The following transcript was generated by AI and may contain inaccuracies.
Richard Frawley: All right, good day everybody, and welcome to our webinar, The First 60 Minutes of Digital Evidence. I’ll give everybody a couple of seconds to get in here and get settled, and to make sure everything’s working.
Let me go over a couple of things we’re going to cover today. First and foremost, why the first 60 minutes matter, which gets into pre-planning and Search Profiles. We’re going to talk about the first 60 minutes on scene and how it all relates. I have Search Profiles in here because a lot of it relates to our tool itself. While there is a lot of learning outside of the tools, a lot of it does relate, and our tool does do a lot of what we’re going to talk about. Then scene arrival, evidence preservation, mobile and computer triage, and finally on-scene decisions and conclusions.
There is a chat message box and there is a questions box. Please use those — I have them up, so I should be able to see them. This webinar is being recorded, so you’ll be able to refer back to it later. You’ll get a link to that, and if you know somebody who couldn’t make it and they want to see it, it will be up on our website.
If you have any questions, there is a questions panel. Please type them in there as we’re going along — ask them as they come up. If I see it and I have the chance to answer it right there in the moment, I will. If not, I’ll save those towards the end.
Looks pretty good. I’ve been talking a couple of minutes and I don’t see any complaints that you can’t hear me, can’t see me, or can’t see the slides, so I’m going to proceed. Again, thank you for being here. I do appreciate it. I know everybody has choices, and you chose to be here for the next forty-five minutes. I hope you take something away.
I’m Rich Frawley. I’m the Director of Training here at ADF Solutions. I’ve been here ten years now. I retired in 2016 from a nice twenty-three year career in law enforcement as a digital forensic examiner and investigator, working all different types of cases — but I did a lot of search warrants, a lot of on-scene work, and a lot of pre-investigations.
If you do the math — and I say this all the time — I started this at the turn of the century, in the late 1900s, right? I learned a lot and did a lot. I learned about triage and on-scene chaos, if you will, early on, and what needed to be done to prevent my lab from becoming a two-year backlog. It was hard enough to keep it under eighteen months at the time, even with triage.
Why the first 60 minutes matter
But we’ll move on. First 60 minutes: why they matter. There are a lot of reasons. First and foremost, those 60 minutes aren’t really going to matter in a lot of the things we’re going to talk about if you let them know you’re coming.
This leads into a podcast I’m doing next week with Cyber Social Hub on seven mistakes that can be made. I think one of the biggest mistakes you could ever make is letting them know you’re coming. That just leads to that destruction of evidence: the remote wiping, the shutting things off, so you don’t have the ability to get those credentials or have something up live that may be encrypted.
Device destruction — there are a lot of stories about that. I used to do a lot of presentations about search warrants and on-scene work, and your basics. One of the pictures I used to use was of a computer that had been shot. They knew we were coming, shot the computer, hit the computer, but missed the hard drive. It was a great picture.
But we can solve that by not letting them know you’re coming. And it’s tough. Sometimes this isn’t your case — you’re coming out because somebody’s asked you to come along on their search warrant as the digital evidence expert, and you don’t have control over whether they’ve been contacted or not.
I had a case, or many, where other departments would come in and say, “Hey, I’ve got this case, it’s going to involve digital evidence.” And the first thing they’d say is, “Can you come out and do an interview with me?” And I’d say, “No. Let’s just do the search warrant so we don’t lose the evidence.”
Of course, that depends on whether that interview is important and what the digital evidence is going to hold. Are we just supporting something you already have? That kind of issue. But once you let them know, you kind of lose that first 60 minutes, or it changes.
There’s a story from 2002 where a suspect’s home was raided and the laptop was found inside the oven next to a can of butane. The hard drive melted so badly they couldn’t get anything off it.
I had one for another town where they came to me with a bunch of computers and explained the story. It was a combination of a sexual assault type case and a production of CSAM material. They had let this guy know they were coming, and there were certain drives that had been formatted and altered. But with everything they seized, we were able to put it back together. It just made it that much harder. It made the examinations that much more intensive — or comprehensive, if you will. It was still there, but it made it that much more difficult in that realm.
Data preservation and integrity on scene
So, not letting them know you’re coming — that’ll help.
