<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-254295412164493706</id><updated>2012-01-17T09:28:34.701-08:00</updated><title type='text'>nibble on dav nads</title><subtitle type='html'>wordup cyber geek girlz.. welcome to NIBBLE on DAV NADS!! This is my palace on the .com domain where i build connectors from connections, plug universal plugs into adapters, convert binary input into burberry output, and port gigabytes into jigabytes. LOL whaat! 2 ya'll hax0rs, start logging yo girlz keyz cause your @Myspace. Wer we spinning platters and pulling magnetic chatters. Dav nads speaks geek for chic and means tweak for twitter. Spread the google wave, followers!</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>41</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-1064104749551221564</id><published>2012-01-16T09:25:00.000-08:00</published><updated>2012-01-16T09:25:06.228-08:00</updated><title type='text'>Timeline Analysis: The Hybird Approach</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/-5nGFvdPAvWY/TxRa4L3MmqI/AAAAAAAAApk/deU8i8log2Y/s1600/VILLE.gif" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-5nGFvdPAvWY/TxRa4L3MmqI/AAAAAAAAApk/deU8i8log2Y/s320/VILLE.gif" width="310" /&gt;&lt;/a&gt;Harlan Carvey recently blogged about approaches to conduct &lt;a href="http://windowsir.blogspot.com/2012/01/timeline-analysis.html"&gt;Timeline Analysis&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;"So, anyway...I've been thinking about some of the things that I put into pretty much all of my timeline analysis presentations.&amp;nbsp; When it comes to creating timelines, IMHO there are essentially two "camps", or approaches.&amp;nbsp; One is what I call the "kitchen sink" approach, which is basically, "Give me &lt;/i&gt;&lt;i&gt;everything and let me do the analysis."&amp;nbsp; The other is what I call the "layered" or "overlay" approach, in which the analyst is familiar with the system being analyzed and adds successive "layers" to the timeline.&amp;nbsp; When I had a chance to chat with Chad Tilbury at &lt;a href="http://pfic-conference.com/"&gt;PFIC&lt;/a&gt; 2011, he recommended a hybrid of the two approaches...get everything, and then &lt;/i&gt;&lt;i&gt;view the data a layer at a time, using something he referred to as a "zoom" capability.&amp;nbsp; This is something I think is completely within reach...but I digress."&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;I very much agree with the various approaches outlined above and their respective descriptions. Well put, Harlan and Chad Tilbury.&lt;br /&gt;&lt;br /&gt;Over the years I have observed the traditional "kitchen sink" approach evolve into a "layered - overlay" approach. Fundamentally this has been the building blocks of timeline analysis. Harlan, Rob Lee, and the Sleuth kit have been primary drivers of this transformation with contributions such as "regtime.pl", "mac_daddy", and "fls". These contributions have allowed us to take the "kitchen sink", a entire hard drive image, and break it up into different "layers". Each layer representing a specific artifact type such as registry or file system.&lt;br /&gt;&lt;br /&gt;What I appreciate about the "layered - overlay" approach is that it is a effective method of "removing the noise". This is my way of saying, hone in on specific areas of interest. In contrast, the "kitchen sink" approach can result in overwhelming volumes of data that can easily lead to distraction.&lt;br /&gt;&lt;br /&gt;For example, if I'm only interested in reviewing USB connections, there are specific "data points" that I only need to look at. In such, I would only apply relevant layers of data points to my timeline (i.e. registry, setupapi.log) to identify the connections. Then if needed, I could double check my results by adding a third layer into the timeline, ".evtx" files (event logs in win7 logs usb connections system) which should essentially overlay my existing USB connections and confirm my results.&lt;br /&gt;&lt;a href="http://www.photoshopessentials.com/images/basics/layer-shortcuts/layer-visibility-2.gif" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="320" src="http://www.photoshopessentials.com/images/basics/layer-shortcuts/layer-visibility-2.gif" width="259" /&gt;&lt;/a&gt;&lt;br /&gt;Perhaps, I then wanted to see if there was any ".lnk" files created on the hard drive image to show files being accessed from the USB device during the date/time of a USB connection. Subsequently, a fourth layer, file system activity could be added to the timeline for review and quickly filtered by ".lnk" files. In summary, this fundamental process of building a timeline is the concept of the "layered - overlay" approach.&lt;br /&gt;&lt;br /&gt;Adobe Photoshop (a graphic design application) is a good example of putting this concept to use. For anyone not familiar with the product (pictured to the right), multiple layers are used to represent and control each part of a image; background, shading/coloring, objects, etc. All of the individual layers merged together (overlayed) make up the "entire picture."&lt;br /&gt;&lt;br /&gt;However, as Harlan alluded to, not using the "kitchen sink" approach will dilute visibility into the context of specific artifacts -- limiting your analysis to specific layers instead of looking at the "entire picture." :&lt;br /&gt;&lt;br /&gt;&lt;i&gt;"the more data we have, the more context there is likely to be available.&amp;nbsp; After all, a file modification can be pretty meaningless, in and of itself...but if you are able to see other events going on "nearby", you'll begin to see what events led up to and occurred immediately following the file modification."&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;So how does Dav Nads' combine the best of the two approaches into one - the Hybird Approach?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-hgUruWq4hLI/TxRcVxdQm4I/AAAAAAAAAp0/aNQLEvp1vwA/s1600/PIRATE.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="227" src="http://3.bp.blogspot.com/-hgUruWq4hLI/TxRcVxdQm4I/AAAAAAAAAp0/aNQLEvp1vwA/s320/PIRATE.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href="http://blogs.vertigo.com/personal/willa/Blog/Lists/Photos/062707_2040_DualMonitor1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;/a&gt;To my knowledge there's no "out of box solution" or "push button" solution for this. It's a process of using multiple tools and applications. It's a manual process but comprehensive process. The process like all processes should be is constantly redefining to adapt to technology and needs..&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It all starts out with owning a lot of real estate, 2 x 24" monitors :-) Having tall and wide monitors is key for any type of timeline analysis. It allows you to see more data (and context) at one glance and increases efficiently by reducing clicking n' scrolling. &lt;br /&gt; &lt;br /&gt;&lt;a href="http://kleinco.com.au/images/stories/articles/splunk5.