±Forensic Focus Partners

Become an advertising partner

±Your Account


Username
Password

Forgotten password/username?

Site Members:

New Today: 0 Overall: 30585
New Yesterday: 5 Visitors: 53

±Latest Articles

RSS Feed Widget

±Follow Forensic Focus

Forensic Focus Facebook PageForensic Focus on TwitterForensic Focus LinkedIn GroupForensic Focus YouTube Channel

RSS feeds: News   Forums   Articles

Search found 1428 matches

Re: EnCase 7 Anti-Forensic for Air-Gapped Examiner

Post Posted: Fri Jun 10, 2016 10:40 am

[quote="athulin"]A bit of tool validation: Does the tool allow binaries to 'escape'? Can a mistake on the part of the analyst make that happen? If it happens, can it be traced? Deciding that it does ...
jhup
Topic: EnCase 7 Anti-Forensic for Air-Gapped Examiner
Replies: 10
Views: 1800
 

Re: EnCase 7 Anti-Forensic for Air-Gapped Examiner

Post Posted: Thu May 26, 2016 7:58 am

[quote="Chris_Ed"]I feel like this article is akin to saying "WE FOUND A SERIOUS PROBLEM WITH HDDs; they are unworkable once smothered in ice cream. DO NOT SOMETHER YOUR HDDs IN ICE CREAM!".[/quote]
...
jhup
Topic: EnCase 7 Anti-Forensic for Air-Gapped Examiner
Replies: 10
Views: 1800
 

Re: I need help making sense of ntuser.dat file internet his

Post Posted: Wed May 25, 2016 9:37 am

[quote="jaclaz"]Regedit does NOT really-really access ntuser.dat (unless you load it as a hive see below), it creates a view of the Registry which is created by "smart merging" information from severa ...
jhup
Topic: I need help making sense of ntuser.dat file internet history
Replies: 34
Views: 4236
 

Re: EnCase 7 Anti-Forensic for Air-Gapped Examiner

Post Posted: Wed May 25, 2016 9:32 am

[quote="Chris_Ed"]...This is not really a true concern, as it is surely good practice for all examiners - to be wary of files you launch?[/quote]

I think it is. Considering that (anecdotally) most ...
jhup
Topic: EnCase 7 Anti-Forensic for Air-Gapped Examiner
Replies: 10
Views: 1800
 

EnCase 7 Anti-Forensic for Air-Gapped Examiner

Post Posted: Tue May 24, 2016 10:28 am

[url=http://www.forensium.com/Web_log/23_EnCase_7_Anti-Forensic_for_Air-Gapped_Examiner]Blog post on the same site that wrote about the [url=http://www.forensicfocus.com/Forums/viewtopic/t=13232/postd ...
jhup
Topic: EnCase 7 Anti-Forensic for Air-Gapped Examiner
Replies: 10
Views: 1800
 

Re: BIOS/EFI Do we still care?

Post Posted: Thu May 12, 2016 1:46 pm

BIOS and BIOS with UEFI is big difference; (and I do not care that it is not called BIOS with UEFI any more.)

A plain old BIOS will only have her internal clock to deal with, on the other hand some ...
jhup
Topic: BIOS/EFI Do we still care?
Replies: 10
Views: 4643
 

Re: Partition size based-on MBR and Win_Properties are different

Post Posted: Thu May 12, 2016 1:40 pm

[quote="athulin"] [i][...][/i]
may be confusing partitions and volumes. Unless the same definitions are used everywhere, interpretation will differ. Partitions hold volumes, and volumes can't alway ...
jhup
Topic: Partition size based-on MBR and Win_Properties are different
Replies: 3
Views: 2146
 
Page 1 of 204
Go to page 1, 2, 3 ... 202, 203, 204  Next