Security Incidents mailing list archives

Re: Computer Forsenics-> www.fish.com/forensics


From: mike () STAR1 SIRIUS COM (mike)
Date: Mon, 3 Jan 2000 14:01:18 -0800


On Mon, 3 Jan 2000, System Administrator wrote:

Hi,
 My apologies to everyone who has sent me mail asking for more information
on computer forsenics, some y2k came up ;). I will write up a short
document explaining what I was talking about, how it is done (recovering
files that were deleted and so forth), "timetravelling", freezing a scene,
and other analysis methods as well as the tools needed to do the job. This
will not be a detailed write up, but will give you a heads up on what you
can do (Dont wanna put myself out of a job anytime soon).


Sorry if this is off-topic but it's incident-reponse related:

Dan Farmer and Wietse Venema did a forensics lecture:
http://www.fish.com/forensics/

It mentions The Coroner's Toolkit (TCT) which I have seen a beta copy of.

I don't believe it's been released yet (supposed to have been released
last year).

Happy New Years folks,
-Mike


Current thread: