DEF CON 32 - Curious Case of Alice&Bob: What You Can Do as Digital Investigators - Catherine Ullman

DEF CON 32 - Curious Case of Alice&Bob: What You Can Do as Digital Investigators - Catherine Ullman

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 53:54

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Digital forensics can only determine what happened on a system, not why someone did it—highlighting its limitation in establishing motive or intent. The investigation reveals that Charlie, not Alice, killed Bob due to drug-related activities, uncovered through timeline correlation, encrypted file analysis, and corroborating evidence from ring camera footage.

Key Takeaways:
• The investigative process begins with a scoping call to define objectives and gather initial information 11:15.
• Forensic data collection includes imaging devices, gathering logs, and using tools like FTK Imager and Axiom, with strict adherence to chain of custody 15:22.
• Data analysis reveals threatening SMS messages between Alice and Bob, but critical evidence—such as Bob’s encrypted file containing drug ledger details and Alice’s admission of logging in to Bob’s machine—points to Charlie as the suspect 28:00.
• Timeline analysis, using UTC timestamps and tools like Timeline Explorer, connects events showing Charlie entered Bob’s home before his death, supported by ring camera footage 32:00.
• Post-incident review emphasizes documentation, tool selection, and team collaboration to ensure transparency and accountability 45:37.

The case concludes that Charlie, not Alice, committed the murder due to drug-related activities, demonstrating how digital forensics, when properly applied, can resolve complex investigations.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

all right good afternoon everyone good afternoon welcome to Defcon welcome to Creator stage thank you for all being here um before we begin just a couple of quick notes uh number one that these talks are being recorded and also being streamed um as far we just got word that there is some technical difficulty with the slides on the Stream So we apologize for that um and yes these uh the video of the talks will be available uh eventually uh having done this for years usually around it could be really quick or it could be in September or October um for those of you this is if this is your first Defcon welcome welcome enjoy and um for this talk it is proudly presented uh by the packet hacking Village and it is my pleasure to introduce to you someone we consider a friend for years she is the au…