Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, July 25, 2009

Forensic Post JuMblE Linkfest

Posted on 10:56 AM by Unknown

Really no rhyme or reason to this mad-hatter collection of forensics links.

Stuff I’ve picked up over the past month mostly for reference purposes.  Probably nothing here for most folks but maybe you will find something of interest.

  • Julie Amero case featured in new forensic book – Sunbelt Blog – Really fascinating cross link to PDF file.  Reading the (lack-of) technical knowledge or legitimate forensic evidence/methodology was stunning…as was the impact.  A must-read for any incident responder.  I’m no forensic expert but if I was on the jury I would have been climbing the walls with discomfort.  Great reading.
  • Hard Drive Errors and Replacements – SANS Computer Forensics, Investigation, and Response blog.  Ever wonder what it would take to pull the platters out of a drive and drop them into another hard-drive chassis?  Now you know!
  • Opensource forensic tools – When A Dumb Boy Learns To Write blog.  A nice collection of forensics tools in an organized list. Nice resource.
  • Forensics 101: Acquiring an Image with FTK Imager - SANS Computer Forensics, Investigation, and Response blog.  I’ve had FTK Imager in my toolbox but this was a great-reminder about how useful it can be. I should have considered this utility when I did my PGP WDE recovery exercise.
  • Unix dd command and image creation – Softpanorama.org – Very thorough reference page with lots and lots of “dd” command tips and information.
  • Windows Incident Response: Mounting a DD image – Windows Incident Response blog – Harlan gives some wonderful tips on what to do with that dd image once you got it.
  • dd (Unix) - Wikipedia, the free encyclopedia.
  • Partition Find and Mount – Another freeware tool that can mount dd images as an accessible “virtual” drive volume..
  • Tools and utilities for Windows – Utility that allows mounting of IMG/dd and other “image” files as physical devices.  Really cool and is in use on my work system..
  • Free Windows Drive tools – SANS Computer Forensics, Investigation, and Response blog.  A few more great tips on tools that sysadmins may find useful in working with drives.
  • Survey of Disk Image Storage Formats -- (PDF link) – 2006 whitepaper from the Common Digital Evidence Storage Format Working Group / Digital Forensic Research Workshop.  A bit dated but still a very good introduction to the different forensic-image file formats.  If you spend some time on the forensics blogs (or working with forensic-imaging related software), you will hear/see references to some of these different image file types.  I found this a good primer on sorting them all out..
  • Stephen Venter: Mount EWF (E01) on Linux – Stephen Venter’s blog – More tips for working with the EWF (Expert Witness Format / EnCase) image file format.

FYI,

--Claus V.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in forensics | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Utility Gumbo
    There’s a lot in this pot.  Probably something everyone can find to enjoy. I’m serving it up tonight out of the back of the truck on the s...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • Windows 8 Linkage: A Bit Behind the Ball
    CC attribution: behind the eight ball by Ed Schipul on flickr . OK. Confession time. I’m more than a bit exhausted this weekend. Besides a...
  • Interesting Malware in Email Attempt - URL Scanner Links
    Last weekend I spent some time with extended family helping confirm for them that their on-line email account got hacked and had been used t...
  • This Week in Security and Forensics: Beware the cake!
    Cube Party! image used with permission from John Walker at "rockpapershotgun.com" Yeah, the cake is a Portal thing.  Let’s d...
  • Windows 8 Linkage: “Passage Public Metro” version
    cc image credit image by david.nikonvscanon on flickr So Claus, where do you stand on Windows 8 at this point? Well, to be honest, I’m re...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ►  2013 (83)
    • ►  November (8)
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ▼  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ▼  July (17)
      • Security and Forensics Linkfest: Duck & Cover edition
      • Windows 7 Linkfest: fresh meat edition
      • BOSSIEs You Might Like!
      • Tweak SharePoint and NAS Links
      • GSD Blog Redo: v 3.0
      • Linkfest for Worship Projectionists
      • USB Tricks for Vista and Windows 7
      • Forensic Post JuMblE Linkfest
      • Video-Editing Resource Roundup
      • Focusing in on Firefox: Cleaning Edition
      • Centreware Web With Firefox Verboten? IIS Not!
      • Hell-in-a-Handbasket System Rescue – Part II File ...
      • Hell-in-a-Handbasket System Rescue – Part I: PGP WDE
      • Rainy-Day Linkfest
      • Inspiring Designs
      • Dead End Linkage
      • VAIO Upgrade – Passing it On
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile