Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Sunday, April 1, 2012

Forensic Linkfest - microwave-ready meals

Posted on 1:26 PM by Unknown

My “For-Sec” to-be-blogged pile is bustin out at the seams.

Unfortunately, I still haven’t been able to find the time to toss the meat on grill in a way that gives it justice…so as of now, that material is still slow-smoking.

In the meantime maybe you will find something noteworthy in the following links-of-note prepared for quick consumption.

NetWitness - Investigator Freeware - Version 9.7.5.4 released 03/16/12. I’ve used this NFAT tool successfully in the past, but had stopped looking for updated versions. So the other day when my one-year’s registration period had expired and I had to “re-enlist” I was advised an update was available. There are a number of free NFAT tools, and each provides its own slant. NetWitness Investigator Freeware version is a must-have tool for your assessment collection. Get the update!

MIR-ROR - This incident response toolset has now been updated to version 2.0: HolisticInfoSec: MIR-ROR 2.0 released. Sure you have to dump a few of the ingredients in the provided bowl before you bake, but it’s, well, a piece of cake. The result is a collection of tools that can speed up your assessment and information collection on a suspect system.

65 Open Source Replacements for Security Software - Datamation’s Cynthia Harvey has composed a knock-out list of great Open Source tools. I’m confident that anybody who regularly reads this blog will find something new or interesting in this list.

NAFT Release - Didier Stevens has released his Network Appliance Forensic Toolkit than can handle network appliances but also supports memory dumps of OS’s like Windows. Basically (for now) it extracts network packets from memory dumps or other devices via pattern recognition.

The Latest Version of Redline Finds Indicators of Compromise and More - Mandiant’s Redline tool has now been updated.

Brett Shavers has a number of new posts about progress in the WinFE building and toolsets.

  • Colin’s Write Protect Application- Windows Forensic Environment Blog
  • WinFE Script Updated - Windows Forensic Environment Blog

The Girl, Unallocated forensic blog has been a great source of how-to’s and advice on approaching investigations. This latest series is quite interesting.

  • Case Experience #2 - IP Theft Investigation Thought Process
  • Case Experience #2.1 - More About IP Theft Thought Process
  • Case Experience #2.2 - Let the Digging Begin
  • Case Experience #2.3 - Digging Into the Registry

Prefetch analysis posts are quite plentiful.

  • Prefetch Analysis, Revisited...Again... - Windows Incident Response blog
  • Second Look at Prefetch Files - Journey Into Incident Response blog

Corey Harrell also has a great in-depth timeline study based on Volume Shadow Copy data. Sharpen your Saw on this one!

  • Volume Shadow Copy Timeline- Journey Into Incident Response blog

We are all learning more and more as Chrome gains in popularity. SANS Computer Forensics and Incident Response blog’s “johnmmccash” has a great roundup of material in his Forensically mining new nuggets of Google Chrome post.

Finally, Security Ripcord blog’s Don C. Weber has a technical post on Hard Drive Acquisition Information Using faidds and makes some interesting observations in the process.

Cheers!

--Claus V.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Chrome/Chromium, forensics, Link Fest, malware tools, NFAT, security, software, utilities | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Utility Gumbo
    There’s a lot in this pot.  Probably something everyone can find to enjoy. I’m serving it up tonight out of the back of the truck on the s...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • Interesting Malware in Email Attempt - URL Scanner Links
    Last weekend I spent some time with extended family helping confirm for them that their on-line email account got hacked and had been used t...
  • Windows 8 Linkage: A Bit Behind the Ball
    CC attribution: behind the eight ball by Ed Schipul on flickr . OK. Confession time. I’m more than a bit exhausted this weekend. Besides a...
  • Lego MiniFig Extravaganza
    picture clipped from Wired’s clip from Gizmodo clip… Thanks in no small part to the Windows 7 RC release, XPM mode research, and a big “l...
  • This Week in Security and Forensics: Beware the cake!
    Cube Party! image used with permission from John Walker at "rockpapershotgun.com" Yeah, the cake is a Portal thing.  Let’s d...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ►  2013 (83)
    • ►  November (8)
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ▼  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ▼  April (13)
      • Forensically Sound: Quick Post #3
      • Bits and Pieces for the Admins - Quick Post #2
      • WinPE 4.0 - Quick Post #1
      • Case of the Unexplained Donut of Death
      • Bits and Pieces: Mini Link Rundown
      • Malware Analysis Resources
      • Zalman ZM-VE series Enclosures: Next-Gen Virtual ODD
      • Windows 8 Linkage: “Passage Public Metro” version
      • For-Sec LiveCD Updates
      • Tools, Tips, and Reverse-Image Searches
      • Forensic Linkfest - microwave-ready meals
      • Neat Portable File Encryption Program via the USAF!
      • No Foolin! Free Download Gold.
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile