﻿<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>theForum » The Criminal Justice System » Police  » SHPO - devices that can connect to the internet</title><generator>InstantForum 2016-2 Final</generator><description>theForum</description><link>https://forum.unlock.org.uk/</link><webMaster>theForum</webMaster><lastBuildDate>Tue, 26 May 2026 12:59:40 GMT</lastBuildDate><ttl>20</ttl><item><title>SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28600.aspx</link><description>Morning everyone, &lt;br /&gt;&lt;br /&gt;One of my SHPO conditions is to report to the police any new devices with the capability of connecting to the internet within 3 days of purchase. &lt;br /&gt;&lt;br /&gt;That’s fine and always adhered to it. &lt;br /&gt;&lt;br /&gt;I’m not tech savvy so here’s my question. &lt;br /&gt;&lt;br /&gt;I have a very old style big bulky TV, I want a new one. &lt;br /&gt;&lt;br /&gt;I know if I get a smart TV that would need to be reported, right? &lt;br /&gt;&lt;br /&gt;What about a non smart TV? The spec says it has a Ethernet connection, does that mean it’s capable of connecting to the internet and therefore I’d need to report? &lt;br /&gt;&lt;br /&gt;I’d rather be safe than sorry and just planning ahead.  </description><pubDate>Wed, 02 Sep 2020 14:07:17 GMT</pubDate><dc:creator>Mark15788</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28818.aspx</link><description>&lt;div data-id="28793" class="if-quote-wrapper" unselectable="on" data-guid="1599051192992"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28793" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28793" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28793" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;Mark15788 - 29 Aug 20 10:52 AM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28793"&gt;&lt;div class="if-quote-message-margin"&gt;Do these systems get used on everyone or just dependant on offence? My offence was not related to images and I’ve never had any software mentioned to me.I’m managed by the neighbourhood team so not even sure how much training they receive. My laptop seems to get less attention than my mobile. &lt;a class="if-quote-goto quote-link" href="#" data-id="28793"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;Hi&lt;br/&gt;&lt;br/&gt;As others say it is amazing the attitude / intruputation of the PPU to defined processes.&lt;br/&gt;&lt;br/&gt;The last of my visits - end of last year- the accompanying officer who looks at my mobile and laptop (even though I have not any IT/internet etc offences) shows concern because of my "admin" habits built over 30 odd years as an IT consultant.&amp;nbsp;&lt;br/&gt;I always clear my history on all devices including old messages and calls on my mobile for both security and operating purposes. However he is not happy and always drops a few words to see my reaction; which I ignore unless asked a direct question.&lt;br/&gt;They have asked to do a software based check on my laptop and not to delete my history which after gaining a statement that they agree I do not have a legal requirement to do so, it is a one off and as a nicety statement "they promise they are not trying to catch me out". I agreed but also asked why do it then but gained no reply.&lt;br/&gt;&lt;br/&gt;I say this not to humiliate the PPU who I believe have a horrendous role,&amp;nbsp; but really just to point out that their actions can give an air of positivity. In that they must have no other concerns so going to the extremes of searching OR their search of my laptop will show my behaviour to be better than the social normality and go on to support my case to have my SOPO/SOR discharged.&amp;nbsp;</description><pubDate>Wed, 02 Sep 2020 14:07:17 GMT</pubDate><dc:creator>JASB</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28813.aspx</link><description>&lt;div data-id="28804" class="if-quote-wrapper" unselectable="on" data-guid="1598971891906"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28804" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28804" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28804" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;Was - 1 Sep 20 11:19 AM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28804"&gt;&lt;div class="if-quote-message-margin"&gt;&lt;br/&gt;&lt;span&gt;[quote]do you really think they are trying to look good at appraisal time.?[/quote]&lt;br/&gt;&lt;/span&gt;&lt;br/&gt;If you are asking my opinion, rather than on the basis of cold hard facts. Yes. Yes I do. I have previously been involved in interfacing with the police (although not in the area of PPUs) and forces are so target driven that it is inevitable. Preventing an offence is notoriously hard to quantify and document and it looks exactly like doing nothing, but an arrest looks like they are doing something (whether or not it is justified) and which they can publicise, Each month I'd get presented with lovely charts of their activities, most of which had little effect on reducing crime.&amp;nbsp;&lt;br/&gt;&lt;br/&gt;In the area of SHPO's the wording is usually so open to interpretation that a non-intent to offend easily becomes a gotcha, so you are at the mercy of individual officers rather than official policy, and the hugely divergent behaviours documented here show this to be the case. I don't think some of them can help themselves. The only slack I'll give them is that they only have to make one mistake and it's all over the papers.&lt;a class="if-quote-goto quote-link" href="#" data-id="28804"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;Although policing in general is all about catching and arresting people, I don't think that the PPUs are measured in the same manner. Their job is to prevent reoffending, by people who have already been caught. If a PPU officer were arresting more people, that would indicate a failure on their part, to prevent reoffending, which would arguably look bad for them. Whether they realise it or not, the PPU are employed to work with ex-offenders, to help those people manage their own risks.&lt;br/&gt;&lt;br/&gt;Things that PPU are measured on, include the number of outstanding visits. Because of huge numbers on the register and big cuts to police numbers, most forces have built up a backlog of overdue visits. Reducing that backlog is now a priority for PPU teams and that is what will look good for them, at appraisal time.&lt;br/&gt;</description><pubDate>Tue, 01 Sep 2020 16:04:16 GMT</pubDate><dc:creator>punter99</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28804.aspx</link><description>&lt;br/&gt;&lt;span&gt;[quote]do you really think they are trying to look good at appraisal time.?[/quote]&lt;br/&gt;&lt;/span&gt;&lt;br/&gt;If you are asking my opinion, rather than on the basis of cold hard facts. Yes. Yes I do. I have previously been involved in interfacing with the police (although not in the area of PPUs) and forces are so target driven that it is inevitable. Preventing an offence is notoriously hard to quantify and document and it looks exactly like doing nothing, but an arrest looks like they are doing something (whether or not it is justified) and which they can publicise, Each month I'd get presented with lovely charts of their activities, most of which had little effect on reducing crime.&amp;nbsp;&lt;br/&gt;&lt;br/&gt;In the area of SHPO's the wording is usually so open to interpretation that a non-intent to offend easily becomes a gotcha, so you are at the mercy of individual officers rather than official policy, and the hugely divergent behaviours documented here show this to be the case. I don't think some of them can help themselves. The only slack I'll give them is that they only have to make one mistake and it's all over the papers.</description><pubDate>Tue, 01 Sep 2020 11:19:13 GMT</pubDate><dc:creator>Was</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28801.aspx</link><description>&lt;div data-id="28635" class="if-quote-wrapper" unselectable="on" data-guid="1598953537290"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28635" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28635" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28635" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;Was - 20 Aug 20 3:13 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28635"&gt;&lt;div class="if-quote-message-margin"&gt;&lt;div data-id="28632" class="if-quote-wrapper" unselectable="on" data-guid="1598953537290"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28632" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28632" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28632" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;Mark15788 - 20 Aug 20 2:40 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28632"&gt;&lt;div class="if-quote-message-margin"&gt;I’m not new to it no, my community order is now complete, I’m nearly 3 years In so fast approaching 2 years left on SOR and SHPO. Was just interested in the TV situation. Why would you need to take every new device to the police station? I’ve always just went the same day as delivery with the information I need and got a written confirmation from them. Hardly going to take a new TV in there to be fair. &lt;a class="if-quote-goto quote-link" href="#" data-id="28632"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;It is the capriciousness of the whole process that is worrying.