Digital Forensics Now-logo

Digital Forensics Now

Technology Podcasts

A podcast by digital forensics examiners for digital forensics examiners. Hear about the latest news in digital forensics and learn from researcher interviews with field memes sprinkled in.

Location:

United States

Description:

A podcast by digital forensics examiners for digital forensics examiners. Hear about the latest news in digital forensics and learn from researcher interviews with field memes sprinkled in.

Language:

English


Episodes
Ask host to enable sharing for playback control

Live from IACIS with the Phone Wizard, Bill Aycock!

5/2/2024
Live from the International Association of Computer Investigative Specialists (IACIS) with special guest Bill "the phone wizard" Aycock!! Notes: Three New SANS Posters https://www.sans.org/posters/ios-third-party-apps-forensics-reference-guide-poster/ https://www.sans.org/posters/android-third-party-apps-forensics/https://www.sans.org/posters/dfir-advanced-smartphone-forensics/ New Release of Mushy https://doubleblak.com/app.php?id=Mushy Blue Crew Forensics https://bluecrewforensics.com/2022/03/07/ios-app-intents/

Duration:00:57:55

Ask host to enable sharing for playback control

From Disaster to Attainment: Crafting Digital Forensic Reports

4/11/2024
Navigating the complexities of digital forensics can be daunting, but this week we've got your back with the exploration of Magnet Forensics' Axiom version 8, and its transformative Mobile View feature. As your hosts we're not just sharing tech updates; we're discussing the impact these tools have on our work and how they shape the narratives we construct. When it comes to the integrity of an investigation, the devil is in the details—and in the documentation. We delve into the craft of forensic reporting, dissecting why an analyst's narrative is just as critical as the raw data pulled from tools. From the subtleties of crafting a timeline to the nuances of articulating the relevance of each artifact, we've got the insights that will assist you on your report writing journey. Finally, join us for a celebration of the community spirit that fuels this field, illustrated by new blogs and newly supported artifacts in the LEAPPS. We also look at the growing significance of vehicle forensics in investigations. And because we all need a good chuckle, don't miss our 'meme of the week' segment. It's an episode brimming with expertise, but not without its moments of laughter because finding joy in our work is paramount. Come for the knowledge, stay for the camaraderie, and enhance your forensic acumen with us. Notes- Job Alert- Upcoming Openings at the New York State Police https://troopers.ny.gov/civilian-employment Capture the Flags Hexordia https://www.hexordia.com/spring2024-weekly-ctf-challenge Oxygen https://oxygenforensics.com/en/training/events/ctf-apr-19-2024/ Belkasoft https://belkasoft.com/belkactf6/info Mobile View and Copilot in Magnet Axiom https://www.magnetforensics.com/blog/bring-your-mobile-evidence-to-life-with-the-new-mobile-view-in-magnet-axiom/ https://www.magnetforensics.com/blog/identify-deepfakes-and-quickly-surface-evidence-with-new-ai-tools-in-magnet-axiom/ DeRR.p. Investigating Power Events on Samsung Devices https://thebinaryhick.blog/2024/04/07/__trashed/ Peer Review Checklist https://www.hexordia.com/blog-1-1/gc0vnvj80ogwx724ovu7avzwvjl742 What's the Buz: Forensic Analysis of Buz for iOS https://laurora4n6.wixsite.com/aurora4n6/post/what-s-the-buz What's New with the LEAPPS? https://www.stark4n6.com/2024/04/splitwise-on-ios.html

Duration:01:24:41

Ask host to enable sharing for playback control

Apple Is At It Again, Changing Our Logicals!

3/28/2024
In mobile forensics, with each update brings new challenges and opportunities. Join us as we dissect the latest iOS 17.4 impacts, including the nuances of SQLite databases and the advent of write-ahead logs in Advanced Logical extractions. Our episode is brimming with insights that could change the way you approach data extraction and parsing. The forensic landscape is ever-evolving, and this episode isn't shy about the hurdles we face, or the workarounds that keep us ahead. Discover how matching forensic work environments with devices' native operating systems and utilizing tools like Christian Perter's and Lionel Notari's for Logical and Unified Log extraction can streamline your investigative processes. Building a personal brand in digital forensics isn't just about notoriety; it's about cultivating a reputation that commands respect and opens doors. This episode celebrates those who contribute to the community, from the creation of new parsers to the latest features in FTK 8, and how these actions bolster not just your standing but the entire field. We explore the unique journeys that shape our professional identities and share laughter over common forensics foibles. It's an episode that champions growth, community, and the personal touch that makes all the difference in a technical world. Notes- A Gift From Apple: https://www.msab.com/blog/apple-deleted-data-itunes-backups/ UFADE Universal Forensic Apple Device Extractor: https://github.com/prosch88/UFADE iOS Unified Logs tool: https://www.ios-unifiedlogs.com/blog FTK LevelDB Support: https://www.exterro.com/ftk-product-downloads What's New with the LEAPPS? https://github.com/abrignoni

Duration:01:26:37

Ask host to enable sharing for playback control

Is Support on Life Support?

3/14/2024
Unlock the secrets of advanced forensic analysis with us! We reveal essential training classes that every digital sleuth needs to stay ahead in an ever-changing tech landscape. Sign-on to be enlightened by experts in the captivating world of data structures through Hexordia's class and IACIS's comprehensive course. But it's not all about the classes; we're also sending a must-read book your way to sharpen that detective wit you pride yourself on. Get ready to explore the controversial yet fascinating realm of facial recognition with our introduction of Exponent Faces, a X-Ways Forensics X-Tension. Whether it's identifying suspects or navigating the ethical minefields of biometric data, we're weighing in with all the expertise you could hope for. Finally, journey with us as we dissect the pivotal role of soft skills and community support for forensic examiners, you'll find this episode is not just about the tech—it's about the people behind the screens who make justice possible. Join us, where knowledge is power and staying updated is as crucial as the evidence itself. Notes: IACIS Advanced Mobile Device Forensics https://www.iacis.com/training/amdf-advanced-mobile-device-forensics/ DFIR Investigative Mindset-Brett Shavers Book release March 22, 2024- 1/2 price for one week! Facial Recognition in DFIR https://www.apiforensics.com/blogs/announcing-exponent-faces.asp https://abcnews.go.com/Business/controversy-illuminates-rise-facial-recognition-private-sector/story?id=96116545 Google Chrome Platform Notification Analysis https://www.sans.org/blog/google-chrome-platform-notification-analysis/ The Digital Forensic Practitioner Survey (DFPulse2024) https://bit.ly/dfpulse What's New with the LEAPPs? https://github.com/abrignoni

Duration:01:06:49

Ask host to enable sharing for playback control

Don't Strive to be Mediocre!

2/29/2024
Embark on a journey through both history and the cutting-edge world of digital forensics with us as we pay homage to the brilliant Dr. Gladys West, whose work underpins the GPS technology we take for granted today. In celebration of Black History Month, we draw inspiration from Dr. Martin Luther King Jr., discussing how we can all contribute to the fight against enduring societal challenges. Our conversation is a testament to the power of empathy and action in fostering societal change, spotlighting the often overlooked breadth of achievements by historical figures like Dr. West and Dr. King. Unravel the complexities of iOS location and Unified Log analysis through our educational talk on the recent breakthroughs highlighted by experts like Ian Whiffin and Lionel Notari. Discover the new feature from Magnet Axiom. The Animated Map Routes feature provides an additional facet for courtroom presentation. We wrap up with a deep appreciation for the significance of training and expertise in digital forensics, engaging with the thoughts presented by Shafik Punja in his 'Bullshit Hunting: Digital Forensics Edition' article. The discussion traverses the critical role of proper forensic training and tools, the ethical responsibilities that accompany our work, and the profound impact that our industry has on legal outcomes and lives. Notes- The Cyber Social Hub- Daily Digital Investigator Episodes https://podcast.cybersocialhub.com/ Belkasoft's Free Android Forensics Class https://belkasoft.com/android-forensics-training Apple Maps - Visited Location? https://www.doubleblak.com/blogPost.php?k=mapssync iOS Unified Logs - WiFi and AirPlane Mode https://www.ios-unifiedlogs.com/post/ios-unified-logs-wifi-and-airplane-mode Animated Map Routes in Magnet Axiom https://www.youtube.com/watch?v=fyPrJKLhD9k 8 Log Files You Can Collect from iOS and Android Devices https://www.magnetforensics.com/blog/8-log-files-you-can-collect-from-ios-and-android-devices/ Candidate Examiner's and Training Programs https://www.bullshithunting.com/p/bullshit-hunting-digital-forensics Sources of Error in Digital Forensics https://www.sciencedirect.com/science/article/pii/S2666281724000027

Duration:01:00:28

Ask host to enable sharing for playback control

The Future: Talking to Your Digital Forensic Tools?

