Julita RubackaDigital Forensics & Evidence

Experience

Three years of evidence work, done by the book.

Individual matters stay confidential. What follows describes the kind of work I carried out in a government digital forensics unit, not specific cases.

Mobile devices

Phone examinations

Acquisitions of phones with Cellebrite UFED, MSAB XRY and MOBILedit. Recovery and review of messages, call logs, contacts, media and app data, including deleted content where the device allowed it.

Storage media

Forensic imaging

Forensic images of computer drives and external media with FTK Imager, verified by hash, then processed and reviewed in Magnet AXIOM.

Triage

Finding the few items that matter

Filtering large volumes of data by dates, file types and keywords, and correlating sources to give investigators clear leads.

Applications

Looking inside apps

Examining Android applications in a controlled emulator, observing their network traffic in Wireshark and reviewing their code when an app behaved differently than it looked.

Reporting

Reports investigators can use

Technical and analytical reports that explain what was found, how, and how certain it is, written for people who are not forensic specialists.

Handling

Chain of custody, every time

Documented handling of every exhibit and secure treatment of sensitive information, in a regulated government environment.

Have a device that needs to talk?

Confidential contact