redrocktx.blogspot.com
RRTX Blog: MetaDiver 2.1 has been released #metadata #data #dfir #infosec
http://redrocktx.blogspot.com/2015/08/metadiver-21-has-been-released-metadata.html
Thursday, August 13, 2015. MetaDiver 2.1 has been released #metadata #data #dfir #infosec. I’m excited to announce that MetaDiver 2.1 has been released! This is close to a full rewrite with better scalability. The ability to review metadata in MetaDiver has been greatly improved. The back-end has been rewritten to use SQLite. Many new documents are now handled including email archives, Windows Shortcuts including lnk and jumplists, legacy doc 97 and archives. Changes in 2.1. Backend rewrite to SQLite.
redrocktx.blogspot.com
RRTX Blog: February 2015
http://redrocktx.blogspot.com/2015_02_01_archive.html
Wednesday, February 25, 2015. Disk Access in Python with libtsk (by HECF Blog). If you have ever been looking for a way to access your computer disk without having to deal with user permissions and constrains the operating system enforces then this is the series to read. David Cowen is working on an excellent series called “ Automating DFIR. My hope is that better information helps to expand the user base beyond just Forensics and Incident response because it can be applied to other industries in tech.
redrocktx.blogspot.com
RRTX Blog: November 2013
http://redrocktx.blogspot.com/2013_11_01_archive.html
Tuesday, November 26, 2013. Download v1.0.7. Info: Right now it's just zipped up without an installer, I hope to add one soon. Just download, unzip and keep the files in the directory with the exe. Requirements: Windows 7 or later and .NET 4.0. Please send feedback if you like it, hate it, whatever. Links to this post. Sunday, November 17, 2013. Scripting with FTK Filters - Updated. Here is a quick and dirty. Begin Script for FTK 5. Use IO: File;. Use File: Copy;. My $path = shift ;. This filter will set...
redrocktx.blogspot.com
RRTX Blog: May 2015
http://redrocktx.blogspot.com/2015_05_01_archive.html
Wednesday, May 20, 2015. Improving Windows External Device Investigations [updated] slides posted from #CEICCONF #DFIR. My slides for the talk I gave at CEIC 2015 on Improving Windows External Device Investigations have been uploaded. You can download them below. Download: Slides for Improving Windows External Device Investigations. By Dave via EasyMetaData.com. Links to this post. Friday, May 15, 2015. Excited to be speaking on Improving Windows External Device Investigations at #CEICCONF next week #DFIR.
redrocktx.blogspot.com
RRTX Blog: Github: My open source projects are being added
http://redrocktx.blogspot.com/2015/06/github-my-open-source-projects-are.html
Tuesday, June 23, 2015. Github: My open source projects are being added. Github account created with open source projects being added. By Dave via EasyMetaData.com. Subscribe to: Post Comments (Atom). View my complete profile. MetaDiver: What’s coming in Alpha 3. Github: My open source projects are being added. MetaDiver 2.0 Alpha2 released #dfir #ediscovery. Botched iTunes Match. A post Mortem on Fixing broken songs. Scripting with FTK Filters - Updated. ShadowKit v1.6 has been released! Finding Shell M...
redrocktx.blogspot.com
RRTX Blog: July 2015
http://redrocktx.blogspot.com/2015_07_01_archive.html
Thursday, July 30, 2015. Demystify Windows 10 – Tips, Tricks and Privacy? So Windows 10 is out and I really like it so far. I’ve taken a few notes to help you on your journey. I’ll post more as I learn more. 1 You can defer upgrades and change how updates are installed to schedule a restart. I’ve read multiple articles with the author complaining about updates being forced… This is not entirely the case. Super easy). Change the selection for “ Choose how updates are installed. If you aren’t cool wi...
redrocktx.blogspot.com
RRTX Blog: June 2015
http://redrocktx.blogspot.com/2015_06_01_archive.html
Tuesday, June 23, 2015. MetaDiver: What’s coming in Alpha 3. The next alpha release of MetaDiver is coming together nicely. Lots of new features in the works. Major new features being added. I’m still coding, plus better testing on various Windows environments before I put it out there for you to break further. I plan to post open source projects relied upon to github. New features coming with v2.0.2 Alpha 3:. Email support – read headers (MSG, PST, EML) – including extended mapi goodies. You can contact...
redrocktx.blogspot.com
RRTX Blog: Links
http://redrocktx.blogspot.com/p/links.html
Hacking Exposed Computer Forensics Second Edition. Http:/ windowsir.blogspot.com/. Subscribe to: Posts (Atom). View my complete profile. Extract document #metadata – #Tika and #exiftool. Botched iTunes Match. A post Mortem on Fixing broken songs. So I have been hearing about iTunes Match for a while and I decided to go with it to get my huge music collection upgraded and cleaned. H. Scripting with FTK Filters - Updated. ShadowKit v1.6 has been released! Access Shadow Copies (VSS) Natively. The latest Vol...
redrocktx.blogspot.com
RRTX Blog: August 2015
http://redrocktx.blogspot.com/2015_08_01_archive.html
Tuesday, August 18, 2015. MetaDiver 2.1.6 released. MetaDiver v2.1.6 has been released. This build fixes a bug in email mappings. By Dave via EasyMetaData.com. Links to this post. Thursday, August 13, 2015. MetaDiver 2.1 has been released #metadata #data #dfir #infosec. I’m excited to announce that MetaDiver 2.1 has been released! Changes in 2.1. Backend rewrite to SQLite. Email header support added: MSG, PST, EML, EMLX. Email extended MAPI added – some extended mapi header information being added. View ...