Forensic Focus - Computer Forensics, Computer Forensic Training, Digital Forensics
LoginRegisterForumsArticles/PapersEducationReviewsInterviewsNewsletterJobsEventsBlogAdvertise
Search Forensic Focus
Custom Search

Find us on Facebook
Follow Forensic Focus on Twitter

Submit article, paper or blog post
Latest Articles
· “The Data Specimen is the Blood of Cyber Forensics”
· Forensic Imaging of Hard Disk Drives- What we thought we knew
· Can Your Digital Images Withstand A Court Challenge?
· Review: Proof Finder by Nuix
· Forensic Toolkit v3 Tips and Tricks ― Not on a Budget
· Is your client an attorney? Be aware of possible constraints on your investigation. (Part 2 of a multi-part series)
· iPhone Tracking – from a forensic point of view (Update!)
· Android Forensics Study of Password and Pattern Lock Protection
· Skype in eDiscovery
· Forensic Toolkit v3 Tips and Tricks – On a budget

read more...
Main Menu
MY ACCOUNT
COMMUNITY
EMPLOYMENT
EDUCATION
RESOURCES
MISC
Follow Forensic Focus

Join newsletter

Join LinkedIn group

Follow on Twitter

Subscribe to news

Subscribe to forums

Subscribe to blog

Subscribe to tweets

Members' blogs

External feeds

Bookmark & share: Bookmark and Share

Newsletter
Newsletter

You must be a
registered user
to receive our newsletter

Register Now!
Forensic Focus

Forensic Focus

Copy and paste the text below to insert the button displayed above on your site. Thanks for your support!


Interview with Nick Furneaux, MD CSITech & Director, Bright Forensics - 07/05/09


Forensic Focus: Nick, can you tell us something about your background and why you decided to work in this particular field?

Nick Furneaux: I’ve worked in IT for almost 20 years and around 10 years ago was involved in writing Intranet and Internet based systems for highly secure environments in the UK. That led on to needing to understand the complexities of security, then securing their systems, then investigating when things went wrong. I found that I loved the investigative side and turned to Computer Forensics full time about 6 years ago.

Nick Furneaux
Nick Furneaux

Forensic Focus: What does your current role involve? Can you describe a typical day?

Nick Furneaux: I am fortunate that my work is varied and fascinating. One day I may be doing a standard disk-based investigation, the next day researching the data stream in a protocol, next teaching RAM analysis and the following night I’m in a covert van with an antenna pointed at someone’s router. I have a personality defect where I get bored if I do the same thing for too long!

Forensic Focus: As someone perhaps best known to the wider computer forensics community as an expert in "live forensics" can you describe how that discipline has developed over the past few years and briefly bring us up to date with current research and practice?

Nick Furneaux: Wow, that’s a question with a 3 day answer. Principle 1 of the ACPO (Association of Chief Police Officers) guidelines says simply ‘Do no harm, make no changes’. The problem is that PC’s are routinely left on now and in that instance it is impossible to comply with Principle 1. If we leave it on we make changes, if we pull the plug we make changes. I remember Jim Gordon from West Mercia Police and I presenting at the F3 conference in the UK 4 years ago, demonstrating how to capture RAM and create a password cracking list, all leading edge stuff at the time, some people were smiling and nodding, others had their arms firmly crossed! That has changed and I don’t know anyone who denies that the ‘best’ evidence from a running machine includes grabbing the volatile data in an appropriate manner.

Current research revolves around the quite staggering amount of data (evidence?) we can extract from RAM. It used to be just running processes, strings and carving files, now we can extract the SAM file and crack the users' passwords, find and grab the type and serial number of every USB key ever plugged into the system, get typed URL’s, Truecrypt passwords and large amounts of timed and dated Internet History, the list goes on. The Volatility framework from Volatile Systems has been a huge leap forward for researchers, with some cool plugins appearing. I’m writing a new plugin at the moment building on the great work done by Moyix, if I can get my head firmly around Python that is!

Forensic Focus: Can you tell us something about the wireless attack techniques you've been working on?

Nick Furneaux: A lot of Police Officers and other Agencies had been speaking to me about the need for a specific course in how to identify, break encryption and exploit wireless routers. There are some good courses out there already but they were heavily focused on theory and were not very hands-on. Working with Jon Evans (now at Qinetic) we developed our own Linux based Virtual Machine with a small Peli-case of adapters, antennas and other bits and pieces, which just work out of the box. We haven’t reinvented the wheel but the course is becoming very popular indeed as you spend 3 days just attacking routers and whizzing around in cars GPS mapping streets and buildings, its loads of fun! I’m afraid it is Law Enforcement only though because of legal issues here in the UK.

