<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6297075682598647525</id><updated>2012-01-19T06:49:15.974-08:00</updated><category term='Treo'/><category term='Vista'/><category term='IACIS'/><category term='Suiche'/><category term='VMWARE'/><category term='Enscript'/><category term='Didier Stevens'/><category term='User Assist'/><category term='RAM Analysis'/><category term='Hiberfil'/><category term='PTFinder'/><category term='RAM'/><category term='DD'/><category term='Registry'/><category term='HogFly'/><category term='Sim'/><category term='Digital Intelligence'/><category term='Guillotine'/><category term='Moyix'/><category term='Forensic'/><category term='Encase'/><category term='Sandman'/><category term='Cell Phone Forensics'/><category term='Speaker'/><category term='Passwords'/><category term='Schuster'/><category term='Volatility'/><category term='Carvey'/><category term='Malware Analysis'/><category term='BIOS'/><category term='ROT-13'/><title type='text'>ForensicZone</title><subtitle type='html'>A site for “Computer Crime” Investigators 
Where we can share our tips, tricks and mistakes…</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>31</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-8259589151044060646</id><published>2011-01-25T16:12:00.000-08:00</published><updated>2011-02-01T14:56:29.191-08:00</updated><title type='text'>EnScripts (EnPacks)  to Carve iPhone SMS Messages</title><summary type='text'>These are tools to find SMS Messages from physical (carve) or logical files, recovered from an iPhone (DOWNLOAD).  This tool is really meant to find unallocated SMS Messages in a Raw disk recovery of the user disk partition as extracted by tools (http://oreilly.com/catalog/9780596153595)like the one created by Johnathon Zdziarski. (http://www.zdziarski.com/blog/?page_id=503).If you obtain a </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/8259589151044060646/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=8259589151044060646&amp;isPopup=true' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8259589151044060646'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8259589151044060646'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2011/01/enscripts-enpacks-to-carve-iphone-sms.html' title='EnScripts (EnPacks)  to Carve iPhone SMS Messages'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-5501827230850390910</id><published>2010-10-17T11:48:00.000-07:00</published><updated>2010-10-18T09:01:26.604-07:00</updated><title type='text'>New Win7 Process Enscript (Beta)</title><summary type='text'>I updated my Basic Memory Analysis Enscripts (Version 6) and rolled them out at the 2010 WACCI Conference.  The newest addition is an Enscript to carve for Windows 7 Processes (Exited and Running).Important ---If you downloaded the new Enscripts prior to 10/17/2010 please update your download to Version 2.1 - I made some changes to the Win7 (Beta) Enscript.The magic number I am using is part of </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/5501827230850390910/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=5501827230850390910&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/5501827230850390910'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/5501827230850390910'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2010/10/new-win7-process-enscript-beta.html' title='New Win7 Process Enscript (Beta)'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_hY2DP93xK6Q/TLtHS-MSRdI/AAAAAAAAAJk/8cVUP4Q9mtk/s72-c/others1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-5766328549376748537</id><published>2010-09-01T08:18:00.000-07:00</published><updated>2010-09-01T14:48:27.512-07:00</updated><title type='text'>The Mystery of  ROT (-29)</title><summary type='text'>I know if your reading my blog you've seen ROT13 and know it is used by Microsoft in the UserAssist Registry Key.But now I’ve found  Microsoft using ROT(-29) or Rotate Minus 29 which is considerably more devious, then ROT13, for the forensic investigator. Do the following steps to uncover ROT(-29):1.  First find a computer running Windows 7 or Vista.2.  Open Notepad and type: “</summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/5766328549376748537/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=5766328549376748537&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/5766328549376748537'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/5766328549376748537'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2010/09/mystery-of-rot-29.html' title='The Mystery of  ROT (-29)'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_hY2DP93xK6Q/TH5wLZvOlVI/AAAAAAAAAIs/iXH4gyC9O4U/s72-c/taskmgr.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-4364601423006442058</id><published>2009-10-16T16:20:00.000-07:00</published><updated>2009-10-20T08:57:57.948-07:00</updated><title type='text'>Walk-Through: Volatility Batch File Maker and Volatility's VadDump</title><summary type='text'>*********** The First 5 Steps are exactly the same as my last posted regarding Walk-Through: Volatility Batch File Maker and Volatility's ProcDump.  The Walk-through Portion is repeated here for future discussions.  Skip if applicable.******************1.  Download  the following files from Hogfly (Website)exemplar6.tar.gz.001exemplar6.tar.gz.002exemplar6.tar.gz.003In my example I placed the </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/4364601423006442058/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=4364601423006442058&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/4364601423006442058'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/4364601423006442058'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2009/10/walk-through-volatility-batch-file_16.html' title='Walk-Through: Volatility Batch File Maker and Volatility&apos;s VadDump'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_hY2DP93xK6Q/Stj2G6J6rBI/AAAAAAAAAIU/xfpgGUwRtTA/s72-c/exemplar6_txt.