Showing posts with label DFIR. Show all posts
Showing posts with label DFIR. Show all posts

Saturday, December 3, 2022

Setting up a forensic workstation - Part II

In the last blog post, Setting up a forensic workstation - Part I, we set up and configured a Windows 10 Pro VM using VirtualBox. With this newly built virtual machine we will now setup and install some free forensic tools and applications needed to perform digital forensic investigations. My plan is to show new users they can accurately perform digital forensic investigations using free and open source tools. There is a time and a place for paid commercial tools in the digital forensic community - but you do not have to pay thousands of dollars to practice and learn the basics of digital forensics and incident response. So without further delay, let’s get started installing our forensic tools.

Thursday, December 1, 2022

Setting up a forensic workstation - Part I

In order to perform digital forensic investigations, it is important to have a workstation that has been previously set up, configured with your common forensic tools and scripts, and validated to ensure that everything is working as expected. Nothing is worse than responding to an incident and finding out that some tool you installed isn’t working because it is missing a dependency; Or the last update you ran accidentally broke some tool. Being prepared with a baseline system that has been tested and validated to work properly will alleviate these concerns.

Monday, November 28, 2022

First Blog Post…

    Hello, and welcome to the “Everything DFIR…” blog! My name is John Asmussen, and I am a digital forensics practitioner. A little background about myself - currently I am a criminal investigator with the Louisiana State Police and I have over 22 years of law enforcement service. For the past 15 years I have been assigned to the FBI New Orleans Division as a Task Force Officer, where I have investigated various types of cyber crimes ranging from Internet Crimes Against Children (ICAC), business email compromises (BEC’s), computer intrusions, ransomware and malware cases, theft of intellectual property, and sextortion cases. I have successfully completed numerous digital forensic courses and hold several digital forensic certifications including: GIAC Certified Forensic Examiner (GCFE), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), GIAC Battlefield Forensics Acquisition (GBFA), GIAC Advanced Smartphone Forensics (GASF), and many more. I have testified numerous times in criminal and civil cases and I have been certified as an expert witness in digital forensics in both the 4th and 6th Judicial Districts of Louisiana.