SlideShare a Scribd company logo
1 of 59
Download to read offline
See the Bigger Picture Faster
Early Case Assessment Best Practices
23 November 2016 Copyright Nuix 2016 2
Presenters
Aidan Jewell, Solutions Consultant, Nuix
Aidan joined Nuix in 2014, bringing a decade of digital forensic investigation experience to
the EMEA team. As a Solutions Consultant, Aidan is responsible for pre and post sales
technical consultation, in addition to sharing his Nuix and investigations experience and
expertise with clients through workshops and the Nuix Bytes YouTube channel.
Carl Barron, Senior Solutions Consultant, Nuix
Carl has joined the company in March 2012. He provides pre and post-sale consultancy,
technical support and solution implementation. Carl brings a wide variety of knowledge in
both hardware and software with an enthusiast approach to help customers improve
workflows. Prior to joining Nuix, Carl worked as a Forensic Technician for a leading
Litigation Support Vendor in London.
23 November 2016 Copyright Nuix 2016 3
Session Agenda
• Introduction
• Outline of current problem (Data Volumes)
• What is ECA?
• Benefits of ECA
• Tiered Processing
• Early Access & Collaboration
• Visuals
• Advanced ECA Features
• Summary
Outline of the current problem
23 November 2016 Copyright Nuix 2016 5
Data volumes and filing in 1986
1986 – back in the good old days…
• Dictate, approve, and send and perhaps 50 documents per day
• All documents received and carbon copies of documents sent were filed
• We had desk diaries
• Some firms kept a central book for attendance notes of important
discussions
• In a couple of days you could read into the documents – involving up to,
say, 2,000 documents - 2 metres of shelf space
23 November 2016 Copyright Nuix 2016 6
Data volumes and filing in 2016
2016 – surrounded by technology…
• Send and receive by email hundreds of documents each day, with
still larger volumes of material coming in via SFTP
• Copies are saved all over the place (and on multiple devices)
• Yet more lurking “in the Cloud”
• Jebb Bush’s email dump – 1,800,000 emails - over a kilometre of
shelf space
23 November 2016 Copyright Nuix 2016 7
Data everywhere
1 Email from me to you…
23 November 2016 Copyright Nuix 2016 8
Data everywhere
1 Email from me to you…~12 copies
Copyright Nuix 2015 923 November 2016
Data Volume
Year 2000
=
20GB Hard Drive 6 Rooms
Copyright Nuix 2015 1023 November 2016
Data Volume
Year 2016
=
1TB Hard Drive 300 Rooms
What is ECA (Early Case Assessment)?
23 November 2016 Copyright Nuix 2016 12
What is ECA?
Definition
• An industry-specific term generally used to describe a variety of tools or methods for investigating and
quickly learning about a Document Collection for the purposes of estimating the risk(s) and cost(s) of
pursuing a particular legal course of action. 1
• A widely abused term in which corporate data is sifted and categorised with a view to determining an
organisation's exposure in the context of a dispute. The best ECA systems allow the sifting to take place
within a corporation's own data store and can be used to drill down rapidly to identify the most pertinent
evidentiary material and to facilitate decisions whether to litigate or settle. 2
1.Maura R. Grossman and Gordon V. Cormack, EDRM page & The Grossman-Cormack Glossary of Technology-Assisted Review, with Foreword by John M. Facciola, U.S. Magistrate
Judge, 2013 Fed. Cts. L. Rev. 7 (January 2013). ↩
2.LitSavant Ltd., Glossary, http://www.litsavant.com/full-glossary.aspx ↩
Why Early Case Assessment?
23 November 2016 Copyright Nuix 2016 14
Why ECA?
• Case Strategy
• Reduce Risk
• Reduce Cost
• Fight or settle?
• Drive into facts of the data
• Proactively manage litigation
23 November 2016 Copyright Nuix 2016 15
Proportionality
• Budgets are limited
• Courts increasingly keen to avoid traditional, standard, disclosure
• Need to cull multiple copies
• Equally, where appropriate, ensure the full history of documents is
recovered
• Involving forensic experts to collect the documents is expensive and feels
like “overkill” (and is both expensive and disruptive)
23 November 2016 Copyright Nuix 2016 16
Early Case Assessment
• Often just a simple investigation
• Over 95% of disputes settle rather than proceed to a hearing
• The key issues are always the same:
– Resource
– Investigate further or stop?
– Fight or flee?
23 November 2016 Copyright Nuix 2016 17
Early Case Assessment
• Numbers, Statistics & Predicting the cost of review
• Investigative Review
• Drive into facts of the data
• Fight or settle?
• Transition into review after
• Case Strategy
Triage & Tiered Processing
Copyright Nuix 2016 1923 November 2016
Triage
Copyright Nuix 2016 2023 November 2016
Tiered Processing
Tier 1
Tier 2
Tier 3
Tier 4
Metadata and Thumbnails
- Identify key files/exhibits/timelines for deeper processing
- 80-90% of the total files (no logs, for example)
Process Text, Extract Entities, Near Duplication
- Performed on tagged items (documents, communications etc.)
- 20-40% of the total files
Forensics
- Analyse registry, slack space etc.
- 1-5% of the total files
Carving
- Smart carving of unallocated clusters
- 1% of the total files
90-95% of Cases
finish here
Copyright Nuix 2016 2123 November 2016
Sample Tier 1 Processing Settings
In the ‘MIME Type Filtering’ tab deselect the following:
Spreadsheets CSV files (deselect Descendants)
System Files Microsoft Registry Decoded Data
Microsoft Registry Key
Containers Java Archive
Microsoft Registry File
No Data Inaccessible Content
Logs All
Copyright Nuix 2016 2223 November 2016
Sample Tier 2 Processing Settings
These settings will be run across only those files selected
for deeper analysis. This will populate the Full Text Indices
for those files, as well as allow for Near Duplicate
highlighting, entity extraction and analysis/linking, and
enhanced multimedia filtering.
In the ‘MIME Type Filtering’ tab deselect the following:
Spreadsheets CSV files (deselect Descendants)
System Files Microsoft Registry Decoded Data
Microsoft Registry Key
Containers Java Archive