2/15/2024
Discover the intersection of digital innovation and forensic expertise as we celebrate and honor the incredible legacy of computing pioneer Mark Dean during Black History Month. With a salute to unsung heroes like Johann, who fuel the open-source tools we rely on, this episode is a tribute to the collaborative spirit that propels digital forensics forward. Peek behind the curtain of the Photos SQLite database with insights from the Forensic Scooter blog, uncovering the depths of data crucial to forensic investigations. We explore how metadata comparison can reveal content manipulation, the importance of distinguishing between cloud and device media origins, and the crafty skills required to validate findings in a world where AI is becoming a pivotal tool. This episode isn't just about the tools we use; it's about the critical thinking and validation skills necessary to ensure AI assists rather than misleads. Fasten your seatbelt as we navigate the evolving landscape of vehicle forensics and tackle the challenges posed by encryption in new vehicle modules. Reflect on how data from vehicle systems can be leveraged in accident reconstruction and criminal investigations, emphasizing the need to stay ahead of technological advancements. Wrapping up, we delve into the latest from the LEAPPs framework and the implications of Android's multi-user support, underscoring the episode's commitment to sharing knowledge that keeps the digital forensics community at the cutting edge. Notes- Black History Month Notable Contributor to Digital Forensics-Mark Dean https://web.eecs.utk.edu/~markdean/ Device Set-up – Transferring data to new iPhone & Effects to Photos.sqlite https://theforensicscooter.com/2024/02/04/device-setup-transferring-data-to-new-iphone-effects-to-photos-sqlite/ Dissecting the Android WiFiConfigStore.xml for Forensic Analysis https://blog.digital-forensics.it/2024/02/dissecting-android-wificonfigstorexml.html AI Generated Imagery https://us5.campaign-archive.com/?u=a5a2a1131e612711f02b96e2c&id=81d1b025e7 Magnet Idea Lab-Project Goose https://magnetidealab.com/projects/project-goose/ Vehicle Forensics How to access logical files in a QNX partition- https://www.youtube.com/watch?v=8SAZthXjT5s The LEAPPS https://github.com/abrignoni

Duration:01:01:27

Ask host to enable sharing for playback control

All About The Latest CTFs, CFPs, C2C, & All The News For You To See

2/1/2024
Embark on an enlightening path as we meld the celebration of Black History Month with the dynamism of mobile forensics. This episode is a tribute not only to the past but a clarion call for the future, as we honor Annie Easley, the trailblazing NASA computer scientist, while also navigating the rapidly evolving landscape of digital investigation tools. As your guides, we unravel the intricacies of open-source forensics tools, and the necessity of test devices, ensuring your knowledge remains at the forefront of technological advancements. With a constant eye on professional growth, we're excited to share information about upcoming conferences, training and opportunities to sharpen your digital forensic skills. We share our experiences, opening doors for you to learn and grow right beside us. Our conversation takes a stimulating turn as we discuss the Rabbit R1, a new AI gadget that promises to redefine app interaction and its implications for data privacy. As we dissect the nuances of AI in fingerprint analysis, we invite you to journey with us through the maze of modern forensics, where even the uniqueness of fingerprints is called into question. As we wrap up, our passion for the subject matter shines through with the introduction of cutting-edge features in mobile forensics updates, and the vital role of resource management in our field. We laugh over the meme of the week but also reflect on the serious undertones it brings to the prioritization of forensic cases. Closing the session, we express our heartfelt gratitude for the engagement and support that fuels our podcast, leaving you with an anticipation for deeper discussions and discoveries in the episodes to come. Join us, and together, let's shape the narrative of digital forensics and its rich connection to history and innovation. Notes- Honoring Annie Easley-Black History Month Feb 2024 https://elective.collegeboard.org/annie-easley-computer-science-pioneer Testing and Validation https://www.hexordia.com/blog-1-1/unlock-rooting-pixel6a https://blog.d204n6.com/2020/08/setting-up-testing-lab-of-ios-and.html Paraben Forensic Innovation Conference https://pfic-conference.com/ Free Android Training from Belkasoft https://belkasoft.com/android-forensics-training Cellebrite Case to Closure Summit and Awards https://global-c2c-summit-2024.cventevents.com/event/ec371a30-107d-4ce4-8bad-44e331148339/summary https://cellebrite.com/en/c2c-summit-digital-justice-awards/ Magnet Virtual Summit/Capture the Flag https://magnetvirtualsummit.com/ https://magnetvirtualsummit.com/capture-the-flag/ Rabbit R1 https://www.theverge.com/2024/1/9/24030667/rabbit-r1-ai-action-model-price-release-date AI- Fingerprints Unique or Maybe Not? https://www.cnn.com/2024/01/12/world/fingerprints-ai-based-study-scn/index.html Layoffs Due to AI https://www.theverge.com/2024/1/14/24038397/google-layoffs-just-the-beginning Hidden Gem in iOS 17 https://www.linkedin.com/posts/luca-cadonici-41299b4b_ios-ipados-passcode-activity-7152770642168160257-VJ7C Android Auto Reboots https://www.bleepingcomputer.com/news/security/grapheneos-frequent-android-auto-reboots-block-firmware-exploits/ The LEAPPS https://github.com/abrignoni

