Diaries by Keyword: forensics

DateAuthorTitle
2014-03-11Basil Alawi S.TaherIntroduction to Memory Analysis with Mandiant Redline
2014-03-07Tom WebbLinux Memory Dump with Rekall
2014-02-09Basil Alawi S.TaherMandiant Highlighter 2
2014-01-10Basil Alawi S.TaherWindows Autorun-3
2013-12-12Basil Alawi S.TaherAcquiring Memory Images with Dumpit
2013-11-21Mark Baggett"In the end it is all PEEKS and POKES."
2013-11-20Mark BaggettSearching live memory on a running machine with winpmem
2013-11-19Mark BaggettWinpmem - Mild mannered memory aquisition tool??
2013-08-26Alex StanfordStop, Drop and File Carve
2013-08-14Johannes UllrichImaging LUKS Encrypted Drives
2013-07-12Rob VandenBrinkHmm - where did I save those files?
2013-05-23Adrien de BeaupreMoVP II
2013-04-25Adam SwangerSANS 2013 Forensics Survey - https://www.surveymonkey.com/s/2013SANSForensicsSurvey
2012-11-02Daniel WesemannThe shortcomings of anti-virus software
2012-09-14Lenny ZeltserAnalyzing Malicious RTF Files Using OfficeMalScanner's RTFScan
2012-06-04Lenny ZeltserDecoding Common XOR Obfuscation in Malicious Code
2011-09-29Daniel WesemannThe SSD dilemma
2011-08-05Johannes UllrichForensics: SIFT Kit 2.1 now available for download http://computer-forensics.sans.org/community/downloads
2011-03-01Daniel WesemannAV software and "sharing samples"
2010-11-17Guy BruneauReference on Open Source Digital Forensics
2010-05-22Rick WannerSANS 2010 Digital Forensics Summit - APT Based Forensic Challenge
2010-05-21Rick Wanner2010 Digital Forensics and Incident Response Summit
2010-04-30Kevin ListonThe Importance of Small Files
2010-04-11Marcus SachsNetwork and process forensics toolset
2010-03-26Daniel WesemannSIFT2.0 SANS Investigative Forensics Toolkit released
2009-12-14Adrien de BeaupreAnti-forensics, COFEE vs. DECAF
2009-11-25Jim ClausingUpdates to my GREM Gold scripts and a new script
2009-08-18Daniel WesemannForensics: Mounting partitions from full-disk 'dd' images
2009-08-13Jim ClausingNew and updated cheat sheets
2009-07-02Daniel WesemannGetting the EXE out of the RTF
2009-02-02Stephen HallHow do you audit your production code?
2009-01-02Rick WannerTools on my Christmas list.
2008-11-17Marcus SachsNew Tool: NetWitness Investigator
2008-08-17Kevin ListonVolatility 1.3 Released
2008-08-15Jim ClausingOMFW 2008 reflections