PaulDotCom mailing list archives

Forensic File Analysis


From: iamnowonmai at gmail.com (iamnowonmai at gmail.com)
Date: Thu, 11 Dec 2008 00:26:34 +0000

TSK will help you compile a timeline, (autopsy is primarily built on the  
sleuthkit tools) mactime, macrobber are the commands you might use here, on  
a dd image of the original drive - as someone mentioned above. Not sure  
with the information given what the state of the evidence is - and how  
reliable it is, though.

Might I also recommend the excellent SANS SEC504 File System Forensics  
course? Don't forget to register via the
pauldotcom link. :)

I actually *do* hold a GCIH and GCFA, although I am primarily known for  
just being lame. :)

iamnowonmai

On Dec 10, 2008 4:30pm, Kevin Shortt <kevin.shortt at gmail.com> wrote:
Any free tools out there that will preserve a windows file properties  
(access time, creator, etc..) for evidentiary purposes?



-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mail.pauldotcom.com/pipermail/pauldotcom/attachments/20081211/90c30bad/attachment.htm 


Current thread: