November 2007 Archives

PTFinder Version 0.3.05

I'm excited to release version 0.3.05 of PTFinder to the public. This version fixes an endianess issue. It provides support for dumps that where obtained while under the effect of the Intel Physical Address Extension (PAE). Also there's a ready-to-run binary available for the Microsoft Windows platform.

Carving MFT Entries from Memory Images

Lance Mueller has released an EnScript that searches a memory dump for MFT entries.

Blog about EnScript

| 2 Comments

Guidance Software's EnCase provides the forensic examiner with a powerful scripting language, called EnScript. Beside the vendor-operated fora there's not much information about EnScript circulating in the net. A blog by Lance Mueller fills some need here.

10/18/2011: Unfortunately Lance Mueller has decided to close his blog. The content will be accessible, though.

Live-response on SUN Solaris

Evtim Batchev of SUN Iberia presented about live-response on the SUN Solaris platform at the 22nd TF-CSIRT meeting. His slides cover several data structures of the Solaris kernel and how they can be used in an examination of a running system.

IJDE Fall 2007 Issue

The Fall 2007 issue of the International Journal of Digital Evidence (IJDE) has been posted. This issue contains three articles.

Catalogue of Kernel-mode Backdoors

Some time ago Skape and Skywing have published a Catalogue of Windows Kernel-mode Backdoor Techniques.

PoolTools Version 1.3.0

I have overhauled PoolFinder and the accompanying tools. The tools now use a SQLite data base instead of flat files for exachanging data. An experimental package now provides stand-alone versions of the tools, along with an embedded Perl interpreter.

Archives

Imprint

This blog is a project of:
Andreas Schuster
Im Äuelchen 45
D-53177 Bonn
impressum@forensikblog.de

Copyright © 2005-2012 by
Andreas Schuster
All rights reserved.
Powered by Movable Type 5.12