<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>geschonneck.com &#187; Tools</title>
	<atom:link href="http://geschonneck.com/category/forensics/tools/feed/" rel="self" type="application/rss+xml" />
	<link>http://geschonneck.com</link>
	<description>This is the private security page of Alexander Geschonneck (Berlin, Germany).</description>
	<lastBuildDate>Sun, 01 Apr 2012 15:19:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Windows Memory Forensics Tools [update]</title>
		<link>http://geschonneck.com/2008/12/23/windows-memory-forensics-tools/</link>
		<comments>http://geschonneck.com/2008/12/23/windows-memory-forensics-tools/#comments</comments>
		<pubDate>Tue, 23 Dec 2008 20:32:58 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[forensics tools]]></category>
		<category><![CDATA[memory analysis]]></category>

		<guid isPermaLink="false">http://geschonneck.com/?p=179</guid>
		<description><![CDATA[SANS recently published a good summary of Windows memory forensics acquisition and analysis tools. It&#8217;s a good compilation of must have tools for the right occasion. SANS forensics [update] new url [/update]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" style="margin-left: 3px; margin-right: 3px;" title="icon" src="/images/icons/plugin_error.png" alt="" width="16" height="16" />SANS recently published a good summary of Windows memory forensics acquisition and analysis tools. It&#8217;s a good compilation <span id="more-179"></span>of must have tools for the right occasion.</p>
<p><a href="http://sansforensics.wordpress.com/2008/12/13/windows-physical-memory-finding-the-right-tool-for-the-job/" target="_blank">SANS forensics</a></p>
<p>[update]<a href="http://computer-forensics.sans.org/blog/2008/12/13/windows-physical-memory-finding-the-right-tool-for-the-job" target="_blank"> new url</a> [/update]</p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2008/12/23/windows-memory-forensics-tools/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>new linux incident response script</title>
		<link>http://geschonneck.com/2008/10/18/new-linux-incident-response-script/</link>
		<comments>http://geschonneck.com/2008/10/18/new-linux-incident-response-script/#comments</comments>
		<pubDate>Sat, 18 Oct 2008 10:53:05 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[forensics tools]]></category>
		<category><![CDATA[ForensiX CD]]></category>
		<category><![CDATA[Live Response]]></category>

		<guid isPermaLink="false">http://geschonneck.com/?p=172</guid>
		<description><![CDATA[We updated the ForensiX Linux Incident Response Script. You can find the new version at my german site http://computer-forensik.org/tools/ix/ix-special/.]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" style="margin: 3px;" title="cover iX special" src="http://www.heise.de/kiosk/special/ix/08/01/cd_min.gif" alt="" width="60" height="60" />We updated the ForensiX Linux Incident Response Script. You can find the new version at <span id="more-172"></span>my german site <a href="http://computer-forensik.org/tools/ix/ix-special/" target="_blank">http://computer-forensik.org/tools/ix/ix-special/</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2008/10/18/new-linux-incident-response-script/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Sleuthkit 2.10</title>
		<link>http://geschonneck.com/2007/12/13/the-sleuthkit-210/</link>
		<comments>http://geschonneck.com/2007/12/13/the-sleuthkit-210/#comments</comments>
		<pubDate>Thu, 13 Dec 2007 08:37:54 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Autopsy]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[The Sleuthkit]]></category>
		<category><![CDATA[TSK]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2007/12/13/the-sleuthkit-210/</guid>
		<description><![CDATA[A new version of The sleuthkit (TSK) is out now. There are some minor bug fixes included. Changelog and download can be found here.]]></description>
			<content:encoded><![CDATA[<p><img src="/images/icons/drive_magnify.png" alt="icon" align="absmiddle" height="16" hspace="3" width="16" />A new version of The sleuthkit (TSK) is out now.  There are some minor bug fixes included. Changelog <span id="more-140"></span>and download can be found <a href="http://sleuthkit.org/sleuthkit/download.php" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2007/12/13/the-sleuthkit-210/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New Forensics Live Response CD published</title>
		<link>http://geschonneck.com/2007/06/21/new-forensics-live-response-cd-published/</link>
		<comments>http://geschonneck.com/2007/06/21/new-forensics-live-response-cd-published/#comments</comments>
		<pubDate>Thu, 21 Jun 2007 12:49:53 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Live Response]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[forensics tools]]></category>
		<category><![CDATA[ForensiX CD]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2007/06/21/new-forensics-live-response-cd-published/</guid>
		<description><![CDATA[I&#8217;m proud to announce, that my team published yesterday a very cool Live Response CD for Linux and Windows in cooperation with the german journal iX. It contains a brand new Linux Live Response script and a build script for your own static binaries. This Live Response Script contains also an extract option, if you [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://computer-forensik.org/images/forensiX-label-small.jpg" align="left" height="102" hspace="3" width="102" />I&#8217;m proud to announce, that my team published yesterday a very cool Live Response CD for Linux and Windows in cooperation with the german journal <em>iX</em>. It contains a brand new Linux Live Response script and a build script for your own static binaries. This Live Response Script contains also an <span id="more-123"></span> extract option, if you like to organize the memory dump for an easy investigation.</p>
<p>More information about <a href="http://digital-forensics.de" target="_blank">the ForensiX CD</a></p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2007/06/21/new-forensics-live-response-cd-published/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Booting EnCase Images</title>
		<link>http://geschonneck.com/2007/05/02/booting-encase-images/</link>
		<comments>http://geschonneck.com/2007/05/02/booting-encase-images/#comments</comments>
		<pubDate>Wed, 02 May 2007 17:48:23 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Live Response]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[LiveView]]></category>
		<category><![CDATA[mount image pro]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2007/05/02/booting-encase-images/</guid>
		<description><![CDATA[GetData now bundles their forensics tool MountImage Pro v2 with Virtual Forensic Computing (VFC) from MD5 Ltd. You can now mount a forensic image with Windows and create a VMware virtual machine configuration. Hmm, WTF is the difference between VFC and the freely available LiveView? VFC is able to mount and boot EnCase and SMART [...]]]></description>
			<content:encoded><![CDATA[<p><img src="/images/icons/drive_magnify.png" align="absmiddle" height="16" hspace="3" width="16" />GetData now bundles their forensics tool MountImage Pro v2 with Virtual Forensic Computing (VFC) from MD5 Ltd. You can now mount a forensic image <span id="more-120"></span>with Windows and create a VMware virtual machine configuration. Hmm, WTF is the difference between VFC and the freely available <a href="http://geschonneck.com/2006/08/29/live-view-released/">LiveView</a>? VFC is able to mount and boot EnCase and SMART images.</p>
<p><a href="http://www.mountimage.com/" target="_blank">Link to GetData</a></p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2007/05/02/booting-encase-images/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sector Inspector (SecInspect.exe)</title>
		<link>http://geschonneck.com/2007/04/09/sector-inspector-secinspectexe/</link>
		<comments>http://geschonneck.com/2007/04/09/sector-inspector-secinspectexe/#comments</comments>
		<pubDate>Mon, 09 Apr 2007 11:52:16 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[forensics tools]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[sector inspector]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2007/04/09/sector-inspector-secinspectexe/</guid>
		<description><![CDATA[Microsoft published a tool called Sector Inspector (SecInspect.exe) with the Windows 2003 Server Resource Kit.  This is a command-line diagnostics tool that allows administrators to view the contents of master boot records, boot sectors, and IA64 GUID partition tables. Additional features include creating hex dumps of binary files and backup/restore of sector ranges.  With this [...]]]></description>
			<content:encoded><![CDATA[<p><img src="/images/icons/drive_magnify.png" title="icons" alt="icons" align="absmiddle" height="16" hspace="3" width="16" />Microsoft published a tool called Sector Inspector (SecInspect.exe) with the Windows 2003 Server Resource Kit.  This is a command-line diagnostics tool that allows administrators to view the contents of master boot records, boot sectors, and IA64 GUID partition tables. Additional features <span id="more-118"></span>include creating hex dumps of binary files and backup/restore of sector ranges.  With this tool you get a bunch of information about a connected (USB/Writeblock) drive. You can use it for documentation purposes during a forensic acquisition.<a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=DD3EF22A-A586-4079-9489-C3EA14573FC4&amp;displaylang=en" target="_blank"></a></p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=DD3EF22A-A586-4079-9489-C3EA14573FC4&amp;displaylang=en" target="_blank">Download Link</a></p>
<p>via <a href="http://forensicir.blogspot.com/2007/04/sector-inspector.html" target="_blank">HogFly</a></p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2007/04/09/sector-inspector-secinspectexe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Sleuthkit 2.08</title>
		<link>http://geschonneck.com/2007/04/06/the-sleuthkit-208/</link>
		<comments>http://geschonneck.com/2007/04/06/the-sleuthkit-208/#comments</comments>
		<pubDate>Fri, 06 Apr 2007 11:34:58 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Autopsy]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[digital investigations]]></category>
		<category><![CDATA[forensics tools]]></category>
		<category><![CDATA[The Sleuthkit]]></category>
		<category><![CDATA[TSK]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2007/04/06/the-sleuthkit-208/</guid>
		<description><![CDATA[The Sleuthkit (TSK) 2.08 is out now. The new version contains several minor bug fixes and many internal updates. This version will cleanly compile on Cygwin and hfind is now available on Win32. Download TSK]]></description>
			<content:encoded><![CDATA[<p><img src="/images/icons/drive_magnify.png" title="icon" alt="icon" align="absmiddle" height="16" hspace="3" width="16" />The Sleuthkit (TSK) 2.08 is out now. The new version contains <span id="more-117"></span><br />
several minor bug fixes and many internal updates. This version will cleanly compile on <a href="http://www.cygwin.com/" target="_blank">Cygwin</a> and hfind is now available on Win32.</p>
<p><a href="http://www.sleuthkit.org/sleuthkit/download.php" target="_blank">Download TSK </a></p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2007/04/06/the-sleuthkit-208/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DFRWS 2007 File Carving Challenge</title>
		<link>http://geschonneck.com/2007/02/20/dfrws-2007-file-carving-challenge/</link>
		<comments>http://geschonneck.com/2007/02/20/dfrws-2007-file-carving-challenge/#comments</comments>
		<pubDate>Tue, 20 Feb 2007 06:44:30 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[dfrws]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[file carving]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2007/02/20/dfrws-2007-file-carving-challenge/</guid>
		<description><![CDATA[The new DFRWS File Carving Challenge for the year 2007 has been released. The say: &#8220;The goal of this challenge is to design and develop AUTOMATED file carving algorithms that have high true positive and low false positive rates.&#8221; The challenge is organized by Brian Carrier, Eoghan Casey and Wietse Venema. The subimssions due is [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.dfrws.org/images/dfrws-logo-1.gif" title="WFRWS Logo" alt="WFRWS Logo" align="left" height="62" hspace="3" width="200" />The new DFRWS File Carving Challenge for the year 2007  has been released.  The say: &#8220;The goal of this challenge is to design and develop AUTOMATED file carving algorithms that have high true positive and low false positive rates.&#8221;</p>
<p><span id="more-113"></span> The challenge is organized by Brian Carrier, Eoghan Casey and Wietse Venema. The subimssions due is july 9, 2007.</p>
<p><a href="http://www.dfrws.org/2007/challenge/submission.html">File Image  and Submission Details</a></p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2007/02/20/dfrws-2007-file-carving-challenge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Sleuthkit 2.07</title>
		<link>http://geschonneck.com/2006/12/16/the-sleutkit-207/</link>
		<comments>http://geschonneck.com/2006/12/16/the-sleutkit-207/#comments</comments>
		<pubDate>Sat, 16 Dec 2006 19:08:41 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Autopsy]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[digital investigations]]></category>
		<category><![CDATA[forensics tools]]></category>
		<category><![CDATA[The Sleuthkit]]></category>
		<category><![CDATA[TSK]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2006/12/16/the-sleutkit-207/</guid>
