Another utility compares file extensions to the data content in order to determine if files have been camouflaged with phony file extensions. For example, an image file might be renamed as a text document and vice versa.
Network Forensics
In order to identify attacks, "network forensics" deals with the capture and inspection of packets passing through a selected node in the network. Packets can be inspected on the fly or stored on disk for later analysis. See forensically clean, slack space, write blocker, file wipe, IDS, Internet forensics and security event management software.
NIST Phases
The National Institute of Standards and Technology "Guide to Integrating Forensic Techniques into Incident Responses" covers four phases, which are briefly summarized below. For the complete 121-page NIST publication, download draft SP 800-86 at http://csrc.nist.gov/publications/nistpubs.
1 - Collection: Identify, label, record and acquire data from possible sources, while preserving the integrity of the data.
2 - Examination: Use manual and automated methods to assess and extract data of particular interest, while preserving the integrity of the data.
3 - Analysis: Use legally justifiable methods and techniques to derive useful information.
4 - Reporting: Describe actions used, explain how tools and procedures were selected, determine what other actions need to be performed, including forensic examination of additional data sources, securing identified vulnerabilities and improving existing security controls. Recommend improvements to policies, guidelines, procedures, tools and other aspects of the forensic process.
![]() | Reproduced with permission from Computer Desktop Encyclopedia. Copyright (c) 1981-2009 The Computer Language Company Inc. All rights reserved. |
Additional Resources
- JDAFTS 20091111001 (Windows)
- JDAFTS, which stands for Jones Dykstra & Associates Forensic Tool Suite, includes case data management applications that extend beyond the capabilities of currently-available forensic software applications. JDAFTS is designed for computer forensics, corporate, government, and law enforcement investigators as well as universities. Easy to use, the tool suite allows forensics...
- Software downloads 2009-11-11
- Snow Leopard gets battery forensics
- There's a lot going on under the hood of Snow Leopard, to be sure, but a subtle change has been made to the battery menu item that will help portable users diagnose failing batteries. Within the new Battery menu bar extra in Mac...
- Blog posts 2009-08-31
- The Importance of Integrating Host and Network Forensics
- It is against list of requirements and with the objective of solving this exact problem that AccessData has integrated its host- AD Enterprise and network- SilentRunner Sentinel based forensic technologies into a single incident response solution. A single investigator can now utilize these tools together to tackle the most elusive...
- White papers 2009-08-28
- Mozilla shuts online store after security breach
- Mozilla shuts online store after security breachMozilla shuts online store after security breachThey must have been running linux.RE: Mozilla shuts online store after security breachIts unfortunate that this has occurred, as Mozilla's name is now partly associated with a crime that would be difficult for them to have prevented. This...
- Discussion threads 2009-08-05
- WinHex 15.4 (Windows)
- WinHex is a universal hexadecimal editor, particularly helpful in the realm of computer forensics, data recovery, low-level data processing, and IT security. An advanced tool for everyday and emergency use: inspect and edit all kinds of files, recover deleted files or lost data from hard drives with corrupt file systems...
- Software downloads 2009-08-02
- Ensuring FISMA Compliance: Integrating Forensics and Incident Response as Mandated by NIST SP 800-86
- The Federal Information Security Management Act FISMA of 2002 mandates that federal agencies must establish incident response capabilities (44 U.S.C. §3544 b(7)). FISMA requires that federal agencies implement an incident response capability consistent with the guidelines and standards established by the National Institute of Standards and Technology NIST (44 U.S.C....
- White papers 2009-04-20
- What Price Time? The Factor That Decides If Either Mac or PC Is Cool
- What Price Time? The Factor That Decides If Either Mac or PC Is CoolVery trueA Mac does not work for me, a Windows machine does.So you are correct: Cool means very little. I enjoy my summers outside, with friends; sitting in the home office working on a "cool looking" machine,...
- Discussion threads 2009-04-16
- MacLockPick 2.1 (Mac)
- MacLockPick II for Microsoft Windows, Apple Mac OS X, and Linux is a fully cross platform tool that allows digital forensics professionals and eDiscovery experts to perform field triage on live computers running a wide variety of operating systems. Similarly, once completed, the results of the field triage operation can...
- Software downloads 2009-03-25
- News to know: iPhone; Google; SAP; Oracle; IBM-Sun