Microsoft Registry File
No Data Inaccessible Content
Logs All
Copyright Nuix 2016 2323 November 2016
Sample Tier 3 Processing Settings
These settings are designed to bring registry analysis and file slack
examination into the investigation, only for those exhibits that
require this deeper level of interrogation.
It also prepares the Unallocated Clusters for intelligent carving by
hashing them.
In the ‘MIME Type Filtering’ tab TICK the following:
System Files Microsoft Registry Decoded Data
Microsoft Registry Key
Containers Microsoft Registry File
Depending on the investigation, you may wish to also TICK:
Containers Java Archive
No Data Inaccessible Content
Logs All
Copyright Nuix 2016 2423 November 2016
Sample Tier 4 Processing Settings
This final tier is for intelligent carving of Unallocated
Clusters.
By identifying and selecting only those ‘chunks’ of UC that
contain data (via hash comparison), carving can be
accomplished 60-80% quicker than if you were to run
carving over all of the UC.
Copyright Nuix 2016 2523 November 2016
Quality Checking Your Data
Corrupted Items/Containers
May also contain encrypted TrueCrypt containers
Non-searchable PDFs
PDFs with no text layer!
Bad Extension
Where the file extension doesn’t match the signature
Encrypted
Files/containers Nuix believes to be encrypted
Not Processed
Poisoned Items
Items that cause workers to get stuck in a loop
Early Access & Collaboration
23 November 2016 Copyright Nuix 2016 27
Early Access & Collaboration
Early Case Assessment
23 November 2016 Copyright Nuix 2016 28
Early Access & Collaboration
“Victorious warriors win first and then go to
war, while defeated warriors go to war first
and then seek to win.”
― Sun Tzu
23 November 2016 Copyright Nuix 2016 29
Early Access & Collaboration
Index
Data
Export
Data
Import
Data
Review
Data
NUIX WORKSTATION
NUIX DIRECTOR
REVIEW PLATFORM
EXPORT + REPORT
23 November 2016 Copyright Nuix 2016 30
Early Access & Collaboration
Index
Data/ECA
Review
Data
NUIX WORKSTATION
NUIX DIRECTOR
NUIX WEB REVIEW & ANALYTICS
23 November 2016 Copyright Nuix 2016 31
Early Access & Collaboration
Copyright Nuix 2015 3223 November 2016
Early Access & Collaboration
Visualisation
Copyright Nuix 2016 3423 November 2016
Visualisation
[1] Ben Shneiderman, “Research Agenda: Visual Overviews for Exploratory Search”, National Science Foundation workshop on Information Seeking Support Systems, June 26-27, 2008
“The purpose of visualisation is insight, not pictures.” [1]
Copyright Nuix 2016 3523 November 2016
Visualisation
Copyright Nuix 2016 3623 November 2016
Visualisation
Analysing Minard's Visualisation Of Napoleon's 1812 March
https://robots.thoughtbot.com/analyzing-minards-visualization-of-napoleons-1812-march
23 November 2016 Copyright Nuix 2016 37
Visualisation
• What does this tell us?
– Lots of data
– Comms in 2000, 2004, 2014
– Lots of recipients
• Much more context
– 2 key communicators
– 3 separate networks
Can this inform better
analysis & review?
23 November 2016 Copyright Nuix 2016 38
Visualisation
• A quick look reveals
– 4 primary sources
– Connect money values
– 3 Countries
– 3 Companies
• Did we expect this?
• Can this inform better
analysis & review?
23 November 2016 Copyright Nuix 2016 39
Visualisation
23 November 2016 Copyright Nuix 2016 40
Visualisation
23 November 2016 Copyright Nuix 2016 41
Visualisation
23 November 2016 Copyright Nuix 2016 42
Visualisation
23 November 2016 Copyright Nuix 2016 43
Visualisation
23 November 2016 Copyright Nuix 2016 44
Visualisation
23 November 2016 Copyright Nuix 2016 45
Visualisation
23 November 2016 Copyright Nuix 2015 46
DEMO
Automatic identification of relevant information
Visualise Links between items/suspects (Pulling a
thread)
23 November 2016 Copyright Nuix 2016 47
Visualisation
23 November 2016 Copyright Nuix 2016 48
Visualisation
Advanced ECA Techniques
Copyright Nuix 2016 5023 November 2016
Cluster Runs
Group documents and emails together
into numerous ‘clusters’ decided by
similarity or thread
Copyright Nuix 2016 5123 November 2016
Cluster Runs
Copyright Nuix 2016 5223 November 2016
Search and Tag
Allows Nuix to automatically tag
items respondent to queries
Can import/share pre-
defined S&T templates
in CSV format
Copyright Nuix 2016 5323 November 2016
Digest/Hash Lists
Digest Lists
Automatically identify files in your
dataset that match by MD5
Shingle Lists
Automatically identify near-duplicates
Word Lists
Automatically identify files containing
keywords
Fuzzy Hash Lists
Compares SSDeep hashes to identify
potential malware
Copyright Nuix 2016 5423 November 2016
Automatic Classifiers – Predictive Coding
Nuix can learn how you tag
items, and once it has built up
a sufficient model, can use
that to automatically tag un-
reviewed items.
Summary
23 November 2016 Copyright Nuix 2016 56
Early Case Assessment
Five Practical Tips for Data Analytics in Early Case Assessment
1. Find Out What You Have
2. Look for Issues in the Data
3. Learn what your key players hold
4. Answer the Who, What and When
5. Reduce the noise
23 November 2016 Copyright Nuix 2016 57
Summary
• The challenge to investigate and come to quick conclusions is will
always exist.
• The traditional approach - reading everything - is no longer an option
• The intermediate solution of coming up with keywords fails as
volumes of data continue to increase – proportionality..
• The ability of Nuix to ingest data from multiple sources, filter out
duplicates and irrelevant - and home in on the relevant – material
make it an indispensible investigation and review tool
FIND OUT MORE:
nuix.com/blog
facebook.com/nuixsoftware
linkedin.com/company/nuix
twitter.com/nuix
youtube.com/nuixsoftware
November 23, 2016 COPYRIGHT NUIX 2015 58
nuix.com
https://www.nuix.com/white-papers/early-case-assessment-evolving-from-tactical-to-practical
Your way forward
Nuix training courses are designed to help
you unlock the full potential of your Nuix
investment and achieve great results, fast.
View our course options online at:
nuix.com/training
Right tool + right way = right results faster

