News

This news feed is supplied with permission from the Forensic Focus website.To read more on any news snippet click on its headline.

Proposed UK law aims to identify suspects by IP address

A law forcing firms to hand details to police identifying who was using a computer or mobile phone at a given time is to be outlined by Theresa May.

The home secretary said the measure would improve national security.

As part of the Counter-Terrorism and Security Bill, providers would have to retain data linking devices to users.

But campaigners warned it could see the revival of the so-called “snoopers’ charter” – a previous attempt to bring in wide-ranging web monitoring powers…

Read (BBC)Posted: 24 November 2014

Discover Evidence on PCs and Mobile Devices with Belkasoft Evidence Center 2015

Belkasoft have released a major update to their flagship forensic tool, Belkasoft Evidence Center. With the version 7.0, Evidence Center becomes a true all-in-one forensic solution, reliably analyzing evidence from all imaginable sources.

Evidence Center is well known for its ability to easily find and analyze 500+ types of evidence (such as documents, emails, chats, system and registry files, etc.). What makes this new release different is the ability not just to analyze supported apps and formats, but also to perform low-level investigations of any piece of evidence on a suspect’s device or image.Posted: 20 November 2014

Oxygen Forensic® Suite Adds Support for Multi-SIM Android OS devices & MBK files

Oxygen Forensic® Suite update with enhanced support for dual-SIM smartphones, iOS photo stream support and Nokia MBK backup extraction. than 500 new smartphone models are supported including recent flagships from Sony, BlackBerry, Nokia and Samsung. A host of new and updated Android and iOS applications are added to the list, including support for the latest versions of eBay, Swarm, Trip Advisor, ChatON, Foursquare, Facebook and Facebook Messenger.

Enhanced dual-SIM Android devices support helps investigators determine which SIM card was user to place or receive calls and SMS messages, while support for Apple’s “My Photo Stream” option allows identifying photos taken with other devices linked to a certain Apple ID. Nokia MBK extraction adds yet another acquisition source for Nokia Ash backups, enabling forensic experts to extract contacts, messages, calendar events, notes, tasks and other available information. The latest version of Oxygen Forensic® Suite adds support for more than 500 devices running Android, BlackBerry 10 and Windows Phone.Posted: 19 November 2014

Paraben Releases Device Seizure v6.8 and P2 Commander v3.7

Paraben has announced the release of Device Seizure v6.8 and P2 Commander v3.7. Here is what is new with these flagship tools at Paraben.

Device Seizure v6.8

* Added support up to and including iOS 8.1
* Added new Android acquisition methods improving overall model support of thousands of new devices
* New Android Physical support through version 4.3
* Improved deleted data recovery from iOS devices
* Removed duplicate records from deleted data recovery
* Faster iOS acquisition times
* Added support for data parsing of the latest versions of supported apps
* Added WhatsApp data parsing for iOS and Android
* Added Skype data parsing for Android
* Added support for 8 LG and Samsung feature phonesPosted: 18 November 2014

Forensic Focus Forum Round-Up

Welcome to this round-up of recent posts to the Forensic Focus forums.

The UK Forensic Science Regulator has issued a draft guidance document for digital forensics method validation.

Forum member UnallocatedClusters gives a description for the data found in iNode files for a non-technical audience.

James Somers has developed a tool which allows users to playback and analyse any Google Docs they have permission to edit.

Which TrueCrypt alternatives do you recommend? Let us know on the forum.

Forum members recommend OSINT training providers.

Is there an HDD dock that allows simultaneous access to the same drive from both Linux and Windows?

Can you recommend an external 2-bay RAID enclosure for an analyst’s flightcase?Posted: 17 November 2014

EnCase® Webinar Features SANS Lead Instructor Rob Lee

A Triage and Collection Strategy for Time-Sensitive Investigations
November 19 at 11:00 a.m. Pacific

With the average hard drive now averaging one terabyte in size, the fallout from the explosion of user-created data has become an overwhelming volume of potential evidence that law-enforcement and corporate investigators spend countless hours examining. Lee will demonstrate a triage and collection strategy that can significantly reduce the amount of digital information you collect, revealing critical evidence faster, including:

• Identify the folders and files that often contain key insights
• Triage effectively to reduce the time spent sifting through collected information
• Eliminate backlogs by over 80 percent by efficiently culling case data

Presenters:
• Rob Lee, SANS Digital Forensic Curriculum Lead, the SANS Institute
• Robert Bond, Product Marketing Manager, Forensics, Guidance Software

Click here to register: www.encase.com/conducting-triagePosted: 13 November 2014

How To Use IEF and Cellebrite to Find More Evidence On iOS Devices

We previously shared a blog post explaining how to find more mobile evidence on Android devices using IEF and Cellebrite, together. We’ve also put together a workflow to help you recover more in your iOS investigations.

Here are step by step instructions on how to use IEF and Cellebrite together to acquire and analyze iOS devices, including physical and logical acquisitions, to get more mobile evidence.

Read (Magnet Forensics)Posted: 13 November 2014

Final 2014 Nuix Investigations Training Classes – UK & East Coast US Dates

Whether you’re new to Nuix software or you’re a power user, Nuix offers training paths to maximize your skillset and keep you up-to-date with the latest workflows and technologies.

By training and getting certified in Nuix Investigations software, you’re becoming an expert in the world’s fastest and most scalable technology on the market for processing large, complex sources of data. Learn from the best and build your career with Nuix.Posted: 11 November 2014