<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6722867217002233231</id><updated>2012-03-07T22:35:18.378-08:00</updated><category term='Geekness'/><category term='TV'/><category term='Tutorial'/><category term='Musings'/><category term='Travel'/><category term='case experience'/><category term='Kinda Sorta Useful'/><category term='Scripts'/><category term='Iraq'/><category term='FE Side'/><title type='text'>Girl, Unallocated</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>40</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-6792776146697267751</id><published>2012-03-06T10:39:00.000-08:00</published><updated>2012-03-06T10:39:28.410-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='case experience'/><title type='text'>Case Experience #2.1 - More About IP Theft Thought Process</title><content type='html'>My last &lt;a href="http://girlunallocated.blogspot.com/2012/02/case-experience-2-ip-theft.html"&gt;case experience&lt;/a&gt; included just some&amp;nbsp;preliminary&amp;nbsp;thoughts when starting an IP Theft case, so I've decided to follow up with some additional ramblings. &amp;nbsp;And rather than talk in generalities, I thought I'd add a hypothetical scenario in this go-around.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;Hypothetical Scenario&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-Lbk6spMz7Pw/T1ZH49ofPwI/AAAAAAAAAMo/aoRjEmRJilM/s1600/chicken-drumstick_png-rl.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="193" src="http://3.bp.blogspot.com/-Lbk6spMz7Pw/T1ZH49ofPwI/AAAAAAAAAMo/aoRjEmRJilM/s200/chicken-drumstick_png-rl.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Kilroy Hankmins has been working as an Engineer at Horde Enterprises for a number of years. &amp;nbsp;In the course of his duties, he had access to a lot of proprietary information. &amp;nbsp;Then, a few weeks ago, Kilroy left Horde Enterprises for their fierce competitor, Alliance Inc., ostensibly for the better chicken package. &amp;nbsp;Some of Kilroy's behavior prior to leaving raised a red flag with the upper management of Horde Enterprises. &amp;nbsp;They have Kilroy's HE issued laptop and want it examined for any evidence that Kilroy took proprietary information when he went over to Alliance Inc.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;Getting Some Context&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;I know I harp on this an awful lot, but getting context before you begin an exam can be helpful in targeting your investigation and mitigating costs for your client. &amp;nbsp;(As a side note, Corey Harrell wrote a great post about &amp;nbsp; &amp;nbsp;&lt;a href="http://journeyintoir.blogspot.com/2012/03/digital-forensics-meets-forensic.html"&gt;understanding his customers&lt;/a&gt; when doing Fraud cases... I recommend checking it out.) &amp;nbsp;Below are some examples of questions to ask the client that I have found helpful when starting an IP theft case of this sort. &amp;nbsp;&lt;span style="font-size: x-small;"&gt;Note: &amp;nbsp;These questions aren't aimed at finding additional data locations that may be of use (that's another set of questions altogether), but just focuses on narrowing down information for the system about to be investigated.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Pre-Investigation Timeline&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;When did Kilroy leave the company?&lt;/li&gt;&lt;li&gt;When did he last have access to the company laptop?&lt;/li&gt;&lt;li&gt;Was the laptop used at all after Kilroy's last access?&lt;/li&gt;&lt;li&gt;Are there any other dates of interest I should be aware of before the investigation?&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;u&gt;Intellectual Property&lt;/u&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;What is the IP of interest in this case?&lt;/li&gt;&lt;li&gt;What format would the IP likely be in?&lt;/li&gt;&lt;li&gt;Do you have a set of search terms that would help identify IP?&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Depending on your client, you may also want to find out more about their security protocols. &amp;nbsp;For example, it could be pertinent to find out if USB ports are disabled on all company computers. &amp;nbsp;I just want to make the point that the questions above aren't exhaustive. &amp;nbsp;I recommend coming up with your own list and adding where needed.&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;Back to the Scenario&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;For the purposes of this scenario, let's assume that the client answered the questions as follows:&lt;/div&gt;&lt;ul&gt;&lt;li&gt;When did Kilroy leave the company? &amp;nbsp;&lt;span style="color: #660000;"&gt;Kilroy submitted his resignation on 2/1/2012 at 12:00pm. &amp;nbsp;His position was terminated that day. &amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;When did he last have access to the company laptop? &amp;nbsp;&lt;span style="color: #660000;"&gt;Kilroy had access to his laptop until 2/3/2012 at 9:00am when he came into HE headquarters to turn it in. &lt;/span&gt;&amp;nbsp;(GU Notes: &amp;nbsp;These last two questions are not always going to have the same answer, and when there is a discrepancy between the two answers this window of time can be especially interesting.)&lt;/li&gt;&lt;li&gt;Was the laptop used at all after Kilroy's last access? &amp;nbsp;&lt;span style="color: #660000;"&gt;Oh, yeah. &amp;nbsp;We had IT poke around to see if this was even worth pursuing. &amp;nbsp;They fired it up a couple times and ran reports for me.&lt;/span&gt; &amp;nbsp;(GU Notes: &amp;nbsp;Sigh. &amp;nbsp;In an ideal world, this shouldn't happen, but it can and does, so be ready for it. &amp;nbsp;It also is possible that the computer will be in constant use after because it was simply assigned to another employee. &amp;nbsp;Either way, you should know.)&lt;/li&gt;&lt;li&gt;Are there any other dates of interest I should be aware of before the investigation? &amp;nbsp;&lt;span style="color: #660000;"&gt;Not that I can think of at the moment.&lt;/span&gt; &amp;nbsp;(GU Notes: &amp;nbsp;This is just covering your bases. &amp;nbsp;Sometimes, there may be information that can shed additional light. &amp;nbsp;Why not ask?)&lt;/li&gt;&lt;li&gt;What is the IP of interest in this case? &amp;nbsp;&lt;span style="color: #660000;"&gt;We are especially concerned about schematics of our products, but, you know, anything proprietary.&lt;/span&gt; &amp;nbsp;(GU Notes: &amp;nbsp;Figuring out what is considered Intellectual Property is one of the big questions I face in any IP theft case, and it varies for each one. &amp;nbsp;Sometimes it is contact information, sometimes it is pricing, and the list goes on. &amp;nbsp;There's no golden answer for figuring this one out - or at least I haven't found one yet - but taking the time to discuss and listen to your client on this topic can really pay off.)&lt;/li&gt;&lt;li&gt;What format would the IP likely be in? &amp;nbsp;&lt;span style="color: #660000;"&gt;We think it would be primarily images or Microsoft Office documents.&lt;/span&gt; &amp;nbsp;(GU Note: &amp;nbsp;This doesn't mean you should ignore everything that isn't in this format - this is just something that can be helpful to know. &amp;nbsp;It can be especially interesting if the information is in proprietary or specialized software.)&lt;/li&gt;&lt;li&gt;Do you have a set of search terms that would help identify IP? &amp;nbsp;&lt;span style="color: #660000;"&gt;We can do one better. &amp;nbsp;We'll send you files that contain the information.&lt;/span&gt; &amp;nbsp;(GU Note: &amp;nbsp;Actually getting examples of real IP can be a great help. &amp;nbsp;However, don't fall into the trap of just locating the files on the system. &amp;nbsp;Especially in a case like this scenario, simply finding the files doesn't show IP theft - the custodian had a right to have them on his HE laptop. &amp;nbsp;What he didn't have a right to do was take the information. &amp;nbsp;So, if we had the AI laptop and found them, that's one thing, but it won't necessarily help here.)&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;So, now that we have some background information we can begin the investigation! &amp;nbsp;Next time I'll follow up with more specific steps using this scenario.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-6792776146697267751?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/6792776146697267751/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2012/03/case-experience-21-more-about-ip-theft.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/6792776146697267751'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/6792776146697267751'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2012/03/case-experience-21-more-about-ip-theft.html' title='Case Experience #2.1 - More About IP Theft Thought Process'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-Lbk6spMz7Pw/T1ZH49ofPwI/AAAAAAAAAMo/aoRjEmRJilM/s72-c/chicken-drumstick_png-rl.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-4873715032667690499</id><published>2012-02-28T10:37:00.001-08:00</published><updated>2012-02-29T05:17:53.202-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='case experience'/><title type='text'>Case Experience #2 - IP Theft Investigation Thought Process</title><content type='html'>I've been reading some of the posts where people have discussed what they find useful in Case Studies, and in addition to unique problems encountered there has been a lot mentioned about the usefulness of discussing the thought process behind an investigation. &amp;nbsp;Not all analysts are going to approach an investigation the same way, and as long as the evidence is found, that's grand. &amp;nbsp;In fact, sharing the different approaches can only help others in streamlining their own processes. &amp;nbsp;As &lt;a href="http://windowsir.blogspot.com/"&gt;Harlan Carvey&lt;/a&gt; stated, "None of us is as smart as all of us." &amp;nbsp;So here's my offering to the collective consciousness.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;Case Experience #2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;IP Theft Investigation Thought Process&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;span style="background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: xx-small; line-height: 14px; text-align: -webkit-auto;"&gt;Standard disclosure:&amp;nbsp; This represents a targeted investigation, and does not include every available scenario. &amp;nbsp;Please don't take this as SOP, but rather a brief insight that may lead the direction of an investigation. &amp;nbsp;Note: &amp;nbsp;This thought process is assuming a Windows OS.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-QAIpP2rVD7E/T00b_9sgbwI/AAAAAAAAAMY/HfPYEQZ2Hzc/s1600/hamster.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="132" src="http://1.bp.blogspot.com/-QAIpP2rVD7E/T00b_9sgbwI/AAAAAAAAAMY/HfPYEQZ2Hzc/s200/hamster.jpg" width="200" /&gt;&lt;/a&gt;&lt;strong&gt;Tools:&lt;/strong&gt;&lt;br /&gt;EnCase v.6.18&lt;br /&gt;RegRipper&lt;br /&gt;NetAnalysis &lt;br /&gt;Log2Timeline on SANS SIFT Workstation&lt;br /&gt;VMWare&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Background:&lt;/b&gt;&lt;br /&gt;Possible theft of Intellectual Property.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Investigation Thought Process:&lt;/strong&gt;&lt;br /&gt;In the case of IP Theft, one of the major areas of interest is ways that data could have left a system. &amp;nbsp;In my experience, this happens most frequently via external drives, e-mail attachments, FTP sites or other online repositories, so those are areas where I tend to begin looking. &amp;nbsp;In these types of investigations, there are certain processes that can take some time to run, so it isn't uncommon for me to start running a supertimeline in a SIFT VM, carve for internet history in NetAnalysis, and (if the client has provided search terms or file names of interest) run search terms in EnCase and let those churn away while I start poking around in the registry and various other artifacts. &amp;nbsp;Below are some descriptions of the items of interest I mentioned above:&lt;br /&gt;&lt;br /&gt;External Drives - Information about external drives attached to a system can be found in the System and NTUser.dat registry hives. &amp;nbsp;I like to run RegRipper and review the reports even if my timeline created in SIFT includes that information. &amp;nbsp;Apart from getting an idea of the system while log2timeline is running, reviewing the registry helps me narrow down time frames and get an idea of if and what drives were connected. &amp;nbsp;If the time frame of interest is further in the past, I can't emphasize enough the added value of analyzing Volume Shadow Copies or Restore Points (depending on the OS). &amp;nbsp;If information of interest is found, I will look into other artifacts such as link files in the Recents folder and Jump Lists.&lt;br /&gt;&lt;br /&gt;E-mail - When looking for e-mail I examine any local mail repositories, but it is important to also look for evidence of webmail being used to send information. &amp;nbsp;This means that internet history can be an important aspect of an IP theft case. &amp;nbsp;If you are lucky, there may be cached messages, or a snapshot of the inbox cached on the system. &amp;nbsp;It isn't uncommon to find the webmail address, which may be of great use to your client and may lead to the ability to access and collect the webmail repository for further analysis. &amp;nbsp;As a side benefit, internet analysis can also bring up gems such as search terms and websites visited that add context to what occurred on the system.&lt;br /&gt;&lt;br /&gt;Online Repositories - Sometimes information about online repositories visited is found primarily in internet history. &amp;nbsp;However, I have also come across instances where FTP software was installed, so it is a good idea to look for information about software installed, run, or present on the system as well as sites visited. &amp;nbsp;Information about software can be found in the SOFTWARE registry hive, the NTUSER.DAT, and in software folders, as well as other locations.&lt;br /&gt;&lt;br /&gt;Super Timeline - A super timeline can be a bit intimidating when you look at all the information that it contains. &amp;nbsp;However, it is unsurpassed in the ability to immediately provide context from a wide range of data sources on a system. &amp;nbsp;Usually, by the time my timeline is ready to analyze, I have some idea of items of interest, so that I can zero in on those time frames. &amp;nbsp;The ability to filter and search within the timeline provides a great way to also look for other events that are similar in nature to the ones that you have already deemed of interest.&lt;br /&gt;&lt;br /&gt;After looking in these initial locations, the investigation becomes more targeted to each specific system and investigation. &amp;nbsp;Typically, I will keep notes as the investigation continues, but it is also common for me to create draft reports that I update as I go along. &amp;nbsp;For me, this helps me get some of the information down in words that can then be modified when the investigation is complete, and I am never faced with the terrifying aspect of &amp;nbsp;a blank page and all the information only in my head.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;A Proposal&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://1.bp.blogspot.com/-LoJXXXE4688/T00ejpHBfbI/AAAAAAAAAMg/3tg1DNLiT_c/s1600/lightbulb.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://1.bp.blogspot.com/-LoJXXXE4688/T00ejpHBfbI/AAAAAAAAAMg/3tg1DNLiT_c/s200/lightbulb.png" width="113" /&gt;&lt;/a&gt;Just a thought - there are many people in the industry that have provided great insight via blogs, forums, and e-mail. &amp;nbsp;From what I've heard, there are even more people who have insight to share, but don't know how or where to share the information. &amp;nbsp;Blogging isn't for everyone, or there may be other reasons that have kept people from putting their thoughts out there. &amp;nbsp;Because of this, I want to offer my blog as a forum to those who want to contribute, but don't have their own site (or for those that do, who just want a change of scenery). &amp;nbsp;If you are interested in doing a guest blog post, feel free to contact me at girlunallocated@gmail.com. &amp;nbsp;I'll give full credit to any authors who guest blog. &amp;nbsp;So... no excuses now! &amp;nbsp;If you've learned something from someone else in the industry, please think about sharing some of your own insight. &lt;br /&gt;&lt;br /&gt;UPDATE: &amp;nbsp;This post was just meant as a very basic outline of what I am thinking at the start of an IP Theft investigation, and is by no means exhaustive or even a complete picture (that would have made for a very long blog post, and who would read that much of me in one sitting?!). &amp;nbsp;However, I don't want to leave it here as there are so many other aspects. &amp;nbsp;I will follow up with Case Experience 2.1 soon, and hope to address additional areas of interest, for those of you who want to follow more of my thought process (you brave souls).&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-4873715032667690499?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/4873715032667690499/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2012/02/case-experience-2-ip-theft.html#comment-form' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/4873715032667690499'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/4873715032667690499'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2012/02/case-experience-2-ip-theft.html' title='Case Experience #2 - IP Theft Investigation Thought Process'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-QAIpP2rVD7E/T00b_9sgbwI/AAAAAAAAAMY/HfPYEQZ2Hzc/s72-c/hamster.jpg' height='72' width='72'/><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-802429153524883921</id><published>2012-02-16T20:54:00.001-08:00</published><updated>2012-02-28T10:37:52.785-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='case experience'/><title type='text'>A Case Experience</title><content type='html'>Last week I had the opportunity to go to Denver to present a CLE presentation I&amp;nbsp;created called "The eDiscovery Roadmap: From Planning to Production."&amp;nbsp; (Don't fear, fellow forensicators, I'm not changing the focus of my blog... this is just an exposition.)&amp;nbsp; Overall, I think it was a success.&amp;nbsp; &lt;span style="font-size: x-small;"&gt;The main metric&amp;nbsp;to determine this was&amp;nbsp;embarrassing moments divided by time spent on stage, and since&amp;nbsp;I only tripped over my heels once, the math definitely works in my favor.&lt;/span&gt;&amp;nbsp;&amp;nbsp;But apart from getting to lecture to a crowd of lawyers and paralegals &lt;strike&gt;trapped&lt;/strike&gt; enthralled for two whole hours, one of the most interesting experiences came after the presentation was over,&amp;nbsp;when I got to read the feedback from attendees.&amp;nbsp; Time and again, the "favorite part" of the presentation was listed as my "Tales From the Trenches," when I took a few minutes after each phase to tell applicable eDiscovery war stories.&amp;nbsp; &lt;br /&gt;&amp;nbsp;﻿&lt;br /&gt;&lt;br /&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-WkHGYxria3k/Tz3IOhqqzfI/AAAAAAAAAL8/-AMbFXsD8V8/s1600/Tales.jpg" imageanchor="1" style="clear: left; cssfloat: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="133" src="http://2.bp.blogspot.com/-WkHGYxria3k/Tz3IOhqqzfI/AAAAAAAAAL8/-AMbFXsD8V8/s200/Tales.jpg" width="200" yda="true" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;"Tales From the Trenches"&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;﻿Of course, I'd like to think that this was because of my impeccable story telling.&amp;nbsp; Just look at some of the titles:&amp;nbsp; "The Eager Attorney and the Hard Drive of Doom"; "The Search Term That Wouldn't Cull"; and, my favorite, "The Ineluctable Modality of the PDF".&amp;nbsp; But once I finished fantasizing about adding "Master Storyteller"&amp;nbsp;to my list of accomplishments, I had to acknowledge that there was probably more to it than my wordsmithing.&amp;nbsp; Whatever you call them - war stories, case studies, investigation experiences - there is a lot of value to learning problems others have faced, and how those problems&amp;nbsp;were dealt with.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;a href="http://windowsir.blogspot.com/"&gt;Harlan Carvey&lt;/a&gt; (without whom I would likely never have new ideas for my blog) started another interesting discussion on the Win4n6 forums this week about sharing case studies within the field.&amp;nbsp; I'll be the first to admit my reluctance in the past about inadvertantly disclosing sensitive material, but when I really thought about it, I feel that there are definitely ways to contribute without crossing, or even getting close, to that line.&amp;nbsp; &lt;a href="http://journeyintoir.blogspot.com/"&gt;Corey Harrell&lt;/a&gt; coined the phrase "Case Experience" to differentiate these shorter, more sanitized&amp;nbsp;communications from&amp;nbsp;"Case Studies", which implies a more complete picture.&amp;nbsp; Yes, I can share case experiences without guilt, and hopefully, I'll even pass on something.&amp;nbsp; It may even be insight.&amp;nbsp; Or knowledge.&amp;nbsp; Or something good.&amp;nbsp; No antibiotics needed.&lt;br /&gt;&lt;br /&gt;And so, without further ado, I present&amp;nbsp;GU's Case Experience #1.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;Case Experience&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;strong&gt;Working Title:&amp;nbsp; The Difference a Minute Makes&lt;/strong&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;Standard disclosure:&amp;nbsp; This represents a targeted investigation, and not all portions of the exam will be discussed.&amp;nbsp; Please don't take this as SOP.&amp;nbsp; Also, my set of tools has been evolving, but steps&amp;nbsp;I&amp;nbsp;mention should&amp;nbsp;be able to be performed with a variety of different tools.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Tools:&lt;/b&gt;&lt;br /&gt;EnCase v.6.18&lt;br /&gt;RegRipper&lt;br /&gt;PhotoRec&lt;br /&gt;VMWare&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Background:&lt;/b&gt;&lt;br /&gt;Possible data spoliation. &amp;nbsp;The client requested an investigation that looked into data deletion on a Windows XP system within a specific time frame. &amp;nbsp;The system in question had been in use for a couple months after the time of interest. &amp;nbsp;The end result was a report that detailed recovered files of interest and a timeline of events.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Investigation Plan:&lt;/b&gt;&lt;br /&gt;Recycle bin analysis&lt;br /&gt;File recovery using EnCase&lt;br /&gt;File carving using PhotoRec&lt;br /&gt;Analysis of carved files on system for context&lt;br /&gt;Search for data deletion software&lt;br /&gt;Registry and restore point analysis&lt;br /&gt;Timeline generation&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Actual Investigation:&lt;/strong&gt;&lt;br /&gt;&lt;em&gt;The scene:&amp;nbsp; Me smoking a cigar in a shadowy room with my feet on the desk, looking debonair.&lt;/em&gt;&amp;nbsp; While recovering the deleted files was of great interest to the client, what makes this case stand out to me&amp;nbsp;is what I found on the system regarding a program called &lt;a href="http://www.piriform.com/ccleaner"&gt;CCleaner&lt;/a&gt;.&amp;nbsp; Many of you are likely familiar with it, and have come across it in your cases (in fact, &lt;a href="http://cheeky4n6monkey.blogspot.com/"&gt;Cheeky4n6Monkey&lt;/a&gt; has some great posts about pulling artifacts relating to CCleaner using a RegRipper plugin)&amp;nbsp; It seems to crop up an awful lot in certain types of cases.&amp;nbsp; What made this one interesting was the reconstruction of events found in restore point registry hives.&amp;nbsp; Luckily for me, though the computer had been in use for quite a while after the timeframe of interest, the restore points for the timeframe were still present.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;I could see that the registry entries showed CCleaner being installed on the system a couple years before the timeframe of interest.&amp;nbsp; Even better, after tracking down RPs for specific dates, and determining the proper user, the keys showed that CCleaner.exe had been run on the system by the user in the "hot zone".&amp;nbsp; Bingo!&amp;nbsp; But wait... it&amp;nbsp;wasn't quite as clear as that.&amp;nbsp; You see, a good minute &lt;em&gt;after&lt;/em&gt; CCleaner.exe was run, a CCleaner installer file called ccsetup###.exe&amp;nbsp;was run, with no indications that CCleaner.exe was run again after the installation.&amp;nbsp; So, was CCleaner simply updated but not run?&amp;nbsp; Or could it have been run after the installer without updating the registry entry?&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-qmlcA1AAjZ8/Tz3VDOiSAzI/AAAAAAAAAMM/dMAQCiCHLao/s1600/Presentation1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="125" src="http://1.bp.blogspot.com/-qmlcA1AAjZ8/Tz3VDOiSAzI/AAAAAAAAAMM/dMAQCiCHLao/s400/Presentation1.jpg" width="400" yda="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&amp;nbsp;I had come across CCleaner enough in the past to know that the program will check for an updated version of the software and ask the user if they want to download it if one is available.&amp;nbsp;&amp;nbsp;So it didn't come as a surprise that an installer file would be run soon after executing the program.&amp;nbsp; The question became, after running the installer, if CCleaner was run what changes, or lack of changes, would occur in the registry?&amp;nbsp; &lt;br /&gt;&lt;br /&gt;It was time to stop speculating, and start researching.&amp;nbsp; I used a Windows XP machine that had CCleaner already installed.&amp;nbsp; Upon firing up the program, I was indeed prompted to update the software.&amp;nbsp; Following the update, I used the default option to start CCleaner automatically, and then ran the default CCleaner process on the system.