PaulDotCom mailing list archives
Anti-forensic tools
From: irongeek at irongeek.com (Adrian Crenshaw)
Date: Wed, 1 Jul 2009 09:25:53 -0400
Thanks for the suggestions. Here are my comments so far: 1. The binders subject would be great for malware analysis, but I'm not so sure for a general "cover your tracks" sort of class. 2. I've played with Alternate Data Streams before ( http://www.irongeek.com/i.php?page=security/altds), but it seems like it only hides things from an investigator that does not know about them. There are tools to find them, and won't they still show up if you do a data carve? 3. Anything out there better than CCleaner or CleanAfterMe? Thanks. Adrian On Wed, Jul 1, 2009 at 8:13 AM, <d4ncingd4n at gmail.com> wrote:
Alternate data streams on the filesystem and stego would be interesting from an antiforensics standpoint also. Sent from my Verizon Wireless BlackBerry -----Original Message----- From: iamnowonmai <iamnowonmai at gmail.com> Date: Wed, 1 Jul 2009 07:37:30 To: PaulDotCom Security Weekly Mailing List<pauldotcom at mail.pauldotcom.comSubject: Re: [Pauldotcom] Anti-forensic tools _______________________________________________ Pauldotcom mailing list Pauldotcom at mail.pauldotcom.com http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom Main Web Site: http://pauldotcom.com _______________________________________________ Pauldotcom mailing list Pauldotcom at mail.pauldotcom.com http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom Main Web Site: http://pauldotcom.com
-------------- next part -------------- An HTML attachment was scrubbed... URL: http://mail.pauldotcom.com/pipermail/pauldotcom/attachments/20090701/dd85544b/attachment.htm
Current thread:
- Anti-forensic tools Xander Solis (Jul 01)
- <Possible follow-ups>
- Anti-forensic tools Ali Emirlioglu (Jul 01)
- Anti-forensic tools iamnowonmai (Jul 01)
- Anti-forensic tools d4ncingd4n at gmail.com (Jul 01)
- Anti-forensic tools Adrian Crenshaw (Jul 01)
- Anti-forensic tools iamnowonmai (Jul 01)
- Anti-forensic tools Chris Merkel (Jul 01)
- Anti-forensic tools Jim Halfpenny (Jul 01)
- Anti-forensic tools Jody & Jennifer McCluggage (Jul 01)
- Anti-forensic tools Joel Folkerts (Jul 01)
- Anti-forensic tools Adrian Crenshaw (Jul 01)
- Anti-forensic tools Joel Folkerts (Jul 01)
- Anti-forensic tools Mad Marv (Jul 01)
- Anti-forensic tools Cody Ray (Jul 01)
- Anti-forensic tools Chris Merkel (Jul 01)
- Anti-forensic tools Adrian Crenshaw (Jul 02)
- Anti-forensic tools Dimitrios Kapsalis (Jul 02)
- Anti-forensic tools Adrian Crenshaw (Jul 02)