<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Uncategorized Archives - Compute Forensics LTD London Computer &amp; Mobile Phone Forensic Expert Witness Investigation Services</title>
	<atom:link href="https://compute-forensics.com/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>https://compute-forensics.com/category/uncategorized/</link>
	<description></description>
	<lastBuildDate>Mon, 26 Jul 2021 14:25:57 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://compute-forensics.com/wp-content/uploads/2018/06/cropped-cropped-CF-1-32x32.png</url>
	<title>Uncategorized Archives - Compute Forensics LTD London Computer &amp; Mobile Phone Forensic Expert Witness Investigation Services</title>
	<link>https://compute-forensics.com/category/uncategorized/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Ransom Decryption Tools #nomoreransom</title>
		<link>https://compute-forensics.com/ransomware-decryption-tools/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Mon, 26 Jul 2021 14:25:53 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1946</guid>

					<description><![CDATA[Ransomware has been in the news often and is here to stay; should you be infected, make sure you remove the computer from the network but keep the system on. Compute will forensically image the system remotely along with the RAM, then decipher the variant. Don&#8217;t contact the propagator of the threat yet. Our Technicians]]></description>
										<content:encoded><![CDATA[
<p>Ransomware has been in the news often and is here to stay; should you be infected, make sure you remove the computer from the network but keep the system on. Compute will forensically image the system remotely along with the RAM, then decipher the variant. Don&#8217;t contact the propagator of the threat yet. </p>



<p>Our Technicians can try and assess if </p>



<p>Before paying, contact us, and we will identify the type and perhaps decrypt with no payment needed to the bad actor! Certainly, don&#8217;t insult or be rude to them unless you want the Ransom doubled! We have a special technique and training to lower the ransom, and in many cases, we pay for ourselves 7 fold compared to trying to &#8216;do it yourself. We are fast, efficient, reasonable, and if you have to pay, you won&#8217;t have the FCA or FBI knocking on the door because compliance checks will have been passed in terms with who the bad actor is; sometimes, using computer forensic techniques, we can recover data from backups, using files carving and other methods. </p>



<p><a href="https://www.nomoreransom.org/crypto-sheriff.php?lang=en">https://www.nomoreransom.org/crypto-sheriff.php?lang=en</a></p>



<p><a href="https://www.nomoreransom.org/en/decryption-tools.html">https://www.nomoreransom.org/en/decryption-tools.html</a></p>



<p>The police are not trained/funded/staffed sufficiently and are too swamped to deal with cybercrime, and ransomware in particular, on its own. And security researchers cannot do it without support from law enforcement agencies. So responsibility for the fight against ransomware is shared between the police, the justice department, Europol and IT security companies and requires a joint effort. Together we will do everything in our power to disrupt criminals&#8217; money-making schemes and return files to their rightful owners without the latter having to pay loads of money.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Bitcoin/Crypto Wallet Data Recovery &#038; Investigation Service</title>
		<link>https://compute-forensics.com/bitcoin-crypto-wallet-recovery-service/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Tue, 29 Jun 2021 16:11:03 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Bitcoin]]></category>
		<category><![CDATA[Crypto]]></category>
		<category><![CDATA[Data Recovery]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1927</guid>

					<description><![CDATA[We offer a Cyrpto recovery service, and charge 20% no win no fee by that we mean: &#62;BTC/LiteCoin/Monero Wallet recovery when the item is lost or deleted from a hard drive &#62;Examination of a hard disk to ascertain login info to an exchange or vendor such as Coinbase, Crypto.com when the password is forgotten &#62;]]></description>
										<content:encoded><![CDATA[
<p>We offer a Cyrpto recovery service, and charge 20% no win no fee by that we mean:</p>



<p>&gt;BTC/LiteCoin/Monero Wallet recovery when the item is lost or deleted from a hard drive</p>



<p>&gt;Examination of a hard disk to ascertain login info to an exchange or vendor such as Coinbase, Crypto.com when the password is forgotten</p>



<p>&gt; Password Recovery &#8211; if you recall some part of your password, or you think the password was not too complex, then we can help you.</p>



<p>&gt;We are a bricks and mortar business you can trust us with your wallet</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p>&#8220;I read Bitcoin hitting 40k then thought about my wallet sitting on a formatted hard disk. Compute Forensics were able to recover this and I gained 80%&#8221;</p><cite>John from London</cite></blockquote>



<p></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>HR! IT! Don&#8217;t Throw Away or Reuse that Ex-Employee&#8217;s Hard Disk</title>
		<link>https://compute-forensics.com/hr-do-not-reuse-that-ex-employees-hard-disk/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Thu, 28 Jun 2018 17:41:46 +0000</pubDate>
				<category><![CDATA[HR Employee Investigations]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Corporate Crime]]></category>
		<category><![CDATA[Employee Investigations]]></category>
		<category><![CDATA[HR]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[IR]]></category>
		<category><![CDATA[Virtualisation]]></category>
		<category><![CDATA[White Collar Crime]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1821</guid>

					<description><![CDATA[I run a Computer Forensics firm in London. I received a call the other day from a recruitment firm. They informed me that they were suspicious that an ex-employee might have been stealing data from their firm and using it to help aid their new company. An hour later I arrived at their offices in central London]]></description>
										<content:encoded><![CDATA[<p>I run a <a href="http://compute-forensics.com/" target="_blank" rel="nofollow noopener">Computer Forensics</a> firm in London. I received a call the other day from a recruitment firm. They informed me that they were suspicious that an ex-employee might have been stealing data from their firm and using it to help aid their new company. An hour later I arrived at their offices in central London expecting to find the laptop complete with a hard disk. The Lenovo laptop was handed over to me in the meeting room by a stern eager looking white collar type. He was asking questions like &#8220;will you be able to get anything back?&#8221; and &#8220;When you delete something is it gone forever?&#8221;. I reassured the director that some evidence should be on there even if the device has been formatted but I cannot tell unless a take a quick look. I attached the hard disk to a blocker to preview the disk and protect my machine from making any writes to the disk, now outside the computer. I saw that luckily the user profile of the culprit was still on the disk or in the &#8216;Windows Old&#8217; folder on the root of the drive. This folder is created when a new installation of Windows is made to store the old user data. The head of IT looked on sheepishly as he morbidly foreseen the question ready to come out of my lips. I asked him &#8220;Has the custodians drive been reused?&#8221;. &#8220;Yes&#8221;, the client replied. I asked &#8220;How long for?&#8221;, &#8220;Two years&#8221; he replied hesitantly. I sighed in disbelief hoping no one heard me.</p>
<p>I continued the investigation from a <a href="http://www.linkedin.com/pulse/computer-forensic-imaging-data-collection-forensics-alistair" target="_blank" rel="noopener">forensic image</a> as not to harm the contents of the original disk I had made. I managed to find fragments of documents, link files and SQLite database for Chrome Browsing recovered from the unallocated clusters (deleted areas of the disk) and active areas in the &#8216;Windows Old&#8217; folder that indicated production of a contact list spreadsheet from an Act! contact database. The client database was then uploaded to the culprits Google Drive Cloud account via Google Chrome. I had found the smoking gun!</p>
<p>I suggested to the IT department to have some safeguards in place for the future. They should list the serial number of the disk and who it is in use by. Ideally, they should take out the disk from the caddy of the laptop and store it in an evidence bag somewhere safe. Another option is to hire a <a href="http://www.linkedin.com/in/computerforensicsexpertwitness" target="_blank" rel="noopener">computer forensic expert</a> to make a certified copy of the disk verifiable by an MD5 hashsum. Prevention is better than cure so safeguards such as blocking USB writing, CD burning and certain sites or exit points of data was implemented. Too many restrictions can hamper productivity so there must be a balance between security and convenience.</p>
<p>Assets must be assessed not just on their material value but on the value of the IP <a href="http://www.linkedin.com/pulse/incident-response-ip-theft-guide-hr-departments-alistair" target="_blank" rel="noopener">intellectual property</a> contained within. What damage would be done if that written off considered worthless £200 laptop got into the wrong hands? Suddenly it seems worth paying £400 securing it.</p>
<p>Your company may have saved itself £70 on the price of a new hard disk but almost lost £1000&#8217;s concerning lost business from other clients. Think before something is reused or is just valued on its material retail price. It may cost you much more than you think. You must protect your assets.</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Free Cloud Based eDiscovery Tool</title>
		<link>https://compute-forensics.com/free-cloud-based-ediscovery-tool/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Tue, 05 Jun 2018 08:23:48 +0000</pubDate>
				<category><![CDATA[Legal]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[eDiscovery]]></category>
		<category><![CDATA[Free]]></category>
		<category><![CDATA[Free Software]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1755</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid vc_custom_1459507906849"><div class="wpb_column vc_column_container vc_col-sm-12 vc_col-lg-9 vc_col-md-9"><div class="vc_column-inner vc_custom_1452702342137"><div class="wpb_wrapper"><div class="vc_custom_heading no_stripe text_align_left" ><h2 style="color: #111111;text-align: left" class="consulting-custom-title">Free Cloud Based eDiscovery Tool</h2></div><div class="post_details_wr ">
    