		<description><![CDATA[Brian Carrierr released version 2.07 of his file system analysis tool The Sleuthkit: There are a lot of updates and bug fixes. The summarized list is below. The executive summary is that there are new flags for ils to find orphan files and new flags for dls to specify allocation status.There were a lot of [...]]]></description>
			<content:encoded><![CDATA[<p>Brian Carrierr released version 2.07 of his file system analysis tool The Sleuthkit:</p>
<blockquote><p><font> There are a lot of updates and bug fixes. The summarized list is below. The executive summary is that there are new flags for ils to  find orphan files and new flags for dls to specify allocation status.There were a lot of internal updates as well. There were a few NTFS bug fixes as well and a sorter fix for Cygwin.</font></p></blockquote>
<p><span id="more-90"></span><font> Updates in version 2.07:</font></p>
<p><font> </font></p>
<ul>
<li><font>Added &#8216;-p&#8217;  flag to ils to find orphan files</font></li>
<li><font>Added &#8216;-a&#8217; and &#8216;-A&#8217; flags to dls to specify allocation status</font></li>
<li><font>Detect and prevent infinite loops in corrupt directories and FAT files.</font></li>
<li><font> Updated AFFLIB, libewf, and file</font></li>
<li><font>improved FAT dentry detection (check size)</font></li>
<li><font>new internal fs_read_file()</font></li>
<li><font> Windows visual studio files included with source code</font></li>
<li><font>cleaned up error reporting code</font></li>
<li><font>added caching to FAT code.</font></li>
<li><font>Added a NULL check to fs_inode_free (Michael Cohen)</font></li>
<li><font>Improved ifind_path code so that allocated names are given priority  (Dave Collett)</font></li>
</ul>
<p><font> Bug Fixes in version 2.07:<br />
</font></p>
<ul>
<li><font> NTFS compression bug with corrupt data</font></li>
<li><font>sanity check to dcat_lib in case the requested number of blocks was too big.</font></li>
<li><font>fs_data lookup bug fixes by Dave Collett.</font></li>
<li><font>sorter does not clear path so it can run under Cygwin</font></li>
<li><font>Memory leak fixes in FAT and NTFS.</font></li>
</ul>
<p>You can download The Sleuthkit <a href="http://www.sleuthkit.org/sleuthkit/" target="_blank">here </a></p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2006/12/16/the-sleutkit-207/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Helix version released</title>
		<link>http://geschonneck.com/2006/10/12/new-helix-version-released/</link>
		<comments>http://geschonneck.com/2006/10/12/new-helix-version-released/#comments</comments>
		<pubDate>Thu, 12 Oct 2006 14:09:13 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Live Response]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[forensics tools]]></category>
		<category><![CDATA[Helix]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2006/10/12/new-helix-version-released/</guid>
		<description><![CDATA[There is a new Helix (Incident Response &#38; Computer Forensics Live CD based on Knoppix) version released. Version 1.8 has a now Andreas Schuster&#8217;s PTFinder included an will no longer change JFS information. You can donwload Helix here. All new features at a glance: Linux Side: - Fixed Helix Mount code for journaled file systems. [...]]]></description>
			<content:encoded><![CDATA[<p>There is a new Helix (Incident Response &amp; Computer Forensics Live CD based on Knoppix) version released. Version 1.8 has a now Andreas Schuster&#8217;s PTFinder included an will no longer change JFS information. You can donwload Helix <a href="http://www.e-fense.com/helix/" target="_blank">here</a>.<br />
All new features at a glance:<span id="more-77"></span></p>
<p>Linux Side:<br />
- Fixed Helix Mount code for journaled file systems. Helix will NO longer change the journal mount count when you mount a journaled file system.<br />
- Updated md5deep suite to 1.12<br />
- Updated Clamav to 0.88.2<br />
- Updated Sleuthkit to 2.06<br />
- Updated Autopsy to 2.08<br />
- Updated Foremost to 1.3<br />
- Updated Scalpel 1.54 to carve data<br />
- Updated EnCase Linen to 5.05f<br />
- Updated Adepto 2.0 &#8211; With AFF support now<br />
- Added endeavour2 file manager<br />
- Added ssdeep 1.0 for fuzy hashing<br />
- Added AFFlib 1.6.31 for image acquisition<br />
- Added NTFS-3G for native NTFS write support<br />
- Added libewf library<br />
- Added ptfinder memory analysis code from Andreas Schuster<br />
- Removed Solaris static binaries from CD<br />
- Replaced evince with xpdf<br />
Windows Side:<br />
- Updated the Helix executable code<br />
