| Paper | Presentation | Conference | Downloads | Author |
|---|---|---|---|
| System for the Proactive, Continuous, and Efficient Collection of Digital Forensic Evidence | DFRWS USA 2011 | Clay Shields (Georgetown University), Ophir Frieder, Mark Maloof | |
| Reconstructing Corrupt DEFLATEd Files | DFRWS USA 2011 | Ralf Brown (CMU) | |
| Privacy-Preserving Network Flow Recording | DFRWS USA 2011 | Bilal Shebaro, Jedidiah Crandall (University of New Mexico) | |
| Extracting the Windows Clipboard from Memory | DFRWS USA 2011 | James Okolica, Gilbert Peterson (US Air Force Institute of Technology) | |
| Empirical Analysis of Solid State Disk Data Retention when used with Contemporary Operating Systems | DFRWS USA 2011 | Christopher King | |
| eDiscovery Case Study | DFRWS USA 2011 | A. J. Krouse | |
| Distributed Forensics and Incident Response in the Enterprise | DFRWS USA 2011 | Michael Cohen (Google), Darren Bilby, Germano Caronni | |
| Digital Forensics in Consumer Online Privacy Class Actions | DFRWS USA 2011 | Scott Kamber | |
| Detecting Data Theft Using Stochastic Forensics | DFRWS USA 2011 | Jonathan Grier (Grier Forensics) | |
| CAT Detect – A Tool for Detecting Inconsistency in Computer Activity Timelines | DFRWS USA 2011 | Andrew Marrington (Zayed University), Ibrahim Baggili (University of New Haven), George Mohay, Andrew Clark | |
| An Evaluation of Forensic Similarity Hashes | DFRWS USA 2011 | Vassil Roussev, Ph.D. (University of New Orleans) | |
| Using NLP Techniques for File Fragment Classification | DFRWS USA 2012 | Oles Zhulyn, Simran Fitzgerald, and George Mathews, and Colin Morris | |
| The Use of Random Sampling in Investigations Involving Child Abuse Material | DFRWS USA 2012 | Michael Wilkinson, Brian Jones, and Syd Pleno | |
| Testing the National Software Reference Library | DFRWS USA 2012 | Neil Rowe (Naval Postgraduate School) | |
| Social Networking Applications on Mobile Devices | DFRWS USA 2012 | Noora Al Mutawa, Ibrahim Baggili (University of New Haven), and Andrew Marrington (Zayed University) | |
| Lessons Learned Writing Computer Forensics Tools and Managing a Large Digital Evidence Corpus | DFRWS USA 2012 | Simson Garfinkel, Ph.D. (Naval Postgraduate School) | |
| IntroLib – Efficient and Transparent Library Call Introspection for Malware Forensics | DFRWS USA 2012 | Zhui Deng, Dongyan Xu (Purdue University), Xiangyu Zhang, and Xuxian Jiang (North Carolina State University) | |
| An Automated Timeline Reconstruction Approach for Digital Forensic Investigations | DFRWS USA 2012 | Christopher Hargreaves and Jonathan Patterson | |
| Visualization in Malware and Forensics | DFRWS USA 2012 | Danny Quist | |
| Triage in Digital Forensics | DFRWS USA 2012 | Ryan Moore | |
| Surveying The User Space Through User Allocations | DFRWS USA 2012 | Andrew White (Dell Secureworks), Bradley Schatz, Ph.D. (Schatz Forensic), Ernest Foo | |
| Finding and Identifying Text in 900+ Languages | DFRWS USA 2012 | Ralf Brown (CMU) | |
| Content Triage with Similarity Digests – The M57 Case Study | DFRWS USA 2012 | Vassil Roussev, Ph.D. (University of New Orleans), Candice Quates | |
| Bin-Carver – Automatic Recovery of Binary Executable Files | DFRWS USA 2012 | Scott Hand, Zhiqiang Lin (The Ohio State University), Guofei Gu, Bhavani Thuraisingham | |
| An Analysis of Ext4 for Digital Forensics | DFRWS USA 2012 | Kevin Fairbanks | |
| Acquiring Forensic Evidence from Infrastructure-as-a-Service Cloud Computing | DFRWS USA 2012 | Josiah Dykstra, Ph.D. (National Security Agency), Alan Sherman | |
| A General Strategy for Differential Forensic Analysis | DFRWS USA 2012 | Simson Garfinkel, Ph.D. (U.S. Census Bureau), Alex Nelson, Ph.D. (NIST), Joel Young | |
