EVTrieve – Windows Event Logs

I thought it was time to share some of the work undertaken in my University dissertation several years ago now. My project focused on Windows Event logs and in particular the artefacts and analysis techniques associated data breach/compromise investigations. Continue reading

Tagged , ,

Big Brother Forensics

Great post from Chat Tilbury (@chadtilbury) in relation to device tracking. The post delves into HTTPS POST requests relating to the Google’s geo-location services called Google Latitude. Responses from the JSON interchange contains details of the location from the source of the request.

Looking forward to part 2.

Tagged ,

Nero BackItUp

Nero and the Nero Multimedia Suite are a prominent software application and for that reason of interest in forensic cases. The Nero Multimedia package has evolved considerably over the years from a simple CD/DVD burning solution to a collection of products including multimedia authoring, editing and also backup. Continue reading

Tagged , ,

Computer Forensic Students Take On A Car

A team of University students from Southern Oregon University getting some hands on forensic experience. They were tasked with searching an exploded car for digital media, whatever they recovered they seized and examined forensically.

Great hands on experience.

Tagged

Quick look at iOS 5

This week sees Apple deliver some eagerly awaited products including the iPhone 4S, iCloud and iOS version 5. Naturally I was curious to take a quick peak at any major changes and what impact they may have on our forensic investigations.
Continue reading

Tagged , , ,

eBay Toolbar in Forensics Investigations

The analysis of artefacts associated with eBay is something we see regularly, in particular fraud investigations. One such resource is the eBay Toolbar, which is designed to keep track on items you are watching, selling or bidding on. Continue reading

Tagged , ,