±Forensic Focus Partners

Become an advertising partner

±Your Account


Username
Password

Forgotten password/username?

Site Members:

New Today: 2 Overall: 30969
New Yesterday: 4 Visitors: 86

±Latest Articles

RSS Feed Widget

±Follow Forensic Focus

Forensic Focus Facebook PageForensic Focus on TwitterForensic Focus LinkedIn GroupForensic Focus YouTube Channel

RSS feeds: News   Forums   Articles

Search found 1246 matches

Re: Where is "Active Directory Information Extractor"?

Post Posted: Mon Jul 04, 2016 10:10 pm

PowerShell is your friend. Virtualize the environment and go crazy. Here is an example: [url=https://gallery.technet.microsoft.com/scriptcenter/Powershell-script-to-5edcdaea]Export list of AD users ...
BitHead
Topic: Where is "Active Directory Information Extractor"?
Replies: 4
Views: 1544
 

Re: Misleading terms FTK and Encase "carved" vs "deleted"

Post Posted: Wed Jun 15, 2016 7:46 pm

There are many issues with both of the big forensic suites that have been documented on this and other sites.
BitHead
Topic: Misleading terms FTK and Encase "carved" vs "deleted"
Replies: 2
Views: 809
 

Re: Beginner Questions - which software and test cases?

Post Posted: Wed Jun 15, 2016 7:41 pm

http://www.linuxleo.com/calug/forensicresource.pdf
BitHead
Topic: Beginner Questions - which software and test cases?
Replies: 6
Views: 1634
 

Re: Added Accreditation for US Forensic Digital Examiners

Post Posted: Sat Mar 26, 2016 2:16 pm

It is a lot of signatures away from reality.
BitHead
Topic: Added Accreditation for US Forensic Digital Examiners
Replies: 1
Views: 709
 

Re: Application and Server Logs Investigation

Post Posted: Thu Mar 10, 2016 8:03 pm

[quote="harshbehl"]Hi
What are the best procedures to investigate the application and server logs ?[/quote]Know what you are looking for. Searching with no predefined goal is a fools errand, much li ...
BitHead
Topic: Application and Server Logs Investigation
Replies: 3
Views: 1019
 

Re: Is it possible to recover a deleted virtual machine?

Post Posted: Wed Mar 02, 2016 8:24 pm

If you knew information about the header and footer, say if it was published in a specification, you could potentially carve the file manually in a hex editor.

https://articles.forensicfocus.com/20 ...
BitHead
Topic: Is it possible to recover a deleted virtual machine?
Replies: 2
Views: 678
 

Re: Microsoft Exchange Question

Post Posted: Wed Mar 02, 2016 8:18 pm

a. http://exchangeserverpro.com/tracking-mailbox-owner-deletes-using-mailbox-audit-logging/

b. https://exchangeserverpro.com/powershell-script-report-mailbox-audit-log-entries/

Do those answer ...
BitHead
Topic: Microsoft Exchange Question
Replies: 1
Views: 415
 
Page 1 of 178
Go to page 1, 2, 3 ... 176, 177, 178  Next