| Modern Ships Voyage Data Recorders – A Forensics Perspective on the Costa Concordia Shipwreck | DFRWS USA 2013 | Mario Piccinelli and Paolo Gubian | |
| Language Translation for File Paths | DFRWS USA 2013 | Neil Rowe (Naval Postgraduate School), Riqui Schwamm, and Simson Garfinkel, Ph.D. (Naval Postgraduate School) | |
| Improved Recovery and Reconstruction of DEFLATEd Files | DFRWS USA 2013 | Ralf Brown (CMU) | |
| Design and Implementation of FROST – Digital Forensic Tools for the OpenStack Cloud Computing Platform | DFRWS USA 2013 | Josiah Dykstra, Ph.D. (National Security Agency) and Alan Sherman | |
| Anti-Forensic Resilient Memory Acquisition | DFRWS USA 2013 | Johannes Stüttgen (University of Erlangen-Nuremberg) and Michael Cohen (Google) | |
| An Evaluation Platform for Forensic Memory Acquisition Software | DFRWS USA 2013 | Stefan Voemel and Johannes Stuettgen | |
| Unicode Search of Dirty Data, Or How I Learned to Stop Worrying and Love Unicode Technical Standard 18 | DFRWS USA 2013 | Jon Stewart, Joel Uckelman | |
| Integrity Verification of User Space Code | DFRWS USA 2013 | Andrew White (Dell Secureworks), Bradley Schatz, Ph.D. (Schatz Forensic), Ernest Foo | |
| FRASH – A Framework To Test Algorithms Of Similarity Hashing | DFRWS USA 2013 | Frank Breitinger (University of New Haven), Georgios Stivaktakis, Harald Baier (University of Applied Sciences, Darmstadt) | |
| File Fragment Encoding Classification – An Empirical Approach | DFRWS USA 2013 | Vassil Roussev, Ph.D. (University of New Orleans), Candice Quates | |
| Automated Identification of Installed Malicious Android Applications | DFRWS USA 2013 | Mark Guido (The MITRE Corporation), Justin Grover (The MITRE Corporation), Jared Ondricek, Dave Wilburn, Drew Hunt, Thanh Nguyen | |
| Android Forensics – Automated Data Collection And Reporting From A Mobile Device | DFRWS USA 2013 | Justin Grover (The MITRE Corporation) | |
| A Study of User Data Integrity During Acquisition of Android Devices | DFRWS USA 2013 | Namheun Son, Yunho Lee, Dohyun Kim, Joshua James (Digital Forensic Investigation Research Laboratory, Hallym University), Sangjin Lee, Kyungho Lee | |
| Ranking Algorithms For Digital Forensic String Search Hits | DFRWS USA 2014 | Nicole Beebe, Ph.D. (UTSA) and Lishu Liu | |
| Multidimensional Investigation of Source Port 0 Probing | DFRWS USA 2014 | Elias Bou-Harb (National Cyber Forensics and Training Alliance / Concordia University ), Nour-Eddine Lakhdari, Hamad Binsalleeh, and Mourad Debbabi (Concordia University) | |
| VMI-PL – A Monitoring Language for Virtual Platforms Using Virtual Machine Introspection | DFRWS USA 2014 | Florian Westphal, Stefan Axelsson (Norwegian University of Science and Technology), Christian Neuhaus, Andreas Polze | |
| These Logs Were Made for Talking | DFRWS USA 2014 | Matt Bromiley | |
| The Regional Computer Forensics Lab System | DFRWS USA 2014 | Sean O'Brien | |
| The National Software Reference Library | DFRWS USA 2014 | Douglas White (NIST) | |
| The Application Of Reverse Engineering Techniques Against The Arduino Microcontroller To Acquire Uploaded Applications | DFRWS USA 2014 | Steve Watson (VTO Labs) | |
| Testing the Forensic Soundness of Forensic Examination Environments on Bootable Media | DFRWS USA 2014 | Ahmed Fathy Abdel Latif Mohamed, Andrew Marrington (Zayed University), Farkhund Iqbal, Ibrahim Baggili (University of New Haven) | |
| Some Practical Thoughts Concerning Active Disk Antiforensics | DFRWS USA 2014 | Travis Goodspeed | |
| Preliminary Forensic Analysis Of The Xbox One | DFRWS USA 2014 | Jason Moore, Ibrahim Baggili (University of New Haven), Andrew Marrington (Zayed University), Armindo Rodrigues |