Better biz models needed for sustainability http://t.co/B5DebtKB http://t.co/erFSwAUB #arcavir
4 minutes ago by V_RaV on twitterZDNet is available in the following editions:
By tapping on Microsoft's Computer Online Forensic Evidence Extractor, Hong Kong police deploy fewer technical experts when gathering PC evidence at crime scenes.
A police officer arrives at the scene of a murder, plugs a thumbdrive into a computer that is still running, and executes some 150 evidence-gathering commands within 15 minutes. A scene from CSI? Not necessarily.
The Hong Kong Police Force's technology crime division is one of many law enforcement departments around the world involved in the testing of Computer Online Forensic Evidence Extractor (Cofee), a free tool from Microsoft which can be loaded onto a portable device such as a USB drive.
Cofee, a program that automates some 150 evidence-gathering commands for computers, was released earlier this year in beta version. Available only to law enforcement agencies, the tool was the brainchild of Anthony Fung, Microsoft's senior regional manager for Internet safety and anti-counterfeiting in the Asia-Pacific region.
Paul Jackson, chief inspector, computer forensics and training, Technology Crime Division, Hong Kong Police Force, told ZDNet Asia Thursday that Cofee is "one of many tools" the force uses to investigate a variety of online crimes and to recover digital evidence.
Data recovered from "live", or running, systems at the scene of a crime have proven to be invaluable in analyzing cases, he said in an e-mail interview.
"Before Cofee was available, similar evidence-gathering functions needed to be carried out using a wider variety of tools," noted Jackson. "Cofee neatly packages these capabilities into one tool which can be swiftly and efficiently deployed--even by non-expert investigators."
According to Jackson, 44 officers in the technology crime division, which falls under the Hong Kong Police's Commercial Crime Bureau, use the tool. Initial usage of the beta software has been in "incidence response" situations, he added, but declined to provide further detail on the nature of the cases.
Cofee, however, is designed to extract information from Windows-based systems. For Linux machines, the Hong Kong Police uses several tools or scripts to collect similar data, which have to be executed by a specialist, said Jackson.
And as the application is still in beta, the investigators do not depend solely on Cofee but also use other tools for validation, noted Jackson.
In an interview with ZDNet Asia last week in Singapore, Microsoft's Fung said law enforcement agencies typically faced challenges in handling computers at the crime scenes, largely due to expensive equipment and lack of trained or expert resources. Hong Kong-based Fung was in the island-state to attend the 13th Annual Conference and General Meeting of the International Association of Prosecutors.
With Cofee, an officer with "no or basic training" can preserve the data in about 15 minutes, and maintain its integrity such that it can be brought back to the forensic labs for analysis, said Fung. In the past, it would take a forensic scientist about three hours to manually execute the commands.
Cofee is based on existing extraction tools, he added. Some of the automated commands include recording the login credentials, providing details of the applications and processes executed at that time, and logging system-to-server communication.
Fung, a former police officer specializing in solving computer-related crimes--having spent 13 years with the Hong Kong Police prior to Microsoft--developed the tool based on his experience in law enforcement and in consultation with police officers in the field. The tool was created by both in-house and external coders.
The software, however, is meant to complement existing tools and is not a silver bullet, stressed Fung. "In fact, in the computer forensics industry, there is no one single tool--[whether available] commercially or through open source code--that can solve all the problems."
According to Fung, the beta phase has closed and Microsoft will issue the release edition "once the legal logistics are complete". The official release does not include support for Windows Vista, but a second version that will come shortly would.
Better biz models needed for sustainability http://t.co/B5DebtKB http://t.co/erFSwAUB #arcavir
4 minutes ago by V_RaV on twitterhttp://t.co/VNaUVSe1 Better biz models needed for sustainability: Companies now see sustaina... http://t.co/i0P8D1Fw http://t.co/wiqTBKkj
4 minutes ago by RavtachSolution on twitterPacnet CEO departs; acquisition rumors gain #steam http://t.co/QSCFfCcy
19 minutes ago by SuperGamePower on twitter5 SaaS adoption speed bumps to avoid http://t.co/AJQYAkOh via @zdnetasia
19 minutes ago by pmarini on twitterRT @SecMash: #InfoSec Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/vFzACdwm #CyberSecurity
19 minutes ago by suhnylla on twitterExperience trumps content in apps monetization http://t.co/MVPlf9gR
19 minutes ago by saffronistah on twitterBetter biz models needed for sustainability. http://t.co/tXuq7174
19 minutes ago by zdnetasia on twitterSudden departure of Pacnet CEO, no explanation - ZDNet Asia: Sudden departure of Pacnet CEO, no explanationZDNet... http://t.co/UVG3OKCG
34 minutes ago by NGTsummit_ASIA on twitter@ChemarieMonica : Malaysia organizations don't realize severity of cyberattacks - ZDN... http://t.co/iO8wdbz8 http://t.co/1QrdIsaV #tech
34 minutes ago by mcjimmm on twitterMalaysia organizations don't realize severity of cyberattacks. http://t.co/QK7PKdaP
49 minutes ago by zdnetasia on twitterRT @daryllau: Malaysia offers some manufacturing benefits over China http://t.co/mH23Uumr
49 minutes ago by nickstersss on twitterMalaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/HniF8J72 #news
49 minutes ago by Nathiet on twitter#InfoSec Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/vFzACdwm #CyberSecurity
1 hour ago by SecMash on twitterhttp://t.co/bTDnDh7J Malaysia organizations don't realize severity of cyberattacks - ZDNet Asi... http://t.co/CzsMF2zn #infosec #security
1 hour ago by CYSEC_COM on twitterMalaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizat... http://t.co/iUpDhbeU #cloud #fail #TCN
1 hour ago by Cloud_Fail on twitterSo much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...
1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoidI reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...
2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than socialThis video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...
2 days ago by TradeBrother on A quick fill handle trick for Microsoft Excelwaiting...
4 days ago by eapete on What should count in a company's market value?Boy, you've opened a can of worms now.
Wait for the rants & raves.
I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...
5 days ago by wykoong on Drop the egos, copy ideas, then innovateEchelon 2012 - The Awesomer Tech Event in Asia
Echelon 2012 – SEA’s longest running tech startup event goes Awesomer. Catch 50 of Asia’s most promising startups & over 40 international speakers on June 11-12.
Startup Asia Jakarta showcases new product-ready tech startups. Plus: hackathon, exhibition, and speakers. Use promo code CBSi50 for 50% discount.
ZDNet Asia Intelligent Singapore video series
Featuring inteviews with CXOs who define "intelligence" in their markets and reveal how their companies drive business efficiencies through ICT.
RAPIER
For those people not lucky enough to be on MSFT's special list to actually get their hands on COFEE, let me suggest you check out RAPIER - you can find it in googlecode.
Open source - does the same things as COFEE.