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="247" src="http://kleinco.com.au/images/stories/articles/splunk5.png" width="320" /&gt;&lt;/a&gt;I use one monitor to display the timeline data output&amp;nbsp; from log2timeline-sift in SPLUNK. This process is described in detail by &lt;a href="http://kleinco.com.au/thoughts-events/item/forensic-timeline-splunking"&gt;Klein&amp;amp;Co.&lt;/a&gt; Why do I use SPLUNK to display my log2timeline-sift output? &lt;br /&gt;&lt;ul&gt;&lt;li&gt;Running log2timeline-sift on a 120GB hard drive image can easily result in a 2-3 GB of output. Not to mention, try running log2timeline on a 500 GB hard drive image. &lt;b&gt;Microsoft Excel ain't going to work to review all of your data. It has limitations, period.&amp;nbsp;&lt;/b&gt; &lt;/li&gt;&lt;li&gt;Sure you can use "l2l_process" to cull your resulting output from log2timeline down by criteria such as date-range, but this still&lt;b&gt; does not guarantee your resulting output will be a manageable volume&lt;/b&gt;. It also takes away context and makes the process of building timeline a iterative process if you need to adjust later on.&lt;/li&gt;&lt;li&gt;Most people know enough Python, SQL, GREP or PERL to &lt;b&gt;be dangerous but not productive&lt;/b&gt;. Therefore, having a GUI based platform similar to Excel tends to be a preference when reviewing timeline data. &lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;SPLUNK indexes timeline data, providing the ability to search, filter, and sort data on the fly. It's also scalable, in the sense it's a enterprise tool that is designed to work with GBs of data. With the click of a button I can easily refine my timeline to only show certain data types. Note, DAV NADS does not work for SPLUNK, it's just the the best solution I have found.&lt;/b&gt;&lt;/li&gt;&lt;/ul&gt;Harlan raises an excellent point,&lt;i&gt; "That leads me to this question...if you're running a tool that someone else designed and put together, and you're just pushing a button or launching a command, how do you know that the tool got everything?&amp;nbsp; How do you know that what you're looking at in the output of the tool is, in fact, &lt;/i&gt;&lt;i&gt;everything?"&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-vGdJprZq3GU/TxNUPP-c76I/AAAAAAAAApE/B9FFzh-VMek/s1600/Capture.JPG" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-vGdJprZq3GU/TxNUPP-c76I/AAAAAAAAApE/B9FFzh-VMek/s320/Capture.JPG" width="276" /&gt;&lt;/a&gt;If I were to rely solely on the using the output of log2timeline and SPLUNK as a review tool for my analysis, that would be a issue for 2 reasons:&lt;br /&gt;&lt;br /&gt;First , let's be honest regardless of what tool used (commercial or open source) they all have or had at one point BUGS. Just as recently as a week ago, a bug in log2timeline was identified on the &lt;a href="http://tech.groups.yahoo.com/group/win4n6/"&gt;win4n6 list&lt;/a&gt; and was subsequently fixed.&lt;br /&gt;&lt;br /&gt;Secondly, timelines are what I like to refer to as skeletons. They do not show you the meat on the bones. Reviewing timeline data may reveal that "Top Secret - Receipt for Coke.docx" was created and opened. However the limitation with timeline data is, you can't view the document. That's when the second monitor comes into the picture...&lt;br /&gt;&lt;br /&gt;I use the second monitor to display the hard drive image in a Forensic tool (Encase, FTK, etc). This allows me now to take a look at "Top Secret - Receipt for Coke.docx" and see that it's just a document that discusses how &lt;a href="http://www.blogger.com/goog_2060230869"&gt;Coke's secret formula is now on &lt;/a&gt;&lt;span class="entry-content"&gt;&lt;a href="http://www.blogger.com/goog_2060230869"&gt;exhibit in World of &lt;/a&gt;&lt;nobr&gt;&lt;a href="http://www.blogger.com/goog_2060230869"&gt;Coca-Cola&lt;/a&gt;&lt;/nobr&gt;&lt;a href="http://blogs.knoxnews.com/harris/2011/12/cokes-secret-formula-is-out.html"&gt; in Atlanta&lt;/a&gt;! This also allows me to potentially see anything that may be in context of this event that is not displayed in my timeline as a layer. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="entry-content"&gt;Leveraging a second tool simultaneously to view the data from a different perspective allows me to also double check and verify findings. For instance, if I see that how_to_kill_the_dog.doc was created on January 1, 2013 in my timeline data, I can quickly check to see if I'm seeing the same thing from my forensic tool or if this is a odd anomaly and potentially a issue with my timeline. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-3mVd8Hpz-n8/TxRdWMd3Q_I/AAAAAAAAAqE/PPuPnb5Fd_A/s1600/HEART.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-3mVd8Hpz-n8/TxRdWMd3Q_I/AAAAAAAAAqE/PPuPnb5Fd_A/s1600/HEART.gif" /&gt;&lt;/a&gt;&lt;/div&gt;From my experience, the Hybrid timeline analysis approach is really finding synergy between the "full kitchen" and "layered - overlay" approaches. The important thing to understand to sucessfully deploy this approach is the strengths and weakness of the tools you use. For instance, identifying the difference between timeline data (output from log2timeline or wherever) that may only contain X where the full disk image contains Z and empowering a processing to fill these gaps. This allows you to develop a Hybird approach, like I described above that fits your needs.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;b style="background-color: blue; color: yellow;"&gt;&lt;span style="color: orange;"&gt;-&lt;/span&gt; DAV NADS,&amp;nbsp; tweetin' @DAVNADS tweet at me cyber girls!&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-1064104749551221564?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/1064104749551221564/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2012/01/timeline-analysis-hybird-approach.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/1064104749551221564'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/1064104749551221564'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2012/01/timeline-analysis-hybird-approach.html' title='Timeline Analysis: The Hybird Approach'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-5nGFvdPAvWY/TxRa4L3MmqI/AAAAAAAAApk/deU8i8log2Y/s72-c/VILLE.gif' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-3317655037610155702</id><published>2012-01-04T07:31:00.000-08:00</published><updated>2012-01-04T07:46:20.743-08:00</updated><title type='text'></title><content type='html'>&lt;a href="http://4.bp.blogspot.com/-2XQwxri-R2U/TtkfrEYTfNI/AAAAAAAABAw/VT3HjeV0tS0/s640/paulyd.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="199" src="http://4.bp.blogspot.com/-2XQwxri-R2U/TtkfrEYTfNI/AAAAAAAABAw/VT3HjeV0tS0/s320/paulyd.jpg" width="320" /&gt;&lt;/a&gt;&lt;b&gt;Thank you to all of my #DFIR followers. Hope everyone had a great New Years. Let 2012 bring many dongles, matching hashes, and cold blowing CPU fans to everyone!