<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post7944909784499554847..comments</id><updated>2010-06-30T15:18:27.567-07:00</updated><category term='Cell Phones'/><category term='CRLF'/><category term='Wireless'/><category term='Vista'/><category term='Kindle'/><category term='CP'/><category term='File Signatures'/><category term='Hash'/><category term='SQL'/><category term='File System'/><category term='Email'/><category term='Patch'/><category term='Exclusion List'/><category term='dd'/><category term='SHA1'/><category term='MFT'/><category term='Photos'/><category term='Service Pack'/><category term='Keywords'/><category term='Import'/><category term='Encryption'/><category term='Firewall'/><category term='export'/><category term='EnScript Requests'/><category term='Install Date'/><category term='Timestamps'/><category term='Office Metadata'/><category term='NIST'/><category term='Password Bypass'/><category term='EnScript Tutorial'/><category term='MAC Address'/><category term='Domains'/><category term='GREP'/><category term='Thumbnails'/><category term='FTP'/><category term='USB History'/><category term='Virus'/><category term='Search Hits'/><category term='Bookmark'/><category term='MD5'/><category term='Winen'/><category term='LogFile'/><category term='EMLX'/><category term='Video'/><category term='Operating System'/><category term='Yahoo'/><category term='Duplicates'/><category term='Icons'/><category term='USNJRNL'/><category term='Restore Points'/><category term='Windows 7'/><category term='Base64'/><category term='Unallocated'/><category term='eBlaster'/><category term='Ghost'/><category term='XOR'/><category term='VSS'/><category term='Selected Text'/><category term='Network Information'/><category term='Forensic Practical'/><category term='Decode'/><category term='SANS'/><category term='Extensions'/><category term='Limewire'/><category term='Search'/><category term='Registry'/><category term='OSX'/><category term='IIS'/><category term='Unused Disk Space'/><category term='Event Logs'/><category term='Norton AV'/><category term='Foreign Language'/><category term='Lanman'/><category term='Redaction'/><category term='UserAssist'/><category term='ICAC'/><category term='LUHN'/><category term='Count'/><category term='Filename'/><category term='thumbcache'/><category term='ROT13'/><category term='HTML'/><category term='Incident Response'/><category term='Anti-Forensics'/><category term='Memory'/><category term='Internet History'/><category term='LEF'/><category term='File Types'/><category term='Triage'/><category term='SearchPak'/><category term='F-Response'/><category term='BitLocker'/><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: Extract MFT records from Memory dump</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/7944909784499554847/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7944909784499554847/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2007/11/extract-mft-records-from-memory-dump.html'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8808940436472220023</id><published>2010-06-30T15:18:27.433-07:00</published><updated>2010-06-30T15:18:27.433-07:00</updated><title type='text'>Mark,

Can you contact me directly?  Lance(at)fore...</title><content type='html'>Mark,&lt;br /&gt;&lt;br /&gt;Can you contact me directly?  Lance(at)forensickb.com&lt;br /&gt;&lt;br /&gt;Lance</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7944909784499554847/comments/default/8808940436472220023'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7944909784499554847/comments/default/8808940436472220023'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2007/11/extract-mft-records-from-memory-dump.html?showComment=1277936307433#c8808940436472220023' title=''/><author><name>Lance Mueller</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2007/11/extract-mft-records-from-memory-dump.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7944909784499554847' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7944909784499554847' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1414078029'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-358892343901975154</id><published>2010-06-30T11:40:04.973-07:00</published><updated>2010-06-30T11:40:04.973-07:00</updated><title type='text'>Hello,

I know I am a little late to the game on t...</title><content type='html'>Hello,&lt;br /&gt;&lt;br /&gt;I know I am a little late to the game on this, but I just ran this enpack against three memory dumps, one dd file and two vmware vmem files.  The enpack output in the console was &amp;quot;A total of 0 search hits were processed, but only 0 valid MFT records were parsed&amp;quot;.  That is odd, but I used volatility to pull out other file information.  Any thoughts or suggestions?&lt;br /&gt;&lt;br /&gt;Thanks.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7944909784499554847/comments/default/358892343901975154'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7944909784499554847/comments/default/358892343901975154'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2007/11/extract-mft-records-from-memory-dump.html?showComment=1277923204973#c358892343901975154' title=''/><author><name>Mark</name><uri>http://www.blogger.com/profile/18343684786509373331</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2007/11/extract-mft-records-from-memory-dump.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7944909784499554847' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7944909784499554847' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-332890915'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-6984002624948205393</id><published>2007-11-14T23:12:00.000-08:00</published><updated>2007-11-14T23:12:00.000-08:00</updated><title type='text'>Well, you can still use the version that is floati...</title><content type='html'>Well, you can still use the version that is floating around out there on the Internet. The problem is it does not work for Windows 2003 (&gt;=sp1) or Vista because the \\.\PhysicalMemory pipe is not accessible like it was in the past.&lt;BR/&gt;&lt;BR/&gt;I would recommend KnTTools by George Garner at http://www.gmgsystemsinc.com/knttools/. They are not free, but its one of the only viable solutions at this point.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7944909784499554847/comments/default/6984002624948205393'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7944909784499554847/comments/default/6984002624948205393'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2007/11/extract-mft-records-from-memory-dump.html?showComment=1195110720000#c6984002624948205393' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2007/11/extract-mft-records-from-memory-dump.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7944909784499554847' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7944909784499554847' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4831173403612254861</id><published>2007-11-14T18:12:00.000-08:00</published><updated>2007-11-14T18:12:00.000-08:00</updated><title type='text'>What do you recommend to capture memory? The vener...</title><content type='html'>What do you recommend to capture memory? The venerable modified DD is not available for free anymore :(&lt;BR/&gt;&lt;BR/&gt;Paul Bobby</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7944909784499554847/comments/default/4831173403612254861'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7944909784499554847/comments/default/4831173403612254861'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2007/11/extract-mft-records-from-memory-dump.html?showComment=1195092720000#c4831173403612254861' title=''/><author><name>Paul</name><uri>http://www.blogger.com/profile/14948721303363357805</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2007/11/extract-mft-records-from-memory-dump.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7944909784499554847' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7944909784499554847' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1174548906'/></entry></feed>
