Arnim Eijkhoudt, Lecturer in Digital Forensics, University of Applied Sciences

Arnim, please tell us about your role as a lecturer in digital forensics, and how you first became interested in the field.

I’ve been fascinated with ‘tinkering’ with computers from a young age: figuring out why things (don’t) work, reverse-engineering, reconstructing what happened and so on. Therefore, it was natural for me to turn to the fields of Forensics and Security after I studied Informatics and became a lecturer. Before 2007 I was already incorporating Computer Security-related topics into my lectures and classes where possible. From 2007 to 2013, the Amsterdam University of Applied Sciences and the University of Amsterdam have offered a joint Minor in Forensic Intelligence & Security (MINFIS).Together with a colleague from the UvA I set up a comprehensive programme that combined our knowledge of both fields. I took over as head of the minor in 2012 and since then we have managed to make it even more successful: we consistently have more signups than we can accept, with students from all over the Netherlands contacting me to see if they can participate.

My primary role as lecturer is twofold: I am one of the key lecturers for the Forensics and Security courses and projects, and I take care of the overall logistics, planning, arranging for guest lectures, etc.

You're currently working on Uforia, a universal forensic indexer and analyser, which was showcased at DFRWS earlier this year. Tell us more about the project and the challenges it aims to address.

A friend and I came up with the idea of Uforia as a back-end for a search engine or for simple file deduplication. After building a simple test version, we realized it could be expanded to do much more. I set out to redesign Uforia as a modular, scalable and flexible framework for parsing the metadata of all files on a filesystem, based on the detection of their MIME-types. I developed a working, complete proof-of concept in 2012. From 2012 onwards, the research and development on Uforia was continued through the EDiscovery lectorate group (http://ediscoverynl.dmci.hva.nl/), part of Create-IT Applied Research (http://www.create-it.hva.nl/). As one of the lectorate members, I am actively directing and supervising the continued development of Uforia as a student project in the minor programme. Most of the back-end code has since been rewritten, and in late 2013 we started developing the website as the first ‘front-end’ for exploring the stored information.


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

Uforia is designed to store discovered information in a simple, compatible yet descriptive way, so that the ways of using the data remain as flexible as possible. Because of this design, we can employ powerful search technology and visualization tools like ElasticSearch and d3js to give insight into the data and deduce internal relationships.

Uforia has already changed significantly since the last time we saw it in May; what can we expect from it in the future? Are there any new developments planned for the next year or so?

As of this writing, we should be finishing our first version of the Documents search and Admin panel. There are still many plans for Uforia, but for the next year or so we hope to finish:

– recoding the main engine in C/C++ for speed
– a comprehensive admin interface
– exploring the possibilities of visualizing pcap-/Netflow-dumps
– tagging evidence items for automated evidence report generation
– reworking the search results to allow for quick subselections.

Anyone who is interested in Uforia’s progress or who wants to experiment with its features is welcome to visit our ‘live demo’ website at http://www.uforia.nl.

You teach forensic intelligence & security at the Hogeschool van Amsterdam. What common challenges do you see your students having to overcome during their forensics education, and what would you say makes a successful student in this area?

The most commonly recurring challenge for students has always been to overcome their (understandable) focus on ‘catching the bad guy’ in their courses and projects, wanting to explain to everything rather than applying critical thinking every step of the way.

One of the ways we teach our students to overcome this, is by incorporating legal & ethics subjects into our courses/lectures. The most successful students are those that quickly pick up on these subjects and begin to apply critical thinking to everything they write and do.

Finally, what do you do to relax when you're not working?

I enjoy traveling, particularly by motorcycle, and spending time with my family.

Arnim Eijkhoudt is a lecturer and digital forensics professional at the University of Amsterdam, where he teaches Forensics, Security and System & Network Engineering. The Uforia project is a simple, flexible and extensible framework for forensic analysis and parsing of file metadata.

Leave a Comment

Latest Videos

In this episode of the Forensic Focus podcast, Si and Desi explore how artificial intelligence is being leveraged to uncover crucial evidence in investigations involving child sexual abuse material (CSAM) and examine the importance of exercising caution when implementing these tools. 

They also discuss a recent murder case in which cyber experts played a vital role in securing a conviction, and explore the unique challenges associated with using digital evidence as an alibi.

Show Notes:

A Practitioner Survey Exploring the Value of Forensic Tools, AI, Filtering, & Safer Presentation for Investigating Child Sexual Abuse Material (CSAM) - https://dfrws.org/wp-content/uploads/2019/06/2019_USA_paper-a_practitioner_survey_exploring_the_value_of_forensic_tools_ai_filtering_safer_presentation_for_investigating_child_sexual_abuse_material_csam.pdf

Man charged with NI murder ‘faked live stream to provide alibi’ (The Guardian) - https://www.theguardian.com/uk-news/2023/feb/02/man-charged-with-ni-faked-live-stream-to-provide-alibi

A YouTuber accused of murder faked a 6-hour livestream to produce an alibi (Sportskeeda) - https://www.sportskeeda.com/esports/news-a-youtuber-accused-murder-faked-6-hour-livestream-produce-alibi

European Interdisciplinary Cybersecurity Conference (EICC) 2023 - https://www.forensicfocus.com/event/european-interdisciplinary-cybersecurity-conference-eicc-2023/#more-493234

YouTuber reportedly faked GTA livestream to have an alibi while he committed murder (Dexerto) - https://www.dexerto.com/entertainment/youtuber-reportedly-faked-gta-livestream-to-have-an-alibi-while-he-committed-murder-2052974/

Forensic Europe Expo - https://www.forensicfocus.com/event/forensic-europe-expo/#more-493225

In this episode of the Forensic Focus podcast, Si and Desi explore how artificial intelligence is being leveraged to uncover crucial evidence in investigations involving child sexual abuse material (CSAM) and examine the importance of exercising caution when implementing these tools.