&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;-DAV NADS&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-3317655037610155702?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/3317655037610155702/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2012/01/thanks-to-all-of-my-dfir-followers.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/3317655037610155702'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/3317655037610155702'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2012/01/thanks-to-all-of-my-dfir-followers.html' title=''/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-2XQwxri-R2U/TtkfrEYTfNI/AAAAAAAABAw/VT3HjeV0tS0/s72-c/paulyd.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-1673173037871023923</id><published>2011-12-18T14:01:00.001-08:00</published><updated>2011-12-18T14:01:57.733-08:00</updated><title type='text'>Digital Forensics SIFT'ing: Cheating Timelines with log2timeline</title><content type='html'>Check out my article on SANS about cheating timeline with log2timeline.&lt;br /&gt;&lt;h2&gt;&lt;a href="http://computer-forensics.sans.org/blog/2011/12/16/digital-forensics-sifting-cheating-timelines-with-log2timeline#" title="Digital Forensics SIFT'ing:  Cheating Timelines with log2timeline"&gt;Digital Forensics SIFT'ing:  Cheating Timelines with log2timeline&lt;/a&gt;&lt;/h2&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-1673173037871023923?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/1673173037871023923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2011/12/digital-forensics-sifting-cheating.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/1673173037871023923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/1673173037871023923'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2011/12/digital-forensics-sifting-cheating.html' title='Digital Forensics SIFT&apos;ing: Cheating Timelines with log2timeline'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-360803549726328013</id><published>2011-11-28T06:30:00.001-08:00</published><updated>2011-11-28T21:24:34.879-08:00</updated><title type='text'>Extending Reg Ripper, again.</title><content type='html'>A few months ago I posted &lt;a href="http://davnads.blogspot.com/2011/06/basic-groundwork-for-cmd-line-scripting.html"&gt;how to automate the process of reporting all date/time instances a USB connection was made (including from Restore Points)&lt;/a&gt;, using a combination of Mount Image Pro, SubInACL.exe, Reg Ripper, and some batch script Kung Foo. For one engagement, the scope was 50 + hard drives. Exercising this process reduced analysis time from hours to minutes per hard drive and translated into a significant time and cost savings to the client.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://cover6.cduniverse.com/MuzeAudioArt/520/524277.jpg" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://cover6.cduniverse.com/MuzeAudioArt/520/524277.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Recently, I received 50 + SYSTEM registry hives from various host systems. &lt;i&gt;Note, due to special circumstances only the SYSTEM hives were provided -- &lt;a href="http://computer-forensics.sans.org/blog/2009/09/09/computer-forensic-guide-to-profiling-usb-thumbdrives-on-win7-vista-and-xp/"&gt;fyi -- there are other artifacts that log USB connections.&lt;/a&gt;&lt;/i&gt;&amp;nbsp;All hives where preserved in Logical Evidence File (L01s) format. Using Encase I took a look at the L01 files. Based on full path information of the SYSTEM registry hives collected, it&amp;nbsp;appeared they were from both active and Restore Point locations.&lt;br /&gt;&lt;br /&gt;For this engagement I needed to report all date/time instances a USB connection was made based on the SYSTEM registry hives provided...&lt;br /&gt;&lt;br /&gt;Since I was dealing with hives from various hosts within the L01s-- the only thing segregating them was the directory structure &amp;nbsp;(full path information) they were preserved in. It would be key to preserve this same full path information for each hive in whatever output/report created. This would allow one to tie a Hive back to a specific host later on.&lt;br /&gt;&lt;br /&gt;Therefore, it was time to put my thinking cap on. Below is the list of options I came up with:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Manually parse out the Hives.&lt;/li&gt;&lt;li&gt;Run the Encase Advanced Enscript USB parser, but that outputs into a messy log file that is not delimited. Experience also tells me it can be hit or miss.&lt;/li&gt;&lt;li&gt; Export the Hives and run Reg Ripper on each of them one by one, manually building a report as I go.&lt;/li&gt;&lt;li&gt;Build a Reg Ripper batch script, but this would not preserve the file name and full path source of the hive in the output.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Script that sh!@t!!&lt;/b&gt;&lt;/li&gt;&lt;/ol&gt;I like being challenged so scripting that sh!@t using Python sounded trivial. Note, as I stated in my post about &lt;a href="http://davnads.blogspot.com/2011/07/dear-dav-nads-help-me-make-some-folders.html"&gt;using Python to automate the process of creating folder structures&lt;/a&gt;, my coding skillz are script kiddie at best so please no LuLzing. &lt;br /&gt;&lt;br /&gt;The requirements of the tool needed to be:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Recursively walk through a directory structure (using Encase I exported all L01's preserving folder paths to a case folder).&lt;/li&gt;&lt;li&gt;Identify any "SYSTEM" or "_REGISTRY_MACHINE_SYSTEM" registry hives.&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: 'Times New Roman', serif;"&gt;For each Hive it finds:&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: 'Times New Roman', serif;"&gt;Append File name to processingaudit log&lt;/span&gt;&lt;span style="font-family: 'Times New Roman', serif;"&gt; &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: 'Times New Roman', serif;"&gt;Run Reg Ripper against it withspecific plug in ( USBSTOR3 to show me all USB connections)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: 'Times New Roman', serif;"&gt;&lt;/span&gt;&lt;span style="font-family: 'Times New Roman', serif;"&gt;Import&lt;/span&gt;&lt;span style="font-family: 'Times New Roman', serif;"&gt; Reg Ripper output intoPython memory based list/db&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: 'Times New Roman', serif;"&gt;Foreach line imported, append full path of original hive parsed (for auditpurposes -- will allow me to tie a hive back to it's original source later).&lt;/span&gt;&lt;span style="font-family: 'Times New Roman', serif;"&gt;&lt;/span&gt;&lt;span style="font-family: 'Times New Roman', serif;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;span style="font-family: 'Times New Roman', serif;"&gt;Export CSV report for all hivefiles found. &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;Below is the pretty Python code I compiled. &lt;span style="font-family: 'Times New Roman', serif;"&gt;For funI’m going to try to add some error handling, convert to OO, and port into an Executable. For now, all I can say is it works and saved me a ton of manual effort/time.