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-6650037362448976186</id><published>2009-10-16T15:25:00.000-07:00</published><updated>2009-10-17T16:11:26.733-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PTFinder'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='HogFly'/><category scheme='http://www.blogger.com/atom/ns#' term='Volatility'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><title type='text'>Walk-Through: Volatility Batch File Maker and Volatility's ProcDump</title><summary type='text'>1.  Download  the following files from Hogfly (Website)exemplar6.tar.gz.001exemplar6.tar.gz.002exemplar6.tar.gz.003In my example I placed the files in e:\exemlar6\ directory2.  Add the downloaded files together and extract with the following cmd prompt code:  Copy /b “exemplar6.tar.gz.001”+ “exemplar6.tar.gz.002”+” exemplar6.tar.gz.003” exemplar6.tar.gz3.  Extract using WinRAR (exemplar6.tar.gz </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/6650037362448976186/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=6650037362448976186&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/6650037362448976186'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/6650037362448976186'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2009/10/walk-through-volatility-batch-file.html' title='Walk-Through: Volatility Batch File Maker and Volatility&apos;s ProcDump'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_hY2DP93xK6Q/Stj2G6J6rBI/AAAAAAAAAIU/xfpgGUwRtTA/s72-c/exemplar6_txt.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-4639378843550317796</id><published>2009-10-16T08:55:00.000-07:00</published><updated>2009-10-16T15:40:29.921-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PTFinder'/><category scheme='http://www.blogger.com/atom/ns#' term='Volatility'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='Schuster'/><category scheme='http://www.blogger.com/atom/ns#' term='Sandman'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>Volatility Batch File Maker</title><summary type='text'>The Tool:   VolatilityBatch File Maker           DownloadI wanted to take the text output of the various tools (Ptfinder, PtFinderFE and Volatility &gt;PsScan2) which identifies all the offsets for (running) processes and input that offset data into several Volatility tools (ProcDump, MemDmp and VadDump).  This program creates three batch files.  After running the batch files I can quickly leverage </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/4639378843550317796/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=4639378843550317796&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/4639378843550317796'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/4639378843550317796'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2009/10/volatility-batch-file-maker.html' title='Volatility Batch File Maker'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_hY2DP93xK6Q/SticbSbNCgI/AAAAAAAAAIM/ECUyLgTDDsk/s72-c/screenshot.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-6585934571491598639</id><published>2009-04-16T13:31:00.000-07:00</published><updated>2009-04-16T13:44:20.768-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Suiche'/><category scheme='http://www.blogger.com/atom/ns#' term='Sandman'/><category scheme='http://www.blogger.com/atom/ns#' term='Hiberfil'/><category scheme='http://www.blogger.com/atom/ns#' term='DD'/><title type='text'>Sandman Shell:  Batch files to Define environment variable _NT_SYMBOL_PATH</title><summary type='text'>I had the following a question from Mr Anonymous about Matthieu Suiche's Sandman Shell Project:“...the same happens with hibrshell. When I execute the command it crashes while "Retrieving Kernel Image base". I tried with 3 different hiberfil.sys files so I guess it's not the file. The bad thing is that I also tried with different pcs and it crashed too, this means that I have no idea of what it </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/6585934571491598639/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=6585934571491598639&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/6585934571491598639'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/6585934571491598639'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2009/04/sandman-shell-batch-files-to-define.html' title='Sandman Shell:  Batch files to Define environment variable _NT_SYMBOL_PATH'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-1855646375488166591</id><published>2009-02-21T14:42:00.000-08:00</published><updated>2009-02-21T15:55:34.617-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='VMWARE'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>VMWare Running?  Better Check for Different Windows Operating System's EPROCESS Blocks</title><summary type='text'>Identify Multiple Windows OS Versions in a Single RAM Capture if the Host Machine is Running VMWare Machines.I often run VMWare Machines, on my host machine,so I can easily grab the machine's RAM contents by suspending the machine and analyzing the VMEM file.  Nothing new there.  But what is cool is when you run several VMWare machines (or just one) and grab the RAM of the host machine.   If you </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/1855646375488166591/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=1855646375488166591&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/1855646375488166591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/1855646375488166591'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2009/02/vmware-running-better-check-your-ram.html' title='VMWare Running?  