Computer Online Forensic Evidence Extractor

Computer Online Forensic Evidence Extractor

Computer Online Forensic Evidence Extractor (COFEE) is a tool kit, developed by Microsoft, to help computer forensic investigators extract evidence from a Windows computer. Installed on a USB flash drive or other external disk drive, it acts as an automated forensic tool during a live analysis. Microsoft provides COFEE devices and online technical support free to law enforcement agencies.


Development and distribution

COFEE was developed by Anthony Fung, a former Hong Kong police officer who now works as a senior investigator on Microsoft's Internet Safety Enforcement Team.[1] Fung conceived the device following discussions he had at a 2006 law enforcement technology conference sponsored by Microsoft.[2] The device is used by more than 2,000 officers in at least 15 countries.[3]

A case cited by Microsoft in April 2008 credits COFEE as being crucial in a New Zealand investigation into the trafficking of child pornography, producing evidence that led to an arrest.[1]

In April 2009 Microsoft and INTERPOL signed an agreement under which INTERPOL would serve as principal international distributor of COFEE. University College Dublin's Center for Cyber Crime Investigations in conjunction with INTERPOL develops programs for training forensic experts in using COFEE.[4] The National White Collar Crime Center has been licensed by Microsoft to be the sole US domestic distributor of COFEE.[5]

Public leak

On November 6, 2009, copies of Microsoft COFEE were leaked onto various BitTorrent websites.[6] Analysis of the leaked tool indicates that it is largely a wrapper around other utilities previously available to investigators.[7] Microsoft confirmed the leak, however a spokesperson for the firm said "We do not anticipate the possible availability of COFEE for cybercriminals to download and find ways to ‘build around' to be a significant concern". [8]


The device is activated by being plugged into a USB port. It contains 150 tools and a graphical user interface to help investigators collect data.[1] The software is reported to be made up of three sections. First COFEE is configured in advance with an investigator selecting the data they wish to export, this is then saved to a USB device for plugging into the target computer. A further interface generates reports from the collected data.[7] Estimates cited by Microsoft state jobs that previously took 3–4 hours can be done with COFEE in as little as 20 minutes.[1][9]

COFEE includes tools for password decryption, Internet history recovery and other data extraction.[2] It also recovers data stored in volatile memory which could be lost if the computer were shut down.[10]

Detect and Eliminate Computer Assisted Forensics (DECAF)

Detect and Eliminate Computer Assisted Forensics (DECAF) is a counter intelligence tool specifically created around obstructing COFEE. DECAF provides real-time monitoring of COFEE signatures on USB devices and in running applications. When a COFEE signature is detected, DECAF performs numerous user-defined processes. These may include COFEE log clearing, ejecting USB devices, and contamination or spoofing of MAC addresses.

See also

  • BackTrack
  • Knoppix STD
  • nUbuntu
  • Windows To Go, bootable USB drive with Windows capable of running data recovery/collection utilities
  • Espresso A COFEE plug-in which creates archives of common high-yield PII locations on a Windows PC (IE, Firefox, Amazon, Windows Live Mails).


  1. ^ a b c d "Brad Smith: Law Enforcement Technology Conference 2008". Microsoft Corporation. 2008-04-28. Retrieved 2008-05-19. 
  2. ^ a b Romano, Benjamin J. (2008-04-29). "Microsoft device helps police pluck evidence from cyberscene of crime". The Seattle Times. Retrieved 2008-05-19. 
  3. ^ "Microsoft Calls on global public-private partnerships to Help in the Fight Against Cybercrime (Q&A with Tim Cranton, Associate General Counsel for Microsoft)". Microsoft Corporation. 2008-04-28. Retrieved 2008-05-19. 
  4. ^ "INTERPOL initiative with Microsoft aims to raise global standards against cybercrime through strategic partnership with IT sector". INTERPOL. Retrieved 2009-07-16. 
  5. ^
  6. ^ "Microsoft COFEE law enforcement tool leaks all over the Internet". TechCrunch. Retrieved 2009-11-07. 
  7. ^ a b "More COFEE Please, on Second Thought". Retrieved 2009-11-09. 
  8. ^ Pullin, Alexandra. "Microsoft's not bothered about COFEE leak". The Inquirer. Retrieved 24 August 2010. 
  9. ^ Valich, Theo (2008-05-07). "Microsoft's new product goes against crime: Meet (Hot) COFEE". Tigervision Media. Retrieved 2008-05-19. 
  10. ^ Mills, Elinor (2008-04-29). "Microsoft hosts its own police academy". CNet Retrieved 2008-05-19. 

External links

Wikimedia Foundation. 2010.

Игры ⚽ Нужна курсовая?

Look at other dictionaries:

  • COFEE — Computer Online Forensic Evidence Extractor (COFEE) модифицированный USB флэш накопитель производства Корпорации Майкрософт, предназначенный для быстрого извлечения с компьютера подозреваемого улик, которые могут доказать его вину в IT… …   Википедия

  • USB flash drive — JumpDrive redirects here. For the fictional propulsion system, see Jump drive. SanDisk Cruzer Micro, a brand of USB flash drives …   Wikipedia

  • Coffee (disambiguation) — Coffee is a widely consumed beverage made from coffee beans. Instant coffee is a soluble powder form of the drink Coffee may also refer to: In computers: COFFEE (Cinema 4D), a computer scripting language CoFFEE, the Collaborative Face to Face… …   Wikipedia

  • Программное обеспечение производства Microsoft — Содержание 1 Операционные системы 1.1 Пользовательские 1.2 Для домашнего сервера …   Википедия

  • Продукция Microsoft — За время своего существования Microsoft выпускала и в настоящее время выпускает различное программное и аппаратное обеспечение, а также разрабатывала концепции такие как Microsoft Courier, и компьютерные платформы такие как Microsoft Tablet PC.… …   Википедия

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”