Time
58 minutes
Difficulty
Beginner
CEU/CPE
1

Video Transcription

00:00
question to, um when did decide to go from working on a file format? Thio Actually, a commercial product. Like what?
00:11
You know, you were working on this kind of academic situation and then yet
00:15
just jump us so well. So we did. We did the original effort for research and paper in about 2009 and being being out there in practice full time really brought things sharply into focus for me.
00:33
Um, specifically the problems that we were facing at the time. So
00:39
in the early this decade, we were starting to see the driver's getting larger than a terabyte. We were
00:45
dealing with imaging terabyte drives of U. S. B two, which for those of you walking to server rooms is still a problem that we run into on occasion. They haven't really lived until you've spent 20 some hours doing that.
01:00
Yeah, literally days. It can take t copy hard drives. So I was out in the field doing large scale acquisitions on the first problem that I was. The first question that I asked myself was, Why can't this go faster?
01:19
I always I was going into into environments with a stack of live see days like these? Yes. Stack pre prepared USB drives like
01:29
the Like these? Yeah, and is going from computer to computer, setting them up and getting them copying.
01:36
Um,
01:38
and then the that was a real trick to I mean, you were essentially distributing by hand.
01:42
Yeah, Yeah, exactly. Um and that that was that was really the only way Thio quickly get through that many computers. So, you know, if you're spending four days solid
01:56
2 p.m. or sorry to, I am in the morning in server rooms,
02:00
trying to acquire an entire company worth of pieces and service.
02:06
That was really the only way,
02:07
um,
02:08
at the Thai, we were just we were focusing mainly on on hardware tricks to make it faster,
02:15
you know, because the formats were just the formats, right?
02:20
So, you know, you were going with, you know, trying to use faster fire aware, And can we use thunderbolt for this? And you know, what's the fastest status speeds we can get? And you know what happens if we write to, you know, you know, flash drives and, you know, raids and just every, you know, every silly thing we could come up with trying to improve the speed.
02:38
Yeah, and I think there's a lot of learnings that you get through three going through all that, um,
02:44
the thing that the next step that we did was starting to
02:50
rather than doing full acquisitions off the computers in the field. We were sort of taking me to the triage approach where,
02:58
um, we would look at a computer and then we were using the linen ante F s, um, programs. There's a program in there that lets you create a
03:07
allocated only image of a off a hard drive. So we were doing things like,
03:14
in essence, creating Justin. Justin allocated clone off the off hard particular hard drives, pulling that the original hard drive and walking away with that and then dealing with the imaging back in the lab but leaving them with a fresh, hard drive that still worked to all intensive purposes like the original.
03:31
So that's kind of what led me toward the idea of off of allocated only acquisitions that you see these days and every metric. Sure, here, I'm kind of so that that was that was the world that I was in there. So the question that I asked was, What are these bottlenecks? Why are we going so slow? We've
03:50
at that point multi cool was starting to be a thing. So we were starting to see new C P is coming out with two and four et cetera, drives who was starting to get you a high speed us bay three,
04:02
um,
04:03
coming through. So there were these high bandwith interconnects, and we did have the CPU. So that's what really drove me to start playing around with
04:14
identifying where the bottlenecks work. And
04:18
the interesting part of doing that was was really coming to the realization that actually, it wasn't hardware issue. It was a software issue. Um, and that, uh, ultimately,
04:31
um, the main problem that we were hitting with using raw Oreo one. Well, men probably eating with the Owen was the slow speed of compression and hashing really it,
04:43
um and then the main probably hitting with role was just the was was hashing on just the the
04:51
amount of time that you waste copying zeros from one device to win, right? There's the sheer iose.
04:57
It was not good.
05:00
Exactly So
05:01
so that it took us a while of off tooling around in in in in spare time to kind of get to a point where we thought we had proof of concept.
05:12
Andi was probably 2015 by 2014 2015 by that time,
05:17
um,
05:18
and decided at that point to commercialize it and had a beta program and showed a few people around. It's, um, some conferences
05:28
on and we finally did the final launch in 26 states.
05:34
Yes. And say, I think I saw you at the SDF con.
05:39
When was that? 2016 to 2016
05:42
17 maybe
05:44
16 or 17 year? Yeah.
05:46
And I think was 16 maybe
05:48
16.
05:50
And I don't think I fully got a time. And then I want to say 2017.
05:55
Um, I'm constantly reviewing tools, right? It's just, you know,
06:00
you have to always looking for the next thing. Anything that'll make it a little bit better.
06:04
And I remember stumbled across the website getting on. I remember this guy
06:09
and then then, you know, seeing some of the test stuff we're going.
06:13
Wait a minute. I don't believe that that that can't be riel.
06:17
And, uh, yeah, they just went from there, so
06:21
So So So you just
06:24
decided like, there's there's a commercial market for this. I'm just I'm just gonna do this. I'm gonna
06:29
I'm gonna write a tool, and I'm just gonna go after guidance software on my own.
06:35
Um, not quite. Uh, I mean, ultimately, I
06:43
and M imagery came about because I had a pressing problem in my practice that I wanted to sell.
06:50
Um,
06:51
so the other problem, we're sort of going backwards again to the sort of you know
06:57
why we commercialized in the other.
06:59
A key part of always own with Demetri was that was made answering, questionable.
07:03
Why can't actually do some real work while I'm waiting for all these hard drives to be imaged on. So that's the other. The other main problem that I have met resold. So it it lets people actually, uh,
07:15
do meaningful analysis while they're doing their acquisition. So they don't have to white hours and hours. Well, they can start doing some real work. Sure. Now, I know in your forensic practice, are you doing mostly criminal type workers we find here in the U. S. That's like the market for that, you know, really? Time forensic stuff tends to be in the
07:33
either the D o d u mark, you know, battlefield acquisition type stuff, or we're ah were
07:38
in law enforcement.
07:40
So So my practice is primarily civil litigation on and, uh, do a little bit of criminal defense work on, and ah, a little bit of criminal prosecution work.
07:51
Uh, incident response. Ah, little bit of that. Uh, but, um, tried thio.
07:58
Keep away from that at the moment. Uh, I tend to come sometimes in at the mop up stage. Hitting the, uh, hitting the timing targets for my artwork
08:11
is not something I really want to do when I've got other people to support around the world with elementary. Yeah.
08:20
Yeah. All right. I I think there was a right answer. The question?
08:24
Um, yeah. Do do you know the exact moment in time where you're just like I'm doing this?
08:30
Um, look, it had to be, I think maybe 20 somewhere in 2014. Probably.
08:37
Yeah.
08:39
One of those moments where you're just like it is three. In the morning and you just had it with something.
08:43
Not working it like that's it, right? My O'Toole, I do with this.
08:50
You gotta have a quick story, like maybe over 90% of it already. A modest will finish on the 20 something nearly that exciting, Okay.

Up Next

Evimetry: Interview with Dr. Bradley Schatz

In this free course we talk to the co-author of AFF4 and creator of Evimetry, Dr. Bradley Schatz. We’ll hear from Dr. Schatz on his involvement in working on both while learning what’s next for Evimetry and Dr. Schatz’s favorite Evimetry feature.

Instructed By

Instructor Profile Image
Brian Dykstra
CEO and President of Atlantic Data Forensics
Instructor