January 19th, 2011 by lhaas                              

viaForensics announces four upcoming mobile forensics training sessions

viaForensics will hold four mobile forensics training sessions in the Chicago area covering Linux use in forensics, iPhone forensics, Android forensics and advanced mobile forensics.

Chicago, January 19, 2011 – viaForensics will hold four independent training sessions covering different topics related to mobile forensics in Oak Park March [...]

January 6th, 2011 by lhaas                              

Illinois Computer Forensic Examiners Meet-Up

Join viaForensics at the

Illinois Computer Forensic Examiners Meet-Up

January 27, 2011 @ 9:00 a.m.

Naperville Police Department Meeting Hall

350 Aurora Ave., Naperville, IL

Feature presentations include: Log2Timeline by Andrew Hoog, CIO of viaForensics F-Response by Matt Shannon, principal with Agile Risk Management LLC [...]

November 17th, 2010 by lhaas                              

Mobile Telephone Evidence: iPhone

From the Mobile Telephone Evidence blog:

Two questions:

1) How many ‘evidence’ handset reader tools can you name off the top of your head?

2) And how many of those tools extract and harvest data from iPhones?

In answer to question one we know we can at least identify thirteen (13) tools and [...]

November 15th, 2010 by lhaas                               1 comment

Updated iPhone Forensics white paper released

FOR IMMEDIATE RELEASE

Contact: Andrew Hoog Chief Investigative Officer viaForensics Phone: +1 312-878-1100 contact us

Updated iPhone Forensics white paper released

viaForensics has released an updated version of its groundbreaking iPhone Forensics white paper.

Chicago, November 15, 2010 – viaForensics has released an updated version of its free white paper on [...]

October 28th, 2010 by ahoog                              

Fixed The Sleuth Kit on Windows Server 2003

For some time now, I (and others) have had problems running The Sleuth Kit (TSK) on Windows Server 2003…in particular, I could not get fls to run.  Here’s a post I made to the sleuth-kit list from January 2010 with some follow up discussions:

http://old.nabble.com/problems-running-sleuthkit-on-Windows-Server-2003-x64-td27189560.html

If you try to run it from the [...]

October 6th, 2010 by lhaas                              

iPhone and Android Forensics Training

FOR IMMEDIATE RELEASE

Contact: Andrew Hoog Chief Investigative Officer viaForensics Phone: +1 312-283-0551 http://viaforensics.com/contact-us

iPhone and Android Forensics Training in Chicago

viaForensics is offering iPhone and Android Forensics training sessions in Chicago October 11th and 12th.

Chicago, October 6, 2010 –

viaForensics is offering cutting-edge mobile forensics training for both Android and iPhone [...]

August 25th, 2010 by ahoog                              

Howto setup headless VirtualBox BackTrack 4 in Ubuntu 10.04

A few months ago, we wrote up directions for setting up a headless VirtualBox in Ubuntu 10.04. Of course, we use VBox all the time and a few weeks ago setup a fresh install of BackTrack 4.  Since a lot of folks have read our previous HOWTO, I thought we’d just just give [...]

May 28th, 2010 by ahoog                              

Howto install log2timeline on Ubuntu 10.04

I previously posted a HOWTO for installing Kristinn Gudjonsson’s log2timeline on Ubuntu 9.10. Since that time, Kristinn setup his own apt-get repository so things are much easier.  Here’s what I did (which is

Add apt-get repository

At this time, Kristinn only has the karmic repository setup and that will work fine for Ubuntu [...]

May 26th, 2010 by ahoog                              

Howto install EvtxParser in Ubuntu 10.04

Andreas Schuster‘s EvtxParser is a fantastic tools for extracting the new log file format found in Windows Vista, Windows 7 as well as the new Windows 2008 Server and other platforms.  Like Kristinn’s log2timeline tool, though, there are a few steps to complete the install.  This should work on most Ubuntu versions but [...]

May 26th, 2010 by ahoog                              

Howto setup headless VirtualBox in Ubuntu 10.04

Like many of you, we work very hard to setup and maintain our forensic lab, in particular storage, software, hardware and security.  We’ve learned a lot and would like to share some of it.  After testing VMWare, KVM, Xen and VirtualBox, we settled on VirtualBox as the best solution for virtualization in our [...]