Blog Archives

DC3 2009

The results for the 2009 challenge are due in 6 days. This year there were 1153 entries with 44 submissions, a slightly lower rate of return than last year. The challenge format was different this year. Last year’s format was a set of discrete problems at various levels of difficulty with some of the higher difficulty problems being more complex forms of the lower problems. This year the challenge was a simulation. We received a case file with information from the investigators and a type of work order for what we were to investigate. The challenge data was a single hard drive image from a system used by the suspect.

Evidence was located in a variety of places from simple chat logs to the windows registry. There were some red herrings along the way including files from previous years, but all in all it was a decent challenge. Some of the documents felt rushed, such as the case file still having track changes enabled, but given the difficulty in constructing believable simulations I cannot call the DoD to task overly much.

Below the fold is our primary report for the challenge we submitted earlier in the month. The full report including the registry report, the evidence files, and so forth will likely be released when the results are announced as they were last year. If DC3 does not release them, I will post a copy for download if anyone is interested.

Tagged with: , , , , ,
Posted in Digital Forensics

DC3 Countdown – 4 days to go

Just a short update. I’ve been busy working away at the final touches on the DC3 2009 submission. 4 days to go until the deadline then I’ll be posting a summary of our findings! Tweet

Tagged with: ,
Posted in Digital Forensics

Disturbing Trends Across the Pond

Two convicted for refusal to decrypt data Since October 2007 when the refusal to disclose decryption keys was made criminal in the UK, the buzz around the smallish digital forensics research community has been alarm. Security researcher, by definition always

Tagged with: , , ,
Posted in Digital Forensics, Law

NOLA Mayor’s Email Saga

The “Louisiana Technology Council” held a press conference today regarding the ongoing attempts to recover Mayor Nagin’s email and calendar information. I just got back from the press conference, but am somewhat disappointed in its content. Some information can be

Tagged with: , ,
Posted in Digital Forensics, Uncategorized

CS Major Quashes Search – Halts Forensic Analysis

New developments occurred in the Calixte case regarding the domestic dispute leading to a detective throwing every book at hand against him. The EFF just published a nice point by point discussion of the verdict from their appeal. Justice Botsford’s

Tagged with: ,
Posted in Law