• Forensics StartMe Updates (12/1/2023)

    By Kevin Pagano
    Shortlink: startme.stark4n6.comQR Code:If people have suggestions for additions please feel free to shoot me a message on the app formerly known as Twitter (@KevinPagano3) or Mastodon.Blog FeedAbhiram's BlogBlue Crew ForensicsFancy ForensicsiOS Unified Logs - Lionel NotariJosh LemonRevo4n6Forensic ToolsBelkasoft T (Triage)EventTranscriptParserEvanole - HexordiaTeraLogger - A Teracopy history log parserMemory / RAM ToolsFOR532 -... [Read More]
  • Cellebrite CTF 2023 - Felix

    By Kevin Pagano
    Previous: AbeRound 2 goes to Felix (not the cat as seen above 😂) as part of the Cellebrite CTF 2023. We get another iPhone image to analyze.Evidence Download: Felix | Official Cellebrite WriteupFelix 01 - Voicemail 📼 (10 points)Felix received a voicemail from +1-416-435-5684. How many seconds in length was the voicemail... [Read More]
  • Cellebrite CTF 2023 - Abe

    By Kevin Pagano
     After a year hiatus Cellebrite was back in full force with another lengthy CTF challenge. This year featured 4 different phones, 2 iPhones and 2 Android devices.Challenge details can be found on Cellebrite's blog. We are going to start with Abe since in my opinion was the easiest of the... [Read More]
  • Introducing TeraLogger

    By Kevin Pagano
    As a preface, I created a 3 part blog series on TeraCopy logs and parsing them so you may want to read those first to understand the underlying files and queries.Part 1 | Part 2 | Part 3I had a case recently where I used SQLECmd (via KAPE) to parse... [Read More]
  • Cyber5W's CCDFA Certification - A Review

    By Kevin Pagano
    As part of winning the Magnet CTF from 2022 I was gifted a coupon to take the Cyber5W Digital Forensic Analyst course on-demand. It only too me over a year to actually get time to plug away at the training and to actually finish it with work and life happening.... [Read More]