Extreme Hexjumping Video
July 29, 2010 by Lee Whitfield
Filed under Methodologies & Best Practices
A few weeks ago I posted a picture of Martin Westman just before he jumped out of a plane while hex-dumping a phone. He has been in touch and sent a link to the Youtube video. I asked Martin if he has any more plans to do things like this in the future and he seems to have some nice ideas… I’m not going to spoil it, you’ll just have to watch out for them.
Fantasy Forensicator League
July 29, 2010 by Lee Whitfield
Filed under Uncategorized
I had a thought a few days ago that I’d like to share. Please don’t take me seriously, I have no intention of starting this up, just thought it would be funny.
With Football (soccer) season just around the corner I have been bombarded with requests to join many different fantasy football leagues. While I was deleting one such email a thought entered my mind. Why not start a Fantasy Forensicator League?
The idea is quite simple, as with other fantasy leagues you’d get a certain amount of virtual cash with which to build your elite team of forensicators. You could choose, lets say, five people to be on your crack squad. Points would be awarded for various accomplishments. I thought something like the following would be awesome:
Giving a presentation – 10 points
Writing a whitepaper/blog post – 5 points
Being on a podcast – 10 points
Releasing a new piece of software – 20 points
Appearing on local radio – 15 points
Appearing on national radio – 20 points
Appearing on local TV – 20 points
Appearing on national TV – 30 points
I’m sure there are loads more. What can you think of?
Episode 31 – They try to send me off to DC but I say R-M-O
July 21, 2010 by Lee Whitfield
Filed under Podcast Episodes
Today we cover Paul Sanderson’s blog post on forensic practitioners, how the current financial situation is affecting forensics, tips for graduates trying to get into the field, the SANS Forensic Summit, and the Forensic 4cast Awards.
Episode 31 - They try to send me off to DC but I say R-M-O [77:27m]: Play Now | Play in Popup | DownloadSANS Forensic Summit
July 13, 2010 by Lee Whitfield
Filed under News
Last week I attended the SANS Forensic Summit in Washington DC. What an experience it was. I got to meet many people for the first time including Mark McKinnon, Joe Garcia, Brian Moran, and Rob Lee (if I listed everyone people would get bored reading, sorry).
The event itself was fantastic I was able to watch presentations given by some of the biggest and best in the field today including Jesse Kornblum, Harlan Carvey, Troy Larson and many others. Mark and I also had the opportunity to give our presentation on Volume Shadow Copies and show a little of what Shadow Analyser will do once we release it. We seem to have gotten some positive feedback from it too. Thanks to the presentation I was even allowed to walk away with on of the SANS ‘Lethal Forensicator’ RMO. It is very nice and more people should carry them.
On the Thursday night we held the second annual Forensic 4cast Awards, the winners have already been listed on here so I won’t do it again but I will say that it was well attended and a lot of fun. I’m working on providing some more footage of the event to post online.
All in all this whole thing was awesome. Well worth attending. Next year’s summit will be moving from Washington DC to Austin, Texas. As you have nearly a year until then it is worth your time making sure that you can attend.
On a side note, while we were in DC Mark and I had the chance to go to see the Iwo Jima memorial and the Arlington Cemetery thanks to our friend Jerod. While the visit didn’t have anything to do with forensics I thought that I would share my feeling about this place.
It is both tragic and inspiring at the same time. Seeing the rows upon rows of graves of those who faithfully served their country until the end humbles me. I think of their contributions to the world, for their shortened lives, and feel not only gratitude but also a deep sense that I need to do more. Why should people like that waste their lives for me to be satisfied with mediocrity? No. I will make sure that, whatever I am and whatever I become, I’ll strive to be the best so that people like them did not, and will not, die in vain.
Now, this DOES apply to forensics. There are many in this field who continue to ‘coast’. They do their work and go home. While this is admirable I fear that it is not enough for the future. We should be actively engaged in researching and presenting our research so that all in the field can benefit from our cumulative knowledge. Let’s not wait for someone else to make the big discoveries, let’s jump in and do it ourselves.
Forensic 4cast Awards – Results #forensicsummit
July 9, 2010 by Lee Whitfield
Filed under News
Last night we held the second annual Forensic 4cast Awards at the SANS Forensic Summit in Washington DC. It was tremendous fun and was broadcast live by SANS on their website. If you want to see their coverage of the event you can do so here https://www.sans.org/webcasts/live-forensic-4cast-awards-ceremony-93653. I will be posting video of the event in the next few days.
The 2010 winners are listed below:
Outstanding Contribution to Digital Forensics – Individual
Rob Lee
Outstanding Contribution to Digital Forensics – Company
SANS
Best Digital Forensics Blog
SANS
Best Digital Forensics Book
Windows Forensic Analysis 2E
Best Digital Forensic Podcast
Inside the Core
Best Computer Forensic Hardware
Tableau T8
Best Computer Forensic Software
FTK Imager
Best Phone Forensic Hardware
Cellebrite UFED
Best Phone Forensic Software
Mobilyze
Digital Forensic Investigator of the Year
Nick Furneaux
Lifetime Achievement
Craig Wilson
4cast Awards – Votes Close Tomorrow
July 5, 2010 by Lee Whitfield
Filed under News
The Forensic 4cast Awards will take place on Thursday evening in Washington DC (have I mentioned that before?) and the voting closes tomorrow. If you have not yet taken the time to place your votes please do. Most of the voting is EXTREMELY close and one or two votes can make all the difference.
You can place your votes here:
http://forensic4cast.com/2010/06/16/forensic-4cast-awards-2010-voting-is-open/
Happy voting!
Shadow Analyser Article by The Register
July 5, 2010 by Lee Whitfield
Filed under News
Greetings all.
As you may (or may not) know Mark McKinnon, Disklabs and I are working together on a project that we call ‘Shadow Analyser’. We have put a lot of time and effort into this and hope to have it released very soon.
This last week The Register published an article about our upcoming software. If you have a few minutes it is well worth a read. It is funny to see my own name being published in such a reputable web page. Maybe I really AM the Amy Winehouse of digital forensics, then again…
Anyway, here’s the link:
http://www.theregister.co.uk/2010/06/30/shadow_analyser_digital_forensics/
Extreme Hex Jumping
July 4, 2010 by Lee Whitfield
Filed under Uncategorized
Meet Martin Westman. He works for Micro Systemation (the creators of XRY and XACT). The picture below is taken from a video in which Martin attempts to perform a hex dump of a Nokia phone using Micro Systemation’s modified Panasonic toughbook that is strapped to his chest while, wait for it…

JUMPING OUT OF A FREAKING AEROPLANE!!!
I’m trying to get hold of the video and will post it as soon as I have it. But it raises several questions; Have any of you tried to do anything to liven up your day-to-day forensics work? Will this spur on more radical behaviour? What other extreme forensics can you think of?
Sneak Peak at the Forensic 4cast Awards
June 24, 2010 by Lee Whitfield
Filed under News
Want to know what the awards will look like? I have to admit, these do look pretty darn cool. I think they are very ‘Geek Chic’.
Anyway, here they are. Feedback is appreciated and, if you’re in contention for an award this year – how much more do you want one now? If you’re not in contention for an award – go out and convince people to nominate and vote for you in 2011.
And yes, that is pin-point accurate laser engraving. Nice.
Episode 30 – Amy Winehouse is no Forensic Guru
June 23, 2010 by Lee Whitfield
Filed under Podcast Episodes
The Forensic 4cast Awards, AccessData merges with CT summation, Google may face prosecution over wiretapping laws, and we talk about what to do if you child porn on your company server.



