Skip to main content

Posts

Showing posts with the label linuxsleuthing

linuxsleuthing code project

linuxsleuthing code project Computers, iPods, Thumbdrives, oh My! Ive been busy with a major case during which many smaller cases have walked through my door. I began longing for a way for criminal investigators to be able to conduct preview examinations of digital storage devices without having to drop the devices off at the computer lab. Many of the questions I receive are relatively simple to answer: "Who owns this computer/iPod?" "Does this computer have any illegal images/videos/files?" "Are there any emails/chats between X and Y stored on this device?" While I understand a preview examination of a digital storage device is not the equivalent of full forensic examination, the plethora of storage devices and the dwindling number of public sector forensic computer examiners begs for an intermediate solution. And, while forensically sound boot-discs exist, e.g., CAINE or the FBIs ImageScan, they do not lend themselves to criminal investigators with litt...