&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;importos, fnmatch, csv&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;a =[]&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;deffind_files(directory, pattern): #Recursively walk directory path for files&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;print 'Recursively search directory for SYSTEM hives..'&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;for root, dirs, files in os.walk(directory):&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;for basename in files:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;if fnmatch.fnmatch(basename, pattern):&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;filename = os.path.join(root, basename)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;yield filename&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;forfilename in find_files('C:\directory_structure_to_search)' ,'*SYSTEM'):&amp;nbsp; #Define dir path and hive type to look for&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;print 'Found Hive:', filename&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;print 'Ripping...'&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;os.system('""C:\\Program Files (x86)&lt;a href="http://www.blogger.com/blogger.g?blogID=254295412164493706"&gt;\\RegRipper032911\\rip.exe&lt;/a&gt; "-r "' + filename + '" -p usbstor3&amp;gt; c:\\final.csv"')&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;print 'Done Ripping.'&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;print 'Processing Output...'&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;with open('c:\\final.csv', 'r+') as f: #Import RegRipper output into list&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;writer = csv.writer(f)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;reader = csv.reader(f)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;for row in reader:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;row.append(filename)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;a.append(row)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;log= open('c:\\log.txt', 'r+') #Append each processed file to log output&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;log.writelines(filename + '\n')&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;output= open('c:\\output.csv', 'r+') #print 'Writing output CSV'&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;wr =csv.writer(output)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;fori in a:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;print i&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;wr.writerow(i)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;printa&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;output.close&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;print'Done'&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;exit&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Truly,&amp;nbsp;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Dav Nads&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: 'Courier New'; font-size: 8pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class="MsoListParagraph" style="margin-left: 1.0in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-360803549726328013?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/360803549726328013/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2011/11/extending-reg-ripper-every-day.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/360803549726328013'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/360803549726328013'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2011/11/extending-reg-ripper-every-day.html' title='Extending Reg Ripper, again.'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-1138347882238347802</id><published>2011-11-13T11:03:00.000-08:00</published><updated>2011-11-14T09:17:29.501-08:00</updated><title type='text'>Intellectual Property (IP) Theft and Technology 1o1o1o1</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.marylandiplaw.com/uploads/image/Report%20IP%20Theft.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://www.marylandiplaw.com/uploads/image/Report%20IP%20Theft.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;I'm working on a paper on High Tech Intellectual Property Theft so I thought I would share some food for thought!&lt;br /&gt;&lt;br /&gt;According to &lt;a href="http://en.wikipedia.org/wiki/Intellectual_property#cite_note-0"&gt;Wikipedia&lt;/a&gt; (whatev that's worth), &lt;b&gt;Intellectual Property (IP)&lt;/b&gt; is a term referring to a number of distinct types of creations of the mind for which a set of &lt;a href="http://en.wikipedia.org/wiki/Exclusive_right" title="Exclusive right"&gt;exclusive rights&lt;/a&gt; are recognized—and the corresponding fields of &lt;a href="http://en.wikipedia.org/wiki/Law" title="Law"&gt;law&lt;/a&gt; and &lt;b&gt;theft&lt;/b&gt; is the illegal taking of another person's &lt;a href="http://en.wikipedia.org/wiki/Property" title="Property"&gt;property&lt;/a&gt; without that person's freely-given &lt;a href="http://en.wikipedia.org/wiki/Consent" title="Consent"&gt;consent&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://t0.gstatic.com/images?q=tbn:ANd9GcSZNxpRhLXCbHv4XklC4XTFWdz03D20bsQ6MxLNDJA-eyEdHFFWJBLt8jRY" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="200" src="http://t0.gstatic.com/images?q=tbn:ANd9GcSZNxpRhLXCbHv4XklC4XTFWdz03D20bsQ6MxLNDJA-eyEdHFFWJBLt8jRY" width="176" /&gt;&lt;/a&gt;&lt;/div&gt;Do the math, &lt;i&gt;&lt;b&gt;IP + Theft is a equation for stealing s$% you shouldn't&lt;/b&gt;&lt;/i&gt;!! If you add technology as a variable into this equation, stealing $#% can get super geeky. For instance, a employee can copy the text from a document containing the recipe for Coke onto a website called &lt;a href="http://pastebin.com/"&gt;pastebin.com&lt;/a&gt;. This is a website where you can freely copy and paste text making it accessible to the world with just a few clicks. It is a convenient and "virtually untraceable" platform for people to share large amounts of text. The website has been traditionally used by programmers to store  source code but also &lt;a href="http://thenextweb.com/socialmedia/2011/06/05/pastebin-how-a-popular-code-sharing-site-became-the-ultimate-hacker-hangout/"&gt;more recently used by HaX0r groups&lt;/a&gt; like Anonymous, 4chan, and LulzSec to post their pirated caches and booties. &lt;br /&gt;&lt;br /&gt;Methods of IP theft are becoming more advanced and mutually difficult to detect. Traditional methods of detection (i.e. usb connection analysis, print spool files, e-mail, etc.) are not going to CUT it in some cases. I used one example of a insider COPYING and PASTING IP out of a network, but their are many other advanced methods such as transferring data from a laptop to a mobile device in someone's pocket via ad-hoc networking, to installing &lt;a href="http://www.mobile-spy.com/"&gt;mobile malware/spyware software&lt;/a&gt; on a VIP.