Duration:01:07:06

Ask host to enable sharing for playback control

Insights, Insots, Inseyets!

1/18/2024
Get ready to navigate the complexities of digital forensics with the latest industry insights, as we shine a light on Cellebrite's recent rebranding journey. From the quirky 'EYE' twist in their new product names to the strategic significance behind the move, we've got it all covered in a dynamic discussion that promises to clarify and critique the changes afoot. Plus, we'll dive into how Cellebrite is contributing to the tireless work of child protection organizations, aligning tech advancements with noble missions. We will guide you through our thoughts relating to advertising effectiveness in the forensics domain, and why the quality work of forensic professionals trumps any single tool on the market. The art of communication from businesses about their products and the role of technology in boosting company progression is key. The conversation turns to the exciting potential of recent password recovery innovations from Arsenal Recon's Password Sledgehammer and new support for location based and messaging applications in the LEAPPs! As we wrap up, the discussion turns to the thrilling possibilities of Android device analysis and the ever-evolving policies of giants like Google. We're not just talking about the next big thing; we're living it, breathing it, and sharing our experiences with you. So plug in, turn up the volume, and prepare for an episode that’s as informative as it is engaging. Notes: Operation Find Them All- https://abcnews-go-com.cdn.ampproject.org/c/s/abcnews.go.com/amp/Business/wireStory/cellebrite-donates-ai-investigative-tools-nonprofits-find-missing-106321858 Magnet Forensics Acquires High Peaks Cyber- https://forensicfocus.com/news/magnet-forensics-acquires-high-peaks-cyber-further-bolstering-the-magnet-graykey-labs-research-team/ Arsenal Password Sledgehammer- https://arsenalrecon.com/products/arsenal-image-mounter/downloads Life360 Stark4N6- https://www.stark4n6.com/ Analysis of Android Settings During a Forensic Investigation- https://blog.digital-forensics.it/2024/01/analysis-of-android-settings-during.html Google Location Data News!- https://www.forbes.com/sites/cyrusfarivar/2023/12/14/google-just-killed-geofence-warrants-police-location-data/?sh=245f8f422c86 https://www.washingtonpost.com/technology/2023/12/14/google-maps-location-history/

Duration:01:04:16

Ask host to enable sharing for playback control

New Year, New Tools, New Ways of Thinking!

