Posts

Metrology

I haven't produced breakout web-links to the other forum discussions as this post is only raising a point about Metrology and standardisation in digital forensics. A recent forum question posted by a PhD student sought ideas for a research area. I suggested the following: You may wish to consider the process of: (a) examination of mobile/feature/smart phones, embedded devices etc with respect

Knowing DUT memory

A newcomer to mobile phone examination asked a question on another forum: "My first question is a general one: how can I know that the data I get in an extraction is everything that was on the device? For example, I recently acquired an image from a ZTE Z667G with prior knowledge that there were messages between 2 subjects using Facebook Messenger. The device was not able to be rooted with

FREE iPhoneReader research tool

 Research and development tools can provide students, newcomers and experienced examiners in the mobile forensics community with practical experience and exposure to logically recovered data isolating the various types of recovered data through a single GUI. Additionally, such tools help develop analytical and assessment skillsets. iPhoneReader.exe is one such tool that can help you do that.

Free Mobile JTAG Training and Tools

Visitors to trewmte.blogspot.com may recall a discussion thread posted back in 2012 regarding a JTAG Tutorial http://trewmte.blogspot.co.uk/2012/09/jtag-tutorial.html. The purpose of that thread was to enable students, newcomers and experienced mobile/smart phone examiners to get a feel for JTAG before undertaking such examinations or purchasing tools etc. Today, Kevin Swartz from

Quoting Statistics

Whether you are a prosecution or defence barrister quoting statistical facts has its benefits when quoted to the jury. Using Stats is not without its pros and cons. However, with the ever increasing size/quantity of network traffic and stored data it appears inevitable describing data in a meaningful way to a jury using statistical statements is being re-defined on a annual basis. For example,

Android Botnet for SMS

Another area where SMS text messages may not have received as much scrutiny is regarding messages sent by mobile botnets. If I may I will re-emphasise the following point, the purpose of the discussions here and below are not as a criticism about tools or processes that are used in extracting, harvesting and/or treating recovered data but that data analysis is still required and cannot be rushed.

Smishing Maybe Smashed, but Fake Tache Goes On

Credit to Google Play Store - Combined screen shots of apps purporting to fake SMS and call logs Continuing on the text messaging discussion about examining raw data. Previously the subject was associated with Emotion Icons  http://trewmte.blogspot.co.uk/2015/03/emotion-icons.html and generally determining the bit-encoding scheme, Unicode, encrypted messaging hidden within Icons sent with