forensics

NavdDoomConductor - Precise Geolocation and Time

Leveraging free, I continues my search for file structure containing the key “latitude”. I stumbled across an intriguing file called NavdDoomConductor.storage and this blog writes up the how and what of locating and understanding this forensic artifact.

Continue reading

Discover New Forensic Evidence with File Structure Analysis

Forensic analysts can discover new evidence in their existing acquisitions by searching through known file structures for responsive artifact/data types leveraging the free forensic tool ftree.

Continue reading

Docker for Forensic Analysts

Docker is a software platform that enables forensic analysts to isolate and run applications or services in a single container. The platform is open source and widely adopted in the development and operations communuity. Docker can change how the forensic community acquires, uses and scales tools.

Continue reading