Chrome Nuts and Bolts: ChromeOS/Chromebook Forensics

Chromebooks have been taking over the classroom and are an up and coming issue for forensic examiners. This presentation will delve into our research into the forensics of the Chrome OS and Chromebooks. We will dive into the hardware and software perspectives of how...

pcapFS – Mounting Network Data for On-the-Fly Analysis

Network traffic analysis is beyond any doubt an essential part during forensic investigations. In particular, the raw data transferred over the network is of great value to a forensic examiner. Nevertheless, all of this raw embedded data needs to be located inside of...

Messaging App Forensics with Autopsy

Messages are increasingly important to digital investigations.  They can tell you who the victim or suspect was communicating with.   In this talk, we will cover how you can more efficiently analyze messages using Autopsy’s new interface and framework.  Autopsy has a...

Microsoft Office Telemetry: Tracking Your Every Move

Starting with Office 2013, Microsoft has released a “compatibility monitoring framework” to help enterprise IT staff management deployments. In doing so, they created a gold mine of data for forensic examiners. Office Telemetry logging includes handy...