Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, March 6, 2010

March Madness Linkfest #3 – Forensic Fallout

Posted on 3:27 PM by Unknown

Still got chores on the list so I’m afraid I’ll have to drop these into the blog-o-sphere a-la “pooh-sticks” and just let them drift on their own.

Let’s open the race up with the usual bundle of sticks from the Windows Incident Response Blog.  The ones listed here are those that I found particularly thoughtful, helpful, and/or engaging.

  • More Thoughts on Timeline Analysis - Windows Incident Response Blog.  Context is everything.
  • Forensic Analysis Process/Procedures - Windows Incident Response Blog.  Great basic step-through of the process.  Mirrors my own approach quite closely.
  • Timeline Analysis...do we need a standard? - Windows Incident Response Blog.  Creating an meaningful (and digestible) timeline for an incident report is a big challenge.  All the data is great for the investigator but time after time I’ve seen management and and legal’s eyes glaze over a bit.  Once you yourself have an accurate handle on the event timeline, you can then distill it down much simpler for the masses.
  • MFT Analysis - Windows Incident Response Blog. Brief highlight.
  • Links Plus - Windows Incident Response Blog.  Lots of great tips, tools, and leads here! 
  • More Links, and a Thanks - Windows Incident Response Blog.  Keydet89 is starting to do linkfests better than even me!  The intro (A Good Example) is a embarrassingly good illustration why even sysadmins and techs need to be trained in the basics of incident response…as well as having a strong in-house incident-response policy in place. (shudders).
  • Researching Artifacts - Windows Incident Response Blog. No, not the Indiana Jones kind either….
  • Forensic Incident Response: Triage of Agent.BTZ – Hogfly has a great walkthrough on a memory image analysis.  A good refresher.
  • Volume Shadow Copy Forensics.. cannot see the wood for the trees?.  And from the friend across the Pond Forensics from the sausage factory, a discussion on Volume Shadow Copies.
  • The Digital Standard: Analyzing RAM Dumps. – Lite but tasty tips on RAM dumps.
  • (IN)SECURE Magazine issue 24 released. – Yeah, not specifically forensics related but too good to pass up.
  • E-Evidence Information Center - What;s New – new whitepapers and material for security and forensics folks.  This one Virtual Machines in Forensics (PDF) by Jay Varda was interesting…
  • FireFoxForensics : woanware. An outstanding tool (among many standing) to extract info on Firefox usage.  Now updated to version 1.0.4.
  • ChromeForensics : woanware.  This one is now at version 1.0.3
  • PrefetchForensics v1.0.1 : woanware.  Great tool for investigating and exporting data regarding Windows Prefetch stores.
  • Prefetch Parser v1.4 released.  SANS Forensics blog recently posted a review of this one in action.
  • WinPrefetchView v1.05. Then there is this Nirsoft tool. Geared more for sysadmins than the forensics crew, it still also nicely is able to output results quite nicely.
  • Tableau Imager: First Look. SANS Forensic blog has a hands on review of new (free) software from Tableau that might take advantage of multi-core systems during the imaging process. Pretty cool stuff.  Only gotcha is that you have to have a Tableau imaging product first.  I’m still trying to get my approved via purchasing.  Failing that looks like I will be investing in one (Tableau T35es eSATA Forensic Bridge) for my personal collection of hardware tools…
  • TimeLord Time Utility for Forensic Analysts. – Neat little tool to help deal with system time, formats, and encoding.
  • Windows Shortcut Files in Forensic Examinations – PDF paper from Harry Parsonage updated in Nov 09 that goes into great detail on Windows shortcut files.  Great material.

Cheers!

--Claus V.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in forensics, Link Fest, security, utilities | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Utility Gumbo
    There’s a lot in this pot.  Probably something everyone can find to enjoy. I’m serving it up tonight out of the back of the truck on the s...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • Interesting Malware in Email Attempt - URL Scanner Links
    Last weekend I spent some time with extended family helping confirm for them that their on-line email account got hacked and had been used t...
  • Windows 8 Linkage: A Bit Behind the Ball
    CC attribution: behind the eight ball by Ed Schipul on flickr . OK. Confession time. I’m more than a bit exhausted this weekend. Besides a...
  • Lego MiniFig Extravaganza
    picture clipped from Wired’s clip from Gizmodo clip… Thanks in no small part to the Windows 7 RC release, XPM mode research, and a big “l...
  • This Week in Security and Forensics: Beware the cake!
    Cube Party! image used with permission from John Walker at "rockpapershotgun.com" Yeah, the cake is a Portal thing.  Let’s d...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ►  2013 (83)
    • ►  November (8)
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ▼  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ▼  March (11)
      • WinPE Multi-boot a Bootable USB Storage device
      • Dealing with the Dell … 2010 Edition
      • Not there yet, but if I click my heels together th...
      • A Census 2010 Drive By…
      • GSD Recent Comment” Sidebar link references fixed
      • Skipping Links in a Sunday Stream
      • WinPE and DISM/PEimg to boost Scratch Space (Ram D...
      • GSD Redesign (again)
      • March Madness Linkfest #3 – Forensic Fallout
      • March Madness Linkfest #2 – Windows Tips
      • March Madness Linkfest #1 – Freeware Apps
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile