Tool Validation in Digital Forensics

 I keep hearing people say you need to use multiple forensic tools for your examination and to validate your findings. Most conversations center around the use of two different big forensic tools suites like Axiom and EnCase or Cellebrite and Oxygen, and I have to disagree. 


You don't need two expenses software packages to get the job done. Think differently. Got SQLite Databases? Look at in a native SQLite DB app. Need EXIF data? Try exiftool. I could go on and on. 



You don't need two pricey tools. IMO, you need one primary tool that can do your heavy lifting that provides a nice overview of the artifacts and, thus, a starting point. But then once you've found the good stuff that's where you're going to move onto something different for the raw data and the validation, and it's going to consist of some native apps, some free tools, and probably a few tools that a small price tag. 


Maybe it's because I'm old, but this is how I roll.



Comments

Popular posts from this blog

The Rising Cost of Mobile Forensics

Time is the longest distance between 2 points

How AI & Deepfakes lead to Sextortion