Saturday, November 29, 2008

Cell site analysis (CSA) and fringe coverage

I'm delighted to see that Greg Smith has been able to update his blog frequently over the past few weeks. Greg is a genuine expert in the field of mobile forensics but it's his enthusiasm and willingness to share his knowledge which makes him stand out just as much as his expertise (check out his recent posts on cell site analysis and fringe coverage to see what I mean). If you're not already subscribed to Greg's blog, do so now!

Wednesday, November 19, 2008

Ultra-thin membrane changes SIM card usage

Fascinating new post from Greg Smith of Trew & Co. on his blog:

Examiners may come across an ultra-thin (0.3mm) membrane that lays over the contacts of a SIM card. Called the V200 SIM Dialer, the membrane is "Prefix base programmable (For routing prefix and bypass prefix setting)". What does that mean? Well, it allows mobile phones installed with SIM Tool Kit menu (most up to date phones have them) and define access to the network. The point being, if you are looking for least-cost routing for calls or want to use a calling card, rather than have mobile network call charges, then this device makes that happen, apparently.

How does it do it? "Dial the desired number directly each time you call, SIM dialer V200 will automatically dial IP access in front of the dialed number". As the manufacturer promotes, using their device will not change your dialling habits and there is "No cutting, No pounching your SIM".


More details and a link to a YouTube vid here.

Thursday, November 13, 2008

Lance Mueller - cell phone forensic tools

For anyone who missed it earlier this month, Lance Mueller posted some interesting thoughts on his blog about the current state of cell phone forensics:

As part of my work, I recently put together a fairly comprehensive cell phone forensic course. As part of the development phase of this project, I had a chance to use most of all the common cell phone forensic tools and put them through the paces with over 50 different phones, most of which were international models.

In opinion, the forensic industry is nowhere near where we are today with cell phone forensics compared to computer forensics. Mostly because it is a fairly new sub-field of digital forensics and the tools just have not been around long and have not yet evolved to the state where the current computer forensic tools are at.


Read the rest, including tool evaluations, here.

Thursday, September 04, 2008

When is a Computer Forensic Investigation Needed? (2 of 2)

by guest blogger Jon Rowe from Pinpoint Labs

In my previous post, I identified several primary differences between computer forensic investigations and electronic discovery processing. Next, I’d like to identify some general case categories and tasks that involve a computer forensic investigator.


Case Categories:

· Employment disputes

· Misuse of company computer

· Embezzlement

· Breach of contract

· Software licensing

· Intellectual property theft

· Insurance fraud

· Sexual harassment


Typical Tasks:

· Recovering deleted files and emails

· Internet activity analysis

· Cell phone and smart phone analysis

· Metadata analysis

· Providing results, recommendations, and action plan


Even if a civil or criminal investigation doesn’t fall within these case categories, you may still need to involve a computer forensic investigator. Why? Because it is no secret that computers are used as a primary source for communication, work product, and research. The listed tasks could apply to investigating almost any suspect involved in a civil or criminal law suit.

Read the Pinpoint Labs blog at www.pinpointlabs.com/wordpress/

Saturday, August 30, 2008

When is a Computer Forensic Investigation Needed? (1 of 2)

by guest blogger Jon Rowe from Pinpoint Labs


Electronic discovery and computer forensic investigations often go hand in hand. The challenge for many in the legal community is how to identify what ESI (Electronically Stored Information) requires more than typical electronic discovery processing.


First, computer investigations are technically electronic discovery, and the line between the two disciplines will continue to blur. Several key differences are:

  1. The qualifications and skills required by the individual performing collections and computer investigations
  2. Computer investigations typically recover and analyze areas of the suspect media unavailable through popular electronic discovery software
  3. Electronic discovery processing often involves a significantly larger amount of data
  4. Most computer forensic applications do not create load files or produce tiffs or electronic bates numbers
  5. Computer forensic investigations often require extensive detailed reports of the processes and findings, as well as appropriate affidavits, before the work can begin and then must describe the findings

In my next post, I will discuss the types of cases and suspect information that differentiate computer forensic investigations and typical electronic discovery processing.


Read the Pinpoint Labs blog at www.pinpointlabs.com/wordpress/