More Related Content

What's hot (14)

Internet
InternetInternet
Internet
 
16. Centralni nervni sistem centralna sinapsa
16. Centralni nervni sistem centralna sinapsa16. Centralni nervni sistem centralna sinapsa
16. Centralni nervni sistem centralna sinapsa
 
Gmizavci
GmizavciGmizavci
Gmizavci
 
Efekat staklene bašte
Efekat staklene bašteEfekat staklene bašte
Efekat staklene bašte
 
Ptice i gmizavci-ponavljanje
Ptice i gmizavci-ponavljanjePtice i gmizavci-ponavljanje
Ptice i gmizavci-ponavljanje
 
Šumski ekosistem
Šumski ekosistemŠumski ekosistem
Šumski ekosistem
 
Ljdska cula
Ljdska culaLjdska cula
Ljdska cula
 
Internet Nemanja
Internet NemanjaInternet Nemanja
Internet Nemanja
 
Efektori
EfektoriEfektori
Efektori
 
FIZIOLOGIJA MIŠICA
FIZIOLOGIJA MIŠICAFIZIOLOGIJA MIŠICA
FIZIOLOGIJA MIŠICA
 
20. Mozdano stablo
20. Mozdano stablo20. Mozdano stablo
20. Mozdano stablo
 
Kičmena moždina
Kičmena moždinaKičmena moždina
Kičmena moždina
 
Периферни нервни систем
Периферни нервни системПериферни нервни систем
Периферни нервни систем
 
Radu u-timu-i-upravljanje-timovima-prezentacija-i-dan
Radu u-timu-i-upravljanje-timovima-prezentacija-i-danRadu u-timu-i-upravljanje-timovima-prezentacija-i-dan
Radu u-timu-i-upravljanje-timovima-prezentacija-i-dan
 

Similar to Nuix webinar presentation: See the bigger picture faster – early case assessment (ECA) best practices

Discovering the research data alliance
Discovering the research data allianceDiscovering the research data alliance
Discovering the research data allianceJisc RDM
 
Faster document review and production
Faster document review and productionFaster document review and production
Faster document review and productionLexbe_Webinars
 
Technology tipping points Big Data and Blockchain use case presentation
Technology tipping points Big Data and Blockchain use case presentationTechnology tipping points Big Data and Blockchain use case presentation
Technology tipping points Big Data and Blockchain use case presentationVinod Kumar Nerella
 
Introduction to big data
Introduction to big data Introduction to big data
Introduction to big data Nathan Krasney
 
Using Qualitative Data Analysis tools to create a virtual tapestry of your or...
Using Qualitative Data Analysis tools to create a virtual tapestry of your or...Using Qualitative Data Analysis tools to create a virtual tapestry of your or...
Using Qualitative Data Analysis tools to create a virtual tapestry of your or...UXPA Boston
 
SplunkLive! Beginner Session
SplunkLive! Beginner SessionSplunkLive! Beginner Session
SplunkLive! Beginner SessionSplunk
 
Abuse helper app - Networkshop44
Abuse helper app - Networkshop44Abuse helper app - Networkshop44
Abuse helper app - Networkshop44Jisc
 
Systems and Services: Adding Value For Research Data Assets
Systems and Services: Adding Value For Research Data AssetsSystems and Services: Adding Value For Research Data Assets
Systems and Services: Adding Value For Research Data AssetsLIBER Europe
 
Research Data Management
Research Data ManagementResearch Data Management
Research Data ManagementZera Day
 
Getting to Grips with Research Data Management
Getting to Grips with Research Data Management Getting to Grips with Research Data Management
Getting to Grips with Research Data Management IzzyChad
 
