Hackers have released an application called Decaf, which is designed to sabotage Microsofts COFEE (Computer Online Forensic Evidence Extractor).
Decaf is a lightweight application that monitors Windows systems for the presence of COFEE, a bundle of some 150 point-and-click tools used by police to collect digital evidence at crime scenes, writes The Registers Dan Goodin. When a USB stick containing the Microsoft software is attached to a protected PC, Decaf automatically executes a variety of countermeasures.
In addition to nuking temporary files within seconds of detecting files or processes associated with the investigative tool, Decaf can also clear all COFEE logs, disable USB drives, and contaminate or spoof a variety of MAC addresses, Goodin writes.
Click here to read the story at The Register.
Loading Comments...