
DFSP # 010 - Investigation Survival Tips
This episode covers Investigation Survival Tips.... for the new guy. Newer examiners are often thrown into a world where it is there mission to find "everything." Not on that, they are usually given i...
25 Apr 201625min

DFSP #009 - Linux for Computer Forensics
In this episode I cover using Linux as a forensic platform... for the new guy. I find many examiners are very Windows-centric. There is nothing wrong with that as most tools and evidence is Windows ba...
18 Apr 201616min

DFSP # 008 - Virtual Machines & Computer Forensics
In this episode I talk all about virtual machines; the reasons you should be using them (more), prebuilt ones that are freely available and loaded with digital forensic tools and a free virtual machin...
11 Apr 201622min

DFSP #007 - File Use & Knowledge Wrap Up
In this episode we wrap up the File Use & Knowledge artifacts discussed previously and talk about how they connect to help strengthen a case.
4 Apr 201629min

DFSP #006 - Resolving Attached USBs
Have you ever been asked to find out what the "F" drive is? Have you ever needed to prove a USB drive was attached to a target system? Collecting and presenting this information is a core skill all co...
28 Mar 201620min

DFSP #003 - What the Shellbag!
In this episode we examine how to use Windows Shellbag records to help prove file use and knowledge. Shellbag records are created by certain user activity and can be used to show where a user has navi...
21 Mar 201628min

DFSP #004 - Windows Prefetch
Windows Prefetch data is a great source of evidence to help determine file use and knowledge of applications running on the system.
14 Mar 201618min

DFSP #003 - Windows Explorer Evidence
Oftentimes you will be asked to find information on a target system that shows if a user accessed certain files, the last time they did and/ or how often they did. Being able to put a picture together...
17 Feb 201616min


