&lt;br /&gt;&lt;br /&gt;However, traditional methods of IP theft &lt;i&gt;&lt;b&gt;may not be as advanced but just as difficult (if not more difficult) to detect&lt;/b&gt;&lt;/i&gt;. For instance, taking pictures of IP with a camera phone or calling a partner and communicating IP over a phone. In these cases it's more important to be aware of these methods and put governance and policies in place to &lt;b&gt;prevent &lt;/b&gt;so your NOT responding to the "&lt;a href="http://listverse.com/2007/08/16/top-10-tips-to-commit-the-perfect-crime/"&gt;perfect crime&lt;/a&gt;".&lt;br /&gt;&lt;br /&gt;Let's also not forget about how the most simple digital crime can become ah so difficult. For instance, a terminated user transferred documents from a computer to a USB storage device a week before they resign. During that week, a Windows Update is also run and all USB last connection date/time  information in the active registry are unfortunately updated. Now you, as a forensic examiner are challenged to think outside of the box and look elsewhere ;-)&lt;br /&gt;&lt;br /&gt;Below is a collaborative (thank you unnamed co-worker) brain dump of potential methods of IP Theft. Note, some of these methods may leave little to NO forensic residue - the emphasis of the paper I'm writing is identification and detection from a Computer Forensic purpose. The purpose of this list is to promote awareness and hopefully assist with your due diligence or your next IP Theft investigation .&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;/b&gt;Personal e-mail account usage (i.e. user logs into personal e-mail account via web mail and attaches documents or copies text to e-mail message).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;/b&gt;Instant Messaging software such as AIM, MSN, Yahoo, Gtalk, or ICQ (i.e. transfer text or attachment over instant messaging conversation)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;/b&gt; Internet activity to online storage tools, file sharing services, social media platforms, and public/private forums (i.e. upload documents to online storage service or copy text to website such as &lt;a href="http://pastebin.com/"&gt;pastebin.com&lt;/a&gt;).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Access to network resources such as file servers (i.e. copy documents from file server directly to USB device) without subsequently accessing it. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Network connectivity to private networks via Bluetooth, wifi, or remote access to transfer data (i.e. computer transfers documents to another computer via Bluetooth network).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Removable storage device (i.e. user copies data to thumb drive or external hard drive). Keep in mind removable storage devices do not not always get tracked comprehensively (i.e. O/S  update occurs that updates all USB last connection date/time  information in registry).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Screen capture applications run from removable devices to minimize forensic residue (i.e. run screen recording tool from USB drive).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Use of non-standard applications/protocols such as VPN, FTP, SFTP, P2P, SHH (i.e. Use FTP application to transfer data to remote server).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Copy data to device that be configured as USB storage device such as mobile phone or music player (i.e. copy data via USB to iPhone or iPod). &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Bypassing the operating system by booting the system into a bootable disk to copy data to an external drive (i.e. anti-forensic or forensic software such as Helix or Knoppix).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Traditional forensic and IT methods of cloning hard drives (i.e. extract hard drive from system and use forensic software/hardware to copy/clone data).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Host and Mobile device based Spyware/Malware &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Other "low tech" methods of exfiltrating data include:&lt;/span&gt;&lt;/li&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Taking hard copy documents or electronic devices,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Photography or video,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;printing,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;scanning,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;use of unknown devices,&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;making a phone call and communicating the IP.&amp;nbsp;&lt;/span&gt;&lt;span style="font-size: small;"&gt; &lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/ol&gt;&lt;br /&gt;&lt;b&gt;Stay tuned.. I will be posting some more forensication soon.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;-Dav Nads &lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-1138347882238347802?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/1138347882238347802/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2011/11/intellectual-property-ip-theft-and.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/1138347882238347802'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/1138347882238347802'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2011/11/intellectual-property-ip-theft-and.html' title='Intellectual Property (IP) Theft and Technology 1o1o1o1'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-7463116676906261490</id><published>2011-11-07T19:10:00.000-08:00</published><updated>2011-11-07T19:12:38.813-08:00</updated><title type='text'>Reminiscing about my CEIC 2010 video competition entry</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="font-weight: normal; padding-bottom: 14px; padding-right: 15px;"&gt;&lt;i&gt;&lt;i&gt;In 2010, Guidance Software hosted a video competition for 2 free passes to their CEIC conference. We did not win because apparently it was not appropriate.&lt;/i&gt;&lt;/i&gt;&lt;/span&gt;&lt;span style="padding-bottom: 14px; padding-right: 15px;"&gt;&lt;i&gt;&lt;i&gt;&lt;span style="font-weight: normal;"&gt;I still went anyways, but reminiscing about our great video!&lt;/span&gt;&lt;/i&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://3.gvt0.com/vi/jRjgUZwzk98/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/jRjgUZwzk98&amp;fs=1&amp;source=uds" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266"  src="http://www.youtube.com/v/jRjgUZwzk98&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;span style="padding-bottom: 14px; padding-right: 15px;"&gt;&lt;i&gt;&lt;i&gt;&lt;span style="font-weight: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-7463116676906261490?