
Cryptocurrency Investigations and Tools

If you believe you may have been a victim of a cryptocurrency scam and need to gather evidence to support a police complaint, Orion Investigations may be able to help.
A cryptocurrency blockchain is a decentralized public digital ledger that exists across a network which contains details of cryptocurrency transactions.
In order to conduct investigations, Orion’s Director of Computer Forensics Services Andrew Smith has developed Blockchain Detective, an investigation tool that simplifies the downloading of cryptocurrency transactions. It automatically generates a visual representation of the transactions (one node per unique address) making it easy to follow the flow of cryptocurrency from one address to the next and automatically identifies exchange addresses.
If you have become a victim of a crypto scam, contact Orion to see how we can assist.
Read full article ==> Cryptocurrency Investigations
Email : forensics@orionforensics.com
Line ID : orionforensics
Mobile Phone : +66(0)89-960-5080

Responding to a RANSOMWARE ATTACK
Responding to a RANSOMWARE ATTACK
When a company becomes a victim of a ransomware attack they will often contact Orion to ask if we can recover their encrypted data. In almost every case the answer is going to be no as we will not have access to a recovery key to decrypt the data. Therefore, it is vital that the company maintains up to date backups of their data.
The number of ransomware attacks continue to rise year on year. According to the Verizon 2022 Data Breach Investigation Report there was a 13% increase in ransomware attacks and ransomware was involved in 25% of all breaches.
One of the trends now employed by the attackers is the double extortion method. The attackers gain access to the network and steal the confidential data. They will then encrypt the data on the network and demand a ransom to be paid to decrypt the data. If the victim has the data backed up and refuses to pay the ransom, the attackers will then threaten to release the data online.
When a company falls victim to a ransomware attack the natural response is to wipe the infected machine and restore the data in order to get up and running again as quickly as possible. As a result, attackers will often use ransomware as a way to destroy any evidence of a data breach after they have extracted the data from the network.
It is therefore important for the company to conduct a thorough investigation even if the encrypted data cannot be recovered.
The purpose of the investigation is to preserve potential evidence in order to:
- Identify how the system came to be infected with ransomware
- Identify if any confidential data has been extracted from the system
- Provide answers to the regulatory authorities and show you have taken reasonable steps to prevent a repeat
- Preserve the data in case decryption keys are released at a later date
If you become a victim of a ransomware attack, how should you respond?
- Do not shut down the infected devices
- Disconnect the infected devices from network
- Preserve logs such as Firewall, VPN, anti-virus logs or any other logs which can be saved
- Document all information pertaining to the ransomware attack
- Photo or copy of the ransom demand note/splash screen
- Ransomware variant name if known
- The file extension of encrypted files
- The date and time of the attack
- The file naming scheme for the ransom note/readme file left by attacker
- Any email addresses or URL or other method provided by the attacker for communications
- Required payment method/bitcoin addresses provided by the attacker
- Ransom amount demanded if known
What information will the investigators need to know from you?
- Number of devices affected
- Type of devices, make, model, size of hard drive
- What OS is on the devices
- Is there encryption on devices and If so what encryption and can IT provide a recovery key?
- Location of devices
- Timeline of events
- Details of ransomware
It is important to respond quickly and get the investigators onsite as soon as possible so that they can begin the process of preserving potential evidence from the infected devices. This will include not only the data from the hard drives and logs but also volatile data such as RAM memory which can provide a wealth of information such as network connections, open ports and destination IP addresses.
We would therefore recommend that you do not wait until you become a victim of a ransomware attack before deciding which investigation company you wish to work with. Do your research, due diligence and complete the vendor onboarding process before an attack occurs. This will ensure a quick response and prevent the loss of any potential evidence.
The Analysis Process Infographic

The Article provided by – Andrew Smith – Director of Computer Forensics Services
Email : forensics@orionforensics.com
Line ID : orionforensics
Mobile Phone : +66(0)89-960-5080
Download Article => RESPOND TO A RANSOMWARE ATTACK
vc_column_text]