&lt;br/&gt;&lt;br/&gt;I bought a new laptop, installed Windows (and nothing else) and within hours of it arriving, well within the 3 days notification period, informed my PPO and asked when they wanted me to bring it in to have the monitoring software installed. She told me I was in breach of my order and they could confiscate it. This is not true, they would need a court order to "confiscate" it, but, in my understanding they could arrest me, wait for their behaviour to be chucked out in court with no legal comeback and seize it for "examination" which could take several years.&amp;nbsp;&lt;br/&gt;&lt;br/&gt;My next laptop I took in the box straight from Argos to the police station and asked them to set it up themselves, which to be fair they did.&amp;nbsp;&lt;br/&gt;&lt;br/&gt;As others have said, they only seem interested in computers, when anyone with an inkling of the Internet of Things knows to be foolish if there is someone who really wants to continue committing offences. But protect yourself.&amp;nbsp;Who knows if your PPO suddenly wants to pad their stats because they are getting near their appraisal?&lt;a class="if-quote-goto quote-link" href="#" data-id="28635"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;Hi it is interesting how varied the actions of the PPO are across the country, I have been in three police areas, the first where I was sentenced and received my SOPO were very poor giving me an indefinite SOPO and restrictions not allowed for a internet only offence. However in the other two areas the PPO have been very pleasant inspecting my phone on one visit. Why is there such a difference across the country, do you really think they are trying to look good at appraisal time.?&lt;br/&gt;&lt;br/&gt;Neil</description><pubDate>Tue, 01 Sep 2020 10:53:29 GMT</pubDate><dc:creator>Neal</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28797.aspx</link><description>Nearly at the half way point you mean? </description><pubDate>Sun, 30 Aug 2020 15:37:10 GMT</pubDate><dc:creator>Mark15788</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28796.aspx</link><description>&lt;div data-id="28795" class="if-quote-wrapper" unselectable="on" data-guid="1598794081252"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28795" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28795" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28795" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;Mark15788 - 29 Aug 20 5:37 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28795"&gt;&lt;div class="if-quote-message-margin"&gt;Thanks for that. I’m all new to this side of stuff, even though I’m almost over the halfway point of a 5 year SHPO. I don’t even know much about my risk level, but I believe here the neighbourhood teams here are only managing low risk so I must be assessed as that. I’ve never breached and they are always saying I’m doing great. So was just very curious how different peoples experiences were. &lt;a class="if-quote-goto quote-link" href="#" data-id="28795"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;I'm the same just under a year to go.&amp;nbsp;</description><pubDate>Sun, 30 Aug 2020 14:28:26 GMT</pubDate><dc:creator>jcdmcr</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28795.aspx</link><description>Thanks for that. 

I’m all new to this side of stuff, even though I’m almost over the halfway point of a 5 year SHPO. 

I don’t even know much about my risk level, but I believe here the neighbourhood teams here are only managing low risk so I must be assessed as that. 

I’ve never breached and they are always saying I’m doing great. 

So was just very curious how different peoples experiences were. </description><pubDate>Sat, 29 Aug 2020 17:37:44 GMT</pubDate><dc:creator>Mark15788</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28794.aspx</link><description>&lt;div data-id="28793" class="if-quote-wrapper" unselectable="on" data-guid="1598717073805"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28793" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28793" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28793" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;Mark15788 - 29 Aug 20 10:52 AM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28793"&gt;&lt;div class="if-quote-message-margin"&gt;Do these systems get used on everyone or just dependant on offence? My offence was not related to images and I’ve never had any software mentioned to me.I’m managed by the neighbourhood team so not even sure how much training they receive. My laptop seems to get less attention than my mobile. &lt;a class="if-quote-goto quote-link" href="#" data-id="28793"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;I guess if they are not IT trained, they won't have access to the software. As for being offence related, I suppose it partly depends on that, partly on what your SHPO says you are not allowed to do and partly on the police's own level of concern about your risk. &lt;br/&gt;&lt;br/&gt;Their biggest worry will be indications of the SHPO being breached, but they could also be fishing for clues as to any other offences that might have been committed. &lt;br/&gt;</description><pubDate>Sat, 29 Aug 2020 17:10:12 GMT</pubDate><dc:creator>punter99</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28793.aspx</link><description>Do these systems get used on everyone or just dependant on offence? 

My offence was not related to images and I’ve never had any software mentioned to me.

I’m managed by the neighbourhood team so not even sure how much training they receive. 

My laptop seems to get less attention than my mobile. </description><pubDate>Sat, 29 Aug 2020 10:52:16 GMT</pubDate><dc:creator>Mark15788</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28792.aspx</link><description>Monitoring software and ostriage are two seperate things. Monitoring software checks your device in real time and feeds things like screenshots back to the PPU, so if you typed in one of their watchwords, it would grab a screenshot of what you were doing at the time. It is very intrusive, because it is running in the background all the time. I offered to let them install it on my device but they said they only have a small number of licences, so they weren't going to bother.&lt;br/&gt;&lt;br/&gt;Ostriage is basically taking a snapshot of what is on your device, at the time the PPU visit you. Sometimes they just do a manual check of my browsing history, but other times they insert a USB stick, which runs the ostriage software. As far as privacy is concerned, it probably comes under the very broad definition of checking or inspecting your devices, which is allowed by the SHPO.&lt;br/&gt;&lt;br/&gt;It's intended for digital forensic investigators to use, when they arrest somebody and seize their devices. The idea is to let them inspect the device for anything naughty, on the spot, rather than having to take it to a lab.&amp;nbsp; The main focus is images (obviously), and certain keywords, but it hoovers up lots of other stuff which might be useful for an investigation. How much use it is to the PPU depends on their level of IT knowledge. Mine is only really interested in the images. &lt;br/&gt;&lt;br/&gt;But by playing around with tools like osforensics, I was able to see what they see. It can be a real eye opener, to find out just how much data they can extract.&lt;br/&gt;</description><pubDate>Sat, 29 Aug 2020 09:19:34 GMT</pubDate><dc:creator>punter99</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28791.aspx</link><description>Mine says something like “if they choose to” I’m nearly at the three year point and never had anything mentioned about it. </description><pubDate>Fri, 28 Aug 2020 21:00:38 GMT</pubDate><dc:creator>Mark15788</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28790.aspx</link><description>One key thing to remember is, they are not your friends.&lt;br/&gt;They will use every tactic possible to bypass your civil rights to collect all the information so they can to use against you. &lt;br/&gt;And they get away with many things because most individuals simply do not know what rights they even have, and police exploit this.&lt;br/&gt;&lt;br/&gt;I have said it before in a previous post, but it really does frustrate me reading about people who get sentenced for dishonesty. Yet the whole justice system is entirely based on dishonesty.&lt;br/&gt;&lt;br/&gt;Far as I am concerned, if it does not state in the orders that you must have monitoring software installed then you simply are not forced to have it.&lt;br/&gt;</description><pubDate>Fri, 28 Aug 2020 19:59:46 GMT</pubDate><dc:creator>xDanx</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28789.aspx</link><description>Yeah that dies make sense. 

I’m only curious as never heard much about this side. 

Checks for me have always been literally a two minute browse of my history. 

Not sure if the actual sexual offence makes a difference to the checks they tend to do or what they look out for. </description><pubDate>Fri, 28 Aug 2020 19:24:37 GMT</pubDate><dc:creator>Mark15788</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28788.aspx</link><description>&lt;div data-id="28785" class="if-quote-wrapper" unselectable="on" data-guid="1598638827790"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28785" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28785" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28785" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;punter99 - 28 Aug 20 5:01 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28785"&gt;&lt;div class="if-quote-message-margin"&gt;I know that my PPU tried to run lazagne.exe (password stealer) on my device, but windows stopped it.&amp;nbsp; Although ostriage isn't available for downloading you could try osforensics - free 30 day trial. shows you the kind of thing ostriage can do&lt;br/&gt;&lt;br/&gt;&lt;a href="https://forums.passmark.com/osforensics-osfmount-osfclone/48008-osforensics-v8-beta-release"&gt;&lt;a href="https://forums.passmark.com/osforensics-osfmount-osfclone/48008-osforensics-v8-beta-release"&gt;https://forums.passmark.com/osforensics-osfmount-osfclone/48008-osforensics-v8-beta-release&lt;/a&gt;&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;lots of fun for techies...&lt;br/&gt;&lt;a class="if-quote-goto quote-link" href="#" data-id="28785"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;Ok the amount of information they collect is scary and I actually can't see why a lot of it is required.&amp;nbsp; Why would they need all of the wifi passwords on your machine for instance????&lt;br/&gt;</description><pubDate>Fri, 28 Aug 2020 19:21:35 GMT</pubDate><dc:creator>lotsofquer</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28787.aspx</link><description>&lt;div data-id="28786" class="if-quote-wrapper" unselectable="on" data-guid="1598636406840"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28786" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28786" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28786" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;Mark15788 - 28 Aug 20 6:33 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28786"&gt;&lt;div class="if-quote-message-margin"&gt;If your order has no requirement to install that sort of software than surely they can’t? Or does your order include that? &lt;a class="if-quote-goto quote-link" href="#" data-id="28786"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;Likely the order is to do with making devices available (for checking) - it's not actually installing any software but just running the software. The software is taking whatever they specify I would imagine and they analyse it later.&amp;nbsp; . Given punter99 mentioned that windows stopped it from stealing passwords then I'd imagine that they use anything they can regardless of legality of doing so or any privacy concerns.&lt;br/&gt;&lt;br/&gt;If you don't allow them then possibly a breach of the order (for not allowing access to devices) or you could make them do it manually meaning they are there for longer but probably not as thorough as the software.&amp;nbsp; Obviously I'll make a decision based on the situation at the time (dependant on what orders I end up subject to) but I'd imagine that I wouldn't be too happy about them stealing passwords or using automated software to take everything and anything. I'll likely make them do it manually if thats an option (obviously one they're not going to present to you or deny exists but - and I'm just spitballing here - I would think that unless your order states they can do so then you can refuse provided you make the device available for checking. Whether that means they take it away for to analyse (and probably use the software anyway but deprive you of a laptop for however many months) or not I don't know.&lt;br/&gt;</description><pubDate>Fri, 28 Aug 2020 18:48:54 GMT</pubDate><dc:creator>lotsofquer</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28786.aspx</link><description>If your order has no requirement to install that sort of software than surely they can’t? Or does your order include that? </description><pubDate>Fri, 28 Aug 2020 18:33:11 GMT</pubDate><dc:creator>Mark15788</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28785.aspx</link><description>I know that my PPU tried to run lazagne.exe (password stealer) on my device, but windows stopped it.&amp;nbsp; Although ostriage isn't available for downloading you could try osforensics - free 30 day trial. shows you the kind of thing ostriage can do&lt;br/&gt;&lt;br/&gt;&lt;a href="https://forums.passmark.com/osforensics-osfmount-osfclone/48008-osforensics-v8-beta-release"&gt;https://forums.passmark.com/osforensics-osfmount-osfclone/48008-osforensics-v8-beta-release&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;lots of fun for techies...&lt;br/&gt;</description><pubDate>Fri, 28 Aug 2020 17:01:01 GMT</pubDate><dc:creator>punter99</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28784.aspx</link><description>&lt;div data-id="28783" class="if-quote-wrapper" unselectable="on" data-guid="1598629322879"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28783" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28783" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28783" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;jcdmcr - 28 Aug 20 4:38 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28783"&gt;&lt;div class="if-quote-message-margin"&gt;&lt;div data-id="28780" class="if-quote-wrapper" unselectable="on" data-guid="1598629322879"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28780" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28780" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28780" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;lotsofquer - 28 Aug 20 4:11 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28780"&gt;&lt;div class="if-quote-message-margin"&gt;&lt;div data-id="28779" class="if-quote-wrapper" unselectable="on" data-guid="1598629322879"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28779" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28779" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28779" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;jcdmcr - 28 Aug 20 3:40 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28779"&gt;&lt;div class="if-quote-message-margin"&gt;&lt;div data-id="28778" class="if-quote-wrapper" unselectable="on" data-guid="1598629322879"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28778" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28778" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28778" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;jcdmcr - 28 Aug 20 3:16 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28778"&gt;&lt;div class="if-quote-message-margin"&gt;Hi&lt;br/&gt;I've just had a visit from my public protection office, I have file auditing turned on filled my c drive event log store in under an hour!!