Computer Forensic Bitmaps and Visualization for Data Identification
The presentation demonstrated BlockWatch’s ability to identify known data in a opaque data region and generate graphics (bitmaps) that show detected fragments as like color’s.
BlockWatch embed’s the MetaData id into the bitmap as the color. This means, the image can be used to query the BlockWatch MetaData XML (i.e. correlate blue <=> msword.exe).
presented by: Shane A. Macaulay