sploited.blogspot.com
Sploited: SANS Forensic Artifact 1: Open/Save MRU
http://sploited.blogspot.com/2012/10/sans-forensic-artifact-1-opensave-mru.html
Wednesday, 10 October 2012. SANS Forensic Artifact 1: Open/Save MRU. As most of you would have seen by now SANS posted a fantastic forensic poster. For everybody to use which will "map a specific artifact to the analysis question that it will help to answer". Basically what that means is that SANS have 8 categories used to determine an analysis question. "Was the file opened? SANS lists the following information within the poster. Called SANS ForensicArtifact1 MRU 1.txt and SANS ForensicArtifact1 MRU...
sploited.blogspot.com
Sploited: SANS Forensic Artifact 6: UserAssist
http://sploited.blogspot.com/2012/12/sans-forensic-artifact-6-userassist.html
Thursday, 27 December 2012. SANS Forensic Artifact 6: UserAssist. I'm a little late to say this but firstly Happy Christmas to my readers out there. I've been fortunate enough to have a little time off but still find myself working the Christmas / New Year period. I hope some of you have more time off and can catch up on some of those tasks you've been avoiding. For today we're moving onto the new category. GUI-based programs launched from the desktop are tracked in the launcher on a Windows System.
writeblocked.info
DFIROnline Updates
http://www.writeblocked.info/index.php/18-dfironline-updates.html
Resources for learning python for forensics. This is just a small collection of the resources that are available if you are interested in. Filegen - file generator for tool testing. One of my students is currently researching data recovery on solid state drives. Part of the. February and March recordings posted. I have just posted the recordings of the February and March meetups to the youtube channel (. Tonight we will have the first 5 minute challenge on DFIROnline. The idea behind this is to have.
writeblocked.net
DFIROnline Updates
http://www.writeblocked.net/index.php/18-dfironline-updates.html
Resources for learning python for forensics. This is just a small collection of the resources that are available if you are interested in. Filegen - file generator for tool testing. One of my students is currently researching data recovery on solid state drives. Part of the. February and March recordings posted. I have just posted the recordings of the February and March meetups to the youtube channel (. Tonight we will have the first 5 minute challenge on DFIROnline. The idea behind this is to have.
unchainedforensics.blogspot.com
Unchained Forensics: September 2011
http://unchainedforensics.blogspot.com/2011_09_01_archive.html
Why be "chained" to commercial forensic tools? Better yet, wouldn't it be comforting to sit in court knowing you can explain WHY and HOW you found evidence. I believe commercial tools have their place, but knowing what is under the hood is too important to ignore. Friday, September 30, 2011. 1 Before you ever ACCEPT the engagement. The next two items go hand in hand. 2 Make sure you know the final result the client is expecting. 3 Make sure you know what YOUR final result is expected to be. A couple of n...
mikeahrendt.blogspot.com
Student of Security: January 2012
http://mikeahrendt.blogspot.com/2012_01_01_archive.html
Topics Related to the Field of InfoSecurity and Forensics. Monday, January 16, 2012. About his new script, I decided I would share my tool as well since it's a small way I can contribute to the community I love. I've posted the project on Google Code here:. Http:/ code.google.com/p/triage-ir/. This is the structure of the Tool folder as it should be seen, or at least similar:. The script is designed to perform basic triage commands, as well as acquire evidence automatically on the system. I designed ...
unchainedforensics.blogspot.com
Unchained Forensics: Musings and Reading Notes
http://unchainedforensics.blogspot.com/2011/08/musings-and-reading-notes.html
Why be "chained" to commercial forensic tools? Better yet, wouldn't it be comforting to sit in court knowing you can explain WHY and HOW you found evidence. I believe commercial tools have their place, but knowing what is under the hood is too important to ignore. Monday, August 15, 2011. Musings and Reading Notes. I am currently actively reading or rereading 3 such books. Mt method of "reading" was cultivated years ago from the book, "How to Read a Book". Written by Harlen Carvey of blogging. Harlen get...
unchainedforensics.blogspot.com
Unchained Forensics: July 2011
http://unchainedforensics.blogspot.com/2011_07_01_archive.html
Why be "chained" to commercial forensic tools? Better yet, wouldn't it be comforting to sit in court knowing you can explain WHY and HOW you found evidence. I believe commercial tools have their place, but knowing what is under the hood is too important to ignore. Monday, July 25, 2011. Why another Digital Forensics Blog? A to take it a step further, how about we practice, test, and PLAY to locate and find the weaknesses and develop out tools even faster and in a more targeted fashion. Remember Clint Eas...
unchainedforensics.blogspot.com
Unchained Forensics: August 2011
http://unchainedforensics.blogspot.com/2011_08_01_archive.html
Why be "chained" to commercial forensic tools? Better yet, wouldn't it be comforting to sit in court knowing you can explain WHY and HOW you found evidence. I believe commercial tools have their place, but knowing what is under the hood is too important to ignore. Monday, August 15, 2011. Musings and Reading Notes. I am currently actively reading or rereading 3 such books. Mt method of "reading" was cultivated years ago from the book, "How to Read a Book". Written by Harlen Carvey of blogging. Harlen get...
unchainedforensics.blogspot.com
Unchained Forensics: Lessons Learned
http://unchainedforensics.blogspot.com/2011/09/lessons-learned.html
Why be "chained" to commercial forensic tools? Better yet, wouldn't it be comforting to sit in court knowing you can explain WHY and HOW you found evidence. I believe commercial tools have their place, but knowing what is under the hood is too important to ignore. Friday, September 30, 2011. 1 Before you ever ACCEPT the engagement. The next two items go hand in hand. 2 Make sure you know the final result the client is expecting. 3 Make sure you know what YOUR final result is expected to be. This is a gre...