Better Check for Different Windows Operating System&apos;s EPROCESS Blocks'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-4935538602200156818</id><published>2009-01-28T18:05:00.000-08:00</published><updated>2009-01-29T16:24:49.448-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='Volatility'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='Registry'/><category scheme='http://www.blogger.com/atom/ns#' term='Moyix'/><title type='text'></title><summary type='text'>Using Volatility (1.3_Beta), Volatility Plugin from Moyix, a test RAM Image (xp-laptop-2005-06-25.img) and a Windows Hash/Password Finder (SamInside or Cain and Abel) identify the  passwords for the following users: Sarah, phoenix and the Administrator. 1. Run hivescan to get hive offsetscommand:    python volatility hivescan -f "C:\Dump\xp-laptop-2005-06-25.img"Offset          (hex)          </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/4935538602200156818/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=4935538602200156818&amp;isPopup=true' title='18 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/4935538602200156818'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/4935538602200156818'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2009/01/using-volatility-1.html' title=''/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><thr:total>18</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-8212613332511694789</id><published>2008-06-05T21:29:00.001-07:00</published><updated>2008-12-09T06:26:34.410-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PTFinder'/><category scheme='http://www.blogger.com/atom/ns#' term='Enscript'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><category scheme='http://www.blogger.com/atom/ns#' term='Encase'/><title type='text'>Winen.exe - RAM Imaging Tool Included in New Version of Encase</title><summary type='text'>Today when I downloaded the latest version of Encase (6.11.0.43) I discovered winen.exe in the Encase Program Folder.  Apparently winen.exe is the new RAM Acquisition Tool Provided by Guidance. Winen.exe is suppose to work on all variations of Windows higher then 2000.A search of Guidance Support Portal and I was able to down Winen.pdf. (Guidance Forum Access Required - 3 pages).The Winen </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/8212613332511694789/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=8212613332511694789&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8212613332511694789'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8212613332511694789'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2008/06/winenexe-ram-imaging-tool-included-in.html' title='Winen.exe - RAM Imaging Tool Included in New Version of Encase'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_hY2DP93xK6Q/SEjLHJ6VawI/AAAAAAAAAEU/tRMzp9HqxsU/s72-c/winen_config.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-5577435260974996489</id><published>2008-05-19T21:44:00.000-07:00</published><updated>2008-12-09T06:26:34.490-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Enscript'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='Digital Intelligence'/><category scheme='http://www.blogger.com/atom/ns#' term='Speaker'/><category scheme='http://www.blogger.com/atom/ns#' term='Guillotine'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'></title><summary type='text'>I am presenting a two-day course on RAM Acquisition and RAM Analysis at Digital Intelligence.   The course is June 10-12, 2008 and is FREE.  The following is a quick synopsis of the training:RAM Analysis – Vista and BeyondEverything run on a computer passes through the RAM at one time or another. The trick is being able to identify data found in a RAM capture and relate it back to the item that </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/5577435260974996489/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=5577435260974996489&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/5577435260974996489'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/5577435260974996489'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2008/05/i-am-presenting-two-day-course-on-ram.html' title=''/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hY2DP93xK6Q/R5g3lm9plHI/AAAAAAAAABE/FIi7tQyqtls/s72-c/dilogo.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-4785422323092205023</id><published>2008-05-03T16:54:00.000-07:00</published><updated>2008-12-09T06:26:34.638-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='BIOS'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>BIOS Magic Numbers in RAM (Beta)</title><summary type='text'>A colleague of mine approached me after teaching a class on finding information in RAM.  He asked me to prove a particular RAM acquisition came form a particular machine.  My first thought was to run to the remnants from the registry.  But do to paging of the registry and many false positives this proved a little more difficult then I originally thought...  But as you guessed by the title I then </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/4785422323092205023/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=4785422323092205023&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/4785422323092205023'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/4785422323092205023'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2008/05/bios-magic-numbers-in-ram-beta.html' title='BIOS Magic Numbers in RAM (Beta)'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_hY2DP93xK6Q/SBz7q5BLN3I/AAAAAAAAADY/wxrIXxoMkho/s72-c/bios.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-1687546367709071582</id><published>2008-05-02T21:44:00.000-07:00</published><updated>2008-05-03T16:48:05.861-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Enscript'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='IACIS'/><category scheme='http://www.blogger.com/atom/ns#' term='Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>RAM Enscript Version 1.0</title><summary type='text'>RAM ENSCRIPT UPDATED!!!  DownloadThe new RAM Enscript contains:OS IdentificationProcesses (Exited / Running)Registry Remnants (UserAssist)MSHTML Remnants MFT Parser.  Runs against RAM Dumps from Windows 2000 to Vista.Many Thanks to the First RAM Analysis Advance Class at IACIS- Thanks for the Hard Work.</summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/1687546367709071582/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=1687546367709071582&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/1687546367709071582'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/1687546367709071582'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2008/05/ram-enscript-version-10.html' title='RAM Enscript Version 1.0'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-7288858178440700269</id><published>2008-03-15T21:32:00.000-07:00</published><updated>2008-12-09T06:26:48.549-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PTFinder'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><title type='text'>Practical of “15 Minute Virus Analysis”</title><summary type='text'>I want to show a practical of my “15 Minute Virus Analysis”You must download the RADA Virus if you want to “play” along.  The RADA Virus is a REAL VIRUS SO BE CAREFUL…The RADA VIRUS was created several years ago to test other geeks participating in the HONEYNET Project. Also download one of the best solutions to the RADA Challenge (But don’t read the solution, yet…).Make three folders in </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/7288858178440700269/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=7288858178440700269&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/7288858178440700269'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/7288858178440700269'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2008/03/practical-of-15-minute-virus-analysis.html' title='Practical of “15 Minute Virus Analysis”'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_hY2DP93xK6Q/R9ynALnBNSI/AAAAAAAAADI/q63vvbiRLdc/s72-c/pic1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-8853604707643293492</id><published>2008-02-29T17:03:00.000-08:00</published><updated>2008-03-15T13:16:08.855-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='Carvey'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='Forensic'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>Fifteen Minute Malaware Analysis</title><summary type='text'>Tools:1.  VMWARE Workstation or VMWARE Server (Sever=free)2.  Windows 2000 (Small$)3.  TextScan - Free (by AnalogX)http://www.analogx.com/contents/download/program/textscan.htm4.  PtfinderFE - Free (PTFINDER by Andreas Schuster and Front-End by Richard McQuown)5.  LSPM (SourceForge)- Free (by Harlan Carvey)Steps:1.  Create a VMWARE Windows 2000 Machine.  Keep the RAM 256 MB or less (Saves </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/8853604707643293492/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=8853604707643293492&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8853604707643293492'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8853604707643293492'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2008/02/fifteen-minute-malaware-analysis.html' title='Fifteen Minute Malaware Analysis'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-8308535038846195652</id><published>2008-02-22T07:50:00.000-08:00</published><updated>2008-02-22T08:35:50.812-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='Guillotine'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>“Lest We Remember: Cold Boot Attacks on Encryption Keys"</title><summary type='text'>Seems like a team of Princeton students have put together a very well done website,  research paper (pdf) and video regarding acquiring RAM. The jist of these items shows:  Information stays in RAM after power loss and then degrades, cooling DRAM Chips will help prevent the decay of volatile memory and keys to Full Disk Encryption can be obtained by capturing RAM.The online community has </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/8308535038846195652/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=8308535038846195652&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8308535038846195652'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8308535038846195652'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2008/02/lest-we-remember-cold-boot-attacks-on.html' title='“Lest We Remember: Cold Boot Attacks on Encryption Keys&quot;'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-8408998666802801538</id><published>2008-01-27T20:43:00.000-08:00</published><updated>2008-12-09T06:26:50.147-08:00</updated><title type='text'>XPSP3 - How this is going to affect RAM Analysis?</title><summary type='text'>Well to sum up XPSP3 (for RAM Analysis) I’d say the prognosis is great.  The key offsets that I look for in the EPROCESS (Page Directory Base, Create Time Low, Create Time High, Exit Time Low, Exit Time High, PID, Image File Name) appear to be the same as XPSP2.  The Kernel Program (NTOSKRNL.exe) I use to gauge the OS Version of the RAM is also similar to previous versions.  I tried to use Windbg</summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/8408998666802801538/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=8408998666802801538&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8408998666802801538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8408998666802801538'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2008/01/xpsp3-how-this-is-going-to-affect-ram.html' title='XPSP3 - How this is going to affect RAM Analysis?'