« August 2006 | Main | October 2006 »

Side notes

IJDE is still alive!

I'm glad to see that the International Journal of Digital Evidence (IJDE) is still alive. The latest issue contains four articles, covering Windows memory forensics, mobile phone forensics, Google desktop search and protected areas of IDE hard drives.

Memory analysis

Microsoft Kernel Memory Space Analyzer

Microsoft has just released version 8.1 of its Kernel Memory Space Analyzers to the public. This program provides a lot help when analyzing Windows memory dumps in DMP format.

(more...)

Memory analysis

Problem when Dumping Memory over FireWire

Arne Vidstrom explains how dumping a PC's main memory over FireWire could cause the Memory Controller Hub of an Intel chipset to hang.

(more...)

Side notes

The Sleuth Kit for Windows

The long awaited Windows version of Brian Carrier's famous file system analysis tool The Sleuth Kit has been released on September 1, 2006.

Memory analysis

PTFinder Version 0.3.00

Version 0.3.00 of PTFinder has been released. This version adds some experimental support for XML output.

(more...)

Side notes

NIST Releases Draft on Cell Phone Forensics

NIST just released the draft version of their guidelines on cell phone forensics to the public. In about a hundred pages the document covers tools and procedures for preserving, acquiring, and examining digital evidence found on cell phones.