Mar 14 2010


Tag: (i)realidad,Informática LegalJoaquim Anguas @ 9:48 pm

Decafme, the guys behind DECAF, the anti-COFEE tool, have released a new version of it.

I must admit that I missed the importance of the initiative when I said it was «an exercise of posing» here, at least in the effects that this tool may have in shaping the way computer evidence is acquired.

Not that I use any tool to collect evidences while the target computer is on, but if I did I would be worried the next time I used one because the new version of DECAF can apply the same actions it did when detected COFEE to any tool it may have a signature for.

The guys at DragonJar make a brief summary here, and you may get some more information here.