They also discuss a recent murder case in which cyber experts played a vital role in securing a conviction, and explore the unique challenges associated with using digital evidence as an alibi.

Show Notes:

A Practitioner Survey Exploring the Value of Forensic Tools, AI, Filtering, & Safer Presentation for Investigating Child Sexual Abuse Material (CSAM) - https://dfrws.org/wp-content/uploads/2019/06/2019_USA_paper-a_practitioner_survey_exploring_the_value_of_forensic_tools_ai_filtering_safer_presentation_for_investigating_child_sexual_abuse_material_csam.pdf

Man charged with NI murder ‘faked live stream to provide alibi’ (The Guardian) - https://www.theguardian.com/uk-news/2023/feb/02/man-charged-with-ni-faked-live-stream-to-provide-alibi

A YouTuber accused of murder faked a 6-hour livestream to produce an alibi (Sportskeeda) - https://www.sportskeeda.com/esports/news-a-youtuber-accused-murder-faked-6-hour-livestream-produce-alibi

European Interdisciplinary Cybersecurity Conference (EICC) 2023 - https://www.forensicfocus.com/event/european-interdisciplinary-cybersecurity-conference-eicc-2023/#more-493234

YouTuber reportedly faked GTA livestream to have an alibi while he committed murder (Dexerto) - https://www.dexerto.com/entertainment/youtuber-reportedly-faked-gta-livestream-to-have-an-alibi-while-he-committed-murder-2052974/

Forensic Europe Expo - https://www.forensicfocus.com/event/forensic-europe-expo/#more-493225

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_7QiFTiuY7Vw

AI In CSAM Investigations And The Role Of Digital Evidence In Criminal Cases

Forensic Focus 22nd March 2023 12:44 pm

Throughout the past few years, the way employees communicate with each other has changed forever.<br /><br />69% of employees note that the number of business applications they use at work has increased during the pandemic.<br /><br />Desk phones, LAN lines and even VOIP have become technologies of the past workplace environment as employees turn to cloud applications on their computers and phones to collaborate with each other in today’s workplace environment.<br /><br />Whether it’s conversations in Teams, file uploads in Slack chats, or confidential documents stored in Office 365, the amount of data stored and where it is stored, is growing quicker than IT and systems administrators can keep up with.<br /><br />Corporate investigators and eDiscovery professionals need to seamlessly collect relevant data from cloud sources and accelerate the time to investigative and discovery review.<br /><br />With the latest in Cellebrite’s remote collection suite of capabilities, investigators and legal professionals can benefit from secure collection with targeted capabilities for the most used workplace applications.<br /><br />Join Monica Harris, Product Business Manager, as she showcases how investigators can:<br /><br />- Manage multiple cloud collections through a web interface<br />- Cull data prior to collection to save time and money by gaining these valuable insights of the data available<br />- Collect data from the fastest growing cloud collaboration applications like Office365, Google Workspace, Slack and Box<br />- Login to a single source for workplace app collection without logging into every app and pulling data from multiple sources for every employee<br />- Utilize a single unified collection workflow for computer, mobile and workplace cloud applications without the need to purchase multiple tools for different types of collections – a solution unique to Cellebrite’s enterprise solution capabilities

Throughout the past few years, the way employees communicate with each other has changed forever.

69% of employees note that the number of business applications they use at work has increased during the pandemic.

Desk phones, LAN lines and even VOIP have become technologies of the past workplace environment as employees turn to cloud applications on their computers and phones to collaborate with each other in today’s workplace environment.

Whether it’s conversations in Teams, file uploads in Slack chats, or confidential documents stored in Office 365, the amount of data stored and where it is stored, is growing quicker than IT and systems administrators can keep up with.

Corporate investigators and eDiscovery professionals need to seamlessly collect relevant data from cloud sources and accelerate the time to investigative and discovery review.

With the latest in Cellebrite’s remote collection suite of capabilities, investigators and legal professionals can benefit from secure collection with targeted capabilities for the most used workplace applications.

Join Monica Harris, Product Business Manager, as she showcases how investigators can:

- Manage multiple cloud collections through a web interface
- Cull data prior to collection to save time and money by gaining these valuable insights of the data available
- Collect data from the fastest growing cloud collaboration applications like Office365, Google Workspace, Slack and Box
- Login to a single source for workplace app collection without logging into every app and pulling data from multiple sources for every employee
- Utilize a single unified collection workflow for computer, mobile and workplace cloud applications without the need to purchase multiple tools for different types of collections – a solution unique to Cellebrite’s enterprise solution capabilities

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_g6nTjfEMnsA

Tips And Tricks Data Collection For Cloud Workplace Applications

Forensic Focus 20th March 2023 12:00 pm

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles

Share to...