How to Scan a non OS Drive or Partition

May 28, 2019

When making decisions on scene it is critically important for an investigator to scan and analyze the Operating System Drive or Partition, or what is commonly referred to as the C:\ drive. ADF digital forensic software tools give investigators out-of-the-box Search Profiles designed to quickly scan and analyze OS partitions with targeted paths that would not be present on a non OS partition.

If you come across a non OS drive or partition, a storage partition, or external storage drive, instead of using the built-in Comprehensive Search Profiles, you can create a Custom Search Profile for non operating system drives using Digital Evidence Investigator®

Read More

Scan an iOS Device with Mobile Device Investigator

May 23, 2019

Learn how to quickly scan an iOS smartphone or tablet device in this 2 minute short "How To" video created by Rich Frawley, our Digital Forensic Specialist and Trainer.  Rich will walk you through how to attach and scan an iOS device with Mobile Device Investigator® (MDI) using an iPhone 7.

Read More

Collect RAM on a Live Computer

April 2, 2019

When conducting digital forensic investigations that involve live (up and running) computers, it is imperative to collect volatile memory so that all your bases covered and so that no vital evidence is lost.  A live analysis conducted in the correct manner will yield the results you are looking for in your investigation.  It has become commonplace and an accepted practice to collect data from a live computer, especially in cases of child exploitation. ADF software makes it easy for you to perform a RAM capture it in the proper manner with as little intrusion as possible.

Read More

How to Conduct a Live Forensic Scan of a Windows Computer

February 22, 2019

Learn how to conduct a Windows live scan with ADF Solutions Digital Evidence Investigator.  Two USB ports are required to complete a scan, one for the Collection Key and one for the Authentication Key, once the scan has started the Authentication Key can be removed. A USB hub may be used in cases where the target computer only has one USB port. 

When running a live scan from a Collection Key it is possible to create a RAM dump of the computer. RAM dumps can then be analyzed with appropriate software (e.g. Volatility). 

Read More

Meet Phill Moore Author of This Week in 4N6 and Think DFIR

February 12, 2019

If you haven’t yet met Phillip Moore and you’re in the digital forensics or incident response fields, you’re likely to at least know him from one of his top forensic blogs:

Read More

Why We Love Forensic Triage and You Should Too!

January 21, 2019

In 2009, the number of backlogged digital evidence requests in publicly funded forensic crime labs was 1,600. By the end of 2014, that number had risen to 7,800. While that's tiny in comparison to the total number of backlogged evidence requests (over 570,000 in 2014!), every one of those requests is associated with a case that affects real people. This is why we love forensic triage, and why you should too.

Read More

Digital Forensic Search Profiles

August 31, 2018

With eleven (11) out-of-the-box Search Profiles inside Digital Evidence Investigator® (DEI), the ADF Digital Forensic team has created software that enables investigators and forensic examiners to obtain the digital evidence needed in a wide variety of evidence collection situations. 

Read More

A Typical Child Exploitation Case Solved by ADF DEI

August 8, 2018

The investigation began after images consistent with child pornography were uploaded to a social media platform.  A search warrant was executed at the residence and an on-scene forensic exam of all electronic media was completed by members of the State Police Computer Crime Unit.  Using ADF Digital Evidence Investigator®, investigators discovered images and videos of sexual abuse of an under age child and were able to identify a resident of the household as the suspect. Specifically, investigators located thumbcache images that resulted in identifying a female child that was being sexually abused and identified the suspect.

Read More

Get Triage & Digital Forensic News (once a month)

Posts by Tag

See all

Recent Posts

CustomButton
  • READY TO ACCELERATE YOUR DIGITAL INVESTIGATIONS?