Systems and Methods For Digital Forensic Triage
First Claim
1. A method for forensic triage comprising:
- coupling, communicatively, a computer and a mobile device, wherein the computer comprises one or more processors conductively coupled to one or more memory modules and the mobile device comprises one or more mobile processors conductively coupled to one or more mobile memory modules and one or more communication modules, and machine readable instructions stored on the one or more mobile memory modules of the mobile device;
booting the computer with the machine readable instructions stored on the one or more mobile memory modules of the mobile device;
receiving a search data set with the one or more mobile processors of the mobile device;
executing, automatically with the one or more processors, the one or more mobile processors, or both, the machine readable instructions stored on the one or more mobile memory modules of the mobile device to search the one or memory modules of the computer in a read only mode for triage data that corresponds to the search data set; and
transmitting the triage data via the one or more communication modules of the mobile device.
3 Assignments
0 Petitions
Accused Products
Abstract
In one embodiment, a method for forensic triage may include coupling, communicatively, a computer and a mobile device. The computer can be booted with machine readable instructions stored on the one or more mobile memory modules of the mobile device. A search data set can be received with one or more mobile processors of the mobile device. One or more processors of the computer, the one or more mobile processors, or both, can execute, automatically, the machine readable instructions stored on the one or more mobile memory modules of the mobile device to search one or memory modules of the computer in a read only mode for triage data that corresponds to the search data set. The triage data can be transmitted via one or more communication modules of the mobile device.
-
Citations
20 Claims
-
1. A method for forensic triage comprising:
-
coupling, communicatively, a computer and a mobile device, wherein the computer comprises one or more processors conductively coupled to one or more memory modules and the mobile device comprises one or more mobile processors conductively coupled to one or more mobile memory modules and one or more communication modules, and machine readable instructions stored on the one or more mobile memory modules of the mobile device; booting the computer with the machine readable instructions stored on the one or more mobile memory modules of the mobile device; receiving a search data set with the one or more mobile processors of the mobile device; executing, automatically with the one or more processors, the one or more mobile processors, or both, the machine readable instructions stored on the one or more mobile memory modules of the mobile device to search the one or memory modules of the computer in a read only mode for triage data that corresponds to the search data set; and transmitting the triage data via the one or more communication modules of the mobile device. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14)
-
-
15. A system for forensic triage comprising:
-
a mobile device comprising one or more mobile processors conductively coupled to one or more mobile memory modules and one or more communication modules; a cloud computing device communicatively coupled to the one or more communication modules of the mobile device, the cloud computing device comprising one or more cloud processors conductively coupled to one or more cloud memory modules; a search data set stored on the one or more mobile memory modules of the mobile device, the one or more cloud memory modules, or both; and machine readable instructions stored on the one or more mobile memory modules of the mobile device, the one or more cloud memory modules, or both, wherein when the one or more communication modules of the mobile device is communicatively coupled to a computer comprising one or more processors conductively coupled to one or more memory modules, the one or more processors, the one or more mobile processors, or both are configured to execute the machine readable instructions to; boot the computer according to the machine readable instructions; search the one or memory modules of the computer in a read only mode for triage data that corresponds to the search data set; and the one or more cloud processors, the one or more mobile processors, or both are configured to execute the machine readable instructions to; compare the triage data, the search data set, or both to a data archive that is protected by a firewall; allow the receipt of data indicative of a match between the triage data and the data archive, the search data set and the data archive, or both; and deny the receipt of predefined segments of the data archive. - View Dependent Claims (16, 17, 18, 19)
-
-
20. A method for forensic triage comprising:
-
coupling, communicatively, a computer and a mobile device, wherein the computer comprises one or more processors conductively coupled to one or more memory modules and the mobile device comprises one or more mobile processors conductively coupled to one or more mobile memory modules and one or more communication modules, and machine readable instructions stored on the one or more mobile memory modules of the mobile device; booting the computer with the machine readable instructions stored on the one or more mobile memory modules of the mobile device; receiving a search data set with the one or more mobile processors of the mobile device, wherein the search data set comprises a keyword list that comprises a plurality of keywords of interest, a hash list that comprises a plurality of hashes that correspond to output from a cryptographic hash function, and a search list that comprises a plurality of identifiers that each correspond to an instance of a system resource; executing, automatically with the one or more processors, the one or more mobile processors, or both, the machine readable instructions stored on the one or more mobile memory modules of the mobile device to search the one or memory modules of the computer in a read only mode for triage data that corresponds to the search data set; coupling, communicatively, the mobile device and a cloud computing device with a cellular network; and transmitting the triage data via the one or more communication modules of the mobile device over the cellular network.
-
Specification