<div class="stm_post_info">
	<div class="stm_post_details clearfix">
		<ul class="clearfix">
			<li class="post_date">
				<i class="fa fa fa-clock-o"></i>
				05/06/2018			</li>
			<li class="post_by">Posted by:				<span>Alistair Ewing</span>
			</li>
			<li class="post_cat">Categories:				<span>Legal, Software, Uncategorized</span>
			</li>
		</ul>
		<div class="comments_num">
			<a href="https://compute-forensics.com/free-cloud-based-ediscovery-tool/#respond"><i class="fa fa-comment-o"></i>No Comments </a>
		</div>
	</div>
			<div class="post_thumbnail">
			<img fetchpriority="high" decoding="async" width="1110" height="550" src="https://compute-forensics.com/wp-content/uploads/2018/06/9-1110x550.jpg" class="attachment-consulting-image-1110x550-croped size-consulting-image-1110x550-croped wp-post-image" alt="" />		</div>
	</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1528114098937" >
		<div class="wpb_wrapper">
			<p>Thanks for browsing to this article. If you require global forensic imaging or any other of our litigation services, please don’t hesitate to <a href="https://compute-forensics.com/contact-us/">contact us</a>!</p>
<h3>The Current Market</h3>
<p>eDiscovery tools <a href="https://accessdata.com/products-services/summation">Summation</a>, <a href="https://www.relativity.com">Relativity</a>, <a href="https://www.vound-software.com">Intella</a> and <a href="https://www.nuix.com">Nuix</a> all have their place in the litigation support arena. As a technology agnostic myself I tend to try and find the best tool for my client in terms dependent on the size of the case and other factors such as if the data involves more than just documents and emails.</p>
<p>I was discouraged to discover that there was no solution for small to medium-sized cases. The answers I found would not cope with additional reviewers, more data and other factors.</p>
<h3>GoldFynch eDiscovery Tool</h3>
<p>A few weeks ago I came across <a href="https://goldfynch.com">Goldfynch</a> and thought I would review some of the features involved in the tool. The <a href="https://goldfynch.com">website</a> promises <strong>Cloud-based eDiscovery, Bank Grade Security, OCR processing, Pay as you go pricing (averages $6/GB/month), No contracts, no commitments</strong> and<strong> Unlimited users</strong>. I started to wonder if it also did the review for my clients too! The company slogan is “If you can use a search engine you can use GoldFynch.” Interestingly GoldFynch is owned by firm search engine firm Mazira who built the tool from the ground up to be intuitive.</p>
<p>GoldFynch is <strong>free</strong> to trial for the first case limited to <strong>512mb</strong> of data. This means reviewers can train using this tool before the case being initiated and pricing is scalable.</p>
<h3>Limitations as of 2018</h3>
<p>Unfortunately, at the time of writing <strong>AD1, XWF, E01, AFF</strong> and other forensic container formats were not supported. These formats are used so a litigator can be sure of the integrity and original path of the files has been preserved when the items were captured at the source.  The collection, documentation and preparation of the ESI, therefore, requires a computer forensic expert to prepare the dataset before upload. Additionally, if you have ESI in more exotic formats such as NSF Lotus Notes or Android Mobile SQL Emails the files may need to be converted which takes some time and skill.</p>
<p>The server location may be relevant in multijurisdictional cases, and the cloud processing server is based in the USA currently. I have conversed with <strong>GoldFynch,</strong> and they are looking at opening servers some other jurisdictions including Europe as the firm develops.</p>
<h3>Platform Review</h3>
<p>I signed up for GoldFynch cloud platform free 512mb trial and decided to try my hand at processing a sample case with public domain data. The sample dataset included <strong>PST, PDF, TIFF, OFFICE </strong>and <strong>JPG</strong> files. The website states, at the time of writing, that <strong>PDF, PST, MBOX, MSG, EML, DOC, DOCX, RTF, XLS, XLSX, PPT, PPTX, POTX, ODT, TIFF, JPEG, ZIP</strong> and<strong> RAR</strong> files are supported. In fact, I discovered that GoldFynch supports 7z (7zip) and a plethora of other data types not listed.</p>
<p>The datasets were compressed as <strong>Zip </strong>and <strong>7zip</strong> file types. Uploading the data was as easy as selecting an ‘Upload Now’ button in the ‘Files’ tab of the web-based interface.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><img decoding="async" class="aligncenter wp-image-1757" src="https://compute-forensics.com/wp-content/uploads/2018/06/3-300x156.jpg" alt="" width="600" height="311" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/3-300x156.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/3-768x398.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/3-1024x531.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/3-600x311.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/3.jpg 1877w" sizes="(max-width: 600px) 100vw, 600px" /></p>
<p>The upload on my enterprise 50mb broadband connection for the dataset took about 20 minutes. Processing took just under an hour to complete for <strong>556.5 MB</strong> of data or <strong>11,861</strong> files. This performance isn’t bad if you factor in the wasted time of software setup, tweaking and moving data to a physical data centre.</p>
<p>If you want to add or remove users, this can be done instantly using the ‘Sharing’ tab. The number of users that can be added to the case is <strong>unlimited.</strong>  The user is sent a registration email when a valid address is entered. There are three types of user Owner, Admin or User each with their own set of permissions which the new user can be assigned as to avoid unintentional modifications to the case by a reviewer.</p>
<p>When the files are uploading <strong>PDF’s</strong> and images are automatically <strong>OCR’d</strong> (made searchable), assigned unique Bate’s numbers and scanned for issues. In the test, <strong>GoldFynch’s</strong> scanning engine identified seven attachments that required passwords to open and previously non-OCR’d documents were flagged in the search.</p>
<p><strong>Decrypting</strong> these files is as comfortable as adding passwords to a bulk <strong>password list</strong> before or after processing event. These could also be exported out and cracked by a <a href="https://compute-forensics.com/" rel="noopener">computer forensic examiner</a>.</p>
<p><img decoding="async" class="aligncenter wp-image-1758" src="https://compute-forensics.com/wp-content/uploads/2018/06/4-300x154.jpg" alt="" width="600" height="308" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/4-300x154.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/4-768x394.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/4-1024x525.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/4-600x308.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/4.jpg 1872w" sizes="(max-width: 600px) 100vw, 600px" />The ‘Overview’ tab displays a chart as so you can see how much data has been uploaded to a case and the status of the processing of the items.  The Activity sub-tab allows the reviewer to go through the changes regarding tagging the reviewers of the case have made.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-1759" src="https://compute-forensics.com/wp-content/uploads/2018/06/1-300x155.jpg" alt="" width="600" height="310" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/1-300x155.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/1-768x397.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/1-1024x529.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/1-600x310.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/1.jpg 1872w" sizes="auto, (max-width: 600px) 100vw, 600px" />The ‘Search’ tab allows examiners to run keyword searches against the dataset. The right-hand column provides for reviewers to filter by file type and date as to quickly find the responsive data. Data can be tagged as <strong>CONFIDENTIAL, IMPORTANT, IRRELEVANT, NON-RESPONSIVE</strong> or <strong>PRIVILEGED.</strong> Admin users can easily assign their own bespoke tags.</p>
<p><img loading="lazy" decoding="async" class="wp-image-1760 aligncenter" src="https://compute-forensics.com/wp-content/uploads/2018/06/5-300x158.jpg" alt="" width="600" height="317" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/5-300x158.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/5-768x405.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/5-1024x540.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/5-600x317.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/5.jpg 1852w" sizes="auto, (max-width: 600px) 100vw, 600px" /></p>
<p>The advanced search allows for multiple queries to be compounded so that you could easily find results containing just the term <strong>‘GUNS’</strong> equal to or after the <strong>01/01/2018</strong> as shown below.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-1761" src="https://compute-forensics.com/wp-content/uploads/2018/06/7-300x155.jpg" alt="" width="600" height="310" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/7-300x155.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/7-768x396.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/7-1024x528.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/7-600x310.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/7.jpg 1863w" sizes="auto, (max-width: 600px) 100vw, 600px" />The ‘Doc Review’ tab has redaction, tagging, download and directory browsing features as found in most review tools. New items are populated fairly quickly, and the interface is intuitive.</p>
<p>The ‘Production’ tab allows the user to export tagged files using a wizard. Paid versions allow export in TIFF, Load File and even Relativity or Concordance formats.</p>
<p>&nbsp;</p>
<h3><img loading="lazy" decoding="async" class="aligncenter wp-image-1762" src="https://compute-forensics.com/wp-content/uploads/2018/06/8-300x151.jpg" alt="" width="600" height="303" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/8-300x151.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/8-768x388.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/8-1024x517.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/8-600x303.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/8.jpg 1853w" sizes="auto, (max-width: 600px) 100vw, 600px" />Summary</h3>
<p><strong>Goldfynch</strong> is a transparently priced tool that could be very useful in small to medium size cases. The power of a cloud-based tool means a forensic expert or IT technician to collect and upload data to the cloud and assign reviewers of that data non-dependant of location. The functionality covers all the fundamental requirements for a review tool and is easy to use.  I am sure new features will be added, without the need for a software upgrade as the service evolves.</p>
<p>Thanks for reading!</p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-3 vc_hidden-sm vc_hidden-xs"><div class="vc_column-inner "><div class="wpb_wrapper">
<div class="stm_sidebar">

            <style type="text/css" scoped>
            .vc_custom_1452056597103{margin-right: 0px !important;margin-bottom: 30px !important;margin-left: 0px !important;}.vc_custom_1451998133493{margin-bottom: 30px !important;}.vc_custom_1452056633692{padding-top: 37px !important;padding-right: 30px !important;padding-bottom: 40px !important;padding-left: 30px !important;}.vc_custom_1527964913946{margin-bottom: 9px !important;}.vc_custom_1527964962623{margin-bottom: 17px !important;}.vc_custom_1527965000155{margin-bottom: 30px !important;}        </style>
        <div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1452056597103"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner vc_custom_1452056633692"><div class="wpb_wrapper"><div class="vc_custom_heading vc_custom_1527964913946 text_align_left" ><div style="font-size: 16px;color: #222222;text-align: left;font-family:Poppins;font-weight:600;font-style:normal" class="consulting-custom-title">Contact Us</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1527964962623" >
		<div class="wpb_wrapper">
			<p><span style="font-size: 13px; line-height: 22px;">Compute Forensics are based in London but are available for contracts and work in the global area. Please don’t hesitate to email us at expert@compute-forensics.com for a free online or call consultation.</span></p>

		</div>
	</div>
<div class="vc_btn3-container vc_btn3-inline vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-sm vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-left vc_btn3-color-white" href="https://compute-forensics.com/contact-us/" title=""><i class="vc_btn3-icon fa fa-phone-square"></i> contacts</a></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid vc_custom_1451998133493"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper"><div class="vc_btn3-container vc_btn3-left vc_custom_1527965000155 vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-lg vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-block vc_btn3-icon-left vc_btn3-color-theme_style_1" href="https://compute-forensics.com/pdf/" title="" target="_blank"><i class="vc_btn3-icon fa fa-file-pdf-o"></i> Computer Forensics Professional Services PDF</a></div></div></div></div></div>
</div>    
</div></div></div></div></div><div data-vc-full-width="true" data-vc-full-width-init="false" class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1459505959648"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper">
<section class="vc_cta3-container" >
    <div class="vc_general vc_cta3 third_bg_color vc_cta3-style-flat vc_cta3-shape-square vc_cta3-align-left vc_cta3-color-classic vc_cta3-icon-size-md vc_cta3-actions-right vc_custom_1530193971059 style=""">
                        <div class="vc_cta3_content-container">
                                    <div class="vc_cta3-content">
                <header class="vc_cta3-content-header">
                    <div class="vc_custom_heading" ><h2 style="font-size: 20px;color: #ffffff;line-height: 24px" class="consulting-custom-title">Are you looking for an eDiscovery Consultant?</h2></div>                                    </header>
                            </div>
                        <div class="vc_cta3-actions"><div class="vc_btn3-container vc_btn3-right vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-md vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-right vc_btn3-color-theme_style_2" href="https://compute-forensics.com/contact-us/" title="">get a quote <i class="vc_btn3-icon fa fa-chevron-right"></i></a></div></div>        </div>
                    </div>
</section></div></div></div></div><div class="vc_row-full-width vc_clearfix"></div>
</div>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How to make a Forensic Image Bootable in VirtualBox for Free</title>
		<link>https://compute-forensics.com/how-to-make-a-forensic-image-bootable-in-virtualbox-for-free/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Tue, 05 Jun 2018 09:22:46 +0000</pubDate>
				<category><![CDATA[Investigative Techniques]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Free Software]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Techniques]]></category>
		<category><![CDATA[Virtualisation]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1765</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid vc_custom_1459507906849"><div class="wpb_column vc_column_container vc_col-sm-12 vc_col-lg-9 vc_col-md-9"><div class="vc_column-inner vc_custom_1452702342137"><div class="wpb_wrapper"><div class="vc_custom_heading no_stripe text_align_left" ><h2 style="color: #111111;text-align: left" class="consulting-custom-title">How to make a Forensic Image Bootable in VirtualBox for Free</h2></div><div class="post_details_wr ">
    