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/7463116676906261490/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2011/11/reminiscing-about-my-ceic-2010-video.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/7463116676906261490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/7463116676906261490'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2011/11/reminiscing-about-my-ceic-2010-video.html' title='Reminiscing about my CEIC 2010 video competition entry'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-5594361270028475906</id><published>2011-08-24T12:18:00.000-07:00</published><updated>2011-08-30T14:22:00.146-07:00</updated><title type='text'>Debian GNU/Linux Postfix Server Incident - p'owned?</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://t2ak.roblox.com/af4839298c6415191586b795ce6af38e" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://t2ak.roblox.com/af4839298c6415191586b795ce6af38e" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Reason to believe a server was compromised and it's a physical Debian GNU/Linux mail server in a production environment?&amp;nbsp; ..Sounds like fun!&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Below is a short list of items to consider when responding to a incident. This is from a technical perspective and by no means a work plan for a comprehensive investigation.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;If you haven't already, try to get a physical or logical image of the device. If the server can't be turned off to acquire physically, consider acquiring the logical partitions live:&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: small;"&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp; Attach USB&lt;br /&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp; mkdir /m1&lt;br /&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp; mount /dev/sdb1 /m1 # Substitute /dev/sdb1 for your USB device’s partition, fdisk –l helps&lt;br /&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp; dd if=/dev/sda1 of=/m1/my_image.img # this cmd is very basic and will dd the partition to the USB disk. If it uses logical volume manager, copy the logical partition as reconstructing the raid/lvm later could be an issue.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Identify all logs that could contain potential evidence related to the intrusion. Logs are going to be one of the key points of analysis in Linux based investigations. To that point, don't forget to inquiry about log retention polices and procedures during your scoping. For instance, are logs from the target server collected using a SIM, backed up to tape, or maybe logging is not even enabled? A good analogy is, make sure to account for ("or eat") all the crumbs that may be surrounding the cookie. &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Here is a short list:&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/secure&lt;br /&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/secure.*&lt;br /&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/messages&lt;br /&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/messages.*&lt;br /&gt;5.&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/wtmp&lt;br /&gt;6.&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/wtmp.*&lt;br /&gt;7.&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/btmp&lt;br /&gt;8.&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/btmp.*&lt;br /&gt;9.&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/mail.log&lt;br /&gt;10.&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/mail.log.*&lt;br /&gt;11.&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/apache&lt;br /&gt;12.&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/auth.log&lt;br /&gt;13.&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/spool/&lt;br /&gt;14.&amp;nbsp;&amp;nbsp;&amp;nbsp; Check syslog configuration (/etc/syslog.conf typically) and see if additional log files are stored&lt;br /&gt;15.&amp;nbsp;&amp;nbsp;&amp;nbsp; If the machine is behind a firewall, check firewall (machine/appliance)logs.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-5594361270028475906?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/5594361270028475906/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2011/08/debian-gnulinux-postfix-server-powned.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/5594361270028475906'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/5594361270028475906'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2011/08/debian-gnulinux-postfix-server-powned.html' title='Debian GNU/Linux Postfix Server Incident - p&apos;owned?'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-403124711041605712</id><published>2011-07-06T16:31:00.000-07:00</published><updated>2011-11-14T08:56:19.625-08:00</updated><title type='text'>Dear Dav Nads, help me make some folders</title><content type='html'>&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace; font-size: small;"&gt;&lt;span style="color: red;"&gt;yoGirl:&lt;/span&gt; Davnads,&amp;nbsp; you put the "sic" in forensic bc you got skillz.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: blue;"&gt;Davnads: &lt;span style="color: black;"&gt;dat rite&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: red;"&gt;yoGirl:&lt;/span&gt; I'm trying to stage some data on my network for a eDiscovery engagement that I need to process using the Cloud. I don't have time to manually create 500 staging folders with sub directories. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: blue;"&gt;Davnads: &lt;span style="color: black;"&gt;Yo chair yo' Problem &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: red;"&gt;yoGirl: &lt;span style="color: black;"&gt;:-(&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: blue;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;Davnads:&amp;nbsp;&lt;span style="color: black;"&gt; Damn sad faces, they always get 2 me. Okay I will help!&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;In response to my fan mail, I created a ugly (I don't program for a paycheck) Python script that will assist the process of creating directory structures in mass. This script uses the &lt;a href="http://pydoc.org/1.6/os.html"&gt;os module&lt;/a&gt;.&amp;nbsp; "As is" the script will read a comma delimited file, containing 3 folder names, line by line.