Computer forensic and auditing tool is used by law enforcement agency to gather and extract information, traces and usage evidences from a computer. One such tool is COFEE (Computer Online Forensic Evidence Extractor), a USB key flash drive-based application which is provided for free by Microsoft to police and investigators around the world.
However, there may be chance that hackers and people with malicious intents uses the COFEE computer forensic tool as a backdoor to access and track private or sensitive data, temporary files, online activity traces, browsing histories and decrypted passwords. Most anti-virus, anti-spyware or anti-malware probably won’t detect and show the forensic utility as a threat.
For users who want to be informed when such a forensic tool is been used or applied on the computer, DECAF is a light-weight application anti-COFEE tool that can detect and sabotage the COFEE suite of forensic utilities, which bundles more than 150 point-and-click tools to college digital evidence at crime scenes.
DECAF works by comparing against signature of COFEE application files or processes. When a USB stick or USB flash drive running COFEE is inserted or plugged into the computer’s USB port, DECAF can detect the presence of COFEE, and automatically execute a series of pre-configured countermeasures. The actions that can be taken include nuke and remove temporary files created by COFEE, clear all COFEE logs, disable USB drives, contaminate or spoof a variety of MAC addresses. Features that currently developers working on include ability to remotely lock down protected system on detection of COFEE.
DECAF can be downloaded from decafme.org, and click on Download link.
Share This Post
- Able2Extract Professional 11 Review – A Powerful PDF Tool
- How to Install Windows 10 & Windows 8.1 with Local Account (Bypass Microsoft Account Sign In)
- How to Upgrade CentOS/Red Hat/Fedora Linux Kernel (cPanel WHM)
- How to Install Popcorn Time Movies & TV Shows Streaming App on iOS (iPhone & iPad) With No Jailbreak
- Stream & Watch Free Torrent Movies & TV Series on iOS with Movie Box (No Jailbreak)
- Windows 10 20H1 Insider Preview Build 18898 Released to the Fast Ring with Task Manager Improvements
- Dashlane Premium Free 1-Year Access With No Cost
- Media Creation Tool for Windows 10 Build 18362 (19H1)
- Windows 10 Insider Preview Build 18885 (20H1) Released to Windows Insiders in Fast Ring – Here What’s New, Fixes, Changes, Improvements
- Google Chrome 74 Released – Here the Changes and Download Links