forensiczone.blogspot.com
ForensicZone: WACCI Conference 2012 - Tip and Tricks Notes
http://forensiczone.blogspot.com/2012/10/wacci-conference-2012-tip-and-tricks.html
A site for “Computer Crime” Investigators Where we can share our tips, tricks and mistakes…. Friday, October 12, 2012. WACCI Conference 2012 - Tip and Tricks Notes. Wisconsin Association Computer Crimes Investigator Conference 2012. Tip and Tricks Notes:. Thank you" for all the great input. UPX ENCASE GREP Expression xE0UPX x00 x00. Im not clear on what youre trying to say here. October 14, 2012 at 4:18 AM. October 14, 2012 at 10:28 AM. Uh, okay.thanks. Any feedback on the tool? Memory Imaging Tool - Wiki.
forensiczone.blogspot.com
ForensicZone: October 2010
http://forensiczone.blogspot.com/2010_10_01_archive.html
A site for “Computer Crime” Investigators Where we can share our tips, tricks and mistakes…. Sunday, October 17, 2010. New Win7 Process Enscript (Beta). I updated my Basic Memory Analysis Enscripts. Version 6) and rolled them out at the 2010 WACCI. Conference. The newest addition is an Enscript to carve for Windows 7 Processes (Exited and Running). Important - -If you downloaded the new Enscripts prior to 10/17/2010 please update your download to Version 2.1. Some Information Regarding the New Enscripts:.
forensiczone.blogspot.com
ForensicZone: June 2008
http://forensiczone.blogspot.com/2008_06_01_archive.html
A site for “Computer Crime” Investigators Where we can share our tips, tricks and mistakes…. Thursday, June 5, 2008. Winenexe - RAM Imaging Tool Included in New Version of Encase. Today when I downloaded the latest version of Encase (6.11.0.43) I discovered winen.exe in the Encase Program Folder. Apparently winen.exe is the new RAM Acquisition Tool Provided by Guidance. Winen.exe is suppose to work on all variations of Windows higher then 2000. Guidance Forum Access Required - 3 pages). I then created a ...
jurnal-singkat.blogspot.com
Micro Journal: Building a portable GSM BTS using the Nuand bladeRF, Raspberry Pi and YateBTS (The Definitive and Step by Step Guide)
http://jurnal-singkat.blogspot.com/2016/04/building-portable-gsm-bts-using-nuand.html
Artikel-artikel singkat berisi daftar tautan gak penting banget tapi kadang diperlukan. Monday, April 25, 2016. Building a portable GSM BTS using the Nuand bladeRF, Raspberry Pi and YateBTS (The Definitive and Step by Step Guide). Https:/ blog.strcpy.info/2016/04/21/building-a-portable-gsm-bts-using-bladerf-raspberry-and-yatebts-the-definitive-guide/. Building a portable GSM BTS using the Nuand bladeRF, Raspberry Pi and YateBTS (The Definitive and Step by Step Guide). Easy to be implemented. My first suc...
forensiczone.blogspot.com
ForensicZone: The Mystery of ROT (-29)
http://forensiczone.blogspot.com/2010/09/mystery-of-rot-29.html
A site for “Computer Crime” Investigators Where we can share our tips, tricks and mistakes…. Wednesday, September 1, 2010. The Mystery of ROT (-29). I know if your reading my blog you've seen ROT13. And know it is used by Microsoft in the UserAssist Registry Key. But now I’ve found Microsoft using ROT(-29) or Rotate Minus 29 which is considerably more devious, then ROT13, for the forensic investigator. Do the following steps to uncover ROT(-29):. 1 First find a computer running Windows 7 or Vista. Number...
forensiczone.blogspot.com
ForensicZone: April 2009
http://forensiczone.blogspot.com/2009_04_01_archive.html
A site for “Computer Crime” Investigators Where we can share our tips, tricks and mistakes…. Thursday, April 16, 2009. Sandman Shell: Batch files to Define environment variable NT SYMBOL PATH. I had the following a question from Mr Anonymous about Matthieu Suiche's Sandman Shell Project. Has anyone the same problem? I have had this problem too! I opened a new command prompt to run Sandman Shell (ha.exe). So here is how to fix both problems. First Make sure that you have the correct symbols installed on y...
forensiczone.blogspot.com
ForensicZone: January 2011
http://forensiczone.blogspot.com/2011_01_01_archive.html
A site for “Computer Crime” Investigators Where we can share our tips, tricks and mistakes…. Tuesday, January 25, 2011. EnScripts (EnPacks) to Carve iPhone SMS Messages. These are tools to find SMS Messages from physical (carve) or logical files, recovered from an iPhone (DOWNLOAD). If you obtain a logical copy of the files from the iPhone then you can use this tool to parse some of the information out of the SMS.db. I created following two Enscripts to carve out SMS Messages:. When creating these ENSCRI...
forensiczone.blogspot.com
ForensicZone: October 2013
http://forensiczone.blogspot.com/2013_10_01_archive.html
A site for “Computer Crime” Investigators Where we can share our tips, tricks and mistakes…. Wednesday, October 16, 2013. Wisconsin Association of Computer Crime Investigators 2013 Conference. Sup" (.been a long while). PTFinderFE is obsolete do to the new innovations in Volatility. Updated 10/20/13)My New Volatility Batch File Maker. Does all that PTFinderFE did and MORE! Known Issue with processing x64 memory and creating Memdump.bat, Procmemdump and Vaddump.bat files -Fix by 10-21-2013.
forensiczone.blogspot.com
ForensicZone: May 2008
http://forensiczone.blogspot.com/2008_05_01_archive.html
A site for “Computer Crime” Investigators Where we can share our tips, tricks and mistakes…. Monday, May 19, 2008. I am presenting a two-day course on RAM Acquisition and RAM Analysis at Digital Intelligence. The course is June 10-12, 2008 and is FREE. The following is a quick synopsis of the training:. RAM Analysis – Vista and Beyond. Saturday, May 3, 2008. BIOS Magic Numbers in RAM (Beta). 1 Using Encase create the following GREP Expression:. X00 x14 x00 x00 x01 x02. x03. 2 Run against the DFRWS Dump.
forensiczone.blogspot.com
ForensicZone: October 2009
http://forensiczone.blogspot.com/2009_10_01_archive.html
A site for “Computer Crime” Investigators Where we can share our tips, tricks and mistakes…. Friday, October 16, 2009. Walk-Through: Volatility Batch File Maker and Volatility's VadDump. The First 5 Steps are exactly the same as my last posted regarding Walk-Through: Volatility Batch File Maker and Volatility's ProcDump. The Walk-through Portion is repeated here for future discussions. Skip if applicable.* * * * * * * * *. 1 Download the following files from Hogfly ( Website. 8 Drop the entire vaddump di...