- Here are today’s notable headlines. You can get News To Know via email alert and RSS daily. For continuous updates see BNET’s around-the-Web tech coverage. Sam Diaz: WSJ: IBM in talks to buy Sun Privacy group to FTC: Google's cloud is unsafe ...
- Blog posts 2009-03-18
- 'Memoryze' utility pinpoints malware code in live memory
- Jamie Butler, a Windows internals expert who co-wrote the definitive book on rootkits, has created a free forensics tool capable of finding malicious code in live memory. The utility, called Mandiant Memoryze, was released at this year's Hack in the Box conference in Kuala Lumpur, Malaysia. ...
- Blog posts 2008-11-10
- GOP gearing up legal attack on e-voting machines
- According to TPM Muckraker and this press release, the Republican National Committee is lining up the computer forensics firm Forensicon to provide analysis on e-voting machines to form the basis of a legal attack against the validity of the 2008 presidential election. Briefly,...
- Blog posts 2008-11-04
- USB History GUI 0.1 (Windows)
- USB History GUI can be used to display the most recent usage details of USB drives. It can be used for computer forensics. It can display the device name, the disk stamp, the volume stamp and the driver. It uses the usbhistory tool. This version is the first release on...
- Software downloads 2008-09-30
- Defendant in key RIAA decision destroyed evidence
- Photo by Luke Gattuso Just because you win a brilliant legal battle doesn't mean you'll win the war. Back in April, Judge Neil Wake handed RIAA opponents a key victory, with a seminal decision against the recording association's "making available" theory of distribution. ...
- Blog posts 2008-08-27
- Romanian authorities arrest cybercrime suspects
- Well, eight days, and a joint effort to help prevent phishing and two major arrests related to identity theft, and I feel like we've made a decent attack on the identity theft culture. Score one for the good guys for once. Just a day after reading...
- Blog posts 2008-07-17
- X-Ways Trace 3.1 (Windows)
- A computer forensics tool that allows to track and examine web browsing activity and deletion of files through the Windows recycle bin that took place on a certain computer. Deciphers Internet Explorer's ever-growing internal history/cache file index.dat. Displays complete URLs, date and time of the last visit, user names,...
- Software downloads 2008-07-03
- Reformed computer criminals - your country needs you
- And trust me, they really do. Over the last year, the UK and US Governments have had an awful problem in keeping basic data protection rules in check, almost to the point where they may have been broadcasting over the radio minutes of the intelligence committee meetings. ...
- Blog posts 2008-06-26
- Do Congressmen's charges of Chinese hacking hold water?
- InfoWorld notes that the congressmen who claimed China hacked their computers probably have scant evidence of the charges. "It's so very hard to conclude that something came from someplace if all you're going from is an IP address," said Marcus Sachs, director of the SANS Internet Storm...
- Blog posts 2008-06-13
- X-Ways Forensics 15.0 (Windows)
- X-Ways Forensics is an advanced work environment for computer forensic examiners. It is closely integrated with the WinHex hex and disk editor and can be purchased as a forensic license for WinHex. X-Ways Forensics comprises all the general and specialist features known from WinHex, such as... Disk cloning and imaging,...
- Software downloads 2008-06-03
- Sorry, conspiracy buffs, there's no Windows "back door"
- Sorry, conspiracy buffs, there's no Windows "back door"What do you expect?From the loosers at ValleyWag and the rest of the SV echochamber?They're like Hillary Clinton. Screeching and screeching lies until people believe they are true.I was actually expecting a refutationAll you've really said is that law enforcement doesn't need a...
- Discussion threads 2008-04-29
- Sorry, conspiracy buffs, there's no Windows "back door"
- Techdirt's Mike Masnick is usually pretty reliable, but he completely blew it today, hitting the publish button on one of the sloppiest, most inflammatory stories I've seen in a long time: Microsoft Gives Vista Backdoor Keys To The Police It's long been assumed that Microsoft has...
- Blog posts 2008-04-29
Neighboring Terms
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Keep Up With The Latest In Document Management with The DocuMentor.
-
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
- Learn more >>
- The more you simplify, the more you save
-
When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%

- Learn more >>
- The best support in the Linux business
-
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.

- Learn more >>
- Reduce risk. Reduce complexity. Increase reliability.
-
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux

- Learn more >>
SmartPlanet
- Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
- More from IBM
- How to Drive Better Business Outcomes with Exceptional Web Experiences Download the eBook
- Driving Business Agility through SOA Connectivity & Integration Read the White Paper from IBM
- Linking Decisions and Information for Organizational Performance Read the Tom Davenport study







