« March 2007 | Main | May 2007 »

Memory analysis

Memory Analysis Summary

Harlan Carvey has posted a great summary article on Windows memory analysis. In fact it is a free sample chapter from his new book on Windows Forensic Analysis.

(more...)

Lab

FTimes Version 3.8.0

Version 3.8.0 of FTimes has been released on SourceForge. This version adds support for SHA-256 hashes and some file systems, UDF among them. It also adds some more tools. Complete information is available from the changelog.

Memory analysis

XMagic to Find Processes

Brendan Dolan-Gavitt wrote in and pointed me to his fine collection of XMagic definitions. With the help of these patterns and a config file (Brendan provides a sample) FTimes can pull some information about processes from a memory dump.

(more...)

Side notes

WDFIA 2007

The 2nd Annual Workshop on Digital Forensics & Incident Analysis will take place from 27-28 August 2007, at Samos, Greece. The CfP will close on 30th of April. The workshop proceedings will be published by IEEE Computer Society Press. Additional information is available at the conference website.

NT event log

GrokEVT Version 0.4.0

GrokEVT is a set of Python scripts for reading Windows Event Log files (.evt) on Unix hosts. New in version 0.4.0 is grokevt-findlogs which carves event records from raw binary data like unallocated clusters or a memory dump.

Carving

Entropy Indicates File Boundaries

One of the problems in file carving is to properly identify the borders of the former files. This especially holds true in case of fragmentation. In their submission to the DFRWS 2006 challenge Klayton Monroe and Jay Smith of KoreLogic Security and Andy Bair of MITRE (at that time) calculate the block-wise entropy to detect file boundaries and identify blocks which are unlikely to belong to a carved file.

(more...)

Lab

The Sleuth Kit Version 2.08

Version 2.08 of The Sleuth Kit has been released. AFFlib now can be compiled in the Cygwin environment. The hfind tools to search hash sets now is also available for the Microsoft Windows platform. As usual the changelog provides a complete overview over bug fixes and API changes.

Library

IJDE Spring 2007 Issue

The Spring 2007 issue of the International Journal of Digital Evidence (IJDE) was just published.

(more...)

Memory analysis

KnTTools and KnTList released

GMG Systems, Inc. now offers KnTTools and KnTList to a limited group of prospective buyers.

(more...)

Library

Undocumented Windows 2000 Secrets - Electronic Edition

One of the few books that really helped me to get into Windows memory analysis is "Undocumented Windows 2000 Secrets" by Sven B. Schreiber. Unfortunately the book is out of print for some time. A few used copies are sold at Amazon and other internet marketplaces - at prices so high that I'm considering to invest in books instead of shares.

Fortunately Sven is so kind to provide an electronic edition of his work as a set of PDF files free of charge at his web site. Thank you very much, Sven!