I’m currently writing phase 2 of the course which is the exploit of machines once you are on the router, getting a remote command shell, setting keyloggers and stuff like that. I’m writing it with a chap from the US who is involved with building BackTrack, he has to remain nameless for the time-being I’m afraid.

Forensic Focus: As a trainer of both corporate and law enforcement personnel, how do you meet the needs of these two groups? Are their requirements very different?

Nick Furneaux: Generally with disk-based forensics I think the requirements are very similar, in fact the Helix Live Forensics course and the new Advanced Live Analysis course are equally popular with both Corporate and Law Enforcement.

The more significant divide arises with covert needs. I do a lot of work in this area and have developed/helped develop several tools for unusual requirements and the needs of the users become very specific. In that world the focus tends to be on safely and quietly gathering intelligence rather than procedural, evidential issues and hence the data being extracted and analysed is oriented toward directing further investigations rather than evidence bags and Court reports. It also means that non-Hi Tech crime trained operatives are often deploying the tools and hence they have to be simpler and fairly fool-proof.

Forensic Focus: What does the phrase "best practice" mean to you in relation to computer forensics?

Nick Furneaux: This is another interesting question and should have the word ‘Debate’ after it.

I have been a member of the British Academy of Forensic Science for several years and watch the traditional forensic sciences very carefully as I think we have a lot to learn from older, more established forensic sciences that have ‘Best Practice’ methods for almost everything they do. They have accepted methods and procedures that are currently missing from our world; I don’t think you can even call Computer Forensics a ‘Science’ yet.

Every HiTech Crime unit I visit does things slightly differently which I think encourages personal free thinking and freedom to work ‘around’ a problem but it can also encourage sloppy work and evidence missed, it really relies upon the motivation and passion of the investigator.

If you visit the FBI in the US you will find everything in their HiTech Crime units is procedural – step1 – step2, virtually laminated cards! This is great for consistency of work but perhaps stifles personal problem solving and lateral thinking around a problem. This is not a critisism of either method, they are just different. As I said – ‘Debate’.

Forensic Focus: What would you most like to see improved within the computer forensics industry?

Nick Furneaux: Standards for what constitutes an Expert Witness! At the moment my Mum can do an Encase course, convince her Solicitor neighbour to use her and start doing investigations. In fact one or two private practitioners I know are less qualified than my Mum! We have issues in the UK where some private investigators are bringing the whole industry into disrepute and we need a solution to that. I don’t have one – sorry.

Secondly, come back Accessdata, we used to love you! The issues surrounding V2 of FTK are concerning as we need at least 2 primary and widely used investigation tools. Prodiscover, X-ways and others are great but Encase and FTK 1.X were always the tools of choice to check and confirm your findings. I do want FTK 2 to be brilliant but its still not there yet for me.

Forensic Focus: Nick, you've travelled widely and worked with computer forensics practitioners in many different countries - have you noticed significant cultural differences in the way people work or is there such a thing as a single global forensic community which transcends national boundaries?

Nick Furneaux: One thing that binds the international community together is a real passion for the work we do and a desire to move it forward and make it better. I see that wherever I go. It is reflected on the forums too although I do wish they, Forensic Focus and others, were less confrontational at times. It is not unusual to see a post raising an idea or thought and then see it mashed by others not challenging, but rubbishing. That is a shame.

As few years ago a couple of us posted on another forum our findings about RAM not being quite as volatile as we all thought. We were completely flamed for over 2 weeks and eventually I backed off and stopped posting. We ended up being right but those who posted hindered our research rather than positively adding to it. More positivism please!

Forensic Focus: What trends do you see in forensic computing and what new challenges do you envisage in the future?

Nick Furneaux: Triage is the buzzword at the moment. With hard drives getting larger the challenges of storage and analysis will continue to mount. Tools to do system triaging to identify the machines that contain the possible evidence we are looking for will become ever more vital, however, the chances of missing data will increase accordingly. The industry may have to come to terms with a trade-off or be prepared for cases to take longer and cost much more money.

Forensic Focus: What qualities do you think are most important for anyone working in this field?

Nick Furneaux: Simple - patience and tenaciousness.

Forensic Focus: What is the most rewarding part of your job? What aspect of your job do you find most challenging?

Nick Furneaux: Rewarding is finding that one piece of evidence tucked away in unallocated space or a memory register that changes the case, love it when that happens.

