A Challenge

Spirovski Bozidar posted a challenge for the forensic community. A (small!) disk image needs to be searched for incriminating evidence. Submissions are due August 20, 2008.

The disk image contains a NTFS formatted volume. It's not the system volume , though. Therefore you don't have to be a Microsoft Windows expert to solve the challenge.

Also, you don't need any expensive forensic software to work on the challenge. A free tool like PyFlag will do the job as well. So, this challenge seems to be suitable for classes on IT security, even if they only glance at digital forensics.

Examining the case in PyFlag

Archives

Imprint

This blog is a project of:
Andreas Schuster
Im Äuelchen 45
D-53177 Bonn
impressum@forensikblog.de

Copyright © 2005-2012 by
Andreas Schuster
All rights reserved.
Powered by Movable Type 5.12