Importance of data
Importance of dataImportance of data
Importance of dataJay Daley
 
DAMA Chicago - Ensuring your data lake doesn’t become a data swamp
DAMA Chicago - Ensuring your data lake doesn’t become a data swampDAMA Chicago - Ensuring your data lake doesn’t become a data swamp
DAMA Chicago - Ensuring your data lake doesn’t become a data swampNVISIA
 
PLOTCON NYC: Interactive Visual Statistics on Massive Datasets
PLOTCON NYC: Interactive Visual Statistics on Massive DatasetsPLOTCON NYC: Interactive Visual Statistics on Massive Datasets
PLOTCON NYC: Interactive Visual Statistics on Massive DatasetsPlotly
 
Make a case for Data Classification in your organization
Make a case for Data Classification in your organizationMake a case for Data Classification in your organization
Make a case for Data Classification in your organizationWatchful Software
 
Research at risk: developing a shared research data management service for UK...
Research at risk: developing a shared research data management service for UK...Research at risk: developing a shared research data management service for UK...
Research at risk: developing a shared research data management service for UK...Jisc RDM
 
Hardcore Data Science - in Practice
Hardcore Data Science - in PracticeHardcore Data Science - in Practice
Hardcore Data Science - in PracticeMikio L. Braun
 
Big Data Europe SC6 WS 3: Ron Dekker, Director CESSDA European Open Science A...
Big Data Europe SC6 WS 3: Ron Dekker, Director CESSDA European Open Science A...Big Data Europe SC6 WS 3: Ron Dekker, Director CESSDA European Open Science A...
Big Data Europe SC6 WS 3: Ron Dekker, Director CESSDA European Open Science A...BigData_Europe
 
White Paper - One Window - Non-US Version
White Paper - One Window - Non-US VersionWhite Paper - One Window - Non-US Version
White Paper - One Window - Non-US VersionStuart Clarke
 

Similar to Nuix webinar presentation: See the bigger picture faster – early case assessment (ECA) best practices (20)

Discovering the research data alliance
Discovering the research data allianceDiscovering the research data alliance
Discovering the research data alliance
 
Faster document review and production
Faster document review and productionFaster document review and production
Faster document review and production
 
Technology tipping points Big Data and Blockchain use case presentation
Technology tipping points Big Data and Blockchain use case presentationTechnology tipping points Big Data and Blockchain use case presentation
Technology tipping points Big Data and Blockchain use case presentation
 
Carpenter/Lagace: NISO Recommended Practices to Support Adoption of Altmetric...
Carpenter/Lagace: NISO Recommended Practices to Support Adoption of Altmetric...Carpenter/Lagace: NISO Recommended Practices to Support Adoption of Altmetric...
Carpenter/Lagace: NISO Recommended Practices to Support Adoption of Altmetric...
 
Introduction to big data
Introduction to big data Introduction to big data
Introduction to big data
 
Splunk live beginner training nyc
Splunk live beginner training nycSplunk live beginner training nyc
Splunk live beginner training nyc
 
Using Qualitative Data Analysis tools to create a virtual tapestry of your or...
Using Qualitative Data Analysis tools to create a virtual tapestry of your or...Using Qualitative Data Analysis tools to create a virtual tapestry of your or...
Using Qualitative Data Analysis tools to create a virtual tapestry of your or...
 
SplunkLive! Beginner Session
SplunkLive! Beginner SessionSplunkLive! Beginner Session
SplunkLive! Beginner Session
 
Abuse helper app - Networkshop44
Abuse helper app - Networkshop44Abuse helper app - Networkshop44
Abuse helper app - Networkshop44
 
Systems and Services: Adding Value For Research Data Assets
Systems and Services: Adding Value For Research Data AssetsSystems and Services: Adding Value For Research Data Assets
Systems and Services: Adding Value For Research Data Assets
 
Research Data Management
Research Data ManagementResearch Data Management
Research Data Management
 
Getting to Grips with Research Data Management
Getting to Grips with Research Data Management Getting to Grips with Research Data Management
Getting to Grips with Research Data Management
 
Importance of data
Importance of dataImportance of data
Importance of data
 
DAMA Chicago - Ensuring your data lake doesn’t become a data swamp
DAMA Chicago - Ensuring your data lake doesn’t become a data swampDAMA Chicago - Ensuring your data lake doesn’t become a data swamp
DAMA Chicago - Ensuring your data lake doesn’t become a data swamp
 
PLOTCON NYC: Interactive Visual Statistics on Massive Datasets
PLOTCON NYC: Interactive Visual Statistics on Massive DatasetsPLOTCON NYC: Interactive Visual Statistics on Massive Datasets
PLOTCON NYC: Interactive Visual Statistics on Massive Datasets
 
Make a case for Data Classification in your organization
Make a case for Data Classification in your organizationMake a case for Data Classification in your organization
Make a case for Data Classification in your organization
 
Research at risk: developing a shared research data management service for UK...
Research at risk: developing a shared research data management service for UK...Research at risk: developing a shared research data management service for UK...
Research at risk: developing a shared research data management service for UK...
 
