Ride the Lightning

Cybersecurity and Future of Law Practice Blog
by Sharon D. Nelson Esq., President of Sensei Enterprises, Inc.

Screencast Tool to Preserve Cyber Investigation Evidence

February 2, 2011

Ben Wright has an interesting post on the SANS blog about using a screencast tool to preserve cyber investigation evidence. The software he uses is BB Flashback. The neat part of his video showing the tool in use is that this is a great way to present the results of the investigation in court, having split screens showing both the investigator describing what he is doing while you can simultaneously watch his computer screen as he navigates the Internet.

Ben focuses more on the authentication of the investigation, which wasn't the part that interested me as much, though it is valuable. Still, the bar for authentication is very low (unless you're in Judge Grimm's court) in most places. Even though websites may change, investigators currently preserve the websites as they existed at the time of the investigation and get that evidence in without much problem. The compelling part is how easy it is to understand via the screenshots precisely what the investigator did. No matter how paitently an expert witness explains what he did, it is far easier to comprehend when you're watching it. Thought-provoking post Ben.

E-mail:        Phone: 703-359-0700