When you get in there, you’re going to have your evidence to triage or go through. What I’d like to say here is that if you’re going out and it’s a reactive type of scene — called out to a homicide — that 60 minutes is going to be on data preservation and integrity. It’s going to be on making sure nothing’s lost, everything is gained, and everything is preserved in the way it should be.
That stuff’s really not going to be touched until it’s back at the lab, or maybe in the crime van if you have one out there. But you’ve got all the material you need to make sure it’s prevented from contacting the networks.
They’re in airplane mode. If it was on, it was left on; if it was off, it was left off. You’re going to deal with the encryption. There are a lot of factors in those types of scenes. So your first 60 minutes is really that: documenting, preserving, integrity.
Now, that all factors in — don’t get me wrong. Just because we’re going to be doing a triage doesn’t mean this stuff doesn’t matter. But it’s not the whole 60 minutes when we get there.
Deciding what you want to walk away with
But in these first 60 minutes, if you are going out and triage is part of what you’re doing — part of your policy, your procedure, and what you’re allowed to do — then you have to decide, and hopefully decide before you get there, what decisions you are going to be making on scene. What do you want to make on scene? What do you want to walk away with?
If you have that question answered before walking in the door, it makes that whole trip, that whole visit, worth it. Are you looking to make an arrest? Are there children in the house and you want to make sure they’re not in harm’s way? Do you want to make sure there was no hands-on? Is this time critical, time sensitive? How much time do we have? Do I need to get in and out and get as much information as I can?
We all know there are all different types of situations. But knowing what decision you want to make makes it easier to decide what you are going to do and where you are going to spend this time.
Victims and witnesses are almost a completely different ball of wax, if you will. The Fourth Amendment doesn’t matter in that victim-witness situation. There are other things you can do, but you still try to follow the same procedures to make sure of the data preservation and integrity.
So when you’re in and you know what decisions you want to make: what methods am I going to use? What is available to me to make these decisions? You’re turning the chaos of on-scene into something that’s going to get me my actionable intelligence and get me ready for court. What can I do here to make it all happen?
Well, I have preview available to me. I’m going to hook up a computer — with us, using the Collection Key. You’re going to plug that in, and you’re either going to boot or run it live. You’re going to collect your RAM and see what’s on there. Screen captures are a fallback from the preview.
Now, with us, a preview is no different from doing your logical acquisition, your advanced logical acquisition. You’re making the same changes to the phone that you would if you were hooking it up to any other tool, as far as just settings, with Android or iOS. You’re hooking it up, and you’re actually starting that logical acquisition procedure and then previewing what’s on that phone — not changing any dates, times, metadata, anything like that.
So it’s really good for your preservation and integrity. Screen capture falls off a little bit more. While it’s really heavy on chain of custody and making sure you’re doing it and still making a connection to the phone, you still have that manual manipulation — which preview, by the way, solves. That on-scene thumb scrolling, what I call manual acquisition of a device, falling back to scrolling with your thumbs and then taking a picture. Preview and screen capture kind of cover both of those.
A targeted extraction falls into that victim-witness type of situation: I just need this off the phone, I just need these files, I just need these chats. There’s a little bit more to learn about targeted extractions, but it can be done, and it’s an avenue you can use while you’re on there, especially if it’s time-sensitive or critical.
And then there’s just an MTP collection: “I need these files off this device.” Again, you’re going to make the connection to the tool the right way, like you would with any other tool, with data preservation and integrity in mind.
Pre-planning when time matters
So, your pre-planning, when time matters and when your decisions need to be made. We went over all that in the previous slide. But on top of never letting them know you’re coming, pre-planning your execution with the right artifacts and knowing what you’re looking for is important.
Remember that triage is not solving the case. That’s a really big one for making your time on scene count. So I’m not solving the case, I’m making a decision — and what do I need to make those decisions? That’s where your pre-planning and building Search Profiles come in, and what kind of speed you want on scene, what kind of confidence levels you want on scene.
If I want to leave a computer behind, or if I want to leave a tablet or a phone behind, what do I need to scan that device and feel confident that there’s nothing on it — that grandma can have her pink iPad back, or the children can have their devices back because they weren’t being used for nefarious reasons?
