
Sign up to save your podcasts
Or


Send us Fan Mail
We are back with a mind-boggling conversation about our experiences, and the ever-evolving face of digital forensics. We're going to share some personal anecdotes, enlighten you about the changing UNIX epoch timestamp, and even discuss how we cope with the advancing age in this fast-paced world.
In the digital world, knowledge is power. We will reveal an amazing cheat sheet from Cellebrite that will simplify your understanding of extractions and the data that they yield. We’ll also delve into the concept of tool transparency, highlighting the pros and cons that come with it. We’ll help you understand why it's crucial to be informed about known bugs in a tool, and navigate the complex process of bug reporting. We’re going to discuss why it's essential to have multiple tools in your arsenal for data validation, and how manual validation is a must when it relates to key evidence.
As we wrap up, we'll talk about the implementation of ALEAPP and iLEAPP in Paraben and its capabilities to choose artifacts to report on. To add some levity, we'll also share a humorous meme that perfectly captures the essence of the repercussions of failing to validate your digital data. So, prepare to embark on a journey that’s bound to make you rethink everything you know about data extraction and tooling analysis.
Notes-
Scholarship Reminders
-https://www.iacis.com/will-docken-scholarship/
-https://www.iacis.com/womens-scholarship/
-https://www.magnetforensics.com/blog/2023-magnet-forensics-scholarship-program-apply-today/
Cellebrite Data Extraction CheatSheet
-https://www.linkedin.com/posts/heather-mahalik-cellebrite_data-extraction-cheatsheet-activity-7125138491805462528-l5-5/
-https://cellebrite.com/en/episode-23-i-beg-to-dfir-data-extractions-explained-ffs-afu-bfu-advanced-logical-digital-forensics-webinar/
Paraben
-https://paraben.com
Send us Fan Mail
Curious about how digital forensics can unlock the secrets held by your tech devices? Join us as we shine a light on RabbitHole, an ingenious tool devised by Alex Caithness of CCL Solutions Group. This episode is sure to be a revelation, as we delve into this unique amalgamation of data format viewers. The plot thickens as we, act as your guides, to dissect the complexities of the RabbitHole - reparse feature, the free form report builder, and the remarkable ability to extract data from various sources.
We step away from the tech talk for a moment to underline the crucial role of Moot Court in nurturing digital forensics examiners. We debate the need for a supportive environment that allows mistakes, honing professionals in the field. We discuss the highlights of what qualities are needed to shape a great witness and throw light on two free cybersecurity courses related to expert witness testimony.
Don't miss our discussion on the new additions to iLEAPP! Media events from the knowledgeC database and connecting Discord attachments to message threads.
Finally we discuss changes to Shellbag artifacts that were implemented in Windows 11 updates as outlined by 13Cubed, and the meme of the week!
So, are you ready to tumble down this fascinating digital RabbitHole with us?
Notes:
CCL Solutions-RabbitHole-
https://www.cclsolutionsgroup.com/forensic-products/rabbithole
Courtroom Testimony Trainings-
CYBRARY.IT-
https://cybrary.it/course/dfir-investigations-and-witness-testimony
NW3C-DF501 Expert Witness Testimony - Digital Forensic Examiners- https://www.nw3c.org/UI/CourseCatalog.html
Connecting Discord Attachments to Message Threads-
https://bluecrewforensics.com/2023/10/30/connecting-discord-attachments-threads-sdwebimage-library/
13 Cubed: An Important Change to ShellBags - Windows 11 2023 Update!
https://www.youtube.com/watch?v=M1nyMIu1Y18&t=4s
Shellbags Explorer by Eric Zimmerman
https://ericzimmerman.github.io/#!index.md
Send us Fan Mail
Ever wondered how to make the most of data analysis tools like iOS Spotlight Store DB and Realm Databases? We're here to share our experiences, tips, and favorite resources to help you elevate your data extraction skills. Join us, as we discuss the amazing work of Yogesh Khatri, the creator of a game-changing parser and as we guide you through the vast world of data extraction and analysis techniques.
We begin our journey with iOS Spotlight Store DB, revealing the treasures hidden within and how to use Yogesh's parser to uncover its secrets. We then navigate through Realm Databases, sharing our encounters with data stores and tools for parsing extracted data. We also share our personal workflow process, granting you a peek into our data analysis strategies. But we're not done yet. Our adventure takes a detour towards Google Maps Geolocation Artifacts, where we highlight the amazing work of The Binary Hick and his research of the audio files and geolocation points related to navigation.
Finally, we explore the nuanced art of analyzing timestamps and locations in images, revealing a fascinating intersection of data and intent. We share how we use Python scripts, manual offsets, and more to make data time-zone aware. Wrapping up our discussion, we emphasize the vitality of research in data analysis and the role of code in automation. So, buckle up for a thrilling ride into the mesmerizing world of data extraction and analysis. You'll come out the other side armed with fresh insights and new tools at your disposal.
Notes:
iOS Spotlight store.db:
https://github.com/ydkhatri/spotlight_parser
Realm Databases:
https://www.mongodb.com/docs/realm/studio/
The Binary Hick-Finding Phones with Google Maps:
https://thebinaryhick.blog/2023/10/17/finding-phones-with-google-maps-part-1-android/
iOS Media Adjustments:
https://www.doubleblak.com/blogPosts.php?id=23
Send us Fan Mail
Ready for the breakdown of the newest player in the mobile forensics field, FTK 8? This latest release includes a facelift, enhanced mobile support, and a plethora of supportive features for mobile devices. From app-specific mobile artifacts like Discord, Facebook, Kik, Snapchat, WhatsApp, to calls, conversations, contacts, MMS, and SMS, FTK 8 is geared up. Plus, its Smart View tab provides new mini and super timeline features as well as enhancements to their multimedia view.