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_hY2DP93xK6Q/R51gh29plQI/AAAAAAAAACM/U4mn1nEsEig/s72-c/process.JPG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-4679176382159745278</id><published>2008-01-23T22:45:00.000-08:00</published><updated>2008-12-09T06:26:50.165-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='Digital Intelligence'/><category scheme='http://www.blogger.com/atom/ns#' term='Speaker'/><category scheme='http://www.blogger.com/atom/ns#' term='IACIS'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>Speaking Engagement</title><summary type='text'>I am presenting a two-day course on RAM Acquisition and RAM Analysis at the International Association of Computer Investigative Specialists (IACIS) 2008 CFCE Course between April 28, 2008 through May 9, 2008 in Orlando, Florida.My sponsor is Digital Intelligence.The following is a quick synopsis of the training:RAM Analysis – Vista and BeyondEverything run on a computer passes through the RAM at </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/4679176382159745278/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=4679176382159745278&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/4679176382159745278'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/4679176382159745278'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2008/01/speaking-engagement.html' title='Speaking Engagement'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hY2DP93xK6Q/R5g3lm9plHI/AAAAAAAAABE/FIi7tQyqtls/s72-c/dilogo.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-3384559687674565185</id><published>2008-01-22T21:36:00.000-08:00</published><updated>2008-12-09T06:26:50.361-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='Guillotine'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>RAM Capture Methodology</title><summary type='text'></summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/3384559687674565185/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=3384559687674565185&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/3384559687674565185'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/3384559687674565185'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2008/01/ram-capture-methodology.html' title='RAM Capture Methodology'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hY2DP93xK6Q/R5bTvG9plCI/AAAAAAAAAAQ/j-2ds1LbAXA/s72-c/ram_ca2.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-7017448545299997386</id><published>2008-01-22T21:34:00.000-08:00</published><updated>2008-01-22T21:35:39.111-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='Guillotine'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>Guillotine Steps and Conditions</title><summary type='text'>Conditions:     •             Machine is On but Not Logged In.               •             Machine is On / Logged On / Not Running Encryption. (Bitlocker,     Best Crypt…). (If running encryption make logical image immediately.)               •             You Have Physical Access to the Machine.               •             You Know What a Hard Drive Molex Cable Looks Like…               (Easiest</summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/7017448545299997386/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=7017448545299997386&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/7017448545299997386'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/7017448545299997386'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2008/01/guillotine-steps-and-conditions.html' title='Guillotine Steps and Conditions'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-184448396149902959</id><published>2008-01-22T21:26:00.000-08:00</published><updated>2008-12-09T06:26:50.621-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='Guillotine'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>"Guillotine Method" for RAM Acquisition.</title><summary type='text'>Scenario#1 You come up to a desktop computer that you     have legal authority to forensically analyze.      The computer is powered up but sitting at the Windows Login Screen.       No chance to get an image of the RAM so you pull the plug from the     back of the machine and retreat to the lab.      At the lab you discover that the hard drive has been encrypted with     BITLOCKER. What could </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/184448396149902959/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=184448396149902959&amp;isPopup=true' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/184448396149902959'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/184448396149902959'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2008/01/guillotine-method-for-ram-acquisition.html' title='&quot;Guillotine Method&quot; for RAM Acquisition.'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_hY2DP93xK6Q/R5ldy29plII/AAAAAAAAABM/FNm-AyCCqec/s72-c/Guillo1.jpg' height='72' width='72'/><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-6758394409872415897</id><published>2007-12-01T21:46:00.000-08:00</published><updated>2008-01-22T21:49:07.197-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ROT-13'/><category scheme='http://www.blogger.com/atom/ns#' term='Didier Stevens'/><category scheme='http://www.blogger.com/atom/ns#' term='User Assist'/><category scheme='http://www.blogger.com/atom/ns#' term='Registry'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>User Assist Data in the RAM Dump</title><summary type='text'>Lately some good information has         been posted on the web regarding the importance of the USER         ASSIST.                   