1/4/2024
Ever found yourself piecing together a complex jigsaw puzzle of digital evidence? That's precisely the journey we invite you to embark on in our latest episode packed with tools, tales, and tech. We're not just talking shop; we're handing you the magnifying glass to examine the intricacies of JSON files with JSON CRACK, and introducing a python tool to automate investigations involving Google Drive File Stream artifacts, DriveFS-sleuth. This episode is a testament to the craft of digital forensics, featuring a blog from Mattia at Zena Forensics that aides in answering the question, "Has the user ever used the XYZ application?". As we unpack the nuances of reverse engineering and celebrate the updates to Hexordia's Evanole, we're reminded that the heart of digital forensics beats to the rhythm of relentless inquiry and meticulous method. We delve into the advanced research and exploitation methodologies With Magnet GrayKey Labs and converse about the importance of these capabilities as well as validation. This is coupled with a live demonstration involving SEGB files and the data that can be overlooked without research and the validation of multiple tools. Raise your glasses—here's to the exuberant spirit of learning and the relentless pursuit of truth that defines our community. So, are you ready to elevate your understanding of the digital landscape and smash those New Year's resolutions? Join us, and let's make 2024 a year of 4K clarity—in forensics and beyond! Notes: JSON Crack- https://jsoncrack.com/ DriveFS Sleuth — Your Ultimate Google Drive File Stream Investigator! https://amgedwageh.medium.com/drivefs-sleuth-investigating-google-drive-file-streams-disk-artifacts-0b5ea637c980https://github.com/AmgdGocha/DriveFS-Sleuth Advanced Research and Exploitation Methodologies With Magnet GRAYKEY Labs https://www.magnetforensics.com/blog/advanced-research-and-exploitation-methodologies-with-magnet-graykey-labs/ Has the user ever used the XYZ application? https://blog.digital-forensics.it/2023/12/has-user-ever-used-xyz-application-aka.html Evanole New Year Reveal! https://www.hexordia.com/evanolece

Duration:01:26:23

Ask host to enable sharing for playback control

Christmas Miracle: Android Memory Forensics. Doing what we didn't know was possible.

12/14/2023
Ever thought about the thin line between privacy and morality? Well, join us, , as we deep-dive into the ethical complexities surrounding this issue in today’s digital age. We bring to you exciting updates from a recent workshop in Panama, where enlightening exchanges with digital forensics experts from all over the world were had. Our exploration takes us through the workings of XRY and XRY Pro, as well as RAMDCoder, a game-changer in analyzing memory dumps from Android devices. We'll show you just how to navigate this tool, offering a glimpse into the future with the upcoming updates that promise to revolutionize device profiling. Intriguing, isn't it? Get ready as we take on mobile device forensics, focusing on the Samsung Galaxy S21 Ultra, and the treasure trove of data within its RAM. Learn from our experiences, including how we recovered from missing a crucial step in the extraction process. Oooops user error strikes again! As we wrap up, we'll discuss phishing attacks and the crucial role organizations play in preventing them. We believe in the power of research and validation, especially in the digital forensics field. We’ll also share insights from Jessica Hyde of Hexordia, underscoring the importance of peer-reviewed research in our field. Get a good laugh as we humorously compare Apple to Darth Vader, highlighting the challenges they present for forensic examiners. SEGB for the WIN! This is an episode that you will not want to miss! Notes: Chat encryption: A moral responsibility or a moral abdication? https://arstechnica.com/tech-policy/2023/12/meta-defies-fbi-opposition-to-encryption-brings-e2ee-to-facebook-messenger/ What makes epoch timestamps tick? https://www.cclsolutionsgroup.com/post/what-makes-epoch-timestamps-tick CheatSheet: https://assets-global.website-files.com/5f02f2c93eab87a6ea84e2f3/656da27da36e0c5cd1715d8a_EpochCheatsheet.pdf MSAB XRY: https://www.msab.com/ BrowserState.db last_visited_time? https://doubleblak.com/beta/browserstate SEGB Parsers! https://github.com/cclgroupltd/ccl-segb

Duration:01:14:38

Ask host to enable sharing for playback control

What To Expect When You Are Expecting a Digital Forensics Class, Two Hardware Solutions, One Neat Tool Capability For Windows, and a Partridge in a Pear Tree.

