Friday, May 3, 2013

I have fully moved over to my new Domain.

See you all there!


Friday, March 29, 2013

New updates

For a more in depth update, visit my new location at

A list of what has come out recently.

BlackBag - BlackLight 2013 R1

Cellebrite - Application v1.8.6.0

Logicube - Dossier v3.3.3RC16

Guidance Software - EnCase v7.06.01

Access Data - FTK 4.2.1
Access Data - PRTK/DNA 7.1.0

Magnet Forensics - Internet Evidence Finder 6.0

Tableau - Tableau Updater v7.02


Friday, March 15, 2013

F-Response has a new version

F-Response has a new version.  4.0.6
There are some pretty big changes.
  • New connectors for all customers with Tactical and above
  • F-Response Database Object Connector - Maps remote databases with embedded file objects to the local examiner's machine where they appear as a local read-only share.
  • F-Response Email connector - provides direct, read-only access to remote GMail, Yahoo! Mail, and IMAP based email data.  F-Response will show it as a read-only, locally attached share.
I can't stress this enough, F-Response is a must for anyone doing acquisitions.  The extra capabilities it adds are immense.
To read more about this release visit

Thank you

I would like to thank everyone for visiting!

I have gotten a bit fed up with blogspot over the past few months and have decided to buy a domain for the blog.

For the next month (through April) I will still be posting here, however I now own

Both sites will get the updates and I will fully transition by April 30th.

I hope to see you there!

Friday, March 1, 2013

Guidance Software has a new update.

EnCase 7.06 is available

It appears that this update is focused heavily on the Mac side of things and a new Network previewer.
I have a Mac that I am currently examining, so I look forward to trying this out.

Updates include:

  • Direct Network Preview
    • Awesome!
    • This allows you to conduct a live examination over a network without the need of a SAFE.
    • It allows you to deploy a servlet to a single computer on the network in order to read, acquire, or monitor a hard drive or computer.
    • I will be testing this out ASAP.
  • Forensic Imager (Pretty much the functionality of Acquisition)
    • No dongle needed and it is free of charge.
  • Macintosh Enhancements
    • Displays all HFS+ file system compressed files as uncompressed
    • Supports Directories' hard links (used in conjunction with Apple Time Machine)
    • Supports OS X 10.8
    • Others
  • Others
To read more visit

Fore sales and training visit the Guidance Software training partner of the year World-Wide for both 2011 and 2012


Micro Systemation has a new release

XRY v6.5 has been released.

This new version includes:

  • Improved Android 4.0 Physical support
  • MTK Chipset NAND decoding
  • Numerous new models supported
  • Others
To read more visit


Friday, February 22, 2013

Passware has a new release

Passware Kit Forensic 12.3 has been released.

New features include:

  • Extraction of Facebook, Google, and other passwords from live memory and hibernation files
  • Distributed password recovery using custom dictionaries
  • Hardware acceleration using ATI cards
  • Others
To read more about this release visit

For sales and training visit


Tableau has a new firmware updater

Tableau Firmware Updater v7.01 has been released.

Remember the Tableau updater is used for all of Tableau's tools.

This update includes updates for:

  • T35es/T35es-R2 - Improved detection of media larger that 2TB
  • T6es - Bug fixed where data corruption could occur during an image.
To read the release notes visit

For training, sales, and other information visit


Cellebrite has a new update

UFED Physical Analyzer 3.6.5 has been released.

This release contains the following maintenance fixes:

  • Resolves decoding issues with Android SMS, iPhone SMS and MMS recipient fields, attachments with iPhone deleted MMS within Excel reports.
To read more about this maintenance update visit

For training, sales, and any other questions visit


Guidance Software has released a new version of EnCase

EnCase 7.05.03 has been released.

The main reason for this update was to fix some bugs.

  • When a snapshot is taken of a machine on a wireless network, EnCase can now determine the IP address.
  • More encryption support
To read more visit

For training with EnCase and for sales visit


Tuesday, February 12, 2013

Cellebrite has a new update.

I meant to post this last Friday but have been sick for the past couple days...sorry.

UFED has been released.

This is a big one.

New abilities include:

  • Physical and File System extractions from 101 HTC and Motorola locked devices running Android
  • Galaxy SIII and Galaxy Note II Physical extractions and decoding while bypassing passwords / PIN / pattern lock
  • Applie iOS 6.1 Physical, File System, and Logical extractions
  • Others (The above seem enough though.)
To read more visit

For training or purchases visit


Friday, February 1, 2013

Vound Software has released a new version of Intella

Intella 1.6.3 has been released.

This release has some pretty big changes!

1.6.3 new features:

  • Indexing support for e01 and l01 formats!
  • Indexing of Hotmail and Yahoo search warrant results
  • Indexing of nested mail containers (The example they give brings clarity here, "e.g. a zipped PST attached to an email in an Mbox file.")
  • Officially supported 64-bit version!
  • Support for 64-bit MS Office and Outlook (Hallelujah! (I had to Google how to spell Hallelujah...))
  • Cellphone improvements such as XRY's XML format
  • Spanish Translation!
  • Others
To read more visit

To purchase please visit


Paraben has released a new Device Seizure

Device Seizure 6 has been released.

I am not sure what the updates are...  On the Paraben website under Device Seizure 6 features, it still says, "Here's what's new in version 5."

I will keep checking with them to see if I can't get some more information for you.

Check for yourself


Access Data has some new releases

FTK 4.2 is now available.
MPE+ 5.2.1 is now available.

The FTK 4.2 release contains the following:

  • Support for Microsoft SQL Server 2008 R2 or 2012 as your FTK database
  • PostgreSQL 9.1.6 supported
  • Browse IIS log file data in HTML format
  • Procsess SAM and NTUSER.dat files into individual records organized by time, with some data shown.  (I'm not sure what it shows, I still need to play with it.)
  • FTK 4.2 can decrypt Bitlocker on Windows 7 and Windows Vista
  • More...
MPE+ 5.2.1 updates include:

  • More advanced features for parsing Android and iOS applications
  • Support for iOS 6.0.1
  • Logical Support for iPhone 5 and iPad mini
  • Others
To read more visit

For purchase, training, or more information.  Visit


New Year

Welcome back to the blog!

January was pretty slim on the updates.  There were a few at the end of the month, but I decided to hold off until today to post them.

Thanks for visiting and making this blog a success last year.  I hope to continue throughout this year as well.

I get to shamelessly brag a little bit about H-11 here.  H-11 Digital Forensics were the Guidance Software Authorized Training Partner of the Year Worldwide for 2012!

Lets make 2013 awesome as well!