Deb Shinder’s Blog RSS

All Blogs  »  Deb Shinder's Blog  »  Microsoft Security Space  »  Blog article: Microsoft COFEE and other forensics tools targeted

Microsoft COFEE and other forensics tools targeted

Last November, the code for Microsoft’s Microsoft’s COFEE (Computer Online Forensic Evidence Extractor) forensics tool was leaked to the Internet. COFEE is distributed free to law enforcement agencies all over the world and used to gather digital evidence from computers that are seized in connection with criminal activity. Microsoft does not make it available to those outside the law enforcement community.
http://www.crunchgear.com/2009/11/06/siren-gif-mic...ernet/

Then in December, several sites reported on the release of software called DECAF that could detect the presence of  imageCOFEE  and delete its files and processes as well as clearing its log files. You can read more about DECAF here:
http://www.theregister.co.uk/2009/12/14/microsoft_...decaf/   

On December 18, that first version was pulled by its makers and it was labeled as fake. Now a new version, DECAF 2, is out there. The new version doesn’t limit itself to COFEE, but also detects other forensics software including EnCase, Helix, Forensic Toolkit and more. DECAF developers say the first version did work and was removed because of legal concerns, and that they were trying to raise awareness for “better security and more privacy tools.”
http://www.thetechherald.com/article.php/200953/50...unched

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 6 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a


Receive all the latest articles by email!

Receive Real-Time & Monthly WindowSecurity.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowSecurity.com member!

Discuss your security issues with thousands of other network security experts. Click here to join!

Community Area

Log in | Register

Solution Center

Follow TechGenix on Twitter