R Hegarty
SlackStick : signature-based file identification for live digital forensics examinations
Hegarty, R; Haggerty, J
Authors
J Haggerty
Abstract
A digital forensics investigation may involve procedures for both live forensics and for gathering evidence from a device in a forensics laboratory. Due to the focus on capturing volatile data during a live forensics investigation, tools have been developed that are aimed at capturing specific data surrounding state information. However, there may be circumstances whereby non-volatile data analysis, such as the identification of files of interest, is also required. In such an investigation, the ability to use file-wise, or hash, signatures is precluded due to pre-processing requirements by the forensics tools. Therefore, this paper presents SlackStick, a novel automated approach run from a USB memory device for the identification of files of interest or non-volatile evidence triage using an alternative signature scheme. Moreover, the approach may be used by inexpert users during a first-response phase of an investigation. The results of the case study presented in this paper demonstrate the applicability of the approach.
Citation
Hegarty, R., & Haggerty, J. (2015, September). SlackStick : signature-based file identification for live digital forensics examinations. Presented at 2015 European Intelligence and Security Informatics Conference, Manchester, UK
Presentation Conference Type | Other |
---|---|
Conference Name | 2015 European Intelligence and Security Informatics Conference |
Conference Location | Manchester, UK |
Start Date | Sep 7, 2015 |
End Date | Sep 9, 2015 |
Acceptance Date | Jun 24, 2015 |
Online Publication Date | Jan 14, 2016 |
Publication Date | Jan 14, 2016 |
Deposit Date | Feb 3, 2020 |
Book Title | 2015 European Intelligence and Security Informatics Conference |
ISBN | 9781479986576 |
DOI | https://doi.org/10.1109/EISIC.2015.28 |
Publisher URL | https://doi.org/10.1109/EISIC.2015.28 |
Related Public URLs | http://www.eisic.eu/eisic2015/ |
Additional Information | Event Type : Conference |
Downloadable Citations
About USIR
Administrator e-mail: library-research@salford.ac.uk
This application uses the following open-source libraries:
SheetJS Community Edition
Apache License Version 2.0 (http://www.apache.org/licenses/)
PDF.js
Apache License Version 2.0 (http://www.apache.org/licenses/)
Font Awesome
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2025
Advanced Search