prove they were a novice or an expert???

10 views
Skip to first unread message

Brad

unread,
Feb 19, 2012, 11:23:44 AM2/19/12
to aff-discuss
Let's suppose the task was reversed. You don't need or prove they are
an expert, you already know they can barely find the 'on' button. But
what if you needed forensics to show that this person barely knew what
a keyboard was even though they used it everyday for years.
My first guess would be control panel access and administrator level
changes, but many knucklehead users default to admin instead of user.
What next?

Greg Freemyer

unread,
Feb 20, 2012, 6:20:57 PM2/20/12
to aff-d...@googlegroups.com
I think I'd take a look at the prefetch files.

See if they are running a lot of different things, or just the basics.

> --
> You received this message because you are subscribed to the Google Groups "aff-discuss" group.
> To post to this group, send email to aff-d...@googlegroups.com.
> To unsubscribe from this group, send email to aff-discuss...@googlegroups.com.
> For more options, visit this group at http://groups.google.com/group/aff-discuss?hl=en.
>

--
Greg Freemyer
Head of EDD Tape Extraction and Processing team
Litigation Triage Solutions Specialist
http://www.linkedin.com/in/gregfreemyer
CNN/TruTV Aired Forensic Imaging Demo -
   http://insession.blogs.cnn.com/2010/03/23/how-computer-evidence-gets-retrieved/

The Norcross Group
The Intersection of Evidence & Technology
http://www.norcrossgroup.com

Benjamin Brink

unread,
Feb 20, 2012, 6:46:37 PM2/20/12
to aff-d...@googlegroups.com
The number of viruses installed? ;-)

An "expert" might setup a fresh/refreshed machine with a simple
configuration to handle a specific or unique task, but it's unlikely
they would allow the machine to be hijacked by others, unless it's being
used as a honeypot.

Simson Garfinkel

unread,
Feb 20, 2012, 7:08:01 PM2/20/12
to aff-d...@googlegroups.com, bulk_extra...@googlegroups.com
bulk_extractor pulls out the prefetch files.
Currently nobody is using this feature. I wish people were.

I'm probably going to shut down either aff-discuss or bulk_extractor-users, and move all the people from one to the other. Or recommend that everybody move to linux_forensics. Any suggestions which to do?

Greg Freemyer

unread,
Feb 20, 2012, 7:45:27 PM2/20/12
to aff-d...@googlegroups.com, bulk_extra...@googlegroups.com
Simson,

I wish there was one main place for all opensource / public domain
tools were discussed.

Assuming you mean the yahoo group linux_forensics, it looks like it
was almost dead last year. Look at the number of messages in history
chart at the bottom of:

http://tech.groups.yahoo.com/group/linux_forensics/?v=1&t=directory&ch=web&pub=groups&sec=dir&slk=3

So I think moving all traffic there is the better of the 2 options,
but wish there was a even more centralized list for the
communications.

Greg

Benjamin Brink

unread,
Feb 20, 2012, 11:11:40 PM2/20/12
to aff-d...@googlegroups.com
Since linux is not the only open source operating system, would a
project specific list, such as one of the first two, or a new, more
generic one, such as foss_forensics, oss_forensics etc have resilience?

>>> The Intersection of Evidence& Technology

Dewhirst, Rob

unread,
Feb 23, 2012, 2:33:03 PM2/23/12
to aff-d...@googlegroups.com
there's a bulk_extractor-users google group? I can't even find it via google.

Greg Freemyer

unread,
Feb 23, 2012, 3:09:32 PM2/23/12
to aff-d...@googlegroups.com

Simson Garfinkel

unread,
Feb 23, 2012, 2:42:42 PM2/23/12
to aff-d...@googlegroups.com
Yes. 

Need to do a better job publicizing it.


I don't understand why Google hasn't indexed it.

But we are thinking about creating a general mailing list. That will probably happen shortly.
Reply all
Reply to author
Forward
0 new messages