Especially by Didier Stevens (http://blog.didierstevens.com/programs/userassist/)         and Harlan Carvey (http://windowsir.blogspot.com/)                            Recently and completely by         coincidence I found some USER ASSIST Remnants in the RAM </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/6758394409872415897/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=6758394409872415897&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/6758394409872415897'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/6758394409872415897'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2007/12/user-assist-data-in-ram-dump.html' title='User Assist Data in the RAM Dump'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-8796004960129919398</id><published>2007-11-22T22:50:00.000-08:00</published><updated>2008-12-09T06:26:50.869-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Enscript'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>RAM Enscript</title><summary type='text'>What will this ENSCRIPT find in a RAM Dump File?1.  Running and Exited Process Information2.  Operations System Information3.  USER ASSIST  RemnantsSee Output: OS     Version             Processes                 User     AssistBACKGROUND:When I originally started I wanted to be able to search a RAM Dump file and find some of the important stuff like the EPROCESS Headers.  I then wanted the OS </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/8796004960129919398/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=8796004960129919398&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8796004960129919398'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8796004960129919398'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2008/01/ram-enscript.html' title='RAM Enscript'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hY2DP93xK6Q/R5gvgm9plGI/AAAAAAAAAA8/5LrhIn97s30/s72-c/Enscri2.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-29259291334195916</id><published>2007-11-02T22:29:00.000-07:00</published><updated>2008-02-29T20:05:45.045-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Enscript'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>RAM Enscript Download</title><summary type='text'>Download RAM Enscript (SourceForge)Concerns---Bugs---CautionConcerns   1. Enscript is in BETA and still evolving!   2. VISTA Process Search String might not collect all processes (still researching to find out what is missed.  An estimate of how many are found- probably 90-95% Solution AS IS.)Known Bug   1. Microsoft Windows XP 2003 Edition is SP1 (Version 5.2600) reports as XPSP2 so check your </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/29259291334195916/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=29259291334195916&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/29259291334195916'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/29259291334195916'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2007/11/ram-enscript-download.html' title='RAM Enscript Download'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-8703110277101538310</id><published>2007-10-26T20:32:00.000-07:00</published><updated>2008-12-09T06:26:51.291-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cell Phone Forensics'/><category scheme='http://www.blogger.com/atom/ns#' term='Sim'/><title type='text'>LOCKED SIM CARD! (by RWM)</title><summary type='text'>During a recent cell phone exam, I encountered an interesting dilemma.  When the phone was powered on it required a SIM PIN.  Making things worse there was no indication who the carrier was, and the owner of the phone was unwilling to provide the code or any information.  The investigator needed information from the phone as quickly as possible.OK- so the SIM card was locked, not the phone.  Some</summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/8703110277101538310/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=8703110277101538310&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8703110277101538310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8703110277101538310'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2007/10/locked-sim-card-by-rwm.html' title='LOCKED SIM CARD! (by RWM)'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hY2DP93xK6Q/R5wJzm9plMI/AAAAAAAAABs/FYmFYRMSw6I/s72-c/Locked1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-8060625628006414534</id><published>2007-10-26T19:43:00.000-07:00</published><updated>2008-12-09T06:26:52.562-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PTFinder'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><title type='text'>PTFinderFE Output</title><summary type='text'></summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/8060625628006414534/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=8060625628006414534&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8060625628006414534'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/8060625628006414534'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2007/10/ptfinderfe-output.html' title='PTFinderFE Output'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_hY2DP93xK6Q/R5v-Km9plJI/AAAAAAAAABU/ZLcLLNvb1go/s72-c/outputImage1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-1357612849283053362</id><published>2007-10-26T19:35:00.000-07:00</published><updated>2008-01-26T19:38:28.413-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PTFinder'/><category scheme='http://www.blogger.com/atom/ns#' term='Carvey'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='Schuster'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>PTFinderFE Facts</title><summary type='text'>Who Created PTFinder ?        Andreas Schuster http://computer.forensikblog.de/en/2006/ Who Created the OS Detection Script ?        