Pieces0310

取证须让证物说话,莫妄以自我心证来给案情下定论.切忌画靶射箭,为找而找. 取证的根基仰赖经验与判断,在IT各领域的经验愈丰富,愈能看出端倪. 取证须善用工具,但不过度依赖工具.工具只能帮你缩小可能范围,但无法告诉你答案,仍需靠人进行分析判断.

首页 新随笔 联系 订阅 管理

随笔分类 -  Digital Forensics

1 2 3 下一页

摘要:USB存储设备的使用记录 阅读全文
posted @ 2022-02-27 21:45 Pieces0310 阅读(1302) 评论(2) 推荐(0)

摘要:This morining I decide to upgrade my workstation to Windows 11. Let me remind you that Windows 11 got some system requirments and one of the most impo 阅读全文
posted @ 2021-10-10 13:58 Pieces0310 阅读(286) 评论(0) 推荐(0)

摘要:有位同好先前有拜读过数年前我的一篇拙作,提及如何查找Mac上的USB存储设备使用痕迹,而由于操作系统已有所不同,他希望我再为各位谈一下. 没错, macOS的日志机制不再像过去是text-based仅是存放在日志文件之中可直接进行检视,而是基于一个所谓”Unified Logging System” 阅读全文
posted @ 2020-12-20 21:15 Pieces0310 阅读(1136) 评论(0) 推荐(0)

摘要:A friend of mine Megan told me that she got an error message as below screenshot when trying to open a virtual machine on suspect's laptop. She tried 阅读全文
posted @ 2020-09-08 23:11 Pieces0310 阅读(288) 评论(0) 推荐(0)

摘要:Forensic examiners usually acquire images from suspect’s PC or Laptop. What if the target computer is not a physical PC/Laptop/Server? Let’s say the t 阅读全文
posted @ 2018-01-26 15:30 Pieces0310 阅读(434) 评论(0) 推荐(0)

摘要:My friend May she found a strange file called "bkp.old" as below in the evidence files. She decided to use forensic tools to take a look at it and fig 阅读全文
posted @ 2017-11-22 18:27 Pieces0310 阅读(498) 评论(0) 推荐(1)

摘要:In my previously article "EnCase missed some USB activities in the evidence files", I mentioned about that EnCase could only "see" few USB records. Ac 阅读全文
posted @ 2017-10-25 15:55 Pieces0310 阅读(374) 评论(0) 推荐(0)

摘要:My friend is a developer and her colleague May was suspected of stealing the source code of an important project "X". The Police searched her apartmen 阅读全文
posted @ 2017-10-06 16:10 Pieces0310 阅读(588) 评论(0) 推荐(0)

摘要:My friend told me that she installed EnCase v8.05 on her workstation which OS version is Win 10. She conducted an index search but no any hits found i 阅读全文
posted @ 2017-07-24 21:07 Pieces0310 阅读(348) 评论(2) 推荐(0)

摘要:Someone ask me how to image a CD/DVD ROM and generate hash value in the same time. A small tool called "dcfldd" could achieve this goal. Compared to d 阅读全文
posted @ 2017-05-08 21:40 Pieces0310 阅读(582) 评论(2) 推荐(0)

摘要:A friend of mine she asked me how to check all timestamps of a file on an NTFS volume. She did not have EnCase or FTK in hand. So I gave her FTK Image 阅读全文
posted @ 2017-01-12 22:27 Pieces0310 阅读(760) 评论(0) 推荐(0)

摘要:We could find some important clue in Restore Point because "System Protection" of volume C is enabled in Windows default settings. Lots of data in "My 阅读全文
posted @ 2016-09-27 22:13 Pieces0310 阅读(736) 评论(2) 推荐(0)

摘要:The evidence is a VM as below. The flat vmdk is the real disk, and the vmdk only 1kb is just a descriptor. As you could see that there is no vmx. What 阅读全文
posted @ 2016-09-25 11:05 Pieces0310 阅读(302) 评论(0) 推荐(0)

摘要:As we know that the Prefetch file is used for optimizing the loading time of the application in the next time that you run it. So we could know whethe 阅读全文
posted @ 2016-09-11 22:40 Pieces0310 阅读(409) 评论(0) 推荐(0)

摘要:My colleague she ask me why Intella could not handle Lotus Notes nsf e-mail archive files. I told her that Intella could index mail and attachments in 阅读全文
posted @ 2016-07-16 09:43 Pieces0310 阅读(297) 评论(0) 推荐(0)

摘要:随着网络的蓬勃发展,伴随而来的是愈来愈多的新型态威胁出现.现今随处可见的勒索病毒便是最好的例子.在现实世界中,如果有人偷了你/妳的东西,要求必须付钱才能赎回,你/妳可以报警处理.但网络世界无国界,加上犯罪者引用匿踪技术,使得追查困难,一旦不幸文件遭到加密,即使付了赎金也不见得就能救回资料. 现今有太 阅读全文
posted @ 2016-07-10 16:47 Pieces0310 阅读(476) 评论(0) 推荐(1)

摘要:My friend she told me last week that FTK could not "see" keywords in a plain text files when doing index search. That's very interesting. I used to tr 阅读全文
posted @ 2016-07-09 10:00 Pieces0310 阅读(534) 评论(0) 推荐(0)

摘要:Last night an explosion on a commuter train carriage in Taipei Songshan railway station wounded at least 21 people. The Criminal Investigation Bureau 阅读全文
posted @ 2016-07-08 10:40 Pieces0310 阅读(332) 评论(0) 推荐(0)

摘要:My friend she showed me a screenshot as below yesterday. The name of this document is “EnCase Forensic Features and Functionality”. She asked me that 阅读全文
posted @ 2016-06-25 13:04 Pieces0310 阅读(397) 评论(0) 推荐(0)

摘要:最近刚好有个案子的证物主机是MBP, OS X版本为El Capitan,案况与营业秘密外泄有关,当中要找有关USB存储设备的使用痕迹. 要提醒大家的是,不同版本的OS X,各种迹证的存放文件名称及路径,往往有所不同.而E1 Capitan的USB存储设备的使用痕迹在/private/var/log 阅读全文
posted @ 2016-06-16 22:29 Pieces0310 阅读(2615) 评论(0) 推荐(0)

1 2 3 下一页