Welcome to this round-up of recent posts to the Forensic Focus forums.
How would you acquire data from a password protected MS Surface Pro?
Forum members discuss malware risk mitigation on forensic workstations.
How can a split E01 image of a Windows 7 Enterprise SP1 physical disk protected by BitLocker be mounted? Forum members come up with a solution.
Minime2k9 asks how to find evidence of remote desktop login outside of the Windows Security log.
Should you keep a chain of custody for forensic investigations in corporate environments? Add your thoughts on the forum.
Forum members discuss a timestamp discrepancy on an acquired Linux machine.
How do you recover deleted Snapchat images on an iPhone 4S? Chime in on the forum.
Forum member liguoroa gives feedback on BlessHex editor.