I'm excited to release version 0.3.05 of PTFinder to the public. This version fixes an endianess issue. It provides support for dumps that where obtained while under the effect of the Intel Physical Address Extension (PAE). Also there's a ready-to-run binary available for the Microsoft Windows platform.
November 2007 Archives
Continue reading PTFinder Version 0.3.05.
Lance Mueller has released an EnScript that searches a memory dump for MFT entries.
Continue reading Carving MFT Entries from Memory Images.
Guidance Software's EnCase provides the forensic examiner with a powerful scripting language, called EnScript. Beside the vendor-operated fora there's not much information about EnScript circulating in the net. A blog by Lance Mueller fills some need here.
10/18/2011: Unfortunately Lance Mueller has decided to close his blog. The content will be accessible, though.
Continue reading Blog about EnScript.
Evtim Batchev of SUN Iberia presented about live-response on the SUN Solaris platform at the 22nd TF-CSIRT meeting. His slides cover several data structures of the Solaris kernel and how they can be used in an examination of a running system.
The Fall 2007 issue of the International Journal of Digital Evidence (IJDE) has been posted. This issue contains three articles.
Continue reading IJDE Fall 2007 Issue.
Some time ago Skape and Skywing have published a Catalogue of Windows Kernel-mode Backdoor Techniques.
Continue reading Catalogue of Kernel-mode Backdoors.
I have overhauled PoolFinder and the accompanying tools. The tools now use a SQLite data base instead of flat files for exachanging data. An experimental package now provides stand-alone versions of the tools, along with an embedded Perl interpreter.
Continue reading PoolTools Version 1.3.0.