&amp;nbsp; I've had a look through and their tool appears to be proprietory and access a number of areas. I'm still going through the log but it appears to do the following&lt;br/&gt;Scan for all executables on your hard drive on all partitions&lt;br/&gt;Scan for all images&lt;br/&gt;Checks for any proxy usage&lt;br/&gt;Scans for all images - to what end i'm not sure. I mean does it copy them or just write the names into a text file?&lt;br/&gt;The program is called:&amp;nbsp;&lt;strong&gt;osTriage2.0.0.3.exe &lt;/strong&gt;and the event log entry is below&lt;br/&gt;There is also a helperapp that runs.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;My concern is that if the app does the following&lt;br/&gt;1 - Copies personally identifiable informaiton to an unencrypted drive&lt;br/&gt;2 - is designed to allow someone with little or no experience to run and potentially arrest someone for just ticking a box.&lt;br/&gt;&lt;br/&gt;==========================================================&lt;br/&gt;An attempt was made to access an object.&lt;br/&gt;&lt;br/&gt;Subject:&lt;br/&gt;Security ID:J***********\*****&lt;br/&gt;Account Name:james&lt;br/&gt;Account Domain:***************&lt;br/&gt;Logon ID:0x2A7F0696&lt;br/&gt;&lt;br/&gt;Object:&lt;br/&gt;Object Server:Security&lt;br/&gt;Object Type:File&lt;br/&gt;Object Name:D:\onedrive\OneDrive - **********\private\salvage\recovered\DSC02402.jpg&lt;br/&gt;Handle ID:0x840&lt;br/&gt;Resource Attributes:S:AI&lt;br/&gt;&lt;br/&gt;Process Information:&lt;br/&gt;Process ID:0x40e0&lt;br/&gt;Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\osTriage2.0.0.3.exe&lt;br/&gt;&lt;br/&gt;Access Request Information:&lt;br/&gt;Accesses:ReadData (or ListDirectory)&lt;br/&gt;&lt;br/&gt;Access Mask:0x1&lt;br/&gt;================================================&lt;br/&gt;&lt;br/&gt;It also accesses the recycle bin too&lt;br/&gt;&lt;br/&gt;A handle to an object was requested.&lt;br/&gt;&lt;br/&gt;Subject:&lt;br/&gt;Security ID:J*******&lt;br/&gt;Account Name:********&lt;br/&gt;Account ******************************&lt;br/&gt;Logon ID:0x2A7F0696&lt;br/&gt;&lt;br/&gt;Object:&lt;br/&gt;Object Server:Security&lt;br/&gt;Object Type:File&lt;br/&gt;Object Name:D:\$RECYCLE.BIN\S-1-5-21-81388288-117615736-41980065-1001\$R5TN288.JPG&lt;br/&gt;Handle ID:0x2b4&lt;br/&gt;Resource Attributes:-&lt;br/&gt;&lt;br/&gt;Process Information:&lt;br/&gt;Process ID:0x40e0&lt;br/&gt;Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\osTriage2.0.0.3.exe&lt;br/&gt;&lt;br/&gt;Access Request Information:&lt;br/&gt;Transaction ID:{00000000-0000-0000-0000-000000000000}&lt;br/&gt;Accesses:SYNCHRONIZE&lt;br/&gt;ReadData (or ListDirectory)&lt;br/&gt;ReadAttributes&lt;br/&gt;&lt;br/&gt;Access Reasons:SYNCHRONIZE:Granted byD:(A;ID;FA;;;BA)&lt;br/&gt;ReadData (or ListDirectory):Granted byD:(A;ID;FA;;;BA)&lt;br/&gt;ReadAttributes:Granted byD:(A;ID;FA;;;BA)&lt;br/&gt;&lt;br/&gt;Access Mask:0x100081&lt;br/&gt;Privileges Used for Access Check:-&lt;br/&gt;Restricted SID Count:0&lt;br/&gt;&lt;br/&gt;==========================================&lt;br/&gt;&lt;br/&gt;This is the process starting&lt;br/&gt;A new process has been created.&lt;br/&gt;&lt;br/&gt;Creator Subject:&lt;br/&gt;Security ID:***************&lt;br/&gt;Account ***************&lt;br/&gt;Account Domain:***************&lt;br/&gt;Logon ID:0x2A7F0696&lt;br/&gt;&lt;br/&gt;Target Subject:&lt;br/&gt;Security ID:NULL SID&lt;br/&gt;Account Name:-&lt;br/&gt;Account Domain:-&lt;br/&gt;Logon ID:0x0&lt;br/&gt;&lt;br/&gt;Process Information:&lt;br/&gt;New Process ID:0x29a0&lt;br/&gt;New Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\Plugins\__tmp\c5865ccc-74af-498f-bba3-6157e3a3b34b\osTriageHelperApp.exe&lt;br/&gt;Token Elevation Type:%%1937&lt;br/&gt;Mandatory Label:Mandatory Label\High Mandatory Level&lt;br/&gt;Creator Process ID:0x40e0&lt;br/&gt;Creator Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\osTriage2.0.0.3.exe&lt;br/&gt;Process Command Line:&lt;br/&gt;&lt;a class="if-quote-goto quote-link" href="#" data-id="28778"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;oh as a side note - it appeared to monitor my arp cache and dns servers!!&lt;a class="if-quote-goto quote-link" href="#" data-id="28779"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;Monitored or took a copy?&lt;br/&gt;&lt;br/&gt;The software isn't proprietary but seems to have been removed from public view (so I guess making it pseudo proprietary). Looks like you have to have law enforcement training to get a copy now. One thing I've just discovered (although not all that surprised) while looking up the software is that Windows logs everything you access and keeps it forever even if you delete a file. If you want to take a look check out Shellbag Analyzer &amp;amp; Cleaner by Goversoft. Given one of the tools on the developer of ostriage website (not goversoft btw - that was another one I found) pulls this information I'd imagine they're taking a copy of it.&lt;br/&gt;&lt;br/&gt;I guess if you have nothing to hide the only issue is the privacy intrusion and potentially some explaining to do if you happen to download something with a name that looks dodgy.&lt;br/&gt;&lt;a class="if-quote-goto quote-link" href="#" data-id="28780"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;I'm not sure - i'm guessing tho they took a copy. Its the latter that bothers me on names of files. Whos to say you access (for example) a news site or any site for that matter where they have given a dodgy name to a file...&lt;br/&gt;&lt;br/&gt;Windows only keeps the thumb cache and the search indexer.&lt;br/&gt;&lt;br/&gt;I have file auditing set up, so I log every file accessed and keep the logs..... BUT i have nothing that audits USB drives. Besides, the only way i can do it is to switch auditing on the USB drive and thats not easily done.&lt;a class="if-quote-goto quote-link" href="#" data-id="28783"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;You can turn off the thumb cache on windows. Not sure about the search indexer.&amp;nbsp; It keeps more than that - take a look at the software I mentioned above (or go directly in to the registry yourself if you don't trust it). It's all there.&amp;nbsp; That software also has the option to delete it.&lt;br/&gt;</description><pubDate>Fri, 28 Aug 2020 16:43:08 GMT</pubDate><dc:creator>lotsofquer</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28783.aspx</link><description>&lt;div data-id="28780" class="if-quote-wrapper" unselectable="on" data-guid="1598628861117"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28780" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28780" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28780" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;lotsofquer - 28 Aug 20 4:11 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28780"&gt;&lt;div class="if-quote-message-margin"&gt;&lt;div data-id="28779" class="if-quote-wrapper" unselectable="on" data-guid="1598628861117"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28779" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28779" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28779" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;jcdmcr - 28 Aug 20 3:40 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28779"&gt;&lt;div class="if-quote-message-margin"&gt;&lt;div data-id="28778" class="if-quote-wrapper" unselectable="on" data-guid="1598628861117"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28778" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28778" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28778" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;jcdmcr - 28 Aug 20 3:16 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28778"&gt;&lt;div class="if-quote-message-margin"&gt;Hi&lt;br/&gt;I've just had a visit from my public protection office, I have file auditing turned on filled my c drive event log store in under an hour!!