- Update code for command shell paths<br />
- Update all Cygwin tools to latest<br />
- Updated all unxutil tools<br />
- Updated Static Binaries (linux)<br />
- Updated MessenPass to v1.08<br />
- Updated Mail PassView to v1.36<br />
- Updated Protected Storage PassView to v1.63<br />
- Updated Network Password Recovery to v1.03<br />
- Updated IECookiesView to v1.70<br />
- Updated IEHistoryView to v1.32<br />
- Updated RegScanner to v1.30<br />
- Updated FTK Imager to 1.5.1<br />
- Updated Forensic Server Project to 1.0<br />
- Updated PsTools Version to 2.34 (Psexec, psinfo, pslist, etc)<br />
- Updated Process Explorer to 10.2<br />
- Added PstPassword v1.00<br />
- Added Access PassView 1.12<br />
- Added PC On/Off Time<br />
- Added Winaudit v2.15<br />
- Added Drive Manager v3.23<br />
- Added ReSysInfo v2.1<br />
- Added Icon to start a NC listener<br />
- Added code to Windows GUI for investigative notes</p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2006/10/12/new-helix-version-released/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>FSP/FRU File Copy Client released</title>
		<link>http://geschonneck.com/2006/10/03/fspfru-file-copy-client-released/</link>
		<comments>http://geschonneck.com/2006/10/03/fspfru-file-copy-client-released/#comments</comments>
		<pubDate>Tue, 03 Oct 2006 13:02:16 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Live Response]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[forensics tools]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2006/10/03/fspfru-file-copy-client-released/</guid>
		<description><![CDATA[Harlan Carvey just released the FSP/FRU File Copy Client on SourceForge. The FCli is a GUI client that the investigator can use to select files to be copied from the suspect system, over to the FSP server.]]></description>
			<content:encoded><![CDATA[<p>Harlan Carvey <a href="http://windowsir.blogspot.com/2006/10/fspfru-file-copy-client-posted.html" target="_blank">just released</a> the FSP/FRU File Copy Client on <a href="http://sourceforge.net/project/showfiles.php?group_id=164158" target="_blank">SourceForge</a>. The FCli is a GUI client that the investigator can use to select files to be copied from the suspect system, over to the FSP server.</p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2006/10/03/fspfru-file-copy-client-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Live Evidence Preview with Shadow 2</title>
		<link>http://geschonneck.com/2006/09/29/live-evidence-preview-with-shadow-2/</link>
		<comments>http://geschonneck.com/2006/09/29/live-evidence-preview-with-shadow-2/#comments</comments>
		<pubDate>Fri, 29 Sep 2006 17:10:20 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[evidence preview]]></category>
		<category><![CDATA[forensics tools]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2006/09/29/live-evidence-preview-with-shadow-2/</guid>
		<description><![CDATA[For the German journal iX we tested recently the Shadow 2 box from VOOM Technologies. The VOOM Shadow 2 is a computer hardware device that is designed to aid the investigation of a suspect hard drive. It provides investigators with virtual read write access from the host computer&#8217;s perspective, while maintaining the original hard drive [...]]]></description>
			<content:encoded><![CDATA[<p>For the German journal <a href="http://www.heise.de/ix/" target="_blank">iX </a>we tested recently the Shadow 2 box from <a href="http://www.voomtech.com/shadow2.html" target="_blank">VOOM Technologies</a><span id="more-70"></span>. The VOOM Shadow 2 is a computer hardware device                     that is designed to aid the investigation of a suspect                     hard drive. It provides investigators with virtual read write access                     from the host computer&#8217;s perspective, while maintaining the                   original hard drive unchanged. You can use this for preview a drive prior to                         imaging in the field. We checked with HPA and DCO &#8211; everything worked fine according to our checksums.<br />
Read more on <a href="http://computer-forensik.org/2006/09/29/hokus-pokus-mit-voom-shadow-2/" target="_blank">my German computer forensics blog</a>.</p>
<p><strong>Update: </strong>No, I have no connection with this vendor. <img src="http://geschonneck.com/wp-content/plugins/more-smilies/Phoenity/wink.png" alt="-)" class="wp-smiley" /> </p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2006/09/29/live-evidence-preview-with-shadow-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 1.370 seconds -->

