±Forensic Focus Partners
±Your Account

![]() |
![]() |
![]() |
![]() |
±Latest Articles
±Latest Jobs
±Latest Webinars
Back to top
Skip to content
Skip to menu
Back to top
Back to main
Skip to menu
When performing a boot scan, what live distribution is used to run your tools? What measures were taken to disable the automatic mounting of file systems? What measures were taken to disable the automatic code execution from a suspect drive? Is there a software write blocker present?
Thank you for the reply! I am not interested in your tools anymore.
@thefuf
WHY? <- Rhetorical question
@PC4N6
Only out of curiosity (and of course only if you can actually disclose this kind of info publicly), what is the plan when (hypothetically) one of your users is standing on the (expert) witness stand (under oath) and is asked how the tool he/she used works?
Just for the record, I was almost flamed for expressing a similar doubt a few years ago:
www.forensicfocus.com/...ic/t=2488/
jaclaz
_________________
- In theory there is no difference between theory and practice, but in practice there is. -
Streamline Your Digital Investigations
Streamline Your Digital Investigations
Posted: Mon Jan 16, 2017 9:59 am
Please use this topic for discussion of the webinar
Streamline Your Digital Investigations
Presenter: Richard Frawley, ADF Solutions
_________________
Senior Editor, Forensic Focus
Web: www.forensicfocus.com
Twitter: twitter.com/ForensicFocus
Facebook: www.facebook.com/forensicfocus
Streamline Your Digital Investigations
Presenter: Richard Frawley, ADF Solutions
_________________
Senior Editor, Forensic Focus
Web: www.forensicfocus.com
Twitter: twitter.com/ForensicFocus
Facebook: www.facebook.com/forensicfocus
-
scar - Forensic Focus
Re: Streamline Your Digital Investigations
Posted: Mon Jan 16, 2017 11:00 am
- scarPlease use this topic for discussion of the webinar
Streamline Your Digital Investigations
Presenter: Richard Frawley, ADF Solutions
When performing a boot scan, what live distribution is used to run your tools? What measures were taken to disable the automatic mounting of file systems? What measures were taken to disable the automatic code execution from a suspect drive? Is there a software write blocker present?
-
thefuf - Senior Member
Re: Streamline Your Digital Investigations
Posted: Wed Jan 18, 2017 3:58 pm
Thank you for your interest in our tools. The operating system used on our Collection Key during a boot scan is forensically sound. It does not automatically mount volumes or allow automatic code execution. We prefer to not discuss technical specifics within a public forum but are happy to assist our customers with this information or others in a private non-disclosure situation.
-
PC4N6 - Newbie
Re: Streamline Your Digital Investigations
Posted: Wed Jan 18, 2017 6:19 pm
- PC4N6Thank you for your interest in our tools. The operating system used on our Collection Key during a boot scan is forensically sound. It does not automatically mount volumes or allow automatic code execution. We prefer to not discuss technical specifics within a public forum but are happy to assist our customers with this information or others in a private non-disclosure situation.
Thank you for the reply! I am not interested in your tools anymore.
-
thefuf - Senior Member
Re: Streamline Your Digital Investigations
Posted: Wed Jan 18, 2017 7:05 pm
- thefuf- PC4N6Thank you for your interest in our tools. The operating system used on our Collection Key during a boot scan is forensically sound. It does not automatically mount volumes or allow automatic code execution. We prefer to not discuss technical specifics within a public forum but are happy to assist our customers with this information or others in a private non-disclosure situation.
Thank you for the reply! I am not interested in your tools anymore.
@thefuf
WHY? <- Rhetorical question

@PC4N6
Only out of curiosity (and of course only if you can actually disclose this kind of info publicly), what is the plan when (hypothetically) one of your users is standing on the (expert) witness stand (under oath) and is asked how the tool he/she used works?
Just for the record, I was almost flamed for expressing a similar doubt a few years ago:
www.forensicfocus.com/...ic/t=2488/
jaclaz
_________________
- In theory there is no difference between theory and practice, but in practice there is. -
-
jaclaz - Senior Member