Unix Review > Archives > 2007 > May 2007

UnixReview.com
May 2007

More Forensic Tools

by Kristy Westphal

I recently spent a week in class learning about a forensic tool made by the IRS that is for use only by Law Enforcement. I really, really, really liked it, but I also learned a few new things about forensic processing of hard drives that I had not considered before. So, even though I may not be able to use the tool for my job, I was inspired to seek out the latest and greatest tools (or even find some old ones) that I could actually use today while doing forensic processing of hard drives and other magnetic media.

One method to help ease the pain of weeding through all the files on a hard drive image is to do a hash match of known files. Essentially, you search the drive for files, such as known operating system files, and when you have a match, you can eliminate them from your examination "landscape". This can in fact reduce your landscape significantly.

Luckily, there are databases easily available to help with this analysis. I got excited while checking out the ForInSect site, which has a plethora of information on forensics, as there are several listed. The owner of this Web site used to maintain an updated version of a hash database by Dan Farmer, but it looks like neither of those are maintained any longer. This is still a worthy site to check out, though, because the list of forensic tools is long and useful.

The NIST site is still maintained, however. Called the National Software Reference Library, they have sets for operating systems, applications, as well as images and graphics.

Sys Admin Spotlight

CMP DevNet Spotlight

Christmas Chaos
Jerry shares his gift recommendations for tech-savvy friends and family.

In the News

CD-ROM

Sys Admin and The Perl Journal CD-ROM version 11.0

Version 11.0 delivers every issue of Sys Admin from 1992 through 2005 and every issue of The Perl Journal from 1996-2002 in one convenient CD-ROM!

Order now!




MarketPlace

Workflow Enabled Help Desk & IT Service Management
Automate service desk activities and integrate processes across IT. Learn more here.

Flowcharts from C/C++ code -- Free trial download
Understand C/C++ code in less time. A new team member ? Inherited legacy code ? Get up to speed faster with Crystal Flow for C/C++. Code-formatting improves readability. Flowcharts are integrated with code browser. Export flowcharts to Visio.

Discover WinDev 11 RAD
and develop 10 times faster ! ALM, IDE, .Net, PDF, 5GL, Database, 64-bit, etc. Free Express version

Online Crash Analysis
Automatically capture customer crash data, no debugger required. Support for .NET, C++, OS X, Java.

Wanna see your ad here?