<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Triage Archives - Compute Forensics LTD London Computer &amp; Mobile Phone Forensic Expert Witness Investigation Services</title>
	<atom:link href="https://compute-forensics.com/tag/triage/feed/" rel="self" type="application/rss+xml" />
	<link>https://compute-forensics.com/tag/triage/</link>
	<description></description>
	<lastBuildDate>Tue, 03 Jul 2018 18:10:17 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://compute-forensics.com/wp-content/uploads/2018/06/cropped-cropped-CF-1-32x32.png</url>
	<title>Triage Archives - Compute Forensics LTD London Computer &amp; Mobile Phone Forensic Expert Witness Investigation Services</title>
	<link>https://compute-forensics.com/tag/triage/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>How to Create a Forensic Windows Based OS for Free for Forensic Imaging and Triage</title>
		<link>https://compute-forensics.com/how-to-create-a-forensic-windows-based-os-for-free-for-forensic-imaging-and-triage/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Mon, 04 Jun 2018 12:29:56 +0000</pubDate>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Data Acquisition]]></category>
		<category><![CDATA[Forensic Imaging]]></category>
		<category><![CDATA[Triage]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1776</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid vc_custom_1459507906849"><div class="wpb_column vc_column_container vc_col-sm-12 vc_col-lg-9 vc_col-md-9"><div class="vc_column-inner vc_custom_1452702342137"><div class="wpb_wrapper"><div class="vc_custom_heading no_stripe text_align_left" ><h2 style="color: #111111;text-align: left" class="consulting-custom-title">How to Create a Forensic Windows Based OS for Free for Forensic Imaging and Triage</h2></div><div class="post_details_wr ">
    
<div class="stm_post_info">
	<div class="stm_post_details clearfix">
		<ul class="clearfix">
			<li class="post_date">
				<i class="fa fa fa-clock-o"></i>
				04/06/2018			</li>
			<li class="post_by">Posted by:				<span>Alistair Ewing</span>
			</li>
			<li class="post_cat">Categories:				<span>Computer Forensics, Software, Uncategorized</span>
			</li>
		</ul>
		<div class="comments_num">
			<a href="https://compute-forensics.com/how-to-create-a-forensic-windows-based-os-for-free-for-forensic-imaging-and-triage/#respond"><i class="fa fa-comment-o"></i>No Comments </a>
		</div>
	</div>
			<div class="post_thumbnail">
			<img fetchpriority="high" decoding="async" width="1030" height="550" src="https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-1030x550.jpg" class="attachment-consulting-image-1110x550-croped size-consulting-image-1110x550-croped wp-post-image" alt="" />		</div>
	</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1530194840588" >
		<div class="wpb_wrapper">
			<h3>Introduction</h3>
<p>This brief overview is designed for those with an IT background, students, forensic analysts or budding first responders.  This will teach you the basics of how to create a Windows-based forensic OS for imaging and less commonly triage for free provided you own a valid Windows licence.</p>
<p>The consultancy <strong>Compute Forensics</strong> offers a worldwide three-day onsite first responder training in English and the Thai language for corporates, military and international police services. Those who have moderate computer literacy can be trained to triage and collect without affecting the original medium before handing over to a computer forensic expert or even the authorities. One should never start using self-made tools without testing.</p>
<p><a href="https://compute-forensics.com/contact-us/" rel="noopener">Contact us</a> for a quote in regards to training, collection or even an investigation.</p>
<p>We also offer a remote triage service, by sending a bootable drive with secure remote access software pre-installed we can forensically image a device from across the world without modifying the contents thus preserving the material.</p>
<p>I recommend the online training and exam from the forensic author, Brett Shavers. He runs an online course which you can find <a href="http://courses.dfironlinetraining.com/forensic-operating-systems?pc=fos-032018">here</a>.</p>
<p>Please be mindful this guide is for research purposes. Please test and <strong>use at your own risk! </strong></p>
<p>Be mindful that specific software may be not allowed for use in corporate settings as you may break the software companies EULA agreement.</p>
<h3>How Does a Forensic Windows OS Work?</h3>