&amp;nbsp; I've had a look through and their tool appears to be proprietory and access a number of areas. I'm still going through the log but it appears to do the following&lt;br/&gt;Scan for all executables on your hard drive on all partitions&lt;br/&gt;Scan for all images&lt;br/&gt;Checks for any proxy usage&lt;br/&gt;Scans for all images - to what end i'm not sure. I mean does it copy them or just write the names into a text file?&lt;br/&gt;The program is called:&amp;nbsp;&lt;strong&gt;osTriage2.0.0.3.exe &lt;/strong&gt;and the event log entry is below&lt;br/&gt;There is also a helperapp that runs.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;My concern is that if the app does the following&lt;br/&gt;1 - Copies personally identifiable informaiton to an unencrypted drive&lt;br/&gt;2 - is designed to allow someone with little or no experience to run and potentially arrest someone for just ticking a box.&lt;br/&gt;&lt;br/&gt;==========================================================&lt;br/&gt;An attempt was made to access an object.&lt;br/&gt;&lt;br/&gt;Subject:&lt;br/&gt;Security ID:J***********\*****&lt;br/&gt;Account Name:james&lt;br/&gt;Account Domain:***************&lt;br/&gt;Logon ID:0x2A7F0696&lt;br/&gt;&lt;br/&gt;Object:&lt;br/&gt;Object Server:Security&lt;br/&gt;Object Type:File&lt;br/&gt;Object Name:D:\onedrive\OneDrive - **********\private\salvage\recovered\DSC02402.jpg&lt;br/&gt;Handle ID:0x840&lt;br/&gt;Resource Attributes:S:AI&lt;br/&gt;&lt;br/&gt;Process Information:&lt;br/&gt;Process ID:0x40e0&lt;br/&gt;Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\osTriage2.0.0.3.exe&lt;br/&gt;&lt;br/&gt;Access Request Information:&lt;br/&gt;Accesses:ReadData (or ListDirectory)&lt;br/&gt;&lt;br/&gt;Access Mask:0x1&lt;br/&gt;================================================&lt;br/&gt;&lt;br/&gt;It also accesses the recycle bin too&lt;br/&gt;&lt;br/&gt;A handle to an object was requested.&lt;br/&gt;&lt;br/&gt;Subject:&lt;br/&gt;Security ID:J*******&lt;br/&gt;Account Name:********&lt;br/&gt;Account ******************************&lt;br/&gt;Logon ID:0x2A7F0696&lt;br/&gt;&lt;br/&gt;Object:&lt;br/&gt;Object Server:Security&lt;br/&gt;Object Type:File&lt;br/&gt;Object Name:D:\$RECYCLE.BIN\S-1-5-21-81388288-117615736-41980065-1001\$R5TN288.JPG&lt;br/&gt;Handle ID:0x2b4&lt;br/&gt;Resource Attributes:-&lt;br/&gt;&lt;br/&gt;Process Information:&lt;br/&gt;Process ID:0x40e0&lt;br/&gt;Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\osTriage2.0.0.3.exe&lt;br/&gt;&lt;br/&gt;Access Request Information:&lt;br/&gt;Transaction ID:{00000000-0000-0000-0000-000000000000}&lt;br/&gt;Accesses:SYNCHRONIZE&lt;br/&gt;ReadData (or ListDirectory)&lt;br/&gt;ReadAttributes&lt;br/&gt;&lt;br/&gt;Access Reasons:SYNCHRONIZE:Granted byD:(A;ID;FA;;;BA)&lt;br/&gt;ReadData (or ListDirectory):Granted byD:(A;ID;FA;;;BA)&lt;br/&gt;ReadAttributes:Granted byD:(A;ID;FA;;;BA)&lt;br/&gt;&lt;br/&gt;Access Mask:0x100081&lt;br/&gt;Privileges Used for Access Check:-&lt;br/&gt;Restricted SID Count:0&lt;br/&gt;&lt;br/&gt;==========================================&lt;br/&gt;&lt;br/&gt;This is the process starting&lt;br/&gt;A new process has been created.&lt;br/&gt;&lt;br/&gt;Creator Subject:&lt;br/&gt;Security ID:***************&lt;br/&gt;Account ***************&lt;br/&gt;Account Domain:***************&lt;br/&gt;Logon ID:0x2A7F0696&lt;br/&gt;&lt;br/&gt;Target Subject:&lt;br/&gt;Security ID:NULL SID&lt;br/&gt;Account Name:-&lt;br/&gt;Account Domain:-&lt;br/&gt;Logon ID:0x0&lt;br/&gt;&lt;br/&gt;Process Information:&lt;br/&gt;New Process ID:0x29a0&lt;br/&gt;New Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\Plugins\__tmp\c5865ccc-74af-498f-bba3-6157e3a3b34b\osTriageHelperApp.exe&lt;br/&gt;Token Elevation Type:%%1937&lt;br/&gt;Mandatory Label:Mandatory Label\High Mandatory Level&lt;br/&gt;Creator Process ID:0x40e0&lt;br/&gt;Creator Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\osTriage2.0.0.3.exe&lt;br/&gt;Process Command Line:&lt;br/&gt;&lt;a class="if-quote-goto quote-link" href="#" data-id="28778"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;oh as a side note - it appeared to monitor my arp cache and dns servers!!&lt;a class="if-quote-goto quote-link" href="#" data-id="28779"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;Monitored or took a copy?&lt;br/&gt;&lt;br/&gt;The software isn't proprietary but seems to have been removed from public view (so I guess making it pseudo proprietary). Looks like you have to have law enforcement training to get a copy now. One thing I've just discovered (although not all that surprised) while looking up the software is that Windows logs everything you access and keeps it forever even if you delete a file. If you want to take a look check out Shellbag Analyzer &amp;amp; Cleaner by Goversoft. Given one of the tools on the developer of ostriage website (not goversoft btw - that was another one I found) pulls this information I'd imagine they're taking a copy of it.&lt;br/&gt;&lt;br/&gt;I guess if you have nothing to hide the only issue is the privacy intrusion and potentially some explaining to do if you happen to download something with a name that looks dodgy.&lt;br/&gt;&lt;a class="if-quote-goto quote-link" href="#" data-id="28780"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;I'm not sure - i'm guessing tho they took a copy. Its the latter that bothers me on names of files. Whos to say you access (for example) a news site or any site for that matter where they have given a dodgy name to a file...&lt;br/&gt;&lt;br/&gt;Windows only keeps the thumb cache and the search indexer.&lt;br/&gt;&lt;br/&gt;I have file auditing set up, so I log every file accessed and keep the logs..... BUT i have nothing that audits USB drives. Besides, the only way i can do it is to switch auditing on the USB drive and thats not easily done.</description><pubDate>Fri, 28 Aug 2020 16:38:43 GMT</pubDate><dc:creator>jcdmcr</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28782.aspx</link><description>&lt;div data-id="28781" class="if-quote-wrapper" unselectable="on" data-guid="1598628832972"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28781" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28781" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28781" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;Mark15788 - 28 Aug 20 4:28 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28781"&gt;&lt;div class="if-quote-message-margin"&gt;So it’s just monitoring software they have installed? Is that part of your order? &lt;a class="if-quote-goto quote-link" href="#" data-id="28781"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;No - its some analysis software that they ran</description><pubDate>Fri, 28 Aug 2020 16:34:03 GMT</pubDate><dc:creator>jcdmcr</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28781.aspx</link><description>So it’s just monitoring software they have installed? 