Confidence level, pre-planning: what do I have available to me? When I’m pre-planning my search, am I doing just something like a threshold, a “show me”? Just show me some images and I’ll take the computer and we’ll be on our way. That’s great — we can do that. We can set up a profile that just looks for images, or just runs hashes or keywords. In a minute, five minutes, you typically are going to run into what you’re looking for by just doing that.
Child exploitation keyword search, or image search, or hashes — all three combined, short, just targeting what you’re looking for. You can come back.
Now, what if it doesn’t find anything? Your one-dimensional search for images or videos didn’t produce anything. Does that mean that computer hasn’t been used? Does it mean that they haven’t been downloading — that they’re just not saving it, they’re deleting it, or putting it off somewhere else, and there’s nothing logically that’s going to pop up on this machine? So where’s the confidence level on that?
So what else am I going to look for? What kind of artifacts am I going to look for, or run second? If I only have that one-dimensional tool, I’m kind of stuck. “Well, I’m not confident it’s the suspect’s computer, but there’s no child exploitation material on there, but we’re going to take it anyway.” If your plan is to just take everything anyway, that works.
Time limitations and what to target
So that’s why you need to do this pre-planning. Know your time limitations. How much time do I have on scene? Do I really need to see something in thirty seconds? It’s nice, it makes you feel good, but truly, it’s five to ten minutes to have a really nice, comprehensive, confident scan and say, “Yes, this is the one we need to look at first,” or, “This has been on ten minutes on grandma’s. There are no keywords, there’s no victim name, there’s no internet history, there are no connections to certain places or things. I feel confident in leaving this behind.”
Make sure when you’re doing these types of scans that it is looking inside your zip files, right? Because I know I’ve come across quite a few cases where things have been viewed and then deleted or gotten rid of, but that zip file’s still there. So if you’re not looking at that, you might be missing a lot.
And target the user areas for this information. Artifacts, you’re going to get from all over. But when you’re looking at files, when you’re looking at pictures, ninety percent of what you’re looking for is going to be in those user profiles. So target that area. Don’t worry about System32 and Windows and ProgramData and Program Files. Go to where all the user information is set. Your AppData is in there by the users as well, so you’re going to have all that information to look at.
And keyword searches are awesome on a triage for file names, especially when you’re doing CSAM-type cases: Lolita, pTHC, age categories. You look at the keyword in the file names. Those keyword searches of file names are quick, low-hanging fruit that comes back early. Looking for those same keywords in the artifacts you’re collecting — in your web browsing history, in your registries, in your logins, in recent files — that brings you back a lot of information quickly.
I would exclude looking for it in content unless I really felt I needed to do something deep. I’m not going to start searching Word documents and spending the time on that when I might have a lot more low-hanging fruit. I’d save that for a deeper dive if I’m not finding anything. It just speeds everything up and gets you what you want, with a lot less to look through in terms of false positives.
But yeah, triage is a beginning. It’s not meant to be the be-all and end-all. You’re not solving the case, you’re making decisions.
So, unique keywords: like I said, Lolita, pTHC, your victim’s name — as long as it’s not something generic that’s going to be found everywhere — their username. The username of your suspect, you’re going to have thousands of those on your computer. But the username of your victim really should not be on grandma’s computer or the kids’ computers. It’s going to be on your suspect’s computer. So remember that when you’re doing your uniqueness.
The first 15 minutes on scene
The first fifteen minutes on scene are usually arrival, security, photos and videos, locating and preserving what may be there, and starting the search. “In this room we have a laptop and a phone, and those we need to do first” — especially if it’s his bedroom or his office or what have you.
And then as you’re going around: where is everything? What is everything? What do we need to do? Laying out your plan on what’s going to be looked at first and what’s going to be looked at second, depending on how many licenses you have on scene and how many computers are on scene. You get those computers going first and you use the licenses. You could be doing ten computers, and then you take that license and start doing the phones.
So your first ten, fifteen minutes is that preservation: making sure nothing’s lost, making sure the scene’s secure. How many computers do I have? How many mobile devices do I have? And your plan of action from there.
