# Forensic Analysis and Remote Evidence Recovery from Syncthing: An Open Source Decentralised File Synchronisation Utility

Canonical URL: https://markscanlon.co/publications/ForensicAnalysisAndRemoteEvidenceRecoveryFromSyncthing

CSL-JSON: https://markscanlon.co/publications/ForensicAnalysisAndRemoteEvidenceRecoveryFromSyncthing.csl.json
BibTeX: https://markscanlon.co/publications/ForensicAnalysisAndRemoteEvidenceRecoveryFromSyncthing.bib
RIS: https://markscanlon.co/publications/ForensicAnalysisAndRemoteEvidenceRecoveryFromSyncthing.ris

Authors: Conor Quinn; Mark Scanlon; Jason Farina; M-Tahar Kechadi
Venue: Digital Forensics and Cyber Crime
Year: 2015
DOI: https://doi.org/10.1007/978-3-319-25512-5_7
PDF: https://markscanlon.co/publications/ForensicAnalysisAndRemoteEvidenceRecoveryFromSyncthing.pdf
Full text: https://markscanlon.co/publications/ForensicAnalysisAndRemoteEvidenceRecoveryFromSyncthing.full.md

## Contribution Summary

This research contributes to the field of digital forensics by providing a comprehensive analysis of Syncthing, a decentralized file synchronization utility. The authors present a forensic analysis of the Syncthing client, its communication protocols, and its peer discovery methods. They also develop a proof-of-concept tool, Synchronisation Service Evidence Retrieval Tool (SSERT), for remote evidence recovery from Syncthing. The study highlights the importance of digital forensics procedures in addressing the challenges posed by decentralized services like Syncthing. The authors' work provides a valuable contribution to the field of digital forensics, particularly in the context of cloudless file synchronization services.

## Abstract

Commercial and home Internet users are becoming increasingly concerned with data protection and privacy. Questions have been raised regarding the privacy afforded by popular cloud-based file synchronisation services such as Dropbox, OneDrive and Google Drive. A number of these services have recently been reported as sharing information with governmental security agencies without the need for warrants to be granted. As a result, many users are opting for decentralised (cloudless) file synchronisation alternatives to the aforementioned cloud solutions. This paper outlines the forensic analysis and applies remote evidence recovery techniques for one such decentralised service, Syncthing.