&amp;nbsp; Following the run, I examined the test registry hives to see what sort of information was present.&amp;nbsp; The test system registry hives mimicked the investigated system:&amp;nbsp; though CCleaner had been run following the updated installer file, the registry just&amp;nbsp;reflected the initial execution of the program.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Moral of the Story&lt;/strong&gt;&lt;br /&gt;Now, I don't expect that this is an earth-shattering revelation.&amp;nbsp; I guess the real point that I want to make is the importance of testing when questions are raised or anticipated.&amp;nbsp; In this case, there were questions, and I had the ability to confidently say "I tested the process and the data is consistent."&amp;nbsp; There are so many variables on systems, testing should be common place.&amp;nbsp; You don't need a plethora of extra equipment to do it, either.&amp;nbsp; Run some virtual machines, have a few baseline setups you can use, and take the time to experiment.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-802429153524883921?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/802429153524883921/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2012/02/case-experience.html#comment-form' title='10 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/802429153524883921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/802429153524883921'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2012/02/case-experience.html' title='A Case Experience'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-WkHGYxria3k/Tz3IOhqqzfI/AAAAAAAAAL8/-AMbFXsD8V8/s72-c/Tales.jpg' height='72' width='72'/><thr:total>10</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-720801096305684484</id><published>2012-02-13T09:22:00.000-08:00</published><updated>2012-02-22T13:13:21.832-08:00</updated><title type='text'>Geolocation From Photos = Good Stuff</title><content type='html'>One of the great things (there are so many, but this is one of them) about DFIR is that there are many different ways to uncover and analyze data.&amp;nbsp; I was recently doing some research on pulling geolocation information from photos taken on an iPhone (mine, actually), and was led to some pretty great resources.&amp;nbsp; In my continuing efforts to contribute, below is a simple layout of how to pull geolocation information from photographs and then map that information using all open source or free&amp;nbsp;tools.&amp;nbsp; Now, this method isn't the fastest, especially when dealing with a large data universe.&amp;nbsp; What I like about the tasks, though, is that it gets you a bit closer to the data, and doesn't rely on "point and click" methods.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Pulling Longitude and Latitude&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="Sectiontext"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;Download ExifTool at &lt;a href="http://www.sno.phy.queensu.ca/~phil/exiftool/index.html"&gt;&lt;span style="color: blue;"&gt;http://www.sno.phy.queensu.ca/~phil/exiftool/index.html&lt;/span&gt;&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-mtwVMUAcJsA/TzlEhdOz_kI/AAAAAAAAAKc/Jl5XCB05Sc0/s1600/1.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="222" sda="true" src="http://2.bp.blogspot.com/-mtwVMUAcJsA/TzlEhdOz_kI/AAAAAAAAAKc/Jl5XCB05Sc0/s320/1.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;div class="Sectiontext"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;Note:&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;This tool can write as well as read Exif information.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;Make sure the data is write-blocked or you are working on a copy and not the original.&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;Extract the tool.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-grReSZFR6aw/TzlEuz7lhwI/AAAAAAAAAKk/Uny0uvzKlno/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="175" sda="true" src="http://4.bp.blogspot.com/-grReSZFR6aw/TzlEuz7lhwI/AAAAAAAAAKk/Uny0uvzKlno/s320/2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="Sectiontext"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;Rename to exiftool.exe (from exiftool(-k).exe) and place in the C:\Windows directory.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;This allows the program to run from the command prompt.&lt;/span&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;Open the CL window.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;Type &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="Sectiontext" style="text-align: center;"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;exiftool –csv sourcedirectory &amp;gt; outputdirectory\logname.csv &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;(or leave outputdirectory out to place file in same location as images).&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-9_9HGtn3alE/TzlFjFF3R2I/AAAAAAAAALM/A6RqXjtMo14/s1600/4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="161" sda="true" src="http://3.bp.blogspot.com/-9_9HGtn3alE/TzlFjFF3R2I/AAAAAAAAALM/A6RqXjtMo14/s320/4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;If all the parameters are correct, the command will run and an output file will be created in the directory specified.&lt;/span&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-QKzhVLplyP4/TzlFu4IDc9I/AAAAAAAAALc/o3u0vXuO8ok/s1600/5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="160" sda="true" src="http://2.bp.blogspot.com/-QKzhVLplyP4/TzlFu4IDc9I/AAAAAAAAALc/o3u0vXuO8ok/s320/5.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;Of particular interest for this project are the Geolocation, or Longitude and Latitude.&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-_jcjPSeqpdY/TzlFs-tenVI/AAAAAAAAALU/frSXOfJnX54/s1600/6.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="160" sda="true" src="http://2.bp.blogspot.com/-_jcjPSeqpdY/TzlFs-tenVI/AAAAAAAAALU/frSXOfJnX54/s320/6.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="Sectiontext"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;&lt;strong&gt;Mapping Longitude and Latitude&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;Now that we have the coordinates, the next step is to map them.&amp;nbsp; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;Download Google Earth from &lt;a href="http://www.google.com/earth/index.html"&gt;&lt;span style="color: blue;"&gt;http://www.google.com/earth/index.html&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-If_1GHyp5gs/TzlGB4rK7XI/AAAAAAAAALk/Bcf8XE55PH4/s1600/7.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="222" sda="true" src="http://2.bp.blogspot.com/-If_1GHyp5gs/TzlGB4rK7XI/AAAAAAAAALk/Bcf8XE55PH4/s320/7.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="Sectiontext"&gt;Add placemark by selecting the yellow pin icon.&amp;nbsp; Fill out corresponding information, i.e. Latitude, Longitude and any identifying information.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;Note:&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;You will need to adapt the format of lat/long to reflect the format shown below, with “°” rather than “deg”.&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-4CeGtpbTsnc/TzlGN2zXDpI/AAAAAAAAALs/-dRkyE9QNG4/s1600/9.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" sda="true" src="http://3.bp.blogspot.com/-4CeGtpbTsnc/TzlGN2zXDpI/AAAAAAAAALs/-dRkyE9QNG4/s320/9.png" width="212" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;, &amp;quot;serif&amp;quot;; font-size: 12pt;"&gt;Repeat for any additional locations.&amp;nbsp; You should now be able to view the locations on Google Earth.&lt;/span&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-iQaqV1-O08w/TzlGdELbehI/AAAAAAAAAL0/k01BmPnZvDc/s1600/10.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="222" sda="true" src="http://3.bp.blogspot.com/-iQaqV1-O08w/TzlGdELbehI/AAAAAAAAAL0/k01BmPnZvDc/s320/10.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="Sectiontext"&gt;If people want to see other methods, let me know and I'll follow up with additional tools.&amp;nbsp; For now, though, hope this is interesting!&lt;br /&gt;&lt;br /&gt;UPDATE:&amp;nbsp; I promised to follow up if people were interested, but the community has already done that for me - and far better than I could have done.&amp;nbsp; For more information and tools, see comments below.&amp;nbsp; Find a tool, and take the time to thank whoever it was that put up the time to make it, and even more, to make it available to everyone.&amp;nbsp; Thank you to all those who created and posted links to more tools!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-720801096305684484?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/720801096305684484/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2012/02/geolocation-from-photos-good-stuff.html#comment-form' title='21 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/720801096305684484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/720801096305684484'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2012/02/geolocation-from-photos-good-stuff.html' title='Geolocation From Photos = Good Stuff'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-mtwVMUAcJsA/TzlEhdOz_kI/AAAAAAAAAKc/Jl5XCB05Sc0/s72-c/1.png' height='72' width='72'/><thr:total>21</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-856196967511393054</id><published>2012-01-19T11:23:00.000-08:00</published><updated>2012-01-19T11:23:50.539-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorial'/><title type='text'>Another CL Tutorial</title><content type='html'>My last tutorial met the usefulness requirements, so as promised I am following up with another video, this time&amp;nbsp;about using one of my favorite commands -&amp;nbsp;robocopy*!&amp;nbsp; (I like it even more because it sounds like a bad B Movie spin-off.)&amp;nbsp; I'll also show you how to automate commands, so you don't have to wait for one to finish in order to start the next one... just click and run.&amp;nbsp; Enjoy!&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Using the Robocopy Command&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object width="320" height="266" class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://i.ytimg.com/vi/f1Ew4tkboL4/0.jpg"&gt;&lt;param name="movie" value="http://www.youtube.com/v/f1Ew4tkboL4?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266"  src="http://www.youtube.com/v/f1Ew4tkboL4?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Forensic4Cast Awards&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;If the other excellent bloggers out there haven't convinced you to submit your &lt;a href="http://www.forensic4cast.com/forensic-4cast-awards/"&gt;nominations&lt;/a&gt; for the Forensic4Cast awards, I'm here to remind you that this is an excellent way to show your appreciation for the people and products that help make our jobs better, and the DFIR community great.&amp;nbsp; Take a few minutes to nominate your favorites!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;* I'm not going to argue whether robocopy is "forensically sound" or not... please don't take this tutorial as an endorsement that it is or isn't.&amp;nbsp; Either way, it's a great tool for different situations.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-856196967511393054?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/856196967511393054/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2012/01/another-cl-tutorial.html#comment-form' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/856196967511393054'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/856196967511393054'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2012/01/another-cl-tutorial.html' title='Another CL Tutorial'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-229403109361096659</id><published>2012-01-17T19:49:00.000-08:00</published><updated>2012-01-18T10:42:21.605-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorial'/><category scheme='http://www.blogger.com/atom/ns#' term='Kinda Sorta Useful'/><title type='text'>Trying Something New - My First Instructional Video</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;strong&gt;"Human beings make life so interesting. Do you know, that in a universe so full of wonders, they have managed to invent boredom.” &lt;/strong&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;-Terry Pratchett (as spoken by Death)&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;There has been an interesting discussion in the Win4n6 group this week about what keeps examiners from&amp;nbsp;learning more about our own field.&amp;nbsp; A lot of thoughtful points and counterpoints have been made, and I find myself agreeing with both sides a lot of the time.&amp;nbsp; I'm as guilty as the next examiner when it comes to occasionally picking up a fluffy fantasy book (see quote above) over reading "Log Parser Toolkit" into the wee hours.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;﻿In addition to reading up on the discussion about learning, there has been dialogue about community contributions.&amp;nbsp; I've been more of a lurker than a contributor recently, and hearing the arguments made about the importance of everyone contributing made me think.&amp;nbsp; Specifically, Harlan Carvey's excellent &lt;a href="http://windowsir.blogspot.com/2012/01/contributing-to-community.html"&gt;post &lt;/a&gt;was a real powerful motivator to get off my rump and do my part (or at least enough of my part&amp;nbsp;for my conscious to freakin' lighten up on the guilt trip).&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Trying to teach, or at least contribute, while you still feel like a learner yourself can be&amp;nbsp;intimidating to say the least.&amp;nbsp; But one thing that I have learned is that if you know a subject pretty well, one of the best ways to take your knowledge to the next level is to teach what you &lt;em&gt;do&lt;/em&gt; know.&amp;nbsp; Seriously.&amp;nbsp; When&amp;nbsp; you actually have to verbalize your thoughts and put together a cohesive study, the knowledge base solidifies and you may even find yourself researching&amp;nbsp;aspects that you hadn't considered prior.&lt;br /&gt;&lt;br /&gt;Inspired by one of the emails on Win4n6 list, I decided to try&amp;nbsp;a basic Windows command prompt tutorial.&amp;nbsp; No, it's&amp;nbsp;nothing new, and yes, it's very basic, but&amp;nbsp;I figure that I have to start somewhere.&amp;nbsp; If it is useful, I'll follow up with a tutorial on the robocopy command and creating CMD&amp;nbsp;batch files.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://i.ytimg.com/vi/Cp5T3Z5k5Qw/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Cp5T3Z5k5Qw?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266"  src="http://www.youtube.com/v/Cp5T3Z5k5Qw?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-229403109361096659?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/229403109361096659/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2012/01/trying-something-new-my-first.html#comment-form' title='15 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/229403109361096659'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/229403109361096659'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2012/01/trying-something-new-my-first.html' title='Trying Something New - My First Instructional Video'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><thr:total>15</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-7029736856205617418</id><published>2011-11-10T08:41:00.000-08:00</published><updated>2011-11-14T08:41:40.626-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Travel'/><title type='text'>5 Side Benefits to Attending a DFIR Conference</title><content type='html'>I got back from the PFIC in Park City yesterday afternoon.&amp;nbsp; &lt;a href="http://windowsir.blogspot.com/2011/11/pfic-2011.html"&gt;Harlan Carvey&lt;/a&gt; already posted a great account of the PFIC so I won't do a full redux.&amp;nbsp; Instead, I have included some side benefits to attendence for those of you who are on the fence about going to future conferences.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;strong&gt;Benefits You May Not Have Considered...&lt;/strong&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;﻿﻿﻿﻿&lt;/div&gt;﻿﻿ &lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;1&amp;nbsp;- If you lose your iPhone, it will get returned.&amp;nbsp; However, it will also have been imaged and analyzed in depth by those who have yet to get the chance to work on one in their cases.&amp;nbsp; To, you know, figure out who it belongs to and stuff.&amp;nbsp; Yeah.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;2&amp;nbsp;- The presenters are the DFIR equivalent of&amp;nbsp;&lt;strike&gt;Justin Bieber&lt;/strike&gt; &lt;strike&gt;Twilight actors&lt;/strike&gt;&amp;nbsp;someone actually good at what they do.&amp;nbsp; And this is a way to meet them in a way that doesn't end with an inconvenient&amp;nbsp;restraining order.&amp;nbsp;﻿﻿﻿ ﻿&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;3&amp;nbsp;- After years of being avoided during parties when you start talking about your work, people you meet actually &lt;em&gt;want&lt;/em&gt; to hear about the details of&amp;nbsp;how you do your&amp;nbsp;job.&amp;nbsp; Extra bonus:&amp;nbsp; Not being compared to a TV character on a crime procedural.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;﻿ &lt;br /&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-wPsJ5n2YHkA/Trv3iZ6voDI/AAAAAAAAAJw/OmFsaoX86co/s1600/hex.png" imageanchor="1" style="clear: left; cssfloat: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="141" nda="true" src="http://4.bp.blogspot.com/-wPsJ5n2YHkA/Trv3iZ6voDI/AAAAAAAAAJw/OmFsaoX86co/s200/hex.png" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;"Nerd Porn"&lt;br /&gt;It's beautiful, isn't it?&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;﻿ &lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;4&amp;nbsp;- No one asks you if you can fix their computer.&amp;nbsp; If someone does have a problem - like malware - they happily tell you what&amp;nbsp;artifacts they examined and analysis insight gained&amp;nbsp;as a result.&amp;nbsp; &lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;5&amp;nbsp;- Nerd Porn*.&amp;nbsp; Because there is something strangely satisfying about watching hex in a room full of strangers.&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;* Phrase coined by @keydet.&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;But of course,&amp;nbsp;the chance to meet up with other people in the industry is by far the biggest bonus to these events.&amp;nbsp; Thanks to all who made&amp;nbsp;the time&amp;nbsp;fun and useful.&amp;nbsp; I'll see you on the flip side...&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;UPDATE:&amp;nbsp; For those who went to the conference and want to catch up with some of the people there, here is a list of attendees that I am aware of:&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;&lt;a href="http://journeyintoir.blogspot.com/"&gt;Journey Into Incident Response&lt;/a&gt; - Corey is as amazingly knowledgeable as his blog suggests, but is also incredibly approachable.&amp;nbsp; &lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;&lt;a href="http://writeblocked.org/"&gt;WriteBlocked&lt;/a&gt; - Mike will melt your brain with his knowledge of NTFS.&amp;nbsp; True story.&amp;nbsp; He is also a great resource for lost iPhones.&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;&lt;a href="http://forensicmethods.com/"&gt;Forensic Methods&lt;/a&gt; - Seeing Chad present solidified my longing to attend a SANS course.&amp;nbsp; Very, very good stuff.&amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;&lt;a href="http://windowsir.blogspot.com/"&gt;Windows IR&lt;/a&gt; - I resisted the urge to bring my DFIR library in order to have Harlan sign each book.&amp;nbsp; It was great to see him present, as he not only knows his stuff but is&amp;nbsp;incredibly good at conveying the concepts.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-7029736856205617418?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/7029736856205617418/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/11/5-side-benefits-to-attending-dfir.html#comment-form' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/7029736856205617418'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/7029736856205617418'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/11/5-side-benefits-to-attending-dfir.html' title='5 Side Benefits to Attending a DFIR Conference'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-wPsJ5n2YHkA/Trv3iZ6voDI/AAAAAAAAAJw/OmFsaoX86co/s72-c/hex.png' height='72' width='72'/><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-8268829221741448049</id><published>2011-11-03T15:47:00.000-07:00</published><updated>2011-11-09T09:44:47.935-08:00</updated><title type='text'>Timelines and Tiaras... and a Broken Promise</title><content type='html'>&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;﻿﻿As I have&amp;nbsp;done before with many a&amp;nbsp;new venture, I started my Linux journey starry-eyed and not willing to bend on any of my self-imposed rules.&amp;nbsp; Multiple people suggested the (Linux-based)&amp;nbsp;&lt;a href="http://computer-forensics.sans.org/community/downloads"&gt;SIFT&lt;/a&gt; workstation, but I demurred.&amp;nbsp; Looking back, I don't know why I didn't jump on it right away... oh, wait.&amp;nbsp; I remember... I was going to do this Old School.&amp;nbsp; From &lt;em&gt;scratch&lt;/em&gt;.&amp;nbsp; Yeah.&amp;nbsp;&amp;nbsp; And then, last Wednesday, I joined in on the HTCIA and COINS "Super Timeline Analysis" &lt;a href="https://www.sans.org/webcasts/htcia-coins-pleased-present-super-timeline-analysis-94739"&gt;webinar&lt;/a&gt;.&amp;nbsp; And it hit me.&amp;nbsp; Yes, really cool tools (like &lt;a href="http://log2timeline.net/"&gt;log2timeline&lt;/a&gt;)&amp;nbsp;can be installed separately, but&amp;nbsp;why reinvent the wheel when SIFT has them already preconfigured?&amp;nbsp;&amp;nbsp;And by using a virtual box&amp;nbsp;it is&amp;nbsp;so easy&amp;nbsp;for SIFT and&amp;nbsp;Windows to work&lt;em&gt; together&lt;/em&gt;... well, I had an epiphany, followed closely by another epiphany&amp;nbsp;(which apparently felt like I wasn't paying&amp;nbsp;it enough attention and so&amp;nbsp;was making&amp;nbsp;itself known by metaphorically jumping on the couches and leaving presents in my shoes):﻿ &lt;br /&gt;﻿ &lt;br /&gt;&lt;div style="text-align: right;"&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;strong&gt;Epiphanies﻿ ﻿﻿﻿﻿&lt;/strong&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;﻿ &lt;br /&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: right; text-align: right;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-1ethX9JtUDc/TrM-44mgNNI/AAAAAAAAAJo/fV6qmuvHdMs/s1600/momo.jpg" imageanchor="1" style="clear: right; cssfloat: right; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="200" ida="true" src="http://2.bp.blogspot.com/-1ethX9JtUDc/TrM-44mgNNI/AAAAAAAAAJo/fV6qmuvHdMs/s200/momo.jpg" width="151" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;This is actually my &lt;br /&gt;"nephew"... not an epiphany.&lt;br /&gt;But you get the idea.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;﻿ &lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;1)&amp;nbsp; I have learned a lot about Linux in the past couple weeks, but I believe that SIFT will allow for continued learning in this area.&amp;nbsp;&amp;nbsp;Hey, it's still Linux.&amp;nbsp; And I will be rocking that command prompt so hard it won't know what hit it.&amp;nbsp; &lt;span style="font-size: x-small;"&gt;Okay, I admit it, I was getting sick of dealing with&amp;nbsp;a dual boot.&amp;nbsp; VMWARE hooray!&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;2)&amp;nbsp; The end goal of testing new procedures is to make&amp;nbsp;the "real"&amp;nbsp;work better.&amp;nbsp; By testing new open source tools&amp;nbsp;with procedures I already use,&amp;nbsp;my analysis process&amp;nbsp;will be more streamlined&amp;nbsp;when I&amp;nbsp;integrate&amp;nbsp;the tools into my investigations.&lt;/div&gt;&lt;br /&gt;So, new plan:&amp;nbsp; I will use a Windows machine, but will limit my usage to open source or free tools, wherever possible.&amp;nbsp; Seems like a decent compromise, right?&amp;nbsp; (You win, John Hodgman)&amp;nbsp; Besides, I'm anxious to&amp;nbsp;play around with&amp;nbsp;&lt;a href="http://dfsforensics.blogspot.com/2011/11/registry-decoder-11-released.html"&gt;RegistryDecoder&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;On Starting With the End&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The coolness of SIFT aside, one of the other things I really enjoyed about the webcast was how Rob Lee worked backwards in time&amp;nbsp;as he&amp;nbsp;demonstrated timeline analysis - starting with the finalized spreadsheet and then showing the steps he took to get there.&amp;nbsp; As a learning tool, I thought that was excellent.&amp;nbsp; If you start off on a journey, it's helpful to&amp;nbsp;know where you are going.&amp;nbsp; If you don't know the expected format, how will you recognize anomalies?&amp;nbsp; &lt;br /&gt;&lt;br /&gt;A similar line of thought can be used when writing reports.&amp;nbsp; "Begin with the end of your case"&amp;nbsp;- great words about report writing&amp;nbsp;coming from&amp;nbsp;a recent &lt;a href="http://unchainedforensics.blogspot.com/2011/09/lessons-learned.html"&gt;post&lt;/a&gt; on Unchained Forensics.&amp;nbsp; The idea of writing the summary &lt;em&gt;before the exam &lt;/em&gt;really got me thinking.&amp;nbsp; On the issue of&amp;nbsp;how&amp;nbsp;familiar&amp;nbsp;an examiner should be with a case prior to performing their analysis, I fall firmly in the category of "the more&amp;nbsp;we know the better&amp;nbsp;we can do&amp;nbsp;our jobs."&amp;nbsp; Context helps an examiner focus their efforts.