Mobile triage
Mobile triage, as I was mentioning earlier: removing the manual thumb scrolling, which has been around since mobile phones came out. There’s really never been that method of hooking up and quickly seeing what’s on there without changing data, and getting enough necessary information to make those decisions.
So preview takes care of that. You’re hooking up the phone like you would — it’s a forensic tool. You’re hooking it up to do an advanced logical acquisition, you’re taking all those steps, and then you’re letting the tool take that information off and show it to you immediately within the viewer of the tool.
Right into the pictures: how many pictures are in that DCIM folder? How many other logical pictures are there in any other area, on an SD card? It’s going to show you, “Hey, we’ve located 4,000 pictures already, and here are the thumbnails, here’s the property, here’s the metadata.” And while you’re looking at all that, we can collect the files for you as well.
Same with video. Here’s how many videos are on here, here are some key frames of those videos so you get an idea of what’s in it. And then if you want to view them while you’re in there, it will start collecting and you’ll be able to preview it if you need it.
But with those key frames, you’re going to be able to say, “I need to look at this one. I don’t need to look at these. I need to look at this one, this one, this one.” So you’re making decisions, you’re seeing things immediately, right away.
And again, back to triage being a beginning, not an end. As soon as you see what you want — if this is a threshold-type scan — “Hey, I see CSAM material on here,” or, “I see what I was looking for” — you can stop it. Whatever’s been collected, or what you’re viewing or observing on that computer at that time on your viewer of the phone, you stop it and it’s there for you to report on. You go back to your office, you bring it back up. I came, I saw, I conquered: in a minute and thirty seconds I saw this, and we decided this phone was going, and it’s going to be first in line.
So it’s real-time viewing of the devices, pictures and videos, and it gets rid of that manual scrolling. Now that’s the biggest problem it solves, because you’re on a goose chase when you’re doing that, especially if you’re not used to those types of phones. “Hey, I do Androids. I’m not used to an iPhone. Where am I looking? What am I going through? It just keeps scrolling.” Or you’re opening up chats and messages and scrolling. You don’t need to do that.
It is a documented acquisition being done. You can start preservation orders and reports as soon as you get back to your office for things that you’ve seen on there.
You’ll have reports for your negative scans: grandma’s pink iPad, the kids’ computers, mom’s work computer, mom’s work phone. “Hey, we came, we saw, this is what we did, this is what we looked for. There was absolutely zero of this. With high confidence, we left this behind.”
And again: beginning, not an end. Keeping that in mind when doing triage is huge. I’m not solving the case. I don’t need to look at everything. I need to make decisions. And stopping at any time is most important. You don’t have to wait for these things to run. If you see what you need to make a decision, seize it and move on. Document and move on.
Prioritising what to look for
All right, what do I have here?
What do I prioritise as what I want to look for when I’m looking at these devices, whether computer or mobile? Recent calls and text messages — if I can get those right away, yeah, absolutely. Logically, they should be there. Maybe I don’t have a lot of the third-party ones, but the ones on the phone.
Some messaging apps, you may need to revert back to a screen capture type of situation. But you’re still connected, you’re still heavy on chain of custody, maybe a little bit more manual.
Photos and videos, absolutely. That could be anywhere in your priority list. CSAM and child exploitation cases, absolutely — that’s going to be right up at the top. A drug case might be down at the bottom. I don’t really need to look at the computer, so maybe I create a profile that’s just looking at artifacts, that’s just looking at text, that’s just looking at keywords, or just specific messaging or calls — which typically is what you’re getting from confidential informants, and you kind of know what’s going to be on there.
So you’ll be able to target that information as well. Again: documented preview or acquisition, preservation and reporting are key in these situations. You’re getting results from positive or negative scans. And again, stopping at any time is key, along with time on scene and getting to everything soon.
Now, I did a presentation a while back, quite a few years back, I think it was called Get In, Get Out, and Get to Breakfast on Time, which used to be our motto. We’d hit the house early and be in and out within two hours if we possibly could, so we could have breakfast with everybody who helped.
That’s kind of what you want to shoot for. You don’t want to be somewhere all day. You don’t want to be in a house where you have to wipe your feet on the way out instead of on the way in. This all helps: knowing what you want, knowing what to prioritise, knowing what you’re looking for, and having your process for the decisions to be made.
