on Jan 21, 2010 at 17:48:53

Digital Forensics Engineer (Boston, MA)
Last post by stacynu in Computer Forensics Job Vacancies on Jan 19, 2010 at 20:18:15

EDISCOVERY & OPERATIONS DIRECTOR, LONDON
Last post by ScottBurkeman in Computer Forensics Job Vacancies on Jan 19, 2010 at 14:49:38

E-DISCOVERY SPECIALIST - LONDON - £50k - £65k + Exc Bens
Last post by emma in Computer Forensics Job Vacancies on Jan 19, 2010 at 11:34:04

FORENSIC NETWORK ADMINISTRATOR - LONDON - £35k - £50k + Bens
Last post by emma in Computer Forensics Job Vacancies on Jan 19, 2010 at 11:27:41

COMPUTER FORENSIC MANAGER - LONDON-£50-£65k
Last post by ScottBurkeman in Computer Forensics Job Vacancies on Jan 19, 2010 at 11:16:56

Computer Forensics Blog
· Computer forensics education directory now online
· US academic institutions - final call for contact details!
· Hidden Hymn
· Adroit Photo Forensics review
· Interview with Russell May, 4N6 Investigation
· Forensic Computing PhD, UK
· The Value of Push Button Computer Forensics
· Academic institutions - updated
· Computer Forensics in the Geek Press – A Taxonomy
· Academic institutions - who are we missing?

read more...
Members' Blogs

Start Blogging

What is Computer Forensics?
Computer forensics (or forensic computing) is the use of specialized techniques for recovery, authentication, and analysis of electronic data with a view to presenting evidence in a court of law.
Computer Forensics Downloads
  1: Forensic Examination of Digital Evidence: A Guide for Law Enforcement (pdf)
  2: ACPO Good Practice Guide for Computer based Electronic Evidence
  3: Electronic Crime Scene Investigation: A Guide for First Responders (pdf)
  4: Ancysoft Data Recovery Software
  5: HELIX incident response CD
  6: PDA Forensic Tools:An Overview and Analysis
  7: Forensics Plan Guide & Forensic Cookbook
  8: Recover My Files
  9: Autopsy Forensic Browser Version 2.03 (source code)
  10: Handy Recovery

Use of this website signifies your agreement to the Terms of Use/Privacy Policy available here.

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2010 Forensic Focus


Interactive software released under GNU GPL, Code Credits, Privacy Policy
.: fisubsilver shadow phpbb2 style by Daz :: CPG-Nuke port by norseman :: ported to CPG-Dragonfly by jamin :.