Hardcore Data Science - in Practice
Hardcore Data Science - in PracticeHardcore Data Science - in Practice
Hardcore Data Science - in Practice
 
Big Data Europe SC6 WS 3: Ron Dekker, Director CESSDA European Open Science A...
Big Data Europe SC6 WS 3: Ron Dekker, Director CESSDA European Open Science A...Big Data Europe SC6 WS 3: Ron Dekker, Director CESSDA European Open Science A...
Big Data Europe SC6 WS 3: Ron Dekker, Director CESSDA European Open Science A...
 
White Paper - One Window - Non-US Version
White Paper - One Window - Non-US VersionWhite Paper - One Window - Non-US Version
White Paper - One Window - Non-US Version
 

Recently uploaded

High Class Call Girls Noida Sector 39 Aarushi 🔝8264348440🔝 Independent Escort...
High Class Call Girls Noida Sector 39 Aarushi 🔝8264348440🔝 Independent Escort...High Class Call Girls Noida Sector 39 Aarushi 🔝8264348440🔝 Independent Escort...
High Class Call Girls Noida Sector 39 Aarushi 🔝8264348440🔝 Independent Escort...soniya singh
 
20240419 - Measurecamp Amsterdam - SAM.pdf
20240419 - Measurecamp Amsterdam - SAM.pdf20240419 - Measurecamp Amsterdam - SAM.pdf
20240419 - Measurecamp Amsterdam - SAM.pdfHuman37
 
Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...
Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...
Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...Sapana Sha
 
Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)
Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)
Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)jennyeacort
 
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdf
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdfKantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdf
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdfSocial Samosa
 
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样vhwb25kk
 
ASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel CanterASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel Cantervoginip
 
Customer Service Analytics - Make Sense of All Your Data.pptx
Customer Service Analytics - Make Sense of All Your Data.pptxCustomer Service Analytics - Make Sense of All Your Data.pptx
Customer Service Analytics - Make Sense of All Your Data.pptxEmmanuel Dauda
 
EMERCE - 2024 - AMSTERDAM - CROSS-PLATFORM TRACKING WITH GOOGLE ANALYTICS.pptx
EMERCE - 2024 - AMSTERDAM - CROSS-PLATFORM  TRACKING WITH GOOGLE ANALYTICS.pptxEMERCE - 2024 - AMSTERDAM - CROSS-PLATFORM  TRACKING WITH GOOGLE ANALYTICS.pptx
EMERCE - 2024 - AMSTERDAM - CROSS-PLATFORM TRACKING WITH GOOGLE ANALYTICS.pptxthyngster
 
How we prevented account sharing with MFA
How we prevented account sharing with MFAHow we prevented account sharing with MFA
How we prevented account sharing with MFAAndrei Kaleshka
 
INTERNSHIP ON PURBASHA COMPOSITE TEX LTD
INTERNSHIP ON PURBASHA COMPOSITE TEX LTDINTERNSHIP ON PURBASHA COMPOSITE TEX LTD
INTERNSHIP ON PURBASHA COMPOSITE TEX LTDRafezzaman
 
9654467111 Call Girls In Munirka Hotel And Home Service
9654467111 Call Girls In Munirka Hotel And Home Service9654467111 Call Girls In Munirka Hotel And Home Service
9654467111 Call Girls In Munirka Hotel And Home ServiceSapana Sha
 
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Generative AI for Social Good at Open Data Science East 2024
Generative AI for Social Good at Open Data Science East 2024Generative AI for Social Good at Open Data Science East 2024
Generative AI for Social Good at Open Data Science East 2024Colleen Farrelly
 
Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...
Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...
Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...limedy534
 
Heart Disease Classification Report: A Data Analysis Project
Heart Disease Classification Report: A Data Analysis ProjectHeart Disease Classification Report: A Data Analysis Project
Heart Disease Classification Report: A Data Analysis ProjectBoston Institute of Analytics
 
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一F sss
 
dokumen.tips_chapter-4-transient-heat-conduction-mehmet-kanoglu.ppt
dokumen.tips_chapter-4-transient-heat-conduction-mehmet-kanoglu.pptdokumen.tips_chapter-4-transient-heat-conduction-mehmet-kanoglu.ppt
dokumen.tips_chapter-4-transient-heat-conduction-mehmet-kanoglu.pptSonatrach
 
Advanced Machine Learning for Business Professionals
Advanced Machine Learning for Business ProfessionalsAdvanced Machine Learning for Business Professionals
Advanced Machine Learning for Business ProfessionalsVICTOR MAESTRE RAMIREZ
 

Recently uploaded (20)

High Class Call Girls Noida Sector 39 Aarushi 🔝8264348440🔝 Independent Escort...
High Class Call Girls Noida Sector 39 Aarushi 🔝8264348440🔝 Independent Escort...High Class Call Girls Noida Sector 39 Aarushi 🔝8264348440🔝 Independent Escort...
High Class Call Girls Noida Sector 39 Aarushi 🔝8264348440🔝 Independent Escort...
 
20240419 - Measurecamp Amsterdam - SAM.pdf
20240419 - Measurecamp Amsterdam - SAM.pdf20240419 - Measurecamp Amsterdam - SAM.pdf
20240419 - Measurecamp Amsterdam - SAM.pdf
 
Call Girls in Saket 99530🔝 56974 Escort Service
Call Girls in Saket 99530🔝 56974 Escort ServiceCall Girls in Saket 99530🔝 56974 Escort Service
Call Girls in Saket 99530🔝 56974 Escort Service
 
Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...
Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...
Saket, (-DELHI )+91-9654467111-(=)CHEAP Call Girls in Escorts Service Saket C...
 
Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)
Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)
Call Us ➥97111√47426🤳Call Girls in Aerocity (Delhi NCR)
 
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdf
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdfKantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdf
Kantar AI Summit- Under Embargo till Wednesday, 24th April 2024, 4 PM, IST.pdf
 
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样
1:1定制(UQ毕业证)昆士兰大学毕业证成绩单修改留信学历认证原版一模一样
 
ASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel CanterASML's Taxonomy Adventure by Daniel Canter
ASML's Taxonomy Adventure by Daniel Canter
 
Customer Service Analytics - Make Sense of All Your Data.pptx
Customer Service Analytics - Make Sense of All Your Data.pptxCustomer Service Analytics - Make Sense of All Your Data.pptx
Customer Service Analytics - Make Sense of All Your Data.pptx
 
EMERCE - 2024 - AMSTERDAM - CROSS-PLATFORM TRACKING WITH GOOGLE ANALYTICS.pptx
EMERCE - 2024 - AMSTERDAM - CROSS-PLATFORM  TRACKING WITH GOOGLE ANALYTICS.pptxEMERCE - 2024 - AMSTERDAM - CROSS-PLATFORM  TRACKING WITH GOOGLE ANALYTICS.pptx
EMERCE - 2024 - AMSTERDAM - CROSS-PLATFORM TRACKING WITH GOOGLE ANALYTICS.pptx
 
How we prevented account sharing with MFA
How we prevented account sharing with MFAHow we prevented account sharing with MFA
How we prevented account sharing with MFA
 
INTERNSHIP ON PURBASHA COMPOSITE TEX LTD
INTERNSHIP ON PURBASHA COMPOSITE TEX LTDINTERNSHIP ON PURBASHA COMPOSITE TEX LTD
INTERNSHIP ON PURBASHA COMPOSITE TEX LTD
 
9654467111 Call Girls In Munirka Hotel And Home Service
9654467111 Call Girls In Munirka Hotel And Home Service9654467111 Call Girls In Munirka Hotel And Home Service
9654467111 Call Girls In Munirka Hotel And Home Service
 
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Defence Colony Delhi 💯Call Us 🔝8264348440🔝
 
Generative AI for Social Good at Open Data Science East 2024
Generative AI for Social Good at Open Data Science East 2024Generative AI for Social Good at Open Data Science East 2024
Generative AI for Social Good at Open Data Science East 2024
 
Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...
Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...
Effects of Smartphone Addiction on the Academic Performances of Grades 9 to 1...
 
Heart Disease Classification Report: A Data Analysis Project
Heart Disease Classification Report: A Data Analysis ProjectHeart Disease Classification Report: A Data Analysis Project
Heart Disease Classification Report: A Data Analysis Project
 
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
办理学位证中佛罗里达大学毕业证,UCF成绩单原版一比一
 
dokumen.tips_chapter-4-transient-heat-conduction-mehmet-kanoglu.ppt
dokumen.tips_chapter-4-transient-heat-conduction-mehmet-kanoglu.pptdokumen.tips_chapter-4-transient-heat-conduction-mehmet-kanoglu.ppt
dokumen.tips_chapter-4-transient-heat-conduction-mehmet-kanoglu.ppt
 
Advanced Machine Learning for Business Professionals
Advanced Machine Learning for Business ProfessionalsAdvanced Machine Learning for Business Professionals
Advanced Machine Learning for Business Professionals
 

Nuix webinar presentation: See the bigger picture faster – early case assessment (ECA) best practices

