RAM is King: Analyzing RAM in AXIOM and AXIOM Cyber
In business, there’s a famous adage, ‘cash is king’. When it comes to digital forensics, there’s a new adage, ‘RAM is king’.
In business, there’s a famous adage, ‘cash is king’. When it comes to digital forensics, there’s a new adage, ‘RAM is king’.
Across the board, businesses strive to establish repeatable processes so that they can replicate past successes and avoid repetitive tasks that eat up valuable time and effort. With the volume of incidents and time constraints on DFIR teams, identifying these opportunities and efficiencies is essential to managing an ever-growing caseload.
In Magnet AXIOM 6.3, we’ve continued to expand the incident response capabilities of AXIOM Cyber—further developing recently introduced features and adding new ones along the way. This release also introduces a new processing option that can expedite your investigations and help you get to your evidence faster.
Magnet AXIOM 6.3 is now available, offering you more control over evidence processing, so you can apply the appropriate collection method for the case at hand.
When the Find My app (creating Find My artifacts) was originally released by Apple in 2019, it was limited to locating user devices, but the app has since expanded to find more than just users’ devices. AirTag data, for example, is also included in the Find My app since they were released in 2021.
Processing evidence sources that contain terabytes of data and hundreds of thousands of artifacts is now a common and sometimes time-consuming process. Magnet AXIOM and Magnet AXIOM Cyber offer you more control over evidence processing by offering the option to process evidence with parsing-only and post-process carving—allowing you to apply the appropriate collection method for the investigation at hand.
We’re very excited to share some of the great new features in Magnet REVIEW 4.0—helping digital forensic examiners bring their investigators and the evidence they need together by enabling secure agency-wide collaboration anytime and from anywhere! With the ever-increasing volumes and complexity of data involved in the typical digital investigation today, delivering a truly modernized … Continued
It is no secret that Slack’s popularity has exploded in recent years- once dubbed “the email killer”, organizations have implemented Slack as an efficient collaboration environment either alongside email, and in some instances, replacing email as their primary internal communication mechanism. Although a large portion of communication and file transfers are taking place within Slack, often organizations are missing this crucial evidence during an investigation, either due to a lack of understanding or improper retention. Furthermore, organizations should be taking a proactive investigative approach and onboarding Slack as part of their insider threat program.
The June 2022 Magnet Forensics CTF was another exciting competition, and we’re happy to announce the winners!
To combat a Child Sexual Abuse Material (CSAM) case, an agency turned to Magnet GRAYKEY to process multiple smartphones. This case study details the events of their investigation and how GRAYKEY helped bring justice to the victims. Note: Due to the sensitivity of this case, and to respect the victims, this case study is anonymous.