Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

November 09, 2009 12:00 AM

Microsoft Digital Forensics Tool Leaks Online

Windows IT Pro
InstantDoc ID #103101
Rating: (9)

A secretive Microsoft utility called Computer Online Forensic Evidence Extractor (COFEE) has leaked online. An automated digital forensics tool for law-enforcement agencies, COFEE isn't available legally to individuals.

"COFEE brings together a number of common digital forensics capabilities into a fast, easy-to-use, automated tool for first responders. And COFEE is being provided—at no charge—to law enforcement around the world," a description of the tool reads.

"With COFEE, law-enforcement agencies without on-the-scene computer-forensics capabilities can now more easily, reliably, and cost-effectively collect volatile live evidence," the description continues. "An officer with even minimal computer experience can be tutored—in less than 10 minutes—to use a preconfigured COFEE device. This enables the officer to take advantage of the same common digital-forensics tools used by experts to gather important volatile evidence, while doing little more than simply inserting a USB device into the computer."

Microsoft ships COFEE on a tiny USB device to law-enforcement agencies in almost 190 countries worldwide. The company has been working with Florida State University and University College Dublin to develop future versions of COFEE that can adapt to the evolving needs of digital forensics.

Security researchers point out that COFEE provides no useful tools for individuals, though of course it's possible that criminals might investigate how the code works to find ways around its capabilities.

The most important aspect of this story, of course, is that I avoided obvious headline puns such as "Microsoft COFEE Leaks Online," "Microsoft COFEE: HOT!" or "CSI: Redmond." You're welcome.

Related Content:

ARTICLE TOOLS

Comments
  • Joe
    3 years ago
    Nov 10, 2009

    "Heck, just plugging a USB device in is going to create disk activity, RAM activity, etc.."

    I would imagine it would be a streamlined environment (knowing Microsoft, probably a customized, bootable WinPE USB stick) to get around that exact problem.

    @sx4sport: +1

    Does Microsoft have a DONUT app to go along with that? (or if you're in Canada, a TIMBIT app?)

  • Gyp
    3 years ago
    Nov 09, 2009

    wtf can I get the Hot Coffee Mod, I've been drivin around for hours and I can't even find a paint booth!

  • Chris
    3 years ago
    Nov 09, 2009

    Ah, sweeps month. A story put together by someone who doesn't understand technology, doesn't site statistics, or bother to indicate where the person actually got the virus.

    infinitetroll - did you write it yourself?

    Where to start....

    First - it never says "Windows only".

    Second - it never says how the person got infected. While it may have been a self-reproducing virus (what virus actually means), more than likely it was a trojan horse that the user launched without paying attention - something that can infect Windows, Linux or Mac.

    Third - It never mentions what version of the OS, or if any AV or anti-malware software was installed. It also fails to mention if any patches were actually applied or if there was a firewall - again something that impacts any system.

    Fourth - The FUD factor of "This could happen to you!!!" is about on par with "They stole my organs!" They don't site any number of users this has happened to. The only numbers they do site is the number of infected computers connected to the internet (20M) and total computers connected (1B). Looking at the number 20 million is classic FUD. Quick math shows it's 2%.

    There's more, but frankly I've already spent more time on this than I care to.

  • Andrew
    3 years ago
    Nov 09, 2009

    Looks like it's perfect for identifying the victims of this nasty little Windows-only virus.

    http://abcnews.go.com/Technology/wireStory?id=9028516

    Another reason NOT to buy a PC.

  • Scott
    3 years ago
    Nov 09, 2009

    Despite not knowing anything about this tool, I disagree with Microsoft's statement about it. Heck, just plugging a USB device in is going to create disk activity, RAM activity, etc...possibly enough to compromise anything found on the PC.

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.