I Hear Chimes: USB Flash Drive Forensics presented at Security B-Sides Iowa 2012

by Philip Polstra,

Tags: Security

Summary : USB flash drives have become ubiquitous, yet their use is not well understood by many users and security professionals. This talk will cover the basics of how USB flash drives work, the way that Windows handles flash drives, forensics related to flash drives, forensics countermeasures, methods of creating forensic images of flash drives, issues related to flash drive forensics, and how to build a compact flash drive forensic duplicator and USB write blocker for under $30 each. Code and hardware specifications for the devices are open source. The need for an organization to support the use of open source hardware and software in the infosec/forensics industry will also be briefly presented.