Educause Security Discussion mailing list archives

Re: Forensics Tools


From: "Ward, Michael" <Mike-Ward () UTC EDU>
Date: Wed, 24 Sep 2014 19:30:20 +0000

Here’s some slides from a presentation I did last year.

http://slug.ceca.utc.edu/docs/2013-4-23-Computer-Forensics-on-the-Cheap.pdf

using SIFT and other “cheap” tools.


On Sep 23, 2014, at 6:18 PM, Daniels, Shane R <srdaniels () UMES EDU> wrote:

Thomas,

F-Response and X-Ways is a good cost effective pairing.  Then add in SIFT and you can do a lot on a small budget.

Shane Daniels

On Sep 23, 2014, at 11:18, Thomas Carter <tcarter () AUSTINCOLLEGE EDU<mailto:tcarter () AUSTINCOLLEGE EDU>> wrote:

I’m looking for good forensics tools for dealing with an individual’s laptop. Specifically looking for changes 
/deletions /etc.  I do realize the minefield this can be, and will be done at the request of, and in conjunction 
with, the HR department and school lawyers. Are there any packages anyone has used in the past they can recommend?

Thomas Carter
Network and Operations Manager
Austin College
903-813-2564
<image001.gif>


CONFIDENTIALITY NOTICE: This message may contain confidential information intended only for the use of the person 
named above and may contain communication protected by law. If you have received this message in error, you are 
hereby notified that any dissemination, distribution, copying or other use of this message may be prohibited and you 
are requested to delete and destroy all copies of the email, and to notify the sender immediately at his/her 
electronic mail.
<image001.gif>


Current thread: