Steve's Technology Update

a place where I unload some of the tech info I run across . . .

Friday, January 31, 2014

NTFS $I30 Index Attributes: Evidence of Deleted and Overwritten Files

http://forensicmethods.com/ntfs-index-attribute
Posted by gamp.sca at 11:19 AM No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

Recycle Bin Forensics

http://dereknewton.com/2010/06/recycle-bin-forensics-in-windows-7-and-vista/
Posted by gamp.sca at 11:16 AM No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

Thursday, January 30, 2014

MacGyver IT: 21 tools for IT Heroes

http://www.infoworld.com/slideshow/137851/macgyver-it-21-tools-it-heroes-235192?source=IFWNLE_nlt_daily_am_2014-01-30
Posted by gamp.sca at 12:22 PM No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

Sunday, January 26, 2014

Windows 7 Forensic Time Information

UTC = Local Time + ActiveTimeBias
Local Time = UTC – ActiveTimeBias
Standard Time = Bias + StandardBias
Daylight Time = Bias + DaylightBias

http://www.forensicfocus.com/downloads/windows-registry-quick-reference.pdf
Posted by gamp.sca at 8:21 PM No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

Forensic Analysis of the Windows 7 Registry

http://ro.ecu.edu.au/cgi/viewcontent.cgi?article=1071&context=adf
Posted by gamp.sca at 7:05 PM No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

Friday, January 10, 2014

Yahoo Messenger Forensics

https://www.cerias.purdue.edu/assets/pdf/bibtex_archive/2011-11.pdf http://www.cerias.purdue.edu/news_and_events/events/security_seminar/details/index/nj3red9gie9h6bvmu8dklllpgo
Posted by gamp.sca at 5:05 PM No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

Windows 7 Registry Forensics: Part 4

http://www.forensicmag.com/articles/2012/04/windows-7-registry-forensics-part-4#.Us7cCU6BrIU
Posted by gamp.sca at 1:35 AM No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

Windows 7 Last Logon Date/Time

Last logon value is stored in "SAM\Domains\Account\Users\F". Bytes 9-16 of this key stores it.
Posted by gamp.sca at 1:20 AM No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

Monday, January 6, 2014

An Examination of the NTFS Volume Boot Record

http://thestarman.pcministry.com/asm/mbr/NTFSBR.htm
Posted by gamp.sca at 10:34 AM No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

Saturday, January 4, 2014

Forensic - Password Hint Location

http://news.softpedia.com/newsImage/Windows-7-and-Windows-8-Registries-Reveal-Password-Hints-Researchers-Find-2.jpg/
Posted by gamp.sca at 6:55 PM No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

Windows 7 Registry Forensics

http://www.dfinews.com/articles/2012/07/windows-7-registry-forensics-part-7#.Usfmck6BrIU
Posted by gamp.sca at 6:52 PM No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Links

  • Steve's Online Information

Blog Archive

  • ►  2018 (2)
    • ►  October (2)
  • ►  2016 (2)
    • ►  October (2)
  • ►  2015 (3)
    • ►  December (1)
    • ►  May (2)
  • ▼  2014 (30)
    • ►  December (1)
    • ►  October (1)
    • ►  September (2)
    • ►  July (1)
    • ►  May (4)
    • ►  April (3)
    • ►  March (5)
    • ►  February (2)
    • ▼  January (11)
      • NTFS $I30 Index Attributes: Evidence of Deleted an...
      • Recycle Bin Forensics
      • MacGyver IT: 21 tools for IT Heroes
      • Windows 7 Forensic Time Information
      • Forensic Analysis of the Windows 7 Registry
      • Yahoo Messenger Forensics
      • Windows 7 Registry Forensics: Part 4
      • Windows 7 Last Logon Date/Time
      • An Examination of the NTFS Volume Boot Record
      • Forensic - Password Hint Location
      • Windows 7 Registry Forensics
  • ►  2013 (14)
    • ►  October (2)
    • ►  September (1)
    • ►  August (4)
    • ►  July (5)
    • ►  January (2)
  • ►  2012 (17)
    • ►  October (1)
    • ►  May (3)
    • ►  April (13)

About Me

gamp.sca
View my complete profile
Simple theme. Powered by Blogger.