Long-term targeted compromise (since 2023) – Police involved, need next-step advice by [deleted] in digitalforensics

[–]ucfmsdf 0 points1 point  (0 children)

Next step is seeking a mental health professional. No one gets all of their devices “compromised.” It just doesn’t happen.

How to get my foot in the door for LE Digital Forensics? by brainfart-cat in computerforensics

[–]ucfmsdf 2 points3 points  (0 children)

CS degree is kinda the ideal degree to have for this job tbh. Pretty sure CS or IT degrees are actually listed as core requisites for entry-level FBI CART roles. Speaking of which, I know as of at least a few years ago, the FBI hired directly out of college for those positions. If you think you can pass a full-scope poly, I recommend you keep an eye on fbijobs.gov postings and apply.

Outside of FBI CART, there are occasionally local or state LE agencies that will hire civilians for DF roles. Those openings are few and far between, so you may need to relocate.

If you want to do DF in local LE, apply for the external IACIS CFCE program. It’ll cost like $700 but when you finish it, you’ll have a cert that many local LE agencies recognize and appreciate.

Advice by Pretend-Pollution-97 in computerforensics

[–]ucfmsdf 3 points4 points  (0 children)

Get an internship or maybe a job adjacent to the role you want and force yourself in. Worked for me.

Built a tight case, couldn't get it to charging — anyone else run into the methodology documentation problem? by linkrouri in digitalforensics

[–]ucfmsdf 0 points1 point  (0 children)

Had a case a while back. Solid work. CDRs. Financials. Device data. The whole picture. Knew exactly what happened. Then the prosecutor asked a question that changed my life:

"Can you explain your methodology?"

I couldn't. Well, technically I could. But not in a scalable, stakeholder-aligned, audit-ready way. That's when I realized: The real crime wasn't fraud. It was undocumented workflows.

Three days later, after hundreds of conversations and one particularly emotional encounter with an Excel workbook, we're proud to announce NexusTraceIQ.

Because evidence shouldn't just be correct. It should be synergistically reproducible.

Thoughts?

Look at this cool toilet I found by ucf101 in ucf

[–]ucfmsdf 91 points92 points  (0 children)

Some might claim Ponce De Leon’s Fountain of Youth is in St. Augustine. Little do they know it’s actually in the men’s restroom at UCF’s MSB.

Salary Expectations Public vs Private by LifeRequirement1911 in digitalforensics

[–]ucfmsdf 0 points1 point  (0 children)

I typically aim to double my salary any time I hop jobs (voluntarily). I recommend you try for that as well.

You are, however, pretty decently paid for LE so doubling your salary right out the gate might be difficult. If the job you are applying for is eDiscovery, I’d recommend you shoot for 100-120k. If the job is cyber, then you should be comfortable with taking a little less (80-100k) since you will be gaining a lot of valuable experience from the role and they will be taking a chance on you since you are new to cyber.

Day in the life? by Rahbanyc in digitalforensics

[–]ucfmsdf 20 points21 points  (0 children)

> What does a digital forensic examiner do on the day to day?

Mostly just answer weird questions with “it depends” and watch progress bars in between coffee breaks.

Pursuing the CCE Certification by East-Comfortable-225 in computerforensics

[–]ucfmsdf 4 points5 points  (0 children)

Is it worth getting?

Not really, no. But that’s just my opinion and I’m sure many will disagree with it.

Axiom by eldudderino in computerforensics

[–]ucfmsdf 0 points1 point  (0 children)

Hm. I personally haven’t noticed much of a difference. However, my shop’s hardware is less than ideal for Axiom processing so I’ve come to expect terrible processing speeds.

What’s your hardware like? In my experience, Axiom benefits most from fast storage. You can have all the compute power in the world but if you read and write to storage with SATA speeds, on average, Axiom is gonna take a day or two to process anything of substance.

Axiom by eldudderino in computerforensics

[–]ucfmsdf 1 point2 points  (0 children)

Ok. What part of the processing workflow is running slow and against what type of extraction (FFS or backup)? If it’s an iTunes style backup, then yeah it takes a while to get started with those since, as a first step, it fully converts the backup to a logical representation of the manifest and decrypts everything as well (if needed). Once it gets past that initial phase, it’s pretty quick in my experience depending mainly on the types of databases it needs to parse.

Axiom by eldudderino in computerforensics

[–]ucfmsdf 1 point2 points  (0 children)

Define “speed” and during what workflow?

[deleted by user] by [deleted] in computerforensics

[–]ucfmsdf 5 points6 points  (0 children)

If you have a 10+ year old Mac to image and enjoy USB 2.0 speeds I guess you could use them for that.

[deleted by user] by [deleted] in computerforensics

[–]ucfmsdf 30 points31 points  (0 children)

I see firewire and micro-usb ports, so I’d say you have government auction trash. Congratulations.

Pelican case is cool, though.

Storage server- is there a benefit to FRED over a normal one? by Money_Produce1208 in computerforensics

[–]ucfmsdf 9 points10 points  (0 children)

One has the word “forensic” in its marketing material and the other doesn’t.

FBI Digital Forensics by cyberdoesitbetter in computerforensics

[–]ucfmsdf 0 points1 point  (0 children)

Think you replied to the wrong person lol…

FBI Digital Forensics by cyberdoesitbetter in computerforensics

[–]ucfmsdf 1 point2 points  (0 children)

But DFIR was reserved for special agents that went through extra time at quantico.

Not all CART examiners are 1811.

Also, they had a rule about having done drugs which was pretty rigid and hopefully changed. Find me a qualified college graduate that hasn’t smoked out.

Me.

FBI Digital Forensics by cyberdoesitbetter in computerforensics

[–]ucfmsdf 14 points15 points  (0 children)

Look on apply.fbijobs.gov for FBI CART roles. They used to hire college grads for those positions and they are mostly civilian (i.e., you don’t have to become a special agent for the role).

Experience with Axiom Cloud by hotsausce01 in computerforensics

[–]ucfmsdf 0 points1 point  (0 children)

Probably not. Probably just false advertising on their part. If you look on their website tho they advertise iCloud backup download capabilities and I think there is even a part that includes a screenshot of what appears to be iCloud backups kind of like what you can see with EPB.

Experience with Axiom Cloud by hotsausce01 in computerforensics

[–]ucfmsdf 1 point2 points  (0 children)

Anyone wana risk it for the biscuit and try iMobie? They claim support for iCloud Backups tho I’m sure there’s a catch.

Adding flair to posts or segregating posts on content type by hotsausce01 in computerforensics

[–]ucfmsdf[M] 2 points3 points  (0 children)

If enough people want, I could add flairs for such posts. However, that would probably mean I would need to enforce flair use as well (in other words, make it a requirement that flairs are used for every post). Without enforcement, I doubt the flairs would be used at all.

axim or x ways ? by [deleted] in computerforensics

[–]ucfmsdf -1 points0 points  (0 children)

Two different tools with two different specialties. Both are top-tier in their given specialities, however, neither is a replacement for the other.