<div class="stm_post_info">
	<div class="stm_post_details clearfix">
		<ul class="clearfix">
			<li class="post_date">
				<i class="fa fa fa-clock-o"></i>
				05/06/2018			</li>
			<li class="post_by">Posted by:				<span>Alistair Ewing</span>
			</li>
			<li class="post_cat">Categories:				<span>Investigative Techniques, Uncategorized</span>
			</li>
		</ul>
		<div class="comments_num">
			<a href="https://compute-forensics.com/how-to-make-a-forensic-image-bootable-in-virtualbox-for-free/#respond"><i class="fa fa-comment-o"></i>No Comments </a>
		</div>
	</div>
			<div class="post_thumbnail">
			<img loading="lazy" decoding="async" width="1016" height="550" src="https://compute-forensics.com/wp-content/uploads/2018/06/Make-a-forensic-image-bootable-1016x550.jpg" class="attachment-consulting-image-1110x550-croped size-consulting-image-1110x550-croped wp-post-image" alt="Make a forensic image bootable in Windows." />		</div>
	</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1533678424687" >
		<div class="wpb_wrapper">
			<p><strong>Thank you for visiting this post hope you find it useful. Please email <a href="mailto:expert@compute-forensics.com">expert@compute-forensics.com</a> for assistance in lab implementation, investigation, data collection, consultancy or anything else.</strong></p>
<p><iframe loading="lazy" src="https://www.youtube.com/embed/Fs_FRxzcVDk?rel=0&amp;showinfo=0" width="560" height="315" frameborder="0" allowfullscreen="allowfullscreen"></iframe></p>
<h3>Introduction</h3>
<p>This ‘how to’ is a simple guide to virtualise your forensic or test disk image file in Windows without converting it, directly with VirtualBox, forensically as not to change the image but to save the IO writes to a temporary location.</p>
<h3>Why would you want to Virtualise a <a href="https://compute-forensics.com/forensic-imaging/">Forensic Image</a>?</h3>
<p>Examining from outside the native operating system and including your image for processing in tools such as Autopsy, FTK and X-ways are all well and good, but it can lead to dreaded ‘scope creep’, and it is always good to observe the operating system as the suspect would see it.</p>
<p>The effectiveness of booting the image in court or using screenshots of a virtualised image to highlight specific examination points such as drug paraphernalia used as Windows wallpaper, for example, can be invaluable in demonstrating a point. The method works for Linux and Windows, the Apple Mac guide for doing this is coming soon!</p>
<h3>Primary reasons for Virtualising a Forensic Image</h3>
<ul>
<li>To provide a better insight into how the accused used the system</li>
<li>To run live forensic tools such as Nirsoft and OSforensics in the Windows environment</li>
<li>To analyse the memory or RAM to see if any Malware or Rootkits only detectable on a live system exists</li>
<li>To display user behaviour and layout of the desktop to clients</li>
<li>To access bespoke tools such as QuickBooks or booking systems in their natural test environment</li>
<li>To decrypt and create a logical image of non-TPM PGP, Bitlockered, Trucrypted or Veracrypted volumes where the password is known or to test techniques where one may have a limited amount of tries</li>
</ul>
<p>In the past, this has been costly or cumbersome. Recently a tool has been released free of charge, from Nanni Bassetti, the creator of <a href="https://www.caine-live.net">Caine</a> live suite of tools, called Imm2Virtual.</p>
<p>The technique relies on three tools, and you need a full forensic image for this to work. This technique is safe as the image, of course, won’t be blocked but also use a working copy to do this, don’t do this with the only copy of the evidence! Using this method <em>all</em> significant forensic image and RAW formats are supported (<strong>AFF, E01, E01x, DD, 001, IMG</strong>.)</p>
<p><strong>WARNING: Make sure you disable internet access on yours or the virtual machine. You do not want to connect to illegal sites or even the suspect’s cloud or private websites. Without a subpoena, you are breaking the law!</strong></p>
<h3>Free Software Tools Needed to Download and Install on your Windows Forensic Machine</h3>
<ol>
<li><a href="https://arsenalrecon.com/weapons/image-mounter/"><strong>Arsenal Image Mounter</strong></a></li>
<li><strong><a href="https://www.virtualbox.org/">VirtualBox</a> </strong></li>
<li><strong><a href="https://github.com/nannib/Imm2Virtual">Imm2Virtual</a></strong></li>
</ol>
<h3>Steps to Making and Booting Your VDMK File</h3>
<ul>
<li>Install or run ‘As Admin’ the items above. It is <em>essential</em><strong> </strong>to run the programs above as admin otherwise disks won’t be visible and you will come across a whole host of other errors.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-1170 size-full" src="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Oracle.jpg?resize=379%2C442&amp;ssl=1" sizes="auto, (max-width: 379px) 100vw, 379px" srcset="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Oracle.jpg?w=379&amp;ssl=1 379w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Oracle.jpg?resize=257%2C300&amp;ssl=1 257w" alt="VMware used in Digital Forensics to Boot an Image" width="377" height="440" data-attachment-id="1170" data-permalink="https://compute-forensics.com/how-to-make-a-computer-forensic-image-forensically-bootable/oracle/" data-orig-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Oracle.jpg?fit=379%2C442&amp;ssl=1" data-orig-size="379,442" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Oracle" data-image-description="" data-medium-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Oracle.jpg?fit=257%2C300&amp;ssl=1" data-large-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Oracle.jpg?fit=379%2C442&amp;ssl=1" /></p>
<ul>
<li>Run Virtual Box as an administrator. Create a new virtual machine, using you suspect image types OS, but do not add a hard disk just yet. Remember to add more RAM to the virtual machine setup. Make a note of the path your VMDK machine was created. The default will be ‘C:\Users\YOURUSERNAME\VirtualBox VMs’.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-1169" src="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Creating-a-forensic-VM.jpg?resize=792%2C585&amp;ssl=1" sizes="auto, (max-width: 792px) 100vw, 792px" srcset="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Creating-a-forensic-VM.jpg?w=792&amp;ssl=1 792w, https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Creating-a-forensic-VM.jpg?resize=300%2C222&amp;ssl=1 300w, https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Creating-a-forensic-VM.jpg?resize=768%2C567&amp;ssl=1 768w" alt="In Virtual Box creating an empty disk" width="790" height="584" data-attachment-id="1169" data-permalink="https://compute-forensics.com/how-to-make-a-computer-forensic-image-forensically-bootable/creating-a-forensic-vm/" data-orig-file="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Creating-a-forensic-VM.jpg?fit=792%2C585&amp;ssl=1" data-orig-size="792,585" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1521131818&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Creating-a-forensic-VM" data-image-description="" data-medium-file="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Creating-a-forensic-VM.jpg?fit=300%2C222&amp;ssl=1" data-large-file="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Creating-a-forensic-VM.jpg?fit=792%2C585&amp;ssl=1" /></p>
<ul>
<li>Run Arsenal Image Mounter as an admin. Mount the forensic image to allow temporary writes to the system cache, not the image! Take note of the physical disk number windows allocated to the virtually mounted disk.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-1168 size-full" src="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?resize=887%2C544&amp;ssl=1" sizes="auto, (max-width: 887px) 100vw, 887px" srcset="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?w=887&amp;ssl=1 887w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?resize=300%2C184&amp;ssl=1 300w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?resize=768%2C471&amp;ssl=1 768w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?resize=80%2C50&amp;ssl=1 80w" alt="" width="846" height="519" data-attachment-id="1168" data-permalink="https://compute-forensics.com/how-to-make-a-computer-forensic-image-forensically-bootable/aresenal_image_mounter_forensics/" data-orig-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?fit=887%2C544&amp;ssl=1" data-orig-size="887,544" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1521132334&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Aresenal_Image_Mounter_Forensics" data-image-description="" data-medium-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?fit=300%2C184&amp;ssl=1" data-large-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?fit=887%2C544&amp;ssl=1" /></p>
<ul>
<li>Select your search bar in Windows and search for CMD. Right-click and run a CMD Window as an administrator. Type DISKPART, then LIST DISK, check the disk number of your mounted disk and type SELECT DISK [INSERT NUMBER]. Now offline the disk by typing OFFLINE DISK.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-1172" src="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/DiskPart_Offilne-Disk-for-Forensic-Purposes.jpg?resize=593%2C518&amp;ssl=1" sizes="auto, (max-width: 593px) 100vw, 593px" srcset="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/DiskPart_Offilne-Disk-for-Forensic-Purposes.jpg?w=593&amp;ssl=1 593w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/DiskPart_Offilne-Disk-for-Forensic-Purposes.jpg?resize=300%2C262&amp;ssl=1 300w" alt="Using DiskPart to Offline your Disk" width="591" height="516" data-attachment-id="1172" data-permalink="https://compute-forensics.com/how-to-make-a-computer-forensic-image-forensically-bootable/diskpart_offilne-disk-for-forensic-purposes/" data-orig-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/DiskPart_Offilne-Disk-for-Forensic-Purposes.jpg?fit=593%2C518&amp;ssl=1" data-orig-size="593,518" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1521134217&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="DiskPart_Offilne-Disk-for-Forensic-Purposes" data-image-description="" data-medium-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/DiskPart_Offilne-Disk-for-Forensic-Purposes.jpg?fit=300%2C262&amp;ssl=1" data-large-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/DiskPart_Offilne-Disk-for-Forensic-Purposes.jpg?fit=593%2C518&amp;ssl=1" /></p>
<ul>
<li>Now run <strong>IMM2VIRTUAL</strong> as an administrator. In the disk-name slot type the exact name that you called your disk and input your physical drive number. In this case, it is ‘5’, and the name was as stated earlier ‘VM1’.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-1173" src="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?resize=1016%2C649&amp;ssl=1" sizes="auto, (max-width: 1016px) 100vw, 1016px" srcset="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?w=1016&amp;ssl=1 1016w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?resize=300%2C192&amp;ssl=1 300w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?resize=768%2C491&amp;ssl=1 768w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?resize=80%2C50&amp;ssl=1 80w" alt="" width="846" height="540" data-attachment-id="1173" data-permalink="https://compute-forensics.com/how-to-make-a-computer-forensic-image-forensically-bootable/im2virtual_screenshot/" data-orig-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?fit=1016%2C649&amp;ssl=1" data-orig-size="1016,649" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1521133522&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="IM2VIRTUAL_Screenshot" data-image-description="" data-medium-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?fit=300%2C192&amp;ssl=1" data-large-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?fit=1016%2C649&amp;ssl=1" /></p>
<ul>
<li>CMD should open a Window with ‘RAW host disk access VMDK file C:\Users\<strong>YOURUSERNAME</strong>\VirtualBox VMs\VM1\VM1.vmdk created successfully.’ If not you probably have the wrong disk number, name, you didn’t know offline the correct disk, or you didn’t run a program as admin.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Now run VirtualBox as admin. Navigate to Settings&gt;Storage. Add the modified VDMK file as a disk. You may need to play around with settings such as disk type, OS and RAM amount to get the virtual disk to boot. After some tinkering, you should be able to boot your image.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-1171" src="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Add-Disk-to-Virtual-Box.jpg?resize=770%2C512&amp;ssl=1" sizes="auto, (max-width: 770px) 100vw, 770px" srcset="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Add-Disk-to-Virtual-Box.jpg?w=770&amp;ssl=1 770w, https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Add-Disk-to-Virtual-Box.jpg?resize=300%2C199&amp;ssl=1 300w, https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Add-Disk-to-Virtual-Box.jpg?resize=768%2C511&amp;ssl=1 768w" alt="Virtual Box Remember to Add your Forensic VDMK File" width="768" height="511" data-attachment-id="1171" data-permalink="https://compute-forensics.com/how-to-make-a-computer-forensic-image-forensically-bootable/add-disk-to-virtual-box/" data-orig-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Add-Disk-to-Virtual-Box.jpg?fit=770%2C512&amp;ssl=1" data-orig-size="770,512" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1521134318&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Add-Disk-to-Virtual-Box" data-image-description="" data-medium-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Add-Disk-to-Virtual-Box.jpg?fit=300%2C199&amp;ssl=1" data-large-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Add-Disk-to-Virtual-Box.jpg?fit=770%2C512&amp;ssl=1" /></p>
<p>There you have it. Remember you can use iso’s such as<a href="http://www.piotrbania.com/all/kon-boot/"> Kon Boot</a> or others to bypass the Windows. The beauty of it is if you mess up the installation you can go back to default settings as you are not modifying the original copy, just the cache.</p>
<p>If you liked this guide please like, share and comment on this page.</p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-3 vc_hidden-sm vc_hidden-xs"><div class="vc_column-inner "><div class="wpb_wrapper">
<div class="stm_sidebar">

