About this talk
A suspect was linked to online financial fraud through ISP records. The user agent data suggested that the transactions had been performed from a Linux system. Yet when the computer was examined, only a Windows hard drive was present. The original forensic examination looked for familiar Windows artefacts, found nothing of value, and concluded that the computer could not have been used. But what if the most important evidence was not on the drive that was examined? This talk presents a real-world forensic case study of a missing Linux hard drive, a suspected dual-boot system, and the Windows registry artefacts that helped prove what had been removed. It is a technical walk-through of how forensic reconstruction can reveal the historical presence of storage devices, expose weak assumptions, and turn apparently absent evidence into a defensible conclusion. The presentation will show how careful analysis of Windows registry hives, storage artefacts, boot-related configuration, and physical indicators allowed the investigation to move from “there is no Linux drive” to “there was a Linux drive, it was used in this computer, and it appears to have been removed.” This is a talk about finding the evidence that someone hoped would stay hidden. About the Speaker - Jason Jordaan: Jason Jordaan is the Principal Forensic Scientist and Founder of DFIRLABS. As a recognised polymath, he is considered by his peers internationally to be a leading specialist in the fields of digital forensics, incident response, cybercrime investigations, and cybersecurity forensic engineering. He was one of the early pioneers in digital forensics in South Africa with his interest and activities in the field beginning in the mid 1990’s. Not only does Jason lead DFIRLABS, but he remains actively involved as a practitioner in these fields and regularly testifies as an expert witness in them. He founded DFIRLABS in 2014 after leaving the Special Investigating Unit, where he was the national head of the Cyber Forensic Laboratory. In this role, he was responsible for the development and implementation of the digital forensics capacity of the Special Investigating Unit, and in conducting digital forensics engagements on several high-profile cybercrime, fraud, and corruption cases in the South Africa public sector. Prior to joining the Special Investigating Unit in 1998, Jason served as a Detective in the South African Police Service Commercial Branch from 1992, where he conducted numerous white-collar crime investigations, with a focus on organised crime. Jason is an active researcher, academic, trainer, advisor and assessor in the international digital forensics and cybersecurity communities. He is a Principal Instructor with the internationally renowned SANS Institute. In this capacity he teaches digital forensics around the world, including to some of the leading international law enforcement, intelligence, and miliary units such as the Federal Bureau of Investigations, the US Secret Service, US Special Operations Command, Scotland Yard, the UK National Crime Agency, and many others. He also has provided digital forensics and incident response training to numerous companies in the Fortune 500 list. He is also as Assistant Professor at the SANS Technology Institute. He has also taught digital forensics at the University of Cape Town, the University of Pretoria, and Rhodes University. He currently serves on the SANS Advisory Board and on the Advisory Board of the Department of Computer Science of the University of Pretoria. He also served on the expert advisory panel for the South African Deputy Minister of Justice for cybercrime legislation and has advised the South African Police Service on the South African National Cybercrime Strategy. Jason is an assessor for the Netherlands Register of Court Experts and is responsible for the assessing the competency of digital forensics practitioners testifying in court in the Netherlands. He is a Director of the Institute of Commercial Forensic Practitioners of South Africa. He has previously served as a Director of the South African Academy of Forensic Sciences, and the South African Chapter of the Association of Certified Fraud Examiners. His digital forensics, cybersecurity, and cyberlaw research has been published in textbooks and international peer-reviewed journals, and he is a frequent speaker at professional, scientific, and technical conferences internationally. He also sits on several international and local conference advisory boards.