course eight. Ever Met Tree Our interview with Dr Bradley Schatz
and I am Bryant Extra on the CEO of Atlantic Data Forensics. I was co founder of Mandy. It I taught cyber crime at the FBI Academy at Quantico for a few years. I have a whole bunch of nifty certifications and things like that. Um, if you have any questions about this course or any of the other courses, you can reach out to me, it's cyber ery at
Atlantic D f dot com
and I will actually respond back to its crazy.
All right, Atlanta data forensics found in 2007. We're headquartered up in Elkridge, Maryland, right off the 95 there by the BW Airport. Ah, we do computer forensics for civil and criminal litigation with full capability of discovery for big law firm cases.
And we do 24 7 incident response. We just never quit doing that right now,
uh, forever. Um, internal corporate HR investigations. Of course. We do instant response training and exercises for folks, and we have offices out in Denver in Detroit, and we're working hard on Nashville at the moment,
right? Prerequisites for this one kind of limited this time. I want to get yourself a ah evaluation copy of ever Metreon, my demetri dot com, you or else there. And also, you should take a look at the advanced F f for public pdf of the elementary website. Everything you wanted to know about the protocol, how it works and all that. That's protocol
All right. Course materials today always helps to have a computer, and you should pick up that evil copy and test it out.
Our target audience, as always, is computer forensics professionals, incident responders, and I t professionals that sometimes get forced into doing this, whether they wanted to or not,
are learning objectives pretty easy. We're gonna hear from one of the authors the f f O R. Forensic format. We're gonna find out how that actually came to be a thing.
And then we're gonna talk to Dr Sheds a little bit about where he plans to take elementary next. And with that,
don't it, uh, Dr Bradley Schatz
and question number one. I feel like you might have heard this before,
but to just wake up one morning and save yourself, I I think the world needs a brand new forensic file format. And I'm just the man to do this.
Um, you know, quite, um, confluence of events. I think I'd say, um
um, back in the beginning of last decade, I was I had the fortune off doing a PhD in computer forensics, and
one of the focuses of that was in pulling together disparity sources of forensic information.
So one of the things I focused on were the limitations off the image format time which were really roll D d
ah, and the CEO one which at the time was fairly poorly understood.
Um So what I was looking at back then was more how to integrate disparity information. When you say back then, were you talking about her?
Oh, that would have been 2000 and 5 2006 All rights. That's That's a good long time ago. Yeah. Point. Yeah, I mean,
so I published a paper, then on it, and
there's a little bit of interest back then from a few researchers in pulling together on openly to find format, but that never really went anywhere.
Um, sort of fast forward Thio 2009. I'd finished my PhD, I I was practicing full time. I just started chats. Forensic. Um, then So that's it's been a decade now.
um, I got together with Michael Cohen, who, um, is done a lot of work in an i r with Ger and with volatility. Hey approached me along with Simpson Garfinkel. They were both wanting to address some of the issues that were
performance issues that were happening with Simpson's approach to forensic image formats, which was a f f. So some of the issues that it was having all the primary issue was having his wasn't performing very well with interface images
and that really came down Thio. It's the size of the compressed chunks that it was using were by default too large.
Yeah, we, uh, we looked at f f.
She's going to say
7 4008 We came to the same conclusion that just
it wasn't wasn't gonna happen for us.
Yeah, yes, So it was. I think it was a really good, good, good step in terms. L've introducing the idea of having a reasonably arbitrary metadata being added to the format
as well as having showing how I and I've been format could be integrated in all sorts of tooling home, et cetera.
yeah, but the three of us got together. Really? Simpson brought his experience with with 1/5. Michael brought
the idea role in creating integrating virtual ization into the forensic format.
And I brought the ability to refer to evidence between evidence containers
and basically they those three paces that we've kind of put into a f F four of actually
proven over time Thio be very extensible on have supported everything. All of the innovation we've done with ever Met Tree.
Um, we've been able to adapt very easily recently. Toe what's one logical image ing
the foundation's over the Zaveri Merit malleable format?
I couldn't agree more.
All right, we're ready for question. Two
show counts. Big surprise.
Computer Forensics File Formats: Why you Should be Using AFF4
If you’re not using AFF4 (Advanced Forensics File Format v4) then your forensics process is ...
1 CEU/CPE Hours Available
Certificate of Completion Offered
MITRE ATT&CK Defender™ (MAD) ATT&CK® SOC Assessments Certification Training
Do you know how to leverage the MITRE ATT&CK® framework to conduct Security Operations Center ...
2 CEU/CPE Hours Available
Certificate of Completion Offered