            <style type="text/css" scoped>
            .vc_custom_1452056597103{margin-right: 0px !important;margin-bottom: 30px !important;margin-left: 0px !important;}.vc_custom_1451998133493{margin-bottom: 30px !important;}.vc_custom_1452056633692{padding-top: 37px !important;padding-right: 30px !important;padding-bottom: 40px !important;padding-left: 30px !important;}.vc_custom_1527964913946{margin-bottom: 9px !important;}.vc_custom_1527964962623{margin-bottom: 17px !important;}.vc_custom_1527965000155{margin-bottom: 30px !important;}        </style>
        <div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1452056597103"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner vc_custom_1452056633692"><div class="wpb_wrapper"><div class="vc_custom_heading vc_custom_1527964913946 text_align_left" ><div style="font-size: 16px;color: #222222;text-align: left;font-family:Poppins;font-weight:600;font-style:normal" class="consulting-custom-title">Contact Us</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1527964962623" >
		<div class="wpb_wrapper">
			<p><span style="font-size: 13px; line-height: 22px;">Compute Forensics are based in London but are available for contracts and work in the global area. Please don’t hesitate to email us at expert@compute-forensics.com for a free online or call consultation.</span></p>

		</div>
	</div>
<div class="vc_btn3-container vc_btn3-inline vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-sm vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-left vc_btn3-color-white" href="https://compute-forensics.com/contact-us/" title=""><i class="vc_btn3-icon fa fa-phone-square"></i> contacts</a></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid vc_custom_1451998133493"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper"><div class="vc_btn3-container vc_btn3-left vc_custom_1527965000155 vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-lg vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-block vc_btn3-icon-left vc_btn3-color-theme_style_1" href="https://compute-forensics.com/pdf/" title="" target="_blank"><i class="vc_btn3-icon fa fa-file-pdf-o"></i> Computer Forensics Professional Services PDF</a></div></div></div></div></div>
</div>    
</div></div></div></div></div><div data-vc-full-width="true" data-vc-full-width-init="false" class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1459505959648"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper">
<section class="vc_cta3-container" >
    <div class="vc_general vc_cta3 third_bg_color vc_cta3-style-flat vc_cta3-shape-square vc_cta3-align-left vc_cta3-color-classic vc_cta3-icon-size-md vc_cta3-actions-right vc_custom_1530193131889 style=""">
                        <div class="vc_cta3_content-container">
                                    <div class="vc_cta3-content">
                <header class="vc_cta3-content-header">
                    <div class="vc_custom_heading" ><h2 style="font-size: 20px;color: #ffffff;line-height: 24px" class="consulting-custom-title">Are you looking for a Computer Forensic Expert?</h2></div>                                    </header>
                            </div>
                        <div class="vc_cta3-actions"><div class="vc_btn3-container vc_btn3-right vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-md vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-right vc_btn3-color-theme_style_2" href="https://compute-forensics.com/contact-us/" title="">get a quote <i class="vc_btn3-icon fa fa-chevron-right"></i></a></div></div>        </div>
                    </div>
</section></div></div></div></div><div class="vc_row-full-width vc_clearfix"></div>
</div>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Top Ten Free Computer Forensic/eDiscovery Software</title>
		<link>https://compute-forensics.com/top-ten-free-computer-forensic-software/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Tue, 05 Jun 2018 09:21:27 +0000</pubDate>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Free Software]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1768</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid vc_custom_1459507906849"><div class="wpb_column vc_column_container vc_col-sm-12 vc_col-lg-9 vc_col-md-9"><div class="vc_column-inner vc_custom_1452702342137"><div class="wpb_wrapper"><div class="vc_custom_heading no_stripe text_align_left" ><h2 style="color: #111111;text-align: left" class="consulting-custom-title">Top Ten Free Computer Forensic/eDiscovery Software</h2></div><div class="post_details_wr ">
    
<div class="stm_post_info">
	<div class="stm_post_details clearfix">
		<ul class="clearfix">
			<li class="post_date">
				<i class="fa fa fa-clock-o"></i>
				05/06/2018			</li>
			<li class="post_by">Posted by:				<span>Alistair Ewing</span>
			</li>
			<li class="post_cat">Categories:				<span>Computer Forensics, Software, Uncategorized</span>
			</li>
		</ul>
		<div class="comments_num">
			<a href="https://compute-forensics.com/top-ten-free-computer-forensic-software/#respond"><i class="fa fa-comment-o"></i>No Comments </a>
		</div>
	</div>
			<div class="post_thumbnail">
			<img loading="lazy" decoding="async" width="938" height="550" src="https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool-938x550.jpg" class="attachment-consulting-image-1110x550-croped size-consulting-image-1110x550-croped wp-post-image" alt="Caine free computer forensic tool" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool-938x550.jpg 938w, https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool-350x204.jpg 350w" sizes="auto, (max-width: 938px) 100vw, 938px" />		</div>
	</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1528114867951" >
		<div class="wpb_wrapper">
			<p>Compiled here is the <strong>Top Ten of FREE Computer Forensic/eDiscovery software picks for 2018</strong>. Sometimes you do not need to spend £1000’s to get the job done. Paid software has its place but sometimes when you want one particular function only or to test out a hypothesis. So get downloading and examining using the software! Please email me at <a href="mailto:expert@compute-forensics.com">expert@compute-forensics.com</a> with any suggestions for 2019. <a href="https://compute-forensics.com/contact-us/" target="_blank" rel="noopener">Contact us</a> should you have an enquiry! <em>Written by Alistair Ewing</em></p>
<h2><i class="fa fa-star-o fa- "></i> 1) <a href="https://www.sleuthkit.org/autopsy/">Autopsy</a> developed by Brian Carrier, Basis Technology, Dan Farmer and Wietse Venema</h2>
<p>Autopsy is The Sleuth Kit’s shiny Windows front-end offering. The features are impressive for a free program; some stand up there with the paid for forensic tools Encase, FTK, X-ways and more recently Nuix Investigator. The suite of tools includes:</p>
<ul>
<li><strong>Data Recovery </strong>using photorec as a carver module</li>
<li><strong>Indexing for Keyword Searching </strong>The program creates a text index for instantaneous keyword searches.</li>
<li><strong>Known Hash Set Filtering </strong>Do you have hash (SHA1/MD5) fingerprints for known noise files or known contraband files? These can be filtered in or out without having to examine the data yourself manually.</li>
<li><strong>Media Metadata </strong>EXIF metadata can be examined, sorted and filtered to find what device was used to make a recording or file, when and sometimes where using geotags.</li>
<li><strong>Timeline Analysis </strong>Autopsy draws file MAC times (created, modified etc.) from files, website visits and other data such as GPS and EXIF. The program is also beginning to support ‘plaso’ files generated using log2timeline although the author states on their website that this time of writing this is in a BETA stage.</li>
<li><strong>Website Records </strong>Supports parsing of current browser records including Firefox, Chrome and Internet Explorer.</li>
</ul>
<p>Autopsy doesn’t have all the bells and whistles as some of the paid-for software, but don’t underestimate the tool’s features. Many of the features aren’t immediately apparent to the uninitiated, but this program has progressed by leaps and bounds.</p>
<p>I tested Autopsy 4.6.0 on a 1gb test image in the industry standard E01 format. The scanning engine quickly discovered signature mismatches (when someone tries to mask a file by changing its extension), file encryption, attached USB devices, web browsing history and more. The GUI interface is not unlike the functional but dated Encase v6 layout. (See Below). You may be a student or a ninja, in any case give Autopsy a whirl.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-1769" src="https://compute-forensics.com/wp-content/uploads/2018/06/Test-Case_Autopsy_NO1-Forensic-Tool-300x162.jpg" alt="" width="600" height="324" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/Test-Case_Autopsy_NO1-Forensic-Tool-300x162.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/Test-Case_Autopsy_NO1-Forensic-Tool-768x414.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/Test-Case_Autopsy_NO1-Forensic-Tool-1024x552.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/Test-Case_Autopsy_NO1-Forensic-Tool-600x324.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/Test-Case_Autopsy_NO1-Forensic-Tool.jpg 1715w" sizes="auto, (max-width: 600px) 100vw, 600px" />2) <a href="https://www.caine-live.net" rel="noopener">Caine</a> by Nanni Bassetti</p>
<p>Caine is a 64bit bootable Linux suite of tools that can be used to forensically image Mac’s and Windows Machines, triage machines without writing to the disk inside and perform partial and full analysis of forensic images and disks. Caine is loaded with Windows executable tools as well for use on a live system if a computer is discovered in a switched-on state and triage or unencrypted image is desired for acquisition. My personal experience is that Caine images most disks without error and has Veracrypt installed so you can package the forensic copies onto an encrypted disk as to remain compliant with your client’s data protection rules. The ISO can be downloaded from the website. The ISO can be made USB bootable by using UNETBOOTIN or <a href="https://rufus.akeo.ie">Rufus</a>. A must for any examiner’s toolkit.</p>
<h2><img loading="lazy" decoding="async" class="aligncenter wp-image-1770" src="https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool-300x193.jpg" alt="" width="600" height="387" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool-300x193.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool-768x495.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool-600x387.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool.jpg 938w" sizes="auto, (max-width: 600px) 100vw, 600px" />3) <a href="https://github.com/keydet89/RegRipper2.8">RegRipper</a> by Harlan Carvey</h2>
<p>Forged using python and operated user-side with an easy to use GUI frontend, Regripper parses registry hives (or even a mounted forensic image with a mod) and outputs the humanly readable data as a text file that can be searched using Notepad++ or similar. Want to find a user’s SID code, the Windows installation dates or MRU (most recently used/viewed items) fast? Then use RR.</p>
<p><a href="https://github.com/keydet89/RegRipper2.8.git"><img loading="lazy" decoding="async" class="aligncenter wp-image-1130 size-full" title="RegRipper Rips Registry Hives from Windows Machines " src="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/RegRipper_Registry-Analysis.jpg?resize=456%2C414&amp;ssl=1" sizes="auto, (max-width: 456px) 100vw, 456px" srcset="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/RegRipper_Registry-Analysis.jpg?w=456&amp;ssl=1 456w, https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/RegRipper_Registry-Analysis.jpg?resize=300%2C272&amp;ssl=1 300w" alt="" width="454" height="412" data-attachment-id="1130" data-permalink="https://compute-forensics.com/top-ten-free-computer-forensic-software/regripper_registry-analysis/" data-orig-file="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/RegRipper_Registry-Analysis.jpg?fit=456%2C414&amp;ssl=1" data-orig-size="456,414" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1520449263&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="RegRipper_Registry-Analysis" data-image-description="" data-medium-file="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/RegRipper_Registry-Analysis.jpg?fit=300%2C272&amp;ssl=1" data-large-file="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/RegRipper_Registry-Analysis.jpg?fit=456%2C414&amp;ssl=1" /></a></p>
<h2>4) <a href="https://arsenalrecon.com/weapons/image-mounter/">Arsenal Image Mounter</a> by Arsenal Recon</h2>
<p>The function of mounting a forensic image in Windows is nothing new but AIM is especially proficient. FTK imager has a built-in image mounter, but this one is a little more advanced, and disks are seen in Windows where others have failed due to it’s faked SCSI driver. Arsenal mounts in many different and rarer image formats and even fakes disk serial number if required if mounting errors occur. <strong>*FREE for non-commercial use</strong></p>
<p><a href="https://arsenalrecon.com/weapons/image-mounter/"><img loading="lazy" decoding="async" class="aligncenter wp-image-1131 size-full" title="Arsenal Image Mounters Supported Formats" src="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/File-Types-Supported.jpg?resize=641%2C180&amp;ssl=1" sizes="auto, (max-width: 641px) 100vw, 641px" srcset="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/File-Types-Supported.jpg?w=641&amp;ssl=1 641w, https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/File-Types-Supported.jpg?resize=300%2C84&amp;ssl=1 300w" alt="" width="639" height="179" data-attachment-id="1131" data-permalink="https://compute-forensics.com/top-ten-free-computer-forensic-software/file-types-supported/" data-orig-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/File-Types-Supported.jpg?fit=641%2C180&amp;ssl=1" data-orig-size="641,180" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1520447766&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="File-Types-Supported" data-image-description="" data-medium-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/File-Types-Supported.jpg?fit=300%2C84&amp;ssl=1" data-large-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/File-Types-Supported.jpg?fit=641%2C180&amp;ssl=1" /></a></p>
<h2>5) <a href="https://www.nirsoft.net">Nirsoft</a> Tools by Nir Sofer</h2>
<p>A full suite of analysis tools for Windows artefacts. For forensic analysis, objects may have to be exported out, or examination must take place to a blocked mounted forensic image visible in Windows.</p>
<h2><img loading="lazy" decoding="async" class="aligncenter wp-image-1771" src="https://compute-forensics.com/wp-content/uploads/2018/06/Nirsoft-Tools-Free-Software-300x58.jpg" alt="" width="600" height="117" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/Nirsoft-Tools-Free-Software-300x58.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/Nirsoft-Tools-Free-Software-768x150.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/Nirsoft-Tools-Free-Software-1024x199.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/Nirsoft-Tools-Free-Software-600x117.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/Nirsoft-Tools-Free-Software.jpg 1833w" sizes="auto, (max-width: 600px) 100vw, 600px" />6) <a href="https://www.cgsecurity.org/wiki/PhotoRec">PhotoRec</a> Christopher Grenier</h2>
<p>Whether its a deleted Microsoft email PST item or a lost Encase E01 file, photorec is a data recovery tool that seems to perform well compared to the rest. The list of carvers preloaded is formidable, and the speed is swift. The carving can be completed on a mounted forensic image as to protect the integrity and only on the volumes free space to save time.</p>
<p>&nbsp;</p>
<h2><img loading="lazy" decoding="async" class="aligncenter wp-image-1772" src="https://compute-forensics.com/wp-content/uploads/2018/06/Photorec-Recovery-300x157.jpg" alt="" width="600" height="315" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/Photorec-Recovery-300x157.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/Photorec-Recovery-768x403.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/Photorec-Recovery-600x315.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/Photorec-Recovery.jpg 974w" sizes="auto, (max-width: 600px) 100vw, 600px" />7) <a href="https://github.com/log2timeline/plaso/wiki">Log2timeline</a> maintained by Kristinn Gudjonsson</h2>
<p>This parser is the no one supertimeline tool and can be used in an advanced forensic analysis to extract event times from 1000’s of log/database filetypes and place them into one plaso file output or CSV spreadsheet for analysis natively or using a graphical program. Most paid for or built-in timeline tools just take into account MAC times and can’t parse as many file, registry or database types as log2timeline. If you need to put together times, user actions and other artefacts in one place then log2timeline is the tool of choice.</p>
<h2>8) <a href="https://accessdata.com/product-download">FTK Imager</a> by AccessData</h2>
<p>Imager needs no introduction. Imager does what it says on the tin and more! FTK imager has little-known eDiscovery uses as the software can image by SID owner, create directory listings and image logically to an AD1 format by folder location. Additionally, the tool includes a hex viewer. In incident response, the suite can be used to collect volatile memory as well as a live registry.</p>
<h2><img loading="lazy" decoding="async" class="aligncenter wp-image-1773" src="https://compute-forensics.com/wp-content/uploads/2018/06/FTK_Imager-Free-Forensic-Software-300x158.jpg" alt="" width="600" height="316" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/FTK_Imager-Free-Forensic-Software-300x158.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/FTK_Imager-Free-Forensic-Software-768x404.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/FTK_Imager-Free-Forensic-Software-1024x539.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/FTK_Imager-Free-Forensic-Software-600x316.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/FTK_Imager-Free-Forensic-Software.jpg 1425w" sizes="auto, (max-width: 600px) 100vw, 600px" />9) <a href="https://www.gnu.org/software/ddrescue/">ddrescue</a> GUI by Hamish McIntyre-Bhatty</h2>
<p>This Linux GUI tool that simply put “copies data from one file or block device (hard disc, cd-rom, etc) to another, trying to rescue the good parts first in case of read errors.” ddrescue also produces a map file so you can go back to reimage the old parts of the disk that didn’t copy the first time in order to get a full transversal. It won’t only create an image filled 0s on the parts it can’t read as most imaging tools do. <strong>*Available on Caine</strong></p>
<h2>10) <a href="https://www.magnetforensics.com/magnet-acquire/">Acquire</a> by Magnet Forensics</h2>
<p>To get this hidden gem, you will have to register on Magnets website. Aquire has the imaging functions you find typically in FTK imager and others. MA shines when collecting from smartphones such as Apple and Android devices (forget about Blackberry!) The program will also take a full physical image of rooted android devices and output the data in an agnostic format. The items are best examined using Magnet’s Axiom or IEF.</p>
<p><a href="https://www.magnetforensics.com"><img loading="lazy" decoding="async" class="aligncenter wp-image-1134 size-full" title="Magnet Forensics Acquire can image Phones as well as Computers" src="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Magnet_Aquire_for_iOS-or-Smartphones.jpg?resize=747%2C498&amp;ssl=1" sizes="auto, (max-width: 747px) 100vw, 747px" srcset="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Magnet_Aquire_for_iOS-or-Smartphones.jpg?w=747&amp;ssl=1 747w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Magnet_Aquire_for_iOS-or-Smartphones.jpg?resize=300%2C200&amp;ssl=1 300w" alt="" width="745" height="497" data-attachment-id="1134" data-permalink="https://compute-forensics.com/top-ten-free-computer-forensic-software/magnet_aquire_for_ios-or-smartphones/" data-orig-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Magnet_Aquire_for_iOS-or-Smartphones.jpg?fit=747%2C498&amp;ssl=1" data-orig-size="747,498" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1520447623&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Magnet_Aquire_for_iOS-or-Smartphones" data-image-description="" data-medium-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Magnet_Aquire_for_iOS-or-Smartphones.jpg?fit=300%2C200&amp;ssl=1" data-large-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Magnet_Aquire_for_iOS-or-Smartphones.jpg?fit=747%2C498&amp;ssl=1" /></a></p>
<p>In real cases these tools require specialist training, don’t hesitate to <a href="https://compute-forensics.com/contact-us/">contact us</a> should you have an enquiry!</p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-3 vc_hidden-sm vc_hidden-xs"><div class="vc_column-inner "><div class="wpb_wrapper">
<div class="stm_sidebar">

