If you are visually impaired or blind, you can visit the PDF version by Pressing CONTROL + ALT + 4
<br /> Digital<br /> The Quarterly Magazine for Digital Forensics Practitioners Issue 34 · February 2018<br /> ForensicS<br /> Magazine<br /> Forensics Europe Expo<br /> Intelligence & Investigations<br /> for the Internet of Things<br /> DFM Sponsored Seminar<br /> Drone<br /> Forensics<br /> How the growing use of Unmanned Aerial Vehicles<br /> creates new forensic challenges for investigators<br /> PLUS<br /> Inconsistent Tool Performance<br /> Faster Searching for Illegal Content<br /> Data Destruction on current hard disks<br /> 9<br /> From the Lab: Device Forensics in the IoT772042 061004<br /> 34<br /> Issue 34 / £14.99 TR Media<br /> <br /> Editorial<br /> 2<br /> 018 is set to be a year of change for<br /> Digital Forensics Magazine. Just as the<br /> <a title="DFM34 - Online page 1" href="http://viewer.zmags.com/publication/50542127?page=1"> Digital The Quarterly Magazine for Digital Fore</a> <a title="DFM34 - Online page 2" href="http://viewer.zmags.com/publication/50542127?page=2"> </a> <a title="DFM34 - Online page 3" href="http://viewer.zmags.com/publication/50542127?page=3"> Editorial 2 </a> <a title="DFM34 - Online page 4" href="http://viewer.zmags.com/publication/50542127?page=4"> </a> <a title="DFM34 - Online page 5" href="http://viewer.zmags.com/publication/50542127?page=5"> Contents FEATURES 8 Inconsistent Tool Performanc</a> <a title="DFM34 - Online page 6" href="http://viewer.zmags.com/publication/50542127?page=6"> NEWS News The Reality of Cyberwarfare Last year,</a> <a title="DFM34 - Online page 7" href="http://viewer.zmags.com/publication/50542127?page=7"> We look forward to seeing how the finalists fare i</a> <a title="DFM34 - Online page 8" href="http://viewer.zmags.com/publication/50542127?page=8"> FEATURE ADVANCED Inconsistent Tool Performance </a> <a title="DFM34 - Online page 9" href="http://viewer.zmags.com/publication/50542127?page=9"> PHASE 1 Acquisition of Software PH</a> <a title="DFM34 - Online page 10" href="http://viewer.zmags.com/publication/50542127?page=10"> FEATURE ADVANCED being performed. Previously </a> <a title="DFM34 - Online page 11" href="http://viewer.zmags.com/publication/50542127?page=11"> These results show significant differences be</a> <a title="DFM34 - Online page 12" href="http://viewer.zmags.com/publication/50542127?page=12"> FEATURE ADVANCED The problem will not go away </a> <a title="DFM34 - Online page 13" href="http://viewer.zmags.com/publication/50542127?page=13"> </a> <a title="DFM34 - Online page 14" href="http://viewer.zmags.com/publication/50542127?page=14"> MAIN FEATURE INTERMEDIATE Drone Forensics David</a> <a title="DFM34 - Online page 15" href="http://viewer.zmags.com/publication/50542127?page=15"> The art and science of UAV forensics is at the po</a> <a title="DFM34 - Online page 16" href="http://viewer.zmags.com/publication/50542127?page=16"> MAIN FEATURE INTERMEDIATE So, a single </a> <a title="DFM34 - Online page 17" href="http://viewer.zmags.com/publication/50542127?page=17"> Flow evidence derives from the communication betw</a> <a title="DFM34 - Online page 18" href="http://viewer.zmags.com/publication/50542127?page=18"> MAIN FEATURE INTERMEDIATE • Vision Positionin</a> <a title="DFM34 - Online page 19" href="http://viewer.zmags.com/publication/50542127?page=19"> Missing Valuable Data Many law enforcement agenci</a> <a title="DFM34 - Online page 20" href="http://viewer.zmags.com/publication/50542127?page=20"> </a> <a title="DFM34 - Online page 21" href="http://viewer.zmags.com/publication/50542127?page=21"> LEGAL Editorial B </a> <a title="DFM34 - Online page 22" href="http://viewer.zmags.com/publication/50542127?page=22"> W i</a> <a title="DFM34 - Online page 