<p>If the build process completes correctly, a unique modified Windows is created on a USB drive, ISO or CD or DVD. When booting from a forensic OS, the BIOS of the host system bypasses the internal physical disk booting from the information on the USB drive (for Windows To Go) or the data saved to the volatile RAM transferred from the boot media (for Mini-WinFE.)</p>
<p>Windows should not mount the internal fixed disk but connected USB disks in the case of Windows To Go or any discs what so ever using WinFE.</p>
<p>Please note: When using <strong>DISKPART </strong>from CMD in Windows To Go you can mount Disks Read Only but NOT Volumes. Doing so writes to the disk. You can still image using Forensics or FTK Imager without doing any mounting. If you want to use specific triage tools in a blocked mounted state, you may need to bring the disk online, but remember never bring the Volume online. <strong>ALWAYS</strong> test your build.</p>
<p>Practice using Diskpart and the toggling of online and offline correct, many think they are smart using the command line, but one wrong move and you could wipe, format or mount a volume leaving you to explain your actions in an Expert Witness or corporate hearing.</p>
<h3><strong>Why Would I Need a Windows Based Forensic OS?</strong></h3>
<p>Other forensic OS’s exist as do physical writeblockers. <strong>Linux</strong> (<a href="https://www.caine-live.net">Caine</a>, <a href="https://sumuri.com/software/paladin/">Paladin</a>, and others) and <strong>Mac</strong> formats (Sumuri’s <a href="https://sumuri.com/software/recon/">Recon</a> &amp; BlackBag’s <a href="https://www.blackbagtech.com/software-products/macquisition.html">Macaquisition</a>) can collect data, but I estimate 80% of forensic software is produced for Windows. Imagine being able to boot into Windows and use tools such as Netcat, FTK Imager, <a href="https://www.osforensics.com">OSforensics</a> or even full-blown FTK on your Bitlockered Frankenstein creation. This would enable you to carry a Swiss army knife of tools at your disposal.</p>
<p>Using a <strong>Windows Forensic OS</strong> you can:</p>
<ul>
<li>Collect data from software RAIDS and logically image the device rather than having to piece together physical images later saving time.</li>
<li>Decrypt Bitlockereddrives and image/triage them in a decrypted state and physical state consecutively using CMD looking something like “manage-bde –unlock E: -recoverypassword 111111-222222-333333-444444-555555-666666-777777-888888.”</li>
<li>Produce decrypted logical images on the fly from Truecrypt, PGP and Veracrypt using default Windows tools.</li>
<li>Boot into your Bitlockered ‘Windows To Go’<strong> </strong>and use your client’s hardware to attach to their domain with admin rights temporarily, run FTK to capture a suspects RAM and physical disk Image remotely without having to lug a laptop or even worse a workstation to the client’s site.</li>
<li>Travel light with a few USB keys in different countries without lugging 20 pelican cases and getting stopped by airport security whom mistake the devices for dirty nuclear bombs.</li>
<li>Use data recovery tools such as photorec without making changes to the drive.</li>
<li>Triage and quickly find and capture forensically the information needed with only primary first responder training and no expensive equipment.</li>
<li>Production of a log2timeline to capture users actions between specific dates.</li>
<li>Windows2go could be sent to a client with a copy of Teamviewer or similar. With instructions and connected to the internet the client could boot into the forensic OS, an examiner from across the world can log in and take over the collection process going on to capturing the internal physical disk as an E01 to an encrypted drive. When complete the client can mail the item back for analysis saving on travel costs.</li>
</ul>
<h3>Forensic OS Route 1: Native to Enterprise ‘Windows To Go’</h3>
<p>If you own a copy of Windows 10 Enterprise and you purchase one of the certified ‘Windows To Go’ drives (See Below) to make your OS. All you need to do is press the “Win Key&amp; Q” together and type ‘Windows To Go’ into the search bar. Plug in your drive and follow the instructions. You will be asked if you want to Bitlocker the drive, it is recommended but be aware it may not boot on Mac’s or specific other systems.</p>
<p><strong>Certified Windowstogo Drives</strong></p>
<ul>
<li>Imation IronKey™ Workspace W300 / W500 / W700</li>
<li>Kingston DataTraveler Workspace</li>
<li>Spyrus Portable Workplace</li>
<li>Spyrus Secure Portable Workplace</li>
<li>Spyrus WorkSafe</li>
<li>Super Talent RC4 / RC8</li>
<li>WD My Passport Enterprise</li>
<li>SanDisk Extreme CZ80 USB 3.0 Flash Drive</li>
<li>SanDisk Extreme CZ88 USB 3.0 Flash Drive</li>
</ul>
