Notifications
Clear all

therev

4 Posts
3 Users
0 Reactions
721 Views
hogfly
(@hogfly)
Reputable Member
Joined: 21 years ago
Posts: 287
Topic starter  

here's a util I came across on Michael zalewski's site.

You can use it to search word docs for changes and metadata etc…

http://lcamtuf.coredump.cx/soft/therev.tgz


   
Quote
Jamie
(@jamie)
Moderator
Joined: 5 years ago
Posts: 1288
 

Thanks for that one,

Cheers,

Jamie


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

I have a Perl script in my book for doing the same thing, and it runs on Windows. I've also listed other tools in my book for pulling metadata from other documents, as well.

Given these are Perl scripts, they can easily be converted to standalone EXEs, which I've started doing:
http://www.windows-ir.com/tools.html

H. Carvey
"Windows Forensics and Incident Recovery"
http://www.windows-ir.com


   
ReplyQuote
Jamie
(@jamie)
Moderator
Joined: 5 years ago
Posts: 1288
 

Thanks Harlan.

I don't know if you saw one of my earlier posts to another topic but I was wondering if you have a short extract from the book which we might be able to add to our "Papers & Articles" page ( http://www.forensicfocus.com/computer-forensics-papers.php )? Please feel free to PM me, thanks.

Kind regards,

Jamie


   
ReplyQuote
Share: