In collaboration with the german IT journal iX I’m going to give some computer forensics lessons in Frankfurt, Munich, Zurich and Vienna this year. 19. – 20.April 2007, Frankfurt/M. (Innside Premium Hotel) 24. – 25.April 2007, München (NH München/Dornach)
computer forensics workshops in Germany, Austria and Switzerland
«
17 January 2007 |
16:29 |
Events, Forensics, Speeches |
No Comments | 1,606 Views
»
How to locate new phishing sites
«
4 January 2007 |
12:45 |
Forensics, Security |
2 Comments | 1,446 Views
»
“Phishing sites are easy to locate once the bad boys start spamming out thousands of mails linking to their site. But how can such sites be found before that?”
“Phishing sites are easy to locate once the bad boys start spamming out thousands of mails linking to their site. But how can such sites be found before that?”
The Sleuthkit 2.07
«
16 December 2006 |
20:08 |
Forensics, Tools |
No Comments | 1,476 Views
»
Brian Carrierr released version 2.07 of his file system analysis tool The Sleuthkit: There are a lot of updates and bug fixes. The summarized list is below. The executive summary is that there are new flags for ils to find orphan files and new flags for dls to specify allocation status.There were a lot of [...]
Brian Carrierr released version 2.07 of his file system analysis tool The Sleuthkit: There are a lot of updates and bug fixes. The summarized list is below. The executive summary is that there are new flags for ils to find orphan files and new flags for dls to specify allocation status.There were a lot of [...]
Malware Analysis with PEiD
«
11 November 2006 |
15:41 |
Forensics, Live Response |
2 Comments | 2,563 Views
»
I’d like to comment on PEiD. If you have to analyse an unknown binary and you like to know some details about packers, compilers and crypto features, you should give PEiD a try.
I’d like to comment on PEiD. If you have to analyse an unknown binary and you like to know some details about packers, compilers and crypto features, you should give PEiD a try.
Buying Phishing Domain Names
«
29 October 2006 |
15:49 |
Security, Stories |
3 Comments | 4,366 Views
»
Mikko from F-Secure made a quick research on the domain name market. They made some searches on Sedo.com and found out that they are reselling domains like chasebank-online.com, citi-bank.com and bankofameriuca.com. According to Mikko and Sedo are more obviously fraudulent domains available,
Mikko from F-Secure made a quick research on the domain name market. They made some searches on Sedo.com and found out that they are reselling domains like chasebank-online.com, citi-bank.com and bankofameriuca.com. According to Mikko and Sedo are more obviously fraudulent domains available,
New Helix version released
«
12 October 2006 |
15:09 |
Forensics, Live Response, Tools |
1 Comment | 2,087 Views
»
There is a new Helix (Incident Response & Computer Forensics Live CD based on Knoppix) version released. Version 1.8 has a now Andreas Schuster’s PTFinder included an will no longer change JFS information. You can donwload Helix here. All new features at a glance:
There is a new Helix (Incident Response & Computer Forensics Live CD based on Knoppix) version released. Version 1.8 has a now Andreas Schuster’s PTFinder included an will no longer change JFS information. You can donwload Helix here. All new features at a glance:
New eventlog format in Vista
«
10 October 2006 |
17:34 |
Forensics |
No Comments | 1,408 Views
»
Andreas Schuster wrote in his blog about the new event log format in Vista. He also has a good
Andreas Schuster wrote in his blog about the new event log format in Vista. He also has a good
additional hands-on training course on computer forensics in Berlin
«
8 October 2006 |
9:30 |
Events, Forensics |
No Comments | 1,435 Views
»
There is an additional hands-on training course on computer forensics in Berlin available. More information here.
There is an additional hands-on training course on computer forensics in Berlin available. More information here.
FSP/FRU File Copy Client released
«
3 October 2006 |
14:02 |
Forensics, Live Response, Tools |
No Comments | 1,294 Views
»
Harlan Carvey just released the FSP/FRU File Copy Client on SourceForge. The FCli is a GUI client that the investigator can use to select files to be copied from the suspect system, over to the FSP server.
Harlan Carvey just released the FSP/FRU File Copy Client on SourceForge. The FCli is a GUI client that the investigator can use to select files to be copied from the suspect system, over to the FSP server.
Live Evidence Preview with Shadow 2
«
29 September 2006 |
18:10 |
Forensics, Tools |
No Comments | 1,841 Views
»
For the German journal iX we tested recently the Shadow 2 box from VOOM Technologies
For the German journal iX we tested recently the Shadow 2 box from VOOM Technologies
