Skip to content

Commit

Permalink
cleanup_wip
Browse files Browse the repository at this point in the history
  • Loading branch information
joachimmetz committed Dec 27, 2023
1 parent 00fa5b8 commit a57b92e
Show file tree
Hide file tree
Showing 39 changed files with 294 additions and 401 deletions.
11 changes: 4 additions & 7 deletions docs/academic_forensics_programs_graduate_level.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,28 +32,27 @@ tags:
* [University of Rhode Island](https://web.uri.edu/cs/dfcsc/)
* University of Texas at San Antonio
* Utica College
[Online](http://www.onlineuticacollege.com/programs/computer-forensics-specialization.asp)\]
* [Center for Information Security University of Tulsa](http://www.cis.utulsa.edu/)
* [West Virginia University](https://forensics.wvu.edu/)

## Europe

* Cranfield University, UK
* Limerick Institute of Technology
* [University of Amsterdam](http://www.studeren.uva.nl/ma-forensic-science)
* University of Amsterdam
* University of Bradford
* University of East London
* University College Dublin
* [University of Technology, Mauritius](https://www.utm.ac.mu/)
* [University of Strathclyde](http://www.strath.ac.uk/science/forensicinformatics/)
* University of Strathclyde
* University of Glamorgan, Wales, UK
* [University of Applied Sciences Albstadt-Sigmaringen, Germany](http://www.digitaleforensik.com),
* University of Applied Sciences Albstadt-Sigmaringen, Germany
Master of Science, Digital Forensics, in cooperation with University of
Mannheim and University of Tübingen, Germany

## Asia

* [Zayed University UAE](http://www.zu.ac.ae/main/en/colleges/colleges/college_information_technology/graduate_certificate_programs/cr_invest/intro.aspx)
* Zayed University UAE

## Australasia

Expand All @@ -67,5 +66,3 @@ tags:

* [American Academy of Forensic Sciences (AAFS)](https://www.aafs.org/)
* [Digital Forensics Association List](http://www.digitalforensicsassociation.org/formal-education/)
* [Forensics Focus List](https://forensicfocus.com/computer-forensics-education-directory)
* [Master's Thesis: The Development of a Standard Digital Forensics Master's Curriculum](https://docs.lib.purdue.edu/cgi/viewcontent.cgi?article=1010&context=techmasters&sei-redir=1#search=%22katie%20strzempka%20thesis%22)
2 changes: 1 addition & 1 deletion docs/android.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,5 +53,5 @@ tags:
- [Android developers: SDK Platform release notes](https://developer.android.com/tools/releases/platforms)
- [Android File Hierarchy : System Structure Architecture Layout](https://www.cnblogs.com/shangdawei/p/4513604.html)
- [Explore The Android File System Hierarchy In-Depth](https://thesecmaster.com/explore-the-android-file-system-hierarchy-in-depth/)
- [Practical android phone forensics](https://resources.infosecinstitute.com/topic/practical-android-phone-forensics/),
- [Practical android phone forensics](https://resources.infosecinstitute.com/topics/digital-forensics/practical-android-phone-forensics/),
by Hashim Shaikh, July 21, 2017
2 changes: 1 addition & 1 deletion docs/apple_iphone.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ Store does not allow in any application it distributes).
by [Belkasoft](belkasoft.md) can make iPhone logical acquisition and analyze
iOS backups and dumps.
* Cellebrite BlackBag Technology Mobilyze
* [Cellebrite UFED](https://www.cellebrite.com/forensic-solutions/ios-forensics.html)
* [Cellebrite UFED](cellebrite_ufed.md)
* [Elcomsoft Mobile Forensic Bundle](https://www.elcomsoft.com/emfb.html) performs physical,
logical and over-the-air acquisition.
* EnCase Neutrino
Expand Down
15 changes: 5 additions & 10 deletions docs/apple_safari.md
Original file line number Diff line number Diff line change
Expand Up @@ -69,22 +69,17 @@ named **LastSession.plist** in the user directory.

The Safari cache is stored in **Cache.db** in the cache directory.

This file uses the [SQLite database
format](sqlite_database_format.md).
This file uses the [SQLite database format](sqlite_database_format.md).