Online Trainings-Cyber Security Training For Managers (1DAY)
While cyber threats may not be in your control, your cyber security strategy is and you should be looking at a risk-based approach. This cyber security training course prepares managers and senior executives to understand, assess, and take a proactive approach in cyber security.
What you will learn from this course :
- Gain the knowledge of the threats faced by organizations and where they come from,
- what is required to create a Cyber Security Compliance Program,
- what is a Cyber Risk Assessment and why it is needed, how to rate your level of risk and how to perform a Cyber Risk Assessment.
- You will also cover what is a Cybersecurity Framework and what is required to prepare an Incident Response Plan.
- The course is a theory [Non-Technical]based course supported by group discussions and several exercises.
Who Should Attend:
Candidates should have a general awareness of information security and the need to respond to such events.
- Executives
- Incident managers
- IT managers
- Security officers
- Data Protection Officers (DPO)
- Manager – Compliance
Date & Time : Due to COVID this course is currently being run as an online course. Please contact us for further details.
Course conten
- Introduction
- Why is it Necessary to Protect Against Cyber Security Threats?
- Data Breach Trends
- Define What is a Cyber Threat
- Where do Cyber Threats Come from?
- Examples of Cyber Threats
- What is Cyber Security Compliance?
- 5 Steps to Creating a Cyber Security Compliance Program
- What is a Cyber Risk Assessment?
- Why Perform a Cyber Risk Assessment?
- What is Risk?
- Risk Assessment Model
- How to Perform a Cyber Risk Assessment?
- Cybersecurity Frameworks
- NIST Cybersecurity Framework
- Cyber Assessment Framework
- Preparing an Incident Response Plan
ภาพถ่ายบรรยากาศการฝึกอบรม

[Hands-on Workshop] Forensic Techniques for Auditors (1 DAY)
🔍 Is Your Organization Ready to Manage Software Copyright Risks?
If you have questions about
- Using software legally within your organization
- Auditing and identifying unauthorized software
- Evidence examination in software copyright infringement cases
- Responding when your organization receives a software copyright infringement notice
- How to collect and preserve digital evidence for use in legal proceedings
Key Point:
A 1-day training course for IT Auditors who want to learn how to apply forensic techniques (Digital Forensics) to enhance existing audit processes. This course includes extensive practical exercises designed to demonstrate the learning objectives.
What you will learn in this course:
- Participants will learn basic forensic techniques for acquiring and preserving data using forensic methods, as well as how to handle electronic evidence
- Participants will learn how to identify installed software, programs executed on a system, how to extract historical information from the file system, and how to identify hidden user activities
Objectives:
- Understand digital forensic methods and tools used to support digital evidence examination processes
- Learn about sources of digital evidence, computer-related evidence, and related devices
- Learn how to examine traces of computer usage history
- Learn how to search for and identify user activities and behavior on a computer
Course Level:
This course is suitable for auditors who want to learn how to apply basic forensic techniques to enhance existing audit processes. No prior experience is required.
What Participants Will Gain 💡
- Understand the principles of Digital Forensics and digital evidence examination
- Learn the legal considerations related to electronic evidence
- Be able to examine software installed and previously executed on a computer
- Understand how to preserve evidence in its original condition so that it can be used in court, including how to handle electronic evidence, preserve it, and perform forensic data extraction
- Become familiar with tools used for forensic evidence acquisition (Forensic Acquisition Tools)
- Understand basic traces created by users by analyzing files or historical records generated by the operating system, including analysis of program usage through Windows Registry, Event Logs, and various artifacts
- Be able to examine USB storage connections and user activities
- Enhance investigation and analysis skills for incidents related to software copyright infringement
Who Should Attend: IT Auditor
- No prior Computer Forensics background is required
Corporate Training:
- In-House Training only
- Fees are charged on a daily rate basis
- Recommended number of participants: 5–10 persons (for larger groups, please contact Sales directly)
————————
Training Date and Time:
![]()
1-day course, 9:00 AM – 4:00 PM Conducted at the client’s organization only (In-House Training only )
Course Content
- Introduction
- Define Digital Forensics
- Legal Consideration
- Evidence Handling & Chain of Custody and Chain of Custody
- How Courts Assess the Integrity of Digital Evidence
- Good Practice Guidelines for Digital Evidence
- The Four Principles of Computer Based Evidence
- Forensic Acquisitions
- Forensic Acquisition Tools
- Windows Registry
- Identifying Installed Software
- Volume Shadow Copies
- Identifying Executed Programs
- Link File Analysis
- USB Forensics
- Searching the Registry
- Event Logs

Cancellation Policy
- Payment is due upon registration
- Delegates who cancel after registration, or who don’t attend, are liable to pay the full course fee and no refunds can be given
- We reserve the right to postpone or cancel a training course at any time.
- If a training course is cancelled by us, we will inform all registered delegates on the course as soon as possible. Upon the cancellation of a course, we will offer to each delegate a full refund for the cost of the course or alternative dates for the course.
- We will not be held liable for any expenses, either direct or indirect, or for loss of time, earnings or business, incurred as a result of a postponed or cancelled course.
Training Atmosphere Photos

Hands-on Workshop |Digital Forensics Foundation Course 4 Days Organized by Tech Direct Co., Ltd.
Orion Forensics has organized training course Hands-on Workshop Digital Forensics Foundation Training Course – 4 DAYS on 20th – 23rd December 2022
Tech Direct Co., Ltd. organized the Hands-on Workshop Digital Forensics Foundation Training Course – 4 DAYS on 20th – 23rd December 2022.
A 4-day practical training course for National Intelligence Agency Thailand and police who are responsible for digital forensic investigations.
- The course is aimed for people wishing to become digital forensic investigators or wishing to update their forensic skills.
- The course is designed by digital forensic experts with many years’ experiences both domestically and internationally.
- The training provides a solid foundation in forensic principles and techniques reinforced by practical hands-on exercises using a wide range of free and open-source forensic tools.

