The Forensic Scooter
This blog was started by Scott Koenig as a place to post and manage some of his digital forensic research.
This is a personal blog. Any views or opinions represented in this blog are personal and belong solely to the blog owner and do not represent those of people, institutions, or organizations that the owner may or may not be associated with in professional or personal capacity, unless explicitly stated.
Additional resources can be found on his GitHub.
Latest from the Blog
As I stated in the future considerations section of the original research write-up, I contacted a few vehicle forensics experts and asked if they would like to assist me with some research and testing, they responded “Absolutely.” During a training event, the experts and I conducted a small test. Forensic Question During the test, IContinue reading “Vehicle and iPhone Speed Comparison”
As many of you are aware, I recently updated my Photos.sqlite queries. Since releasing the different query iterations, I have received several questions about how I was able to decode the data included in the queries. That’s a great question! I also noticed several questions being posted to the listservs and DFIR Discord about theContinue reading “Photos.sqlite Query Documentation & Notable Artifacts”
I would like to start off by saying thank you to everyone who has reached out about the Photos.sqlite queries I previously posted. After chatting with some people who have used the queries, it was suggested that I update the queries to include the following: Restructuring the query output Renaming and clarifying the column namesContinue reading “Photos.Sqlite Queries – Update”
Get new content delivered directly to your inbox.