Monday, December 14, 2009

Detect and Eliminate Computer Assisted Forensics (DECAF)

Hey Folks,
today I wanna point out this interesting tool, called DECAF. It's an anti Microsoft Computer Online Forensic Evidence Extractor (COFEE).

As many of you probably remember ....

Computer Online Forensic Evidence Extractor (COFEE), designed exclusively for use by law enforcement agencies. COFEE brings together a number of common digital forensics capabilities into a fast, easy-to-use, automated tool for first responders. And COFEE is being provided—at no charge—to law enforcement around the world.
With COFEE, law enforcement agencies without on-the-scene computer forensics capabilities can now more easily, reliably, and cost-effectively collect volatile live evidence. An officer with even minimal computer experience can be tutored—in less than 10 minutes—to use a pre-configured COFEE device. This enables the officer to take advantage of the same common digital forensics tools used by experts to gather important volatile evidence, while doing little more than simply inserting a USB device into the computer.


The new software against COFEE seems to be really useful for everybody who needs max privacy and for whom don't like be investigated. The web site claims:



DECAF is a counter intelligence tool specifically created around the obstruction of the well known Microsoft product COFEE used by law enforcement around the world.
DECAF provides real-time monitoring for COFEE signatures on USB devices and running applications. Upon finding the presence of COFEE, DECAF performs numerous user-defined processes; including COFEE log clearing, ejecting USB devices, drive-by dropper, and an extensive list of Lockdown Mode settings. The Lockdown mode gives the user an automated approach to locking down the machine at the first sign of unusual law enforcement activity.
DECAF is highly configurable giving the user complete control to on-the-fly scenarios. In a moments notice, almost every piece of hardware can be disabled and pre-defined files can be deleted in the background. DECAF also gives the user an opportunity to simulate COFEE's presence by sending the application into a 'Spill the cofee' type mode. Simulation gives the user an opportunity to test his or her configuration before going live.
Future versions will have text message and email triggers so in case the computer needs to enter into lockdown mode the user can do it remotely. It will also have notification services where in the case of an emergency, someone can be notified (private torrent tracker admins). DECAF's next release is going to be available in a more light-weight version and/or a windows service.


Once run the software it appears the following window, very intuitive and very smooth.


This is the main screen about the "Lock Down" option.



Well, people who don't want "be investigate" need to install this "tiny" and "dirty" DECAF-software, BUT they must be aware that exist plenty other ways to investigate into their Windows machine.

9 comments:

Anonymous said...

Hi !.
might , probably curious to know how one can collect a huge starting capital .
There is no need to invest much at first. You may commense earning with as small sum of money as 20-100 dollars.

AimTrust is what you thought of all the time
The company incorporates an offshore structure with advanced asset management technologies in production and delivery of pipes for oil and gas.

Its head office is in Panama with offices everywhere: In USA, Canada, Cyprus.
Do you want to become really rich in short time?
That`s your choice That`s what you desire!

I`m happy and lucky, I began to take up income with the help of this company,
and I invite you to do the same. If it gets down to select a proper partner who uses your savings in a right way - that`s AimTrust!.
I make 2G daily, and what I started with was a funny sum of 500 bucks!
It`s easy to join , just click this link http://zuvasaqy.freehostyou.com/hijimewy.html
and go! Let`s take our chance together to get rid of nastiness of the life

Anonymous said...

Amiable dispatch and this enter helped me alot in my college assignement. Say thank you you seeking your information.

Anonymous said...

Opulently I assent to but I contemplate the brief should prepare more info then it has.

Anonymous said...

What a great resource!

Anonymous said...

[b]Buy [url=http://www.webjam.com/viagra100]Generic Viagra[/url] Online - No Prior Prescription Required (Price from $1 per Tablet!)[/b]
http://www.webjam.com/viagra100
http://www.jugindex.org/display/~livitra167
We Accept All Major Credit Cards (Visa, Mastercard, Amex, JCB, Diners Club), EuroCard (Online Check for European Countries), ACH (USA Online Check), Western Union, Money Gram and Wire Transfer!
Buy Generic Viagra (Sildenafil Citrate 100mg) for Only $1 / pill - No Prescription Required - We add 20 gift Generic Viagra pills to every order for more than 100 pills of any Erectile Dysfunction drug.

Anonymous said...

Hi
Costume Jewellery Watches, items on auctions & discount prices on

[url=http://aerowatches.my3gb.com]chronoswiss watches[/url]
[url=http://dieselwatch.freehostking.com]citizen watch collection[/url]
[url=http://eoswatches.10fast.net]citizen watches discount[/url]
[url=http://watches.awardspace.biz]concord diamond watch[/url]
[url=http://repwatch.bravehost.com]corum mens watch[/url]

Cris said...

HI friends, this information is very interesting, I would like read more information about this topic, thanks for sharing.

homes for sale in costa rica

Liz said...

Hello .. firstly I would like to send greetings to all readers. After this, I recognize the content so interesting about this article. For me personally I liked all the information. I would like to know of cases like this more often. In my personal experience I might mention a book called Generic Viagra in this book that I mentioned have very interesting topics, and also you have much to do with the main theme of this article.

Generic Viagra said...

I already got what I needed, without telling lies, I have more than 2 hours of looking for any information like this. In my college work needed to review articles online, I really thank you very much to the writers.