Warren Kruse, Vice President of Cyber Investigations, Consilio

Warren, tell us about your role.

I am Vice President of Cyber Investigations for Consilio, a global Legal Consulting and Services company.  I assist clients of all sizes dealing with data forensics, electronic discovery and cyber review challenges.

What are some of the most prevalent case types you see come through?

Although I cannot talk about specific cases, I see many employment matters, like potential theft of intellectual property and trade secrets. While those cases occur often when employees leave a company and go to a competitor and may start using trade secrets from the preview company, I was surprised to see an increase on those matters during the pandemic when people were working from home.   

What’s an investigation that has caught you by surprise recently? How did you solve it?


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

Can’t give specifics but I can say that just when I think I’ve seen it all, something comes around that surprises me even further.  We approach and execute on each case with an inquisitive but detailed eye towards the data and leverage of robust tools and workflows.

Are there any particular tools that you’ve been relying on? 

I use a combination of tools especially for cross validation.  I’m a big fan of Magnet’s tools and I rely on Magnet AXIOM and Magnet AXIOM Cyber for most if not all my investigations, along with other tools to assist in validating my findings. The value we provide clients is by application of the right tool, the right process to achieve a requested result.

Why does Magnet Forensics have your trust?

As the saying goes “trust but verify” when Magnet comes out with an update, I test it against my personal data that I am familiar with. They also have a nice beta program so you get a look before it is released.  They also have very good training so you not only understand the tools but get a better sense of a lot of what’s going on in the entire field of digital forensics.  

What do you find to be the biggest challenge in your role?

Hard drives and data sizes continue to explode in size, but the time people have to get results is shorter than in the past. This requires more leverage of smarter tools to get through more, faster.

There is something else worth mentioning even though it’s really a second item. As a big fan of being prepared, we like to get as much detail in advance of especially mobile devices where we often times find instances of the “smoking gun” evidence. For instance, we like to be aware if there are any 3rd party application data that we should ensure is collected during our acquisition quality control (QC) steps. Many times, the entire store of evidence may not be on the device and is best collected from the cloud repository versus the mobile devices. This is often overlooked and is helpful to allow smooth collections and least inconvenience to the client and counsel.

This is something AXIOM and AXIOM Cyber do really well. I rely on features like Connections and Timeline to help quickly get that data from different sources and organize it to really tell the story of the evidence.

Prediction time: What do you think will be the biggest change that DFIR professionals will see over the next few years?

I think the pandemic changed a large part of the way we used to do data forensics, lab or on-site analysis. I think they will both come back to some degree over time but our ability to work remotely has increased and clients’ comfort with it has also increased.  AXIOM Cyber is a perfect tool for the remote world we are in.  

If you were talking to someone who just started off in the field, what advice would you give them that you would have wanted to hear when you started out?

I’ve actually worked with many people that started off right out of college and I would tell them to listen and never stop learning. I’d suggest that they work alongside more than one more experienced DFIR expert and learn from them. My friend Mike Barba used to say watching some people do DFIR is like watching ice skating, while others is like watching hockey. As long as you “do no harm” everyone does things differently, learn the different ways then make one your own.  

Any other tips you’d like to share with readers?

I love this field because it never stops changing!  Never a dull moment! But it changes fast so you must keep up with it or it will quickly pass you by. There are tons of learning opportunities.  If you see a webinar or some other free of inexpensive training don’t assume that you know it already. Sign up and attend as much as you can. I’ve picked up great tips on topics that I was pretty comfortable with.

I’m actually hosting a webinar on August 25 with Magnet Forensics, called “Digital Forensics and eDiscovery: Where One Stops and the Other Begins”, and I think it can be a great chance for readers to learn a bit about how to better manage workflows between digital forensic and e-discovery teams.

Leave a Comment

Latest Videos

Si and Desi interview Emi Polito from Amped about how to become an Amped FIVE Certified Examiner (AFCE). They discuss the exam requirements, format, timeline for certification, and Amped’s future plans. Emi explains that the certification is aimed at demonstrating competency with the Amped FIVE video analysis software after completing training. The exam consists of multiple choice questions on theory and practical exercises using the software. Emi talks about the online exam format and process for passing or failing.

