Thoughts on Analysis
Brief
Warning - before you get started reading this blog post, it's only fair that I warn you... in this post, I make the recommendation that you document your analysis process. If you find this traumatic, you might want to just move on. ;-)
Robert Jan Mora, a name that I've known for some time within the DFIR community, recently posted something pretty fascinating on LinkedIn , having to do with a case that he worked a bit ago. His post, in turn, leads to this The Wire article , from India, and includes an interview with him.
The "so what" of the article itself has to do with an initial report that states that no malware was present, and two subsequent reports, one of which is from Robert Jan's analysis, stating that malware was found on a USB device.
In his LinkedIn post, Robert Jan emphasizes the need for malware scans in a law enforcement environment.