Is that part of your order? </description><pubDate>Fri, 28 Aug 2020 16:28:53 GMT</pubDate><dc:creator>Mark15788</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28780.aspx</link><description>&lt;div data-id="28779" class="if-quote-wrapper" unselectable="on" data-guid="1598626975926"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28779" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28779" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28779" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;jcdmcr - 28 Aug 20 3:40 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28779"&gt;&lt;div class="if-quote-message-margin"&gt;&lt;div data-id="28778" class="if-quote-wrapper" unselectable="on" data-guid="1598626975926"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28778" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28778" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28778" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;jcdmcr - 28 Aug 20 3:16 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28778"&gt;&lt;div class="if-quote-message-margin"&gt;Hi&lt;br/&gt;I've just had a visit from my public protection office, I have file auditing turned on filled my c drive event log store in under an hour!!&amp;nbsp; I've had a look through and their tool appears to be proprietory and access a number of areas. I'm still going through the log but it appears to do the following&lt;br/&gt;Scan for all executables on your hard drive on all partitions&lt;br/&gt;Scan for all images&lt;br/&gt;Checks for any proxy usage&lt;br/&gt;Scans for all images - to what end i'm not sure. I mean does it copy them or just write the names into a text file?&lt;br/&gt;The program is called:&amp;nbsp;&lt;strong&gt;osTriage2.0.0.3.exe &lt;/strong&gt;and the event log entry is below&lt;br/&gt;There is also a helperapp that runs.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;My concern is that if the app does the following&lt;br/&gt;1 - Copies personally identifiable informaiton to an unencrypted drive&lt;br/&gt;2 - is designed to allow someone with little or no experience to run and potentially arrest someone for just ticking a box.&lt;br/&gt;&lt;br/&gt;==========================================================&lt;br/&gt;An attempt was made to access an object.&lt;br/&gt;&lt;br/&gt;Subject:&lt;br/&gt;Security ID:J***********\*****&lt;br/&gt;Account Name:james&lt;br/&gt;Account Domain:***************&lt;br/&gt;Logon ID:0x2A7F0696&lt;br/&gt;&lt;br/&gt;Object:&lt;br/&gt;Object Server:Security&lt;br/&gt;Object Type:File&lt;br/&gt;Object Name:D:\onedrive\OneDrive - **********\private\salvage\recovered\DSC02402.jpg&lt;br/&gt;Handle ID:0x840&lt;br/&gt;Resource Attributes:S:AI&lt;br/&gt;&lt;br/&gt;Process Information:&lt;br/&gt;Process ID:0x40e0&lt;br/&gt;Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\osTriage2.0.0.3.exe&lt;br/&gt;&lt;br/&gt;Access Request Information:&lt;br/&gt;Accesses:ReadData (or ListDirectory)&lt;br/&gt;&lt;br/&gt;Access Mask:0x1&lt;br/&gt;================================================&lt;br/&gt;&lt;br/&gt;It also accesses the recycle bin too&lt;br/&gt;&lt;br/&gt;A handle to an object was requested.&lt;br/&gt;&lt;br/&gt;Subject:&lt;br/&gt;Security ID:J*******&lt;br/&gt;Account Name:********&lt;br/&gt;Account ******************************&lt;br/&gt;Logon ID:0x2A7F0696&lt;br/&gt;&lt;br/&gt;Object:&lt;br/&gt;Object Server:Security&lt;br/&gt;Object Type:File&lt;br/&gt;Object Name:D:\$RECYCLE.BIN\S-1-5-21-81388288-117615736-41980065-1001\$R5TN288.JPG&lt;br/&gt;Handle ID:0x2b4&lt;br/&gt;Resource Attributes:-&lt;br/&gt;&lt;br/&gt;Process Information:&lt;br/&gt;Process ID:0x40e0&lt;br/&gt;Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\osTriage2.0.0.3.exe&lt;br/&gt;&lt;br/&gt;Access Request Information:&lt;br/&gt;Transaction ID:{00000000-0000-0000-0000-000000000000}&lt;br/&gt;Accesses:SYNCHRONIZE&lt;br/&gt;ReadData (or ListDirectory)&lt;br/&gt;ReadAttributes&lt;br/&gt;&lt;br/&gt;Access Reasons:SYNCHRONIZE:Granted byD:(A;ID;FA;;;BA)&lt;br/&gt;ReadData (or ListDirectory):Granted byD:(A;ID;FA;;;BA)&lt;br/&gt;ReadAttributes:Granted byD:(A;ID;FA;;;BA)&lt;br/&gt;&lt;br/&gt;Access Mask:0x100081&lt;br/&gt;Privileges Used for Access Check:-&lt;br/&gt;Restricted SID Count:0&lt;br/&gt;&lt;br/&gt;==========================================&lt;br/&gt;&lt;br/&gt;This is the process starting&lt;br/&gt;A new process has been created.&lt;br/&gt;&lt;br/&gt;Creator Subject:&lt;br/&gt;Security ID:***************&lt;br/&gt;Account ***************&lt;br/&gt;Account Domain:***************&lt;br/&gt;Logon ID:0x2A7F0696&lt;br/&gt;&lt;br/&gt;Target Subject:&lt;br/&gt;Security ID:NULL SID&lt;br/&gt;Account Name:-&lt;br/&gt;Account Domain:-&lt;br/&gt;Logon ID:0x0&lt;br/&gt;&lt;br/&gt;Process Information:&lt;br/&gt;New Process ID:0x29a0&lt;br/&gt;New Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\Plugins\__tmp\c5865ccc-74af-498f-bba3-6157e3a3b34b\osTriageHelperApp.exe&lt;br/&gt;Token Elevation Type:%%1937&lt;br/&gt;Mandatory Label:Mandatory Label\High Mandatory Level&lt;br/&gt;Creator Process ID:0x40e0&lt;br/&gt;Creator Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\osTriage2.0.0.3.exe&lt;br/&gt;Process Command Line:&lt;br/&gt;&lt;a class="if-quote-goto quote-link" href="#" data-id="28778"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;oh as a side note - it appeared to monitor my arp cache and dns servers!!&lt;a class="if-quote-goto quote-link" href="#" data-id="28779"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;Monitored or took a copy?