You also have the right to make the decision to just go in, seize everything, and leave. That’s there too. It doesn’t really help in the lab, and it doesn’t help the future of this case, but it still can be one of your decisions.
Looking for evidence that matches the case: if I’m doing a drug case and I’m looking to triage for specific information, last on my priority list is those pictures and videos. They may come later, or if I’m not finding anything, maybe then I look at pictures and videos and do a quick preview, but I’m going to be focusing on the other stuff.
Pictures do tell a lot, though. You think drug case — it’s not child exploitation — but there are plenty of pictures on the dealers’ phones of the drugs, of the money, of the weapons, of all three in one picture.
So if you’re classifying as well, you’re going to see those. CSAM and sex crimes: absolutely, pictures high priority, videos high priority. Fraud and ID theft: again, pictures aren’t really going to be part of it, unless it’s some type of insurance scam where they’re submitting the same accident photos over and over.
And then homicide: again, it’s not really going to be something you’re doing on scene. That’s a bag and tag, and preserve, and make sure that everything was done right so that evidence is there back at the lab.
And then passcodes, biometrics, and act fast. If it’s up and running and live — let’s say a computer’s up and Windows is up and you’re able to get in there and get the information — do it.
There’s a lot of information on a live computer: encryption keys, RAM, and one of the biggest that maybe gets overlooked sometimes is web credentials, those saved usernames and passwords in browsers. If you can get that on a live scan, just think of all the preservation orders you could do, all the bank accounts you may have access to, all the phone accounts.
You know where their money is, you know where their calls are, you know what social media they have, you know where they’ve been going, you know where they’ve been shopping. There are so many things you can get out of there. So if it’s up and running, make sure you handle those in the right way.
Computer triage
Computer triage — I kind of mixed them together, but that was more heavy on mobile. Immediate decisions could be made with a computer, whether it’s on or whether it’s off. It’s a tried and true methodology; we’ve been doing computers for years. A couple of things change: encryption, whether you need to go into the BIOS, whether you’re using a boot key.
You can go to the single boot key menu, and you shouldn’t even be touching the BIOS or changing anything in there with Secure Boot or any security settings. You shouldn’t have to do that. Your boot key should be Windows-based for a Windows machine, so it’s a trusted operating system. You don’t have to worry about that. You’re not going to brick it.
Now, that’s going to go to my podcast I’m doing on mistakes: bricking computers because you just haven’t kept up, or you didn’t think, you didn’t read, you just went in without pre-planning.
Tried and true methodology: if it’s powered on, leave it on. If it’s off, leave it off. That’s where decisions get made. Can I do that live scan? It’s up and running — can I do that and gain information? Is it allowed by my policy and procedure? What am I going to change? Is it documented?
Right. So yeah, you plug something into a machine and Windows says, “Hey, something was plugged in.” You execute a program and Windows says, “Hey, something was executed.” But from that point forward — especially with ADF, running from the key, collecting your RAM — from that point forward, no changes are made to any dates, times, or metadata. You can open and close files while you’re searching and nothing’s going to change. You can get the encryption keys on that live.
If it’s not up and running, you can boot to it a hundred percent forensically sound. If it’s encrypted, you’ll need the credentials, or you can image that way as well. So just having that ability in that first sixty minutes can save you from taking stuff that you don’t need to — the stuff in the closets that’s years old or doesn’t get used any more.
And pictures and videos, of course. Those are your instant, “Yeah, there it is. I see it.” Again, you can stop those scans. Everything you saved up to that point is there for you. Great for knock and talks if it’s not a warrant. If it’s consensual, anything you collect is there on that key for you. When they say no, or when you see what you want, you can stop it.
Priority artifacts are a lot easier to get off a computer. Again, tried and true methodology, a lot of stuff there. Browser history, downloads, recent documents, USB activity. Artifacts that relate to user interaction, user manipulation.
I have these files on the machine that were found — are they tied to any of these artifacts? Email, peer-to-peer, messaging, downloads, web history. Just those five. Have they been looking for it? Did they download it? Were there any recent files? And then we automatically link those for you. So getting the pictures and being able to look and say, “Hey, are these linked to anything?” immediately is just awesome. Those artifacts that go towards user manipulation are awesome.