Harlan Carvey http://windowsir.blogspot.com/ What does PTFinder Do ?        PTFinder searches a memory dump of a system running Microsoft Windows for traces of processes and threads.  Some functional checks are also applied.  (According to Andreas Schuster)</summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/1357612849283053362/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=1357612849283053362&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/1357612849283053362'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/1357612849283053362'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2007/10/ptfinderfe-facts.html' title='PTFinderFE Facts'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-7088534608432375419</id><published>2007-10-23T22:48:00.000-07:00</published><updated>2008-01-23T22:53:45.923-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cell Phone Forensics'/><title type='text'>Cell Phone Terms and Dictionary</title><summary type='text'>TERMS-DEFINITIONS-ACRONYMSAcquisition – A process by which digital evidence is duplicated, copied, or imaged. (NIST)Analysis – The examination of acquired data for its significance and probative value to the case. (NIST)Authentication Mechanism – Hardware or software-based mechanisms that force users to prove their identity before accessing data on a device. (NIST)Bluetooth – A wireless protocol </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/7088534608432375419/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=7088534608432375419&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/7088534608432375419'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/7088534608432375419'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2008/10/cell-phone-terms-and-dictionary.html' title='Cell Phone Terms and Dictionary'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-2809897340198785789</id><published>2007-10-01T22:49:00.000-07:00</published><updated>2008-01-23T22:52:21.284-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cell Phone Forensics'/><title type='text'></title><summary type='text'>“Carving” out pictures from a Handset (FTK) UPDATE 01/03/2007If you have Encase you want to follow this link - Carving” out pictures from a Handset (Encase) for the following two reasons.   1. FTK (Versions 1.61a and  1.62.1) do not seem to be adding sub-case items correctly   2. Encase, after you set up and run the correct search parameters, will automatically bookmark the “carved images”.End of</summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/2809897340198785789/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=2809897340198785789&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/2809897340198785789'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/2809897340198785789'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2007/10/carving-out-pictures-from-handset-ftk.html' title=''/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-6324744027306871382</id><published>2007-09-26T20:30:00.000-07:00</published><updated>2008-01-26T20:31:03.404-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cell Phone Forensics'/><category scheme='http://www.blogger.com/atom/ns#' term='Treo'/><title type='text'>TREO 650 PALMONE</title><summary type='text'>Carrier:  Verizon    I was unable to make a download the contents of the handset using the following products ENCASE, BITPIM, PARABEN or DD so I made backup copy of the internal contents in the most forensically sound manner possible using VERIZON WIRELESS SOFTWARE INSTALLATION DISC (A/N 185-10134-01).  I installed PALM DESKTOP SOFTWARE and used HOTSYNC to make back-up files of the TREO 360 file </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/6324744027306871382/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=6324744027306871382&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/6324744027306871382'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/6324744027306871382'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2007/09/treo-650-palmone.html' title='TREO 650 PALMONE'/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6297075682598647525.post-876916197966391882</id><published>2007-09-26T20:08:00.000-07:00</published><updated>2008-12-09T06:26:54.093-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cell Phone Forensics'/><category scheme='http://www.blogger.com/atom/ns#' term='Encase'/><title type='text'></title><summary type='text'>“Carving” out pictures from a Handset (ENCASE V5)The first thing I want to clarify is the definition of “Carve” in this page.  So you, or another investigator, manually review a handset using its internal operating system and determine the picture you need is no longer on the handset. Sometimes images might not be accessible to the user but there might be images still residing in the logical </summary><link rel='replies' type='application/atom+xml' href='http://forensiczone.blogspot.com/feeds/876916197966391882/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6297075682598647525&amp;postID=876916197966391882&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/876916197966391882'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6297075682598647525/posts/default/876916197966391882'/><link rel='alternate' type='text/html' href='http://forensiczone.blogspot.com/2008/09/carving-out-pictures-from-handset.html' title=''/><author><name>ForensicZone</name><uri>http://www.blogger.com/profile/07501220425644973307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://2.bp.blogspot.com/_hY2DP93xK6Q/Sl0FjIjCSqI/AAAAAAAAAHc/ygdIn_cox5I/S220/Rorschach_blot_05.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_hY2DP93xK6Q/R5wHb29plKI/AAAAAAAAABc/yEe9ypKloyw/s72-c/carveE6.jpg' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
