Pages
(Move to ...)
Blog
Code Snippets
▼
Tuesday, October 19, 2010
Booting Disk Images in Linux
›
A Picture can be Worth a Thousand Words Sometimes there is no substitute for booting a computer to gather data. But the forensic conseque...
Thursday, October 7, 2010
Android SMS Parsing
›
There are two ways to skin this cat... but one is much better! A colleague was looking for help parsing a Android mms/sms database (mmssms...
1 comment:
Wednesday, October 6, 2010
Previewer is Dead, long live CAINE!
›
A brief history... In the summer of 2009, I created a forensic boot disc primarily intended for preview examinations of digital media call...
2 comments:
Tuesday, October 20, 2009
Processing Vista $RECYCLE.BIN
›
The MS Windows recycle bin differs in Vista from XP. In XP, an deleted file is moved to the "\Recycler\$SID\ folder where "$SID...
Tuesday, August 4, 2009
linuxsleuthing code project
›
Computers, iPods, Thumbdrives, oh My! I've been busy with a major case during which many smaller cases have walked through my door. I b...
1 comment:
Tuesday, March 10, 2009
Identifying Owners of Stolen iPods
›
iTunes is your friend I have gone from years of computer forensics without ever encountering Apple Products in any meaningful way to seemi...
Using grep to Unearth Old Windows User Names (7/30/08):
›
Identifying Deleted User Accounts in Windows I was recently presented with three laptop computers suspected as stolen. My task was to iden...
‹
›
Home
View web version