&amp;nbsp; Not only is it more cost effective, but things may be overlooked or misinterpreted&amp;nbsp;if the background to the case isn't known. &amp;nbsp;At this point in my musings,&amp;nbsp;I found myself humming the following melody:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;WARNING:&amp;nbsp; This video should not be viewed by those who don't like extreme cheesiness, musicals, general cheesiness, Shakespeare, self-aware cheesy dialogue, and/or &lt;em&gt;really&lt;/em&gt; cheesy choreography.&amp;nbsp; Don't say I didn't warn you.&amp;nbsp; &lt;/span&gt;&lt;br /&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://2.gvt0.com/vi/rO-CN9lJvYo/0.jpg" height="266" style="clear: left; float: left;" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/rO-CN9lJvYo&amp;fs=1&amp;source=uds" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266"  src="http://www.youtube.com/v/rO-CN9lJvYo&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;br /&gt;For those that don't want to torture themselves with my questionable musical tastes, the song is two characters comparing themselves - very happily -&amp;nbsp;to Shakespeare's &lt;em&gt;Romeo and Juliet&lt;/em&gt;.&lt;br /&gt;&amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;/div&gt;&lt;div align="center"&gt;"I bet Romeo marries his Juliet&lt;/div&gt;&lt;div align="center"&gt;They have a baby&lt;/div&gt;&lt;div align="center"&gt;And make lots of friends!&lt;/div&gt;&lt;div align="center"&gt;That's probably the way the play ends.﻿"&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;I can't help thinking that if the characters in the song had a bit more context (i.e. that &lt;em&gt;Romeo and Juliet&lt;/em&gt; is a tragedy) they would have been less apt to tempt the powers of&amp;nbsp;Literary Device&amp;nbsp;by comparing themselves to the star-crossed lovers.&amp;nbsp; Lucky for us examiners, there is nothing wrong with going through a few different hypotheses during an examination.&amp;nbsp; In fact, I think it is beneficial to the process to explore both expected and unexpected data.&amp;nbsp; That doesn't mean we should try to force the data where it doesn't fit, but knowing how and why&amp;nbsp;it doesn't fit can be important as well.&amp;nbsp; I may just have to try out this idea of pre-examination summaries.&amp;nbsp; It is certainly intriguing... once I've tested it for myself I'll let you know how it went.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;﻿﻿﻿ ﻿&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;﻿﻿﻿﻿﻿﻿&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;/div&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-Ng9oUtQppWo/TrMTUEU0umI/AAAAAAAAAJg/Nj7OnvMe2-s/s1600/SIFT.jpg" imageanchor="1" style="clear: left; cssfloat: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="128" ida="true" src="http://2.bp.blogspot.com/-Ng9oUtQppWo/TrMTUEU0umI/AAAAAAAAAJg/Nj7OnvMe2-s/s200/SIFT.jpg" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Playing around with timelines!&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; text-align: center;"&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Sure as I am breathing&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;You can make command-line prompting&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Language fun&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; text-align: left;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-8268829221741448049?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/8268829221741448049/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/11/timelines-and-tiaras-and-broken-promise.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/8268829221741448049'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/8268829221741448049'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/11/timelines-and-tiaras-and-broken-promise.html' title='Timelines and Tiaras... and a Broken Promise'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-1ethX9JtUDc/TrM-44mgNNI/AAAAAAAAAJo/fV6qmuvHdMs/s72-c/momo.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-989579033796487505</id><published>2011-10-31T14:16:00.000-07:00</published><updated>2011-10-31T14:16:54.086-07:00</updated><title type='text'>My Tale... Now Told</title><content type='html'>I was interviewed by Michael Kassner for an article on &lt;a href="http://www.techrepublic.com/blog/security/breaking-into-the-digital-forensics-field-melia-kelleys-path/6796?tag=content;blog-list-river"&gt;TechRepublic&lt;/a&gt;.&amp;nbsp; The article focuses mainly on my time in Iraq and how I "broke in" to the field.&amp;nbsp; Hopefully people find it an interesting read - Michael did a great job translating my rambling into a cohesive article.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;And lest you think I have forgotten about my Linux quest, know that a post about timeline analysis is coming soon.&amp;nbsp;&lt;span style="font-size: x-small;"&gt; Spoiler Alert:&amp;nbsp; I am going to try to tie it in to a musical number.&amp;nbsp; Those who know my taste in music may well consider that a threat.&amp;nbsp; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-989579033796487505?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/989579033796487505/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/10/my-tale-now-told.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/989579033796487505'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/989579033796487505'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/10/my-tale-now-told.html' title='My Tale... Now Told'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-4877060467847579190</id><published>2011-10-27T12:23:00.000-07:00</published><updated>2011-10-27T15:49:27.040-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Musings'/><title type='text'>This Break in Your Regularly Scheduled Linux Posting is Brought to You by Musings</title><content type='html'>﻿﻿﻿ &lt;br /&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: right; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-afP_oQddhwQ/TqmhtbwPMfI/AAAAAAAAAIc/34x9BKW2C3A/s1600/Logan.jpg" imageanchor="1" style="clear: left; cssfloat: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="169" ida="true" src="http://2.bp.blogspot.com/-afP_oQddhwQ/TqmhtbwPMfI/AAAAAAAAAIc/34x9BKW2C3A/s200/Logan.jpg" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Guess which one my brother is?&lt;br /&gt;Hint:&amp;nbsp; He's the one that looks like a &lt;br /&gt;younger brother.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Though not a language guru myself, I have two younger brothers that have gone through the DLI (Defense Language Institute) as part of their training in the Army.&amp;nbsp; Never having been myself, it appears to be a pretty intense study (Arabic and Korean aren't the easiest languages to learn, either).&amp;nbsp; As an older sister, I feel that it is my right to be proud of what my baby brothers have accomplished.&amp;nbsp; &lt;span style="font-size: x-small;"&gt;It is also within my rights (according to subsection II b of the Elder Sister Contract) to rib them for the fact that I've been to Iraq and they haven't.&amp;nbsp; &lt;/span&gt;&lt;span style="font-size: small;"&gt;Learning a new language is hard&amp;nbsp;biscuits, especially if you haven't been exposed&amp;nbsp;to the situation&amp;nbsp;before to know its best to dunk them in your drink of choice.&amp;nbsp; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Luckily, my research (from watching &lt;em&gt;13th Warrior&lt;/em&gt;) shows that immersion is a great way to become conversant in Old Norse.&amp;nbsp; My own attempts to sit down with Linux next to a roaring fire have been less successful, but I'm getting there.&amp;nbsp;&amp;nbsp;Learning to operate a&amp;nbsp;command line&amp;nbsp;or learning a programming language really &lt;em&gt;is&lt;/em&gt; learning another language, and some of the same tactics used to learn one may well help in learning another.&amp;nbsp; An hour course in a language may well teach you how to put together the syllables to say "where's the bathroom" or how to run a specific script in a certain environment, but what then?&amp;nbsp; And why bother in the first place?&lt;br /&gt;&lt;br /&gt;I get it (I really, really do) -&amp;nbsp;it can be intimidating.&amp;nbsp; The "native speakers" set a pretty high bar.&amp;nbsp; And we've spent so long working on the language we know now.&amp;nbsp; And this language sure works for the people we need to talk to right now, right?&amp;nbsp; In his post on learning &lt;a href="http://journeyintoir.blogspot.com/2011/10/book-review-perl-programming-for.html"&gt;Perl Programming&lt;/a&gt;, &lt;span class="fn"&gt;Corey Harrell&lt;/span&gt; gives great reasons on why&amp;nbsp;learning&amp;nbsp;a new&amp;nbsp;language&amp;nbsp;was important to his work:&amp;nbsp; deeper understanding, extending current capabilities, and a baseline that will allow for the&amp;nbsp;expansion of future capabilities.&amp;nbsp; Yes, it's hard, but worth it.&amp;nbsp; As examiners, it behooves us to have a variety of tools at our disposal, and then to use all the tools appropriate for any given exam.&amp;nbsp; It's a digital Arms Race out there, and there is no end goal.&amp;nbsp; We need to keep moving - not just as an industry, but as individuals.&amp;nbsp; &lt;br /&gt;﻿﻿&lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;The good news is that, just like spoken languages, the more digital languages you learn the easier it is to pick up new ones.&amp;nbsp; And Korean or Arabic, DOS or python, there is value to each (check out &lt;a href="http://blog.commandlinekungfu.com/"&gt;Command Line Kung Fu&lt;/a&gt;&amp;nbsp;to&amp;nbsp;glimpse the possibilities).&amp;nbsp;&amp;nbsp;&amp;nbsp;So get out there, eat a biscuit/sit around a fire/practice high kicks.&amp;nbsp; I'm doing it too... and would love the company.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-4877060467847579190?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/4877060467847579190/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/10/this-break-in-your-regularly-scheduled.html#comment-form' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/4877060467847579190'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/4877060467847579190'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/10/this-break-in-your-regularly-scheduled.html' title='This Break in Your Regularly Scheduled Linux Posting is Brought to You by Musings'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-afP_oQddhwQ/TqmhtbwPMfI/AAAAAAAAAIc/34x9BKW2C3A/s72-c/Logan.jpg' height='72' width='72'/><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-5232875199921874306</id><published>2011-10-24T16:34:00.000-07:00</published><updated>2011-10-26T11:50:17.322-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kinda Sorta Useful'/><title type='text'>Paying the Boatman - Escape Across the River Linux</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-vpfs4x8g8Ds/TqXV9t8c46I/AAAAAAAAAH8/doiTpyFpZkw/s1600/styx.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="153" src="http://3.bp.blogspot.com/-vpfs4x8g8Ds/TqXV9t8c46I/AAAAAAAAAH8/doiTpyFpZkw/s200/styx.jpg" width="200" /&gt;&lt;/a&gt;Close as I am to the stuff of legends &amp;lt;/sarcasm&amp;gt;,&amp;nbsp; surprises have lurked around every corner as I quest for a completely open source exam.&amp;nbsp; However, those adventures require another telling, at another time.&amp;nbsp; The chants have been spoken, rites performed, and my computer is now excised from the commercial shores.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Troubleshooting aside, I have also been spending time downloading additional tools.&amp;nbsp; The great &lt;a href="http://righteousit.wordpress.com/"&gt;Hal Pomeranz&lt;/a&gt; (of Linux and dancing fame) provided me with an expanded list of Linux tools for the exam.&amp;nbsp; I have also been loading my system with old favorites like &lt;a href="http://regripper.wordpress.com/"&gt;regripper&lt;/a&gt; and a command-line &lt;a href="http://accessdata.com/support/adownloads"&gt;FTK imager&lt;/a&gt;.&amp;nbsp; I'm not going to go through the full list now, but I will include which tools I am using for each exercise as I move forward.&lt;br /&gt;&lt;br /&gt;After giving much thought (i.e. a couple minutes while nomming a biscuit), I haven't decided what to actually examine.&amp;nbsp; My thoughts are as follows:&amp;nbsp; 1) there's no way I want to examine my own drive... there's just some stuff no one needs to know;&amp;nbsp; 2) if I created the image I'd know what I was looking for and that kind of defeats the purpose.&amp;nbsp; So, if anyone has a recommendation for a test image to use, please let me know.&amp;nbsp; We can play Show-me-your-method-and-I'll-show-you-mine.&amp;nbsp; Until then, I'm going to just do a couple generic steps to keep me moving forward in my task.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;A Short Step in a Long Journey&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;I've made no secret of my love affair with RegRipper, and since it was the first tool that opened my eyes to the wonders of Open Source tools, it seems only appropriate that I use it as a starting place for this exam.&amp;nbsp; No installation is required to run RR, and since Perl comes pre-installed on Ubuntu, all that is needed is to download the &lt;a href="http://code.google.com/p/winforensicaanalysis/downloads/detail?name=rr_tools.zip&amp;amp;can=2&amp;amp;q="&gt;code&lt;/a&gt; and you are ready to go.&amp;nbsp;&amp;nbsp; &lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-kKr63ARd0wg/TqXxA5SzEJI/AAAAAAAAAIE/FBpAs1xQM-0/s1600/Sampl.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="105" src="http://4.bp.blogspot.com/-kKr63ARd0wg/TqXxA5SzEJI/AAAAAAAAAIE/FBpAs1xQM-0/s400/Sampl.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Navigate to the folder that contains the extracted contents of the download.&amp;nbsp; In my case, the account is called "work" and I have been placing all of my programs in a folder called "tools", so to navigate to regripper I type "cd /home/work/tools/regripper".&amp;nbsp; Once at the prompt I ran the corresponding plugins across each of the five hive types.&amp;nbsp; The command line version is really just like the windows GUI I was utilizing previously, just without the browsing option.&amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;style type="text/css"&gt; &lt;!--  @page { margin: 0.79in }  P { margin-bottom: 0.08in } --&gt; &lt;/style&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in; text-align: center;"&gt;perl rip.pl -r /home/work/Desktop/OSExam/OSExamRegistry/SAM &amp;gt; /home/work/Desktop/OSExam/SAMRip.txt -f sam&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-KMXYVB8SVlM/TqbbcGuV6ZI/AAAAAAAAAIU/PvXSJdk3OV0/s1600/Plugins.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="141" src="http://3.bp.blogspot.com/-KMXYVB8SVlM/TqbbcGuV6ZI/AAAAAAAAAIU/PvXSJdk3OV0/s400/Plugins.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;**&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in; text-align: left;"&gt;I interpret this script as saying &lt;i&gt;"Hey, you.&amp;nbsp; Yeah, you.&amp;nbsp; Perl.&amp;nbsp; I came all the way out to your directory, so I need you to do something, see?&amp;nbsp; What I need you to do is go out to this SAM file... yeah, here's the directions... and put the information you get into a file.&amp;nbsp; Yeah, yeah, here's a map.&amp;nbsp; Oh, you want to know what information to get?&amp;nbsp; Here's this list that the Boss made.&amp;nbsp; 's called sam.&amp;nbsp; It has everything you need to know."&lt;/i&gt;&amp;nbsp; To me, this script has a Jersey accent.*&amp;nbsp; This script can then be altered for each of the remaining hives: &amp;nbsp; SECURITY, software, system, and of course, NTUSER.DAT.&amp;nbsp; In fact, if the hives have been exported to the same location, a simple replace function can make it quick and painless.&lt;/div&gt;&lt;div style="margin-bottom: 0in; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in; text-align: left;"&gt;&lt;a href="http://2.bp.blogspot.com/-RWeRqQAg7_Q/TqX1a6rUZUI/AAAAAAAAAIM/Q1GRTwUztSA/s1600/RipOutput.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="93" src="http://2.bp.blogspot.com/-RWeRqQAg7_Q/TqX1a6rUZUI/AAAAAAAAAIM/Q1GRTwUztSA/s200/RipOutput.png" width="200" /&gt;&lt;/a&gt;And voilà!&amp;nbsp; Triage can begin by looking over the information found in the registry.&amp;nbsp; &lt;/div&gt;&lt;div style="margin-bottom: 0in; text-align: left;"&gt;Stay tuned for the next installment. &lt;/div&gt;&lt;div style="margin-bottom: 0in; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span style="font-size: x-small;"&gt;*It may also belong to the mafia, but you didn't hear it from me.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;** As Hal noted, the plugin is usually given prior to the output.&amp;nbsp; For reasons as yet unknown to me, it works find in my system to do it before or after.&amp;nbsp; So, if you try to run my command and it doesn't work for you, change the plugin location! &lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-5232875199921874306?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/5232875199921874306/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/10/paying-boatman-escape-across-river.html#comment-form' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/5232875199921874306'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/5232875199921874306'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/10/paying-boatman-escape-across-river.html' title='Paying the Boatman - Escape Across the River Linux'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-vpfs4x8g8Ds/TqXV9t8c46I/AAAAAAAAAH8/doiTpyFpZkw/s72-c/styx.jpg' height='72' width='72'/><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-5923049939998941255</id><published>2011-10-20T14:40:00.000-07:00</published><updated>2011-10-20T15:24:03.306-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kinda Sorta Useful'/><title type='text'>Crossing the River Linux</title><content type='html'>For as much as I profess to love open source, I have a confession to make:&amp;nbsp; up to this point in my career, Windows has been my OS of choice.&amp;nbsp; Oh, I'd do my time with MAC OSs when needed, but then it was straight back.&amp;nbsp; Well, I've decided to break that cycle.&amp;nbsp; It's time for rehab.&amp;nbsp; My goal is to undergo a self-imposed Open-Source/Free Tool immersion program, the end goal of which is to conduct a comprehensive (practice) forensic exam using &lt;i&gt;only&lt;/i&gt; open source tools.&amp;nbsp; So... Let's do this!&amp;nbsp; Lerooooy.....&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;Rehab Day 1&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;This first entry could alternatively have been called &lt;i&gt;Ubuntu for the Absolute Beginner&lt;/i&gt;.&amp;nbsp; Beyond forensic boot CDs like Helix and Raptor, I have very limited experience in a Linux environment.&amp;nbsp; I decided to use &lt;a href="http://www.ubuntu.com/download/ubuntu/download"&gt;Ubuntu&lt;/a&gt; as my OS because it is the distribution used in the examples found in &lt;a href="http://www.amazon.com/Digital-Forensics-Open-Source-Tools/dp/1597495867/ref=sr_1_1?ie=UTF8&amp;amp;qid=1319144168&amp;amp;sr=8-1"&gt;&lt;i&gt;Digital Forensics with Open Source Tools&lt;/i&gt;&lt;/a&gt;.&amp;nbsp; But on a personal level, they had me at &lt;i&gt;Oneiric Ocelot.&amp;nbsp; &lt;/i&gt;&lt;span style="font-size: x-small;"&gt;Oh, you non-commercial guys are adorable.&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-V3qUxuFagGw/TqBn1GKVLeI/AAAAAAAAAHg/V5quuI3hnyY/s1600/commandprompt.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="141" src="http://3.bp.blogspot.com/-V3qUxuFagGw/TqBn1GKVLeI/AAAAAAAAAHg/V5quuI3hnyY/s200/commandprompt.png" width="200" /&gt;&lt;/a&gt;After burning the ISO to a CD and installing on a spare 500GB HD, I was ready to go.&amp;nbsp; The Terminal was &lt;i&gt;eventually&lt;/i&gt; found by selecting Dash Home and searching for "command."&lt;br /&gt;I am pretty comfortable using a command prompt, so I figured that this wouldn't be too much of a stretch, but I have come away with some lessons learned:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;1.&amp;nbsp; Linux is sensitive to caps.&amp;nbsp; You can't just type upper and lowercase without regard like you can in DOS/Windows.&amp;nbsp; &lt;span style="font-size: x-small;"&gt;Remember this.&amp;nbsp; I can't tell you how many times I typed a path before I remembered that one of the directories needed to be capitalized.&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;2.&amp;nbsp; The directory slash is opposite than it is in Windows.&amp;nbsp; Windows = \&amp;nbsp; Linux = /&lt;/div&gt;&lt;div style="text-align: center;"&gt;3.&amp;nbsp; Putting a / at the beginning of a path denotes an explicit path (you need to write out the full path), whereas leaving it out is a relative path (the path starts in the directory you are currently in).*&lt;/div&gt;&lt;br /&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: right; margin-left: 1em; text-align: right;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-ACInr5JHjpA/TqBn7gqtu7I/AAAAAAAAAHo/_0QN3VuYy0w/s1600/pg12.png" imageanchor="1" style="clear: right; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="128" src="http://3.bp.blogspot.com/-ACInr5JHjpA/TqBn7gqtu7I/AAAAAAAAAHo/_0QN3VuYy0w/s200/pg12.png" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;It's like pg 12 of DFwOST... &lt;span style="font-size: xx-small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;except its on my computer!&lt;/span&gt;&lt;/td&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;/td&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;/td&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;Installing Software&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;All of the software that I downloaded comes with installation instructions, but just in case it saves someone the time of going through them, here's the instructions for what I installed today. &lt;br /&gt;&lt;br /&gt;Perl and Python were pre-loaded with the OS.&lt;br /&gt;&lt;br /&gt;Installed Python 3 (as recommended in DFwOST) by typing "sudo apt-get install python3-minimal" into Terminal.&lt;br /&gt;&lt;br /&gt;Installed Ruby by typing "sudo apt-get install ruby" into Terminal&lt;br /&gt;&lt;br /&gt;Installed &lt;a href="http://www.sleuthkit.org/"&gt;The Sleuth Kit&lt;/a&gt; by downloading and extracting the tar.gz.&amp;nbsp; In terminal I navigated to the extracted folder and typed "./configure" followed by "make" followed by "sudo make install".&lt;br /&gt;&lt;br /&gt;Installed &lt;a href="http://log2timeline.net/"&gt;log2timeline &lt;/a&gt;by downloading and extracting tgz.&amp;nbsp; In terminal I navigated to extracted folder and typed "perl Makefile.PL" (note capitals!) followed by "make" followed by "sudo make install".&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-TLJe08i4QQo/TqCVJyR8ztI/AAAAAAAAAHw/lBnb4S1iUXQ/s1600/images.jpeg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="193" src="http://3.bp.blogspot.com/-TLJe08i4QQo/TqCVJyR8ztI/AAAAAAAAAHw/lBnb4S1iUXQ/s200/images.jpeg" width="200" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;What's Next?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now that my system is up and running, I will start the examination and keep you updated.&amp;nbsp; I know that I may be late to the Linux party, but hopefully this proves helpful to someone out there.&amp;nbsp; And if nothing else, at least I got chicken.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;* This realization (which was immensely helpful!) came from reading "The Beginner's Guide v3.78" at http://linuxleo.com/.&amp;nbsp; If you are interested in Linux for forensics, check it out.&amp;nbsp; Lots of interesting tips.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-5923049939998941255?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/5923049939998941255/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/10/crossing-river-linux.html#comment-form' title='14 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/5923049939998941255'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/5923049939998941255'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/10/crossing-river-linux.html' title='Crossing the River Linux'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-V3qUxuFagGw/TqBn1GKVLeI/AAAAAAAAAHg/V5quuI3hnyY/s72-c/commandprompt.png' height='72' width='72'/><thr:total>14</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-6923773829859648464</id><published>2011-10-17T14:28:00.000-07:00</published><updated>2011-10-19T12:41:31.673-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FE Side'/><title type='text'>FE Side 4  - And a Poll... Just Because</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: left;"&gt;UPDATE:&amp;nbsp; The voters have spoken... "Stats" won by one vote.&amp;nbsp; Thank you for your input!&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: center;"&gt;&lt;img border="0" height="316" oda="true" src="http://2.bp.blogspot.com/-kGh7aIjVcwg/TpydqJVP_8I/AAAAAAAAAHQ/cJ8lmy7ktn4/s400/Stats.png" width="400" /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-6923773829859648464?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/6923773829859648464/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/10/fe-side-poll-just-because.html#comment-form' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/6923773829859648464'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/6923773829859648464'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/10/fe-side-poll-just-because.html' title='FE Side 4  - And a Poll... Just Because'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-kGh7aIjVcwg/TpydqJVP_8I/AAAAAAAAAHQ/cJ8lmy7ktn4/s72-c/Stats.png' height='72' width='72'/><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-296634311215717031</id><published>2011-10-13T10:31:00.000-07:00</published><updated>2011-10-13T12:47:45.210-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Musings'/><title type='text'>Digital Park</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: left;"&gt;I bought &lt;em&gt;Digital Forensics With Open Source Tools&lt;/em&gt; as soon as it was available, but I have to admit that I haven't been able to really sit down and test the procedures until recently.