Showing posts with label PARABEN. Show all posts
Showing posts with label PARABEN. Show all posts

Friday, May 2, 2025

Digital Forensics:Data Triage and Acquisition Tool Free to All

Digital Forensics:Data Triage and Acquisition Tool Free to All

DP2C is a data triage and bitstream imaging tool for the collection of data from computers and hard drives. This update to the DP2C software is exciting because it allows users to install the software on their own personal USB drive.

Data Triage and Acquisition Tool Free to All
Photo by:Paraben Corporation.

The DP2C Operator Course!

This course will go through the operations to successfully use the DP2C tool in digital investigations. 


Digital Forensics:Data Triage and Acquisition Tool Free to All
 DP2C Operator Course



Digital Forensics:Data Triage and Acquisition Tool Free to All
Photo by:Paraben Corporation.

DP2C is the perfect quick solution for examiners to triage many machines in a short amount of time to detect the most important data, especially when in the field. Users can boot directly into DP2C without logging into Windows to acquire data, which ensures a forensically sound acquisition. 

Digital Forensics:Data Triage and Acquisition Tool Free to All
Photo by:Paraben Corporation.

Data Triage and Acquisition Tool Free to All

Data Triage and Acquisition Tool Free to All

Digital Forensics:Data Triage and Acquisition Tool Free to All
Photo by:Paraben Corporation.

อ่านเพิ่มเติม: 


Video by:Paraben Corporation.

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูล  เผยแพร่ความรู้และให้โอกาสในการค้นคว้าหาข้อมูลเพื่อการศึกษา   บุคคลที่สนใจโดยทั่วไป รวมถึงนักเรียน นิสิต นักศึกษา  ในการเรียนรู้เท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD

Tuesday, August 15, 2023

DIGITAL FORENSICS: pfic-conference 2023

DIGITAL FORENSICS: pfic-conference 2023

PFIC brings together the best in digital data training covering a broad range of topics from DFIR, OSINT, eDiscovery, ransomware, malware, and more. When you attend PFIC you are guaranteed to learn something new.

AUGUST 1-4, 2023

The cost is $199.00 U.S. Virtual

วันนี้แอด จะมาเล่าประสบการณ์ในงาน pfic-conference 2023  แอดได้รับสิทธิในการเข้างาน Online นี้ฟรีจาก The Cyber Socal Hub และ การสนับสนุนจาก Paraben Corporation. สิ่งที่ได้รับจากงานนี้คือ   ได้เข้าอบรมและ เอกสาร Materials และ Software ให้ทดลองใช้
DIGITAL FORENSICS: pfic-conference 2023


Agenda:
DIGITAL FORENSICS: pfic-conference 2023

DIGITAL FORENSICS: pfic-conference 2023

DIGITAL FORENSICS: pfic-conference 2023

Sponsors:
DIGITAL FORENSICS: pfic-conference 2023

Presentation  

DIGITAL FORENSICS: pfic-conference 2023

DIGITAL FORENSICS: pfic-conference 2023

DIGITAL FORENSICS: pfic-conference 2023


Bonus Free 3 Month software :
DIGITAL FORENSICS: pfic-conference 2023

DIGITAL FORENSICS: pfic-conference 2023
3-month license of E3:CLOUD software from attending PFIC 2023.

DIGITAL FORENSICS: pfic-conference 2023


DIGITAL FORENSICS: pfic-conference 2023

Materials:
DIGITAL FORENSICS: pfic-conference 2023


ที่มา : pfic-conference


อ่านเพิ่มเติม: OSForensics

                     Paraben Corporation


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Saturday, April 23, 2022

Digital forensics:DSMO-DS Certified Mobile Operator

Digital forensics:DSMO-DS Certified Mobile Operator

Mobile Operator Course & Certification


หลักสูตรอบรมการตรวจพิสูจน์อุปกรณ์สื่อสารเคลื่อนที่ 

The mobile operator course is designed to get you started using the E3 Forensic Platform with mobile-related evidence.

Course Details

  • Online Course
  • 4 hours
  • Includes lectures and lab
  • DSMO certification included

This introductory certification is designed for those just getting started with Paraben's E3:DS or E3:Universal. You will learn the basics of our premiere forensic tool for mobile devices and become proficient in its use for your investigations by completing a sample E3:DS practical case file. 

Course Curriculum

Acquiring a Feature Phone Physically

Acquisition Wizard
Android Logical Acquisition


EXIF


Acquisition Type

Wifi.db Mac address
  Device Information




อ่านเพิ่มเติม:Computer Operator Course & Certification


Referents:parabenacademy

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Thursday, February 17, 2022

Cloud Forensics:Google Drive forensics with Paraben's E3

Cloud Forensics:Google Drive forensics with Paraben's E3


The scenario was pretty basic. I performed each and every of the following actions (wherever applicable):

Install native Google Drive app.

Execute the application and synced it with my Google Drive’s account.

The scope of this research was to locate those artifacts that could prove that the above actions were made from the user. Lets see how that went.

Paraben's Electronic Evidence Examiner 

Start Electronic Evidence Examiner.


Add Evidence
Add evidence (if you add evidence before creating or opening a new case, the case will be created automatically and saved to the default location. The name of the case file will be case.e3).
Add New Evidence
The Add New Evidence window opens.
Select the evidence category (Image File) and the Source type.

Navigate to the Evidence Source and select it. 
Enter the Evidence name (opened image name by default) and click OK.

Get OS info

Content Analysis





Google Drive Forensic Artifacts 

Directories created when Google Drive is installed

<SYSTEMROOT>\Program Files\Google\Drive

In this folder you will find the executable file of the application

<SYSTEMROOT>\Program Files (x86)\Google\Drive

Here you will find information about the updates of the application

<SYSTEMROOT>\Users\<username>\GoogleDrive

This is the default folder used for synchronizing the user’s files with Google Drive cloud service

<SYSTEMROOT>\Users\<username>\AppData\Local\Google\Drive

Here you will find all the native app’s files that store information about the app and the user’s data


<SYSTEMROOT>\Users\<username>\AppData\Local\Google\Drive

Event Log
Path: C:\Windows\System32\winevt\Logs\Application.evtx
Event ID: 1033
Event Description Summary: Windows Installer installed the product.
Provider Name: MsInstaller

Prefetch
Application Name: GOOGLEDRIVESYNC.EXE
File Path:C:\Windows\Prefetch\GOOGLEDRIVESYNC.EXE-XXXXXXXX.pf

C:\Users\\AppData\Local\ Google\Drive\user_default\snapshot.db This database stores information about the files that have been synced with the user’s Google Drive account.

C:\Users\\AppData\Local\G oogle\Drive\cloud_graph\cloud_graph.db This database also stores information about the files that have been synced with the user’s Google Drive account.
C:\Users\\AppData\Local\ Google\Drive\user_default\sync_config.db This database stores information such as user’s Google Drive account email.

C:\Users\\AppData\Local\ Google\Drive\global.db This database also stores information such as user’s Google Drive account email.
Lnk File

Windows 10 Activity Timeline > Advance Search

Registry

The installation of Google drive creates various keys and values inside the Registry. View the registry hives listed below in the forensic image of the suspect's hard disk.

  • SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
  • SOFTWARE\Google\Drive

  • NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Run\GoogleDriveSync

Paraben's Electronic Evidence Examiner Investigative Report


อ่านเพิ่มเติม: Google Drive

                 CLOUD FORENSICS GOOGLE DRIVE 

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD 


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง ADMIN เพื่อแก้ไขต่อไป
ขอบคุณครับ

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...