<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post4350526719259137621..comments</id><updated>2009-04-09T08:30:02.865-07:00</updated><category term='Cell Phones'/><category term='CRLF'/><category term='Wireless'/><category term='Vista'/><category term='Kindle'/><category term='CP'/><category term='File Signatures'/><category term='Hash'/><category term='SQL'/><category term='File System'/><category term='Email'/><category term='Patch'/><category term='Exclusion List'/><category term='dd'/><category term='SHA1'/><category term='MFT'/><category term='Photos'/><category term='Service Pack'/><category term='Keywords'/><category term='Import'/><category term='Encryption'/><category term='Firewall'/><category term='export'/><category term='EnScript Requests'/><category term='Install Date'/><category term='Timestamps'/><category term='Office Metadata'/><category term='NIST'/><category term='Password Bypass'/><category term='EnScript Tutorial'/><category term='MAC Address'/><category term='Domains'/><category term='GREP'/><category term='Thumbnails'/><category term='FTP'/><category term='USB History'/><category term='Virus'/><category term='Search Hits'/><category term='Bookmark'/><category term='MD5'/><category term='Winen'/><category term='LogFile'/><category term='EMLX'/><category term='Video'/><category term='Operating System'/><category term='Yahoo'/><category term='Duplicates'/><category term='Icons'/><category term='USNJRNL'/><category term='Restore Points'/><category term='Windows 7'/><category term='Base64'/><category term='Unallocated'/><category term='eBlaster'/><category term='Ghost'/><category term='XOR'/><category term='VSS'/><category term='Selected Text'/><category term='Network Information'/><category term='Forensic Practical'/><category term='Decode'/><category term='SANS'/><category term='Extensions'/><category term='Limewire'/><category term='Search'/><category term='Registry'/><category term='OSX'/><category term='IIS'/><category term='Unused Disk Space'/><category term='Event Logs'/><category term='Norton AV'/><category term='Foreign Language'/><category term='Lanman'/><category term='Redaction'/><category term='UserAssist'/><category term='ICAC'/><category term='LUHN'/><category term='Count'/><category term='Filename'/><category term='thumbcache'/><category term='ROT13'/><category term='HTML'/><category term='Incident Response'/><category term='Anti-Forensics'/><category term='Memory'/><category term='Internet History'/><category term='LEF'/><category term='File Types'/><category term='Triage'/><category term='SearchPak'/><category term='F-Response'/><category term='BitLocker'/><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: Recovering video files in unallocated space</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/4350526719259137621/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4350526719259137621/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/recovering-video-files-in-unallocated.html'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-735206978903011274</id><published>2009-04-09T08:30:00.000-07:00</published><updated>2009-04-09T08:30:00.000-07:00</updated><title type='text'>John, I am only the author of the EnScript. For cl...</title><content type='html'>John, I am only the author of the EnScript. For claification on the search terms, you should contact Sgt. Lang (his email and phone are listed in the training video).&lt;BR/&gt;&lt;BR/&gt;Here is some info he provided me:&lt;BR/&gt;"Note: Please check your work, i.e. the source of many of the GREPs in the first list are from outside sources and you may find non-child porn videos in your searches. If that happens please let us know so that we can update the lists. The same is true if you find a GREP statement that has a large number of false hits. We tried to check every statement for false hits before adding to these lists, but some may have gotten by us."</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4350526719259137621/comments/default/735206978903011274'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4350526719259137621/comments/default/735206978903011274'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/recovering-video-files-in-unallocated.html?showComment=1239291000000#c735206978903011274' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/recovering-video-files-in-unallocated.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-4350526719259137621' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/4350526719259137621' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-7727563741454244951</id><published>2009-04-09T08:20:00.000-07:00</published><updated>2009-04-09T08:20:00.000-07:00</updated><title type='text'>Question about the keyword list: as presented here...</title><content type='html'>Question about the keyword list: as presented here, it's generic to movie files in general, but in an associated posting on the Guidance support forums, it refers to "harvesting 10 bytes of data from the data portion of videos we have found to contain child pornography". Are these search terms generic to movie files, or are they specific to certain known child exploitation videos.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4350526719259137621/comments/default/7727563741454244951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4350526719259137621/comments/default/7727563741454244951'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/recovering-video-files-in-unallocated.html?showComment=1239290400000#c7727563741454244951' title=''/><author><name>johnmccash</name><uri>http://www.blogger.com/profile/11156773431595966251</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/recovering-video-files-in-unallocated.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-4350526719259137621' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/4350526719259137621' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-934315204'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8974035574285311016</id><published>2009-04-09T07:58:00.000-07:00</published><updated>2009-04-09T07:58:00.000-07:00</updated><title type='text'>I updated the GREP keyword list to a ZIP file. I h...</title><content type='html'>I updated the GREP keyword list to a ZIP file. I have tested it and it should work fine now.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4350526719259137621/comments/default/8974035574285311016'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4350526719259137621/comments/default/8974035574285311016'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/recovering-video-files-in-unallocated.html?showComment=1239289080000#c8974035574285311016' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/recovering-video-files-in-unallocated.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-4350526719259137621' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/4350526719259137621' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3390852378300290018</id><published>2009-04-09T06:00:00.000-07:00</published><updated>2009-04-09T06:00:00.000-07:00</updated><title type='text'>Lance - I attempted to import the grep keyword lis...</title><content type='html'>Lance - I attempted to import the grep keyword list into EE 6.13, and it says it's an invalid import file.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4350526719259137621/comments/default/3390852378300290018'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4350526719259137621/comments/default/3390852378300290018'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/recovering-video-files-in-unallocated.html?showComment=1239282000000#c3390852378300290018' title=''/><author><name>johnmccash</name><uri>http://www.blogger.com/profile/11156773431595966251</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/recovering-video-files-in-unallocated.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-4350526719259137621' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/4350526719259137621' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-934315204'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-760367021975164234</id><published>2009-04-09T05:25:00.000-07:00</published><updated>2009-04-09T05:25:00.000-07:00</updated><title type='text'>Problems with the keyword file. It display in the ...</title><content type='html'>Problems with the keyword file. It display in the browser. Once saved the import fails.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4350526719259137621/comments/default/760367021975164234'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4350526719259137621/comments/default/760367021975164234'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/recovering-video-files-in-unallocated.html?showComment=1239279900000#c760367021975164234' title=''/><author><name>Robert</name><uri>http://www.blogger.com/profile/16056201303475723075</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/recovering-video-files-in-unallocated.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-4350526719259137621' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/4350526719259137621' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1171440299'/></entry></feed>