&amp;nbsp; I am one of those "lucky" DFIR folks that works for a company that has&amp;nbsp;the budget that allows us to purchase and maintain licenses in the major forensic suites as well as software for specific areas of analysis (i.e. internet analysis, portable devices, etc).&amp;nbsp; However, I've&amp;nbsp;noticed a recent&amp;nbsp;trend in the way I conduct my own examinations.&amp;nbsp; While I still use the commercial software for the&amp;nbsp;"big picture," more and more I am turning to open source tools for certain processes and for validating my findings within the suites.&amp;nbsp; This could be because I've leveled recently and a new Talent Point was available.&amp;nbsp; (In which case, booyah.&amp;nbsp; I think I'm close to a flying mount.)&amp;nbsp; &lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;But my situation got me thinking.&amp;nbsp; So put safety belts on your brain -&amp;nbsp;I'm about to start analogizing...&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;If I hadn't already convinced you of my complete lack of cool, I have another confession to make:&amp;nbsp; I love dinosaurs.&amp;nbsp; Well, the love extends beyond dinosaurs to any number of prehistoric, now-extinct animals (limiting my research of natural history to the Mesozoic would leave out gems like the &lt;em&gt;Leptictidium&lt;/em&gt; and &lt;em&gt;Panthera atrox&lt;/em&gt;).﻿&amp;nbsp; And like any amateur dino hobbyist, I visit museums, dig sites, and dino parks.&amp;nbsp; And, of course, watch the shows.&amp;nbsp; Hollywoodized adventure, educational, even cartoons at times.&amp;nbsp; Granted, sometimes I just watch so I can roll my eyes and explain &lt;em&gt;why that is totally wrong... &lt;/em&gt;but I still watch them.&amp;nbsp; &lt;span style="font-size: xx-small;"&gt;I'll get back to DFIR eventually... I promise.&amp;nbsp; &lt;/span&gt;&lt;span style="font-size: small;"&gt;This brings me to the two shows for this discussion:&amp;nbsp; &lt;em&gt;Jurassic Park&lt;/em&gt; and &lt;em&gt;Prehistoric Park&lt;/em&gt;.&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;﻿ ﻿﻿﻿﻿﻿&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;﻿&lt;/div&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="clear: right; cssfloat: right; float: right; margin-bottom: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-x2Ir6dNM0Q0/TpRr8NWVYyI/AAAAAAAAAG4/echwhw50S_o/s1600/JPFence.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="131" kca="true" src="http://2.bp.blogspot.com/-x2Ir6dNM0Q0/TpRr8NWVYyI/AAAAAAAAAG4/echwhw50S_o/s200/JPFence.jpg" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;"We spared no expense."&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;"We spared no expense" is a phrase repeated many times by the character John Hammond (aka Old Guy).&amp;nbsp; He had teams of scientists, Paleontologists, and what I can only assume was a proto-Crocodile Hunter.&amp;nbsp; And Jeff Goldblum can wail all he wants about Nature having it's way, but I see the whole fiasco&amp;nbsp;as an information&amp;nbsp;and systems breakdown.&amp;nbsp; Much of the problems encountered in the show revolve around the idea that the dinosaurs are genetically altered (with the frog DNA), and apparently&amp;nbsp;no one really took the time to figure out what the changes would be.&amp;nbsp; If more attention was paid to the small details, and additional research done on the processes used, the outcome of the show could have been drastically different (i.e. not as entertaining).&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&amp;nbsp;﻿ &lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;/div&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-PfqA74pctw4/TpRsBC-33iI/AAAAAAAAAHA/P4y_ft4YQy0/s1600/PPFence.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="112" kca="true" src="http://4.bp.blogspot.com/-PfqA74pctw4/TpRsBC-33iI/AAAAAAAAAHA/P4y_ft4YQy0/s200/PPFence.jpg" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; text-align: center;"&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Wooden fence?&amp;nbsp; Check.&amp;nbsp; Does the job.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;﻿By contrast, Prehistoric Park never mentions&amp;nbsp;a large&amp;nbsp;budget.&amp;nbsp; And the wooden handmade fences and small staff suggest it isn't very large.&amp;nbsp; (Maybe they spent it all on the time machine)&amp;nbsp; Also, by contrast, no changes are made to the dinosaurs.&amp;nbsp; Nigel simply goes back in time and gets them.&amp;nbsp; And because he is a paleontologist and adventurer (and The Man!) he knows enough about them to escape injury.&amp;nbsp; Being chased by a T-Rex?&amp;nbsp; No problem.&amp;nbsp; He just heads for covered ground.&amp;nbsp; And&amp;nbsp;since the T-Rex is bottom heavy and not very nimble, it doesn't chase him there.&amp;nbsp; (I guess that frog DNA really increased the nimbleness of the T-Rex in &lt;em&gt;Jurassic Park&lt;/em&gt;... that thing crashed through undergrowth like nothing else).&amp;nbsp; Of course, Nigel got away with it because he knows a lot about the creatures he would be encountering.&amp;nbsp; So... do you see where I'm going with this? &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;And finally to my point.&amp;nbsp; Using forensic software is great, especially if you have the budget.&amp;nbsp; But be wary ﻿of not understanding the processes used to present the data that you are seeing.&amp;nbsp; (See questions raised during the Casey Anthony trial regarding search terms)&amp;nbsp; A big budget isn't everything, though.&amp;nbsp; If you have the knowledge and willingness to get in and "get your hands dirty" (digitally speaking),&lt;em&gt;&amp;nbsp;you don't need the big budget&lt;/em&gt;.&amp;nbsp; &amp;nbsp;Plus, that method helps you understand the data on a deeper level, and puts you in direct contact with your data.&amp;nbsp; Booyah.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-296634311215717031?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/296634311215717031/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/10/digital-park.html#comment-form' title='9 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/296634311215717031'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/296634311215717031'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/10/digital-park.html' title='Digital Park'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-x2Ir6dNM0Q0/TpRr8NWVYyI/AAAAAAAAAG4/echwhw50S_o/s72-c/JPFence.jpg' height='72' width='72'/><thr:total>9</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-6542464548784614254</id><published>2011-09-19T16:03:00.000-07:00</published><updated>2011-10-20T15:24:17.943-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kinda Sorta Useful'/><title type='text'>On Writing</title><content type='html'>Every now and then,&amp;nbsp;I see requests for&amp;nbsp;sample reports from people in the field.&amp;nbsp; And while I can't share&amp;nbsp;reports I've written due to confidentiality issues, I thought it might make for an interesting post to write about some of the guidelines that I like to follow when writing.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;I did hesitate just a bit on posting about this, mostly because it shouldn't be taken as&amp;nbsp;DFIR Gospel (actually, nothing I write&amp;nbsp;in this blog should&amp;nbsp;be taken as such,&amp;nbsp;but I believe&amp;nbsp;you&amp;nbsp;are&amp;nbsp;savvy enough to know that).&amp;nbsp;&amp;nbsp;The following guidelines are just some things I've learned along the way that I try to adhere to in my own reports.&amp;nbsp; A lot of it will probably just sound like common sense.&amp;nbsp; Many of you are probably doing what I lay out, or something much better.&amp;nbsp; That said, if you want to add any ideas of your own, please feel free!&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;span style="font-size: x-large;"&gt;Girl, Unallocated Presents:&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size: large;"&gt;Report Writing Guidelines&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size: large;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Comic Sans MS&amp;quot;;"&gt;&lt;b&gt;Resist the Urge to Use&amp;nbsp;Comic Sans&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;br /&gt;... or any other&amp;nbsp;distracting font.&amp;nbsp; Times New Roman is your friend.&amp;nbsp; And whatever you do, absolutely &lt;i&gt;no&lt;/i&gt; Wing Dings.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Wingdings;"&gt;&lt;span lang="EN" style="font-family: Wingdings; line-height: 115%;"&gt;Balloons explode. They explode suddenly, and unexpectedly. They are filled with the capacity to give me a little fright, and I find that unbearable.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Be&amp;nbsp;Cautious of&amp;nbsp;Absolutes&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;There are a few times when you can say with certainty that something is &lt;i&gt;always&lt;/i&gt; true, or &lt;i&gt;never&lt;/i&gt; occurs.&amp;nbsp; Even if you are very sure&amp;nbsp;of a statement, be careful&amp;nbsp;about using absolutes.&amp;nbsp; (Unless you have tested&amp;nbsp;every eventuality and are sure there will be&amp;nbsp;no subsequent research with&amp;nbsp;opposing conclusions... these situations can create havoc during cross-examinations)&amp;nbsp; Useful phrases include:&amp;nbsp;"This leads me to believe..."&amp;nbsp; "It is&amp;nbsp;my professional opinion..."&amp;nbsp; "The evidence indicates...".&amp;nbsp; I'm not saying that you should be wishy-washy.&amp;nbsp; This language is a means of presenting the information as what it is - a professional opinion.&amp;nbsp; Being able to express opinions is what seperates an &lt;i&gt;expert&lt;/i&gt; &lt;i&gt;witness&lt;/i&gt;&amp;nbsp;from other kinds of witnesses.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Break it Up&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Reports&amp;nbsp;can get&amp;nbsp;long and are often very detailed.&amp;nbsp; For the reader, they&amp;nbsp;can seem&amp;nbsp;(&lt;span style="font-size: x-small;"&gt;le gasp&lt;/span&gt;) dry.&amp;nbsp;&amp;nbsp;Also, it seems to me that&amp;nbsp;with almost every report I write, the intended audience tends to&amp;nbsp;focus in on one or two items out of the entire report as&amp;nbsp;the items of real interest to them.&amp;nbsp;&amp;nbsp;And while I would like to think that they&amp;nbsp;marvel over every word as a&amp;nbsp;manifestation of genius, I know that what they really want to do is to zero in on the really juicy bits, and be able to navigate easily to other points as needed.&amp;nbsp; So, like many before me, I oblige by breaking my report up into sections.&amp;nbsp; A few sections that are frequently used by myself and others in the industry are as follows:&lt;br /&gt;&lt;br /&gt;Title Page - Include case name, date, investigator name and contact information.&amp;nbsp; &lt;br /&gt;Evidence - This should include serial numbers, hash values, custodian information, etc.&amp;nbsp; &lt;br /&gt;Objectives - Especially important to include if you were asked to perform a targeted investigation.&amp;nbsp; Also a good idea to include any&amp;nbsp;specific search terms requested.&lt;br /&gt;Steps Taken - Be detailed here.&amp;nbsp; Remember, your results should be reproducible.&lt;br /&gt;Relevant Findings - Subcategories will&amp;nbsp;depend&amp;nbsp;on purpose of the exam.&amp;nbsp; They&amp;nbsp;can include:&amp;nbsp; timeline; deleted data; encrypted/password protected; search terms; malware; etc., etc.&lt;br /&gt;Conclusion - Tie it all together.&amp;nbsp; &lt;br /&gt;Exhibits - I reserve exhibits A and B for my CV and Chain of Custody, respectively.&amp;nbsp; Certainly not necessary, but it makes it so I always remember to include them in my reports.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;An additional touch that I like to include is hyperlinks&amp;nbsp;within the report to make navigation easier.&amp;nbsp; Some places where hyperlinks prove useful is within the Table of Contents and&amp;nbsp;to referenced exhibits.&amp;nbsp; For example, I will usually include a hyperlink to the Chain of Custody form somewhere in the Evidence section.&amp;nbsp; And if you are now shaking your head and wondering why I make extra work for myself, wonder no more.&amp;nbsp;&amp;nbsp;With a little bit of effort up front, it is&amp;nbsp;fast and easy.&amp;nbsp; If you haven't been introduced into the wonderful world of Report Hyperlinking, please read on...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Create&amp;nbsp;a Template&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Templates are easy to create and will end up saving you many hours of work&amp;nbsp;down the road.&amp;nbsp; The template doesn't have to be anything crazy, but just having one will make report writing easier, if for no other reason than&amp;nbsp;because you won't have to remember to include things that are already built-in.&amp;nbsp; Templates can also make your life easier by automating or simplifying boring things like page numbers, footnotes, and hyperlinks.&lt;br /&gt;&lt;br /&gt;Speaking of hyperlinks, the steps below are a simple outline of how to create&amp;nbsp;sections within your report&amp;nbsp;that will allow for quick and easy hyperlinking.&lt;br /&gt;&amp;nbsp;&amp;nbsp;&lt;img height="75" src="http://1.bp.blogspot.com/-QGKYcGhcr-g/Tne2Zu35wLI/AAAAAAAAAGk/fMiwtKny2lM/s320/Pic2.png" style="filter: alpha(opacity=30); left: 174px; mozopacity: 0.3; opacity: 0.3; position: absolute; top: 1562px; visibility: hidden;" width="96" /&gt;&amp;nbsp;﻿ ﻿﻿﻿﻿&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-7ookwT6hX1g/Tne2OoyA5DI/AAAAAAAAAGg/YODJ3ln8myM/s1600/Pic1.png" imageanchor="1" style="clear: left; cssfloat: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="354" rba="true" src="http://4.bp.blogspot.com/-7ookwT6hX1g/Tne2OoyA5DI/AAAAAAAAAGg/YODJ3ln8myM/s400/Pic1.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;On the References Tab, select "Add Text."&amp;nbsp; Add top level sections using Level 1.&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;﻿﻿﻿ &lt;/div&gt;﻿﻿﻿﻿ &lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-QGKYcGhcr-g/Tne2Zu35wLI/AAAAAAAAAGk/fMiwtKny2lM/s1600/Pic2.png" imageanchor="1" style="clear: left; cssfloat: left; height: 157px; margin-bottom: 1em; margin-left: auto; margin-right: auto; width: 210px;"&gt;&lt;img border="0" height="310" rba="true" src="http://1.bp.blogspot.com/-QGKYcGhcr-g/Tne2Zu35wLI/AAAAAAAAAGk/fMiwtKny2lM/s400/Pic2.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;Add subsections&amp;nbsp;below&amp;nbsp;the main section using Level 2.&amp;nbsp; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;Any content should be added in regular text underneath a Section or Subsection.&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;﻿﻿﻿﻿﻿﻿﻿﻿﻿﻿﻿﻿﻿﻿ ﻿﻿﻿﻿﻿ &lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-FToiB9yd4j8/Tne2n8Iwh1I/AAAAAAAAAGo/wVmb391SruI/s1600/Pic3.png" imageanchor="1" style="cssfloat: left; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="311" rba="true" src="http://4.bp.blogspot.com/-FToiB9yd4j8/Tne2n8Iwh1I/AAAAAAAAAGo/wVmb391SruI/s400/Pic3.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;Add a Table of Contents.&amp;nbsp; Also located on the References tab.&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;﻿﻿﻿﻿﻿&lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;﻿ &lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-tMu4KuNt-z0/Tne2vjB44WI/AAAAAAAAAGs/ou-7WvonSyI/s1600/Pic4.png" imageanchor="1" style="cssfloat: left; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="283" rba="true" src="http://2.bp.blogspot.com/-tMu4KuNt-z0/Tne2vjB44WI/AAAAAAAAAGs/ou-7WvonSyI/s400/Pic4.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;Your TOC includes page numbers and is automatically hyperlinked to each of your sections.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;Note:&amp;nbsp; You will need to update the TOC if changes are made to the report.&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;﻿ &lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-V-RMKbFsiho/Tne3AI-79eI/AAAAAAAAAG0/Omnx-UpsowU/s1600/Pic6.png" imageanchor="1" style="cssfloat: left; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="260" rba="true" src="http://2.bp.blogspot.com/-V-RMKbFsiho/Tne3AI-79eI/AAAAAAAAAG0/Omnx-UpsowU/s400/Pic6.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;Added&amp;nbsp; bonus for hyperlinking elsewhere within your report!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;Select item/text to be hyperlinked and choose "Place in The Document."&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;You will be given your Sections as hyperlink location options.&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;﻿﻿﻿&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Note:&amp;nbsp; Though hyperlinks don't work if you print out the report (obviously!), they will still work if you convert the report to PDF within MS Word.&amp;nbsp; Awesomesauce all around.&amp;nbsp; &lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;﻿&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Confidentiality/Draft Language&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Additional benefits to a report template&amp;nbsp;include consistent formatting and&amp;nbsp;standardized language.&amp;nbsp; Use Confidentiality language whenever appropriate.&amp;nbsp; Also, I recommend having the word "Draft" in a header, footer or watermark on every page until the report is finalized.&amp;nbsp; Those of you familiar with the recent changes to the FRCP may recall that drafts of expert reports have additional protection from discovery, but it behooves you to make your drafts easily recognizable as such.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Conclusion&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;I hope that this information may help someone out there is some small way.&amp;nbsp; Obviously, reports are something that could be discussed for much longer.&amp;nbsp; Again, feel free to share any of your own little tidbits.&amp;nbsp; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-6542464548784614254?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/6542464548784614254/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/09/on-writing.html#comment-form' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/6542464548784614254'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/6542464548784614254'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/09/on-writing.html' title='On Writing'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-QGKYcGhcr-g/Tne2Zu35wLI/AAAAAAAAAGk/fMiwtKny2lM/s72-c/Pic2.png' height='72' width='72'/><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-6439902614255762611</id><published>2011-09-10T00:18:00.000-07:00</published><updated>2011-09-10T00:30:33.695-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Travel'/><title type='text'>すべての魚に感謝 (Thanks for all the fish)</title><content type='html'>One of the many things that I love about my job is the opportunities I have for travel.&amp;nbsp;&amp;nbsp;Most often&amp;nbsp;the travel is just a few cities or states away, but this summer has been especially eventful in that area with trips to the UK, Germany and, most recently, Japan.&amp;nbsp; In Europe, I found it more or less easy to fit in.&amp;nbsp;&amp;nbsp;I&amp;nbsp;have become&amp;nbsp;fairly adept at matching my wardrobe to those around me and as long as I didn't speak too much&amp;nbsp;I would sometimes even be taken as a local.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Naturally, I assumed that it would be more difficult to fit in while in Tokyo, so in the weeks leading up to my departure I read books on the culture and business practices in&amp;nbsp;Japan (offer and recieve business cards with&amp;nbsp;both hands, then take time to study them thoroughly),&amp;nbsp;listened to&amp;nbsp;an audiobook&amp;nbsp;of Japanese phrases (&lt;em&gt;eigo o hanasemasu ka&lt;/em&gt; being an important one), downloaded translation apps, and made sure to memorize the Kanji for the subway stations I would be frequenting (品川 for hotel).&amp;nbsp; And I did this with only a touch of self-importance.&amp;nbsp; Seriously.&amp;nbsp; I was only a &lt;em&gt;bit&lt;/em&gt; smug about how easily I would fit in and how I would impress those around me as a Westerner who &lt;em&gt;got it&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;And then I actually arrived in Japan.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;All those phrases I had so carefully practiced while driving simply abandoned my brain at the first indication that they would actually be needed.&amp;nbsp; And while I managed to get the business card thing right, I was politely ignored by fellow travellers as I&amp;nbsp;talked on my blackberry while I walked to work.&amp;nbsp; Silence being encouraged&amp;nbsp;on public transport&amp;nbsp;(including elevators), or in public in general, was something I hadn't&amp;nbsp;heard about.&amp;nbsp; A Westerner who "got it" I was not.&amp;nbsp; Luckily, most of the people I interacted with seemed, if not pleased,&amp;nbsp;at least&amp;nbsp;conscious of my poor attempts and were helpful.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;But being so wrapped up in trying to prepare for cultural differences caused me to overlook something that should have been apparent:&amp;nbsp; the most frequently used computers in Asia are often&amp;nbsp;different makes and models from those I have run across in the US and Europe.&amp;nbsp; And while there was certainly nothing disasterous, it would probably have been a good idea to have done some research on computers in the region&amp;nbsp;(particularly&amp;nbsp;laptops and how to get to their hard drives in case their specs don't allow them to run from a bootable CD).&amp;nbsp; &lt;br /&gt;&lt;br /&gt;I fly out of Japan in a couple days.&amp;nbsp; It has been an amazing experience and&amp;nbsp;one I won't forget soon.&amp;nbsp;&amp;nbsp;In the meantime, I'll leave you with a picture I&amp;nbsp;snapped with&amp;nbsp;my blackberry&amp;nbsp;this afternoon.&amp;nbsp; It was too surreal a moment not to capture:&lt;br /&gt;﻿ &lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-ds3Io0fzqjw/TmsAkjMTZsI/AAAAAAAAAFk/aDffsGV4bew/s1600/SeaLion.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="400" nba="true" src="http://2.bp.blogspot.com/-ds3Io0fzqjw/TmsAkjMTZsI/AAAAAAAAAFk/aDffsGV4bew/s400/SeaLion.jpg" width="300" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;That's right, my friends.&amp;nbsp; What you are seeing involves a Japanese man, a Sea Lion, and a naked doll doing a high kick.&amp;nbsp; Sometimes, life is almost&amp;nbsp;too beautiful.&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-6439902614255762611?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/6439902614255762611/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/09/thanks-for-all-fish.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/6439902614255762611'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/6439902614255762611'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/09/thanks-for-all-fish.html' title='すべての魚に感謝 (Thanks for all the fish)'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-ds3Io0fzqjw/TmsAkjMTZsI/AAAAAAAAAFk/aDffsGV4bew/s72-c/SeaLion.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-4768567924387258748</id><published>2011-09-06T23:51:00.000-07:00</published><updated>2011-09-07T03:21:31.667-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Musings'/><title type='text'>Catch-10110</title><content type='html'>I have a strange background for someone who has made DFIR my career choice.&amp;nbsp; My major in college was English Literature.&amp;nbsp; I guess if nothing else it explains why I enjoy writing reports, and why I liken the analysis process to uncovering a story.&amp;nbsp; Fellow literature geeks inside the field may well recognize the following passage:&lt;br /&gt;&lt;blockquote&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="color: black;"&gt;There was only one catch and that was Catch-22, which specified that a concern for one's safety in the face of dangers that were real and immediate was the process of a rational mind. Orr was crazy and could be grounded. All he had to do was ask; and as soon as he did, he would no longer be crazy and would have to fly more missions. Orr would be crazy to fly more missions and sane if he didn't, but if he were sane he had to fly them. If he flew them he was crazy and didn't have to; but if he didn't want to he was sane and had to. Yossarian was moved very deeply by the absolute simplicity of this clause of Catch-22 and let out a respectful whistle.&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;﻿﻿ &lt;br /&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: right; margin-left: 1em; text-align: right;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-fB-jX8aGI-U/TmcJvJXbTBI/AAAAAAAAAFg/Xws5mpVFHN0/s1600/SPWOW.jpg" imageanchor="1" style="clear: right; cssfloat: right; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="117" nba="true" src="http://2.bp.blogspot.com/-fB-jX8aGI-U/TmcJvJXbTBI/AAAAAAAAAFg/Xws5mpVFHN0/s200/SPWOW.jpg" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Artistic approximation.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;﻿﻿ &lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;But for those starting out in this field, the situation may seem all too familiar, and the&amp;nbsp;recognition&amp;nbsp;is far more personal than&amp;nbsp;reading a novel.&amp;nbsp; In DFIR, we have Catch-10110:&amp;nbsp; you can't get hired without experience, but you can't get experience until you are hired.&amp;nbsp; For the geeky out there, it's like trying to level without being able to get XP from quests.&amp;nbsp; And we all know the outcome of not getting XP from quests.