Ladies and Gents,
A new version of the Law Enforcement and Forensic Examiner's
Introduction to Linux, A Beginner's Guide is now available at its new
home
http//
Info from the changelog is posted below. Please direct any questions or
correspondence to bgrundy (at) LinuxLEO.com
Barry.
From the Change Log
Version 3.20
-added compression on the fly exercise (for dd).
-added dd over the wire (network acquisition).
-added more detailed Sleuthkit section (commands)
-added TSK NTFS exercises (ADS, deleted files,sorter)
-added deleted file allocation determination and recovery exercise
(TSK/EXT2)
-removed support for Autopsy (I just don't use it anymore-I'll add it
back if
enough people request it).
-added libewf section.
-removed reference to NASA loopback (unsupported)
-added SMART filtering section using NTFS (classroom exercise)
-added SMART search section using EXT (classroom exercise).
-added section on configuring Slackware if a 2.6 kernel version is used
(12.x).
Version 2.55
-added a changelog 😉
-Document is now Slackware centric
-updated to Sleuthkit 2.0x (full disk images and split support)
-updated to Autopsy 2.0x (for use with new TSK)
-formatting changes for readability
Helix for Beginners (BJ Gleason & Drew Fahey)
http//
Helix for Beginners (BJ Gleason & Drew Fahey)
http//www.e-fense.com/helix/Docs/Helix0307.pdf
The document described on page 79 of the Helix guide (and on the Helix disk) is an older version of this doc. What I posted is an update to the guide referenced in the Helix book (which is really good, by the way).
well posted bg,
nice to see it homed on such a clean looking website too ) wtg
Kern
edit typo
nice to see it homed on such a clean looking website too ) wtg
Seconded. Very nice and clean site.
Updated again.
Version 3.65 is now available at
Changelog
Version 3.65
-Switched to 2.6 kernel install in intro (Slackware 12.1).
-Added brief section on device detection (by request).
-updated details for recent versions of Linux tools.
-updated Sleuthkit and libewf section to account for changes in install for
TSK > 2.50 (autotools build design).
-moved libewf before TSK to account for lib install
-added section on alternative imaging tools (dc3dd,ddrescue)
-added dls exercises by request (TSK).
-added brief exercise on sigfind (TSK).
questions, suggestions and flames to bgrundy [at] linuxleo.com
Excellent news! Your guide has been extremely helpful to me, Barry. I appreciate your work putting it together.
KP
Very nice )
I'm very interested in the use of Linux in this field
Thank you
Barry,
Excellent book, I just passed that link around to my team. I'm an avid Linux user but relatively new to the forensics side of things.
Igor That Helix link is broken, any idea where I might be able to find it?
They just re-did the
KP