New
#1
Hackers Brew Self-Destruct Code to Counter Police Foren
Hackers have released an application designed to thwart a Microsoft-packaged forensic toolkit used by law enforcement agencies to examine a suspect’s hard drive during a raid.
The hacker tool, dubbed Decaf is designed to counteract the Computer Online Forensic Evidence Extractor, aka COFEE. The latter is a suite of 150 bundled, off-the-shelf forensic tools that run from a script. Microsoft combined the programs into a portable tool that can be used by law enforcement agents in the field before they bring a computer back to their forensic lab. The script runs on a USB stick that agents plug into the machine.
The tools scan files and gather information about activities performed on the machine, such as where the user surfed on the internet or what files were downloaded.
Someone submitted the COFEE suite to the whistleblower site Cryptomelast month, prompting Microsoft lawyers to issue a take-down notice to the site. The tool was also being distributed through the Bit Torrent file sharing network.
This week two unnamed hackersreleased decaf, an application that monitors a computer for any signs that COFEE is operating on the machine
More..............Hackers Brew Self-Destruct Code to Counter Police Forensics | Threat Level | Wired.com