11/30/2023
Get ready to journey into the world of digital forensics as we share our insights on the crucial art of utilizing a diverse range of tools. A single tool just won't cut it, and reliance on just one could cause you to miss out on important finds. We also give our listeners the floor, inviting you to voice your thoughts on the IACIS Advanced Mobile Device Forensics class, and the topics you'd love to see covered. How do you feel about forensic extraction tools? We dissect unique features of tools like duplicators, TX1, and Atrio, and dive into latest updates from OpenText and ArcPoint Forensics. These updates have made it possible to create Android and iOS backups using duplicators, a game changer in the field. With Atrio, we open up an intriguing discussion about their forensic triaging and AI capabilities. We discuss the role of AI in identifying CSAM and brainstorm ways to enhance the tooling. We share our own learning experiences from various classes, highlighting the absolute necessity of continual learning and outside research in this ever-evolving field. We also explore the features and potential of Arsenal, a digital forensics tool which aids in mounting and virtualizing E01 images. The unique capabilities provided by Arsenal to bypass the password to a Windows logon screen and access DPAPI-protected data is a must try! Whether you're a seasoned expert or just dipping your toes in the water, this episode is sure to pique your interest in the vast world of digital forensics. Notes- IACIS Advanced Mobile Device Forensics (AMDF) https://iacis.com/training/amdf-advanced-mobile-device-forensics/ OpenText Duplicator Update https://www.youtube.com/watch?v=L3qGa7H6NBs ArcPoint Forensics https://www.arcpointforensics.com/ DFIR Diva- https://dfirdiva.com/ Arsenal Recon- https://arsenalrecon.com/ Hexordia Mobile Data Structure-Virtual Live Training- https://academy.cyber5w.com/courses/hexordia-mobile-data-structures-dec-2023

Duration:01:04:33

Ask host to enable sharing for playback control

Vendor Transparency, Mobile Device Extractions, & Brigs Learns the Difference Between Validation and Verification

11/16/2023
We are back with a mind-boggling conversation about our experiences, and the ever-evolving face of digital forensics. We're going to share some personal anecdotes, enlighten you about the changing UNIX epoch timestamp, and even discuss how we cope with the advancing age in this fast-paced world. In the digital world, knowledge is power. We will reveal an amazing cheat sheet from Cellebrite that will simplify your understanding of extractions and the data that they yield. We’ll also delve into the concept of tool transparency, highlighting the pros and cons that come with it. We’ll help you understand why it's crucial to be informed about known bugs in a tool, and navigate the complex process of bug reporting. We’re going to discuss why it's essential to have multiple tools in your arsenal for data validation, and how manual validation is a must when it relates to key evidence. As we wrap up, we'll talk about the implementation of ALEAPP and iLEAPP in Paraben and its capabilities to choose artifacts to report on. To add some levity, we'll also share a humorous meme that perfectly captures the essence of the repercussions of failing to validate your digital data. So, prepare to embark on a journey that’s bound to make you rethink everything you know about data extraction and tooling analysis. Notes- Scholarship Reminders -https://www.iacis.com/will-docken-scholarship/ -https://www.iacis.com/womens-scholarship/ -https://www.magnetforensics.com/blog/2023-magnet-forensics-scholarship-program-apply-today/ Cellebrite Data Extraction CheatSheet -https://www.linkedin.com/posts/heather-mahalik-cellebrite_data-extraction-cheatsheet-activity-7125138491805462528-l5-5/ -https://cellebrite.com/en/episode-23-i-beg-to-dfir-data-extractions-explained-ffs-afu-bfu-advanced-logical-digital-forensics-webinar/ Paraben -https://paraben.com

Duration:01:03:46

Ask host to enable sharing for playback control

Digital Forensics, Moot Court, and New Tool. Come Down the RabbitHole ™ with Us!

11/2/2023
Curious about how digital forensics can unlock the secrets held by your tech devices? Join us as we shine a light on RabbitHole, an ingenious tool devised by Alex Caithness of CCL Solutions Group. This episode is sure to be a revelation, as we delve into this unique amalgamation of data format viewers. The plot thickens as we, act as your guides, to dissect the complexities of the RabbitHole - reparse feature, the free form report builder, and the remarkable ability to extract data from various sources. We step away from the tech talk for a moment to underline the crucial role of Moot Court in nurturing digital forensics examiners. We debate the need for a supportive environment that allows mistakes, honing professionals in the field. We discuss the highlights of what qualities are needed to shape a great witness and throw light on two free cybersecurity courses related to expert witness testimony. Don't miss our discussion on the new additions to iLEAPP! Media events from the knowledgeC database and connecting Discord attachments to message threads. Finally we discuss changes to Shellbag artifacts that were implemented in Windows 11 updates as outlined by 13Cubed, and the meme of the week! So, are you ready to tumble down this fascinating digital RabbitHole with us? Notes: CCL Solutions-RabbitHole- https://www.cclsolutionsgroup.com/forensic-products/rabbithole Courtroom Testimony Trainings- CYBRARY.IT- https://cybrary.it/course/dfir-investigations-and-witness-testimony NW3C-DF501 Expert Witness Testimony - Digital Forensic Examiners- https://www.nw3c.org/UI/CourseCatalog.html Connecting Discord Attachments to Message Threads- https://bluecrewforensics.com/2023/10/30/connecting-discord-attachments-threads-sdwebimage-library/ 13 Cubed: An Important Change to ShellBags - Windows 11 2023 Update! https://www.youtube.com/watch?v=M1nyMIu1Y18&t=4s Shellbags Explorer by Eric Zimmerman https://ericzimmerman.github.io/#!index.md

