Category "Library"

Memory Analysis Summary

Harlan Carvey has posted a great summary article on Windows memory analysis. In fact it is a free sample chapter from his new book on Windows Forensic Analysis.

IJDE Spring 2007 Issue

The Spring 2007 issue of the International Journal of Digital Evidence (IJDE) was just published.

Undocumented Windows 2000 Secrets - Electronic Edition

One of the few books that really helped me to get into Windows memory analysis is "Undocumented Windows 2000 Secrets" by Sven B. Schreiber. Unfortunately the book is out of print for some time. A few used copies are sold at Amazon and other internet marketplaces - at prices so high that I'm considering to invest in books instead of shares.

Fortunately Sven is so kind to provide an electronic edition of his work as a set of PDF files free of charge at his web site. Thank you very much, Sven!

FATKit

The upcoming issue of Digital Investigation (Vol. 3, Issue 4) will contain an interesting article by Nick L.Petroni, AAron Walters, Timothy Fraser and William A. Arbaugh about their memory analysis tool FATKit. A preprint is available free of charge at the FATKit website.

Forensics in Grid Computing

Conducting a forensic analysis on a single computer sometimes can be a cumbersome work. Now imagine you'd have to do the same - on a pool of distributed computers collaborative working to solve a problem. Syed Naqvi, Philippe Massonet and Alvaro Arenas address this scenario in their paper Scope of Forensics in Grid Computing - Vision and Perspectives.

Fingerprinting using JPEG Quantization Tables

The paper Digital Image Ballistics from JPEG Quantization by Hany Farid describes how digital stills can be attributed to camera makes due to certain differences in the implementation of JPEG compression.

Linux Memory Analysis

In his master thesis Jorge M. Urrea-Civilian examines data structures of the Linux 2.6 series kernel. He describes how the virtual address space of a process can be reconstructed from a swap file and the physical memory. The thesis might become the foundation of tools to analyze a Linux memory dump.

All about Write Blockers

In his presentation at the Techno Security 2006 conference Robert Botchek summarizes the basics of write blockers. The speaker is president of Tableau, LLC, a manufacturer of write blocking devices.

A Book in Portuguese

There are a lot of books in print about digital forensics, but most of them are in English. Well, here's one in Portugese, entitled Perícia Forense Aplicada à Informática by Andrey Rodrigues de Freitas. I feel some of my dear readers might find this information useful.

Data Lifetime

I was quite surprised to actually see parts of the main memory survive a reboot for the first time. Well, Farmer and Venema were not the first to describe this. Here are two more interesting papers on that topic.

 1 2 

Archives

Imprint

This blog is a project of:
Andreas Schuster
Im Äuelchen 45
D-53177 Bonn
impressum@forensikblog.de

Copyright © 2005-2012 by
Andreas Schuster
All rights reserved.
Powered by Movable Type 5.12