I gotta admit I was a bit harsh in my reply - my apologies to the OP. ... I gotta admit I was a bit harsh in my reply - my apologies to the OP. On Fri, Apr 1,...
Just trying to throw a little humor into the mix. Next time I'll work on my timing and delivery. dwr Dale W. Rogers Rogers Computer Forensics Roseville, CA...
No POVS beyond this point. POV stands for Point of View, obviously. Â So if you put up a sign that says "No POVS beyond this point," the meaning is obvious. Â ...
Request for Proposal – DFRWS Forensic Challenge 2012 The DFRWS Challenge The DFRWS Conference is soliciting proposals from individuals or teams interested in...
All, As a result of last Thu's first meet-up, I've looked into the possibility of having meetings at the Reston Regional Library. I went to the web site this...
As a follow-up, what we need from those who will be attending (or would like to attend) is: - What would you like to see discussed or presented? - Would you be...
Harlan, Sorry if this came up and I overlooked it. Have you considered the Reversespace in Herndon? http://hackerspaces.org/wiki/Reverse_Space A colleague of...
Advanced Prefetch Analyzer by Allan Hay: http://www.ash368.com/ Jimmy Weg, CFCE Agent in Charge, Computer Crime Unit Montana Division of Criminal Investigation...
I highly recommend that DFI news write-up. Very informative. Realize that there is no "tool" to analyze the prefetch files. There are tools to extract pieces...
Jimmy, Thanks for the website information. It is good to have more than one tool to do the same job. L ________________________________ From: "Weg, Jimmy"...
Anderson, ... I always use strings (remember to run strings w/ different '-e' encodings on every file) but wrt prefetch files I find Harlan's pref.pl script to...
Please pardon a cross post if you've seen this elsewhere. I have a system with two drives: Disk 1 (Win7) was formatted on 6/29/2010 and Win7 was installed on...
EnCase, but I'm a hopeless forensic geek so I tend to do a lot in hex. :) I think it's a result of getting into the industry when we didn't have all of these...
... Depends on what you mean by "analyze". I have a Perl script that I use not only for extracting the time stamp and run count metadata, but also extracting...
Jimmy, Just to confirm, while there is no "Admin" user on Disk1 (Win7), you found MSIE records related to Admin, right? Do the MSIE records point to the C:...
Thanks, Greg. I just solved the mystery. The MSIE index records that I recovered, by scavenging the physical disk, actually were in a recovery set of IMG...
Glad you solved the mystery. Thank you for the clarification regarding dates of files downloaded with Frostwire. I wasn't certain if files downloaded by...
I know that there are a couple of commercial options out there and I looked at the latest libpff but it does not, currently, support this. Has anyone used a...