March 2008 Archives

JPEGsnoop Version 1.2.0

JPEGsnoop by Calvin Hass provides a deep insight into the internals of JPEG files. Also the program identifies digital cameras and image editing software by their characteristic quantization tables.

FTK 2.0 - Installation

Recently the new version of AcessData's Forensic Toolkit arrived in the mail. Of course I felt a strong urge to try it out. Here is what I experienced so far.

More about the Rich Header

About two years ago I wrote about the Rich header which can be found in most executable files for the Microsoft Windows platform. Now Daniel Pistelli went on a thorough investigation into that matter.

A Small RAM Dumper

When freezing RAM (the Princeton way) or rapidly powercycling a machine (The Guillotine) you will need a small tool to obtain the memory image, like msramdmp by Robert Wesley McGrew.

Archives

Imprint

This blog is a project of:
Andreas Schuster
Im Äuelchen 45
D-53177 Bonn
impressum@forensikblog.de

Copyright © 2005-2012 by
Andreas Schuster
All rights reserved.
Powered by Movable Type 5.12