            <style type="text/css" scoped>
            .vc_custom_1452056597103{margin-right: 0px !important;margin-bottom: 30px !important;margin-left: 0px !important;}.vc_custom_1451998133493{margin-bottom: 30px !important;}.vc_custom_1452056633692{padding-top: 37px !important;padding-right: 30px !important;padding-bottom: 40px !important;padding-left: 30px !important;}.vc_custom_1527964913946{margin-bottom: 9px !important;}.vc_custom_1527964962623{margin-bottom: 17px !important;}.vc_custom_1527965000155{margin-bottom: 30px !important;}        </style>
        <div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1452056597103"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner vc_custom_1452056633692"><div class="wpb_wrapper"><div class="vc_custom_heading vc_custom_1527964913946 text_align_left" ><div style="font-size: 16px;color: #222222;text-align: left;font-family:Poppins;font-weight:600;font-style:normal" class="consulting-custom-title">Contact Us</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1527964962623" >
		<div class="wpb_wrapper">
			<p><span style="font-size: 13px; line-height: 22px;">Compute Forensics are based in London but are available for contracts and work in the global area. Please don’t hesitate to email us at expert@compute-forensics.com for a free online or call consultation.</span></p>

		</div>
	</div>
<div class="vc_btn3-container vc_btn3-inline vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-sm vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-left vc_btn3-color-white" href="https://compute-forensics.com/contact-us/" title=""><i class="vc_btn3-icon fa fa-phone-square"></i> contacts</a></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid vc_custom_1451998133493"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper"><div class="vc_btn3-container vc_btn3-left vc_custom_1527965000155 vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-lg vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-block vc_btn3-icon-left vc_btn3-color-theme_style_1" href="https://compute-forensics.com/pdf/" title="" target="_blank"><i class="vc_btn3-icon fa fa-file-pdf-o"></i> Computer Forensics Professional Services PDF</a></div></div></div></div></div>
</div>    
</div></div></div></div></div><div data-vc-full-width="true" data-vc-full-width-init="false" class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1459505959648"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper">
<section class="vc_cta3-container" >
    <div class="vc_general vc_cta3 third_bg_color vc_cta3-style-flat vc_cta3-shape-square vc_cta3-align-left vc_cta3-color-classic vc_cta3-icon-size-md vc_cta3-actions-right vc_custom_1530194067346 style=""">
                        <div class="vc_cta3_content-container">
                                    <div class="vc_cta3-content">
                <header class="vc_cta3-content-header">
                    <div class="vc_custom_heading" ><h2 style="font-size: 20px;color: #ffffff;line-height: 24px" class="consulting-custom-title">Are you looking for a Computer Forensic Consultant?</h2></div>                                    </header>
                            </div>
                        <div class="vc_cta3-actions"><div class="vc_btn3-container vc_btn3-right vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-md vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-right vc_btn3-color-theme_style_2" href="https://compute-forensics.com/contact-us/" title="">get a quote <i class="vc_btn3-icon fa fa-chevron-right"></i></a></div></div>        </div>
                    </div>
</section></div></div></div></div><div class="vc_row-full-width vc_clearfix"></div>
</div>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How to Create a Forensic Windows Based OS for Free for Forensic Imaging and Triage</title>
		<link>https://compute-forensics.com/how-to-create-a-forensic-windows-based-os-for-free-for-forensic-imaging-and-triage/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Mon, 04 Jun 2018 12:29:56 +0000</pubDate>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Data Acquisition]]></category>
		<category><![CDATA[Forensic Imaging]]></category>
		<category><![CDATA[Triage]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1776</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid vc_custom_1459507906849"><div class="wpb_column vc_column_container vc_col-sm-12 vc_col-lg-9 vc_col-md-9"><div class="vc_column-inner vc_custom_1452702342137"><div class="wpb_wrapper"><div class="vc_custom_heading no_stripe text_align_left" ><h2 style="color: #111111;text-align: left" class="consulting-custom-title">How to Create a Forensic Windows Based OS for Free for Forensic Imaging and Triage</h2></div><div class="post_details_wr ">
    
