<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>eDiscovery Archives - Compute Forensics LTD London Computer &amp; Mobile Phone Forensic Expert Witness Investigation Services</title>
	<atom:link href="https://compute-forensics.com/category/ediscovery/feed/" rel="self" type="application/rss+xml" />
	<link>https://compute-forensics.com/category/ediscovery/</link>
	<description></description>
	<lastBuildDate>Fri, 24 Aug 2018 12:05:38 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://compute-forensics.com/wp-content/uploads/2018/06/cropped-cropped-CF-1-32x32.png</url>
	<title>eDiscovery Archives - Compute Forensics LTD London Computer &amp; Mobile Phone Forensic Expert Witness Investigation Services</title>
	<link>https://compute-forensics.com/category/ediscovery/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>How is a Remote Forensic Collection or Analysis Conducted?</title>
		<link>https://compute-forensics.com/how-is-a-remote-forensic-collection-conducted/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Tue, 17 Jul 2018 14:13:01 +0000</pubDate>
				<category><![CDATA[eDiscovery]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Remote Collection]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1883</guid>

					<description><![CDATA[Compute Forensics have been to over 20 countries such as the UK, France, Thailand, Singapore and USA performing collections and on-site investigations. In person is the most straightforward way to reassure none of the actions of the forensic examiner is going to harm the data or the organisation&#8217;s network. It is like having a computer forensic expert]]></description>
										<content:encoded><![CDATA[<p>Compute Forensics have been to over 20 countries such as the UK, France, Thailand, Singapore and USA performing collections and on-site investigations. In person is the most straightforward way to reassure none of the actions of the forensic examiner is going to harm the data or the organisation&#8217;s network.</p>
<blockquote><p>It is like having a computer forensic expert in your office! Alistair Ewing Director Compute Forensics Ltd</p></blockquote>
<p>As technology advances remote forensic services are being more commonly utilised in the eDiscovery or forensic sphere. Compute Forensics can collect and triage data remotely either <strong>1)</strong> On the corporate network to a server or system on the same local IP range in a live state but a blocked mode. <strong>2)</strong> Across the internet with a secure AES encrypted connection using a forensic operating system with a remote connection. The original disk is untouched as the OS or method blocks writes to the drive. The image and working copy is made to a Bitlockered or Veracrypted disk connected to the system by the client.</p>
<p><iframe src="https://www.youtube-nocookie.com/embed/two7QJNhMLc?rel=0&amp;showinfo=0" width="560" height="315" frameborder="0" allowfullscreen="allowfullscreen"></iframe></p>
<p>Travel costs and board costs can be out of proportion to the case, or the data may reside on a home connection so it may be required to perform a remote collection.</p>
<h2>Situations when a Remote Aquisition is Useful</h2>
<ol>
<li>The budget doesn&#8217;t suit an onsite collection.</li>
<li>The data is in a far away location.</li>
<li>The data and the user is on the same corporate network. The physical and volatile data needs to be collected onsite but remotely without the culprit&#8217;s knowledge but with the authority of the organisation.</li>
<li>The collection or triage is on a tight schedule.</li>
<li>There are only 1 or 2 devices on the client site.</li>
</ol>
<h2>Is a Remote Collection Safe and Forensically Sound?</h2>
<p>Yes, all the data packets sent and received during the remote collection at the client end including, keyboard and mouse signals, images and files transfers are encrypted. Only the Computer Forensic Expert has access to the AES-256 and RSA-1024 cryptographic keys. The internal disk is untouched should the instructions be executed diligently; a pre-briefing exercise ensures this.</p>
<h3>The following steps display the methods entailed in a remote collection:</h3>
<h2>How a Remote Collection is Conducted on a Machine in an Off State</h2>
<ol>
<li>The client gives us information about the machine model etc. A contract allowing us to make a remote collection is to be completed by both parties before the forensic imaging. The technique works on Intel Based Macs as well as most PC Laptop models and tower PCs.</li>
<li>A bespoke digital forensic OS is uploaded to a secure location in an ISO format and made available for download. The client burns this to an optical disk or a USB using <a href="https://rufus.akeo.ie/">Rufus</a>.</li>
<li>The CD or USB is added to the system along with a USB 3.0 destination drive that is larger in capacity than the internal drives.</li>
<li>The system is connected to an ethernet connection buy the client.</li>
<li>When switching on the system, the user at the client side presses a key, DEL/F12/F8 or similar, during the power on self-test stage as the machine is waking up. On the system&#8217;s BIOS or the UFEI, the boot menu. The attached boot USB or CD is booted from bypassing the OS on the system but using the system&#8217;s hardware to function.</li>
<li>In the forensic OS, the client right clicks and selects the &#8216;connect to network&#8217; option.</li>
<li>From there the <a href="https://compute-forensics.com/staff/computer-expert-witness/">forensic examiner</a> takes over the system and begins the collection process.</li>