&amp;nbsp; You have to spend the entire time in the forest killing boars and that takes &lt;em&gt;forever&lt;/em&gt;.&amp;nbsp; &lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;The other side of the coin, and a very valid one at that, is the concern of sending people out in to the field unprepared.&amp;nbsp; If a first responder or investigator gets something wrong, the worst case scenarios are pretty&amp;nbsp;grim - including contaminating evidence that cannot be used in court (evidence that could have convicted or exonerated someone)&amp;nbsp;or, if you need a more personal reason, getting&amp;nbsp;sued.&amp;nbsp; It's pretty heady stuff.&amp;nbsp; With that much at stake, it's no wonder that employers are looking for people who are tried and tested in the field.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;The middle ground for many has become skill-based certifications with a practical portion.&amp;nbsp; The idea being, if you know it and can do it and can prove that, you get a piece of paper saying so.&amp;nbsp; Personally, I love certifications.&amp;nbsp; I may, in fact, have a slight addiction to seeing official-looking pieces of paper with my name on them.&amp;nbsp; However, it seems to me (and please prove me wrong, if there is something you know that I don't!) that most of the certifications out there: a) cover the basics wonderfully, but don't branch out into other areas of expertise OR b) have a layered approach to the other areas, but are vendor specific.&amp;nbsp; Of course, the lack of a certification doesn't mean that the knowledge isn't out there for the learning.&amp;nbsp; The DFIR community has amazing resources from books, blogs (many of which are written by the book authors!), and online networking galore.&amp;nbsp; Not to mention the whole personal research aspect.&amp;nbsp; &lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;But in&amp;nbsp;My Perfect World* a vendor-neutral certifying board would have levels&amp;nbsp;of certifications based on&amp;nbsp;content, experience, difficulty, maybe even exam score.&amp;nbsp; Specialized certifications would also be available once certain prerequisites were achieved.&amp;nbsp; Think of the possibilities!&amp;nbsp; To know offhand that you could tell a&amp;nbsp;client that you are Level 49 DFIR Certified with a First Responder spec would be awesome.&amp;nbsp; You could even assemble a &lt;strike&gt;raid&lt;/strike&gt; team with &lt;strike&gt;tank&lt;/strike&gt;&amp;nbsp;Investigator,&amp;nbsp;&lt;strike&gt;DPS&lt;/strike&gt;&amp;nbsp;Developer,&amp;nbsp;and &lt;strike&gt;healer&lt;/strike&gt;&amp;nbsp;Incident Response&amp;nbsp;specs.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;*I have a lot of perfect worlds.&amp;nbsp; This one just applies to the world of DFIR certifications.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-4768567924387258748?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/4768567924387258748/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/09/catch-10110.html#comment-form' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/4768567924387258748'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/4768567924387258748'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/09/catch-10110.html' title='Catch-10110'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-fB-jX8aGI-U/TmcJvJXbTBI/AAAAAAAAAFg/Xws5mpVFHN0/s72-c/SPWOW.jpg' height='72' width='72'/><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-1525956522557331591</id><published>2011-08-30T15:51:00.000-07:00</published><updated>2011-09-23T11:11:39.369-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FE Side'/><title type='text'>The FE Side 3</title><content type='html'>All new FE Side for your viewing pleasure.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-WQdNHk4RUaM/Tl1pIMiliQI/AAAAAAAAAEQ/1mVfStZnZWc/s1600/Response.png" imageanchor="1" style="cssfloat: left; height: 317px; margin-left: 1em; margin-right: 1em; width: 413px;"&gt;&lt;img border="0" height="315" src="http://3.bp.blogspot.com/-WQdNHk4RUaM/Tl1pIMiliQI/AAAAAAAAAEQ/1mVfStZnZWc/s400/Response.png" width="400" xaa="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Let me know if you want to see more.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-1525956522557331591?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/1525956522557331591/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/08/fe-side-3.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/1525956522557331591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/1525956522557331591'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/08/fe-side-3.html' title='The FE Side 3'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-WQdNHk4RUaM/Tl1pIMiliQI/AAAAAAAAAEQ/1mVfStZnZWc/s72-c/Response.png' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-864740789406001920</id><published>2011-08-26T12:04:00.000-07:00</published><updated>2011-08-30T16:17:28.079-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Iraq'/><title type='text'>Part 3 of 3 - What My Time In Iraq Taught Me</title><content type='html'>&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Much of what I learned from my time in Iraq had nothing to do with forensics.&amp;nbsp; For example, I learned that if everyone else in a room stands up when a General walks in the room, it's best if you do too.&amp;nbsp; Also, comments regarding military uniform should never involve certain words, "adorable" being foremost among them.&amp;nbsp; I learned the importance of humor and friendship.&amp;nbsp; I learned which days it was best to show up early at the DFAC, and why it is sometimes best to wear a hat, even in 115 degree weather.&lt;/div&gt;&lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;I also learned things that I believe make me a better examiner today.&amp;nbsp; One thing that I must stress is that Media Exploitation is a different beast from&amp;nbsp;Digital Forensics.&amp;nbsp; Oh, a lot of the hardware and software are the same, but the end goals are different.&amp;nbsp; Where forensics focuses on evidence to be used in a court of law, exploitation is looking for actionable intelligence.&amp;nbsp; And while the nature of digital data doesn't change, how you approach the analysis may.&amp;nbsp; With that caveat, here are some lessons learned that I came away with.&amp;nbsp; &lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;strong&gt;What I Learned&lt;/strong&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;strong&gt;Triage&lt;/strong&gt; - What a hard lesson this was.&amp;nbsp; Coming from a legal background, I had a terribly hard time coming to grips with the fact that I couldn't leave every byte unturned.&amp;nbsp; Every time I turned over a report, the thought nagged at me - "What if I didn't find everything?"&amp;nbsp; When lives could be at stake, this fear can eat away at you if you let it.&amp;nbsp; Conversely, holding on to data in an effort to find everything could be just as dangerous, if not more so.&amp;nbsp; A report that may have been of vital importance may be too late just hours later.&amp;nbsp; Naturally, the solution was to triage.&amp;nbsp; Certain file types, specific keywords, and known programs had been found to hold the most "low-hanging fruit" (man, I hate that phrase).&amp;nbsp; I learned, eventually, that in a "boots on the ground" capacity it was my job to get out the most data I could in the fastest manner possible.&amp;nbsp; The media would be more fully investigated later -&amp;nbsp;something I held on to in those moments of doubt.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;strong&gt;Context&lt;/strong&gt; - Many times, especially in the early days, I would come across something that I was sure showed nefarious activity.&amp;nbsp; Immediately jumping into action, I would excitedly call over one of the native interpreters and ask them to take a look.&amp;nbsp; More often than not, they would answer my eager questions with a dismissive hand gesture and explain that what I had found was nothing more than a well-known yearly battle reenactment/religious event/local cuisine.&amp;nbsp; Eventually, I learned enough that I could spot these on my own, and thereby spend more time on what could actually be of value.&amp;nbsp; Conversely, there were many times that something would appear to be completely innocent or of little consequence, but when put in context with other pieces of information proved to be very important.&amp;nbsp; These were harder to spot.&amp;nbsp; Staying as up-to-date as possible with local happenings proved to be the most valuable way to identify these.&amp;nbsp; Some I didn't know the importance of&amp;nbsp;until long after the fact.&amp;nbsp; Either way, context helped to reduce time spent on trifles, and allows for identification of those items that are not.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;a href="http://1.bp.blogspot.com/-f053seLsX_g/Tlft7YWUO3I/AAAAAAAAAEM/wZv4Ef3MMv0/s1600/MacGyver.jpg" imageanchor="1" style="clear: right; cssfloat: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="200px" qaa="true" src="http://1.bp.blogspot.com/-f053seLsX_g/Tlft7YWUO3I/AAAAAAAAAEM/wZv4Ef3MMv0/s200/MacGyver.jpg" width="168px" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;strong&gt;Ingenuity&lt;/strong&gt; - "Necessity is the Mother of Invention."&amp;nbsp; Perhaps the most useful skill I learned in Iraq was problem solving.&amp;nbsp; There is always a certain amount of problem solving in DFIR, but my time there helped me take mine to a new level.&amp;nbsp; When presented with media that was involved in an IED explosion, you quickly become aware of the advantages of soldering irons, replacement parts, and some good, old-fashioned MacGyvering.&amp;nbsp; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-864740789406001920?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/864740789406001920/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/08/part-3-of-3-what-my-time-in-iraq-taught.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/864740789406001920'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/864740789406001920'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/08/part-3-of-3-what-my-time-in-iraq-taught.html' title='Part 3 of 3 - What My Time In Iraq Taught Me'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-f053seLsX_g/Tlft7YWUO3I/AAAAAAAAAEM/wZv4Ef3MMv0/s72-c/MacGyver.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-1652413253367266308</id><published>2011-07-20T17:44:00.000-07:00</published><updated>2011-08-30T16:17:44.340-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Iraq'/><title type='text'>Living, or Something Like it, in Iraq (part 2 of a 3 part series)</title><content type='html'>I have gone digging through the archives again to find a few moments I captured in writing after actually arriving in theater.&amp;nbsp; Below are excerpts from different times, so hopefully they make sense.&amp;nbsp; All pictures are mine, and should only be used for the Powers of Good.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;The transport day is over! I have had a shower and a good 12 hours of sleep, so I am feeling amazingly refreshed. I am now in Kuwait in what is fondly called Tent City (the name is so apt no further description is needed). And hovering just over the skyline of tent tops... the golden arches themselves! We may be living in tents out in the desert, but that is no reason we shouldn't get our daily intake of golden fries and McFlurries. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;Every place I have lived for any significant period of time has been able to get a hold on my heart in some way. I love California for the ocean, Utah for the towering mountains. Wales for the intense green and castles so old they are almost a part of the earth itself. The Phillipines for the lushness and exotic feel. If I was to guess now what part of the Middle East would impact me, my first impression would be the sky at sunset.&amp;nbsp; Evening fading into night here is truly breathtaking.&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;&amp;nbsp;﻿ &lt;/span&gt;&lt;br /&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: right; margin-left: 1em; text-align: right;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-Dr9acWYPQzQ/Tid0HWxaHYI/AAAAAAAAAEE/PMr4i-brFwo/s1600/CIMG0106+%25282%2529.JPG" imageanchor="1" style="clear: right; cssfloat: right; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;span style="color: black;"&gt;&lt;img border="0" height="200px" src="http://4.bp.blogspot.com/-Dr9acWYPQzQ/Tid0HWxaHYI/AAAAAAAAAEE/PMr4i-brFwo/s200/CIMG0106+%25282%2529.JPG" t$="true" width="169px" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="color: black;"&gt;Me in Iraq.&amp;nbsp;&amp;nbsp;With all my gear.&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;Never could get my helmet on straight.&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style="color: black;"&gt;﻿ &lt;/span&gt;&lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="color: black;"&gt;Greetings from Baghdad! I have been in Camp Slayer for the last few days, and should stay here for a few more until the trip to Tallil – my final destination. So far Baghdad has been different from what I had imagined. There are lakes and canals – yesterday before work I took a few minutes to sit at a little area by a pond surrounded with palm trees and other exotic vegetation. Little birds were flying in the rushes. It looked, more than anything else, just how I’ve always pictured an oasis. Of course, this isn’t the natural state of the land - Saddam had all of these waterways artificially built. There are whole hills made of the dirt from their excavation. There are also many beautiful buildings that are now a part of the base. Just yesterday I had to get some administrative stuff out of the way at the Perfume Palace (this is where Saddam housed his “Female Companions”), and, for the first time in my life, someone said “Have fun at the palace”… and meant it.&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-RBSdZ2tYLRg/TidyuEzwuBI/AAAAAAAAAD8/ygmQvNAbcfU/s1600/CIMG0001.JPG" imageanchor="1" style="clear: left; cssfloat: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;span style="color: black;"&gt;&lt;img border="0" height="150px" src="http://1.bp.blogspot.com/-RBSdZ2tYLRg/TidyuEzwuBI/AAAAAAAAAD8/ygmQvNAbcfU/s200/CIMG0001.JPG" t$="true" width="200px" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="color: black;"&gt;CHU, sweet CHU. (Really mine)&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style="color: black;"&gt;I packed pretty light, so there isn't much to decorate with. The bedding was something I scavanged from someone else leaving (yes, I washed it). The walls definitely need some sprucing up so I am on the lookout for pictures, posters etc. Also scavanged is my mini fridge (I also use it as my desk), complete with Skoal stickers (you all know how much I loves me some chewing tobacco), and a very dusty chair which, when covered with a blanket, is quite comfortable.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;The Number One survival mechanism that I have come up with thus far is staying busy. Work does a pretty good job of that for a large portion of the day, but the hours just before sleep are always the worst. So now that I am settled in to one place I have had to make an effort to keep myself busy (thereby not sliding into self-pity on a regular basis).&amp;nbsp;&amp;nbsp; That is why, on two nights a week, I make my way to the library for two different book clubs. One is doing the works of C.S. Lewis and the other is more thematic it its choices - it started with Dante's "Inferno", now is on Virgil's "Aeneid" and is moving next to "Purgatorio" (perhaps too apt for our situation, but I guess it does put some perspective on things). I am also considering joining the salsa dancing lessons that take place a couple times a week too. Apparently quite a few people do it. Isn't that what Iraq is all about? Salsa lessons?&lt;/span&gt;&lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="color: black;"&gt;&amp;nbsp;﻿﻿﻿﻿﻿﻿﻿﻿﻿﻿﻿﻿﻿﻿﻿﻿﻿﻿ &lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;&lt;span style="color: black;"&gt;It's been a hectic week here for the team, so our OIC offered us a chance to get out of the office and spend some time relaxing at the pool. The experience was so invigorating I had to take pictures to remember the event. Below is a shot the Lieutenant dunking&amp;nbsp;the Airman.&lt;br /&gt;&amp;nbsp;﻿ &lt;/span&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: 1em; margin-right: 1em; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-mYzRhKtCArY/TidyLsaSS5I/AAAAAAAAAD4/4YSnSRGZC78/s1600/Swimming.JPG" imageanchor="1" style="clear: left; cssfloat: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;span style="color: black;"&gt;&lt;img border="0" height="320px" src="http://4.bp.blogspot.com/-mYzRhKtCArY/TidyLsaSS5I/AAAAAAAAAD4/4YSnSRGZC78/s320/Swimming.JPG" t$="true" width="240px" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="color: black;"&gt;I'm the one behind the camera.&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-1652413253367266308?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/1652413253367266308/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/07/living-or-something-like-it-in-iraq.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/1652413253367266308'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/1652413253367266308'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/07/living-or-something-like-it-in-iraq.html' title='Living, or Something Like it, in Iraq (part 2 of a 3 part series)'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-Dr9acWYPQzQ/Tid0HWxaHYI/AAAAAAAAAEE/PMr4i-brFwo/s72-c/CIMG0106+%25282%2529.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-629511148252456721</id><published>2011-07-20T03:16:00.000-07:00</published><updated>2011-08-30T16:18:47.974-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Iraq'/><title type='text'>Listen:  Girl, Unallocated Has Become Unstuck in Time</title><content type='html'>I am doing research for a future post.&amp;nbsp; In the meantime, it has been suggested I could write about my MEDEX experience in Iraq.&amp;nbsp; And what better way to do this, than to go directly to the source?&amp;nbsp; Below is something I wrote not quite two years ago as I prepared to head out...&lt;br /&gt;&lt;br /&gt;EDIT:&amp;nbsp; A bit of background is probably warranted.&amp;nbsp; The following was written while I was going through CRC in Georgia, a five-day process which includes some training and lots and lots of paperwork.&amp;nbsp; Anyone who has been deployed as a civilian has likely gone through it.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="color: #333333; font-family: &amp;quot;Verdana&amp;quot;, &amp;quot;sans-serif&amp;quot;;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;Today was rough. We had formation at 0530 - that's 3:30 am my time... and this is a girl who likes her full eight hours of sleep at night - where we formed up and marched to the tent for powerpoint presentations that lasted until 1730. Now, I'm a huge fan of the slideshow presentation format. Just ask anyone who I've forced to sit through my own powerpoint creations (only certain really geeky lawyers find them interesting, but that doesn't keep me from subjecting my near and dear to obscure industry jokes). Even as a self-proclaimed aficionado, twelve hours of having slides read (yelled) verbatim dampened even my enthusiasm. So, in an effort to help those who come after me, I have created&lt;br /&gt;&lt;br /&gt;A&amp;nbsp;List to Surviving CRC TSIRT&lt;br /&gt;&lt;br /&gt;1. A good sense of humor. This is number one on the list for a reason. It is the most effective weapon in your arsenal. When everything is looking bleak, you might be surprised at how much morale can be improved with a Christopher Walken impression. And if you can't bring yourself to pull out the good humor...&lt;br /&gt;&lt;br /&gt;2. A good attitude is a nice second. Sure, you could pick out the spelling errors or get angry that there are too many or too few breaks, but that really does no one any good. Remember that you are being paid to learn. And how well you absorb this knowledge may not only save your life one day, but someone else's as well. That's quite a sobering thought.&lt;br /&gt;&lt;br /&gt;3. Bring a book! This cannot be overstated. Just do it.&lt;br /&gt;&lt;br /&gt;4. Get to know the people around you. I am amazed at the caliber of the people in our military and in other positions going over to serve their country. And the life stories alone are fantastic! There are very few other places I can think of where so many people from all over the country (and world) meet in one place. Maybe all military bases are like this, but I thought it was fascinating to hear about everyone's background. &lt;br /&gt;&lt;br /&gt;5. Don't chew tobacco and spit it out in a cup ALL day. The girl sitting a couple seats over from you will get really grossed out. Just saying.&lt;br /&gt;&lt;br /&gt;Tomorrow should go a little easier. Even so, we are forming up at 0600 for H1N1 testing, so I best be off for the night. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="color: #333333; font-family: &amp;quot;Verdana&amp;quot;, &amp;quot;sans-serif&amp;quot;;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;As you probably know, the Army uses last names a lot. Recently, I have been having many conversations that invariably follow this basic script:&lt;br /&gt;&lt;br /&gt;Army: Last name?&lt;br /&gt;Me: Kelley.&lt;br /&gt;Army: &lt;span style="font-family: times new roman;"&gt;(with a long-suffering sigh for silly contractors who don't get how things in the military work)&lt;/span&gt; No. I need your &lt;em&gt;last&lt;/em&gt; name.&lt;br /&gt;Me: That is my last name.&lt;br /&gt;Army: &lt;span style="font-family: times new roman;"&gt;(general backtracking and checking of paperwork to verify... once someone asked if I was sure it was my last name)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;/span&gt;&lt;br /&gt;And so it is I have joined the select ranks of those with two first names (watch out, John Stewart). It only really becomes an issue where last name only is used, but with six months ahead of me surrounded by the military, it's a good thing I've already memorized my lines.&lt;br /&gt;&lt;br /&gt;I was asked earlier if I could describe how civilians go about formations, and that is a very good question, since we really don't. Oh, we give it a go. We form up in rows (in civilian gear - military gear isn't allowed) and generally meander in the direction we are supposed to go. It looks pretty sad compared to the neat, compact rows of the Army personnel ahead of us. For a while we had a Sergeant calling commands to us, but seeing what little raw material he had to work with, I think he figured some groups are beyond help. By the end of the week all he could manage was a vague arm wave and a pained expression.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: black; font-family: Times, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;Stay tuned for more insights about what it was actually like doing DFIR work in Iraq!&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-629511148252456721?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/629511148252456721/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/07/listen-girl-unallocated-has-become.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/629511148252456721'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/629511148252456721'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/07/listen-girl-unallocated-has-become.html' title='Listen:  Girl, Unallocated Has Become Unstuck in Time'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-5186548615702822856</id><published>2011-07-11T15:41:00.000-07:00</published><updated>2011-09-07T23:10:08.244-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Travel'/><title type='text'>Girl, Unallocated in Tapeland</title><content type='html'>&lt;strong&gt;Backup Tapes&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;No, I haven't disappeared.&amp;nbsp; I have merely moved on to another plane of existence.&amp;nbsp; And by that, I mean that I have fallen down the rabbit hole and landed in Tapeland.&amp;nbsp; Also known as London.&amp;nbsp;&amp;nbsp;Of course,&amp;nbsp;those two&amp;nbsp;places are not really mutually inclusive - they just are in this particular instance.&amp;nbsp; I am in London, and surrounded by backup tapes.&amp;nbsp; Outside of work I am surrounded by posh-sounding, fast-walking, neutral-color-wearing Londoners... while in work I am inundated with DLT and LTO tapes.&amp;nbsp; It's a strange, strange world.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Randomness&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;If you haven't listened to the &lt;a href="http://www.forensic4cast.com/2011/06/episode-38-independent-women/"&gt;"Independent Women"&lt;/a&gt; podcast on Forensic 4Cast, head over and listen now.&amp;nbsp; Revel in the amazing amount of "ums" I am able to fit into a single sentence.&amp;nbsp; Added bonus:&amp;nbsp; make a game of it.&amp;nbsp; Put your best ideas for a 4Cast game in comments and win an exclusive FE T-shirt!*&lt;br /&gt;&lt;br /&gt;*This does not actually promise any FE merchandise, exclusive** or otherwise.&amp;nbsp; I just thought it sounded cool.&lt;br /&gt;**There is no such thing as exclusive FE merchandise. &amp;nbsp;Although, maybe I should see what I could do with some puffy paint. &amp;nbsp;Would probably be on par with quality of originals.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-5186548615702822856?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/5186548615702822856/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/07/girl-unallocated-in-tapeland.