  • 1. See the Bigger Picture Faster Early Case Assessment Best Practices
  • 2. 23 November 2016 Copyright Nuix 2016 2 Presenters Aidan Jewell, Solutions Consultant, Nuix Aidan joined Nuix in 2014, bringing a decade of digital forensic investigation experience to the EMEA team. As a Solutions Consultant, Aidan is responsible for pre and post sales technical consultation, in addition to sharing his Nuix and investigations experience and expertise with clients through workshops and the Nuix Bytes YouTube channel. Carl Barron, Senior Solutions Consultant, Nuix Carl has joined the company in March 2012. He provides pre and post-sale consultancy, technical support and solution implementation. Carl brings a wide variety of knowledge in both hardware and software with an enthusiast approach to help customers improve workflows. Prior to joining Nuix, Carl worked as a Forensic Technician for a leading Litigation Support Vendor in London.
  • 3. 23 November 2016 Copyright Nuix 2016 3 Session Agenda • Introduction • Outline of current problem (Data Volumes) • What is ECA? • Benefits of ECA • Tiered Processing • Early Access & Collaboration • Visuals • Advanced ECA Features • Summary
  • 4. Outline of the current problem
  • 5. 23 November 2016 Copyright Nuix 2016 5 Data volumes and filing in 1986 1986 – back in the good old days… • Dictate, approve, and send and perhaps 50 documents per day • All documents received and carbon copies of documents sent were filed • We had desk diaries • Some firms kept a central book for attendance notes of important discussions • In a couple of days you could read into the documents – involving up to, say, 2,000 documents - 2 metres of shelf space
  • 6. 23 November 2016 Copyright Nuix 2016 6 Data volumes and filing in 2016 2016 – surrounded by technology… • Send and receive by email hundreds of documents each day, with still larger volumes of material coming in via SFTP • Copies are saved all over the place (and on multiple devices) • Yet more lurking “in the Cloud” • Jebb Bush’s email dump – 1,800,000 emails - over a kilometre of shelf space
  • 7. 23 November 2016 Copyright Nuix 2016 7 Data everywhere 1 Email from me to you…
  • 8. 23 November 2016 Copyright Nuix 2016 8 Data everywhere 1 Email from me to you…~12 copies
  • 9. Copyright Nuix 2015 923 November 2016 Data Volume Year 2000 = 20GB Hard Drive 6 Rooms
  • 10. Copyright Nuix 2015 1023 November 2016 Data Volume Year 2016 = 1TB Hard Drive 300 Rooms
  • 11. What is ECA (Early Case Assessment)?
  • 12. 23 November 2016 Copyright Nuix 2016 12 What is ECA? Definition • An industry-specific term generally used to describe a variety of tools or methods for investigating and quickly learning about a Document Collection for the purposes of estimating the risk(s) and cost(s) of pursuing a particular legal course of action. 1 • A widely abused term in which corporate data is sifted and categorised with a view to determining an organisation's exposure in the context of a dispute. The best ECA systems allow the sifting to take place within a corporation's own data store and can be used to drill down rapidly to identify the most pertinent evidentiary material and to facilitate decisions whether to litigate or settle. 2 1.Maura R. Grossman and Gordon V. Cormack, EDRM page & The Grossman-Cormack Glossary of Technology-Assisted Review, with Foreword by John M. Facciola, U.S. Magistrate Judge, 2013 Fed. Cts. L. Rev. 7 (January 2013). ↩ 2.LitSavant Ltd., Glossary, http://www.litsavant.com/full-glossary.aspx ↩
  • 13. Why Early Case Assessment?
  • 14. 23 November 2016 Copyright Nuix 2016 14 Why ECA? • Case Strategy • Reduce Risk • Reduce Cost • Fight or settle? • Drive into facts of the data • Proactively manage litigation
  • 15. 23 November 2016 Copyright Nuix 2016 15 Proportionality • Budgets are limited • Courts increasingly keen to avoid traditional, standard, disclosure • Need to cull multiple copies • Equally, where appropriate, ensure the full history of documents is recovered • Involving forensic experts to collect the documents is expensive and feels like “overkill” (and is both expensive and disruptive)
  • 16. 23 November 2016 Copyright Nuix 2016 16 Early Case Assessment • Often just a simple investigation • Over 95% of disputes settle rather than proceed to a hearing • The key issues are always the same: – Resource – Investigate further or stop? – Fight or flee?
  • 17. 23 November 2016 Copyright Nuix 2016 17 Early Case Assessment • Numbers, Statistics & Predicting the cost of review • Investigative Review • Drive into facts of the data • Fight or settle? • Transition into review after • Case Strategy
  • 18. Triage & Tiered Processing
  • 19. Copyright Nuix 2016 1923 November 2016 Triage
  • 20. Copyright Nuix 2016 2023 November 2016 Tiered Processing Tier 1 Tier 2 Tier 3 Tier 4 Metadata and Thumbnails - Identify key files/exhibits/timelines for deeper processing - 80-90% of the total files (no logs, for example) Process Text, Extract Entities, Near Duplication - Performed on tagged items (documents, communications etc.) - 20-40% of the total files Forensics - Analyse registry, slack space etc. - 1-5% of the total files Carving - Smart carving of unallocated clusters - 1% of the total files 90-95% of Cases finish here
  • 21. Copyright Nuix 2016 2123 November 2016 Sample Tier 1 Processing Settings In the ‘MIME Type Filtering’ tab deselect the following: Spreadsheets CSV files (deselect Descendants) System Files Microsoft Registry Decoded Data Microsoft Registry Key Containers Java Archive Microsoft Registry File No Data Inaccessible Content Logs All
  • 22. Copyright Nuix 2016 2223 November 2016 Sample Tier 2 Processing Settings These settings will be run across only those files selected for deeper analysis. This will populate the Full Text Indices for those files, as well as allow for Near Duplicate highlighting, entity extraction and analysis/linking, and enhanced multimedia filtering. In the ‘MIME Type Filtering’ tab deselect the following: Spreadsheets CSV files (deselect Descendants) System Files Microsoft Registry Decoded Data Microsoft Registry Key Containers Java Archive Microsoft Registry File No Data Inaccessible Content Logs All