Challenging is not finding that one piece of evidence tucked away in unallocated space or a memory register that changes the case, hate it when that happens.

Forensic Focus: What do you do to relax when you're not working? What are your plans for the future?

Nick Furneaux: Sorry, relaxing, what is that exactly? Anyone sat up in bed at 11:30 last night reading Python for Dummies does not have a handle on relaxation! Seriously, I like to run, go climbing with my 11 year old and eat my wife's curries, best in the world, well apart from India I’m guessing!

Plans for the future are many and varied, aside from CSITech I’m Technical Director of my brother's company, Bright Forensics which sells Helix 3 Enterprise, NUIX and other forensic tools, I think that has an exciting future so will be investing some time in that.

Otherwise, I will be continuing to work, research and train in the most fascinating industry in the world!





--

Nick Furneaux can be contacted as follows:

Email: nick@csitech.co.uk

Web: http://www.csitech.co.uk


Forensic Education

computer forensics education choices COURSE DIRECTORY

User Info

Welcome Anonymous

Nickname

Membership:
Latest: Draugrs
New Today: 0
New Yesterday: 13
Overall: 20808

People Online:
Members: 0
Visitors: 37
Bots: 5
Staff: 0
Staff Online:

No staff members are online!
Latest Jobs

Data Analytics Assistant Director, Dubai
Last post by ScottBurkeman in Digital Forensics Job Vacancies on Feb 02, 2012 at 17:14:03

Experienced Forensic Computer Analyst, Surrey
Last post by pickle in Digital Forensics Job Vacancies on Jan 31, 2012 at 12:35:31

eDiscovery Analyst and Assistant Manager, London £35-£50000
Last post by ScottBurkeman in Digital Forensics Job Vacancies on Jan 23, 2012 at 14:12:11

QCC Vacancy - Digital Forensics Sales Executive (London)
Last post by garybrevans in Digital Forensics Job Vacancies on Jan 20, 2012 at 13:17:43

E-Discovery Consultant- London- £40-£50K basic + 10% bonus
Last post by Teval in Digital Forensics Job Vacancies on Jan 20, 2012 at 10:09:56

Senior Software Licence Review Manager. London. Up to £100K
Last post by Tyrrell66 in Digital Forensics Job Vacancies on Jan 19, 2012 at 13:46:41

Senior Forensic Manager - London
Last post by diana2012 in Digital Forensics Job Vacancies on Jan 18, 2012 at 18:05:43

Data Analytics Consultant
Last post by Nicola in Digital Forensics Job Vacancies on Jan 18, 2012 at 18:04:08

Forensic General Investigations Accountant Consultant London
Last post by Nicola in Digital Forensics Job Vacancies on Jan 17, 2012 at 15:13:44

Forensic Technology - Sr. Consultant Needed in Boston, MA
Last post by mfeeley in Digital Forensics Job Vacancies on Jan 12, 2012 at 18:39:18

Blog
· Harry Onderwater
· Forensic Toolkit v3 Tips and Tricks ― Not on a Budget
· Is your client an attorney? Be aware of possible constraints (Part 2)
· iPhone Tracking – from a forensic point of view
· Android Forensics Study of Password and Pattern Lock Protection
· Skype in eDiscovery
· Forensic Toolkit v3 Tips and Tricks – On a budget
· Anonymous, what does it mean?
· YouDetect – Implementing the principles of statistical classifiers and cluster analysis for the purposes of classifying illegally acquired multimedia files
· Advice for Digital Forensics Job Seekers

read more...
Members' Blogs

Start Blogging

What is Computer Forensics?
Computer forensics (or forensic computing) is the use of specialized techniques for recovery, authentication, and analysis of electronic data with a view to presenting evidence in a court of law.
Downloads
  1: Forensic Examination of Digital Evidence: A Guide for Law Enforcement (pdf)
  2: ACPO Good Practice Guide for Computer based Electronic Evidence
  3: Ancysoft Data Recovery Software
  4: Electronic Crime Scene Investigation: A Guide for First Responders (pdf)
  5: HELIX incident response CD
  6: PDA Forensic Tools:An Overview and Analysis
  7: Recover My Files
  8: Autopsy Forensic Browser Version 2.03 (source code)
  9: Handy Recovery
  10: PC On/Off Time

Use of this website signifies your agreement to the Terms of Use/Privacy Policy available here.

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2011 Forensic Focus


Interactive software released under GNU GPL, Code Credits, Privacy Policy
.: fisubsilver shadow phpbb2 style by Daz :: CPG-Nuke port by norseman :: ported to CPG-Dragonfly by jamin :.