HITB LAB: You Forgot Your Wallet! Tracing Bits of Coins in Disk and Memory

HITB Labs are 120 minute hands-on sessions. Please by at the track room at least 5 – 10 minutes before the scheduled start time.

______________

PRESENTATION SLIDES (PDF)

There has been a lot of buzz around Bitcoin, and the so-called “dark web” since the FBI shut down the underground website “Silk Road” last year.

One must wonder what kind of evidence is available to various agencies in case of an investigation. Bitcoin clients generate traceable footprints both on disk and memory. Even if the disk is encrypted, memory can yield latest transactions and possibly wallet information depending on the client configuration. All this data can aid an investigator with connecting the dots.

In this 120-minute lab session, I’ll show you how to use open source tools to acquire Bitcoin client information from system disk and memory and demonstrate what is possible from an attribution perspective.

CONFERENCE
Location: Track 3 / HITB Labs Date: October 15, 2014 Time: 4:00 pm - 6:00 pm Cem Gurkok