Emi also discusses the broader challenges many organizations face with validation and accreditation. He emphasizes Amped's commitment to developing tools that facilitate that process. The hosts reflect on the confusing accreditation landscape and Amped’s passion for improving training and certification in forensics. This episode provides an overview of Amped's new certification and perspective on challenges in the field of video forensics.

Show Notes:

Introducing The AFCE Certification (Amped FIVE Certified Examiner) - https://www.forensicfocus.com/news/introducing-the-afce-certification-amped-five-certified-examiner/

Video Evidence Principles With Amped Software - https://www.forensicfocus.com/podcast/video-evidence-principles-with-amped-software/

Digital Image Authenticity And Integrity With Amped Authenticate - https://www.forensicfocus.com/podcast/digital-image-authenticity-and-integrity-with-amped-authenticate/

File Analysis And DVR Conversion Training From Amped Software - https://www.forensicfocus.com/reviews/file-analysis-and-dvr-conversion-training-from-amped-software/

Amped FIVE Speed Estimation 2d Filter And Training From Amped Software - https://www.forensicfocus.com/reviews/amped-five-speed-estimation-2d-filter-and-training-from-amped-software/

Amped Software’s Martino Jerian on Key Challenges and Opportunities for Video Evidence - https://www.forensicfocus.com/podcast/amped-softwares-martino-jerian-on-key-challenges-and-opportunities-for-video-evidence/

LEVA 2023 Training Symposium - https://www.leva.org/

Forensic Collision Investigation & Reconstruction Ltd - https://www.fcir.co.uk/

Amped FIVE Certified Examiner - https://ampedsoftware.com/afce-certification 

Introducing the Amped FIVE Certification Program - https://blog.ampedsoftware.com/2023/10/04/introducing-the-amped-five-certification-program

Amped Software YouTube - https://www.youtube.com/ampedsoftware
How to Use the Validation Tool in Amped FIVE - https://blog.ampedsoftware.com/2023/03/29/how-to-use-the-validation-tool-in-amped-five

Si and Desi interview Emi Polito from Amped about how to become an Amped FIVE Certified Examiner (AFCE). They discuss the exam requirements, format, timeline for certification, and Amped’s future plans. Emi explains that the certification is aimed at demonstrating competency with the Amped FIVE video analysis software after completing training. The exam consists of multiple choice questions on theory and practical exercises using the software. Emi talks about the online exam format and process for passing or failing.

Emi also discusses the broader challenges many organizations face with validation and accreditation. He emphasizes Amped's commitment to developing tools that facilitate that process. The hosts reflect on the confusing accreditation landscape and Amped’s passion for improving training and certification in forensics. This episode provides an overview of Amped's new certification and perspective on challenges in the field of video forensics.

Show Notes:

Introducing The AFCE Certification (Amped FIVE Certified Examiner) - https://www.forensicfocus.com/news/introducing-the-afce-certification-amped-five-certified-examiner/

Video Evidence Principles With Amped Software - https://www.forensicfocus.com/podcast/video-evidence-principles-with-amped-software/

Digital Image Authenticity And Integrity With Amped Authenticate - https://www.forensicfocus.com/podcast/digital-image-authenticity-and-integrity-with-amped-authenticate/

File Analysis And DVR Conversion Training From Amped Software - https://www.forensicfocus.com/reviews/file-analysis-and-dvr-conversion-training-from-amped-software/

Amped FIVE Speed Estimation 2d Filter And Training From Amped Software - https://www.forensicfocus.com/reviews/amped-five-speed-estimation-2d-filter-and-training-from-amped-software/

Amped Software’s Martino Jerian on Key Challenges and Opportunities for Video Evidence - https://www.forensicfocus.com/podcast/amped-softwares-martino-jerian-on-key-challenges-and-opportunities-for-video-evidence/