<div class="stm_post_info">
	<div class="stm_post_details clearfix">
		<ul class="clearfix">
			<li class="post_date">
				<i class="fa fa fa-clock-o"></i>
				04/06/2018			</li>
			<li class="post_by">Posted by:				<span>Alistair Ewing</span>
			</li>
			<li class="post_cat">Categories:				<span>Computer Forensics, Software, Uncategorized</span>
			</li>
		</ul>
		<div class="comments_num">
			<a href="https://compute-forensics.com/how-to-create-a-forensic-windows-based-os-for-free-for-forensic-imaging-and-triage/#respond"><i class="fa fa-comment-o"></i>No Comments </a>
		</div>
	</div>
			<div class="post_thumbnail">
			<img loading="lazy" decoding="async" width="1030" height="550" src="https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-1030x550.jpg" class="attachment-consulting-image-1110x550-croped size-consulting-image-1110x550-croped wp-post-image" alt="" />		</div>
	</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1530194840588" >
		<div class="wpb_wrapper">
			<h3>Introduction</h3>
<p>This brief overview is designed for those with an IT background, students, forensic analysts or budding first responders.  This will teach you the basics of how to create a Windows-based forensic OS for imaging and less commonly triage for free provided you own a valid Windows licence.</p>
<p>The consultancy <strong>Compute Forensics</strong> offers a worldwide three-day onsite first responder training in English and the Thai language for corporates, military and international police services. Those who have moderate computer literacy can be trained to triage and collect without affecting the original medium before handing over to a computer forensic expert or even the authorities. One should never start using self-made tools without testing.</p>
<p><a href="https://compute-forensics.com/contact-us/" rel="noopener">Contact us</a> for a quote in regards to training, collection or even an investigation.</p>
<p>We also offer a remote triage service, by sending a bootable drive with secure remote access software pre-installed we can forensically image a device from across the world without modifying the contents thus preserving the material.</p>
<p>I recommend the online training and exam from the forensic author, Brett Shavers. He runs an online course which you can find <a href="http://courses.dfironlinetraining.com/forensic-operating-systems?pc=fos-032018">here</a>.</p>
<p>Please be mindful this guide is for research purposes. Please test and <strong>use at your own risk! </strong></p>
<p>Be mindful that specific software may be not allowed for use in corporate settings as you may break the software companies EULA agreement.</p>
<h3>How Does a Forensic Windows OS Work?</h3>
<p>If the build process completes correctly, a unique modified Windows is created on a USB drive, ISO or CD or DVD. When booting from a forensic OS, the BIOS of the host system bypasses the internal physical disk booting from the information on the USB drive (for Windows To Go) or the data saved to the volatile RAM transferred from the boot media (for Mini-WinFE.)</p>
<p>Windows should not mount the internal fixed disk but connected USB disks in the case of Windows To Go or any discs what so ever using WinFE.</p>
<p>Please note: When using <strong>DISKPART </strong>from CMD in Windows To Go you can mount Disks Read Only but NOT Volumes. Doing so writes to the disk. You can still image using Forensics or FTK Imager without doing any mounting. If you want to use specific triage tools in a blocked mounted state, you may need to bring the disk online, but remember never bring the Volume online. <strong>ALWAYS</strong> test your build.</p>
<p>Practice using Diskpart and the toggling of online and offline correct, many think they are smart using the command line, but one wrong move and you could wipe, format or mount a volume leaving you to explain your actions in an Expert Witness or corporate hearing.</p>
<h3><strong>Why Would I Need a Windows Based Forensic OS?</strong></h3>
<p>Other forensic OS’s exist as do physical writeblockers. <strong>Linux</strong> (<a href="https://www.caine-live.net">Caine</a>, <a href="https://sumuri.com/software/paladin/">Paladin</a>, and others) and <strong>Mac</strong> formats (Sumuri’s <a href="https://sumuri.com/software/recon/">Recon</a> &amp; BlackBag’s <a href="https://www.blackbagtech.com/software-products/macquisition.html">Macaquisition</a>) can collect data, but I estimate 80% of forensic software is produced for Windows. Imagine being able to boot into Windows and use tools such as Netcat, FTK Imager, <a href="https://www.osforensics.com">OSforensics</a> or even full-blown FTK on your Bitlockered Frankenstein creation. This would enable you to carry a Swiss army knife of tools at your disposal.</p>
<p>Using a <strong>Windows Forensic OS</strong> you can:</p>
<ul>
<li>Collect data from software RAIDS and logically image the device rather than having to piece together physical images later saving time.</li>
<li>Decrypt Bitlockereddrives and image/triage them in a decrypted state and physical state consecutively using CMD looking something like “manage-bde –unlock E: -recoverypassword 111111-222222-333333-444444-555555-666666-777777-888888.”</li>
<li>Produce decrypted logical images on the fly from Truecrypt, PGP and Veracrypt using default Windows tools.</li>
<li>Boot into your Bitlockered ‘Windows To Go’<strong> </strong>and use your client’s hardware to attach to their domain with admin rights temporarily, run FTK to capture a suspects RAM and physical disk Image remotely without having to lug a laptop or even worse a workstation to the client’s site.</li>
<li>Travel light with a few USB keys in different countries without lugging 20 pelican cases and getting stopped by airport security whom mistake the devices for dirty nuclear bombs.</li>
<li>Use data recovery tools such as photorec without making changes to the drive.</li>
<li>Triage and quickly find and capture forensically the information needed with only primary first responder training and no expensive equipment.</li>
<li>Production of a log2timeline to capture users actions between specific dates.</li>
<li>Windows2go could be sent to a client with a copy of Teamviewer or similar. With instructions and connected to the internet the client could boot into the forensic OS, an examiner from across the world can log in and take over the collection process going on to capturing the internal physical disk as an E01 to an encrypted drive. When complete the client can mail the item back for analysis saving on travel costs.</li>
</ul>
<h3>Forensic OS Route 1: Native to Enterprise ‘Windows To Go’</h3>
<p>If you own a copy of Windows 10 Enterprise and you purchase one of the certified ‘Windows To Go’ drives (See Below) to make your OS. All you need to do is press the “Win Key&amp; Q” together and type ‘Windows To Go’ into the search bar. Plug in your drive and follow the instructions. You will be asked if you want to Bitlocker the drive, it is recommended but be aware it may not boot on Mac’s or specific other systems.</p>
<p><strong>Certified Windowstogo Drives</strong></p>
<ul>
<li>Imation IronKey™ Workspace W300 / W500 / W700</li>
<li>Kingston DataTraveler Workspace</li>
<li>Spyrus Portable Workplace</li>
<li>Spyrus Secure Portable Workplace</li>
<li>Spyrus WorkSafe</li>
<li>Super Talent RC4 / RC8</li>
<li>WD My Passport Enterprise</li>
<li>SanDisk Extreme CZ80 USB 3.0 Flash Drive</li>
<li>SanDisk Extreme CZ88 USB 3.0 Flash Drive</li>
</ul>
<h3>Using Other Drives Including an M.2 SSD in a USB 3.1 Caddy</h3>
<p>If you are a ‘Cheap Charlie’ or are feeling more adventurous, you can try other disks, although they are unsupported officially.</p>
<p>I tested a “SAMSUNG M.2 NGFF 128GB SSD SOLID STATE DRIVE MZ-NTE1280” (£40 from Amazon) inside a USB 3.1 “Type C To M.2 NGFF PCI-E SSD Hard Disk Case Enclosure 2242/2260/2280 caddy” (£10 pictured below.) When the enclosure arrived in the post, it looked like something out of a Christmas cracker. When I assembled the device, which took two minutes, I was pleased with how robust it felt. Windows To Go recognised the disk. Windows To Go was installed in about 10 minutes using the built-in GUI.</p>
<p>Speeds faster than the ‘certified’ drives were noted in tests at around 500mb a second read/write and use was not noticeably slower than using my native Crucial M.2 built into my high-end test laptop.</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-1182 aligncenter" src="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Bespoke_Windows-yo-go_Caddy.jpg?resize=485%2C393&amp;ssl=1" alt="Make your own bootable Windows for travel" width="483" height="391" data-attachment-id="1182" data-permalink="https://compute-forensics.com/how-to-create-forensic-windows-based-os-for-free-for-forensic-imaging-and-triage/bespoke_windows-yo-go_caddy/" data-orig-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Bespoke_Windows-yo-go_Caddy.jpg?fit=485%2C393&amp;ssl=1" data-orig-size="485,393" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1521662693&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Bespoke_Windows-to-go_Caddy" data-image-description="" data-medium-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Bespoke_Windows-yo-go_Caddy.jpg?fit=300%2C243&amp;ssl=1" data-large-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Bespoke_Windows-yo-go_Caddy.jpg?fit=485%2C393&amp;ssl=1" /></p>
<p>To use the newly created OS on a stick, you need to plug it into a computer and press whatever button you need to boot from your disk, not the internal drive (Esc, F11, F12, Delete.) On first boot, you will have to setup Windows just like any other new installation of Windows. Do not wait until you are on the client site!</p>
<h3>Using DISKPART to Bring Disks Online</h3>
<p>When you use Windows To Go any attached USB devices will be writable. The internal disks will be offline and unavailable to Windows. FTK Imager and other software will still be able to view, image and parse the internal drives. If you wish to Triage using other tools you may need to bring the disk online using disk manager or DISKPART in CMD as an admin. The command would be something like:</p>
<p>1) Run CMD as an admin</p>
<p>2) Type DISKPART</p>
<p>3) LIST DISKS</p>
<p>4) SELECT DISK 2 (2 being an example of the internal disk under review)</p>
<p>5) ONLINE DISK. The disk should then be shown in explorer but in a blocked state. Practice taking the disks offline and online using DISKPART before using this on evidence! You should be able to use Nirsoft and other live tools to analyse the internal disk without writing to it.</p>
<p><img loading="lazy" decoding="async" class="aligncenter" src="https://i1.wp.com/support.ca.com/cadocs/0/CA%20ARCserve%20Replication%20and%20High%20Availability%20r16%205-ENU/Bookshelf_Files/HTML/VMS/2069447.png?w=1140&amp;ssl=1" alt="list disk and volume command" width="534" height="181" /></p>
<p>It is noteworthy to mention boot USB producing software Rufus produces Windows To Go but this has not been tested yet!</p>
<p>The downside to this method is that you need to learn the command prompt of DISKPART, this isn’t easy but not ideal for first responders. People with less Windows knowledge and whom want a cleaner smaller build should consider building a custom Mini-WinFE.</p>
<h3>Forensic OS Route 2: Building your Own Custom Mini-WinFE</h3>
<p>Using a GUI assembler and Windows installation media, it is possible to build a bootable OS in minutes that will have a GUI disk read/write toggler, can contain tools such as FTK Imager or DD and be under 300mb in size. This is enough to fit onto a writable CD or Mini CD (recommended for compatibility even old systems have CD drives) or even a dated 1.0 or 2.0 USB key.</p>
<p>The beauty of that is you can customise a stripped down version of Windows that can triage, is blocked using a GUI and that boots in seconds without all the ‘fluff’ the Windows To Go build contains.</p>
<p>Producing a Mini-WinFE is tricky, and if you add too many features you may end up bypassing the protection making the internal disks prone to changes, not good!</p>
<p>The secret is not to add too many features and test your creation on your system, not evidence.</p>
<p>Below is a step by step how-to produce your first basic 32-bit Forensic Mini-WinFE:</p>
<p><strong><img loading="lazy" decoding="async" class="aligncenter wp-image-1781" src="https://compute-forensics.com/wp-content/uploads/2018/06/PE-Bakery_Build-Mini_WINFE-300x241.jpg" alt="" width="600" height="481" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/PE-Bakery_Build-Mini_WINFE-300x241.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/PE-Bakery_Build-Mini_WINFE-768x616.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/PE-Bakery_Build-Mini_WINFE-600x481.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/PE-Bakery_Build-Mini_WINFE.jpg 883w" sizes="auto, (max-width: 600px) 100vw, 600px" />(Above) Mini-WinFE’s GUI </strong></p>
<ol>
<li>Download Mini-WinFE <a href="http://www.brettshavers.cc/index.php/brettsblog/entry/windows-forensic-environment-newest-project-is-complete">here</a> or <a href="https://ln.sync.com/dl/62e6302b0#r8in7m6s-xydgcwp9-hb2dbfg9-ijybm5rm">here.</a></li>
<li>Extract the Zip to a clean directory and run the launcher inside the Mini-WinFE folder as an admin.</li>
<li>Mount your Windows installation ISO or slip the DVD into your disk drive. I prefer 32-bit as it boots on both types of system. I used Windows 10 Enterprise as the Windows build.</li>
<li>In settings point your source directory to your Windows DVD location or the folder you have dumped the contents of the Windows installation media.</li>
<li>Create a working directory in the Mini-WinFE folder you just extracted and use this as your target directory.</li>
<li>Go to the FTK imager tab and point FTK to any 32-bit EXE. You can register and download Imager from <a href="https://accessdata.com/product-download">here</a>. I like to use version 3.1.1. A 64-bit version cannot be built into the cache for a 32-bit machine.</li>
<li>In the ‘Path to 32-bit’ area press the folder button and select the FTK image EXE file you have installed or extracted.</li>
<li>Option 1 allows you to select booting from FLAT or RAM. I would choose RAM; FLAT means the item boots from the medium and results in a larger ISO or USB output.</li>
<li>Tick all the programs boxes except add custom batch and folders unless you wish to do this.</li>
<li>Tick the create ISO tab and read the hover over suggestions.</li>
<li>In the create ISO section option 3 the drop-down box allows a user to select the Firmware type. Older computers use BIOS (Basic Input Output System) newer have UFEI firmware and can ofter boot the older BIOS software or UFEI. There are three options; I would select the ‘both’ option if you are unsure.</li>
<li>Select ‘oscdimg’ for an option.</li>
<li>Change the optimise option to ‘yes’ for option 5. This will result in a smaller ISO.</li>
<li>Selecting ‘yes’ for option 6 will build the ISO file in a newly created \mistyPR.Project.Output folder path in your project folder. Selecting ‘no’ will name the iso with the date and time to allow you to make multiple builds without writing over the older builds.</li>
<li>Select the triangular ‘Play’ logo with the ‘Build’ tab underneath.</li>
<li>If all goes well, you should have built your first forensic ISO. The file can be found in the output folder of your Mini-WinFE folder or the root of that folder.</li>
<li>The ISO can be burnt to CD, Mini-CD or DVD, or you can also use <a href="https://unetbootin.github.io">Unetbootin</a> or <a href="https://rufus.akeo.ie">Rufus</a> to make a bootable USB from the ISO.</li>
<li>Sometimes a system won’t boot from a USB or not from sometimes a CD or DVD. Produce a few versions and label them.</li>
<li>You will have to tinker to get different builds to boot on different systems. To work on my system, I had to enter the BIOS, change the boot from UFEI to legacy. Be careful on evidence that has a TPM chip linked BitLocker as you could end up rendering the drive unbootable by disabling TMP in the BIOS.</li>
<li>Be sure to photograph the Bios when working with real evidence. In the boot setup of the BIOS take all the internal disks offline and have your forensic USB followed by CD/DVD in the boot order.</li>
<li>If the process works, you will be greeted by the disk manager, and this shows you which disks you can make writable or bring online for triage. <strong>Be careful not to bring the evidence volumes online.</strong> You can right click to find out more about the disk to make sure you make the correct selection. You don’t need to bring a disk online to image it though.</li>
<li>Closing the file manager window results in a forensic desktop being displayed.</li>
<li>Right-clicking on the desktop displays the drop-down menu in which you can scroll through and make utilisation of the differing tools.</li>
<li>Below displays a screenshot of the ISO successfully running in a test virtual box environment.</li>
</ol>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-1782" src="https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-300x246.jpg" alt="" width="600" height="492" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-300x246.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-768x629.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-1024x839.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-600x492.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows.jpg 1030w" sizes="auto, (max-width: 600px) 100vw, 600px" />Please Like or Share this guide should you find it useful!</p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-3 vc_hidden-sm vc_hidden-xs"><div class="vc_column-inner "><div class="wpb_wrapper">
<div class="stm_sidebar">

