Microsoft handing out free COFEE.. Its not Starbucks related

You have heard me mention COFEE (Computer Online Forensic Evidence Extractor) before when I was speaking about EnCase’s latest portable forensics tool.
Microsoft have now published a press release detailing how COFEE is going to be given out to US Law Enforcement types at no cost.

Today at the Digital Crimes Consortium, Microsoft Corp. and the National White Collar Crime Center (NW3C) — the nation’s premier provider of economic and high-tech crime training to law enforcement agencies — announced an agreement establishing NW3C as the first U.S.-based distributor of the Computer Online Forensic Evidence Extractor (COFEE). A Microsoft-developed program, COFEE uses digital forensic technologies to help investigators gather evidence of live computer activity at the scene of a crime, regardless of their technical expertise. This agreement will make COFEE available to law enforcement agencies at no charge so they can better combat the growing and increasingly complex ways that criminals use the Internet to commit crimes. This distribution agreement broadens availability for law enforcement agencies, building on Microsoft’s April 2009 distribution agreement with INTERPOL, which is making the COFEE tool available to law enforcement in each of its 187 member countries.

This is interesting for Microsoft, and I think in some ways it does show some continued commitment to InfoSec, but it also doesnt do their publicity any harm.

I have not got my hands on a copy of COFEE, I guess for obvious reasons. However I would guess at it being abit similar to WOLF (Windows Online Forensics) which Microsoft use for their internal incident response. I have seen this tool, and it is quick and simple to use. This is the basic selling (I know its free) of COFEE for law enforcement, they can simply plug and go. It my understanding they will plug it in, it will run a few scripts and collect all the relevant digital evidence and volatile data. I don’t see this as being a replacement for EnCase and FTK type offerings, but its going to be a handy bit of kit for law enforcement response units, I just hope it doesn’t dumb down the forensics skill set.

Microsoft COFEE

Microsoft COFEE

Law enforcement agents with less than 10 minutes training can capture live evidence of illegal activity by inserting the COFEE USB device into a computer. The evidence is then preserved for analysis, protecting it from being destroyed when the computer is turned off for moving.

Be Sociable, Share!

3 Responses to “Microsoft handing out free COFEE.. Its not Starbucks related”

  1. Andrew Waite says:

    For those thinking of going looking for the tool, there are several copies of ‘COFEE’ I’ve seen floating around on line which are actually just WOLF. Yet to see fakes with malicious intent but probably won’t take long…

    Slightly worried that this is setting the barrier to entry lower for the law enforcement agencies, if they can just plug-and-prosecute some may not see the need for more knowledgeable guys on the ground.

  2. […] This post was mentioned on Twitter by Joe Burton, Joe Burton. Joe Burton said: Microsoft handing out free COFEE.. Its not Starbucks relat.. Training Today! […]

  3. Social comments and analytics for this post…

    This post was mentioned on Twitter by Joe Burton: Microsoft handing out free COFEE.. Its not Starbucks relat..
    Training Today!…

Leave a Reply

Your email address will not be published. Required fields are marked *