LEVA 2023 Training Symposium - https://www.leva.org/

Forensic Collision Investigation & Reconstruction Ltd - https://www.fcir.co.uk/

Amped FIVE Certified Examiner - https://ampedsoftware.com/afce-certification

Introducing the Amped FIVE Certification Program - https://blog.ampedsoftware.com/2023/10/04/introducing-the-amped-five-certification-program

Amped Software YouTube - https://www.youtube.com/ampedsoftware
How to Use the Validation Tool in Amped FIVE - https://blog.ampedsoftware.com/2023/03/29/how-to-use-the-validation-tool-in-amped-five

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_VKk-mhlae1c

Becoming An Amped FIVE Certified Examiner (AFCE)

Forensic Focus 1st December 2023 4:25 pm

Subscribe to the Forensic Focus Podcast: https://www.forensicfocus.com/podcast/

Si and Desi are joined by Brittany and Ailsa from digital forensics software company ADF Solutions. They discuss how ADF is addressing key challenges for digital forensics practitioners, including handling the massive volumes of data from mobile devices and the cloud.

The guests outline ADF's focus on developing their software as an easy-to-use onsite triage tool that can help quickly identify pertinent evidence. Key features include advanced handling of video files, AI-assisted classification of images, and new screen recording capabilities for mobile devices that allow suspects to safely share relevant data. 

The hosts and guests also explore ADF's ongoing research into areas like facial recognition, handling new device types like games consoles and smart watches, and identifying deepfake media.

00:00 – Introduction to Ailsa and Brittany
03:00 – The challenge of vast amounts of data
05:50 – Recovering data from Chromebooks
08:50 – Triaging using ADF tools
12:30 – Benefits of using ADF Solutions’ tools
15:50 – Limitations in types of apps
17:20 – Keeping up with technological advancements
19:15 – ADF customer base
21:00 - Artificial intelligence in classifying images
30:00 – ADF Solutions’ triaging kit
37:00 – Training with ADF
40:00 – Target user
44:50 – Roadmap of future devices to examine
51:30 – Main focus for ADF Solutions going forwards

Show Notes:
AI-generated CSAM article on Sky News - https://news.sky.com/story/thousands-of-ai-generated-child-abuse-images-being-shared-online-research-finds-12991727

Subscribe to the Forensic Focus Podcast: https://www.forensicfocus.com/podcast/

Si and Desi are joined by Brittany and Ailsa from digital forensics software company ADF Solutions. They discuss how ADF is addressing key challenges for digital forensics practitioners, including handling the massive volumes of data from mobile devices and the cloud.

The guests outline ADF's focus on developing their software as an easy-to-use onsite triage tool that can help quickly identify pertinent evidence. Key features include advanced handling of video files, AI-assisted classification of images, and new screen recording capabilities for mobile devices that allow suspects to safely share relevant data.

The hosts and guests also explore ADF's ongoing research into areas like facial recognition, handling new device types like games consoles and smart watches, and identifying deepfake media.

00:00 – Introduction to Ailsa and Brittany
03:00 – The challenge of vast amounts of data
05:50 – Recovering data from Chromebooks
08:50 – Triaging using ADF tools
12:30 – Benefits of using ADF Solutions’ tools
15:50 – Limitations in types of apps
17:20 – Keeping up with technological advancements
19:15 – ADF customer base
21:00 - Artificial intelligence in classifying images
30:00 – ADF Solutions’ triaging kit
37:00 – Training with ADF
40:00 – Target user
44:50 – Roadmap of future devices to examine
51:30 – Main focus for ADF Solutions going forwards

Show Notes:
AI-generated CSAM article on Sky News - https://news.sky.com/story/thousands-of-ai-generated-child-abuse-images-being-shared-online-research-finds-12991727

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_4z-EgH54KZk

The Power Of Digital Forensics: How ADF Solutions Is Revolutionizing The Digital Forensics Industry

Forensic Focus 30th November 2023 2:57 pm

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles