Hex dump search tips

When you’re searching for anything (and let’s face it, it’s normally a set of keys isn’t it?!), it always helps to know what you’re looking for. That sounds pretty obvious but it’s very relevant for forensic examiners searching large volumes of data. For example, finding SMS messages in a hex dump of some Samsung handsets is a whole lot easier once you know that the keyword “DEADBEEF” appears within the memory dump in between SMS messages. Suddenly, finding deleted text messages got a whole lot easier!!

One question which often crops up during training courses and conference presentations is, “Where can I go to find out what these search terms and keywords are?”. Up until now, there hasn’t been a good answer to that question which is why we are now providing a page on the Control-F website to help people like yourselves find evidence more quickly.

The new page provides information on key types of data that you might want to search a memory dump for (e.g. ICCIDs, MMS messages etc.) along with different encoding schemes that we’ve encountered and search terms or regular expressions to save you time.

We hope that you find it useful and would love to hear your feedback (and receive contributions!). We use Gary Kessler’s file signature page all of the time and if this page becomes half as useful, we’ll be delighted.

Phone Forensics Deconstructed

TURN DATA INTO EVIDENCE

This 3 day ‘next level’ mobile phone forensics course is designed to give phone examiners a greater understanding of the data they already retrieve, coupled with the skills to find and recover traces of the ever increasing Internet browsing, social networking and satnav usage with mobile phones. Find out more…

Memory Card Forensics Course

RETRIEVING DELETED DATA FROM MOBILE PHONE MEMORY CARDS

Running again 22-24 November 2010, this course is designed to teach mobile phone examiners how to retrieve deleted data from memory cards whilst ensuring compliance with the ACPO Principles of Digital Computer Based Evidence.  Without proper training and equipment this critical evidence could be overlooked.  Find out more …..

White Paper on Handset Imaging

Download our free white paper on recovering deleted data from specific phones – Kevin Mansell collaborated with Royal Military Police’s digital forensics unit in Portsmouth to publish a white paper for the F3 Annual Conference 11-13 November 2008. Titled ‘Recovering Deleted Data from FAT Partitions Within Mobile Phone Handsets Using Traditional Imaging’ the paper explores how deleted and unallocated data can quickly and easily be retrieved from the internal memory of certain handsets using easily accessible data cables and computer forensic imaging tools.