How To Decrypt BitLocker Volumes With Passware

Decrypting BitLocker volumes or images is challenging due to the various encryption options offered by BitLocker that require different information for decryption. This article explains BitLocker protectors and talks about the best ways to get the data decrypted, even for… Read more

How To Use Magnet AXIOM In Mac USB Investigations

Hey everyone, Trey Amick from Magnet Forensics here. Today we’re talking about Mac USB investigations, and what happens when we’ve been alerted that a USB has been inserted into an end point. Different organisations handle USB policies differently. Some have… Read more

How To Integrate LACE Carver With Griffeye Analyze DI Pro

Let’s talk about the exciting new LACE Carver integration with Analyze DI Pro. Once you have the proper license, you can head over to your Downloads page on MyGriffeye.com and go to the LACE Carver download. Once the app package… Read more

How To Boot Scan A Mac With APFS And FileVault 2

Hi, I’m Rich Frawley and I’m the Digital Forensic Specialist with ADF Solutions. Today we are going to conduct a boot scan of a MacBook Air that has APFS and FileVault 2 enabled. At this point you have decided on… Read more

How To Acquire Data From A Mac Using MacQuisition

Written by: Justin Matsuhara, Solutions Engineer, BlackBag Technologies Stephanie Thompson, Solutions Engineer, BlackBag Technologies Depending on the digital forensic imaging tool you have available, creating a forensic image of a Mac computer can be either an anxiety-creating situation, or as… Read more

How To Acquire Video Data With MD-VIDEO From HancomGMD

Due to the rapidly growing need for securing safe environments around the world, digital surveillance systems have become ubiquitous. A significant number of new surveillance systems are installed each year, and the importance of acquiring actionable data from these systems… Read more

How To Acquire Mobile Data With MD-NEXT From HancomGMD

by Michelle Oh, HancomGMD  With an ever-increasing range of features and dramatically increased storage capacity, digital devices have become essential to our daily life. Their ability to store vast amounts of data means that these devices have proliferated and are… Read more

Walkthrough: Carving With Belkasoft Evidence Center

by Yuri Gubanov, Danil Nikolaev & Igor Mikhailov © Belkasoft Research Carving is an irreplaceable technique widely used in data recovery and digital forensics. By using carving, we essentially perform a low-level scan of media for various artifacts, looking for… Read more

How To: Create A Logical Image On Falcon NEO

Welcome to Logicube’s tutorial on the Forensic Falcon NEO. In this episode, we’ll show you how to perform a logical image. The logical imaging feature of Falcon NEO shortens the evidence collection process by allowing investigators to select and acquire… Read more