            <style type="text/css" scoped>
            .vc_custom_1452056597103{margin-right: 0px !important;margin-bottom: 30px !important;margin-left: 0px !important;}.vc_custom_1451998133493{margin-bottom: 30px !important;}.vc_custom_1452056633692{padding-top: 37px !important;padding-right: 30px !important;padding-bottom: 40px !important;padding-left: 30px !important;}.vc_custom_1527964913946{margin-bottom: 9px !important;}.vc_custom_1527964962623{margin-bottom: 17px !important;}.vc_custom_1527965000155{margin-bottom: 30px !important;}        </style>
        <div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1452056597103"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner vc_custom_1452056633692"><div class="wpb_wrapper"><div class="vc_custom_heading vc_custom_1527964913946 text_align_left" ><div style="font-size: 16px;color: #222222;text-align: left;font-family:Poppins;font-weight:600;font-style:normal" class="consulting-custom-title">Contact Us</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1527964962623" >
		<div class="wpb_wrapper">
			<p><span style="font-size: 13px; line-height: 22px;">Compute Forensics are based in London but are available for contracts and work in the global area. Please don’t hesitate to email us at expert@compute-forensics.com for a free online or call consultation.</span></p>

		</div>
	</div>
<div class="vc_btn3-container vc_btn3-inline vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-sm vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-left vc_btn3-color-white" href="https://compute-forensics.com/contact-us/" title=""><i class="vc_btn3-icon fa fa-phone-square"></i> contacts</a></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid vc_custom_1451998133493"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper"><div class="vc_btn3-container vc_btn3-left vc_custom_1527965000155 vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-lg vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-block vc_btn3-icon-left vc_btn3-color-theme_style_1" href="https://compute-forensics.com/pdf/" title="" target="_blank"><i class="vc_btn3-icon fa fa-file-pdf-o"></i> Computer Forensics Professional Services PDF</a></div></div></div></div></div>
</div>    
</div></div></div></div></div><div data-vc-full-width="true" data-vc-full-width-init="false" class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1459505959648"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper">
<section class="vc_cta3-container" >
    <div class="vc_general vc_cta3 third_bg_color vc_cta3-style-flat vc_cta3-shape-square vc_cta3-align-left vc_cta3-color-classic vc_cta3-icon-size-md vc_cta3-actions-right vc_custom_1530552651544 style=""">
                        <div class="vc_cta3_content-container">
                                    <div class="vc_cta3-content">
                <header class="vc_cta3-content-header">
                    <div class="vc_custom_heading" ><h2 style="font-size: 20px;color: #ffffff;line-height: 24px" class="consulting-custom-title">Looking for a Remote Collection or Investigation Service?</h2></div>                                    </header>
                            </div>
                        <div class="vc_cta3-actions"><div class="vc_btn3-container vc_btn3-right vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-md vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-right vc_btn3-color-theme_style_2" href="https://compute-forensics.com/contact-us/" title="">get a quote <i class="vc_btn3-icon fa fa-chevron-right"></i></a></div></div>        </div>
                    </div>
</section></div></div></div></div><div class="vc_row-full-width vc_clearfix"></div>
</div>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Bitcoin Wallet Recovery</title>
		<link>https://compute-forensics.com/bitcoin-wallet-recovery/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Mon, 04 Jun 2018 11:25:10 +0000</pubDate>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Investigative Techniques]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Bitcoin]]></category>
		<category><![CDATA[Data Recovery]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1775</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid vc_custom_1459507906849"><div class="wpb_column vc_column_container vc_col-sm-12 vc_col-lg-9 vc_col-md-9"><div class="vc_column-inner vc_custom_1452702342137"><div class="wpb_wrapper"><div class="vc_custom_heading no_stripe text_align_left" ><h2 style="color: #111111;text-align: left" class="consulting-custom-title">Bitcoin Wallet Recovery</h2></div><div class="post_details_wr ">
    
<div class="stm_post_info">
	<div class="stm_post_details clearfix">
		<ul class="clearfix">
			<li class="post_date">
				<i class="fa fa fa-clock-o"></i>
				04/06/2018			</li>
			<li class="post_by">Posted by:				<span>Alistair Ewing</span>
			</li>
			<li class="post_cat">Categories:				<span>Computer Forensics, Investigative Techniques, Uncategorized</span>
			</li>
		</ul>
		<div class="comments_num">
			<a href="https://compute-forensics.com/bitcoin-wallet-recovery/#respond"><i class="fa fa-comment-o"></i>No Comments </a>
		</div>
	</div>
			<div class="post_thumbnail">
			<img loading="lazy" decoding="async" width="768" height="539" src="https://compute-forensics.com/wp-content/uploads/2018/06/Bitcoin-Data-Recovery.jpg" class="attachment-consulting-image-1110x550-croped size-consulting-image-1110x550-croped wp-post-image" alt="" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/Bitcoin-Data-Recovery.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/Bitcoin-Data-Recovery-300x211.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/Bitcoin-Data-Recovery-600x421.jpg 600w" sizes="auto, (max-width: 768px) 100vw, 768px" />		</div>
	</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1528115106362" >
		<div class="wpb_wrapper">
			<p>Lost your cryptocurrency wallet? Was the bitcoin storage unit accidentally deleted? Has the disk become faulty or has the drive been formatted accidentally? Compute Forensics may be able to help. Using specialist data recovery techniques Compute can forensically capture from a forensic bit for bit copy of the original drive and carve your data to recover your funds. It does not matter the format of your wallet; we can tailor carving recovery queries and retrieve your lost crypto wallet.</p>
<h4>If a Cryptocurrency Wallet is Deleted is it Gone Forever?</h4>
<p>Take note, when space a file marked a deleted has not been occupied by new data there is still a good chance of recovery. Additionally just because a drive cannot be read in Windows or on an Apple Mac system does not mean that a data recovery specialist using specialised tools and techniques.</p>
<h4>Is Bitcoin the Future?</h4>
<p>Cryptocurrency is fast becoming the new alternative payment system. As well as being an exciting new investment opportunity Bitcoin, Litecoin and others of that ilk offer alternative ways for consumers and enterprises to exchange payment for goods and services out of the reach of the middlemen like the banks.</p>
<p>The medium provides a real opportunity for libertarianism and financial freedom. Now the small coffee farmer from the foothills of Peru Mexico can trade their product armed with only a computer and internet access in exchange for bitcoin in the West without even owning a bank account. The currency is still in its early phases but may become a national currency 30 years from now for some countries.</p>
<h4>Contact us for a Quote!</h4>
<p>Contact us for an estimate; we can operate on a % of wallet value as payment or fixed fee recovery option.</p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-3 vc_hidden-sm vc_hidden-xs"><div class="vc_column-inner "><div class="wpb_wrapper">
<div class="stm_sidebar">

