<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post5002190918550507987..comments</id><updated>2010-10-24T06:25:49.706-07:00</updated><category term='Cell Phones'/><category term='CRLF'/><category term='Wireless'/><category term='Vista'/><category term='Kindle'/><category term='CP'/><category term='File Signatures'/><category term='Hash'/><category term='SQL'/><category term='File System'/><category term='Email'/><category term='Patch'/><category term='Exclusion List'/><category term='dd'/><category term='SHA1'/><category term='MFT'/><category term='Photos'/><category term='Service Pack'/><category term='Keywords'/><category term='Import'/><category term='Encryption'/><category term='Firewall'/><category term='export'/><category term='EnScript Requests'/><category term='Install Date'/><category term='Timestamps'/><category term='Office Metadata'/><category term='NIST'/><category term='Password Bypass'/><category term='EnScript Tutorial'/><category term='MAC Address'/><category term='Domains'/><category term='GREP'/><category term='Thumbnails'/><category term='FTP'/><category term='USB History'/><category term='Virus'/><category term='Search Hits'/><category term='Bookmark'/><category term='MD5'/><category term='Winen'/><category term='LogFile'/><category term='EMLX'/><category term='Video'/><category term='Operating System'/><category term='Yahoo'/><category term='Duplicates'/><category term='Icons'/><category term='USNJRNL'/><category term='Restore Points'/><category term='Windows 7'/><category term='Base64'/><category term='Unallocated'/><category term='eBlaster'/><category term='Ghost'/><category term='XOR'/><category term='VSS'/><category term='Selected Text'/><category term='Network Information'/><category term='Forensic Practical'/><category term='Decode'/><category term='SANS'/><category term='Extensions'/><category term='Limewire'/><category term='Search'/><category term='Registry'/><category term='OSX'/><category term='IIS'/><category term='Unused Disk Space'/><category term='Event Logs'/><category term='Norton AV'/><category term='Foreign Language'/><category term='Lanman'/><category term='Redaction'/><category term='UserAssist'/><category term='ICAC'/><category term='LUHN'/><category term='Count'/><category term='Filename'/><category term='thumbcache'/><category term='ROT13'/><category term='HTML'/><category term='Incident Response'/><category term='Anti-Forensics'/><category term='Memory'/><category term='Internet History'/><category term='LEF'/><category term='File Types'/><category term='Triage'/><category term='SearchPak'/><category term='F-Response'/><category term='BitLocker'/><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: EnScript to parse USNJRNL</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/5002190918550507987/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/5002190918550507987/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/09/enscript-to-parse-usnjrnl.html'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1876521799137205295</id><published>2010-10-24T06:25:49.706-07:00</published><updated>2010-10-24T06:25:49.706-07:00</updated><title type='text'>Hi all,

I can also discover a normal executable w...</title><content type='html'>Hi all,&lt;br /&gt;&lt;br /&gt;I can also discover a normal executable which parses also the USNJRNL File and dumps its contents to a log (for those who don&amp;#39;t own EnCase)&lt;br /&gt;&lt;br /&gt;Just post into this comments if you guys want a copy :-)&lt;br /&gt;&lt;br /&gt;kind regards&lt;br /&gt;&lt;br /&gt;Markus</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/5002190918550507987/comments/default/1876521799137205295'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/5002190918550507987/comments/default/1876521799137205295'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/09/enscript-to-parse-usnjrnl.html?showComment=1287926749706#c1876521799137205295' title=''/><author><name>Markus</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/09/enscript-to-parse-usnjrnl.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-5002190918550507987' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/5002190918550507987' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1330384149'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4042972198760141478</id><published>2010-07-07T01:06:48.847-07:00</published><updated>2010-07-07T01:06:48.847-07:00</updated><title type='text'>Lance,
Is there a way to parse fragments of the US...</title><content type='html'>Lance,&lt;br /&gt;Is there a way to parse fragments of the USNJRNL from unallocated clusters?&lt;br /&gt;&lt;br /&gt;Regards Richard</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/5002190918550507987/comments/default/4042972198760141478'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/5002190918550507987/comments/default/4042972198760141478'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/09/enscript-to-parse-usnjrnl.html?showComment=1278490008847#c4042972198760141478' title=''/><author><name>DC1743</name><uri>http://www.blogger.com/profile/14186532367794900206</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/09/enscript-to-parse-usnjrnl.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-5002190918550507987' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/5002190918550507987' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-149359294'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1257256767572666953</id><published>2010-03-17T09:34:47.452-07:00</published><updated>2010-03-17T09:34:47.452-07:00</updated><title type='text'>Lance:

I saw your post on the Win4n6 group. Thank...</title><content type='html'>Lance:&lt;br /&gt;&lt;br /&gt;I saw your post on the Win4n6 group. Thanks for doing this. I sincerely appreciate it. &lt;br /&gt;&lt;br /&gt;Best regards, Phil</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/5002190918550507987/comments/default/1257256767572666953'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/5002190918550507987/comments/default/1257256767572666953'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/09/enscript-to-parse-usnjrnl.html?showComment=1268843687452#c1257256767572666953' title=''/><author><name>Phil Rodokanakis</name><uri>http://www.blogger.com/profile/17663314202364550318</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://philr.us/images/PhilR_2.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/09/enscript-to-parse-usnjrnl.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-5002190918550507987' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/5002190918550507987' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1449037696'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-2789278467553186878</id><published>2010-03-17T09:06:45.327-07:00</published><updated>2010-03-17T09:06:45.327-07:00</updated><title type='text'>Output to CSV functionality added 03/17/10, v1.2</title><content type='html'>Output to CSV functionality added 03/17/10, v1.2</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/5002190918550507987/comments/default/2789278467553186878'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/5002190918550507987/comments/default/2789278467553186878'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/09/enscript-to-parse-usnjrnl.html?showComment=1268842005327#c2789278467553186878' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/09/enscript-to-parse-usnjrnl.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-5002190918550507987' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/5002190918550507987' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8912915560798788041</id><published>2010-03-16T17:54:56.388-07:00</published><updated>2010-03-16T17:54:56.388-07:00</updated><title type='text'>Lance:

I know this is a rather dated post, so I d...</title><content type='html'>Lance:&lt;br /&gt;&lt;br /&gt;I know this is a rather dated post, so I don&amp;#39;t know if you&amp;#39;re still monitoring it. But I recently came across the need for examining the USNJRNL file and used your EnScript to parse it--thank you very much for making this available by the way.&lt;br /&gt;&lt;br /&gt;I was wondering, however, if it&amp;#39;s possible to output the parsed text in a delimited format. Having the output in delimited format would allow one to open in a spreadsheet and sort by date, Reason code, etc. That would be very helpful, I would think.&lt;br /&gt;&lt;br /&gt;Anyway, thanks again for making this available. &lt;br /&gt;&lt;br /&gt;Best regards, Phil</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/5002190918550507987/comments/default/8912915560798788041'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/5002190918550507987/comments/default/8912915560798788041'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/09/enscript-to-parse-usnjrnl.html?showComment=1268787296388#c8912915560798788041' title=''/><author><name>Phil Rodokanakis</name><uri>http://www.blogger.com/profile/17663314202364550318</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://philr.us/images/PhilR_2.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/09/enscript-to-parse-usnjrnl.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-5002190918550507987' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/5002190918550507987' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1449037696'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-7909197046773582310</id><published>2008-09-02T07:52:00.000-07:00</published><updated>2008-09-02T07:52:00.000-07:00</updated><title type='text'>Dang! I was looking for those structures myself fo...</title><content type='html'>Dang! I was looking for those structures myself for a long time and put serious work into it and NOW THEY POST THE DATA!!!!!!!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/5002190918550507987/comments/default/7909197046773582310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/5002190918550507987/comments/default/7909197046773582310'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/09/enscript-to-parse-usnjrnl.html?showComment=1220367120000#c7909197046773582310' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/09/enscript-to-parse-usnjrnl.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-5002190918550507987' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/5002190918550507987' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-16672145'/></entry></feed>
