wazeforensics.blogspot.com
Waze Forensics : January 2014
http://wazeforensics.blogspot.com/2014_01_01_archive.html
A Digital Forensic Capstone Research Project. Wednesday, January 22, 2014. From a first glance, Waze, now owned by Google (isn’t everything? Here is a list of some of the other features that are available on the Waze App. Pick Up (allows a user to text or email another Wazer their location to get “picked up”). Save Parking Location (friends on Waze can see where you parked). Link to Facebook, Twitter, and FourSquare. Drive Sharing (watching other Waze Friends drive to a location). To an average user.
lahaie4n6.blogspot.com
Under the Hill Forensics: January 2014
http://lahaie4n6.blogspot.com/2014_01_01_archive.html
Under the Hill Forensics. A blog about my capstone and my life as a forensicator. And no, I do not live in the Shire with Bilbo Baggins. Monday, January 20, 2014. IDrive Forensics: Up in the Clouds. Welcome to my first blog post for my Capstone project! I will be doing my Capstone on a cloud service called IDrive. Before I start with what I am doing, let me introduce myself. My name is Colby Lahaie. And I am currently a senior attending Champlain College. In the Computer and Digital Forensics. For this p...
lahaie4n6.blogspot.com
Under the Hill Forensics: Hidden Behind the Cumulonimbus Part 2A
http://lahaie4n6.blogspot.com/2014/04/the-cloud-continues-to-dissipate.html
Under the Hill Forensics. A blog about my capstone and my life as a forensicator. And no, I do not live in the Shire with Bilbo Baggins. Sunday, April 13, 2014. Hidden Behind the Cumulonimbus Part 2A. This is part two of "Hidden Behind the Cumulonimbus Part. Blog post. This blog continues to cover the IDTEMP folder. Delete and Archive Cleanup Files. After deleting files within IDrive there is one additional file created in the IDTEMP folder. This files is called “Delete.txt”. This file is similar to the ...
lahaie4n6.blogspot.com
Under the Hill Forensics: March 2014
http://lahaie4n6.blogspot.com/2014_03_01_archive.html
Under the Hill Forensics. A blog about my capstone and my life as a forensicator. And no, I do not live in the Shire with Bilbo Baggins. Friday, March 21, 2014. Hidden Behind the Cumulonimbus. After conducting some additional analyses, I have found a very important folder. I found this folder located at: C: Users Capstone PC AppData Local IDrive. This folder is called IDTEMP. However, after searching through the RAM image, with WinHex, which I dumped with DumpIt, I found an entry pointing to this folder.
lahaie4n6.blogspot.com
Under the Hill Forensics: Hidden Behind the Cumulonimbus Part 2
http://lahaie4n6.blogspot.com/2014/04/the-cloud-begins-to-dissipate.html
Under the Hill Forensics. A blog about my capstone and my life as a forensicator. And no, I do not live in the Shire with Bilbo Baggins. Sunday, April 13, 2014. Hidden Behind the Cumulonimbus Part 2. I have been very busy over the past few weeks trying to finish analyzing my data and finalizing my capstone paper. This blog post is a continuation of the previous and will consist of 2 parts because there is a lot of data that I would like to present to my fellow investigators. Within this file, an investig...
lahaie4n6.blogspot.com
Under the Hill Forensics: Not a Cloud in the Sky
http://lahaie4n6.blogspot.com/2014/04/not-cloud-in-sky_16.html
Under the Hill Forensics. A blog about my capstone and my life as a forensicator. And no, I do not live in the Shire with Bilbo Baggins. Wednesday, April 16, 2014. Not a Cloud in the Sky. This is my last blog post for my Capstone and will detail my conclusion for my findings. After conducting this forensic analysis of the IDrive Windows application, the investigator found that the data is stored in two default locations, which are: “ C: Program Files (x86) IDriveWindows. Furthermore, if a user shares fil...
lahaie4n6.blogspot.com
Under the Hill Forensics: The Cloud Begins to Dissipate
http://lahaie4n6.blogspot.com/2014/04/the-cloud-begins-to-dissipate_16.html
Under the Hill Forensics. A blog about my capstone and my life as a forensicator. And no, I do not live in the Shire with Bilbo Baggins. Wednesday, April 16, 2014. The Cloud Begins to Dissipate. In this blog post I will be talking about the local database file and the Session files. After a backup has completed within IDrive, a local SQLite 3 database file is create. This file is located: C: Users Username AppData Local IDrive IBCOMMON idriveusername LDBNEW. Number (DIRID), the file. The “Backup...
lahaie4n6.blogspot.com
Under the Hill Forensics: April 2014
http://lahaie4n6.blogspot.com/2014_04_01_archive.html
Under the Hill Forensics. A blog about my capstone and my life as a forensicator. And no, I do not live in the Shire with Bilbo Baggins. Wednesday, April 16, 2014. Not a Cloud in the Sky. This is my last blog post for my Capstone and will detail my conclusion for my findings. After conducting this forensic analysis of the IDrive Windows application, the investigator found that the data is stored in two default locations, which are: “ C: Program Files (x86) IDriveWindows. Furthermore, if a user shares fil...
wazeforensics.blogspot.com
Waze Forensics : March 2014
http://wazeforensics.blogspot.com/2014_03_01_archive.html
A Digital Forensic Capstone Research Project. Wednesday, March 12, 2014. Progress Update and Log File Analysis. This blog post will consist of general updates to the progress of my project as well as some interesting artifacts I found in one particular log file. Was not where I was expecting it to be. My project has branched out into three main categories of analysis and examination. The categories are the following:. Android memory analysis using LiME and Volatility. Waze Direct Messages from Memory Dump.