<li>All system data such as disk serial numbers are seized by specialist software to help produce the analysis report.</li>
<li>Any forensic images, logs or findings are exported to the encrypted attached USB stick or&#8230;</li>
<li>Uploaded via SFTP to the eDiscovery firms remote storage box or direct to a cloud-based eDiscovery platform such as <a href="https://goldfynch.com/">Goldfynch</a>.</li>
</ol>
<h2>On an Apple Device</h2>
<ol>
<li>Start OS X</li>
<li>Hold the option key until CD is displayed as an option (takes a little bit to appear)</li>
<li>Release the option key</li>
<li>Use the arrow keys (or mouse) to select the CD</li>
<li>Press Return.</li>
<li>The investigation begins.</li>
</ol>
<h2>How a Remote Collection is Conducted onsite on a Machine in an On State</h2>
<ol>
<li>A machine connected to the corporate network with Accessdata&#8217;s FTK installed is prepared.</li>
<li>The IP of a culprit&#8217;s machine is entered onto the examination machine.</li>
<li>The evidential disk is connected to remotely without the user&#8217;s knowledge after a remote agent is pushed to the machine remotely.</li>
<li>The examiner gains access to the file system through the remote agent. The volatile data can be analysed for malware and passwords. The disk can be copied and triaged.</li>
</ol>
<p>Should you require a forensic collection, please don&#8217;t hesitate to contact a member of our team.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Lower E-discovery Litigation Costs by Implementing a Decent ESI Governance Strategy</title>
		<link>https://compute-forensics.com/lower-e-discovery-litigation-costs-by-implementing-a-decent-esi-governance-strategy/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Thu, 28 Jun 2018 18:31:45 +0000</pubDate>
				<category><![CDATA[eDiscovery]]></category>
		<category><![CDATA[Infosec]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[ESI]]></category>
		<category><![CDATA[Governance Strategy]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1834</guid>

					<description><![CDATA[Businesses need to be proactive and improve their processes of storage and release of information rather than be reactive. It is better to have essential retention and storage policies in the event of litigation. We have performed too many collections where the IT department has no idea where the data is stored; this is usually]]></description>
										<content:encoded><![CDATA[<div id="ember1174" class="ember-view">
<div class="reader-article-content">
<p>Businesses need to be proactive and improve their processes of storage and release of information rather than be reactive. It is better to have essential retention and storage policies in the event of litigation. We have performed too many collections where the IT department has no idea where the data is stored; this is usually the case in smaller firms where they outsource the IT department. Having well organised easily locatable ESI electronically stored information will not only save you money and time in the likely event of litigation it may also have other effects such as being able to source key IP intellectual property assets in the event of an <a href="http://www.linkedin.com/pulse/incident-response-ip-theft-guide-hr-departments-alistair" rel="noopener">employee investigation</a> or disastrous loss as the result of rogue malware or hardware failures.</p>
<h3>What Businesses Need to Consider Before an E-discovery Exercise</h3>
<ul>
<li><strong>Invest Time Preparing Now </strong>The amount of time spent organising a proper governance strategy and migrating to an E-discovery friendly office platform will significantly reduce costs in the future. It is a false economy not to invest time money and resources into this endeavour now.</li>
<li><strong>Record Trail </strong>Policies of must be in place, you must record when they were approved and by whom. Example &#8220;We back up the exchange server every eight months, it is stored in this location and is deleted after X amount of time.&#8221; This will display to litigators that you are well organised leading to them giving you less hassle as the case progresses.</li>
<li><strong>Deletion Policy </strong>It is not efficient to hold onto ESI forever, but you must adhere to retention that has met the regulatory requirement. The deletion should be documented by explaining why an archive was deleted and the action must conform to the particular need in your industry or country. Missing project emails, gaps in dates and undocumented deletions are all unacceptable.</li>
<li><strong>Intentional Withholding </strong>is Hiding or withholding information will cause you added hassle and undermine you organisations credibility. You must explain why specific emails were withheld from a date range or a custodian&#8217;s data has been deleted before the time that has been allocated. If a forensic preview discovers ESI that was not disclosed after the pre-collection questionnaire this, it undermines the credibility of the company and can lead to further financial losses. I have worked on a case where a denied an email was sent by an ex-employee. Other custodians that have left the company emails were archived, but this person&#8217;s emails were not available. I was presented with a drive that they said this individual used. They were bluffing as no user profile belonging to this person existed; they handed me a computer that was never used by this individual. Additionally, they stated that they migrated servers and didn&#8217;t bring forward the custodian in question but the other employees that had left the company before this custodian exited had their PST email archive files in the migration in a PST backup folder. I discovered that the custodians PST file was on the server at some point, it had been present after examining migration logs and other records. As a result, they received a hefty fine for hiding this information and had to pay back the claim.</li>