Duration:01:09:27

Ask host to enable sharing for playback control

New iOS Geolocation Artifacts, iOS Location Shenanigans, Time Zones, Do You Realm?, and The Meme Of The Week!

10/18/2023
Ever wondered how to make the most of data analysis tools like iOS Spotlight Store DB and Realm Databases? We're here to share our experiences, tips, and favorite resources to help you elevate your data extraction skills. Join us, as we discuss the amazing work of Yogesh Khatri, the creator of a game-changing parser and as we guide you through the vast world of data extraction and analysis techniques. We begin our journey with iOS Spotlight Store DB, revealing the treasures hidden within and how to use Yogesh's parser to uncover its secrets. We then navigate through Realm Databases, sharing our encounters with data stores and tools for parsing extracted data. We also share our personal workflow process, granting you a peek into our data analysis strategies. But we're not done yet. Our adventure takes a detour towards Google Maps Geolocation Artifacts, where we highlight the amazing work of The Binary Hick and his research of the audio files and geolocation points related to navigation. Finally, we explore the nuanced art of analyzing timestamps and locations in images, revealing a fascinating intersection of data and intent. We share how we use Python scripts, manual offsets, and more to make data time-zone aware. Wrapping up our discussion, we emphasize the vitality of research in data analysis and the role of code in automation. So, buckle up for a thrilling ride into the mesmerizing world of data extraction and analysis. You'll come out the other side armed with fresh insights and new tools at your disposal. Notes: iOS Spotlight store.db: https://github.com/ydkhatri/spotlight_parser Realm Databases: https://www.mongodb.com/docs/realm/studio/ The Binary Hick-Finding Phones with Google Maps: https://thebinaryhick.blog/2023/10/17/finding-phones-with-google-maps-part-1-android/ iOS Media Adjustments: https://www.doubleblak.com/blogPosts.php?id=23

Duration:01:03:27

Ask host to enable sharing for playback control

FTK Mobile, Cellphone Forensics Tool Comparisons, and New Open Source Artifacts. Competition is Heating Up in the Mobile Forensics Space.

10/5/2023
Ready for the breakdown of the newest player in the mobile forensics field, FTK 8? This latest release includes a facelift, enhanced mobile support, and a plethora of supportive features for mobile devices. From app-specific mobile artifacts like Discord, Facebook, Kik, Snapchat, WhatsApp, to calls, conversations, contacts, MMS, and SMS, FTK 8 is geared up. Plus, its Smart View tab provides new mini and super timeline features as well as enhancements to their multimedia view. Our chat extends beyond the merits of FTK 8 to the realm of portable cases and the case review aspect of all digital forensic tools. Uncover how the right network setup can boost review speed and why understanding the limitations of portable cases is crucial for examiners and stakeholders alike. We also discuss how focusing on artifact-based reviews, can enhance efficiency. But that's not it! We also delve into the importance of data validation and why a user-friendly interface is key for people reviewing and examining cases. Interested in hearing about comparative analysis? Tune in for an in-depth discussion about comparing the capabilities of one forensic tool to another and the possible outcomes of such a competitive assessment. New to iLEAPP? We've got you covered! Together, we unearth new artifacts like the last car connection and voicemail artifacts, even recently deleted (trashed) voicemail - critical elements that will revolutionize your review process. Understanding the significance of analyzing torrent data encoded in Bencode, linking media on a device to files used to acquire that media, is another key takeaway from our conversation. To wrap things up, we express our heartfelt gratitude to you, our listeners and thank you for joining us on this fascinating journey into the world of digital forensics. Notes: FTK 8 https://www.exterro.com/ftk-8-0 iOS 15 Image Forensics Analysis and Tools Comparison Project- https://blog.digital-forensics.it/2023/09/ios-15-image-forensics-analysis-and.html LEAPPS https://github.com/abrignoni