<h3>Using Other Drives Including an M.2 SSD in a USB 3.1 Caddy</h3>
<p>If you are a ‘Cheap Charlie’ or are feeling more adventurous, you can try other disks, although they are unsupported officially.</p>
<p>I tested a “SAMSUNG M.2 NGFF 128GB SSD SOLID STATE DRIVE MZ-NTE1280” (£40 from Amazon) inside a USB 3.1 “Type C To M.2 NGFF PCI-E SSD Hard Disk Case Enclosure 2242/2260/2280 caddy” (£10 pictured below.) When the enclosure arrived in the post, it looked like something out of a Christmas cracker. When I assembled the device, which took two minutes, I was pleased with how robust it felt. Windows To Go recognised the disk. Windows To Go was installed in about 10 minutes using the built-in GUI.</p>
<p>Speeds faster than the ‘certified’ drives were noted in tests at around 500mb a second read/write and use was not noticeably slower than using my native Crucial M.2 built into my high-end test laptop.</p>
<p><img decoding="async" class="size-full wp-image-1182 aligncenter" src="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Bespoke_Windows-yo-go_Caddy.jpg?resize=485%2C393&amp;ssl=1" alt="Make your own bootable Windows for travel" width="483" height="391" data-attachment-id="1182" data-permalink="https://compute-forensics.com/how-to-create-forensic-windows-based-os-for-free-for-forensic-imaging-and-triage/bespoke_windows-yo-go_caddy/" data-orig-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Bespoke_Windows-yo-go_Caddy.jpg?fit=485%2C393&amp;ssl=1" data-orig-size="485,393" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1521662693&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Bespoke_Windows-to-go_Caddy" data-image-description="" data-medium-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Bespoke_Windows-yo-go_Caddy.jpg?fit=300%2C243&amp;ssl=1" data-large-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Bespoke_Windows-yo-go_Caddy.jpg?fit=485%2C393&amp;ssl=1" /></p>
<p>To use the newly created OS on a stick, you need to plug it into a computer and press whatever button you need to boot from your disk, not the internal drive (Esc, F11, F12, Delete.) On first boot, you will have to setup Windows just like any other new installation of Windows. Do not wait until you are on the client site!</p>
<h3>Using DISKPART to Bring Disks Online</h3>
<p>When you use Windows To Go any attached USB devices will be writable. The internal disks will be offline and unavailable to Windows. FTK Imager and other software will still be able to view, image and parse the internal drives. If you wish to Triage using other tools you may need to bring the disk online using disk manager or DISKPART in CMD as an admin. The command would be something like:</p>
<p>1) Run CMD as an admin</p>
<p>2) Type DISKPART</p>
<p>3) LIST DISKS</p>
<p>4) SELECT DISK 2 (2 being an example of the internal disk under review)</p>
<p>5) ONLINE DISK. The disk should then be shown in explorer but in a blocked state. Practice taking the disks offline and online using DISKPART before using this on evidence! You should be able to use Nirsoft and other live tools to analyse the internal disk without writing to it.</p>
<p><img decoding="async" class="aligncenter" src="https://i1.wp.com/support.ca.com/cadocs/0/CA%20ARCserve%20Replication%20and%20High%20Availability%20r16%205-ENU/Bookshelf_Files/HTML/VMS/2069447.png?w=1140&amp;ssl=1" alt="list disk and volume command" width="534" height="181" /></p>
<p>It is noteworthy to mention boot USB producing software Rufus produces Windows To Go but this has not been tested yet!</p>
<p>The downside to this method is that you need to learn the command prompt of DISKPART, this isn’t easy but not ideal for first responders. People with less Windows knowledge and whom want a cleaner smaller build should consider building a custom Mini-WinFE.</p>
<h3>Forensic OS Route 2: Building your Own Custom Mini-WinFE</h3>
<p>Using a GUI assembler and Windows installation media, it is possible to build a bootable OS in minutes that will have a GUI disk read/write toggler, can contain tools such as FTK Imager or DD and be under 300mb in size. This is enough to fit onto a writable CD or Mini CD (recommended for compatibility even old systems have CD drives) or even a dated 1.0 or 2.0 USB key.</p>
<p>The beauty of that is you can customise a stripped down version of Windows that can triage, is blocked using a GUI and that boots in seconds without all the ‘fluff’ the Windows To Go build contains.</p>
<p>Producing a Mini-WinFE is tricky, and if you add too many features you may end up bypassing the protection making the internal disks prone to changes, not good!</p>
<p>The secret is not to add too many features and test your creation on your system, not evidence.</p>
