Showing posts with label Digital Forensics. Show all posts
Showing posts with label Digital Forensics. Show all posts

Wednesday, May 3, 2017

Verizon DBIR Shows Attack Patterns Vary Widely By Industry

From Dark Reading:

Verizon DBIR Shows Attack Patterns Vary Widely By Industry

"It's not always the newest or the most sophisticated threat you need to worry about, Verizon's breach and security incident data for 2016 shows.

Among the many key takeaways in the 2017 edition Verizon’s annual Data Breach Investigations Report (DBIR), released Thursday, is that there are significant differences in why and how organizations across different industries are attacked."

Tuesday, June 30, 2015

Stealthy Fobber Malware Takes Anti-Analysis To New Heights

From Dark Reading:

Stealthy Fobber Malware Takes Anti-Analysis To New Heights

Built off the Tinba banking Trojan and distributed through the elusive HanJuan exploit kit, Fobber info-stealer defies researchers with layers upon layers of encryption.

A stealthy new info-stealing browser injection malware aims to make security researchers' job very difficult. Fobber evades detection and defies anaylsis by sliding from one program to another, using randomly generated filenames, encrypting command-and-control communications with a custom algorithm, and encrypting individual pieces of code within the payload, so that each function must be separately, painstakingly decrypted before it can be run.

Saturday, May 9, 2015

U.S. Attorney: Managing Fraud Investigations

If you suspect you've been breached get law enforcement involved right away.  Do not turn off any suspect system(s) or attempt to initiate your own investigation (unless you happen to be a certified digital forensic investigator) or make any changes to the suspect system(s) whatsoever. Start with your local PD, they will escalate as needed.  After that start the customer notification process.  Study after study has shown that companies that get ahead of a breach fare much better than those that don't.

From Data Breach Today:

U.S. Attorney: Managing Fraud Investigations

Knowing exactly when to share information with law enforcement in the wake of a breach is challenging, says Assistant U.S. Attorney William Ridgway, a featured speaker at Information Security Media Group's Fraud Summit Chicago on May 19.

The USBKILL anti-forensics tool - it doesn't do *quite* what it says on the tin

From Sophos Naked Security:

The USBKILL anti-forensics tool - it doesn't do *quite* what it says on the tin

A hacker who very modestly goes by the handle Hephaest0s has just announced an "anti-forensic kill switch" dubbed, well, usbkill.

Wednesday, May 6, 2015

Breach Detection, Prevention Harder Than 2 Years Ago Despite Security Spending: Survey

From Security Week:


Breach Detection, Prevention Harder Than 2 Years Ago Despite Security Spending: Survey


A new report from Enterprise Strategy Group found that many enterprises feel breach prevention and detection is more difficult today than two years ago.


According to a survey of 200 IT and information security professionals, 75 percent agreed that detecting and preventing a breach has become harder. Fifty-nine percent said malware has grown more sophisticated during the last 24 months and presents fresh challenges - even though the vast majority (87 percent) said they have increased endpoint security spending during the same period.

Tuesday, April 28, 2015

Champlain College Awarded for Best Cybersecurity Higher Education Program

From Forensic Magazine:

Champlain College Awarded for Best Cybersecurity Higher Education Program

Champlain College has been recognized for the second time as winner of the Professional Award for Best Cybersecurity Higher Education Program at the 2015 SC Awards. The award was presented during the 2015 SC Awards Gala held in San Francisco.

Thursday, March 12, 2015

Dusting for Cyber Fingerprints: Coding Style Identifies Anonymous Programmers

From Forensic Magazine:

Dusting for Cyber Fingerprints: Coding Style Identifies Anonymous Programmers

A team of computer scientists, led by researchers from Drexel University’s College of Computing & Informatics, have devised as way to lift the veil of anonymity protecting cyber criminals by turning their malicious code against them. Their method uses a parsing program to break down lines of code, like an English teacher diagramming a sentence, and then another program captures distinctive patterns that can be used to identify its author.

Thursday, February 19, 2015

The Possible Put Into Digital Forensic Practice With Grier Technology

From Forensic Magazine:

The Possible Put Into Digital Forensic Practice With Grier Technology

After listening to colleagues for years and exploring it further, Jonathan Grier saw how pressing the need was for technology like his. As explained in the previous discussion with Grier, his technology decreases the time to image a hard drive by 3 to 13 times, speeding digital investigation and reducing the use of resources.

This $150,000 Kickstarter Campaign Wants To Turn Kids Into Crime Scene Investigators

From Forbes:

This $150,000 Kickstarter Campaign Wants To Turn Kids Into Crime Scene Investigators

London-based startup Forensic Outreach is hoping to raise at least $150,000 via Kickstarter to create a “virtual faculty” that would get kids into the science behind crime scene investigation. The CASE Academy already has an impressive line-up of teachers and backers, including Kimberlee Sue Moran, current FBI forensic examiner and cryptanalyst, and Thomas Mauriello, former special agent with the US Department of Defense.

Tuesday, February 17, 2015

eDiscovery tools and methodologies can “significantly enhance” digital forensic investigation: UK Home Office report

From Business Wire:

eDiscovery tools and methodologies can “significantly enhance” digital forensic investigation: UK Home Office report

LONDON--()--Nuix, a technology company that enables people to make fact-based decisions from unstructured data, welcomes the findings of the report ‘eDiscovery in Digital Forensic Investigations’ published by the United Kingdom Home Office. The report concludes that “Giving investigators rapid access to the digital information in a form that they can understand and work with has the potential to significantly enhance an investigation.”

Wednesday, February 11, 2015

Government Contract to Grier Forensics Speeds-Up Digital Investigation

From Forensics Magazine:

Government Contract to Grier Forensics Speeds-Up Digital Investigation

It is often the case that the spur to innovation in America takes the form of a government solicitation. As an instrument of the people, the government gives power to the those that develop ideas and tools that benifit everyone. Forensic tools are no exception.

Tuesday, February 10, 2015

Digital Evidence Requires an Understanding of 'Cyberlaw'

From Forensic Magazine & Irish Times:

Digital Evidence Requires an Understanding of 'Cyberlaw'

How is the criminal justice system learning to cope with the unique complexities of digital evidence, with the analysis of mobile phone data, satellite imagery and emails? And that’s before you add in all the potentially sensitive material on social media sites such as Facebook, Twitter, YouTube, Flickr and Instagram.

Monday, February 9, 2015

US Army Releases Cyber-Forensic Code to Github

From Infosecurity magazine:

US Army Releases Cyber-Forensic Code to Github

The Army Research Laboratory (ARL) is releasing its cyber-forensic framework code publically to help others detect and understand cyber-attacks.