A look at decaf antiforensics anti-cofee tool
praetorianprefect.com
A look at decaf antiforensics anti-cofee tool
1–4 of 4 posts
Re: A look at decaf antiforensics anti-cofee tool
#2Re: A look at decaf antiforensics anti-cofee tool
#3This problem is isomorphic to the antivirus problem. You can't even trust the memory controller to tell you the truth about live memory contents. When you compare Decaf to, say, a modern rootkit, it's apparent how superficial this forensics conflict really is.
Not sure I approve of antiforensics because I suspect COFEE could help convict a lot of criminals. On the other hand it seems an invasion of privacy and the US 5th Amendment IMO.
Re: A look at decaf antiforensics anti-cofee tool
#4Unfortunately when a tool like COFEE that is inserted into the machine on USB, whilst it's running, cracking the password as it's inserted, it would access the RAM on the machine when it got inserted. Which can be construed as Data Tampering as it would have to Read & Write Data from the Hard-Disk!
By reading and writing to the Suspects computer via a USB device it paves the possibility of a rouge application spreading via the USB. How can anyone determine the effects of COFEE if it is closed source and distributes in the marvelous Self *.exe'cuting Binary .Win32 format?
In Forensics, you read and reconstruct the Data from a Disk-Image of the HDD or in the Case of a USB device you would Extract the Data from Thumbs.db which is a hidden file on any Fat16 formatted USB Pen. Only the accepted norm is you do not tamper with the Data in anyway by allowing your machine to Write to it!