&lt;br /&gt;&lt;br /&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: small;"&gt;Folder_Names.csv&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;David Nides,HDD &lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;SN XX&lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;,Mobile Phone&lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;,Network Share&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;Danny Nides&lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;,HDD &lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;SN XX&lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;,SharePoint Data&lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;,Network Share&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;For each line, it will create a directory structure consisting of the parent folder named based on the first line variable, and sub directories using the second, third, and forth line variables. For example:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace; font-size: small;"&gt;&amp;nbsp; &amp;gt;David Nides&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp; &amp;gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;HDD SN XX&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp; &amp;gt;&amp;gt;Mobile Phone&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp; &amp;gt;&amp;gt;Network Share&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp; &amp;gt;Danny Nides&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp; &amp;gt;&amp;gt;HDD SN XX&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp; &amp;gt;&amp;gt;Share Point Data&lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp; &amp;gt;&amp;gt;Network Share&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif; font-size: small;"&gt;The code is listed below. Note it is currently set to write the folder structure out to the "D:\" drive but this can be easily changed. Let me know if you have any questions.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif; font-size: small;"&gt;----------------------------------------------------------------------------------------------------- &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;#Created by David Nides, 6/29/11&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;#This python script will input a CSV file (refer to the input.txt template)&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;#Parse each row and create a directory.&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;import os&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;import csv&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;file = csv.reader(open('folder_names.csv'), delimiter=',')&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;for row in file:&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; os.chdir('d:')&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; os.mkdir(row[0])&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; print "creating ",row[0]&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; temp1='d:/'+row[0]+'/'+row[1]&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; temp2='d:/'+row[0]+'/'+row[2]&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; temp3='d:/'+row[0]+'/'+row[3]&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; os.mkdir(temp1)&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; print "creating ",temp1&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; os.mkdir(temp2)&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; print "creating ",temp2&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; os.mkdir(temp3)&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; print "creating ",temp3&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; os.chdir('d:')&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-403124711041605712?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/403124711041605712/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2011/07/dear-dav-nads-help-me-make-some-folders.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/403124711041605712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/403124711041605712'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2011/07/dear-dav-nads-help-me-make-some-folders.html' title='Dear Dav Nads, help me make some folders'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-9011055662033840517</id><published>2011-06-21T16:25:00.000-07:00</published><updated>2011-11-14T08:59:23.996-08:00</updated><title type='text'>Basic Groundwork for cmd line Scripting Computer Forensic Tasks + VIDEO BONUS</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://fastcache.gawkerassets.com/assets/images/17/2011/04/medium_reboottb.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://fastcache.gawkerassets.com/assets/images/17/2011/04/medium_reboottb.png" /&gt;&lt;/a&gt;&lt;/div&gt;Watch the video tutorial that I created for our internal team to see this in action and how it works: &lt;br /&gt;&lt;a href="http://dl.dropbox.com/u/27705041/final%20bat%20with%20redact.wmv"&gt;http://dl.dropbox.com/u/27705041/final%20bat%20with%20redact.wmv&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Task:&lt;/b&gt; 50 hard drives, Windows XP, report all date/time instances a USB drive connection was made.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Purposed Solution: &lt;/b&gt;Open Encase, Mount Image using Physical Disk Emulator module, Manually change Window’s security permissions/ownership of System Volume Information directory OR export Restore Point directory, Open up CMD prompt, Execute RegRipper against %/Windows/System32/config/SYSTEM and Restore Point, slice and dice output, and misc.&lt;br /&gt;&lt;br /&gt;~ 1 hour per hard drive.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Alternative Solution:&lt;/b&gt; Batch script that shit!&lt;br /&gt;&lt;br /&gt;~ 2 hours of development resulting in ~5 mins per hard drive.&lt;br /&gt;&lt;br /&gt;This is the groundwork and a start to scripting computer forensic tasks via the command line. It’s simple, yet very powerful stuff that anyone can do.&lt;br /&gt;&lt;br /&gt;Also, a special thank you to &lt;a href="http://integriography.wordpress.com/"&gt;David Kovar&lt;/a&gt; who was so kind to give me a few pointers along the way. He has volunteered to take this initiative and port it over to Python. More to come from &lt;a href="http://integriography.wordpress.com/"&gt;David &lt;/a&gt;and I as we work together on expanding on this.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Requirements:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;1. Windows XP Examiner Machine&lt;br /&gt;2. Image with Windows XP&lt;br /&gt;3. &lt;a href="http://www.mountimage.com/download-computer-forensics-software.php"&gt;Mount Image Pro&lt;/a&gt; (fully functional 30 day demo available)&lt;br /&gt;4. &lt;a href="http://www.microsoft.com/downloads/en/details.aspx?familyid=e8ba3e56-d8fe-4a91-93cf-ed6985e3927b&amp;amp;displaylang=en"&gt;SubInACL.exe &lt;/a&gt;&lt;br /&gt;5. &lt;a href="http://regripper.wordpress.com/"&gt;RegRipper&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;About the Batch:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;• Will prompt for disk image Full Path Location (.ad1, .e01, .dd, .vmdk, etc…)&lt;br /&gt;&lt;br /&gt;• Automatically mount disk image using Mount Image Pro CLI&lt;br /&gt;&lt;br /&gt;• List disk mounting information (drive letters mounted, volume name, file system, etc...)