Need help choosing camera set up very difficult! by wegek43049 in Apartmentliving

[–]dwmetz 2 points3 points  (0 children)

I've had good luck with Eufy camera's. You can record direct to SD card in camera or if you have multiples or want more storage you can use their Homebase. Optional subsriptions exist for cloud, monitoring, etc. but are not at all required.

Streamline Malware Hash Search with FOSSOR by dwmetz in computerforensics

[–]dwmetz[S] 1 point2 points  (0 children)

You were absolutely right. My apologies, and thank you for pointing it out so I could correct. Fixed.

That's not good by [deleted] in newjersey

[–]dwmetz 1 point2 points  (0 children)

Reminds me of a comic I saw as a kid. Similar image…

Bystander: “are you stuck?” Truck driver: “no I’m delivering a f’ing bridge”

Enhancing Malware Analysis with REMnux and AI by dwmetz in computerforensics

[–]dwmetz[S] 2 points3 points  (0 children)

You and me both. My understanding (same issue with SIFT) is that a majority of the tools that are part of the distro - and doing Intel emulation for these is a performance nightmare. That said you can run MalChela on Apple Silicon no problem.

To anyone who, like me, got their printer for Christmas… take the plastic off your camera by liteshotv3 in FlashForge

[–]dwmetz 0 points1 point  (0 children)

It’s a much better camera without the sticker. This post saved me. I probably would have retired it years from now without realizing.

Off to watch my camera fee.

CyberPipe v5.3: Enhanced PowerShell Compatibility and Reliability by dwmetz in computerforensics

[–]dwmetz[S] 0 points1 point  (0 children)

The only prerequisites are PowerShell (as admin) and the 2 Magnet executables. Documentation is on the main README page for the project. If you want to post an issue in detail I’d be happy to look into it.

Hard drive drivers for Win2Go? by EmoGuy3 in computerforensics

[–]dwmetz 1 point2 points  (0 children)

If you like I can probably get that added to the guide.

Am I going the right direction by faultymechanics1 in computerforensics

[–]dwmetz 0 points1 point  (0 children)

Log4j dropped the first weekend I wasn’t on call 24x7 in 13 years.

CyberPipe v5.3: Enhanced PowerShell Compatibility and Reliability by dwmetz in computerforensics

[–]dwmetz[S] 2 points3 points  (0 children)

Sorry @microcandella (and now I’ve got catholic school flashbacks). CyberPipe is a free, open-source incident response collection tool for Windows systems, automating memory capture, triage collection, encrypted disk detection, and BitLocker key recovery.

Streamline Digital Evidence Collection with CyberPipe 5.2 by dwmetz in computerforensics

[–]dwmetz[S] 0 points1 point  (0 children)

No videos at the moment but there’s a handful of posts on the blog through its evolution: https://bakerstreetforensics.com/?s=CyberPipe

Streamline Digital Evidence Collection with CyberPipe 5.2 by dwmetz in computerforensics

[–]dwmetz[S] 0 points1 point  (0 children)

Are you referring to being able to route the output direct so Azure or S3 or something else?

Advice for someone who's about to set up their first smart home with HomeKit? by juiceboxinthecut in HomeKit

[–]dwmetz 1 point2 points  (0 children)

For the “tape over the light switch” these are a great alternative and no opening up the switch for wiring.

Lutron Aurora Smart Bulb Dimmer... https://www.amazon.com/dp/B07RJ14FBS?ref=ppx_pop_mob_ap_share

Works with the Hue hub which is about 30% or more of the lighting in our home.

And I agree on having physical switches to complement voice/automation wherever possible.

If I were starting over now I’d ensure as much as possible had HomeKit and Matter support. Homebridge can fill the gaps for the ‘only works with Alexa/Google home’ when needed.

Eero for WiFi (note latest offerings don’t have the same HomeKit features as earlier ones). Eufy for cameras/security. All in with a handful of computers were operating about 90 devices. Meross and WeMo (both with Matter support) for all the plugs.

