florensik.wordpress.com
Read-only mounting on the Mac | Flo's Forensic Scratchpad
https://florensik.wordpress.com/2010/09/03/read-only-mounting-on-the-mac
Flo's Forensic Scratchpad. Flo ren sic /fləˈrɛnsɪk/ belonging to, used in, or suitable to courts of judicature or to public discussion conducted by the owner of the blog. Read-only mounting on the Mac. Although it’s obvious I thought I post it here for the more gui-oriented Mac Users out there ;). Hdiutil attach -readonly -noverify -noautofsck /path/image file/image.dmg. This actually mounts .dmg images or dd disk images of HFS/HFS drives read-only. September 3, 2010. Laquo; Lack of postings. Get every n...
florensik.wordpress.com
Notes on flash analysis | Flo's Forensic Scratchpad
https://florensik.wordpress.com/2010/09/17/notes-on-flash-analysis
Flo's Forensic Scratchpad. Flo ren sic /fləˈrɛnsɪk/ belonging to, used in, or suitable to courts of judicature or to public discussion conducted by the owner of the blog. Notes on flash analysis. Recently I had the luck to get a malicious flash sample. Until further notice from the source I got the file from, I cannot offer them for download, but I compiled a quick list of tools / commands to get a glimpse on the analysis of flash files and what’s inside. Tools used in this article:. For flash files, thi...
florensik.wordpress.com
Lack of postings | Flo's Forensic Scratchpad
https://florensik.wordpress.com/2010/06/24/lack-of-postings
Flo's Forensic Scratchpad. Flo ren sic /fləˈrɛnsɪk/ belonging to, used in, or suitable to courts of judicature or to public discussion conducted by the owner of the blog. Some might be asking themselves why there hasn’t been a posting for some time. The reason is simply that I currently don’t do any forensic / malware research stuff but instead am very busy with other aspects of my life. As soon as I encounter something worth showing , it will be here :). June 24, 2010. Comments Off on Lack of postings.
florensik.wordpress.com
Forensic Software fails on ext4 | Flo's Forensic Scratchpad
https://florensik.wordpress.com/2010/12/15/forensic-software-fails-on-ext4
Flo's Forensic Scratchpad. Flo ren sic /fləˈrɛnsɪk/ belonging to, used in, or suitable to courts of judicature or to public discussion conducted by the owner of the blog. Forensic Software fails on ext4. I recently got a nice image of a server intrusion to analyze only to figure out they used ext4. Tools that failed to analyse ext4 correctly:. Encase ver. 6.18. Sleuthkit ver. 3.2.0. FTK Demo ver. 1.81.6. FTK 32 does not exist as a Trial / Demo Version ready for download. ). In the end I was able to do so...
florensik.wordpress.com
New Radix Anti-Rootkit version released | Flo's Forensic Scratchpad
https://florensik.wordpress.com/2010/04/19/new-radix-anti-rootkit-version-released
Flo's Forensic Scratchpad. Flo ren sic /fləˈrɛnsɪk/ belonging to, used in, or suitable to courts of judicature or to public discussion conducted by the owner of the blog. New Radix Anti-Rootkit version released. Today a new version of the free Radix Anti-Rootkit Software was release at:. Http:/ www.usec.at/radix.html. Besides some bugfixes, new Features in this release:. 10012 – FEAT: Windows 7 support. 8211; FEAT: Enumerating registered Registry Callback functions (Windows XP ). April 19, 2010. You are ...