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/5186548615702822856'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/5186548615702822856'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/07/girl-unallocated-in-tapeland.html' title='Girl, Unallocated in Tapeland'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-7061949487448070744</id><published>2011-06-23T20:00:00.000-07:00</published><updated>2011-08-26T14:31:42.464-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FE Side'/><title type='text'>The FE Side... cont.</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: left;"&gt;Credit for another cartoon goes to ﻿Greg Pendergast, for mentioning&amp;nbsp;FE in his &lt;a href="http://computer-forensics.sans.org/blog/2011/06/24/digital-forensics-case-leads-there-is-no-therne"&gt;blog post&lt;/a&gt;.&amp;nbsp; Thanks for the props!&amp;nbsp; Happy to oblige with yet another badly drawn episode&amp;nbsp;from the life of Frustrated Examiner...&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-OuBEF7BLFqk/TgP18ulv3TI/AAAAAAAAACo/z-Oozqqq3Do/s1600/pr0n.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="315" i$="true" src="http://3.bp.blogspot.com/-OuBEF7BLFqk/TgP18ulv3TI/AAAAAAAAACo/z-Oozqqq3Do/s400/pr0n.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;I should also mention that this particular cartoon was inspired by painful memories dredged up while reading comments on &lt;a href="http://happyasamonkey.wordpress.com/2011/06/23/animalising-the-htcu/"&gt;happyasamonkey's&lt;/a&gt; blog.&amp;nbsp; Does that deserve thanks?&amp;nbsp; I can't decide...﻿&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;EDIT:&amp;nbsp; It seems the FE Side comes in twos... here's another:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-TdVo0mkRcD4/TgTR-fF81YI/AAAAAAAAACs/-HW6D33i4mU/s1600/rorschach.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" i$="true" src="http://2.bp.blogspot.com/-TdVo0mkRcD4/TgTR-fF81YI/AAAAAAAAACs/-HW6D33i4mU/s400/rorschach.png" width="335" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-7061949487448070744?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/7061949487448070744/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/06/fe-side-cont.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/7061949487448070744'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/7061949487448070744'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/06/fe-side-cont.html' title='The FE Side... cont.'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-OuBEF7BLFqk/TgP18ulv3TI/AAAAAAAAACo/z-Oozqqq3Do/s72-c/pr0n.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-1976431515283201239</id><published>2011-06-21T10:42:00.000-07:00</published><updated>2011-09-07T03:23:25.157-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Scripts'/><title type='text'>I'm Going Legit!  Also, Girl-Power</title><content type='html'>&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;I knew when I came to Hollywood I'd make it big.&amp;nbsp; That's right, my gentle readers... I'm going to be on the media.&amp;nbsp; And by media, I mean a &lt;a href="http://www.forensic4cast.com/"&gt;podcast&lt;/a&gt;.&amp;nbsp; (Which is much better than anything video-based.&amp;nbsp; This way I can eat as&amp;nbsp;many pre-show eclairs as necessary to calm my nerves)&amp;nbsp; What's even better is that I am making &lt;em&gt;history&lt;/em&gt;.&amp;nbsp; Years from now, when my daughter is studying the history of DFIR, she will have a test question along the lines of "What were the twitter handles of the participants in the first all-female Forensic 4cast podcast?"&amp;nbsp; The essay question may ask her to detail the repercussions in the industry that originated with this very podcast.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;In honor of this event, I have decided to expand my earlier script pitches to include plots that are based around a group of female forensicators.&amp;nbsp; Enjoy!&lt;br /&gt;&lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; text-align: center;"&gt;&lt;strong&gt;The Sisterhood of the Traveling Pelican Case&lt;/strong&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;a href="http://3.bp.blogspot.com/-hEVxMgER5AU/TgDQ3FVZzsI/AAAAAAAAACc/5DtvB4kZncw/s1600/PelicanBD.png" imageanchor="1" style="clear: right; cssfloat: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="141" i$="true" src="http://3.bp.blogspot.com/-hEVxMgER5AU/TgDQ3FVZzsI/AAAAAAAAACc/5DtvB4kZncw/s200/PelicanBD.png" width="200" /&gt;&lt;/a&gt;Four female forensicators in disparate parts of the world work for a company that has a small forensics budget.&amp;nbsp; Because of this they can only afford one forensic kit contained in a single pelican case.&amp;nbsp; The pelican case is therefore shipped to each investigator as the need arises.&amp;nbsp; To make it easily recognizable, the case is bedazzled within an inch of its life.&amp;nbsp; Remarkably, whatever&amp;nbsp;equipment is&amp;nbsp;needed for the&amp;nbsp;investigation can always be found in the case.&amp;nbsp; The big question at the end... what did the case actually hold?&amp;nbsp; &lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Spoiler alert:&amp;nbsp; there was a thumb drive with open source tools, a bootable CD, write-blockers, and a bag of peanuts.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; text-align: center;"&gt;&lt;strong&gt;The (Digital) Craft&lt;/strong&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;﻿﻿ &lt;br /&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-G4-WQw7ze4k/TgDZYqmX6QI/AAAAAAAAACg/zFjU5uE4u0I/s1600/girlcomputer.JPG" imageanchor="1" style="clear: left; cssfloat: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" i$="true" src="http://2.bp.blogspot.com/-G4-WQw7ze4k/TgDZYqmX6QI/AAAAAAAAACg/zFjU5uE4u0I/s1600/girlcomputer.JPG" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Ha!&amp;nbsp; Wait until the cheerleaders see this!&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;﻿﻿ Young, budding forensicators at an all-girls college get tired of being picked on for being "nerds."&amp;nbsp; Instead of using their investigative powers for good, they join a hacking collective and get up to all kinds of mischief.&amp;nbsp; At first, they are thrilled by their ability to get the attention of those in power.&amp;nbsp; But things quickly begin to change for the worse, as the FBI is on their trail.&amp;nbsp; And since we now know that &lt;a href="http://www.guardian.co.uk/technology/2011/jun/06/us-hackers-fbi-informer"&gt;1 in 4 hackers&lt;/a&gt; is an FBI informant, they instantly begin to suspect that one among them is passing information on to the authorities.&amp;nbsp; After an exciting network war, the girls eventually come to realize the error of their way and take the oath of the &lt;a href="http://girlunallocated.blogspot.com/2011/06/digics-paladin.html"&gt;Digics Paladin&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;EDIT:&lt;/strong&gt;&amp;nbsp; Random Zombie Comment Inspired by Twitter and "Pride and Prejudice and Zombies"&lt;br /&gt;&lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;a href="http://1.bp.blogspot.com/-i8yUy26pFeU/TgDt-yjWHqI/AAAAAAAAACk/QnlhkmXHW0M/s1600/pride_prejudice_zombies_l.jpg" imageanchor="1" style="clear: right; cssfloat: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="200" i$="true" src="http://1.bp.blogspot.com/-i8yUy26pFeU/TgDt-yjWHqI/AAAAAAAAACk/QnlhkmXHW0M/s200/pride_prejudice_zombies_l.jpg" width="131" /&gt;&lt;/a&gt;I didn't like the book, but I &lt;em&gt;absolutely love&lt;/em&gt; the idea.&amp;nbsp; The dichotomy of the original work with the idea of the new is original - and jarring. One of my theories is that zombies are a social commentary; not nearly as nuanced, perhaps, but a metaphor nonetheless. It is suggested in the book that zombies represent the author's idea of marriage: "an endless curse that sucks the life out of you and just won't die." But when you look at the legend of zombies as a whole - all the terrible B movies included - they represent so much more. Zombies are, essentially, the fear of ourselves, the fear of the mob, the fear of what we can become when reason is forgone. So what better way of highlighting this aspect than placing it in a work that values reason and sensibility above almost any other virtue? Indeed, zombies would have seemed almost too at home in works about the French Revolution, but serve as a stark contrast in the world of manners that was Regency England.&lt;/div&gt;Next installment - "A Critical Look at the Undead in Popular Culture: Where the Vampire Myth Went Wrong."&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-1976431515283201239?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/1976431515283201239/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/06/im-going-legit-also-girl-power.html#comment-form' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/1976431515283201239'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/1976431515283201239'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/06/im-going-legit-also-girl-power.html' title='I&apos;m Going Legit!  Also, Girl-Power'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-hEVxMgER5AU/TgDQ3FVZzsI/AAAAAAAAACc/5DtvB4kZncw/s72-c/PelicanBD.png' height='72' width='72'/><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-6423775204656842679</id><published>2011-06-14T11:52:00.000-07:00</published><updated>2011-09-07T03:13:11.805-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TV'/><title type='text'>Sherlock and the Un-Scientific Method</title><content type='html'>Hi.&amp;nbsp; My name is GU, and I'm addicted to British TV Dramas.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-W6eAFGi0Bnw/Tfepkj3VenI/AAAAAAAAACY/u20PeV-cP-c/s1600/sherlock_bbc.jpg" imageanchor="1" style="clear: right; cssfloat: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="135" src="http://2.bp.blogspot.com/-W6eAFGi0Bnw/Tfepkj3VenI/AAAAAAAAACY/u20PeV-cP-c/s200/sherlock_bbc.jpg" t8="true" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Whew.&amp;nbsp; That was tough.&amp;nbsp; The first step is to&amp;nbsp;acknowledge that&amp;nbsp;you have a problem.&amp;nbsp; In the past it was BBC America that fueled my addiction, but Netflix is fast replacing it as my dealer of choice.&amp;nbsp; So, imagine my glee when I log into Netflix and see a recommendation for &lt;em&gt;Sherlock&lt;/em&gt;, a "modern-day refresh of&lt;strong&gt; &lt;/strong&gt;Sherlock Holmes."&amp;nbsp; Yes please!&amp;nbsp; Everything was there:&amp;nbsp; accent-rich voices, scarves and wool coats, and enough significant looks and pauses to keep fan-fic writers in a&amp;nbsp;frenzy for weeks.&amp;nbsp; I should have loved it, but I can't say that I did.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;I have come to grips with the fact that my profession has ruined a large majority of digital-based dramas... but since &lt;em&gt;Sherlock&lt;/em&gt; was more investigative, and less digital, I thought I was safe to sit back and enjoy.&amp;nbsp; Maybe if I had turned off my inner skeptic it would have been more of a pleasant watch.&amp;nbsp;&amp;nbsp;After taking some time to think about what frustrated me so much, I've come to realize that the real mental block was caused&amp;nbsp;by Sherlock's hypotheses&amp;nbsp;always being taken&amp;nbsp;as fact - no testing, no alternate explanations for what was observed put forth.&amp;nbsp; He never got beyond the third step of the Scientific Method.&amp;nbsp; Yes, I've read all Sir Arthur Conan Doyle's works, and didn't have as much of a problem with the concept when set in Victorian England.&amp;nbsp; The only justification that I can offer for my annoyance when set in present day versus the original timeframe is the fact that when the books were written, forensics was an emerging science.&amp;nbsp; Now we&amp;nbsp;should&amp;nbsp;know better.&amp;nbsp; &lt;br /&gt;﻿﻿﻿﻿ &lt;br /&gt;Now, I know there is some debate over whether digital forensics is a true science.&amp;nbsp; And I'm not going to argue one way or the other.&amp;nbsp; What I would argue, though, is that regardless of whether we are a Science or not, following the Scientific Method should be a part of every investigation we do.&amp;nbsp; Most likely, many of us already do this, just not in so many words.&amp;nbsp; Below are the basic steps of the Scientific Method, with brief explanations to how this fits in a DFIR investigation.&lt;br /&gt;﻿ &lt;br /&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-mnnZCdWt6kw/Tfeh-GGrRrI/AAAAAAAAACU/VvGmyVSc2VY/s1600/Scientific+Method.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-mnnZCdWt6kw/Tfeh-GGrRrI/AAAAAAAAACU/VvGmyVSc2VY/s320/Scientific+Method.jpg" t8="true" width="279" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;The Scientific Method... I recommend it.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;﻿ &lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Question - Some questions can be very broad, but the more defined a question, the more defined an answer.&amp;nbsp; Some investigations will have many questions.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;﻿﻿&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Observation - This step could also be known as "gathering information."&amp;nbsp; This is where a lot the time during an investigation is spent.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Hypothesis - The hypothesis should be explanatory and based on information obtained during the Observation stage.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Test - Do Not overlook this step.&amp;nbsp; DFIR is not the place to make assumptions without corroborating evidence.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Results - Take time to analyze.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Contradict Hypothesis - If your results contradict your hypothesis, it's time to come up with a new one that is supported by the facts.&amp;nbsp; You can also take this time to analyze your testing process to make sure that it is testing the right kinds of information.&lt;/div&gt;﻿﻿ &lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Support Hypothesis - If your results support your hypothesis, congratulations!&amp;nbsp; You aren't done, though.&amp;nbsp; Look for data that refutes it as well.&amp;nbsp; You can be sure the other side will be looking for this information as well.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Report - Your report should contain the results, as well as the steps taken to come to your conclusions.&amp;nbsp; As &lt;a href="http://girlunallocated.blogspot.com/2011/05/musings-on-structured-analysis.html#comments"&gt;Harlan Carvey&lt;/a&gt; so perfectly stated, "If you didn't document it, it didn't happen... If you can't explain what you did, to the degree that another analyst can do the same things with the same tools and same data...did it really happen?"&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-6423775204656842679?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/6423775204656842679/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/06/sherlock-and-un-scientific-method.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/6423775204656842679'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/6423775204656842679'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/06/sherlock-and-un-scientific-method.html' title='Sherlock and the Un-Scientific Method'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-W6eAFGi0Bnw/Tfepkj3VenI/AAAAAAAAACY/u20PeV-cP-c/s72-c/sherlock_bbc.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-3851979777152808804</id><published>2011-06-07T20:54:00.000-07:00</published><updated>2011-08-30T16:16:34.110-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FE Side'/><title type='text'>The FE Side</title><content type='html'>Original comic, featuring my very own FE (Frustrated Examiner).&amp;nbsp; &lt;br /&gt;﻿﻿﻿﻿ &lt;br /&gt;﻿﻿ &lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-NEVCEuoS23Y/Te7x_SQTByI/AAAAAAAAACI/z_6gFalljSs/s1600/Watched.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="400px" src="http://4.bp.blogspot.com/-NEVCEuoS23Y/Te7x_SQTByI/AAAAAAAAACI/z_6gFalljSs/s400/Watched.png" t8="true" width="387px" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;﻿﻿ EDIT:&amp;nbsp; I am sure you are all deeply impressed by my skillz of an artist.&amp;nbsp; As it happens, I went to the StrongBad School of Design (he makes drawing FUN).&amp;nbsp; And since I was having so much fun, here's one more.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-HPPLWhEXVSE/Te9kHLg3fEI/AAAAAAAAACM/tqHl_A3TZ9Y/s1600/iOS.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400px" src="http://2.bp.blogspot.com/-HPPLWhEXVSE/Te9kHLg3fEI/AAAAAAAAACM/tqHl_A3TZ9Y/s400/iOS.png" t8="true" width="393px" /&gt;&lt;/a&gt;&lt;/div&gt;﻿﻿﻿﻿POST EDIT:&amp;nbsp; As you may have observed, it appears FE has no arms.&amp;nbsp; This explains a lot.&amp;nbsp; Mostly, it explains the fact that I can't draw.&amp;nbsp; If she is brought back for more editions, I'll see if I can grant her at least one arm.&amp;nbsp; Warning:&amp;nbsp; it may be beefy... or it may just be a wing.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-3851979777152808804?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/3851979777152808804/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/06/fe-side.html#comment-form' title='9 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/3851979777152808804'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/3851979777152808804'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/06/fe-side.html' title='The FE Side'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-NEVCEuoS23Y/Te7x_SQTByI/AAAAAAAAACI/z_6gFalljSs/s72-c/Watched.png' height='72' width='72'/><thr:total>9</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-1515745242291570144</id><published>2011-06-06T08:42:00.000-07:00</published><updated>2011-09-07T03:21:58.756-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Musings'/><title type='text'>Grudging Praise</title><content type='html'>I am about to commit forensic blasphemy.&amp;nbsp; Brace yourselves before reading on.&lt;br /&gt;&lt;br /&gt;There &lt;i&gt;is&lt;/i&gt; something we can learn from CSI.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-grg1-BrGhrA/TezhohvdaKI/AAAAAAAAACE/80HmALRgxF8/s1600/mob_440.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://2.bp.blogspot.com/-grg1-BrGhrA/TezhohvdaKI/AAAAAAAAACE/80HmALRgxF8/s200/mob_440.jpg" t8="true" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;&lt;/div&gt;Put down the pitchforks, and let me explain. &lt;span style="font-size: x-small;"&gt;You there, with the scythe and torch... please put those down too.&lt;/span&gt; The brilliance inherent in CSI and its many incarnations is&amp;nbsp;its ability to enthrall millions of people -&amp;nbsp;most of whom would otherwise have no interest in science or technology.&amp;nbsp; Think about that.&amp;nbsp; Millions of people tune in every week &lt;em&gt;of their own free will&lt;/em&gt; to get a dose of pseudo-forensics.&amp;nbsp; Think:&amp;nbsp; How many jurors actually &lt;em&gt;want&lt;/em&gt; to be there?&amp;nbsp; I will be the first to admit to being visually geared... Like a magpie, shiny always gets my attention (the browncoat in me likes it too).&lt;br /&gt;&lt;br /&gt;One skill that I rarely hear mentioned in the DFIR community is that of good instruction.&amp;nbsp;&amp;nbsp;And that's a shame, in my opinion.&amp;nbsp; It is our job to be technically adept, to know how to find the information on a system and to interpret what it means.&amp;nbsp; But that knowledge doesn't do us much good if we aren't able to communicate our findings - whether it be&amp;nbsp;to&amp;nbsp;our&amp;nbsp;boss, a client, judge or jury.&amp;nbsp; And even if we can communicate that information, getting our&amp;nbsp;audience to understand and remember is yet another hurdle.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;But what does this have to do with CSI (or NCIS or Bones or any other of crime-procedural&amp;nbsp;television lineup)?&amp;nbsp; Their purpose is to entertain, not educate.&amp;nbsp; And that is absolutely true.&amp;nbsp; But I realized recently that the tactics they use to captivate their audience are often the same things that I have found to&amp;nbsp;be the most useful ways to convey concepts to my clients; namely, graphics and analogy.&amp;nbsp; Take another scenario from Frustrated Examiner (still completely made up).&amp;nbsp; FE's Lawyer Client (LC) wants to understand a process that played a part&amp;nbsp;in a recent&amp;nbsp;investigation.&amp;nbsp; FE knows that LC is very intelligent, though not very technical.&amp;nbsp; To help educate LC, FE creates a detailed description of the process, being careful to limit techese.&amp;nbsp; The write-up includes a glossary and&amp;nbsp;multiple references to white-papers (all helpfully included).&amp;nbsp; But at the end of the day, what actually helps LC understand the process is a brief analogy and&amp;nbsp;simple animation in powerpoint.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;LC:&amp;nbsp; Why didn't you just show me that first?&lt;br /&gt;FE:&amp;nbsp; ...&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;a href="http://4.bp.blogspot.com/-RkEJHkIBPlc/Tezcq5AZwrI/AAAAAAAAAB8/-6CBdsyAY5w/s1600/12%252520your%252520argument%252520is%252520invalid.jpg" imageanchor="1" style="clear: right; cssfloat: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="160" src="http://4.bp.blogspot.com/-RkEJHkIBPlc/Tezcq5AZwrI/AAAAAAAAAB8/-6CBdsyAY5w/s200/12%252520your%252520argument%252520is%252520invalid.jpg" t8="true" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;Words of Caution:&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;No amount of amazing graphics can compensate for a lack of substance.&amp;nbsp;&lt;span style="font-size: x-small;"&gt; Read that last line a few times until it sinks in.&amp;nbsp; &lt;/span&gt;&lt;span style="font-size: small;"&gt;Even if the shark had laserbeams on its forehead, it still wouldn't negate any argument (no matter my own prejudice on the subject... that raptor looks pretty convincing to me).&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-1515745242291570144?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/1515745242291570144/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/06/grudging-praise.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/1515745242291570144'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/1515745242291570144'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/06/grudging-praise.html' title='Grudging Praise'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-grg1-BrGhrA/TezhohvdaKI/AAAAAAAAACE/80HmALRgxF8/s72-c/mob_440.jpg' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-4338946777384589863</id><published>2011-06-02T00:12:00.000-07:00</published><updated>2011-09-07T23:12:02.502-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Geekness'/><title type='text'>Digics Paladin</title><content type='html'>&amp;nbsp; &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;strong&gt;A DFIR Paladin Manifesto﻿ &lt;/strong&gt;&lt;/div&gt;﻿ &lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-8NnjbxBMeLk/TeckScQBhCI/AAAAAAAAAB4/sXV7D8T8JtM/s1600/Paladin.png" imageanchor="1" style="clear: left; cssfloat: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="200px" src="http://2.bp.blogspot.com/-8NnjbxBMeLk/TeckScQBhCI/AAAAAAAAAB4/sXV7D8T8JtM/s200/Paladin.png" t8="true" width="151px" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Me, amed with my shield of write-blocking.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;﻿ &lt;br /&gt;﻿&lt;br /&gt;&lt;div style="text-align: left;"&gt;We are paladins.&amp;nbsp; Unlike hackers (warlocks) and criminals (death knights), we follow a strict code of ethics.&amp;nbsp; Whether working for plaintiff or defense, our search is for&amp;nbsp;Truth, or as close to the truth as we can reconstruct with the data available to us.&amp;nbsp; Though opinions or interpretations of data may vary, we conduct examinations&amp;nbsp;without intentional bias.&amp;nbsp; &lt;/div&gt;&lt;br /&gt;Our armor is made of pelican cases and our arsenal is&amp;nbsp;varied and ever-growing.&amp;nbsp; We acknowledge that constant training and&amp;nbsp;staying&amp;nbsp;informed&amp;nbsp;about new&amp;nbsp;tools and techniques&amp;nbsp;is essential to keep us viable in any raid.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Those new to the field may find that no amount of solo questing compares to having a mentor to guide them through the pitfalls and help them level up where needed.&amp;nbsp; Those well-established acknowledge that we were all n00bs&amp;nbsp;once, and&amp;nbsp;share their hard-earned knowledge.&amp;nbsp; In return, they receive appreciation, recognition and maybe even gain new insights themselves.&lt;br /&gt;&lt;br /&gt;Our motto (from the ever-relevant Eric Cartman) is proudly proclaimed to all: &amp;nbsp;"You can just hang around outside in the sun all day, tossing a ball around, or you can sit at your computer and do something that matters!"&lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: left;"&gt;Also, I Am A Geek.&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-4338946777384589863?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/4338946777384589863/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/06/digics-paladin.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/4338946777384589863'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/4338946777384589863'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/06/digics-paladin.html' title='Digics Paladin'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-8NnjbxBMeLk/TeckScQBhCI/AAAAAAAAAB4/sXV7D8T8JtM/s72-c/Paladin.png' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-8335722847612221663</id><published>2011-05-31T12:43:00.000-07:00</published><updated>2011-09-07T03:22:17.143-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Musings'/><title type='text'>Musings on Structured Analysis</title><content type='html'>Starting a new investigation is always exciting for me.&amp;nbsp; What goodies will this image contain?