Forensic Lab Setup
Forensic Lab Setup
What is a Lab
Things to Consider
Workstations
Hardware Write Protection
Software
Training
Tool Kits
The Computer Forensics
Lab
Forensic-Computers.com
The Computer Forensics Lab
Forensic-Computers.com
Things To Consider
“Investigative Needs”
The facility or room you have for your lab may be out of your
control.
The size of the lab should be major factor in the planning of
furniture and how many systems you put in it.
If you have a closet for a lab, you will be limited if not crippled.
Do not forget to have a place to secure the original evidence.
Climate control (Heating & Air Conditioning)
Proper lighting
Does the lab have enough power for all you want to install?
Do not forget to plan for growth.
Workstations
Forensic-Computers.com
Critical Hardware Choices
One major decision point is whether to roll your own or purchase
complete systems.
Self-Built Forensic Systems
Great to do to learn hardware.
Initial purchase can be less expensive.
Investigator/Examiner must decide what parts to order.
Investigator/Examiner must integrate components from various suppliers
and maintain purchase records in the event of product failure.
Investigator/Examiner is then responsible for all troubleshooting and repair.
The investment of time can be substantial which means a loss of investigative
time.
Commercially Purchased Forensic Systems
Vendor does all integrating and testing.
Vendor is responsible for warranty issues when problems occur and they will.
System arrives ready for use.
Investigator/Examiner can begin validation testing and investigating.
Building Your Own
At the end of the day you want systems that will do the job.
How fast the job gets done will in part depend on your budget.
Is the system configured to accept the media routinely received
in a investigation?
Is the hardware easy to use?
Do you need portable forensic systems?
Portable Workstations
Portables come in a verity of shapes and
sizes.
Some are built specifically for mobile
forensics.
Laptops can work well as long as you test
before you buy or buy from a forensics
company that has tested them.
The portable solution you choose should
give you the same basic capabilities as you
lab systems.
Hardware Write Protection
Forensic-Computers.com
Hardware Write Protection
Regardless which brand you choose you must run them through your
own validation testing.
A write blocker from one company (not Tableau) can be converted to
READ WRITE if the user downloaded a firmware update and applied
it. This could be bad for you case……
Just because a company makes write blockers does not mean
everything they make is write protected.
IF IN DOUBT – ASK……..
Forensic Software & Training
Forensic-Computers.com
Forensic Software
AccessData – Windows based Forensic Tool Kit and the Ultimate Tool Kit
http://www.acessdata.com
ASRData – Linux based SMART
http://www.asrdata.com
Blackbag Technologies – Mac OS X based Macintosh Forensic Suite and
MacQuisition Boot disk
http://www.blackbagtech.com
Guidance Software – Windows based EnCase
http://www.encase.com
SubRosaSoft – Mac OS X, Linux and Windows based MacForensicsLab
http://www.macforensicslab.com
Paraben – Windows based hard disk, PDA, and cell phone forensics
software and hardware
http://www.paraben.com
Technology Pathways – Windows based ProDiscover family of forensic and
security software
http://www.techpathways.com
Forensic Software
There are other forensic packages out there that will the job and
some of them are free or low cost:
Autopsy and Sleuth Kit (no cost)
Technology Pathways – ProDiscover Basic is free and they have a U3
version the runs from a USB Thumb Drive
WinHex – an excellent Hex editor also has a forensics package
Unix, Linux, and Mac OS X all have utilities included that work very well
for forensics (dd, netcat, cryptcat, grep, strings, etc.)
There are also a number of “Live” or Bootable CDROMS that have been
built by forensic investigators like Helix that are no cost.
Forensics Training
Greg Dominguez
Vice President
Forensic Computers
540-726-9530
[email protected]