Mar 14
DECAF 2.0
Decafme, the guys behind DECAF, the anti-COFEE tool, have released a new version of it.
I must admit that I missed the importance of the initiative when I said it was «an exercise of posing» here, at least in the effects that this tool may have in shaping the way computer evidence is acquired.
Not that I use any tool to collect evidences while the target computer is on, but if I did I would be worried the next time I used one because the new version of DECAF can apply the same actions it did when detected COFEE to any tool it may have a signature for.
The guys at DragonJar make a brief summary here, and you may get some more information here.
Comentarios desactivados en DECAF 2.0

