The Electronic Evidence Information Center

Home


Digital Forensics BIBLIO


What's New


ALL
Other Resources


Digital Forensic Books


OS Specific Articles


Links to Links


Reciprocal Links


About This Site

  November 2004


FEATURED SITE(S)

James Nerlinger's ISP Contact List (Updated October 2004) [PDF]

American Academy of Applied Forensics (Digital Evidence Training)


Past Updates

2004
January 2004 February 2004 March 2004
April 2004 May 2004 June 2004
July 2004 August 2004 September 2004
October 2004 November 2004 December 2004

2003
February 2003 March 2003 April 2003
May 2003 June 2003 July 2003
August 2003 September 2003 October 2003
November 2003 December 2003  


Within the Bibliography section

Brown, Christopher

Carrier, Brian

Carrier, Brian D. & Eugene H. Spafford

Christy, Jim

Cox, Charlie

Devera, Dean

Dykstra, Brian & Virtual War Unlimited

EU Commission

Guttman, Boaz

Hodges, Keith

Laliberte, Scott & Ajay Gupta

Lam, Patrick

Lewis, Paul G.

Linux Security Research Center (Chonnam National University)

Maurer, Ueli

Medford, MA Police Department

Mislan, Richard P.

Morgester, Robert M.

NIST, Rick Ayers & Wayne Jansen

NHTCU

Othman, Kamal Hilmi

Parsons, Ian

  • Forensic tools (Group Test) August 2004
    Tools Tested: AccessData Ultimate Toolkit, EnCase Forensic Edition, Freeware and open-source tools, NetWitness Professional Edition, ProDiscover Incident Response, Vogon Investigation Software, Wiebetech Forensic ComboDock

Phifer, Lisa

Rathore, Balwant

Rusch, Jonathan J.

Sedory, Daniel B.

Seward, Jack

Smith, Stuart

Sremack, Joseph C.

Stenhouse, David P.

Tran, Peter M.

Wolfe, Heank


Within Legalese section

Brill, Alan E. et alia

Cohen, Adam I. & Gina A. Dombosch

eneate

Fujitsu

Llewellyn, Virginia R. & E. Pennock Gheen

NCSC's Civil Action Publication

Natsui, Takato

Setec Investigations

Seward, Jack

Sinrod, Eric J.

Sinrod, Eric J. & William P. Reilly

Withers, Ken

Zweig, Michael P. & Mark J. Goldberg


Within Other Tools section

Ontrack PowerControls [Demo available]
Tool for copying and searching mailbox data directly from Microsoft Exchange Server backups, un-mounted databases (.edb), and Information Store files.

Partition Image [Free]
A Linux/UNIX utility which saves partitions in many formats to an image file.

Resource Hacker [Free]
A freeware utility to view, modify, rename, add, delete and extract resources in 32bit Windows executables and resource files (*.res).

RKDetect [Free]
An anomaly detection tool which can find services hidden by generic Windows rootkits, like Hacker Defender.

SecCheck [Free]
A Windows forensic tool which aids in the detection and removal of malicious applications, backdoors, trojans, worms, and viruses.

Sleuthkit/Autopsy Searchtools patch (by P. Bakker) [Free]
Provides indexed searching capabilities for Sleuthkit/Autopsy tools

Win32 Analyzer [Free]
This script uses various Windows and 3rd Party tools to provide an effective forensic snapshot of your computer.

Win32 First Responder's Analyzer Tookit [Free - from Archive.org]
Win32 Analyzer Toolkit is a self-extracting exe meant for floppy, highlighting the use of simple scripts on Windows32 platforms to perform basic security tasks.
This script uses various Windows and 3rd Party tools to provide an effective forensic snapshot of your computer.

Windows Forensic Toolchest (WFT) [Free]
Provides automated incident response on a Windows system, and collects security-relevant information from the system


Within Projects section

The Digital Evidence Project (ABA)


Within Forums section

Cell Phone Forensics [Yahoo group]

DoD IA Newsletter

PG Lewis & Associates, LLC Monthly e-Newsletter

Windows IR [Yahoo Group]


Within Links to Links section

SecGuru


© 2004 All rights reserved