The Electronic Evidence Information Center

Home


Digital Forensics BIBLIO


What's New


ALL
Other Resources


Digital Forensic Books


OS Specific Articles


Links to Links


Reciprocal Links


About This Site

  OPERATING SYSTEM-SPECIFIC

This is my initial attempt to organize some of the content within this site into categories.

Articles, papers, & presentations presented below are specific to a particular operating system. [They will continue to be listed in the Bibliography section]


Linux | Unix | Windows | Win95 | WinNT | WinXP | Handhelds

Macintosh

DD’s Ultimate Guide to Mac OS Forensics

Donnelly, Derrick

Dornseif, Max

Hawkins, Peter

Miller, Roland E. III

  • GIAC Certified Forensic Analyst Practical Assignment [PDF] September 2002

    "A detailed forensic analysis of a Mac OS X system using primarily open source forensic utilities on a Mac OS X analysis system. The paper clearly illustrates the potential of using Mac OS X for forensic analysis as well as some of the issues related to analyzing Mac OS X itself; in this case the Public Beta. The analysis is contained in Part I of the paper." Anonymous

Rennich, Joel

Siracusa, John


Back to Top

Linux

Belshaw, Gary

Carrier, Brian

Chuvakin, Anton

Crane, Aaron

Fung, James

Holcroft, Stephen

Kralik, James and Shlomo Koenig

Murphy, Keven

Red Hat Linux 8.0: The Official Red Hat Linux Security Guide

Rogers, Russ

Rude, Thomas

Willis, Chuck


Back to Top

Unix

Cheng, Derek

Dittrich, Dave

Farmer, Dan and Wietse Venema

Hamilton, Martin

Jones, Keith

Kuethe, Chris

Lam, Alan S. H.

  • Computer Forensics Analysis October 2000

    A step-by-step analysis of a compromised Unix box, detailing commands and switches.
    This seminar introduces some basic techniques in Computer Forensics. It shows how to collect evidence without interfering the activities of the inspected system. It also discusses how hackers hide their traces when breaking into a system and the methods to work against it.

Lee, Rob

Pettinari, Cmdr. Dave

Prosise, Chris and Kevin Mandia

  • Incident Response: Investigating Computer Crime
    Chapter 11
    [PDF] Initial Response to Unix Systems

Sans Institute

the grugq

Widdowson, Liam & John Ferlito


Back to Top

Windows, General

Barish, Stephen

Bates, Jim

Burke, Joseph

Fulton, Lora & Eric Jacobsen (Boston University)

Grinler

Jones, Keith J.

Lawler, James A.

Lee, Rob

Lewis, Jack

  • The New De-Tech-Tives [PDF] Spring/Summer 1999

    The Social Secuirty Administration Office of the Inspector General's Experience (Page 39)

Marcella, Albert, and Robert Greenfield

  • Cyber Forensics: A Field Manual for Collecting, Examining, and Preserving Evidence of Computer Crimes.

    Table of contents and introduction [PDF]

    Chapter 3 The Liturgical Forensic Examination: Tracing Activity on a Windows-Based Desktop [PDF]

Morris, Jamie

Rose, Curtis W.

Yaw, Tan Koon


Back to Top

Windows 95

Leibolt, Gregory


Back to Top

Windows NT/2000

Carvey, Harlan

Haase, Norman

Henson, Teena J.

Jacobsen, Eric and Lora Fulton (Boston University)

Mandia, Kevin

Mares, Dan

Martin, Damon

Oliviera, Flávio de Souza, Célio Cardoso Guimarães & Paulo Lício de Geus

Sanderson, Paul

Schultze, Eric

van Essen, Maarten


Back to Top

Windows XP

Leibrock, Larry

Sedory, Daniel B.

Stone, Kimberly & Richard Keightley


Back to Top

Handhelds

Burnette, Michael W.

de Haas, Job

Frichot, Christian

Grand, Joe

GSM-Security.net

Guidance Software

Mislan, Richard P.

NIST

PDA 4N6

PDAZap

Paraben's PDA Seizure

Peikari, Cyrus & Seth Fogie

Schiffman, Mike D.

SEARCH

Watson, David

Weiss, Aaron

Willassen, Svein Yngvar


© 2005 All rights reserved