            <style type="text/css" scoped>
            .vc_custom_1452056597103{margin-right: 0px !important;margin-bottom: 30px !important;margin-left: 0px !important;}.vc_custom_1451998133493{margin-bottom: 30px !important;}.vc_custom_1452056633692{padding-top: 37px !important;padding-right: 30px !important;padding-bottom: 40px !important;padding-left: 30px !important;}.vc_custom_1527964913946{margin-bottom: 9px !important;}.vc_custom_1527964962623{margin-bottom: 17px !important;}.vc_custom_1527965000155{margin-bottom: 30px !important;}        </style>
        <div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1452056597103"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner vc_custom_1452056633692"><div class="wpb_wrapper"><div class="vc_custom_heading vc_custom_1527964913946 text_align_left" ><div style="font-size: 16px;color: #222222;text-align: left;font-family:Poppins;font-weight:600;font-style:normal" class="consulting-custom-title">Contact Us</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1527964962623" >
		<div class="wpb_wrapper">
			<p><span style="font-size: 13px; line-height: 22px;">Compute Forensics are based in London but are available for contracts and work in the global area. Please don’t hesitate to email us at expert@compute-forensics.com for a free online or call consultation.</span></p>

		</div>
	</div>
<div class="vc_btn3-container vc_btn3-inline vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-sm vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-left vc_btn3-color-white" href="https://compute-forensics.com/contact-us/" title=""><i class="vc_btn3-icon fa fa-phone-square"></i> contacts</a></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid vc_custom_1451998133493"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper"><div class="vc_btn3-container vc_btn3-left vc_custom_1527965000155 vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-lg vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-block vc_btn3-icon-left vc_btn3-color-theme_style_1" href="https://compute-forensics.com/pdf/" title="" target="_blank"><i class="vc_btn3-icon fa fa-file-pdf-o"></i> Computer Forensics Professional Services PDF</a></div></div></div></div></div>
</div>    
</div></div></div></div></div><div data-vc-full-width="true" data-vc-full-width-init="false" class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1459505959648"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper">
<section class="vc_cta3-container" >
    <div class="vc_general vc_cta3 third_bg_color vc_cta3-style-flat vc_cta3-shape-square vc_cta3-align-left vc_cta3-color-classic vc_cta3-icon-size-md vc_cta3-actions-right vc_custom_1530194033529 style=""">
                        <div class="vc_cta3_content-container">
                                    <div class="vc_cta3-content">
                <header class="vc_cta3-content-header">
                    <div class="vc_custom_heading" ><h2 style="font-size: 20px;color: #ffffff;line-height: 24px" class="consulting-custom-title">Are you looking for a Data Recovery Expert?</h2></div>                                    </header>
                            </div>
                        <div class="vc_cta3-actions"><div class="vc_btn3-container vc_btn3-right vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-md vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-right vc_btn3-color-theme_style_2" href="https://compute-forensics.com/contact-us/" title="">get a quote <i class="vc_btn3-icon fa fa-chevron-right"></i></a></div></div>        </div>
                    </div>
</section></div></div></div></div><div class="vc_row-full-width vc_clearfix"></div>
</div>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Global Forensic Imaging Service</title>
		<link>https://compute-forensics.com/computer-forensic-imaging/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Fri, 22 Jan 2016 05:43:23 +0000</pubDate>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Investigative Techniques]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Data Acquisition]]></category>
		<category><![CDATA[Forensic Imaging]]></category>
		<guid isPermaLink="false">http://consulting.stylemixthemes.com/?p=748</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid vc_custom_1459507906849"><div class="wpb_column vc_column_container vc_col-sm-12 vc_col-lg-9 vc_col-md-9"><div class="vc_column-inner vc_custom_1452702342137"><div class="wpb_wrapper"><div class="vc_custom_heading no_stripe text_align_left" ><h2 style="color: #111111;text-align: left" class="consulting-custom-title">Global Forensic Imaging Service</h2></div><div class="post_details_wr ">
    
<div class="stm_post_info">
	<div class="stm_post_details clearfix">
		<ul class="clearfix">
			<li class="post_date">
				<i class="fa fa fa-clock-o"></i>
				22/01/2016			</li>
			<li class="post_by">Posted by:				<span>Alistair Ewing</span>
			</li>
			<li class="post_cat">Categories:				<span>Computer Forensics, Investigative Techniques, Legal, Uncategorized</span>
			</li>
		</ul>
		<div class="comments_num">
			<a href="https://compute-forensics.com/computer-forensic-imaging/#respond"><i class="fa fa-comment-o"></i>No Comments </a>
		</div>
	</div>
			<div class="post_thumbnail">
			<img loading="lazy" decoding="async" width="768" height="550" src="https://compute-forensics.com/wp-content/uploads/2016/01/2011-07-13-09-54-24-768x550.jpg" class="attachment-consulting-image-1110x550-croped size-consulting-image-1110x550-croped wp-post-image" alt="" srcset="https://compute-forensics.com/wp-content/uploads/2016/01/2011-07-13-09-54-24-768x550.jpg 768w, https://compute-forensics.com/wp-content/uploads/2016/01/2011-07-13-09-54-24-350x250.jpg 350w, https://compute-forensics.com/wp-content/uploads/2016/01/2011-07-13-09-54-24-255x182.jpg 255w" sizes="auto, (max-width: 768px) 100vw, 768px" />		</div>
	</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1530092935130" >
		<div class="wpb_wrapper">
			<p><strong>Compute Forensics LTD</strong> offer a global reach for our personalised forensic imaging process. We have agents and associates available at short notice to collect a plethora of data forensically. We cater to law firms, litigation support and even provide services for other digital forensic companies!</p>
<h4>Why perform a forensic acquisition? Why not just copy the data?</h4>
<p>Using IT staff or a layperson to copy data for a legal case or tribunal may jeopardise the integrity of the source data. Files are volatile, and any access or removal may result in data loss, a change in time stamp records or inadmissible evidence. Using a Compute Forensics LTD vetted Digital Forensic Expert ensures that the data can be copied in its entirety where possible including deleted areas and other partitions not picked up by copying. Along with that full chain of custody logs, exhibit tracking, digital fingerprints and collection reports can be produced to your companies or international standards. The end product will be working, and a backup copy of the target disk be it a Windows Machine, Apple Mac, Linux server or mobile phone (4000+ models supported) and documentation above. The deliverables can then be examined and exhibited. The exhibits and documents must appear robust enough to stand the scrutiny of the worlds most vigilant expert witnesses. The main advantage of examing a forensic image over the source disk is that exploring, even in a blocked state, may wear the source storage unit thus rendering any chance of precious data recovery and investigation impossible.</p>

		</div>
	</div>
<div class="vc_row wpb_row vc_inner vc_row-fluid vc_custom_1452700243026"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<ul>
<li style="margin-bottom: 15px;"><strong>Tools and techniques</strong><br />
<span style="font-size: 13px;">Compute Forensics use a parallel forensic imaging approach, so the client only billed for the hour. The method the collection expert uses mean that specialist can copy as many drives at once as there are power sources. We image using tested forensic boot USB disks, and the fastest USB 3.0-3.1 write blocking equipment only.</span></li>
<li style="margin-bottom: 15px;"><strong>Remote Imaging</strong><br />
<span style="font-size: 13px;">On occasions, it may not be possible for an examiner to go the location of the data in person. In these circumstances, Compute can mail out a custom USB disk or CD and an encrypted destination USB 3.0 external drive. Compute can carefully guide the client through booting up the forensic write-blocked operating system. The user establishes a secure remote connection through the internet, and the expert can then go on to set the target disk copying to the now unencrypted destination drive. On completion the client can unplug the destination disk, sending it tracked to the processing lab preferred location. Should the destination data drive become lost in the postal system the client’s intellectual property is safe as the entire drive is locked using Veracrypt or similar needing a password to view the contents.</span></li>
</ul>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<ul>
<li style="margin-bottom: 15px;"><strong>What happens when you come across Faulty Disks?</strong><br />
<span style="font-size: 13px;">We do not except filling in data with zeros on faulty sectors where evidence may reside or retrying defective drives further damaging the disk. Using advanced data recovery tools can copy the whole disc and retry bad areas until we get as close to a full 100% read as possible.</span></li>
<li style="margin-bottom: 15px;"><strong>We have a server or system that cannot be powered down, can you still aid us?</strong><br />
<span style="font-size: 13px;">Yes! By using special forensic software and techniques, our digital collection specialists can copy live files that are in use while preserving the Last Modified dates and other relevant metadata.</span></li>
</ul>
<p>Once all the data has completed copying over and verifying, the files are then to be packaged inside a forensic container file. Unique digital fingerprints as MD5 or SHA1 hash sums are generated and certified identical to the original to ensure data integrity before signing the data out.</p>
<p>There is no need for server downtime!</p>

		</div>
	</div>
</div></div></div></div></div></div></div><div class="wpb_column vc_column_container vc_col-sm-3 vc_hidden-sm vc_hidden-xs"><div class="vc_column-inner "><div class="wpb_wrapper">
<div class="stm_sidebar">

            <style type="text/css" scoped>
            .vc_custom_1452056597103{margin-right: 0px !important;margin-bottom: 30px !important;margin-left: 0px !important;}.vc_custom_1451998133493{margin-bottom: 30px !important;}.vc_custom_1452056633692{padding-top: 37px !important;padding-right: 30px !important;padding-bottom: 40px !important;padding-left: 30px !important;}.vc_custom_1527964913946{margin-bottom: 9px !important;}.vc_custom_1527964962623{margin-bottom: 17px !important;}.vc_custom_1527965000155{margin-bottom: 30px !important;}        </style>
        <div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1452056597103"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner vc_custom_1452056633692"><div class="wpb_wrapper"><div class="vc_custom_heading vc_custom_1527964913946 text_align_left" ><div style="font-size: 16px;color: #222222;text-align: left;font-family:Poppins;font-weight:600;font-style:normal" class="consulting-custom-title">Contact Us</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1527964962623" >
		<div class="wpb_wrapper">
			<p><span style="font-size: 13px; line-height: 22px;">Compute Forensics are based in London but are available for contracts and work in the global area. Please don’t hesitate to email us at expert@compute-forensics.com for a free online or call consultation.</span></p>

		</div>
	</div>
<div class="vc_btn3-container vc_btn3-inline vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-sm vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-left vc_btn3-color-white" href="https://compute-forensics.com/contact-us/" title=""><i class="vc_btn3-icon fa fa-phone-square"></i> contacts</a></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid vc_custom_1451998133493"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper"><div class="vc_btn3-container vc_btn3-left vc_custom_1527965000155 vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-lg vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-block vc_btn3-icon-left vc_btn3-color-theme_style_1" href="https://compute-forensics.com/pdf/" title="" target="_blank"><i class="vc_btn3-icon fa fa-file-pdf-o"></i> Computer Forensics Professional Services PDF</a></div></div></div></div></div>
</div>    
</div></div></div></div></div><div data-vc-full-width="true" data-vc-full-width-init="false" class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1459505959648"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper">
<section class="vc_cta3-container" >
    <div class="vc_general vc_cta3 third_bg_color vc_cta3-style-flat vc_cta3-shape-square vc_cta3-align-left vc_cta3-color-classic vc_cta3-icon-size-md vc_cta3-actions-right vc_custom_1527966594214 style=""">
                        <div class="vc_cta3_content-container">
                                    <div class="vc_cta3-content">
                <header class="vc_cta3-content-header">
                    <div class="vc_custom_heading" ><h2 style="font-size: 20px;color: #ffffff;line-height: 24px" class="consulting-custom-title">Are you looking for a Compute Forensic Consultant?</h2></div>                                    </header>
                            </div>
                        <div class="vc_cta3-actions"><div class="vc_btn3-container vc_btn3-right vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-md vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-right vc_btn3-color-theme_style_2" href="https://compute-forensics.com/contact-us/" title="">get a quote <i class="vc_btn3-icon fa fa-chevron-right"></i></a></div></div>        </div>
                    </div>
</section></div></div></div></div><div class="vc_row-full-width vc_clearfix"></div>
</div>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