<p>Below is a step by step how-to produce your first basic 32-bit Forensic Mini-WinFE:</p>
<p><strong><img loading="lazy" decoding="async" class="aligncenter wp-image-1781" src="https://compute-forensics.com/wp-content/uploads/2018/06/PE-Bakery_Build-Mini_WINFE-300x241.jpg" alt="" width="600" height="481" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/PE-Bakery_Build-Mini_WINFE-300x241.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/PE-Bakery_Build-Mini_WINFE-768x616.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/PE-Bakery_Build-Mini_WINFE-600x481.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/PE-Bakery_Build-Mini_WINFE.jpg 883w" sizes="auto, (max-width: 600px) 100vw, 600px" />(Above) Mini-WinFE’s GUI </strong></p>
<ol>
<li>Download Mini-WinFE <a href="http://www.brettshavers.cc/index.php/brettsblog/entry/windows-forensic-environment-newest-project-is-complete">here</a> or <a href="https://ln.sync.com/dl/62e6302b0#r8in7m6s-xydgcwp9-hb2dbfg9-ijybm5rm">here.</a></li>
<li>Extract the Zip to a clean directory and run the launcher inside the Mini-WinFE folder as an admin.</li>
<li>Mount your Windows installation ISO or slip the DVD into your disk drive. I prefer 32-bit as it boots on both types of system. I used Windows 10 Enterprise as the Windows build.</li>
<li>In settings point your source directory to your Windows DVD location or the folder you have dumped the contents of the Windows installation media.</li>
<li>Create a working directory in the Mini-WinFE folder you just extracted and use this as your target directory.</li>
<li>Go to the FTK imager tab and point FTK to any 32-bit EXE. You can register and download Imager from <a href="https://accessdata.com/product-download">here</a>. I like to use version 3.1.1. A 64-bit version cannot be built into the cache for a 32-bit machine.</li>
<li>In the ‘Path to 32-bit’ area press the folder button and select the FTK image EXE file you have installed or extracted.</li>
<li>Option 1 allows you to select booting from FLAT or RAM. I would choose RAM; FLAT means the item boots from the medium and results in a larger ISO or USB output.</li>
<li>Tick all the programs boxes except add custom batch and folders unless you wish to do this.</li>
<li>Tick the create ISO tab and read the hover over suggestions.</li>
<li>In the create ISO section option 3 the drop-down box allows a user to select the Firmware type. Older computers use BIOS (Basic Input Output System) newer have UFEI firmware and can ofter boot the older BIOS software or UFEI. There are three options; I would select the ‘both’ option if you are unsure.</li>
<li>Select ‘oscdimg’ for an option.</li>
<li>Change the optimise option to ‘yes’ for option 5. This will result in a smaller ISO.</li>
<li>Selecting ‘yes’ for option 6 will build the ISO file in a newly created \mistyPR.Project.Output folder path in your project folder. Selecting ‘no’ will name the iso with the date and time to allow you to make multiple builds without writing over the older builds.</li>
<li>Select the triangular ‘Play’ logo with the ‘Build’ tab underneath.</li>
<li>If all goes well, you should have built your first forensic ISO. The file can be found in the output folder of your Mini-WinFE folder or the root of that folder.</li>
<li>The ISO can be burnt to CD, Mini-CD or DVD, or you can also use <a href="https://unetbootin.github.io">Unetbootin</a> or <a href="https://rufus.akeo.ie">Rufus</a> to make a bootable USB from the ISO.</li>
<li>Sometimes a system won’t boot from a USB or not from sometimes a CD or DVD. Produce a few versions and label them.</li>
<li>You will have to tinker to get different builds to boot on different systems. To work on my system, I had to enter the BIOS, change the boot from UFEI to legacy. Be careful on evidence that has a TPM chip linked BitLocker as you could end up rendering the drive unbootable by disabling TMP in the BIOS.</li>
<li>Be sure to photograph the Bios when working with real evidence. In the boot setup of the BIOS take all the internal disks offline and have your forensic USB followed by CD/DVD in the boot order.</li>
<li>If the process works, you will be greeted by the disk manager, and this shows you which disks you can make writable or bring online for triage. <strong>Be careful not to bring the evidence volumes online.</strong> You can right click to find out more about the disk to make sure you make the correct selection. You don’t need to bring a disk online to image it though.</li>
<li>Closing the file manager window results in a forensic desktop being displayed.</li>
<li>Right-clicking on the desktop displays the drop-down menu in which you can scroll through and make utilisation of the differing tools.</li>