23" href="http://viewer.zmags.com/publication/50542127?page=23"> the human driver to do so. In all other </a> <a title="DFM34 - Online page 24" href="http://viewer.zmags.com/publication/50542127?page=24"> LEGAL FEATURE Trade Secret – 1. A formula, pr</a> <a title="DFM34 - Online page 25" href="http://viewer.zmags.com/publication/50542127?page=25"> Where is the Evidence? DFM readers are probably a</a> <a title="DFM34 - Online page 26" href="http://viewer.zmags.com/publication/50542127?page=26"> LEGAL NEWS LEGAL News powers to take action where</a> <a title="DFM34 - Online page 27" href="http://viewer.zmags.com/publication/50542127?page=27"> </a> <a title="DFM34 - Online page 28" href="http://viewer.zmags.com/publication/50542127?page=28"> FROM THE LAB ADVANCED Device Forensics in the In</a> <a title="DFM34 - Online page 29" href="http://viewer.zmags.com/publication/50542127?page=29"> definition for the IoT will be used: “The IoT is a</a> <a title="DFM34 - Online page 30" href="http://viewer.zmags.com/publication/50542127?page=30"> FROM THE LAB ADVANCED State of the IoT It has </a> <a title="DFM34 - Online page 31" href="http://viewer.zmags.com/publication/50542127?page=31"> </a> <a title="DFM34 - Online page 32" href="http://viewer.zmags.com/publication/50542127?page=32"> FROM THE LAB ADVANCED relevant information fr</a> <a title="DFM34 - Online page 33" href="http://viewer.zmags.com/publication/50542127?page=33"> Figure 2. IoT Forensics (Reprinted from Zawoad, S</a> <a title="DFM34 - Online page 34" href="http://viewer.zmags.com/publication/50542127?page=34"> FROM THE LAB ADVANCED IoT Device Evidence Extr</a> <a title="DFM34 - Online page 35" href="http://viewer.zmags.com/publication/50542127?page=35"> also be available from the microprocessor manufac</a> <a title="DFM34 - Online page 36" href="http://viewer.zmags.com/publication/50542127?page=36"> FROM THE LAB ADVANCED a UART connection allow</a> <a title="DFM34 - Online page 37" href="http://viewer.zmags.com/publication/50542127?page=37"> </a> <a title="DFM34 - Online page 38" href="http://viewer.zmags.com/publication/50542127?page=38"> T his year Digital Forensi</a> <a title="DFM34 - Online page 39" href="http://viewer.zmags.com/publication/50542127?page=39"> levels of cybercrime are on the rise. Coupled wit</a> <a title="DFM34 - Online page 40" href="http://viewer.zmags.com/publication/50542127?page=40"> ADVERTORIAL UNIVERSITY OF WARWICK CYBER SECURITY,</a> <a title="DFM34 - Online page 41" href="http://viewer.zmags.com/publication/50542127?page=41"> 41</a> <a title="DFM34 - Online page 42" href="http://viewer.zmags.com/publication/50542127?page=42"> FEATURE ADVANCED Faster Searching for Known Ille</a> <a title="DFM34 - Online page 43" href="http://viewer.zmags.com/publication/50542127?page=43"> Triage Tools and the Triage Process In some cases</a> <a title="DFM34 - Online page 44" href="http://viewer.zmags.com/publication/50542127?page=44"> FEATURE ADVANCED Figure 2 </a> <a title="DFM34 - Online page 45" href="http://viewer.zmags.com/publication/50542127?page=45"> Figure 3 The Future? Tools Designed for Triage </a> <a title="DFM34 - Online page 46" href="http://viewer.zmags.com/publication/50542127?page=46"> FEATURE ADVANCED Further Develo</a> <a title="DFM34 - Online page 47" href="http://viewer.zmags.com/publication/50542127?page=47"> </a> <a title="DFM34 - Online page 48" href="http://viewer.zmags.com/publication/50542127?page=48"> FEATURE ADVANCED Data Carving on Auto-Pilot with</a> <a title="DFM34 - Online page 49" href="http://viewer.zmags.com/publication/50542127?page=49"> Figure 1. PNG Format & Rendered Image Note: To th</a> <a title="DFM34 - Online page 50" href="http://viewer.zmags.com/publication/50542127?page=50"> FEATURE ADVANCED Data Carving Example Now we w</a> <a title="DFM34 - Online page 