On-scene decision-making as a force multiplier
Your on-scene decision-making and this triage methodology really go towards the force multiplier, if you will. I used to love using this phrase and then it became kind of a buzzword. I still like it because it’s true. The impact of making your decisions on scene on what’s going to happen later on with this case is laid out right here.
Your lab backlog goes down. Your device prioritisation goes up. You know now, from the scene going back to the lab, which ones are more important, which one’s going to have the information, so you’re getting your information back faster.
Bagging and tagging: not as much time spent on everything. Believe me, I spent hours in houses where there were just boxes of hard drives and computers stacked up, and there was no way triage was going to be done on everything. But you’re only bagging and tagging what you’re deciding is important.
Investigations continue from this point if you’ve gathered a lot of information on scene. What I call the early case assessment type of triage: that computer’s going to the lab for the full deep dive, which it should be. But you now have all this information to continue that case as soon as you get back to your office. You have that information to start working on preservation orders, further search warrants, arrest warrants, referrals, whatever you may have in that case.
You’re already doing it. You’re not waiting for that computer to come back, whether it’s a week, two weeks, two months, six months, a year — you have that information to work with.
And triage, compared to everything else digital forensics-wise, is low cost, easy to use, easy to do. It still requires a little bit of training, a little bit of work, but once you have all that, it really smooths out all the stumbling blocks you had before. You bag and tag everything, you send it back, and now you’re at the mercy of the lab for results for you to continue that case. So the folder goes back into your desk and you’re working on another one. This way, that folder stays open, nothing gets stale, and things are moving right through the system the way they should.
Knowing your goals — I mentioned this throughout, and it’s really probably a nice sign to have. Take a screenshot and put it up. Triage is a beginning. It’s not an end. It’s a beginning. It’s where you make your decisions. It’s targeted: you want to target user profiles, you want to target user artifacts that show intention. It’s for decisions. You’re not solving the case. This isn’t going right to court.
You will have enough — if you make a decision on scene to arrest, you’ll usually have enough for a report and your probable cause hearing the next day. But it’s for decisions: I want to do A, B, and C when I’m on scene.
It requires thought. What am I looking for? Where am I looking for it? How can I make this fast? If I’m going out on a threshold and I don’t see anything, how do I build my confidence that they’re not downloading and doing everything, or receiving these and then deleting them? So it requires a little bit of thought before you go out. What evidence do I have? What’s unique that I can look for?
What’s leading me to believe how many devices are going to be on scene? That’s the worst — when you show up expecting one or two things and you open up the closet and they’re running a server farm. That happened on an eBay fraud. I thought I was going to have a computer and the fake laptop that they kept selling over and over again. We opened the closet and there were seven servers in there, and he’s hosting websites.
So trying to figure that stuff out: pre-planning, getting ahead, trying to figure out what you’re in for when you get there. And it requires confidence. I’m confident in doing these types of scans — live scans, collecting RAM, boot. I’m confident in these decisions, and I’m confident that when I did it to this tablet, this phone, this computer, and I left it behind, I’m not going to worry that I left evidence behind. I’m confident in those decisions, and I’m very confident in the decision I made on scene because I did find what I was looking for.
Consensual situations
Consensual situations: this is where a lot of that screencasting or targeted extraction comes in. What I like to say here is that it’s really the same as being on scene, just with that warrant difference — but maybe sometimes you have to move a little faster.
You still want to preserve as best you can, especially with victims and witnesses. But you may have that taillight guarantee, where if they walk out that door, as long as you can see them, that evidence may still be there. But as soon as they’re gone, that evidence could be gone forever. So you want to get it right then and there, especially if they’re reluctant.
This tool really lends itself to being able to do screencasting and collect information with them sitting next to you, and you’re both seeing it — being really transparent: “This is what I’m taking, and this is what it means.” Involving them.
You know your case better than anyone else when it comes to these situations: whether you’re going to seize it, whether you’re going to leave it behind, whether you’re going to do a targeted extraction so you don’t have an acquisition at the end. Like I said, I love using the collection as an interview.
