<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post1961617445562160198..comments</id><updated>2011-06-01T06:49:51.547-07:00</updated><category term='Cell Phones'/><category term='CRLF'/><category term='Wireless'/><category term='Vista'/><category term='Kindle'/><category term='CP'/><category term='File Signatures'/><category term='Hash'/><category term='SQL'/><category term='File System'/><category term='Email'/><category term='Patch'/><category term='Exclusion List'/><category term='dd'/><category term='SHA1'/><category term='MFT'/><category term='Photos'/><category term='Service Pack'/><category term='Keywords'/><category term='Import'/><category term='Encryption'/><category term='Firewall'/><category term='export'/><category term='EnScript Requests'/><category term='Install Date'/><category term='Timestamps'/><category term='Office Metadata'/><category term='NIST'/><category term='Password Bypass'/><category term='EnScript Tutorial'/><category term='MAC Address'/><category term='Domains'/><category term='GREP'/><category term='Thumbnails'/><category term='FTP'/><category term='USB History'/><category term='Virus'/><category term='Search Hits'/><category term='Bookmark'/><category term='MD5'/><category term='Winen'/><category term='LogFile'/><category term='EMLX'/><category term='Video'/><category term='Operating System'/><category term='Yahoo'/><category term='Duplicates'/><category term='Icons'/><category term='USNJRNL'/><category term='Restore Points'/><category term='Windows 7'/><category term='Base64'/><category term='Unallocated'/><category term='eBlaster'/><category term='Ghost'/><category term='XOR'/><category term='VSS'/><category term='Selected Text'/><category term='Network Information'/><category term='Forensic Practical'/><category term='Decode'/><category term='SANS'/><category term='Extensions'/><category term='Limewire'/><category term='Search'/><category term='Registry'/><category term='OSX'/><category term='IIS'/><category term='Unused Disk Space'/><category term='Event Logs'/><category term='Norton AV'/><category term='Foreign Language'/><category term='Lanman'/><category term='Redaction'/><category term='UserAssist'/><category term='ICAC'/><category term='LUHN'/><category term='Count'/><category term='Filename'/><category term='thumbcache'/><category term='ROT13'/><category term='HTML'/><category term='Incident Response'/><category term='Anti-Forensics'/><category term='Memory'/><category term='Internet History'/><category term='LEF'/><category term='File Types'/><category term='Triage'/><category term='SearchPak'/><category term='F-Response'/><category term='BitLocker'/><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: New version of EnCase includes stand-alone utility...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/1961617445562160198/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1961617445562160198/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/06/new-version-of-encase-includes-stand.html'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4016492411901457201</id><published>2011-05-31T22:57:50.169-07:00</published><updated>2011-05-31T22:57:50.169-07:00</updated><title type='text'></title><content type='html'>This comment has been removed by a blog administrator.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1961617445562160198/comments/default/4016492411901457201'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1961617445562160198/comments/default/4016492411901457201'/><author><name>seartho</name><uri>http://www.blogger.com/profile/16225748350963388747</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://2.bp.blogspot.com/-xr8WhCJCytc/Tav_mwdREVI/AAAAAAAAAAY/whZw04DDPjE/s220/1.JPG'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/06/new-version-of-encase-includes-stand.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1961617445562160198' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1961617445562160198' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.contentRemoved' value='true'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1909793775'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1038031810147213459</id><published>2008-06-15T04:13:00.000-07:00</published><updated>2008-06-15T04:13:00.000-07:00</updated><title type='text'>Anytime you interface with a live system, you're g...</title><content type='html'>Anytime you interface with a live system, you're going to leave footprints or artifacts.  There have been 'forensic' and incident response applications where the authors have espoused deleting these artifacts...however, the list is never complete.  IMHO, if you must interact with a live system, leave the artifacts in order to assist in establishing a legit timeline.&lt;BR/&gt;&lt;BR/&gt;I would be curious how winen compares to &lt;A HREF="http://windowsir.blogspot.com/2008/06/memory-collection-and-analysis.html" REL="nofollow"&gt;mdd&lt;/A&gt;.  Not head-to-head, per se, but use winen to dump memory, then open that dump in EnCase and dump it out to HBGary's Responder, and compare that to a similar dump from mdd.&lt;BR/&gt;&lt;BR/&gt;In a way, I find it surprising that GSI is segregating itself this way...one of the things one *should* try to avoid is methods of collection that channelize the analyst into a single application for analysis.  Sure, .EO&lt;I&gt;x&lt;/I&gt; files can be opened and 'dumped' to  dd-style format with FTK Imager, but that requires additional steps.  The ability to verify information by using different tools/procedures is important in this field.  &lt;BR/&gt;&lt;BR/&gt;Also, it's kind of interesting that winen collects physical memory in a format that even HBGary's Responder tool doesn't recognize.&lt;BR/&gt;&lt;BR/&gt;Note:  this isn't a comment to bash EnCase or anyone...just pointing out some issues that should be considered when deciding to use these tools.&lt;BR/&gt;&lt;BR/&gt;&lt;A HREF="http://windowsir.blogspot.com" REL="nofollow"&gt;WindowsIR&lt;/A&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1961617445562160198/comments/default/1038031810147213459'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1961617445562160198/comments/default/1038031810147213459'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/06/new-version-of-encase-includes-stand.html?showComment=1213528380000#c1038031810147213459' title=''/><author><name>Keydet89</name><uri>http://www.blogger.com/profile/08966595734678290320</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://a652.ac-images.myspacecdn.com/images01/55/m_ab5e482b5e1cd7c3fe90874adf42cf2b.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/06/new-version-of-encase-includes-stand.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1961617445562160198' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1961617445562160198' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-570367412'/></entry></feed>
