Saturday, April 9, 2016

DIGITAL FORENSICS:Open Source Digital Forensics Conference

DIGITAL FORENSICS:Open Source Digital Forensics Conference


OSDFCon

OSDFCon

OSDFCon was started in 2010 by Brian Carrier at Basis Technology, following his years of research and development on open source digital forensic projects The Sleuth Kit and Autopsy. The first OSDFCon focused on The Sleuth Kit, and included both invited speakers and times dedicated to discussion and collaboration. Those discussions led to the creation of Autopsy 3, a platform for digital forensics development which now has tens of thousands of downloads each release.

2016 Autopsy Module Development Contest




ShellBags by Mark McKinnon

Recycle Bin
  • Summary: The module will export the SAM Hive and an $I file that exists on a Windows Vista+ system. It will parse the SAM hive getting userids. It will then parse the $I file getting the actual file location where the $R is suppose to be. It will add an artifact called TSK_RECYCLE_BIN and add the userid and actual file location to the artifact for each $R file.
  • Author: Mark McKinnon
  • Source Code: https://github.com/markmckinnon/Autopsy-Plugins/tree/master/Recycle_Bin
  

OSDFCon 2020 Slide
 
 
Ref:
 
หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

No comments:

Post a Comment

Digital Forensics:User Access Logging (UAL)

 Digital Forensics:UAL  Log What Is User Access Logging? UAL is a feature included by default in Server editions of Microsoft Windows, start...