Skip to search.

Breaking News Visit Yahoo! News for the latest.

×Close this window

linux_forensics

The Yahoo! Groups Product Blog

Check it out!

Group Information

  • Members: 1327
  • Category: Forensics
  • Founded: Aug 14, 2003
  • Language: English
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Hear how Yahoo! Groups has changed the lives of others. Take me there.

Messages

Advanced
Messages Help
  Newest  |  < Newer  |  Older >  |  Oldest
Topics Messages Latest Post

Anyone know if there is work being done to implement support for EnCase v7's new Ex01 file format in libewf or other open source libraries? Otherwise I guess...
13 May 2, 2012
1:16 am

David Kovar
dkovar
Send Email

http://nps.edu/Academics/Institutes/Cebrowski/Relationships/Employment-Opportunities.html Employment Opportunities Cebrowski Institute > Relationships ...
1 May 1, 2012
11:56 am

Simson Garfinkel
simsongarfinkel
Send Email

I've got a bunch of keyword hits in a "Pictures.pd6" file. The file appears to be database used by Windows Live Photo Gallery. It's located on a Windows Vista...
3 Apr 26, 2012
9:03 pm

Lehr, John
slopd4256
Send Email

Does any one know how to view the log files found in the \home\userid\.local\share\gvfs-metadata&#92; folder? Thanks [Non-text portions of this message have been...
5 Apr 26, 2012
6:50 pm

Jacques B.
jboucher_work
Send Email

All, We have an experimental version of SleuthKit on github that has EXT4 support. We are looking for people to test it. You can find it at: ...
1 Apr 19, 2012
10:55 pm

Simson Garfinkel
simsongarfinkel
Send Email

All, Is there a handy linux forensic tool to verify a drive is 100% zeros? fyi: We got the drive from opposing and it was thought to have data on it. A casual...
20 Apr 19, 2012
9:35 am

Jacques B.
jboucher_work
Send Email

All, The following sources sought notices have been posted to FBO.GOV. Simson D--SOURCES SOUGHT NOTICE: Bulk_Extractor Unicode Solicitation Number:...
1 Apr 18, 2012
4:51 pm

Simson Garfinkel
simsongarfinkel
Send Email

I'm getting the following error when running log2timeline (v .63) Any suggestions??? Is it an error with a specific file in the recycle bin or the recycle bin...
4 Apr 17, 2012
3:16 pm

New User
fornzix
Send Email

Are there any Linux memory dump images available for experimantal/research purpose? (Any version of kernel would do.) Images for Windows are available for...
19 Apr 16, 2012
4:51 am

suba surianarayanan
suba_suriana...
Send Email

ANNOUNCING AFFLIB 3.7 I'm happy to announce the release of AFFLIB 3.7. Significant highlights of the release include the following: - Copyright Clarification....
11 Apr 15, 2012
7:27 pm

The Dog's Bollix
ISXPRO
Send Email

Hi Everyone. A friendly reminder that proposals for OSDF are due by next monday (4/16). And if you are interested in participating in a hack-a-thon, e-mail us...
1 Apr 12, 2012
1:40 pm

Brian Carrier
bdcarrier
Send Email

Some cell phones are not fully supported by Cellebrite (in our case, LG-265). Sometimes the only option appears to be photographing all the SMS messages...
5 Apr 3, 2012
11:16 pm

Jeff Bryner
jbryner1
Send Email

I am writing here since this is an experts' forum. Please read this link - http://www.thehindu.com/news/cities/chennai/article3255359.ece   This person was...
15 Mar 30, 2012
7:53 pm

Brad
bcddd214
Send Email

We're thinking about hosting an open source forensics hack-a-thon along with the Sleuth Kit and Open Source Digital Forensics Conference...
1 Mar 30, 2012
7:06 pm

Brian Carrier
bdcarrier
Send Email

All, I just packaged up ext4magic for openSUSE. It's a file recovery tool for ext4 filesystems. ...
1 Mar 28, 2012
11:06 pm

Greg Freemyer
gregfreemyer
Send Email

I've created a super timeline by means of log2timeline. It is composed of these files: * PC01HD01_part02.csv : TimeLine partiion (C:) # log2timeline -p -r -z...
5 Mar 26, 2012
2:06 pm

Paolo
samikap
Send Email

I'm working with bitstream copy of Windows 7 Starter. I got the timezone information by using regripper perl rip.pl -r /mnt/ewf/Windows/System32/config/SYSTEM...
18 Mar 25, 2012
6:19 pm

Simson Garfinkel
simsongarfinkel
Send Email

A client of mine has a laptop where the user has encrypted their home directory - I imagine this would have been done using LUKS? I understand Ubuntu offers...
6 Mar 22, 2012
1:44 pm

Nathan Jordan
njordan27
Send Email

Hi Paolo, ... I found this code in Win.pm file of log2timeline ( ...
1 Mar 22, 2012
8:05 am

Giuseppe Specchio
peppespe
Send Email

Hi All I have extracted a list of graphics files from folder full of data using: /# find . -type f -exec file {} \; > ../../../notes/file-types.txt/ I then...
12 Mar 20, 2012
3:16 pm

Jacques B.
jboucher_work
Send Email

Be it a Linux or Windows application, I'm looking for a Windows Link Viewer that people use and trust. I performed a quick google search of link viewer...
2 Mar 19, 2012
3:22 pm

Lehr, John
slopd4256
Send Email

I know yaru does a good job of showing deleted registry keys, along with the hex output. Are there any other recommended FOSS tools which do the same - show ...
2 Mar 15, 2012
2:54 pm

Andrew Case
tgotelnet
Send Email

Okay, I'm tying to do my first linux created file inventory. It's of a thumb drive with not that much data on it, so this should not get too crazy. There are...
6 Mar 9, 2012
6:05 pm

Lehr, John
slopd4256
Send Email

Linux dump ram.../dev/mem does not work more, so we must use /dev/fmem...it works, but in a forensics live analysis how much affect the compiling operations...
11 Mar 6, 2012
8:23 pm

Andrew Case
tgotelnet
Send Email

We're doing it again this year, but a few months later than last year. Sorry if you receive this multiple times. 2012 Sleuth Kit and Open Source Digital...
1 Mar 6, 2012
6:12 pm

Brian Carrier
bdcarrier
Send Email

Simson, You might want to consider adding "file inventory creator" to the description of fiwalk. We have to create a file inventory on a reasonable percentage...
1 Mar 3, 2012
11:27 pm

Greg Freemyer
gregfreemyer
Send Email

All, I assume we all have to create file inventories from others to peruse from time to time. I'd like to leverage exiftool v8.65, which I think has a lot more...
2 Mar 3, 2012
12:28 pm

Simson Garfinkel
simsongarfinkel
Send Email

All, I just came across this mailing list. I've decided to try and get more DFIR (Digital Forensic / Incident Response) apps in to openSUSE. This mailing list...
20 Feb 25, 2012
12:27 am

Greg Freemyer
gregfreemyer
Send Email

What is the best open source tool for grabbing a snapshot of the windows memory hash values to compare with hard drive data? [Non-text portions of this message...
2 Feb 20, 2012
10:04 pm

Jacques B.
jboucher_work
Send Email

I was curious if there were any techniques in recovering cached network connection. I cannot find anything significant on the web. Regards, Brad [Non-text...
10 Feb 19, 2012
2:42 pm

Brad
bcddd214
Send Email
  Newest  |  < Newer  |  Older >  |  Oldest
Add to My Yahoo!      XML What's This?

Copyright © 2010 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines NEW - Help