<li><strong>Standardisation of Backups </strong>I have worked on a case where sometimes emails were available on the server, others were in a backup folder, other on the custodian&#8217;s hard disk and even some in VHD disk clones. Having ESI in multiple areas is haphazard. Each forensic image had to have every archive and backup examined for case ESI. Users had the admin rights to take emails off the server when they backed up leading to fragmented loci of the documents and email files involved in the case. The outsourced IT firm engaged in the business had no backup policy in place. This leads to an expensive long drawn out investigation, extraction and comparison process to ensure I had the full range of emails and ESI. For the forensic collector, the process should be as simple as work files are stored on this location, backups here and the rest is on the server along with all the logs and audits. It should all be auditable and defensible. Only admins should be allowed to perform backup tasks and records must be kept to show a full transversal expired. If this isn&#8217;t the case, then the email system used should automatically retain all the emails sent and received regardless of the user actions.</li>
<li><strong>Using BYOD in an Organisation </strong>Allowing your staff to use their own devices not only opens up the door to security risks but leads to the embarrassing prospect of having to encroach on their privacy and investigate their device to source potential ESI that may be stored in personal Gmail or online Outlook accounts. This lowers staff morale and gives the impression of lax policy. Just look at the recent Hilary Clinton scandal where she used personal email for government matters. A leak here could cost your company embarrassment for the sake of not allowing them to use their home mobile phone or computer. Just fork out for the devices. Prep and provide digital work items for staff that have been selected for security and retention in mind. iPhones backup to iCloud this way ESI can be retrieved from the iCloud location using <a href="http://www.iphonebackupextractor.com/" rel="nofollow noopener">iPhone Backup Extractor</a> and searched for ESI even if the phone has a forgotten code or the custodian is unavailable. Configure laptops to retain data and perhaps install monitoring software that tells you if a specific non-complaint action has occurred.</li>
<li><strong>Consider Migrating to Gmail or Office 365 for Business </strong>These cloud-based options reduce time in collecting ESI and retention can be performed via a click of a button in the settings. Make sure devices have two-step authentication and mobile devices synced with these services have decent passwords to enter your assets as you are exposed to the web using these services. In many ways, these webmail platforms can act as review tools in themselves allowing you to triage and keyword search specific projects involved in the case reducing preview time before a collection which can be done remotely. In some cases, this reduces costs for a manual data acquisition. It must be noted though these searches don&#8217;t recognise characters in documents and don&#8217;t have the raw power and options of tools like my personal favourite <a href="http://www.nuix.com/" rel="nofollow noopener">Nuix</a>. The knock effect is this will improve efficiency and stability in your business compared to using something debunked such as Lotus Notes. The only drawback is your data is stored offsite in Google&#8217;s or Microsoft&#8217;s server this may go against clients wishes in specific sectors.</li>
<li><strong>Keep Asset Lists for Data Mapping </strong>A simple spreadsheet detailing hard disk serial numbers, locations of ESI, users assigned to a domain and if more than one user uses a specific computer cuts time when handed to an E-discovery company as needed. It additionally saves costly second collection attempts because of gaps in the contiguous layout of the ESI concerning date range. It may even be used to produce directory listings periodically of all your devices so one can quickly find where ESI is stored. This can work in harmony with your security audit as well. Early case assessments can then be conducted with precision and promptly. <a href="http://compute-forensics.com/" rel="nofollow noopener">Compute Forensics</a> can aid in this.</li>
<li><strong>Regional Issues </strong>Some multinationals have used a &#8216;one size fits all&#8217; for all the countries they are based and have opened themselves up to litigation. The governance programme must be suited to the particular jurisdiction. It is worthwhile to consult a local lawyer to run through the nuances of that specific jurisdiction or industry.</li>
</ul>
<p>Please contact me if you need any advice regarding this topic, a few days of consultation could save your firm a small fortune in the future. Add me as a connection a.ewing@compute-forensics.com. Like and share if you found this useful.</p>
</div>
</div>
<div class="reader-flag-content__wrapper mb4 clear-both" data-ember-action="" data-ember-action-1175="1175"></div>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