&amp;nbsp; After popping the drive in a write-blocked bay, my fingers itch to start running as many processes as my&amp;nbsp;poor little&amp;nbsp;machine can handle:&amp;nbsp; NetAnalysis; RegRipper; PhotoRec (my new favorite carver); and enough encripts to make any CPU gnash its teeth and long for the day it can retire to&amp;nbsp;the far less challenging world of high-performance computer gaming.&amp;nbsp; Like many other techies, I have had to fight my inherent nature to start mucking about immediately without a care for a structured process.&amp;nbsp; The problem is, once an investigation gets underway, we analysts can get so caught up in the minutiae of the exam that things we have done many times as a matter of course may slip the mind.&amp;nbsp; Take the following (completely made-up) scenario between Frustrated Examiner (FE) and Calm Reason (CR):&lt;br /&gt;&lt;br /&gt;FE:&amp;nbsp; Why is&lt;em&gt; xyz&lt;/em&gt; not in the registry?!&amp;nbsp; &lt;br /&gt;CR:&amp;nbsp; Well, did you check the restore points?&lt;br /&gt;FE:&amp;nbsp; &lt;span style="font-size: x-small;"&gt;*crickets*&lt;/span&gt;&amp;nbsp; Um... one moment.&amp;nbsp; &lt;span style="font-size: x-small;"&gt;*Furious mouse clicks*&lt;/span&gt;&amp;nbsp; Uh... never mind.&lt;br /&gt;&lt;br /&gt;The problem here, as many would point out, could be solved simply by following a list that&amp;nbsp;includes a&amp;nbsp;bullet-point along the lines of "Restore Point Analysis Performed."&amp;nbsp; Check.&amp;nbsp; There is a lot to be said for the checklist method of analysis.&amp;nbsp; It can focus even the most hex-centric mind.&amp;nbsp; Checklists save the day.&amp;nbsp; And there&amp;nbsp;is much rejoicing.&amp;nbsp; So why is it that my own experience with checklists has been checkered with resentment&amp;nbsp;that occasionally leads to&amp;nbsp;drawing unflattering facial hair on its typeface?&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Where comprehensive checklists go wrong&amp;nbsp;is in being, well, comprehensive.&amp;nbsp; With skyrocketing data storage and efforts to mitigate costs in litigation, it is very rare that I am asked to perform a complete examination of any media larger than a thumb drive.&amp;nbsp; Usually, a DF investigation is performed with a specific question in mind that the analysis is supposed to answer.&amp;nbsp; And the steps taken to answer one question, while perfectly valid in that instance, may be completely&amp;nbsp;extraneous in the attempt to&amp;nbsp;uncover answers to&amp;nbsp;a different&amp;nbsp;question.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;While in Las Vegas at the ADUC, I attended a lecture by &lt;a href="http://jessekornblum.livejournal.com/"&gt;Jesse Kornblum&lt;/a&gt; with the intimidating title &lt;a href="http://www.kyrus-tech.com/wp-content/uploads/2011/05/Statistical-Validation-and-Data-Analytics-in-eDiscovery.pdf"&gt;"Statistical Validation and Data Analytics in eDiscovery."&lt;/a&gt;&amp;nbsp; It is a testament to his devotion to his work that a presentation with that title was one of the most fun and entertaining lectures of the conference.&amp;nbsp; And to prove that I did indeed have some cognitive functions on my third day in Vegas, I have decided to create my very own decision tree for targeted checklists.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-6RYtcszbmZE/TeU8GfpkC9I/AAAAAAAAAB0/62Twp4lBir0/s1600/Decision+tree.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="302" src="http://1.bp.blogspot.com/-6RYtcszbmZE/TeU8GfpkC9I/AAAAAAAAAB0/62Twp4lBir0/s400/Decision+tree.jpg" t8="true" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;﻿A flow chart, while pretty and impressive to upper management, is great but it still does not solve all investigative ills.&amp;nbsp; Checklists are great tools - but like any other tool in DFIR,&amp;nbsp;they&amp;nbsp;are &lt;em&gt;just a tool&lt;/em&gt;.&amp;nbsp; Sticking rigidly to a&amp;nbsp;list of procedures takes the investigator out of the investigation.&amp;nbsp; While I wouldn't argue that analysts should dump the binary content of a drive out of the box and just pick up random bits without&amp;nbsp;any sort of structure, neither would I recommend blinders.&amp;nbsp; Follow the white rabbit!&amp;nbsp; Just remember to take notes along the way.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-8335722847612221663?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/8335722847612221663/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/05/musings-on-structured-analysis.html#comment-form' title='19 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/8335722847612221663'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/8335722847612221663'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/05/musings-on-structured-analysis.html' title='Musings on Structured Analysis'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-6RYtcszbmZE/TeU8GfpkC9I/AAAAAAAAAB0/62Twp4lBir0/s72-c/Decision+tree.jpg' height='72' width='72'/><thr:total>19</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-353317299196186213</id><published>2011-05-27T13:56:00.000-07:00</published><updated>2011-08-30T16:19:05.891-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Iraq'/><title type='text'>Reminiscing About Iraq</title><content type='html'>&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;In&amp;nbsp;one week it will have been a year since I left Iraq.&amp;nbsp; And I have realized, with growing horror over the past twelve months, that I am becoming one of &lt;em&gt;Those People&lt;/em&gt;.&amp;nbsp; The ones with never-ending stories about the good old days in a combat zone.&amp;nbsp; But given that it is the anniversary of my departure (though not of my return home - it took another week or so what with waiting for a flight in Kuwait and debriefing at Fort Benning), I am going to indulge my reflective side just this once.&amp;nbsp; Of course, I have no desire to lose my security clearance (even though I don't use it for my current job, it makes me seem so much more interesting and exciting), so I won't be reminiscing about methods used or data found, etc.&amp;nbsp; Below are simply some random observations, in no particular order.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; text-align: center;"&gt;&lt;strong&gt;The Good Ol' Days In Iraq&lt;/strong&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;strong&gt;Terminology&lt;/strong&gt; - The military is very fond of acronyms, as I am sure many are aware.&amp;nbsp; It always amazes me how long and/or inventive some acronyms&amp;nbsp;can be.&amp;nbsp; Some even take longer to say than the&amp;nbsp;word or phrase&amp;nbsp;of which they&amp;nbsp;are a shortened version.&amp;nbsp; Ironically enough, Hollywood has started using similar strategies for their naming of celebrity couples.&amp;nbsp; For example, the particular brand of digital forensics I did&amp;nbsp;in conjunction with&amp;nbsp;the military was called Media Exploitation, which was shorted to MEDEX.&amp;nbsp; Compare this to "Bennifer" and draw your own conclusions.&amp;nbsp; As a public service to the DFIR community as a whole, here&amp;nbsp;is my suggestion for our very own celebrity supercouple name:&amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;a href="http://2.bp.blogspot.com/-fix3zuG_oO8/TeAEuri9BSI/AAAAAAAAABs/OJQVMcuytnQ/s1600/initech_tag_0809081.jpg" imageanchor="1" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-fix3zuG_oO8/TeAEuri9BSI/AAAAAAAAABs/OJQVMcuytnQ/s1600/initech_tag_0809081.jpg" t8="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Digital Forensics&amp;nbsp;= "Digics"&amp;nbsp; &lt;span style="font-size: x-small;"&gt;Tell your friends.&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Incident Reponse = This is a hard one to come up with.&amp;nbsp; Most ideas&amp;nbsp;sound like a company from &lt;em&gt;Office Space&lt;/em&gt;.&amp;nbsp; I think IR is just going to have to stick around.&amp;nbsp; &lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;strong&gt;Weather&lt;/strong&gt; - I had heard about how dusty and sandy it could be.&amp;nbsp; And for a while I felt like I had seen all the dust I could possibly see.&amp;nbsp; Then came Easter 2010.&amp;nbsp; The team was heading to the DFAC for our special Easter meal when we saw an honest-to-Gates wall of sand approaching.&amp;nbsp; We stopped and stared.&amp;nbsp; It was amazing.&amp;nbsp; None of us had the foresight to capture the moment, but luckily someone else on base did and posted it to YouTube for posterity.&amp;nbsp; &lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: center;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://1.gvt0.com/vi/8kov2Dxpnnk/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/8kov2Dxpnnk&amp;fs=1&amp;source=uds" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266" src="http://www.youtube.com/v/8kov2Dxpnnk&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;As you can well imagine, we were finding sand in places you wouldn't imagine for days afterwards.&amp;nbsp;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;strong&gt;Work&lt;/strong&gt; - Speaking of sand everywhere... computers were no exception.&amp;nbsp; Epic amounts of dust and/or sand could be&amp;nbsp;found in every piece of electronic equipment used or analyzed at any given time... &lt;em&gt;even if they had just been&amp;nbsp;cleaned&lt;/em&gt;.&amp;nbsp; No amount of crusty keyboards and cat hair-plugged chassis witnessed since can compare.&amp;nbsp; I also learned the immense importance of gloves as a matter of personal hygiene in addition to preservation of evidence.&amp;nbsp; Timeframes for report turnaround were tight.&amp;nbsp; Knowing there is a possibility that you have information that may save lives does tend to&amp;nbsp;put those&amp;nbsp;12 hour days&amp;nbsp;in perspective.&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Time out for a rare moment devoid of&amp;nbsp;sarcasm:&amp;nbsp; despite the weather that felt like a hair blow dryer blasting in your face all day, the long hours and distance from family, I wouldn't trade the experience for anything.&amp;nbsp; I have never worked with a finer group of people.&amp;nbsp; They&amp;nbsp;welcomed this civilian geek with open arms and became my second family.&amp;nbsp; Thank you, for what you did for me personally, but more importantly for what you did and continue to do&amp;nbsp;for our country.&amp;nbsp; Happy Memorial Day, troops!&amp;nbsp; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-353317299196186213?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/353317299196186213/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/05/reminiscing-about-iraq.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/353317299196186213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/353317299196186213'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/05/reminiscing-about-iraq.html' title='Reminiscing About Iraq'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-fix3zuG_oO8/TeAEuri9BSI/AAAAAAAAABs/OJQVMcuytnQ/s72-c/initech_tag_0809081.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-3602658658049051145</id><published>2011-05-24T09:41:00.000-07:00</published><updated>2011-10-27T20:33:12.411-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Musings'/><title type='text'>Anti-Forensics Strategies</title><content type='html'>I always get a thrill when I examine a system where a user tried to cover their tracks.&amp;nbsp; To paraphrase &lt;a href="http://www.craigball.com/"&gt;Craig Ball's&lt;/a&gt; point on the matter, "sometimes the gaping hole where&amp;nbsp;data should be is the most incriminating evidence."&amp;nbsp; That said, a lot of the tools out there that your average computer user uses to "clean house" still leave an awful lot of artifacts behind (I'm looking at you, CCleaner).&amp;nbsp; Yes, there are anti-forensic techniques that can certainly make push-button examinations more difficult.&amp;nbsp; But at the end of the day, it's not a program that does an investigation - it's the investigator.&amp;nbsp; And as &lt;a href="http://windowsir.blogspot.com/"&gt;Harlan Carvey&lt;/a&gt;&amp;nbsp;has observed, "As far as analysis is concerned, the 'best' tool is that grey, goopy gunk between your ears."&amp;nbsp; &lt;br /&gt;&lt;br /&gt;So what does this mean?&amp;nbsp; Well, I'm switching sides for a moment to give you bad guys out there some&amp;nbsp;ideas to mess with any examiner that may end up digging through your cess-pit of a computer.&amp;nbsp; Yeah, they'll probably still find the dirt that's there, but the least you can do is make it interesting for the poor guy/gal who has to turn over your digital midden heap in the course of their work.&amp;nbsp; So, without further ado:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;strong&gt;Investigation Slowing Strategies&lt;/strong&gt;&lt;/div&gt;&lt;br /&gt;Funny Videos - This is probably the very best way to slow down any investigation.&amp;nbsp; Have lots and lots of funny videos stored throughout your drive (Tip:&amp;nbsp; this is especially useful if your nefarious misdeeds are video based).&amp;nbsp; Now, don't get lazy and just&amp;nbsp;download the most popular funny vids - we've seen them all.&amp;nbsp; Get creative.&amp;nbsp; Really look for those out-there, maybe a bit geeky gems that will keep any investigator enthralled, despite the clips'&amp;nbsp;complete lack of relevance to the case.&amp;nbsp; Extra marks if you create your own.&lt;br /&gt;&lt;br /&gt;File and Folder&amp;nbsp;Names - Investigators are well aware that there usually isn't a folder entitled "All My&amp;nbsp;Illegal/Unethical Stuff" on a drive that will hand them the investigation on a platter.&amp;nbsp;&amp;nbsp;But why not throw out a red herring?&amp;nbsp; Create folders with sinister names that contain pictures of bunny rabbits and clips of Dane Cook comedy routines.&amp;nbsp; Something along the line of Tobias'&amp;nbsp;business cards (from &lt;em&gt;Arrested Development&lt;/em&gt;)&amp;nbsp;is a perfect example.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://2.gvt0.com/vi/UrIpPqcln6Y/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/UrIpPqcln6Y&amp;fs=1&amp;source=uds" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266" src="http://www.youtube.com/v/UrIpPqcln6Y&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;br /&gt;Internet Search Terms - One of my favorite things in any investigation is to see the progression of search terms people use on their computers.&amp;nbsp; The sequence leading up to generating that perfect term to&amp;nbsp;get the search engine to spit out&amp;nbsp;whatever website they so desperately want to find can be an incredible insight into how the human mind works.&amp;nbsp; Bearing that in mind, try to create as many assinine and unintelligible search terms and then run them.&amp;nbsp; Hey, maybe you'll end up being surprised by what you find.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;EDIT:&lt;/strong&gt;&amp;nbsp; After seeing some well thought-out responses to this post, I have to come clean.&amp;nbsp; The intent was pretty much a tongue-in-cheek reference to my own foibles doing exams (i.e. having way too much fun with some of the funny videos... &lt;span style="font-size: x-small;"&gt;btw, have you seen this &lt;a href="http://www.youtube.com/watch?v=4Z2Z23SAFVA"&gt;one&lt;/a&gt;?&amp;nbsp; Brilliant!&lt;/span&gt;...), and a&amp;nbsp;bit of forensic humor inspired by&amp;nbsp;comments found in &lt;a href="http://happyasamonkey.wordpress.com/2011/05/04/bin-laden-hard-drive-prelim-forensic-report/"&gt;happyasamonkeys&lt;/a&gt; blog.&amp;nbsp; This is my &lt;em&gt;Screwtape Letters&lt;/em&gt;.&amp;nbsp; I actually feel a bit humbled by the responses.&amp;nbsp; Maybe I need to go legit and leave all this satire behind!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-3602658658049051145?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/3602658658049051145/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/05/anti-forensics-strategies.html#comment-form' title='10 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/3602658658049051145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/3602658658049051145'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/05/anti-forensics-strategies.html' title='Anti-Forensics Strategies'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><thr:total>10</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-5074227079646556860</id><published>2011-05-23T10:46:00.000-07:00</published><updated>2011-09-07T23:10:31.379-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Travel'/><title type='text'>Forensics and Load Files in Las Vegas</title><content type='html'>&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-doX_LbE2O3g/TdqWe653BqI/AAAAAAAAAA8/inPJWJQSb6o/s1600/epic-win-photos-hacked-irl-we-cant-stop-here.jpg" imageanchor="1" style="clear: right; cssfloat: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="320px" j8="true" src="http://4.bp.blogspot.com/-doX_LbE2O3g/TdqWe653BqI/AAAAAAAAAA8/inPJWJQSb6o/s320/epic-win-photos-hacked-irl-we-cant-stop-here.jpg" width="264px" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;I got to go to my first conference last week.&amp;nbsp; While I lusted after a chance to hit the CEIC in Florida, alas, I&amp;nbsp;had to settle for the closer Sin City.&amp;nbsp; Much knowledge was imparted and epiphanies abounded - not least of which was the realization that while I can rock sequins like none other, feather headdresses aren't really the best look for me.&amp;nbsp; I guess I don't have the cheekbones to pull off that particular look (curse you, Vegas Showgirls, and your impossible standards).&lt;/div&gt;&lt;br /&gt;The conference was an interesting mix of digital forensic folks, corporate eDisco&amp;nbsp;types and law firm paralegals.&amp;nbsp; And because I am now entrenched in the most Materialistic and Judgemental place on earth, I just had to go all Joan Rivers on the proceedings.&amp;nbsp; Mic in hand (perhaps it was just the rolled up agenda booklet... after a while everything in Vegas seems to go hazy) I hit the lecture halls prepared to release strings of vitriolic comments and&amp;nbsp; thinly disguised personal jibes.&amp;nbsp; &lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-tiGR3A0ez20/TdqanccW7eI/AAAAAAAAABA/OEHHQYMBPGY/s1600/KMD09MadameTussaudsLA_158.jpg" imageanchor="1" style="cssfloat: right; height: 140px; margin-left: auto; margin-right: auto; width: 158px;"&gt;&lt;img border="0" height="200px" j8="true" src="http://2.bp.blogspot.com/-tiGR3A0ez20/TdqanccW7eI/AAAAAAAAABA/OEHHQYMBPGY/s200/KMD09MadameTussaudsLA_158.jpg" width="198px" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Definitely not me, BTW&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;Maybe it was the Law Firm element, but I had markedly few easy targets.&amp;nbsp; Oh, there were a few black-socks-with-sandals scandals&amp;nbsp;to be seen, but they were the exception.&amp;nbsp; The women there managed to easily straddle the line between professional and stylish (Honorable Mention for a girl who wore a fetching lavender blouse with light&amp;nbsp;cascading ruffles, a plum pullover and &lt;em&gt;the most&lt;/em&gt; adorable shoes - no, it wasn't me, but how I wish it had been).&amp;nbsp;&amp;nbsp;They guys didn't fare quite as well on the overall fashion spectrum, but nothing was atrocious enough for me to get that reality show pilot&amp;nbsp;I was scheming.&amp;nbsp; &lt;span style="font-size: x-small;"&gt;Forensic Fashion Makeovers, if you must know.&lt;/span&gt;&amp;nbsp; (But just FYI - I'm watching you, men.&amp;nbsp; No easy rides from here on out.)&lt;br /&gt;&lt;br /&gt;To be somewhat serious, I actually had a great time and came away feeling like the days (no... probably more like the evenings when the real fun began) were well spent.&amp;nbsp; Not really because of the lectures and labs (although there were a couple fantastic presenters), but because of the profound joy of mingling with my own kind.&amp;nbsp; I even got to meet a&amp;nbsp;couple of those shadowy personas I follow on 'tinterwebs.&amp;nbsp; End result:&amp;nbsp; I'm hooked.&amp;nbsp; Must get to more conferences in future.&amp;nbsp; Withdrawals from being back in the corporate world are already taking effect.&amp;nbsp; I miss Candy Mountain!&lt;br /&gt;﻿﻿ &lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-UqUkovkRHCA/TdrX6P7d1cI/AAAAAAAAABE/yMD6YaYocuM/s1600/memes-chaaaaarlieeeee.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="195px" j8="true" src="http://3.bp.blogspot.com/-UqUkovkRHCA/TdrX6P7d1cI/AAAAAAAAABE/yMD6YaYocuM/s320/memes-chaaaaarlieeeee.jpg" width="320px" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Artistic Interpretation of my Physical State Following the Conference&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-5074227079646556860?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/5074227079646556860/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/05/forensics-and-load-files-in-las-vegas.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/5074227079646556860'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/5074227079646556860'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/05/forensics-and-load-files-in-las-vegas.html' title='Forensics and Load Files in Las Vegas'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-doX_LbE2O3g/TdqWe653BqI/AAAAAAAAAA8/inPJWJQSb6o/s72-c/epic-win-photos-hacked-irl-we-cant-stop-here.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-1203364539336364675</id><published>2011-05-17T13:32:00.000-07:00</published><updated>2011-09-07T03:23:12.175-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Scripts'/><title type='text'>Script Pitches</title><content type='html'>&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;Google, you are dead to me. Perhaps I shouldn't have been surprised by the blogger site crash, but it still feels like a betrayal. We are still so early in our relationship and already you go offline and even lose my most recent (and for anyone who didn't read it, most brilliant) post. You twisted the knife further by removing some reader comments.&amp;nbsp; Maybe this is a sign that our union just wasn't meant to be. Luckily for you, I'm a sucker for second chances. Bring flowers and some bubbly by and we may just be able to reconcile. Besides, everyone knows that making up is great for chemistry. I'll be waiting.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;A Tribute To The Greatest Blog In The World&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;What follows is not the greatest blog in the world - this is just a tribute. I cannot fully reconstruct the post that seems to be lost forever, but I will do my best to remember what phrases and witticisms I can.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;There are other great posts out about TV and movie plot ideas that incorporate the world of digital forensics.&amp;nbsp; Some of my favorites include &lt;/span&gt;&lt;a href="http://happyasamonkey.wordpress.com/2010/05/10/the-acquisition-will-not-be-televised/"&gt;&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;happyasamonkey&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt; (I admit that I outright snorted at &lt;em&gt;How Clean is Your Computer&lt;/em&gt;) and &lt;/span&gt;&lt;a href="http://faintingchicken.wordpress.com/2011/02/27/if-computer-forensics-was-like-top-gun/"&gt;&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;faintingchicken&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;.&amp;nbsp; So, in an effort to throw out my two cents way too late to be cool, here are my ideas for Hollywood.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;a href="http://4.bp.blogspot.com/-fPcahPlk8dc/TdLYtZfocaI/AAAAAAAAAAw/UUa6d00j1ek/s1600/zombie.jpg" imageanchor="1" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;&lt;img border="0" height="200" j8="true" src="http://4.bp.blogspot.com/-fPcahPlk8dc/TdLYtZfocaI/AAAAAAAAAAw/UUa6d00j1ek/s200/zombie.jpg" width="182" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;Pitch 1 - Forensic examiners are actually a subspecies of undead.&amp;nbsp; This premise works nicely to explain why we tend to work in dimly-lit lairs and have an aversion to the "normal" populace.&amp;nbsp; I haven't decided yet if we would dissolve, explode or sparkle in the sunlight, but I expect the latter would go far enhancing the perceived&amp;nbsp;"sexiness" of the industry.&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;a href="http://2.bp.blogspot.com/-73CQoX77GMs/TdLZOBZEqfI/AAAAAAAAAA0/lS6xp1tRvFs/s1600/Rocky.jpg" imageanchor="1" style="clear: right; cssfloat: right; float: right; height: 281px; margin-bottom: 1em; margin-left: 1em; width: 223px;"&gt;&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;&lt;img border="0" height="135" j8="true" src="http://2.bp.blogspot.com/-73CQoX77GMs/TdLZOBZEqfI/AAAAAAAAAA0/lS6xp1tRvFs/s200/Rocky.jpg" width="200" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;Pitch 2 - Two innocent young adults are stranded in the woods without cell phone reception and come across an ill-maintained mansion&amp;nbsp; populated with a cast of outlandish characters (a la Rocky Horror Picture Show).&amp;nbsp; In a surprising twist at the end, it is revealed that&amp;nbsp;grounds is populated entirely with former forensic analysts that were so warped by what they viewed on computers that they were deemed unfit to remain in mainstream society and were banished there by a shadowy branch of The Government.&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;a href="http://1.bp.blogspot.com/-MbSkJ2lybUk/TdLaY_ddaKI/AAAAAAAAAA4/fdqx1A1vPgI/s1600/Follies.jpg" imageanchor="1" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;&lt;img border="0" height="200" j8="true" src="http://1.bp.blogspot.com/-MbSkJ2lybUk/TdLaY_ddaKI/AAAAAAAAAA4/fdqx1A1vPgI/s200/Follies.jpg" width="133" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Georgia, &amp;quot;Times New Roman&amp;quot;, serif;"&gt;Pitch 3 - An All-Singing, All-Dancing Forensics Extravaganza!&amp;nbsp; While this may initially be relegated to Broadway, I anticipate a movie would soon be in the works (musicals are hot right now, see?).&amp;nbsp; To add an air of authenticity, the chorus should&amp;nbsp;be cast entirely of real computer forensic analysts.