The In-House \ On-Site Training available -please contact Digital Forensics Team directly at forensics@orionforensics.com





Orion Forensics Investigations Participated in Cyber Defense Initiative Conference (CDIC) 2022
On November 9-10, 2022, Orion Forensics Investigations Participated in the Cyber Defense Initiative Conference CDIC 2022 at the BITEC Exhibition and Convention Center.
CDIC is the largest cybersecurity conference and presentation in Thailand.
There were many government and private sectors participating in the meeting.


Organizing this event The presentation under the theme
“Optimizing Security of Things and Digital Supply Chain Risk”
The event is important in enhancing security potential in various areas such as;
- The Importance of empowering cybersecurity for connected IoT devices
- Risk management in the digital information
- Blockchain, AI-powered, Quantum technology advancements are applied both positively in defense and negatively in attack.
- Major changes to the new version of ISO/IEC 27002 include the “Information Security, Cybersecurity & Privacy Protection” controls for ISO/IEC 27001 (ISMS) certification organizations to know when implementing them.
- Promulgation of law Cyber Security Act and Personal Data Protection Act, Etc.

Over two days, Orion Forensics Investigations participated in the event as set up booth, give away prizes to attendees and discuss Digital Forensics Services and Digital Forensics Training Courses, as well as build relationships with other cybersecurity leaders in attendance.
Although, Orion Forensics Investigations has brought and presented sample of equipment in work – related in Digital Forensics, both in terms of software and hardware for study and experiment purposely.

Read More

Hands-on Workshop |Digital Forensics Foundation Course 4 Days to GrowPro Consulting & Services Co.,Ltd.
Orion Forensics LAB has organized training course On-Site| hands-on Workshop Digital Forensics Foundation Training Course (4 DAYS) for GrowPro Consulting & Services Co.,Ltd. on 6th – 9th September 2022
A 4 day practical training course for people who are responsible for digital forensic investigations or are wishing to become a digital forensic investigator. The course will provide a solid foundation in the understanding of digital forensics principles and techniques. Each subject is covered in depth and supported by practical scenario based exercises to reinforce the learning points.
As required from expertise, Orion Forensics lab had adapted the curriculum to meet the professional workload of Cloud data collection, Malware Analysis and the Volatility Framework to analyze RAM Memory.
Hands-on Workshop Digital Forensics Foundation Training Course (4 DAYS) Digital Forensics Foundation Training Course 4 Days



In-House \ On-Site Training available -please contact sales directly at forensics@orionforensics.com
][/vc_row]</p>
Read MoreOffences according to the 2007 Computer Crime Act , Judgement of the Supreme Court 2600/2563
Offences according to the 2007 Computer Crime Act section 3 and 7, Judgement of the Supreme Court 2600/2563”A case study of an ex-employee who illegally accessed their company email account after have resigned from the company
Read MoreEXPERT WITNESSES – THEIR ROLE & RESPONSIBILITIES
With the Johnny Depp vs Amber Heard trial currently underway and being broadcast live around the world, I thought now would be an appropriate time to discuss what an expert witness is and what their role & responsibilities are.
Read More
Digital Forensics Training to Tokio Marine Life Insurance (Thailand) PCL.
Orion Forensics was invited to conduct a 2-day course training to Tokio Marine Life Insurance (Thailand) PCL. On the first day was an online class ,The training course was Digital Evidence – Unlocking the Secrets, which is a theory course throughout the training. The 2nd day of Training was an In-House Class, which is Workshop class – Forensic Techniques for Auditor -This course is a one day workshop for It /Auditor /Fraud Analyst or those who working on fraud investigations or Who works related to digital evidence. the event hold on 3rd-4th March 2022 .The Location is S31 Sukhumvit Hotel.
Orion Forensics would like to thank Tokio Marine Life Insurance (Thailand) PCL. for giving us the opportunity to lecture and educate employees to upskill of digital forensics and are able to apply digital forensics techniques to adapt to the current work.
Course Training Activity




Day1 (Online Class ,Participants 26 Person) and Day 2 (In-House Class, Participants 15 Person).
All Course Training CLICK
Read More



