Jesse M. Lindmar · @jlindmar
35 followers · 14 posts · Server infosec.exchange

The Virginia Department of Forensic Science (DFS) is seeking a qualified or trainee candidate to perform Digital & Multimedia evidence analyses, with a focus on mobile and computer device analysis, at the Central Regional Laboratory, located in Richmond, Virginia.

jobs.virginia.gov/jobs/forensi

If anyone has questions beyond the information that is available in the posting, please feel free to reach out to me. I would love the opportunity to discuss the details of the position with anyone who is interested.

#digitalforensics #computerforensics #mobileforensics #dfir

Last updated 2 years ago

Zach · @1312
2 followers · 29 posts · Server mastodon.sdf.org

This is quite interesting. It appears to be a Police Sergeant trying to obtain a forensic image of the phone of a crime victim, who has filed a report over a cop assaulting him. This investigating officer tells the victim, who is a citizen journalist, and a well-known cop-watcher, that she needs his phone in order to verify that the video hasn't been "doctored". (cont)

vid.puffyan.us/watch?v=w4DRvY2

#computerforensics #civilrights #independentjournalism #tempeaz

Last updated 2 years ago

Man, I love old episodes. Lol.

#forensicsfiles #computerforensics

Last updated 2 years ago

Jesse M. Lindmar · @jlindmar
33 followers · 10 posts · Server infosec.exchange

For those of you interested in learning how to use X-Ways Forensics, there are still a few seats left in the March 06-09 training course taking place in the Washington, DC/Baltimore area:

x-ways.net/training/washington

#digitalforensics #computerforensics #mobileforensics #dfir

Last updated 2 years ago

Jesse M. Lindmar · @jlindmar
29 followers · 30 posts · Server infosec.exchange

Resoundingly, the poll showed that most don't use X-Ways Forensics for anything other than analyzing traditional, computer-based storage devices.

So, WHY don't you use it for data from other sources (e.g., mobile phone extractions, chip dumps, etc.)?

#dfir #digitalforensics #mobileforensics #computerforensics

Last updated 2 years ago

Jesse M. Lindmar · @jlindmar
16 followers · 24 posts · Server infosec.exchange

SQLite Query Tip: when converting timestamps with millisecond precision, consider using the "strftime" function instead of "datetime".

The "strftime" function includes the "%f" substitution that allows for fractional seconds (SS.SSS) to be displayed. This can be very helpful if wanting to be very precise when determining timeline activity.

sqlite.org/lang_datefunc.html

Keep in mind that if your query requires dividing by an integer by another integer (e.g. converting Apple CFAbsoluteTime, 18-digit, nanosecond precision timestamps), you will need to use the "CAST AS FLOAT" operator in order to avoid rounding issues, e.g.:

strftime('%m-%d-%Y %H:%M:%f', CAST([table].[field] AS FLOAT) / 1000000000 + 978307200, 'unixepoch')

Bonus points if you can explain WHY I am dividing by 1000000000 and adding 978307200 in the above example. Consider the value represented by [table].[field] to be an Apple CFAbsoluteTime, 18-digit, nanosecond precision timestamp.

#dfir #digitalforensics #mobileforensics #computerforensics

Last updated 2 years ago

Jesse M. Lindmar · @jlindmar
14 followers · 23 posts · Server infosec.exchange

SQLite Query Tip: try using the "IFNULL" function in your queries to clearly identify truly empty (blank) values in a source database - for example, you could output "[NULL]".

Doing this can help avoid confusion about why a value is blank in a query's output.

#dfir #digitalforensics #mobileforensics #computerforensics

Last updated 2 years ago

Jesse M. Lindmar · @jlindmar
14 followers · 23 posts · Server infosec.exchange

SQLite Query Tip: when converting/interpreting values (e.g. "0" = "False" or "No"), I recommend including the original values in the output.

This not only shows transparency in your work; but is helpful when verifying converted/interpreted values when you don't have access to the query.

For example, you could output both the original and converted/interpreted fields/values so they are adjacent, or include both values in the same cell (e.g. "0 [No]", or use the "||" concatenation operator).

#dfir #digitalforensics #mobileforensics #computerforensics

Last updated 2 years ago

Is TAILS still any good?
It's been a few years since I tried it. Just curious if it is still popular.

tails.boum.org/news/version_5.

#privacy #infosec #opsec #cybersecurity #computerforensics

Last updated 2 years ago

Jesse M. Lindmar · @jlindmar
14 followers · 23 posts · Server infosec.exchange

X-Ways Software just released X-Ways Forensics 20.7 SR-2. Check the release notes (x-ways.net/winhex/forum/messag) for the details.




#digitalforensics #mobileforensic #computerforensics #dfir

Last updated 2 years ago

Jesse M. Lindmar · @jlindmar
7 followers · 7 posts · Server infosec.exchange

In the event that anyone was still unsure, "...digital evidence examination rests on a firm foundation based in computer science."

"Digital Investigation Techniques: A NIST Scientific Foundation Review"
nvlpubs.nist.gov/nistpubs/ir/2




#digitalforensics #computerforensics #mobileforensics #dfir

Last updated 2 years ago

Jesse M. Lindmar · @jlindmar
7 followers · 7 posts · Server infosec.exchange

X-Ways Software just released X-Ways Forensics 20.7 SR-1. Check the release notes (x-ways.net/winhex/forum/messag) for the details.




#digitalforensics #mobileforensic #computerforensics #dfir

Last updated 2 years ago

Sylvia · @ThatGalSilver
148 followers · 10 posts · Server tech.lgbt

Since I’ve moved home to tech.lgbt it’s time for a new post!!

Hi! My name is Sylvia, Sylvie, Silvy, Silver or any variant of that. I’m 28 years old, a -binary , as fuck though I’ve always identified as some sort of !

My interests include but are not limited to: , gender identity related topics, (I went to college for , although I didn’t finish my minor classes), and and .

#introduction #non #transgender #woman #sapphic #bisexual #gaming #technology #computerforensics #music #comics #films

Last updated 2 years ago

Jesse M. Lindmar · @jlindmar
7 followers · 7 posts · Server infosec.exchange

X-Ways Forensics 20.7 SR-0 was just released.

x-ways.net/winhex/forum/messag

I'm excited to see that the "functionality of Excire Forensics is now included..."!

#dfir #digitalforensics #computerforensics #mobileforensics

Last updated 2 years ago