&amp;nbsp; Start working on you high kicks, boys.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-1203364539336364675?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/1203364539336364675/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/05/script-pitches.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/1203364539336364675'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/1203364539336364675'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/05/script-pitches.html' title='Script Pitches'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-fPcahPlk8dc/TdLYtZfocaI/AAAAAAAAAAw/UUa6d00j1ek/s72-c/zombie.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-5940597981415029603</id><published>2011-05-05T11:23:00.000-07:00</published><updated>2011-09-07T23:11:45.431-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Geekness'/><title type='text'>Geek and Gamer Gurlz</title><content type='html'>Yet another departure from my original intent... but had to share this musical shout-out to all my fellow geeky girls out there. &lt;br /&gt;&lt;br /&gt;&lt;iframe allowfullscreen="" frameborder="0" height="349" src="http://www.youtube.com/embed/_eJmYKN_1QE?rel=0" width="560"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;***Warning: Not kid friendly. Maybe not work friendly. You decide.***&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-5940597981415029603?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/5940597981415029603/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/05/geek-and-gamer-gurlz.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/5940597981415029603'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/5940597981415029603'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/05/geek-and-gamer-gurlz.html' title='Geek and Gamer Gurlz'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/_eJmYKN_1QE/default.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-756577644501481615</id><published>2011-05-02T15:29:00.000-07:00</published><updated>2011-09-07T03:10:58.295-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TV'/><title type='text'>Circumventing Safesearch with Reno 911</title><content type='html'>The clip below doesn't really have anything to do with digital forensics, but I chuckled a bit, so I'm including it anyway.  I did mention in a previous post that it is common practice to remove hard drives when performing acquisitions - a process that will usually require the examiner to open the chassis in order to access the drive.  Opening the chassis is the pivotal part of the scene below:&lt;br /&gt;&lt;br /&gt;&lt;table style='font:11px arial; color:#333; background-color:#f5f5f5' cellpadding='0' cellspacing='0' width='512' height='340'&gt;&lt;tbody&gt;&lt;tr style='background-color:#e5e5e5' valign='middle'&gt;&lt;td style='padding:2px 1px 0px 5px;'&gt;&lt;a target='_blank' style='color:#333; text-decoration:none; font-weight:bold;' href='http://www.comedycentral.com/shows/reno_911/index.jhtml'&gt;RENO 911!&lt;/a&gt;&lt;/td&gt;&lt;td style='padding:2px 5px 0px 5px; text-align:right; font-weight:bold;'&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style='height:14px;' valign='middle'&gt;&lt;td style='padding:2px 1px 0px 5px;' colspan='2'&gt;&lt;a target='_blank' style='color:#333; text-decoration:none; font-weight:bold;' href='http://www.comedycentral.com/videos/index.jhtml?videoId=230036&amp;title=safe-search'&gt;Safe Search&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style='height:14px; background-color:#353535' valign='middle'&gt;&lt;td colspan='2' style='padding:2px 5px 0px 5px; width:512px; overflow:hidden; text-align:right'&gt;&lt;a target='_blank' style='color:#96deff; text-decoration:none; font-weight:bold;' href='http://www.comedycentral.com/'&gt;www.comedycentral.com&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr valign='middle'&gt;&lt;td style='padding:0px;' colspan='2'&gt;&lt;embed style='display:block' src='http://media.mtvnservices.com/mgid:cms:item:comedycentral.com:230036' width='512' height='288' type='application/x-shockwave-flash' wmode='window' allowFullscreen='true' flashvars='autoPlay=false' allowscriptaccess='always' allownetworking='all' bgcolor='#000000'&gt;&lt;/embed&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style='height:18px;' valign='middle'&gt;&lt;td style='padding:0px;' colspan='2'&gt;&lt;table style='margin:0px; text-align:center' cellpadding='0' cellspacing='0' width='100%' height='100%'&gt;&lt;tr valign='middle'&gt;&lt;td style='padding:3px; width:33%;'&gt;&lt;a target='_blank' style='font:10px arial; color:#333; text-decoration:none;' href='http://www.comedycentral.com/videos/index.jhtml?videoId=227641&amp;title=dangles-sex-tape'&gt;Lt. Jim Dangle's Sex Tape&lt;/a&gt;&lt;/td&gt;&lt;td style='padding:3px; width:33%;'&gt;&lt;a target='_blank' style='font:10px arial; color:#333; text-decoration:none;' href='http://www.comedycentral.com/videos/index.jhtml?videoId=168906&amp;title=terry-time'&gt;Terry Time&lt;/a&gt;&lt;/td&gt;&lt;td style='padding:3px; width:33%;'&gt;&lt;a target='_blank' style='font:10px arial; color:#333; text-decoration:none;' href='http://ccinsider.comedycentral.com/2010/07/06/thomas-lennon-and-ben-garant-review-reno-911-porn-parody/'&gt;Thomas Lennon and Ben Garant Review RENO 911! Porn Parody&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;b&gt;What They Got Right&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Nothing.  Seriously.  But then, I think that was the point.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;What They Got Wrong&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Where to start?  &lt;a href="http://en.wikipedia.org/wiki/Safesearch"&gt;Safe search&lt;/a&gt; is not hardware or even firmware.  Opening the computer case and playing with the wires (or any other physical hardware) would have had no effect on the filtering functionality.  As far as I can tell from watching the video, the only thing that was done within the computer chassis was exchanging molex power connectors.  And unless one of the molex connectors was bad, the exchange should have no effect. Even then, the only effect would be a loss of power to whichever drive was given the bad power connector. &lt;br /&gt;&lt;br /&gt;Safety is always a concern when working with electronic equipment.  Yes, there is always the chance of electrocution, etc. if proper protocols are not followed.  That being said, it is much more common for computer components to "fry" from static electricity if the person is not properly grounded - disturbing if you ruin your motherboard or RAM, but not a process that involves explosions and smoke.  The most unbelievable part of this skit is the fact that multiple computers &lt;i&gt;that weren't even messed with&lt;/i&gt; are the ones that experienced the explosion.  In no situation that I could begin to imagine would switching molex power connectors cause this kind of action.&lt;br /&gt;&lt;br /&gt;I guess if nothing else this can act as a cautionary tale for playing with components you are not familiar with.  Always play safe!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-756577644501481615?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/756577644501481615/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/05/circumventing-safesearch-with-reno-911.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/756577644501481615'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/756577644501481615'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/05/circumventing-safesearch-with-reno-911.html' title='Circumventing Safesearch with Reno 911'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-9217816116619321951</id><published>2011-04-27T09:02:00.000-07:00</published><updated>2011-09-07T23:11:28.471-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Geekness'/><title type='text'>Hacking Makes for Good Scripts</title><content type='html'>Okay, I know this is a bit of a departure (already?!) from the intent of this blog.&amp;nbsp; &lt;span style="font-size: x-small;"&gt;I really am working on a post about a &lt;em&gt;Castle&lt;/em&gt; episode, so stay tuned.&amp;nbsp; &lt;/span&gt;&lt;span style="font-size: small;"&gt;However, with everything going on in the news about &lt;a href="http://www.cnn.com/2011/TECH/gaming.gadgets/04/26/playstation.network.hack/index.html?hpt=T2"&gt;Sony being hacked&lt;/a&gt;, I wanted a chance to share a video that is NOT Hollywood scripted, but maybe should be.&amp;nbsp; &lt;/span&gt;&lt;span style="font-size: small;"&gt;It's a little long (about 10 minutes), but worth every second.&amp;nbsp; Spoiler alert:&amp;nbsp; someone gets hacked &lt;em&gt;during&lt;/em&gt; the interview.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://3.gvt0.com/vi/OZJwSjor4hM/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/OZJwSjor4hM&amp;fs=1&amp;source=uds" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266" src="http://www.youtube.com/v/OZJwSjor4hM&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;span style="font-size: x-small;"&gt;Disclaimer:&amp;nbsp; I do not agree with either side, though there is definitely more crazy on one end than on the other.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I do have some small&amp;nbsp;education with intrusion analysis and incident response, and I am starting to think this is an area I should seriously consider investing more time in as an area of expertise.&lt;br /&gt;&lt;br /&gt;Also, I'm very proud of the pun in the title. Please take a moment to appreciate.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-9217816116619321951?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/9217816116619321951/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/04/hacking-makes-for-good-scripts.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/9217816116619321951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/9217816116619321951'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/04/hacking-makes-for-good-scripts.html' title='Hacking Makes for Good Scripts'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-7315048001788851898</id><published>2011-04-21T10:27:00.000-07:00</published><updated>2011-09-07T03:10:33.114-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TV'/><title type='text'>Just Enhance!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://1.gvt0.com/vi/Vxq9yj2pVWk/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Vxq9yj2pVWk&amp;fs=1&amp;source=uds" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266" src="http://www.youtube.com/v/Vxq9yj2pVWk&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;div align="left" class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;The clip says it all.&amp;nbsp; I wake in terror awaiting the day I am asked to "just enhance" a reflection off a grimy window in a grainy sur﻿veillance video.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-7315048001788851898?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/7315048001788851898/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/04/just-enhance.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/7315048001788851898'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/7315048001788851898'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/04/just-enhance.html' title='Just Enhance!'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-1983757913527221746</id><published>2011-04-20T12:29:00.000-07:00</published><updated>2011-09-07T03:10:11.505-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TV'/><title type='text'>"The Whistleblower" cont.</title><content type='html'>As I mentioned in my last post, the representation of digital forensics on "The Whistleblower" was actually fairly accurate.&amp;nbsp; That said, there were some things that were&amp;nbsp;wrong.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;strong&gt;What They Got Wrong&lt;/strong&gt;&lt;/div&gt;&lt;br /&gt;&lt;strong&gt;Timeline&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The timeline is incredibly inaccurate.&amp;nbsp; Not only were the hard drives of&amp;nbsp;10+&amp;nbsp;employees&amp;nbsp;imaged (ostensibly one at a time!)&amp;nbsp;in one day, all of them were apparently analyzed before end of business.&amp;nbsp; Even if IT Guy had a DF lair with multiple super computers running throughout the day, there simply would not have been enough time to parse and analyze&amp;nbsp;all that data.&amp;nbsp; From the information that was gathered, it seems the investigation wasn't even targeted to specific types of data.&amp;nbsp; So, while the condensed time frame makes for a more exciting script, it simply doesn't mesh with reality.&lt;br /&gt;&lt;br /&gt;There are many different variables that play into the amount of time it takes to image and analyze data.&amp;nbsp; On the imaging side, it depends on the hard drive size, the connection type, if there are bad sectors on the drive, etc.&amp;nbsp; If the image capture is done via a sata to sata connection, it will be faster than if the connection utilizes USB.&amp;nbsp;&amp;nbsp; Also, what many people may not realize is that a forensic (or bitstream) image captures the &lt;em&gt;entire&lt;/em&gt; drive.&amp;nbsp; So, even if there is only 30GB of active data on a 500GB hard drive, all 500GB&amp;nbsp;will be collected.*&amp;nbsp; On the analysis side, timeframes can vary depending on if the analysis is targeted, and how wide of a target area is being looked at.&amp;nbsp; For example, simply locating all active images on a computer takes much less time than recovering deleted data&amp;nbsp;or recreating activities that took place on the machine.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Personnel&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;In this episode, IT Guy plays a pivotal role throughout the entire process of collection and analysis.&amp;nbsp; Now, I would not say that IT personnel (they aren't always IT guys... some of pretty awesome IT gals) should never be a part of a collection effort - in fact, one of the best bits of advice I got about going onsite to perform imaging was to be friendly to the IT staff.&amp;nbsp; They know more about their specific systems and setup than any outside digital forensics expert, and can provide valuable background and assistance.&amp;nbsp; That said, there are situations where IT personnel should not be used - and instances with legal ramifications almost always fall into that category.&amp;nbsp; Especially - and I can not stress this enough - when it comes to the investigations themselves.&amp;nbsp;&amp;nbsp;You can look &lt;a href="http://www.forensic4cast.com/index.php?s=alfie+moon"&gt;here&lt;/a&gt; for an example&amp;nbsp;of what can happen when someone with an&amp;nbsp;IT background, but no forensics training, performs an investigation.&amp;nbsp; For those of you with background in forensics, I apologize in advance for&amp;nbsp;any damage you cause yourself&amp;nbsp;while reading this report.&amp;nbsp; For those without the background, at least note the Final Result:&amp;nbsp; the evidence that this&amp;nbsp;"expert"&amp;nbsp;said was not present was indeed found, and the report was NOT submitted as evidence.&lt;br /&gt;&lt;br /&gt;*&amp;nbsp;&lt;span style="font-size: x-small;"&gt;There are few absolutes when it comes to digital forensics.&amp;nbsp; The field is ever-changing and circumstances can vary widely from case to case.&amp;nbsp; Because of this, I will not be detailing all the possible&amp;nbsp;circumstances and outcomes unless they are specifically mentioned as a part of the scenario I am analyzing.&amp;nbsp; General concepts described will be best practices, as I understand them at the time of the writing.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-1983757913527221746?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/1983757913527221746/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/04/whistleblower-cont.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/1983757913527221746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/1983757913527221746'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/04/whistleblower-cont.html' title='&quot;The Whistleblower&quot; cont.'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-4114537352613858662</id><published>2011-04-14T11:17:00.000-07:00</published><updated>2011-09-07T03:09:46.068-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TV'/><title type='text'>"The Whistleblower" from The Office</title><content type='html'>Oh, &lt;em&gt;The Office&lt;/em&gt;.&amp;nbsp; I truly love you.&amp;nbsp; It was your&amp;nbsp;humor that got me and my second DOMEX team through the time in Iraq.&amp;nbsp; In fact, a subsequent OIC observed during transition that no conversation went by without a quote from either &lt;em&gt;The Office&lt;/em&gt; or &lt;em&gt;Stepbrothers&lt;/em&gt; (&lt;span style="font-size: x-small;"&gt;we may have been going a bit crazy at that point, but please don't judge&lt;/span&gt;).&amp;nbsp; The 6th season finale ranks as one of my favorites.&amp;nbsp; Not because it had the best office pranks or a gratuitous musical number (love those, too!), but because - of course! -&amp;nbsp;it involved computer forensics.&lt;br /&gt;&lt;br /&gt;If you haven't seen this episode, you can check out the synopsis on wikipedia &lt;a href="http://en.wikipedia.org/wiki/Whistleblower_(The_Office)"&gt;here&lt;/a&gt;.&amp;nbsp; For my purposes, the salient point is simply that employees' computers are being collected and searched for&amp;nbsp;data about an information leak to the media.&amp;nbsp; ***Disclaimer:&amp;nbsp; I Am Not A Lawyer, so I won't be discussing the legalities of the situation.***&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;strong&gt;What They Got Right&lt;/strong&gt;&lt;/div&gt;&lt;br /&gt;&lt;strong&gt;Collection Method&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Unfortunately, we don't get to see&amp;nbsp;the exact steps&amp;nbsp;IT Guy used to collect the data from the drives.&amp;nbsp; Did he use write blockers?&amp;nbsp; Were bitstream images created?&amp;nbsp; What software was utilized?&amp;nbsp; However, we do know that he pulled the physical hard drives -&amp;nbsp;a very common collection method.&amp;nbsp; There are ways to create forensic images without pulling the drives, such as using a live boot cd.&amp;nbsp;&amp;nbsp;However, pulling the drive can result in faster acquisition times.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Reactions&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;I have yet to collect data from a thrilled custodian.&amp;nbsp; This is usually for perfectly valid reasons.&amp;nbsp; It can be inconvenient or downright impossible for someone to do work without their computer for the time it takes to image.&amp;nbsp; Of course, there are other reasons that people have negative reactions, as evidenced by Kevin's mad dash (ostensibly to delete something he didn't want found... not that the deleted information couldn't have been recovered, but we can talk more about that later).&amp;nbsp; This leads very nicely into the next category...&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Data Found&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;object height="288" width="512"&gt;&lt;param name="movie" value="http://www.hulu.com/embed/EkXLlCYns7kgPcwtbD9Ebw"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;embed src="http://www.hulu.com/embed/EkXLlCYns7kgPcwtbD9Ebw" type="application/x-shockwave-flash"  width="512" height="288" allowFullScreen="true"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;The climax of the episode involves IT Guy revealing some of the information he found on the hard drives (computer forensics is a field that appeals to the inherently nosy).&amp;nbsp; Web history (Darryl's facebook account), pictures (Ryan's attempt at being a photographer), e-mails (is this how Nick found out Kelly thinks she's a size 2?) are all there for analysis on almost any computer.&amp;nbsp; In fact, the only slightly unbelievable thing about this is the &lt;em&gt;lack&lt;/em&gt; of salacious material.&amp;nbsp; Anyone who has been in the industry long knows how much personal information people have on their work computers:&amp;nbsp; online shopping, porn (yes, even on work computers), dating sites, more porn... the list goes on.&amp;nbsp; Although, come to think of it, IT Guy didn't mention what he found on Creed's computer - that I would like to see.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-2ameA3lxKF0/Ta8r9DrMFXI/AAAAAAAAAAQ/sKEuqZne9mM/s1600/villainy.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="254" i8="true" src="http://2.bp.blogspot.com/-2ameA3lxKF0/Ta8r9DrMFXI/AAAAAAAAAAQ/sKEuqZne9mM/s320/villainy.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;All in all, this was a fairly accurate depiction.&amp;nbsp; Next&amp;nbsp;post I will be going over what was NOT accurate in the episode.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-4114537352613858662?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/4114537352613858662/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/04/whistleblower-from-office.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/4114537352613858662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/4114537352613858662'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/04/whistleblower-from-office.html' title='&quot;The Whistleblower&quot; from The Office'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-2ameA3lxKF0/Ta8r9DrMFXI/AAAAAAAAAAQ/sKEuqZne9mM/s72-c/villainy.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6722867217002233231.post-7354045274731216738</id><published>2011-04-12T20:56:00.000-07:00</published><updated>2011-10-13T12:48:07.989-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TV'/><title type='text'>Hollywood and Computer Forensics</title><content type='html'>Hollywood is not&amp;nbsp;accurate.&amp;nbsp; This concept is well understood by most at this point.&amp;nbsp; A&amp;nbsp;historical reconstructionist doesn't turn to &lt;em&gt;The Tudors&lt;/em&gt; for clothing concepts, just like lawyers don't do case research on &lt;em&gt;Law and Order&lt;/em&gt;.&amp;nbsp; None of the Special Agents I know &lt;span style="font-size: x-small;"&gt;(I don't know any)&lt;/span&gt; would take notes from James Bond.&amp;nbsp; &lt;span style="font-size: x-small;"&gt;There may be something to this whole zombie thing, though.&amp;nbsp; I hope someone in the pharmaceutical industry&amp;nbsp;is looking into that.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In college I took a class in forensic science.&amp;nbsp; This wasn't&amp;nbsp;the digital forensics I do now... this was the "glamorous" kind -&amp;nbsp;complete&amp;nbsp;with fingerprint dusting and luminol.&amp;nbsp; I came to class prepared with oversized&amp;nbsp;sunglasses and pithy quotes.&amp;nbsp; The professor was a veteran in the forensic science field and had recently seen an explosion of interest following the release of &lt;em&gt;CSI&lt;/em&gt; and other crime procedurals.&amp;nbsp; He showed how well he knew his audience (this was an undergraduate class after all), when he gave us the assignment to watch one episode of &lt;em&gt;CSI&lt;/em&gt; - any episode - and document ten things done by the team that were incorrect.&amp;nbsp; Easy, right?&amp;nbsp; You bet.&amp;nbsp; But then he drove home the point when we were also assigned to&amp;nbsp;find five things on the show&amp;nbsp;that were done correctly.&amp;nbsp; He said finding the five would be the more difficult task.&amp;nbsp; He was right.&lt;br /&gt;&lt;br /&gt;Digital forensics doesn't get as much time in the Hollywood limelight, though it does seem to be cropping up more and more.&amp;nbsp; We industry professionals now have quirky characters people can use as a reference when we tell them what we do ("Oh!&amp;nbsp; You're like Abby on NCIS" is a common one).&amp;nbsp; In some ways, this is great.&amp;nbsp; Computer forensics is interesting!&amp;nbsp; And what better way to find the next generation of tech gurus than to show them the career path in an exciting format?&amp;nbsp; In many other ways, it can really be a pain.&amp;nbsp; Like the criminal lawyers who bemoan the &lt;em&gt;CSI&lt;/em&gt; un-education of jurors, digital forensics practitioners find they have to educate (or de-educate and then re-educate) clients on what amazing things we really can do and what amazing things are frankly impossible (or so cost-prohibitive they might as well be).&lt;br /&gt;&lt;br /&gt;I recently relocated to Southern California for my job as a&amp;nbsp;forensic consultant&amp;nbsp;(before this I was in Iraq, so it was quite the scenery change).&amp;nbsp; Doing forensic investigations with Hollywood literally a few minutes' drive away, I can't help but think about that college assignment.&amp;nbsp; So I'm going to take the assignment a step (or&amp;nbsp;side step)&amp;nbsp;further&amp;nbsp;by applying it to computer forensics and looking at whatever shows I happen to see.&amp;nbsp;&amp;nbsp;Stay tuned for the next installment on "The Whistleblower" episode from &lt;em&gt;The Office&lt;/em&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6722867217002233231-7354045274731216738?l=girlunallocated.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://girlunallocated.blogspot.com/feeds/7354045274731216738/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://girlunallocated.blogspot.com/2011/04/hollywood-and-computer-forensics.html#comment-form' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/7354045274731216738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6722867217002233231/posts/default/7354045274731216738'/><link rel='alternate' type='text/html' href='http://girlunallocated.blogspot.com/2011/04/hollywood-and-computer-forensics.html' title='Hollywood and Computer Forensics'/><author><name>Girl, Unallocated</name><uri>http://www.blogger.com/profile/14531145168136293345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://2.bp.blogspot.com/-k-pYNe3DQOo/Td1t872_2nI/AAAAAAAAABM/fBY0_VmLlsM/s220/girlunallocated.png'/></author><thr:total>6</thr:total></entry></feed>