## External Links

- [Official website](https://www.apple.com/macos/ventura/)
- [Safari Cache
Revisited](http://www.appleexaminer.com)
* [Safari Cache Revisited](http://www.appleexaminer.com)
by Sean Cavanaugh
- [Analyzing Apple Safari
Artifacts](http://www.appleexaminer.com),
* [Analyzing Apple Safari Artifacts](http://www.appleexaminer.com),
by Selena Ley
- [iOS / macOS - Tracking Downloads from Safari Without Downloads](https://blog.d204n6.com/2021/05/ios-macos-tracking-downloads-from.html)
* [iOS / macOS - Tracking Downloads from Safari Without Downloads](https://blog.d204n6.com/2021/05/ios-macos-tracking-downloads-from.html)
by Scott Vance, Friday, 28 May 2021

## Tools

- [J.A.F.A.T. Archive of Forensics Analysis
Tools](https://jafat.sourceforge.net/) home of Safari Forensic Tools (SFT)
* [J.A.F.A.T. Archive of Forensics Analysis Tools](https://jafat.sourceforge.net/) home of Safari Forensic Tools (SFT)
22 changes: 5 additions & 17 deletions docs/blackberry_forensics.md
Original file line number Diff line number Diff line change
Expand Up @@ -90,24 +90,17 @@ export and click "OK"
5. Select your output type from the bottom list of selections and click
"Save As..."

## Blackberry IPD File Format (.ipd)

For a more advanced and in depth look at the file format of (.ipd)
backup files visit the following site.

<https://www.blackberry.com/us/en>

## Blackberry BBB File Format (Mac OS X) (.bbb)

Blackberry backups generated via Mac OS X are given the extension .bbb,
these are simply .zip compressed files containing a standard .ipd file.

## Acquisition with Paraben's Device Seizure
## Acquisition with Paraben Device Seizure

`* You may purchase a copy of Device Seizure on Paraben's Website `[`here`](https://paraben.com/paraben-for-mobile-forensics/)`.`
More information on [Paraben Device Seizure](paraben_device_seizure.md)

As an alternative to acquiring the Blackberry through Amber Blackberry
Converter, Paraben's Device Seizure is a simple and effective method to
Converter, Paraben Device Seizure is a simple and effective method to
acquire the data. The only drawback, is that this method takes
significantly more time to acquire than using Amber Blackberry
Converter.
Expand Down Expand Up @@ -136,7 +129,7 @@ Now wait until the program is done acquiring data from the device.

Please Note: In some instances the wait can be up to 30-45 minutes.

## BlackBerry Simulator
## BlackBerry simulator

`* For simulating a backup copy of the physical device. This is helpful if the device is low on battery, needs to be turned off, `
`* or you don't want to alter the data on the physical device.`
Expand All @@ -145,8 +138,7 @@ This is a step by step guide to downloading and using a BlackBerry
simulator. In this example the version 4.0.2 was used in order to
simulate the 7230 series.

1. Select a simulator to download from the drop-down list on the
[BlackBerry website](https://www.blackberry.com/Downloads/entry.do?code=060AD92489947D410D897474079C1477).
1. Download the BlackBerry simulator

- For this example look through the list and download BlackBerry
Handheld Simulator v4.0.2.51.
Expand Down Expand Up @@ -200,7 +192,3 @@ transfer across a USB port.
## References

- [phoneMiner](https://www.amraksoftware.com/), phoneMiner
- [BlackBerry Simulator](https://www.blackberry.com/Downloads/entry.do?code=060AD92489947D410D897474079C1477),
Simulator Download website
- [IPD](https://www.blackberry.com/us/en),
IPD File Format
8 changes: 0 additions & 8 deletions docs/caselaw.md
Original file line number Diff line number Diff line change
Expand Up @@ -92,13 +92,5 @@ for interfering with the discovery process.
## External links

- [SETEC Investigations: Case Summaries](http://www.setecinvestigations.com/resources/casesummaries.php)
- [How to Evaluate a Digital Forensic Report – Part 1: A Brief History of Digital Forensics](http://www.lawandforensics.com/evaluate-digital-forensic-report-part-1-4/),
by Daniel B. Garrie, January 31, 2014
- [How to Evaluate a Digital Forensic Report – Part 2: Daubert](http://www.lawandforensics.com/evaluate-digital-forensic-report-part-2-4/),
by Daniel B. Garrie, February 4, 2014
- [How to Evaluate a Digital Forensic Report – Part 3: Experts](http://www.lawandforensics.com/evaluate-digital-forensic-report-part-3-4/),
by Daniel B. Garrie, February 10, 2014
- [How to Evaluate a Digital Forensic Report – Part 4 & Conclusion](http://www.lawandforensics.com/evaluate-digital-forensic-report-part-4-4/),
by Daniel B. Garrie, February 14, 2014
- [The Laptop, Slack Space and Child Pornography](http://cyb3rcrim3.blogspot.com/2015/08/the-laptop-slack-space-and-child.html),
by Susan Brenner, August 03, 2015
8 changes: 4 additions & 4 deletions docs/cell_phone_forensics_research.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ forensics with the right mix of methods, techniques, and tools.