<li>Below displays a screenshot of the ISO successfully running in a test virtual box environment.</li>
</ol>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-1782" src="https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-300x246.jpg" alt="" width="600" height="492" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-300x246.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-768x629.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-1024x839.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-600x492.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows.jpg 1030w" sizes="auto, (max-width: 600px) 100vw, 600px" />Please Like or Share this guide should you find it useful!</p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-3 vc_hidden-sm vc_hidden-xs"><div class="vc_column-inner "><div class="wpb_wrapper">
<div class="stm_sidebar">

            <style type="text/css" scoped>
            .vc_custom_1452056597103{margin-right: 0px !important;margin-bottom: 30px !important;margin-left: 0px !important;}.vc_custom_1451998133493{margin-bottom: 30px !important;}.vc_custom_1452056633692{padding-top: 37px !important;padding-right: 30px !important;padding-bottom: 40px !important;padding-left: 30px !important;}.vc_custom_1527964913946{margin-bottom: 9px !important;}.vc_custom_1527964962623{margin-bottom: 17px !important;}.vc_custom_1527965000155{margin-bottom: 30px !important;}        </style>
        <div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1452056597103"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner vc_custom_1452056633692"><div class="wpb_wrapper"><div class="vc_custom_heading vc_custom_1527964913946 text_align_left" ><div style="font-size: 16px;color: #222222;text-align: left;font-family:Poppins;font-weight:600;font-style:normal" class="consulting-custom-title">Contact Us</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1527964962623" >
		<div class="wpb_wrapper">
			<p><span style="font-size: 13px; line-height: 22px;">Compute Forensics are based in London but are available for contracts and work in the global area. Please don’t hesitate to email us at expert@compute-forensics.com for a free online or call consultation.</span></p>

		</div>
	</div>
<div class="vc_btn3-container vc_btn3-inline vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-sm vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-left vc_btn3-color-white" href="https://compute-forensics.com/contact-us/" title=""><i class="vc_btn3-icon fa fa-phone-square"></i> contacts</a></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid vc_custom_1451998133493"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper"><div class="vc_btn3-container vc_btn3-left vc_custom_1527965000155 vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-lg vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-block vc_btn3-icon-left vc_btn3-color-theme_style_1" href="https://compute-forensics.com/pdf/" title="" target="_blank"><i class="vc_btn3-icon fa fa-file-pdf-o"></i> Computer Forensics Professional Services PDF</a></div></div></div></div></div>
</div>    
</div></div></div></div></div><div data-vc-full-width="true" data-vc-full-width-init="false" class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1459505959648"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper">
<section class="vc_cta3-container" >
    <div class="vc_general vc_cta3 third_bg_color vc_cta3-style-flat vc_cta3-shape-square vc_cta3-align-left vc_cta3-color-classic vc_cta3-icon-size-md vc_cta3-actions-right vc_custom_1530552651544 style=""">
                        <div class="vc_cta3_content-container">
                                    <div class="vc_cta3-content">
                <header class="vc_cta3-content-header">
                    <div class="vc_custom_heading" ><h2 style="font-size: 20px;color: #ffffff;line-height: 24px" class="consulting-custom-title">Looking for a Remote Collection or Investigation Service?</h2></div>                                    </header>
                            </div>
                        <div class="vc_cta3-actions"><div class="vc_btn3-container vc_btn3-right vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-md vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-right vc_btn3-color-theme_style_2" href="https://compute-forensics.com/contact-us/" title="">get a quote <i class="vc_btn3-icon fa fa-chevron-right"></i></a></div></div>        </div>
                    </div>
</section></div></div></div></div><div class="vc_row-full-width vc_clearfix"></div>
</div>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
