Profile avatar
4n6.bsky.social
Digital Forensic Analyst. Criminal Trial Expert. Computer, Cell Phone, CSLI, Audio/Video analysis, etc. I love them all. Oh yeah, I also love me some games (PC, PS5 and TTRPG). #DFIR #CyberSecurity #digitalforensics #CriminalDefense #ttrpg
121 posts 95 followers 61 following
Prolific Poster
Conversation Starter

Last week a judge denied me the ability to testify at a motion hearing. Her reason? I wouldn't add anything to the argument and she didn't care about the scientific part of the case. The case involved video forensic and Snapchat issues. 100% going to be appealed.

Why we do what we do. ##criminaldefense #dfir ##CyberSec

NESPIN needs to be better. Maybe don't screenshot a Word document with editing visible in your email blasts? More importantly, the Cellebrite CCPA/CCO Courses are necessary for any examiner if testimony is a requirement to their position.

A forensic examiner in Massachusetts reached out to me regarding a position. While I don't, does anyone have any remote work or in-person work in the New England area for them? Please private message me and I can relay your information to them.

Thank you @magnetforensics.bsky.social AXIOM 8.8's best feature (IMO)

LeadsOnline's CellHawk has a nice new update! #CSLI #DigitalForensics #DFIR

Pop quiz. If a GrayKey extraction fails the hash validation and the original extraction is no longer on the GrayKey, should it be used as evidence?

Assume the State compelled a phone password from a suspect. Assume that statement was invalid as they invoked counsel. If LE dumped the phone using the password, inevitable discovery argument? Note: It'd be 2 years before bruteforce support became available. #dfir #legal ##criminaldefense

Who are the people to follow for #DFIR #CriminalDefense #Digitalforensics?

Geofence Warrants: Legitimate tools for law enforcement or 4th Amendment violations?

Zoom Hearings are the worst. I'd rather sit in court.

Seems like the AFU Reboot is timer based (3 days) and not associated with wireless access, as originally thought: naehrdine.blogspot.com/2024/11/reve...

The biggest hurtle in digital forensics is explaining your findings in layterms for non-techies. Luckily, my retail repair experience helps during testimony. Tip: Use analogies.

My remote extraction setup...what's yours? My kit includes: + Two laptops, each with a 2nd USBc monitor. Three external HDDs 10 USB Flash Drives (16gb to 512gb) Gloves and masks Electronic Toolkit reMarkable Notebook Rulers (for scale) 5g mobile Hotspot Dongles...so many dongles..

If you're curious why everybody's username is a domain, it's because every user is essentially a website

Streamline investigations with our award-winning Unified #DFIR Platform. From lightning-fast data acquisition to AI-powered analytics and automated workflows, Detego empowers you to extract, analyse, and report on data from 1000s of devices. 🖥️💻⚡📱📲 Request a trial: zurl.co/GXwv vimeo.com/896833843

Doing a phone today with Cellebrite Inseyets (such a bad name).

I'm a digital forensic nerd. If you are too, follow me! #dfir ##criminaljustice ##CyberSec #law

In #Pyhton of course. 😂 If you want to learn Python for #DigitalForensics from scratch I did a live class online on YouTube during the start of the pandemic. Check it out here: youtube.com/playlist?lis...

Isolation rooms will be more and more important going forward. The days of Faraday Bags being the standard may be over.

Digital forensics is more than knowing tech. It requires an analytical mind that can parse their own knowledge base and adapt it to human activity from a human standpoint. AI will never be able to replace a real digital forensic analyst, nor should it. It can be a useful tool. That's all.

Interesting. Thoughts?

What are some of your AI horror stories? I'll start.

Screenshot case today. Officer admitted to taking a screenshot of a screenshot "to preserve it" in case it deleted when he downloaded it to a PC. He only downloaded the screenshot of a screenshot and not the original. Corruption or incompetence? #dfir #digitalforensics #lawyer #criminaljustice

@openaidalle.bsky.social I don't know if OpenAI has an official ChatGPT account, but this is not a good look. Been working on a document file for about 2 weeks....

Bluesky now has over 10 million users, and I was #1,499,995!

New CJA Ruling this month regarding Snapchat 'investigations' by Boston Police Department in Massachusetts: May be huge for 'undercover investigations' using false/fabricated 'undercover' accounts. #criminaljustice #dfir #criminaldefense #defenseattorney #legal #law @forensicfocus.bsky.social

Uncovering the truth. Best part of my day. ##digitalforensics #dfir

What is the justification for Law Enforcement only tools such as TraX? Can anyone explain it? ##digitalforensics #dfir #criminaljustice

😄I will be talking about the LEAPPs & #MobileForensics topics at the 2024 NW ICAC Conference. 🔎Check out the details and register here: https://buff.ly/46P1Z11 👋If you are there say hi and get a sticker* #DFIR #DigitalForensics * Valid while supplies last. 😆

I'm curious to hear from other digital forensic analysts / examiners.... What are the best and worst parts of your job? #dfir ##criminaldefense #criminaljustice #cybersec

Another screen shot case. How it feels sometimes #criminaldefense #dfir #cybersecurity

A judge in a case I am assisting in as an Expert requested the ADA inquire from other prosecutors and detectives regarding interactions with me in previous cases. They even wrote an affidavit about me related to this inquiry. Is this legal? Seems entirely inappropriate. #legal #criminaljustice

UK-based digital forensic investigators and the impact of exposure to traumatic material (PDF)

Thought exercise #dfir and #lawenforcement and #lawyers Search Warrant obtained for phone, for all content on 1/2/34. You do a Full File System and use Cellebrite PA to report. 1.When you create the UFDR, do you include "items without a timestamp? 2.Do you convert to local time? 3.Why(not)?