[The Future of Mobile Forensics](https://belkasoft.com/future-of-mobile-forensics), Oleg Afonin, Danil Nikolaev, Yuri Gubanov by [Belkasoft](belkasoft.md) Research, June 2015

[Data Acquisition from Cell Phone using Logical Approach](http://www.waset.org/pwaset/v26/v26-6.pdf), Keonwoo Kim, Dowon Hong, Kyoil Chung, and Jae-Cheol Ryou, PROCEEDINGS OF WORLD ACADEMY OF SCIENCE, ENGINEERING AND TECHNOLOGY VOLUME 26 DECEMBER 2007 ISSN 1307-6884
[Data Acquisition from Cell Phone using Logical Approach](https://publications.waset.org/7561/data-acquisition-from-cell-phone-using-logical-approach), Keonwoo Kim, Dowon Hong, Kyoil Chung, and Jae-Cheol Ryou, PROCEEDINGS OF WORLD ACADEMY OF SCIENCE, ENGINEERING AND TECHNOLOGY VOLUME 26 DECEMBER 2007 ISSN 1307-6884
This article discusses three approaches for acquiring data from cell phones:
physically removing the flash RAM chips and reading them directly; reading the
data out using the JTAG interface, and running software on the cell phone to
Expand All @@ -25,6 +25,6 @@ by James Luck & Mark Stokes, SMALL SCALE DIGITAL DEVICE FORENSICS JOURNAL, VOL.

## US Government Publications

[Guidelines on Cell Phone Forensics](https://csrc.nist.gov/publications/detail/sp/800-101/archive/2007-05-30) (NIST SP 800-101), May 2007
[Cell Phone Forensic Tools: An Overview and Analysis](https://csrc.nist.gov/publications/detail/nistir/7250/final) (NISTIR 7250)
[PDA Forensic Tools: An Overview and Analysis](https://csrc.nist.gov/publications/detail/nistir/7100/final) (NISTIR 7100)
* [Guidelines on Cell Phone Forensics](https://csrc.nist.gov/pubs/sp/800/101/final) (NIST SP 800-101), May 2007
* [Cell Phone Forensic Tools: An Overview and Analysis](https://csrc.nist.gov/pubs/ir/7250/final) (NISTIR 7250)
* [PDA Forensic Tools: An Overview and Analysis](https://csrc.nist.gov/pubs/ir/7100/final) (NISTIR 7100)
2 changes: 1 addition & 1 deletion docs/computer_forensics.md
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,7 @@ ethical and a professional responsibility to:

Equivalent or other perspectives on forensic profession:

* [Forensic Focus Webinar: Being Your Own Expert Witness](https://www.forensicfocus.com/c/aid=103/webinars/2015/being-your-own-expert-witness/)
* [Forensic Focus Webinar: Being Your Own Expert Witness](https://www.forensicfocus.com/webinars/being-your-own-expert-witness/)

## Terminology

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,4 +45,4 @@ protected by copyright, trademark, or trade-secret designation.

## External Links

- [Official website](https://www.justice.gov/criminal-ccips)
- [Official website](https://www.justice.gov/criminal/criminal-ccips)
1 change: 0 additions & 1 deletion docs/forensic_accounting.md
Original file line number Diff line number Diff line change
Expand Up @@ -64,6 +64,5 @@ the final examination needs to be completed.

## External links

- [Times of India Article on CFAP](https://epaper.timesgroup.com/Repository/ml.asp?Ref=VE9JQkcvMjAwOS8wNS8wNCNBcjAzMjAx)
- [CFAP Information Powerpoint](https://www.slideshare.net/indiaforensic/certified-forensic-accounting-professional)
- [Certification programs offered by Indiaforensic](https://www.indiaforensic.com/education/)
Loading

0 comments on commit a57b92e

Please sign in to comment.