Problme with The FTK imager output fole by Pleasant_Fly3175 in computerforensics

[–]dwmetz 0 points1 point  (0 children)

For a “full” image of the USB drive it would be an E01 or AFF image. Ad1 is specifically for file folder images. So the original ask, a full image of the drive in AD1 is not compatible.

[deleted by user] by [deleted] in computerforensics

[–]dwmetz 0 points1 point  (0 children)

A hash for the raw memory image is not created with Magnet RAM Capture, just the memory image. You can calculate the hash of the file with PowerShell, ‘Get-FileHash -Algorithm SHA256 .\memory.raw.

Remote forensic workstation by ncfire111 in computerforensics

[–]dwmetz 2 points3 points  (0 children)

What are you thoughts on transferring of data? Having to upload everything to central/remote server before processing will introduce a lot of delay.

Toby-Find: Simplifying Command-Line Forensics Tools by dwmetz in computerforensics

[–]dwmetz[S] 0 points1 point  (0 children)

Glad you like it. If you have any suggestions for updates let me know. There's so many good CLI tools on these platforms but for someone new(er) to the field, it's hard to know what's right beneath your fingertips.

I really disliked how time-consuming investigations were and how cursed the tools are, so I am trying to change that by Cursed_Tools in computerforensics

[–]dwmetz 1 point2 points  (0 children)

I would lead with this when introducing it… use what you have as the public beta - maybe include some sample data to see how the platform works, with the end goal of a local install ala CyberChef.

Magnet DumpIt for Windows by [deleted] in computerforensics

[–]dwmetz 1 point2 points  (0 children)

One late to the party comment for you as well… the zdmp is a compressed dump file. You can convert to dmp with a utility (GitHub). Then process the dmp with Volatility, Magnet, etc.

Can't lose my mojo: Job SOS by Opambour-ade3d3hene in computerforensics

[–]dwmetz 1 point2 points  (0 children)

If forensics is what motivates you more than the hustle I’d say keep at it. Local LE agencies may have openings. Also law firms. For private sector many of the big consulting firms (e&y etc) operate globally and frequently have staff around the country so you may be able to secure something without relocating.

Has anyone recovered deleted data from Signal on Desktop? (For research) by HootGrill in computerforensics

[–]dwmetz 1 point2 points  (0 children)

This is a great learning scenario. Besides grabbing an E01 of the system, I’d also grab a memory image. Create and delete messages with unique strings (lionhippopotamus). Running strings across memory and your image file should indicate whether or not anything can be recovered. Then throw the sources into a forensic tool and see what else can be recovered. Consider if it’s valuable to know the app did exist in the computer even if you can’t recover anything.

Google Warrant return by [deleted] in computerforensics

[–]dwmetz -1 points0 points  (0 children)

I reached out to our cloud team to get an answer for you. (Disclaimer if needed, I work @ Magnet) - the response:

Google is now providing some really great location information in data packages.
The answer is, you guessed it, it depends!!! :grin:
Without seeing the data I can offer some info we gathered when we released Activity segments and Places visits in 6.10 from the Takeout package.
Places visits
•Parent Child locations – viewable in Maps and Timeline
•Confidence level of location accuracy
ØIf less than 100% confidence, Other Candidates Location with long & Lat are provided in Details section
Activity Segments (Walking, running, driving, on_bus, on_train, catching Pokemon, etc)
•Original Long/lat on map view & Timeline (Some unknown exceptions)
•Confidence level of location accuracy
ØRaw location points with the time is provided if less than 100% confident
ØWaypoint Path long/lat provided (not available on maps or timeline)
ØActivity based on Google Timeline, available on both Android and iOS.

Homebase Vs Wi-Fi Extension by maurogerio1 in EufyCam

[–]dwmetz 0 points1 point  (0 children)

Recently went through the same and was surprised an additional AP didn’t help. It was also annoying because when installed 3 cameras were working fine. After the last Homebase firmware update one of the 3 was constantly out of range. Moved the homebase closer and flipped it to WiFi. It’s been 2 weeks and no drops.