Deep Dive on Portable Case Part One

One of the most important parts of the forensic process is reporting and collaborating on findings. Magnet Forensics has built Portable Case, a feature of Magnet AXIOM and Magnet IEF to help foster that collaboration and make it more integrated, and thus less painful.

Our Director of Forensics, Jessica Hyde, and our Forensic Consultant, Jamie McQuaid are taking an in-depth look at Portable Case to help our customers understand all the benefits and features.

In part one, Jessica gives an overview of Portable Case and its benefits.

Using Portable Case to Collaborate

Often during a digital forensic examination, it is necessary to collaborate on a case with other stakeholders.  This can include attorneys, other investigators, subject matter experts, translators, Human Resources, and clients. AXIOM allows the forensic examiner to collaborate in this way via Portable Case.

portable case 6

Sometimes sharing a report is not always the best way for a stakeholder to review data. Often you may have multiple people with differing expertise involved in a case.  By sharing a Portable Case, stakeholders can explore the evidence and add their own comments. The examiner can collaborate with the stakeholders and merge their feedback in the form of tags, comments and bookmarks back into the case.

The examiner has the option to create a portable case containing some or all the artifacts that have been parsed from the case. This allows the examiner to provide the stakeholders with the necessary portions of the case without overwhelming them if it is not necessary.

Workload management

If a case requires multiple examiners, you can pass a portable case to additional examiners.  This allows multiple examiners to provide feedback and merge comments.  Content review can be shared across a team and the results merged together. With portable case, you can create different content in different portable cases. For example: you can divide the case by type of content with one examiner looking at pictures and videos while another looks at the user’s emails and chats.

No additional license required

Portable case includes an executable so that your stakeholders can look at the case and navigate through the artifact data just as the examiner would and take advantage of the different views and filters. You can share the portable case without the need for an additional AXIOM license.

The portable case provides an easy interface for other examiners or stakeholders working on the investigation.  The primary difference is that they will not have access to the File System or Registry views. 

Comment, Tag, and Bookmark

Stakeholders and examiners that are reviewing evidence in portable case will be able to add bookmarks, tags, and comments.  Additionally, they can see any comments, tags, and bookmarks that were previously created for artifacts in the portable case and add their own thoughts and comments making for easy collaboration.

Merge feedback

Once the other stakeholders and/or examiners have added their own comments, tags, and bookmarks, they can be merged into the original case.  The examiner is then able to view the additional input provided by the stakeholders or users in the context of their current examination.

Relevant Evidence Compliance

Another area where Portable Case can be used is in jurisdictions where only relevant data may be kept, searched, and submitted in court.   Portable case allows for the separation of relevant from non-relevant information by filtering based on a warrant and creating a portable case.  The examiner can then work off the portable case and seal non-relevant data from what was originally collected in the seizure.

Wrapping it up

Regardless of your reason, the Portable Case export in AXIOM allows examiners to easily collaborate with others involved in an investigation.  This could include other examiners so that workload on large cases can be shared, sharing data with subject matter experts, or even a way to allow an attorney or client to view data and provide feedback via tags comments and bookmarks.  Everyone can now collaborate in a format that is easy to use.

Part Two

In part two of our Portable Case blog series, Jamie will guide users through a step by step in setting up and sharing a case. Check back in the coming week!

If you have any questions or comments, feel free to reach out:  jessica.hyde@magnetforensics.com.