CSI SQL Server – Methods for collecting digital evidence

Forensic analysis of database systems is very specific and demanding task, and it was the main inspiration for writing this article. In this article you will find information about what digital forensic is and what kind of methods you can

Intro to Report Writing for Digital Forensics

So you’ve just completed your forensic examination and found that forensic gem or smoking gun in your case, so how do you proceed? Depending on where you fall as a forensicator (e.g., law enforcement, intelligence, criminal defense work, incident response,

Insiders Doubt 2008 Pentagon Hack Was Foreign Spy Attack

In the fall of 2008, a variant of a three year-old, relatively-benign worm began winding its way through the U.S. military’s networks, spread by troops using thumb drives and other removable storage media…”Some guys wanted to reach out and touch

High tech crime fighters in Garfield County Sheriff’s Office

When a detective with the Garfield County Sheriff’s Office collects a computer, cell phone, digital camera, thumb drive, or any other technological device that potentially holds evidence pertaining to a case, they take it to one person — Detective Cpl.

‘Web 2.0’ as evidence

by Sean McLinden "In a recent intellectual property case for which we were retained, among the electronically stored information (ESI) that the plaintiff sought for production were internal company blogs and wikis used by the defendant’s developers to discuss new

Scalability: A Big Headache

by Dominik Weber"Scalability is simply the ability of our forensic tools and processes to perform on larger data sets. We have all witnessed the power of Moore's law. Hard drives are getting bigger and bigger. A 2 TB SATA hard

Single Sign On

by Si Biles"Calling something a “Holy Grail” is an interesting term – the intended meaning is well known to most of us – i.e. something miraculous that will solve all of your problems. However given that it’s supposedly a cup,

Guidance Intros Forensics For Live Control Systems

Guidance Software announced Wednesday that it’s created the first-ever approach to conducting computer forensics on live industrial control and supervisory control and data acquisition (SCADA) systems. The company said that the benefit of its new program would be to help

Paraben Corporation Announces Release of the iRecovery Stick

Paraben Corporation has announced the release of the first consumer tool for recovering deleted data from iPhones. The iRecovery Stick recovers user data, both active and deleted, such as deleted text (SMS) messages, deleted contacts, and deleted calendar items, from

Dell Accused of Concealing Evidence in PC Suit

Dell has been accused of withholding evidence, including e-mails among its top executives, in a lawsuit over faulty computers it sold to businesses, according to a filing made Thursday. Advanced Internet Technologies filed a motion in Federal District Court in

Need help to start from scratch…

"I work for a small police department in Georgia, and being the only one in my division able to competently use a computer I got sent to the Mississippi State University Introduction to Digital Forensics one week course. Now my

Suspect in $9 Million RBS WorldPay Hack Extradited to U.S.

One of the alleged ringleaders behind the 2008 hack of RBS WorldPay has been extradited to the U.S., where he was arraigned Friday in the Northern District of Georgia on charges that he helped coordinate the global $9.5 million bank

Your mobile forensics training course needs YOU!

"I am currently finalising the details for the Introduction to Connection Records course and wondered what do you want to know? Training is not about the trainer. It’s about your learning! Currently the course will contain lectures and practical exercises

Authentication and Authorisation

by Simon Biles "Authentication and Authorisation are fundamental to information security – identifying who a user is (authentication), and what they are allowed (authorised) to do allow us to restrict access to data in such a way that only the