OS X Forensics Blog

OS X and iOS Forensics Blog

  • Recommended Mac/iOS Tools
  • Recommended Training
  • Conferences
  • Publications
  • About
Posted by osxforensics on February 18, 2014
Posted in: iPhone Forensics. Leave a comment

Things are beginning to wind down after a long 6 months of development,  of which  Lantern 4 will come out soon.  Lots of great things ahead for Katana not just Lantern 4, but a host of new exciting products to help investigators and examiners

Back from a Long Haidas

Posted by osxforensics on February 18, 2014
Posted in: iPhone Forensics. Leave a comment

Things are beginning to wind down after a long 6 months of development and Lantern 4 will soon come out.  Lots if great things ahead for Katana not just Lantern 4 but a host of new exciting products to help investigators and examiners

Free iOS Imager

Posted by osxforensics on December 22, 2011
Posted in: iPhone, iPhone Forensics. Tagged: iPhoen Forensics. Leave a comment

Katana Forensics now has a Law Enforcement Version and a public Version of Lantern Lite – “The iOS Physical Imager”  Now everyone has the capacity to image iOS Devices.  All ranges of Forensics and Security have the ability to analyze these devices.  See the details at http://www.katanaforensics.com.

 

Survey – Which Device do you encounter more in your labs?

Posted by osxforensics on November 23, 2011
Posted in: iPad, iPhone, iPhone Forensics, Security. Tagged: Forensics, iPad, iPhone, iPhone Forensics. Leave a comment

The Cheapest Tool for iOS Just Got Cheaper!!

Posted by osxforensics on November 23, 2011
Posted in: iPad, iPhone, iPhone Forensics. Tagged: iOS Forensics, iPhone Forensics. Leave a comment

Now in until Sat. Nov. 26, 2011 Katana Forensics is having a black Friday sale. 10% off on the popular Lantern iOS Forensic Software.  You’ll never see this offer again!!!  GET IT HERE  —>Katana Store

Time Converter

Posted by osxforensics on November 19, 2011
Posted in: Mac Forensics, Uncategorized. Tagged: Forensics, iOS Forensics. Leave a comment

Katana Forensics has updated its FREE time converter application.  This time it converts Mac Absolute Time and Unix Epoch Time.  Most can’t distinguish which is which.  This updated app already knows and converts the values on the fly.  Just copy and paste. Visit http://www.katanaforensics.com and get the FREE application.  Another tool for your war chest.

New Free iOS Imager “Lantern Lite”

Posted by osxforensics on November 19, 2011
Posted in: iPad, iPhone, iPhone Forensics, Security, Uncategorized. Tagged: Forensics, iOS Forensics, iPad, iPhone. Leave a comment

Lantern Lite, the open source project has taken its first step.  It was released to Law Enforcement.  After some modifications and improvements, the utility will be released to the public.  Security professionals will finally have access to a free tool to examine  iDevices.

This is meant for all that do forensics, and keeping it free and away from forensic tool makers that can’t innovate, just copy.  The days of paying to image an iDevice is over.  It is parsing the data where one uses grey matter.

Further information can be seen at www.lanternlite.org

Using a Lantern Acquisition in Windows

Posted by osxforensics on June 6, 2011
Posted in: iPhone, iPhone Forensics, Mac Forensics. Tagged: Forensics, iOS Forensics, iPad, iPhone, iPhone Forensics, Lantern 2.0. Leave a comment

My good friend Shafik Punja asked “Remember how you showed me to take a Lantern case file and bring it into Encase?”  I responded that I did remember showing him how to do it. Shafik he asked me to place this blog so that others can benefit from this as well.  So here it is using a case folder using the new Lantern 2.  This will also work using FTK.  Unfortunately I do not have FTK running in my VM, so this method can also work the same way.  For this demonstration I am using Parallels.  Just like it better now, but again, if you have VMware Fusion, this will work also.

1. Acquire an iDevice using Lantern.

2.  Start you Windows virtual machine

3. Depending on your VM software, set up file sharing

4. Copy the Lantern case file (the icon that looks like a briefcase) and bring it into Windows.  As you see in the following figure, the case file looks like a file folder.  The Lantern case file in 2.0 is an Apple/Mac package.  Basically a folder.  Windows 7 sees this package as a folder.

5. Open You windows base forensic tool, in this demonstration open Encase and create a case.

6. Then just drag and drop the Lantern folder into Encase as seen below,

7. Then you can run whatever process you care to do at this time.  It is just that simple!

For older Lantern version 1 case files.  It is essential a Zip file.  Just unzip the files and bring them into Encase or FTK using the same method as described above.  If you have any questions drop me an email.  info@katanaforensics.com

Imaging a MacBook Air with Free Tools

Posted by osxforensics on May 7, 2011
Posted in: Mac Forensics. Tagged: Mac Forensics, MacBook Air. Leave a comment

Here is a short PDF on imaging the MacBook Air wth WinFE+FTK Imager

Imaging a MacBook Air

COURT SUPPRESSES EVIDENCE FOUND DURING CARETAKING SEARCH OF CELL PHONE

Posted by osxforensics on April 26, 2011
Posted in: Mobile Forensics. Tagged: Mobile Forenscsi. Leave a comment

Interesting read,

http://www.llrmi.com/articles/legal_update/2011_co_schutter.shtml

Posts navigation

← Older Entries
  • Blogroll

    • Cyber Crime 101
    • CyberSpeak
    • Forensic 4cast
    • Paradigm Solution's Blog
    • SANS Computer Forensic and Incident Response
  • Recent Posts

    • (no title)
    • Back from a Long Haidas
    • Free iOS Imager
    • Survey – Which Device do you encounter more in your labs?
    • The Cheapest Tool for iOS Just Got Cheaper!!
  • Twitter

    • Leaving twitter for Parler. Can’t support censorship. #LeaveTwitter 3 months ago
    • RT @MarshaBlackburn: Another “whistleblower?” 5 months ago
    • Pretty much impossible. Having done cell phone forensics for over 2 decades. And the improbable “I forgot my passwo… twitter.com/i/web/status/1… 5 months ago
    • What an NFL game? They all can kiss my @ss twitter.com/atensnut/statu… 5 months ago
    • Texans' JJ Watt calls booing during moment of unity 'unfortunate' foxnews.com/sports/texans-… I really don’t care. Did… twitter.com/i/web/status/1… 5 months ago
Blog at WordPress.com.
OS X Forensics Blog
Blog at WordPress.com.
Cancel

 
Loading Comments...
Comment
    ×