&lt;br/&gt;&lt;br/&gt;The software isn't proprietary but seems to have been removed from public view (so I guess making it pseudo proprietary). Looks like you have to have law enforcement training to get a copy now. One thing I've just discovered (although not all that surprised) while looking up the software is that Windows logs everything you access and keeps it forever even if you delete a file. If you want to take a look check out Shellbag Analyzer &amp;amp; Cleaner by Goversoft. Given one of the tools on the developer of ostriage website (not goversoft btw - that was another one I found) pulls this information I'd imagine they're taking a copy of it.&lt;br/&gt;&lt;br/&gt;I guess if you have nothing to hide the only issue is the privacy intrusion and potentially some explaining to do if you happen to download something with a name that looks dodgy.&lt;br/&gt;</description><pubDate>Fri, 28 Aug 2020 16:11:08 GMT</pubDate><dc:creator>lotsofquer</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28779.aspx</link><description>&lt;div data-id="28778" class="if-quote-wrapper" unselectable="on" data-guid="1598625581048"&gt;&lt;a class="quote-para" unselectable="on" style="display: none;" href="#" data-id="28778" title="Move Cursor Below" contenteditable="false"&gt;&lt;span unselectable="on"&gt;+&lt;/span&gt;&lt;/a&gt;&lt;a class="quote-delete" unselectable="on" style="display: none;" href="#" data-id="28778" title="Delete Quote" contenteditable="false"&gt;&lt;span unselectable="on"&gt;x&lt;/span&gt;&lt;/a&gt;&lt;span unselectable="on" class="quote-markup"&gt;[quote]&lt;/span&gt;&lt;div unselectable="on" class="if-quote-header" contenteditable="false"&gt;&lt;div unselectable="on" class="if-quote-toggle-wrapper"&gt;&lt;a class="if-quote-toggle quote-link" href="#" data-id="28778" title=" "&gt;&lt;/a&gt;&lt;/div&gt;&lt;span unselectable="on" class="quote-markup"&gt;[b]&lt;/span&gt;jcdmcr - 28 Aug 20 3:16 PM&lt;span unselectable="on" class="quote-markup"&gt;[/b]&lt;/span&gt;&lt;/div&gt;&lt;div class="if-quote-message if-quote-message-28778"&gt;&lt;div class="if-quote-message-margin"&gt;Hi&lt;br/&gt;I've just had a visit from my public protection office, I have file auditing turned on filled my c drive event log store in under an hour!!&amp;nbsp; I've had a look through and their tool appears to be proprietory and access a number of areas. I'm still going through the log but it appears to do the following&lt;br/&gt;Scan for all executables on your hard drive on all partitions&lt;br/&gt;Scan for all images&lt;br/&gt;Checks for any proxy usage&lt;br/&gt;Scans for all images - to what end i'm not sure. I mean does it copy them or just write the names into a text file?&lt;br/&gt;The program is called:&amp;nbsp;&lt;strong&gt;osTriage2.0.0.3.exe &lt;/strong&gt;and the event log entry is below&lt;br/&gt;There is also a helperapp that runs.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;My concern is that if the app does the following&lt;br/&gt;1 - Copies personally identifiable informaiton to an unencrypted drive&lt;br/&gt;2 - is designed to allow someone with little or no experience to run and potentially arrest someone for just ticking a box.&lt;br/&gt;&lt;br/&gt;==========================================================&lt;br/&gt;An attempt was made to access an object.&lt;br/&gt;&lt;br/&gt;Subject:&lt;br/&gt;Security ID:J***********\*****&lt;br/&gt;Account Name:james&lt;br/&gt;Account Domain:***************&lt;br/&gt;Logon ID:0x2A7F0696&lt;br/&gt;&lt;br/&gt;Object:&lt;br/&gt;Object Server:Security&lt;br/&gt;Object Type:File&lt;br/&gt;Object Name:D:\onedrive\OneDrive - **********\private\salvage\recovered\DSC02402.jpg&lt;br/&gt;Handle ID:0x840&lt;br/&gt;Resource Attributes:S:AI&lt;br/&gt;&lt;br/&gt;Process Information:&lt;br/&gt;Process ID:0x40e0&lt;br/&gt;Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\osTriage2.0.0.3.exe&lt;br/&gt;&lt;br/&gt;Access Request Information:&lt;br/&gt;Accesses:ReadData (or ListDirectory)&lt;br/&gt;&lt;br/&gt;Access Mask:0x1&lt;br/&gt;================================================&lt;br/&gt;&lt;br/&gt;It also accesses the recycle bin too&lt;br/&gt;&lt;br/&gt;A handle to an object was requested.&lt;br/&gt;&lt;br/&gt;Subject:&lt;br/&gt;Security ID:J*******&lt;br/&gt;Account Name:********&lt;br/&gt;Account ******************************&lt;br/&gt;Logon ID:0x2A7F0696&lt;br/&gt;&lt;br/&gt;Object:&lt;br/&gt;Object Server:Security&lt;br/&gt;Object Type:File&lt;br/&gt;Object Name:D:\$RECYCLE.BIN\S-1-5-21-81388288-117615736-41980065-1001\$R5TN288.JPG&lt;br/&gt;Handle ID:0x2b4&lt;br/&gt;Resource Attributes:-&lt;br/&gt;&lt;br/&gt;Process Information:&lt;br/&gt;Process ID:0x40e0&lt;br/&gt;Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\osTriage2.0.0.3.exe&lt;br/&gt;&lt;br/&gt;Access Request Information:&lt;br/&gt;Transaction ID:{00000000-0000-0000-0000-000000000000}&lt;br/&gt;Accesses:SYNCHRONIZE&lt;br/&gt;ReadData (or ListDirectory)&lt;br/&gt;ReadAttributes&lt;br/&gt;&lt;br/&gt;Access Reasons:SYNCHRONIZE:Granted byD:(A;ID;FA;;;BA)&lt;br/&gt;ReadData (or ListDirectory):Granted byD:(A;ID;FA;;;BA)&lt;br/&gt;ReadAttributes:Granted byD:(A;ID;FA;;;BA)&lt;br/&gt;&lt;br/&gt;Access Mask:0x100081&lt;br/&gt;Privileges Used for Access Check:-&lt;br/&gt;Restricted SID Count:0&lt;br/&gt;&lt;br/&gt;==========================================&lt;br/&gt;&lt;br/&gt;This is the process starting&lt;br/&gt;A new process has been created.