51" href="http://viewer.zmags.com/publication/50542127?page=51"> Metadata Values Figure 4. WinHex Sh</a> <a title="DFM34 - Online page 52" href="http://viewer.zmags.com/publication/50542127?page=52"> FEATURE ADVANCED Fi</a> <a title="DFM34 - Online page 53" href="http://viewer.zmags.com/publication/50542127?page=53"> </a> <a title="DFM34 - Online page 54" href="http://viewer.zmags.com/publication/50542127?page=54"> MORE THAN A MAG Digital Forensics Magazine prides</a> <a title="DFM34 - Online page 55" href="http://viewer.zmags.com/publication/50542127?page=55"> </a> <a title="DFM34 - Online page 56" href="http://viewer.zmags.com/publication/50542127?page=56"> FEATURE ADVANCED Data Destruction for Current Ha</a> <a title="DFM34 - Online page 57" href="http://viewer.zmags.com/publication/50542127?page=57"> Figure 1. Steps Taken to Evaluate the Data Overri</a> <a title="DFM34 - Online page 58" href="http://viewer.zmags.com/publication/50542127?page=58"> FEATURE ADVANCED the binary value for the sta</a> <a title="DFM34 - Online page 59" href="http://viewer.zmags.com/publication/50542127?page=59"> A. Phase B. Amplitude Figure 6</a> <a title="DFM34 - Online page 60" href="http://viewer.zmags.com/publication/50542127?page=60"> FEATURE ADVANCED original data. Because the d</a> <a title="DFM34 - Online page 61" href="http://viewer.zmags.com/publication/50542127?page=61"> </a> <a title="DFM34 - Online page 62" href="http://viewer.zmags.com/publication/50542127?page=62"> COMPETITION Competition Fancy winning a nifty li</a> <a title="DFM34 - Online page 63" href="http://viewer.zmags.com/publication/50542127?page=63"> </a> <a title="DFM34 - Online page 64" href="http://viewer.zmags.com/publication/50542127?page=64"> FEATURE ADVANCED Wordlist Password Cracking Usin</a> <a title="DFM34 - Online page 65" href="http://viewer.zmags.com/publication/50542127?page=65"> Before taking out any other tool for wordlis</a> <a title="DFM34 - Online page 66" href="http://viewer.zmags.com/publication/50542127?page=66"> FEATURE ADVANCED • For clusters, be consisten</a> <a title="DFM34 - Online page 67" href="http://viewer.zmags.com/publication/50542127?page=67"> 2X XEON I7 980X I7 4500 1 core = 1324 c/s</a> <a title="DFM34 - Online page 68" href="http://viewer.zmags.com/publication/50542127?page=68"> FEATURE ADVANCED GPU DEVICE PERFORMANCE Ge</a> <a title="DFM34 - Online page 69" href="http://viewer.zmags.com/publication/50542127?page=69"> I tried many wordlist generation tools, incl</a> <a title="DFM34 - Online page 70" href="http://viewer.zmags.com/publication/50542127?page=70"> </a> <a title="DFM34 - Online page 71" href="http://viewer.zmags.com/publication/50542127?page=71"> NEXT ISSUE NEXT Issue Continuing our aim of bring</a> <a title="DFM34 - Online page 72" href="http://viewer.zmags.com/publication/50542127?page=72"> 360 36 Letters, emails, tweets, connections and m</a> <a title="DFM34 - Online page 73" href="http://viewer.zmags.com/publication/50542127?page=73"> TWITTER We are regularly tweeting tools, tips and</a> <a title="DFM34 - Online page 74" href="http://viewer.zmags.com/publication/50542127?page=74"> </a> <a title="DFM34 - Online page 75" href="http://viewer.zmags.com/publication/50542127?page=75"> BOOK Reviews T his book </a> <a title="DFM34 - Online page 76" href="http://viewer.zmags.com/publication/50542127?page=76"> REVIEWS BOOKS </a> <a title="DFM34 - Online page 77" href="http://viewer.zmags.com/publication/50542127?page=77"> BACK ISSUES BACK Issues Digital The Quarterly M</a> <a title="DFM34 - Online page 78" href="http://viewer.zmags.com/publication/50542127?page=78"> T he FBI is at it again. T</a> <a title="DFM34 - Online page 79" href="http://viewer.zmags.com/publication/50542127?page=79"> </a> <a title="DFM34 - Online page 80" href="http://viewer.zmags.com/publication/50542127?page=80"> </a>