  • 23. Copyright Nuix 2016 2323 November 2016 Sample Tier 3 Processing Settings These settings are designed to bring registry analysis and file slack examination into the investigation, only for those exhibits that require this deeper level of interrogation. It also prepares the Unallocated Clusters for intelligent carving by hashing them. In the ‘MIME Type Filtering’ tab TICK the following: System Files Microsoft Registry Decoded Data Microsoft Registry Key Containers Microsoft Registry File Depending on the investigation, you may wish to also TICK: Containers Java Archive No Data Inaccessible Content Logs All
  • 24. Copyright Nuix 2016 2423 November 2016 Sample Tier 4 Processing Settings This final tier is for intelligent carving of Unallocated Clusters. By identifying and selecting only those ‘chunks’ of UC that contain data (via hash comparison), carving can be accomplished 60-80% quicker than if you were to run carving over all of the UC.
  • 25. Copyright Nuix 2016 2523 November 2016 Quality Checking Your Data Corrupted Items/Containers May also contain encrypted TrueCrypt containers Non-searchable PDFs PDFs with no text layer! Bad Extension Where the file extension doesn’t match the signature Encrypted Files/containers Nuix believes to be encrypted Not Processed Poisoned Items Items that cause workers to get stuck in a loop
  • 26. Early Access & Collaboration
  • 27. 23 November 2016 Copyright Nuix 2016 27 Early Access & Collaboration Early Case Assessment
  • 28. 23 November 2016 Copyright Nuix 2016 28 Early Access & Collaboration “Victorious warriors win first and then go to war, while defeated warriors go to war first and then seek to win.” ― Sun Tzu
  • 29. 23 November 2016 Copyright Nuix 2016 29 Early Access & Collaboration Index Data Export Data Import Data Review Data NUIX WORKSTATION NUIX DIRECTOR REVIEW PLATFORM EXPORT + REPORT
  • 30. 23 November 2016 Copyright Nuix 2016 30 Early Access & Collaboration Index Data/ECA Review Data NUIX WORKSTATION NUIX DIRECTOR NUIX WEB REVIEW & ANALYTICS
  • 31. 23 November 2016 Copyright Nuix 2016 31 Early Access & Collaboration
  • 32. Copyright Nuix 2015 3223 November 2016 Early Access & Collaboration
  • 34. Copyright Nuix 2016 3423 November 2016 Visualisation [1] Ben Shneiderman, “Research Agenda: Visual Overviews for Exploratory Search”, National Science Foundation workshop on Information Seeking Support Systems, June 26-27, 2008 “The purpose of visualisation is insight, not pictures.” [1]
  • 35. Copyright Nuix 2016 3523 November 2016 Visualisation
  • 36. Copyright Nuix 2016 3623 November 2016 Visualisation Analysing Minard's Visualisation Of Napoleon's 1812 March https://robots.thoughtbot.com/analyzing-minards-visualization-of-napoleons-1812-march
  • 37. 23 November 2016 Copyright Nuix 2016 37 Visualisation • What does this tell us? – Lots of data – Comms in 2000, 2004, 2014 – Lots of recipients • Much more context – 2 key communicators – 3 separate networks Can this inform better analysis & review?
  • 38. 23 November 2016 Copyright Nuix 2016 38 Visualisation • A quick look reveals – 4 primary sources – Connect money values – 3 Countries – 3 Companies • Did we expect this? • Can this inform better analysis & review?
  • 39. 23 November 2016 Copyright Nuix 2016 39 Visualisation
  • 40. 23 November 2016 Copyright Nuix 2016 40 Visualisation
  • 41. 23 November 2016 Copyright Nuix 2016 41 Visualisation
  • 42. 23 November 2016 Copyright Nuix 2016 42 Visualisation
  • 43. 23 November 2016 Copyright Nuix 2016 43 Visualisation
  • 44. 23 November 2016 Copyright Nuix 2016 44 Visualisation
  • 45. 23 November 2016 Copyright Nuix 2016 45 Visualisation
  • 46. 23 November 2016 Copyright Nuix 2015 46 DEMO Automatic identification of relevant information Visualise Links between items/suspects (Pulling a thread)
  • 47. 23 November 2016 Copyright Nuix 2016 47 Visualisation
  • 48. 23 November 2016 Copyright Nuix 2016 48 Visualisation
  • 50. Copyright Nuix 2016 5023 November 2016 Cluster Runs Group documents and emails together into numerous ‘clusters’ decided by similarity or thread
  • 51. Copyright Nuix 2016 5123 November 2016 Cluster Runs
  • 52. Copyright Nuix 2016 5223 November 2016 Search and Tag Allows Nuix to automatically tag items respondent to queries Can import/share pre- defined S&T templates in CSV format
  • 53. Copyright Nuix 2016 5323 November 2016 Digest/Hash Lists Digest Lists Automatically identify files in your dataset that match by MD5 Shingle Lists Automatically identify near-duplicates Word Lists Automatically identify files containing keywords Fuzzy Hash Lists Compares SSDeep hashes to identify potential malware
  • 54. Copyright Nuix 2016 5423 November 2016 Automatic Classifiers – Predictive Coding Nuix can learn how you tag items, and once it has built up a sufficient model, can use that to automatically tag un- reviewed items.
  • 56. 23 November 2016 Copyright Nuix 2016 56 Early Case Assessment Five Practical Tips for Data Analytics in Early Case Assessment 1. Find Out What You Have 2. Look for Issues in the Data 3. Learn what your key players hold 4. Answer the Who, What and When 5. Reduce the noise
  • 57. 23 November 2016 Copyright Nuix 2016 57 Summary • The challenge to investigate and come to quick conclusions is will always exist. • The traditional approach - reading everything - is no longer an option • The intermediate solution of coming up with keywords fails as volumes of data continue to increase – proportionality.. • The ability of Nuix to ingest data from multiple sources, filter out duplicates and irrelevant - and home in on the relevant – material make it an indispensible investigation and review tool
  • 58. FIND OUT MORE: nuix.com/blog facebook.com/nuixsoftware linkedin.com/company/nuix twitter.com/nuix youtube.com/nuixsoftware November 23, 2016 COPYRIGHT NUIX 2015 58 nuix.com https://www.nuix.com/white-papers/early-case-assessment-evolving-from-tactical-to-practical
  • 59. Your way forward Nuix training courses are designed to help you unlock the full potential of your Nuix investment and achieve great results, fast. View our course options online at: nuix.com/training Right tool + right way = right results faster