Duration:01:03:47

Ask host to enable sharing for playback control

Navigating the Digital Forensics Maze: Insightful Discussions and Valuable Resources

9/21/2023
Stay tuned as we navigate the mesmerizing maze of digital forensics, sharing insights that you wouldn't want to miss! We kick-start this thrilling journey with a sneak-peek into the Regional Computer Forensics Lab in Boston. The fun doesn't stop here as we also delve into the exhilarating Cellebrite Capture the Flag challenge and touch upon the awe-inspiring Difference Makers Awards. We then turn to the indispensable resources for those wishing to take on the digital forensics world. From the empowering IACIS Women in Law Enforcement Scholarship to the unique Magnet Forensics Scholarship, we've got you covered. Don't miss our take on the complimentary Belkasoft iOS Forensics Course and DFIR Artifact Museum. Plus, we'll guide you through using the intriguing Eric Zimmerman's SQLECmd and Timeline Explorer. Finally, we discuss the invaluable act of giving back to the digital forensics community. We share the secrets of adjusting to corporate culture, continuing education, and the pivotal role of mentoring. We even touch upon the remarkable Digital Forensics Intern Program by Notre Dame. So, tune in as we unravel the complex world of digital forensics. What's more? We've got some valuable advice for newbies waiting at the end. Get ready to embark on this digital journey with us! Notes: Difference Makers Awards 2023: https://www.sans.org/about/awards/difference-makers/ IACIS Scholarship: https://www.iacis.com/will-docken-scholarship/ IACIS Women's Scholarship: https://www.iacis.com/womens-scholarship/ Magnet Scholarship: https://www.magnetforensics.com/blog/2023-magnet-forensics-scholarship-program-apply-today Belkasoft iOS Free Training: https://belkasoft.com/ios-forensics-training Eric Zimmerman's SQLECmd: https://ericzimmerman.github.io/#!index.md DFIR Artifact Museum: https://github.com/AndrewRathbun/DFIRArtifactMuseum J & L Forensics Blog: https://jnl4n6.com/2023/09/13/new-to-cyber-preston-mcnair/

Duration:01:01:39

Ask host to enable sharing for playback control

Leveling Up in Digital Forensics: Strategies, Tools, and the CSAM Debate

9/7/2023
Looking to level up your expertise in digital forensics? We promise this episode will arm you with actionable insights, strategies, and tools to sharpen your skills. Our conversation covers a wide spectrum of topics from the importance of conferences to the rising debate surrounding Apple's proposed scanning for CSAM material. We peel back the layers on forensic labs, discussing how to measure effectiveness, the role of leap artifacts in investigations, and the critical need for continual learning and collaboration. In this episode, we navigate the various pathways to proficiency in digital forensics – whether that's through formal education like criminal justice degrees, on-the-job training, or the value of certifications. We explore the growing need for standardization in the field and the relevance of experience and research in establishing credibility. And let's not forget about Ryan Benson's Unfurl tool – we discuss its capabilities in breaking down URLs, a vital tool for digital forensics cases. Lastly, we delve into the contentious subject of Apple's decision not to scan for CSAM material. We analyze the potential implications of such a move and the concerns raised by the Heat Initiative in their recent letter. Apple's reported cyber tip line reports are also put under the spotlight as we compare it to Google's numbers. From seasoned professionals to those just starting out, this episode promises to challenge your thinking, ignite debates, and bring you valuable tips and insights to help you stay ahead in the digital forensics field. Tune in for an enlightening and inspiring session! Notes: https://github.com/abrignoni/iLEAPP https://dfir.blog/unfurl/ https://www.documentcloud.org/documents/23933180-apple-letter-to-heat-initiative

Duration:01:09:57

Ask host to enable sharing for playback control

Inaugural Episode - 0

8/25/2023
Hear the latest news on digital forensics with your hosts Alexis "Brigs" Brignoni & Heather Charpentier for the week of August 25, 2023. Episode Notes: https://thebinaryhick.blog/2023/08/13/android-airtags-part-ii/ https://www.hexordia.com/blog-1-1/io-plus-s-tool-release https://www.sans.org/blog/six-steps-to-successful-mobile-validation-paper/

Duration:00:54:52