±Forensic Focus Partners

Become an advertising partner

±Your Account


Username
Password

Forgotten password/username?

Site Members:

New Today: 0 Overall: 32585
New Yesterday: 7 Visitors: 114

±Follow Forensic Focus

Forensic Focus Facebook PageForensic Focus on TwitterForensic Focus LinkedIn GroupForensic Focus YouTube Channel

RSS feeds: News Forums Articles

±Latest Articles

RSS Feed Widget

±Latest Webinars

Streamline Your Digital Investigations

Discussions related to Forensic Focus webinars. Please use the appropriate topic for each webinar.
Reply to topicReply to topic Printer Friendly Page
Forum FAQSearchView unanswered posts
 
  

Streamline Your Digital Investigations

Post Posted: Mon Jan 16, 2017 5:59 am

Please use this topic for discussion of the webinar

Streamline Your Digital Investigations

Presenter: Richard Frawley, ADF Solutions
_________________
Senior Editor, Forensic Focus
Web: www.forensicfocus.com
Twitter: twitter.com/ForensicFocus
Facebook: www.facebook.com/forensicfocus 

scar
Forensic Focus
 
 
  

Re: Streamline Your Digital Investigations

Post Posted: Mon Jan 16, 2017 7:00 am

- scar
Please use this topic for discussion of the webinar

Streamline Your Digital Investigations

Presenter: Richard Frawley, ADF Solutions


When performing a boot scan, what live distribution is used to run your tools? What measures were taken to disable the automatic mounting of file systems? What measures were taken to disable the automatic code execution from a suspect drive? Is there a software write blocker present?  

thefuf
Senior Member
 
 
  

Re: Streamline Your Digital Investigations

Post Posted: Wed Jan 18, 2017 11:58 am

Thank you for your interest in our tools. The operating system used on our Collection Key during a boot scan is forensically sound. It does not automatically mount volumes or allow automatic code execution. We prefer to not discuss technical specifics within a public forum but are happy to assist our customers with this information or others in a private non-disclosure situation.  

PC4N6
Newbie
 
 
  

Re: Streamline Your Digital Investigations

Post Posted: Wed Jan 18, 2017 2:19 pm

- PC4N6
Thank you for your interest in our tools. The operating system used on our Collection Key during a boot scan is forensically sound. It does not automatically mount volumes or allow automatic code execution. We prefer to not discuss technical specifics within a public forum but are happy to assist our customers with this information or others in a private non-disclosure situation.


Thank you for the reply! I am not interested in your tools anymore.  

thefuf
Senior Member
 
 
  

Re: Streamline Your Digital Investigations

Post Posted: Wed Jan 18, 2017 3:05 pm

- thefuf
- PC4N6
Thank you for your interest in our tools. The operating system used on our Collection Key during a boot scan is forensically sound. It does not automatically mount volumes or allow automatic code execution. We prefer to not discuss technical specifics within a public forum but are happy to assist our customers with this information or others in a private non-disclosure situation.


Thank you for the reply! I am not interested in your tools anymore.

@thefuf
WHY? <- Rhetorical question Wink

@PC4N6
Only out of curiosity (and of course only if you can actually disclose this kind of info publicly), what is the plan when (hypothetically) one of your users is standing on the (expert) witness stand (under oath) and is asked how the tool he/she used works?

Just for the record, I was almost flamed for expressing a similar doubt a few years ago:
www.forensicfocus.com/...ic/t=2488/


jaclaz
_________________
- In theory there is no difference between theory and practice, but in practice there is. - 

jaclaz
Senior Member
 
 

Reply to topicReply to topic

Share and Like this forum topic to get more replies




Page 1 of 1