Meridian Discovery Profile
Meridian Discovery

@meridian

Followers
214
Following
1
Media
36
Statuses
215

Meridian Discovery is an #eDiscovery, computer forensics and hosting service provider for corporations, law firms and government agencies.

Los Angeles, CA
Joined February 2010
Don't wanna be here? Send us removal request.
@meridian
Meridian Discovery
7 years
RT @armangungor: Just published a new blog post on forensic authentication of Word documents and Compound File Binary format. https://t.co/….
m.klr.co
0
7
0
@meridian
Meridian Discovery
7 years
We recover the file system timestamps of a file attached to an email via Outlook #DFIR #eDiscovery #DigitalForensics
Tweet media one
0
1
2
@meridian
Meridian Discovery
7 years
"The xmpMM:History is an array of ResourceEvents that describe the steps taken to make the changes from. " #Dfir #Ediscovery
Tweet media one
0
1
1
@meridian
Meridian Discovery
7 years
"Sometimes the requesting party requires a native file production, based solely on the benefits that they. " #Ediscovery #Dfir
Tweet media one
0
1
0
@meridian
Meridian Discovery
7 years
"It was expected that timestamp resolution beyond seconds would be lost. " #DFIR #eDiscovery
Tweet media one
0
0
0
@meridian
Meridian Discovery
7 years
"File system timestamps can survive the transit to the recipient’s mailbox, sometimes with 100-ns resolution" #DFIR
Tweet media one
0
12
14
@meridian
Meridian Discovery
7 years
"The PDF might have been modified by someone in Eastern Standard Time (e.g., in winter) having rolled. " #Dfir #Ediscovery
Tweet media one
0
1
0
@meridian
Meridian Discovery
7 years
"It is crucial to fully understand what it means to produce in native file format, and to weigh the. " #Dfir #Ediscovery
Tweet media one
0
2
1
@meridian
Meridian Discovery
7 years
"File system timestamps are not designed to be manipulated by the end user — besides legitimate updates. " #DFIR
Tweet media one
0
0
1
@meridian
Meridian Discovery
8 years
Forensic Analysis of Email Attachment Timestamps in Outlook #Dfir #Ediscovery #DigitalForensics
Tweet media one
0
2
2
@meridian
Meridian Discovery
8 years
"According to the PDF 1.7 specification, the document information dictionary contains the following. " #Dfir #Ediscovery
Tweet media one
0
0
0
@meridian
Meridian Discovery
8 years
"When the end user accesses her e-mails over the web interface, the back-end data structures are queried. " #Dfir #Ediscovery
Tweet media one
0
0
2
@meridian
Meridian Discovery
8 years
"Full resolution timestamps can be obtained in numerous ways such as by reviewing the underlying raw. " #DFIR
Tweet media one
0
2
1
@meridian
Meridian Discovery
8 years
Does plucking the file from the filesystem and attaching it to an email result in total loss of filesystem metadata?
Tweet media one
0
0
0
@meridian
Meridian Discovery
8 years
"XMP allows metadata to be embedded into electronic documents, and enables software and systems to. " #Dfir
Tweet media one
0
0
0
@meridian
Meridian Discovery
8 years
"For instance, a reviewer lacking the requisite experience can miss hidden content and comments in a. " #Dfir
Tweet media one
0
0
0
@meridian
Meridian Discovery
8 years
"On a related note, even most mainstream computer forensics software do not display timestamps beyond. " #DFIR
Tweet media one
0
0
0
@meridian
Meridian Discovery
8 years
"Additionally, having access to timestamps with 100-nanosecond resolution is useful in date forgery analysis" #Dfir
Tweet media one
0
1
0
@meridian
Meridian Discovery
8 years
"Some of the XMP metadata properties in the XMP packet that can be interesting during PDF forensic. " #Dfir
Tweet media one
0
0
0
@meridian
Meridian Discovery
8 years
"The metadata load file would contain, among other things, the cryptographic hash of the original file as. " #Dfir
Tweet media one
0
0
0