4n6k.com
4n6k: Forensic FOSS: 4n6k_volatility_installer.sh - Install Volatility For Linux Automatically
http://www.4n6k.com/2014/08/forensic-foss-4n6kvolatilityinstallersh.html
Tuesday, August 26, 2014. Forensic FOSS: 4n6k volatility installer.sh - Install Volatility For Linux Automatically. These posts will consist of open source software for use in everyday forensic investigations. Of this project by @wzod. 4n6k volatility installer.sh. Is a bash script that installs Volatility 2.4 (and all dependencies) for Ubuntu Linux with one command. Why Do I Need It? An internet connection and an APT-based Linux distribution [for the time being]. This script has been tested on stock...
4n6k.com
4n6k: About
http://www.4n6k.com/p/about.html
TL;DR: I enjoy doing research and writing about it. More details on LinkedIn. I've taken up the task of learning as much as possible about digital forensics on my own time. My particular focus and interest lie within behavioral analysis of user activity/malware artifacts. Discovering the process by which a user interacts with a computer could be a key determinant in the prosecution or defense of a guilty or innocent individual - I'd say that's a pretty big deal, wouldn't you? Add me on LinkedIn. Registry...
4n6k.com
4n6k: Posts
http://www.4n6k.com/p/forensic-posts.html
Shellbags Forensics: Addressing a Misconception. Interpretation, step-by-step testing, new findings, and more). Timelines, interpretation, testing, and more). Jump List Forensics: AppIDs Part 1. Jump List Forensics: AppIDs Part 2. Jump List Forensics: AppID Master List (400 AppIDs). Forensics Quickie: PowerShell Versions and the Registry. Forensics Quickie: NTUSER.DAT Analysis (SANS CEIC 2015 Challenge #1 Write-Up). Forensics Quickie: Merging VMDKs and Delta/Snapshot Files (2 Solutions). Possible Unknown...
4n6k.com
4n6k: January 2012
http://www.4n6k.com/2012_01_01_archive.html
Sunday, January 8, 2012. Forensics Quickie: Recovering Deleted Files With Scalpel (.CR2 Photos). These posts will consist of small tidbits of useful information that can be explained very succinctly. SD card was accidentally formatted; RAW photos in .cr2 format from a Canon Rebel T3 needed to be recovered. Boot up a Linux VM (I chose Ubuntu) and install Scalpel with:. Sudo apt-get install scalpel. Check to see if the required filetype signature is supported by Scalpel by default :. Links to this post.
metadatum.wordpress.com
PST File Size Limits | MetaDatum
https://metadatum.wordpress.com/2013/06/28/pst-file-size-limits
A bit about bytes…. PST File Size Limits. On June 28, 2013. So it was late, I went home to get some sleep. Next morning, I come in and discover that the export is still running. File size is still the same, as well. I’m perplexed, to say the least. I decided to consult with my boss to see if we could figure out what was going on. It was at this point, I learned about an interesting feature of PST files. They have a size limit! Fortunately, I also learned there is a solution for this. Correct me if I’m wr...
metadatum.wordpress.com
Cookies and Tracking – Firefox | MetaDatum
https://metadatum.wordpress.com/2013/05/18/cookies-and-tracking-firefox
A bit about bytes…. Cookies and Tracking Firefox. On May 18, 2013. In this section, I would like to discuss Cookies and information Tracking in respect to Firefox. I admit, I’m a Firefox user. There is nothing to be ashamed of here, it is a great browser. One of the things I like about it is its easy and more comprehensive options for privacy. Let me show you how I do it. For those new to the settings, here is how to get to them. On a side note, another one I use is Noscript. This is a great one to h...
metadatum.wordpress.com
KeepNote | MetaDatum
https://metadatum.wordpress.com/2013/07/02/keepnote
A bit about bytes…. On July 2, 2013. So the first program I’m using it called KeepNote. So far I’m really liking it. Does not Snyc (Pro for me anyways! I can back up and restore notebooks if needed, however. You can create a nice folder structure for your notes, even tabs (which are different notebooks) for different types of content. Keeps track of times and dates (it’s not optimal, but depending on how you set up your notes, you can make this happen). Has text formatting options. Ability to attach files.
4n6k.com
4n6k: August 2014
http://www.4n6k.com/2014_08_01_archive.html
Tuesday, August 26, 2014. Forensic FOSS: 4n6k volatility installer.sh - Install Volatility For Linux Automatically. These posts will consist of open source software for use in everyday forensic investigations. Of this project by @wzod. 4n6k volatility installer.sh. Is a bash script that installs Volatility 2.4 (and all dependencies) for Ubuntu Linux with one command. Why Do I Need It? An internet connection and an APT-based Linux distribution [for the time being]. This script has been tested on stock...
4n6k.com
4n6k: February 2012
http://www.4n6k.com/2012_02_01_archive.html
Friday, February 24, 2012. Forensics Quickie: Extracting Unallocated Space with The Sleuth Kit. These posts will consist of small tidbits of useful information that can be explained very succinctly. You'd like to do a keyword search - not only within user documents, but within deleted items, as well. We will need to extract unallocated space, first and foremost. Boot up a Linux VM (I chose Ubuntu) and install The Sleuth Kit:. Sudo apt-get install sleuthkit. Sudo apt-get install xmount. 1 The Sleuth Kit.