forensicadventures.blogspot.com
Maegan's Forensic Adventures: The ReFS Forensics Adventure Continues
http://forensicadventures.blogspot.com/2014/03/the-refs-forensics-adventure-continues.html
Tuesday, March 11, 2014. The ReFS Forensics Adventure Continues. Over the past few months I have been attempting to understand ReFS. This post will outline what I have done with the project so far and what discoveries I have made. Sample ReFS Virtual Drive. ReFS is not bootable. This was an expected result based on prior research and information posted on MSDN. Timestamps are in same format as NTFS (Windows 64 bit Little Endian). Subscribe to: Post Comments (Atom). View my complete profile. Watermark tem...
forensicadventures.blogspot.com
Maegan's Forensic Adventures: March 2014
http://forensicadventures.blogspot.com/2014_03_01_archive.html
Thursday, March 20, 2014. File Tables in ReFS. MACE times in unallocated space file table. MACE times in allocated space file table. File Table Entry Example. Tuesday, March 11, 2014. The ReFS Forensics Adventure Continues. Over the past few months I have been attempting to understand ReFS. This post will outline what I have done with the project so far and what discoveries I have made. Sample ReFS Virtual Drive. Timestamps are in same format as NTFS (Windows 64 bit Little Endian). File Tables in ReFS.
forensicadventures.blogspot.com
Maegan's Forensic Adventures: April 2014
http://forensicadventures.blogspot.com/2014_04_01_archive.html
Saturday, April 12, 2014. Nearing the End of the ReFS Adventure. I am nearing the end of my semester and finishing up my Capstone project. I have made quite a bit of progress in discovering ReFS's structure and how it compares to NTFS. Below are my findings, including updates to the findings talked about in my post, File Tables in ReFS. Compared to NTFS there is the possibility for a significantly more slack space with ReFS. This is due to the file system defaulting to large cluster sizes. This a...These...
forensicadventures.blogspot.com
Maegan's Forensic Adventures: January 2014
http://forensicadventures.blogspot.com/2014_01_01_archive.html
Monday, January 20, 2014. An Introduction to the ReFS Forensics Adventure. This is my first post in a series of posts for my Digital Forensics Capstone. At Champlain College. Each senior has the ability to chose one project and conduct cutting-edge research on it; I have chosen to do my project on Resilient File System (ReFS). Windows Server 2012: Main operating system being used for this project. The questions I would like to answer through my research include:. What does the structure of ReFS look like?
forensicadventures.blogspot.com
Maegan's Forensic Adventures: ReFS/NTFS Comparison
http://forensicadventures.blogspot.com/2014/04/refsntfs-comparison.html
Sunday, April 6, 2014. In my last post I talked about the ReFS file table. Here's a visual comparing ReFS to NTFS:. Subscribe to: Post Comments (Atom). 160;is a recent graduate of Champlain College with a Bachelors Degree in Computer and Digital Forensics. View my complete profile. Nearing the End of the ReFS Adventure. Under the Hill Forensics. Final Update and Conclusions. Google Glass Timeline Forensics. A Forensic Examiner's Guide to Google Glass. Nick Aspinwall Digital Forensics Research.
forensicadventures.blogspot.com
Maegan's Forensic Adventures: CEIC 2014
http://forensicadventures.blogspot.com/2014/06/ceic-2014.html
Monday, June 2, 2014. A little over a week ago I had the opportunity to attend Guidance Software's Computer and Enterprise Investigations Conference (CEIC). I attended a number of sessions including Field Triage and RAM Analysis, Defrag Forensics, Vehicle System Forensics, Examining Volume Shadow Copies, APT Attacks Exposed, and Advanced Decryption, but the two that stuck with me the most were Analysis and Correlation of Mac Logs and SSD Forensics. This year was my second time going to the SSD Forensics.
forensicadventures.blogspot.com
Maegan's Forensic Adventures: June 2014
http://forensicadventures.blogspot.com/2014_06_01_archive.html
Monday, June 2, 2014. A little over a week ago I had the opportunity to attend Guidance Software's Computer and Enterprise Investigations Conference (CEIC). I attended a number of sessions including Field Triage and RAM Analysis, Defrag Forensics, Vehicle System Forensics, Examining Volume Shadow Copies, APT Attacks Exposed, and Advanced Decryption, but the two that stuck with me the most were Analysis and Correlation of Mac Logs and SSD Forensics. This year was my second time going to the SSD Forensics.
forensicadventures.blogspot.com
Maegan's Forensic Adventures: An Introduction to the ReFS Forensics Adventure
http://forensicadventures.blogspot.com/2014/01/an-introduction-to-refs-adventure.html
Monday, January 20, 2014. An Introduction to the ReFS Forensics Adventure. This is my first post in a series of posts for my Digital Forensics Capstone. At Champlain College. Each senior has the ability to chose one project and conduct cutting-edge research on it; I have chosen to do my project on Resilient File System (ReFS). Windows Server 2012: Main operating system being used for this project. The questions I would like to answer through my research include:. What does the structure of ReFS look like?
SOCIAL ENGAGEMENT