&lt;br/&gt;&lt;br/&gt;Creator Subject:&lt;br/&gt;Security ID:***************&lt;br/&gt;Account ***************&lt;br/&gt;Account Domain:***************&lt;br/&gt;Logon ID:0x2A7F0696&lt;br/&gt;&lt;br/&gt;Target Subject:&lt;br/&gt;Security ID:NULL SID&lt;br/&gt;Account Name:-&lt;br/&gt;Account Domain:-&lt;br/&gt;Logon ID:0x0&lt;br/&gt;&lt;br/&gt;Process Information:&lt;br/&gt;New Process ID:0x29a0&lt;br/&gt;New Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\Plugins\__tmp\c5865ccc-74af-498f-bba3-6157e3a3b34b\osTriageHelperApp.exe&lt;br/&gt;Token Elevation Type:%%1937&lt;br/&gt;Mandatory Label:Mandatory Label\High Mandatory Level&lt;br/&gt;Creator Process ID:0x40e0&lt;br/&gt;Creator Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\osTriage2.0.0.3.exe&lt;br/&gt;Process Command Line:&lt;br/&gt;&lt;a class="if-quote-goto quote-link" href="#" data-id="28778"&gt;&lt;span class="goto"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="quote-markup"&gt;[/quote]&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;oh as a side note - it appeared to monitor my arp cache and dns servers!!</description><pubDate>Fri, 28 Aug 2020 15:40:12 GMT</pubDate><dc:creator>jcdmcr</dc:creator></item><item><title>RE: SHPO - devices that can connect to the internet</title><link>https://forum.unlock.org.uk/FindPost28778.aspx</link><description>Hi&lt;br/&gt;I've just had a visit from my public protection office, I have file auditing turned on filled my c drive event log store in under an hour!!&amp;nbsp; I've had a look through and their tool appears to be proprietory and access a number of areas. I'm still going through the log but it appears to do the following&lt;br/&gt;Scan for all executables on your hard drive on all partitions&lt;br/&gt;Scan for all images&lt;br/&gt;Checks for any proxy usage&lt;br/&gt;Scans for all images - to what end i'm not sure. I mean does it copy them or just write the names into a text file?&lt;br/&gt;The program is called:&amp;nbsp;&lt;strong&gt;osTriage2.0.0.3.exe &lt;/strong&gt;and the event log entry is below&lt;br/&gt;There is also a helperapp that runs.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;My concern is that if the app does the following&lt;br/&gt;1 - Copies personally identifiable informaiton to an unencrypted drive&lt;br/&gt;2 - is designed to allow someone with little or no experience to run and potentially arrest someone for just ticking a box.&lt;br/&gt;&lt;br/&gt;==========================================================&lt;br/&gt;An attempt was made to access an object.&lt;br/&gt;&lt;br/&gt;Subject:&lt;br/&gt;Security ID:J***********\*****&lt;br/&gt;Account Name:james&lt;br/&gt;Account Domain:***************&lt;br/&gt;Logon ID:0x2A7F0696&lt;br/&gt;&lt;br/&gt;Object:&lt;br/&gt;Object Server:Security&lt;br/&gt;Object Type:File&lt;br/&gt;Object Name:D:\onedrive\OneDrive - **********\private\salvage\recovered\DSC02402.jpg&lt;br/&gt;Handle ID:0x840&lt;br/&gt;Resource Attributes:S:AI&lt;br/&gt;&lt;br/&gt;Process Information:&lt;br/&gt;Process ID:0x40e0&lt;br/&gt;Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\osTriage2.0.0.3.exe&lt;br/&gt;&lt;br/&gt;Access Request Information:&lt;br/&gt;Accesses:ReadData (or ListDirectory)&lt;br/&gt;&lt;br/&gt;Access Mask:0x1&lt;br/&gt;================================================&lt;br/&gt;&lt;br/&gt;It also accesses the recycle bin too&lt;br/&gt;&lt;br/&gt;A handle to an object was requested.&lt;br/&gt;&lt;br/&gt;Subject:&lt;br/&gt;Security ID:J*******&lt;br/&gt;Account Name:********&lt;br/&gt;Account ******************************&lt;br/&gt;Logon ID:0x2A7F0696&lt;br/&gt;&lt;br/&gt;Object:&lt;br/&gt;Object Server:Security&lt;br/&gt;Object Type:File&lt;br/&gt;Object Name:D:\$RECYCLE.BIN\S-1-5-21-81388288-117615736-41980065-1001\$R5TN288.JPG&lt;br/&gt;Handle ID:0x2b4&lt;br/&gt;Resource Attributes:-&lt;br/&gt;&lt;br/&gt;Process Information:&lt;br/&gt;Process ID:0x40e0&lt;br/&gt;Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\osTriage2.0.0.3.exe&lt;br/&gt;&lt;br/&gt;Access Request Information:&lt;br/&gt;Transaction ID:{00000000-0000-0000-0000-000000000000}&lt;br/&gt;Accesses:SYNCHRONIZE&lt;br/&gt;ReadData (or ListDirectory)&lt;br/&gt;ReadAttributes&lt;br/&gt;&lt;br/&gt;Access Reasons:SYNCHRONIZE:Granted byD:(A;ID;FA;;;BA)&lt;br/&gt;ReadData (or ListDirectory):Granted byD:(A;ID;FA;;;BA)&lt;br/&gt;ReadAttributes:Granted byD:(A;ID;FA;;;BA)&lt;br/&gt;&lt;br/&gt;Access Mask:0x100081&lt;br/&gt;Privileges Used for Access Check:-&lt;br/&gt;Restricted SID Count:0&lt;br/&gt;&lt;br/&gt;==========================================&lt;br/&gt;&lt;br/&gt;This is the process starting&lt;br/&gt;A new process has been created.&lt;br/&gt;&lt;br/&gt;Creator Subject:&lt;br/&gt;Security ID:***************&lt;br/&gt;Account ***************&lt;br/&gt;Account Domain:***************&lt;br/&gt;Logon ID:0x2A7F0696&lt;br/&gt;&lt;br/&gt;Target Subject:&lt;br/&gt;Security ID:NULL SID&lt;br/&gt;Account Name:-&lt;br/&gt;Account Domain:-&lt;br/&gt;Logon ID:0x0&lt;br/&gt;&lt;br/&gt;Process Information:&lt;br/&gt;New Process ID:0x29a0&lt;br/&gt;New Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\Plugins\__tmp\c5865ccc-74af-498f-bba3-6157e3a3b34b\osTriageHelperApp.exe&lt;br/&gt;Token Elevation Type:%%1937&lt;br/&gt;Mandatory Label:Mandatory Label\High Mandatory Level&lt;br/&gt;Creator Process ID:0x40e0&lt;br/&gt;Creator Process Name:\Device\HarddiskVolume12\osTriage2.0.0.3 - SOPO\osTriage2.0.0.3.exe&lt;br/&gt;Process Command Line:&lt;br/&gt;</description><pubDate>Fri, 28 Aug 2020 15:16:27 GMT</pubDate><dc:creator>jcdmcr</dc:creator></item></channel></rss>