“Show me what’s on here.” Okay, you’re willing to give me your Kik chats from the weekend. However, to make this really look good in court, I’m going to need some settings, so do you mind if we go to settings and collect this? Oh, did you talk to anybody else, or use any of the other apps?
The interview, and “show me,” and “oh, let me just collect that” type of thing. Or maybe you walk yourself right into saying, “Sorry, I have to make an acquisition of this device now, but I’ll get it back to you.”
So you know your case better than anybody else. You know whether it’s hinky, whether you can trust them or not. Using the interview method with a reluctant witness, getting them on your side, allows you to collect more relevant information and really make that case go where it needs to go. You may have to go back and get that phone, but if it’s going to walk out that door, you may never see it again. It’s best to collect what you can at the time, and then move on.
Questions
I’m going to answer a couple of questions here. I’m going to leave this up: we have a case study here from the New Jersey State Police on how they’re using our tool with ICAC cases, and it’s a great read. You can use that to do that.
Q: What are the most overlooked artifacts investigators should check during that first 60 minutes?
Richard Frawley: It’s a good question. For triage, like I said, I’d make sure it’s using artifacts that show user interaction with a file, and linking those files. Downloads, recent files, messaging, peer-to-peer. Email’s a great source of that stuff, but it takes so long to parse that out if it’s on that computer. I typically don’t look at email in a triage — that’s deeper. In a triage, I should be able to find other stuff to support my decisions, and it’s usually those user interactions.
Live scan: again, if you’re doing a live scan of a computer, those web credentials are huge. If they’re saving usernames and passwords — I mentioned it before — not only for all the sites they’re using and what they’re doing, but those passwords can be repetitive. They use them over and over and over again. So if you’re going to come across encryption or password-protected files, that may also be in there. And it’s great for having a password list if there’s something else you can’t get into. So that’s really important.
As well as the encryption one that gets you the BitLocker keys — we have one of those that’s run live. If it’s up and running and it’s encrypted, we’ll grab those keys for you.
And if you’re doing probation as well, I would look for stuff like saved networks — maybe that’s a violation, maybe they’re not supposed to be somewhere, a Starbucks or something using Wi-Fi. Just those types of things. Think about what your decision is, and then try to put the artifacts in there.
Q: How do you balance speed with preserving forensic integrity in time-sensitive investigations?
Richard Frawley: Well, with the preview, we try to make sure that you’re connecting that phone like you would back at the lab, like you have it hooked up to do your advanced logical acquisition. Same methodology.
Now, if you have to step back for a screenshot and do some manual manipulation, at least you’re connected, at least you’re getting a chain of custody: date, time, hash, device that it’s coming from. It all goes towards that chain of custody, instead of saying maybe that’s all you’re collecting off the device.
Instead of having somebody send you something, instead of having somebody download something and give it to you where you kind of lose that date and time, that hash value, that device that it came from — collect it this way, and then you can report on it and put it towards everything that makes up your good chain of custody.
In critical situations where you need this information, where if it walks or you miss it: screenshot, preview, a collection. You can hook up the phone to this tool and download stuff over MTP. Again, don’t have them send it to you. Witnesses — somebody witnessed something, somebody took a video of something, and that’s all you need of it. You can connect and download it. You have it. If you showed you hooked up the phone, you have all the information you need, and you have that chain of custody.
Q: How do you know when you have enough information to stop the on-scene triage?
Richard Frawley: That comes right down to: what am I looking for, and what are my decisions? If you see it and you know that’s good enough to make the decision you want — either I’m seizing it and I’m taking it, this goes top of the line, this shows user interaction.
So is that enough to put the person behind the phone or behind the keyboard, that they did it? Not yet. Good old-fashioned police work on scene: you have the information, you get an interview out of it, and that might be good enough. “Hey, I saw what I wanted, I can make my decision.” That’s when you stop it.
So with that, thank you. I don’t see any other questions here. If there are, please send them through. I appreciate your time. I know, like I said, you had choices, and you chose to be here. I appreciate it.
Download that case study, take a look. Visit adfsolutions.com if you’d like to try out our tool. I’m Rich Frawley — [email protected] — if you want to talk about something or ask a question.
Again, I appreciate it. Everybody have a great day, and we’ll see you next time.