Our chat extends beyond the merits of FTK 8 to the realm of portable cases and the case review aspect of all digital forensic tools. Uncover how the right network setup can boost review speed and why understanding the limitations of portable cases is crucial for examiners and stakeholders alike. We also discuss how focusing on artifact-based reviews, can enhance efficiency. But that's not it! We also delve into the importance of data validation and why a user-friendly interface is key for people reviewing and examining cases.
Interested in hearing about comparative analysis? Tune in for an in-depth discussion about comparing the capabilities of one forensic tool to another and the possible outcomes of such a competitive assessment.
New to iLEAPP? We've got you covered! Together, we unearth new artifacts like the last car connection and voicemail artifacts, even recently deleted (trashed) voicemail - critical elements that will revolutionize your review process. Understanding the significance of analyzing torrent data encoded in Bencode, linking media on a device to files used to acquire that media, is another key takeaway from our conversation. To wrap things up, we express our heartfelt gratitude to you, our listeners and thank you for joining us on this fascinating journey into the world of digital forensics.
Notes:
FTK 8
https://www.exterro.com/ftk-8-0
iOS 15 Image Forensics Analysis and Tools Comparison Project-
https://blog.digital-forensics.it/2023/09/ios-15-image-forensics-analysis-and.html
LEAPPS
https://github.com/abrignoni
Send us Fan Mail
Stay tuned as we navigate the mesmerizing maze of digital forensics, sharing insights that you wouldn't want to miss! We kick-start this thrilling journey with a sneak-peek into the Regional Computer Forensics Lab in Boston. The fun doesn't stop here as we also delve into the exhilarating Cellebrite Capture the Flag challenge and touch upon the awe-inspiring Difference Makers Awards.
We then turn to the indispensable resources for those wishing to take on the digital forensics world. From the empowering IACIS Women in Law Enforcement Scholarship to the unique Magnet Forensics Scholarship, we've got you covered. Don't miss our take on the complimentary Belkasoft iOS Forensics Course and DFIR Artifact Museum. Plus, we'll guide you through using the intriguing Eric Zimmerman's SQLECmd and Timeline Explorer.
Finally, we discuss the invaluable act of giving back to the digital forensics community. We share the secrets of adjusting to corporate culture, continuing education, and the pivotal role of mentoring. We even touch upon the remarkable Digital Forensics Intern Program by Notre Dame. So, tune in as we unravel the complex world of digital forensics. What's more? We've got some valuable advice for newbies waiting at the end. Get ready to embark on this digital journey with us!
Notes:
Difference Makers Awards 2023:
https://www.sans.org/about/awards/difference-makers/
IACIS Scholarship:
https://www.iacis.com/will-docken-scholarship/
IACIS Women's Scholarship:
https://www.iacis.com/womens-scholarship/
Magnet Scholarship:
https://www.magnetforensics.com/blog/2023-magnet-forensics-scholarship-program-apply-today
Belkasoft iOS Free Training:
https://belkasoft.com/ios-forensics-training
Eric Zimmerman's SQLECmd:
https://ericzimmerman.github.io/#!index.md
DFIR Artifact Museum:
https://github.com/AndrewRathbun/DFIRArtifactMuseum
J & L Forensics Blog:
https://jnl4n6.com/2023/09/13/new-to-cyber-preston-mcnair/
Send us Fan Mail
Looking to level up your expertise in digital forensics? We promise this episode will arm you with actionable insights, strategies, and tools to sharpen your skills. Our conversation covers a wide spectrum of topics from the importance of conferences to the rising debate surrounding Apple's proposed scanning for CSAM material. We peel back the layers on forensic labs, discussing how to measure effectiveness, the role of leap artifacts in investigations, and the critical need for continual learning and collaboration.
In this episode, we navigate the various pathways to proficiency in digital forensics – whether that's through formal education like criminal justice degrees, on-the-job training, or the value of certifications. We explore the growing need for standardization in the field and the relevance of experience and research in establishing credibility. And let's not forget about Ryan Benson's Unfurl tool – we discuss its capabilities in breaking down URLs, a vital tool for digital forensics cases.
Lastly, we delve into the contentious subject of Apple's decision not to scan for CSAM material. We analyze the potential implications of such a move and the concerns raised by the Heat Initiative in their recent letter. Apple's reported cyber tip line reports are also put under the spotlight as we compare it to Google's numbers. From seasoned professionals to those just starting out, this episode promises to challenge your thinking, ignite debates, and bring you valuable tips and insights to help you stay ahead in the digital forensics field. Tune in for an enlightening and inspiring session!
Notes:
https://github.com/abrignoni/iLEAPP
https://dfir.blog/unfurl/
https://www.documentcloud.org/documents/23933180-apple-letter-to-heat-initiative
Send us Fan Mail
Hear the latest news on digital forensics with your hosts Alexis "Brigs" Brignoni & Heather Charpentier for the week of August 25, 2023.
Episode Notes:
From the publisher's feed
A podcast by digital forensics examiners for digital forensics examiners. Hear about the latest news in digital forensics and learn from researcher interviews with field memes sprinkled in.