&lt;br /&gt;&lt;br /&gt;• Prompt for drive letter that %/SYSTEM VOLUME INFORMATION/% is located. This is where Restore Points are saved. By default this directory is protected and not accessible by the system. This can be automated later on&lt;br /&gt;&lt;br /&gt;• Prompt for local Administrator account name&lt;br /&gt;&lt;br /&gt;• Automatically Change ownership and grant full access to the %/SYSTEM VOLUME INFORMATION/% directory using SysInternal’s Subinacl.exe.&lt;br /&gt;&lt;br /&gt;• List %/SYSTEM VOLUME INFORMATION/% information&lt;br /&gt;&lt;br /&gt;• Prompt for Restore Point Directory Name you would like to parse&lt;br /&gt;&lt;br /&gt;• Then do work...&lt;br /&gt;&lt;br /&gt;• Currently set to execute RegRipper (RipXP.exe) using the USBSTOR3 plugin. This will parse the local SYSTEM hive and every Restore Point System Hive subsequently outputting a nice CSV file showing every USB drive (and corresponding date/time) EVER plugged into the system.&lt;br /&gt;&lt;br /&gt;• Anything that is cmd line accessible can be set to be executed after the drive is mounted. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Get Started: &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Copy the code below into notepad, save as XXX.bat, and execute via the command line. Make sure you have the three dependencies installed and your paths are defined to the three executables.&lt;br /&gt;&lt;br /&gt;Let me know if you have any questions or suggestions… It is just a rough draft but gets the job done for me! A lot more to come... stay tuned&lt;br /&gt;&lt;br /&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;------------------------------------------------------------------------&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;@ECHO OFF&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;::v.1&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;::Date: 6/15/2010&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;::Created by: David Nides, KPMG LLP&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;::This batch script will mount image using Mount Image Pro (MIP4.exe),  use Microsoft's SubInACL (SubInACL.exe)  command to take ownership and grant full access to System Volume Information, and then do work such as execute RipXP.exe.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;:: This requires that you have installed Mount Image Pro (Demo is available for free), &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;:: SubInACL (http://www.microsoft.com/downloads/en/details.aspx?familyid=e8ba3e56-d8fe-4a91-93cf-ed6985e3927b&amp;amp;displaylang=en)&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;:: Any other tools you want to cool&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;::Set full path of where all your .exe's are located below&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;set MIP_PATH="C:\Program Files\GetData\Mount Image Pro v4\MIP4"&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;set RR_PATH="C:\Program Files\Reg Ripper\RegRipper032911\ripxp"&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;set SUBINACL_PATH="C:\Program Files\Windows Resource Kits\Tools\subinacl"&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;:input for Mount Image Pro CMD Line&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;set /P IMAGELOC="Enter Image full path (e.g d:\image.dd): "&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;echo Your input was: %IMAGELOC%&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;echo ----------------------------------------------&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;echo Please wait while drive is being mounted.....&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;echo ----------------------------------------------&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;%MIP_PATH% mount "%IMAGELOC%"&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;echo ----------------------------------------------&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;echo Please wait while mounted device details are populated.....&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;%MIP_PATH% STATUS&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;echo ----------------------------------------------&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;:input to locate SYSTEM VOLUME INFORMATION - this can be automated later&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;set /P MOUNTED_DRIVE_LETTER="Look at the above List of Mounted Devices and input drive letter where SYSTEM VOLUME INFORMATION directory is located (e.g. H): "&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;echo Your input was: %MOUNTED_DRIVE_LETTER%&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;echo ----------------------------------------------&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;:input collect username to setowner and grant access to&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;set /P USER="Enter Administratve user account name to setowner and grant access to SYSTEM VOLUME INFORMATION (e.g. Administrator): "&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;echo Your input was: %USER%&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;%SUBINACL_PATH% /subdirectories "%MOUNTED_DRIVE_LETTER%:\System Volume Information" /setowner="%USER%" /grant="%USER%"=F&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;echo ----------------------------------------------&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;dir /ah "%MOUNTED_DRIVE_LETTER%:\System Volume Information\"&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;set /P RP_FOLDER_NAME="Enter Restore Point Folder you would like to parse in /System Volume Information/ (e.g. _restore{46DE8921-1D39-44D2-A9E9-64119261F211}): "&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;echo ----------------------------------------------&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;echo Lets do work......&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;echo ----------------------------------------------&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;::The below can be set for user config later. In the mean time this is the tell RegRipper to do X section.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;::set /P HIVE_to_PARSE="Enter Registry Hive to Parse (e.g. SYSTEM, SAM, NTUSER, SECURITY, SOFTWARE): "&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;::set /P RR_PLUGIN="RR Plugin to Parse with (e.g. USBSTOR3) "&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;%RR_PATH% -r "%MOUNTED_DRIVE_LETTER%:\WINDOWS\system32\config\SYSTEM" -d "%MOUNTED_DRIVE_LETTER%:\System Volume Information\%RP_FOLDER_NAME%" -p usbstor3&amp;gt;&amp;gt; c:\output.csv&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;span style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif; font-size: small;"&gt;If&amp;nbsp; &lt;/span&gt;&lt;span style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;you are interested in reading more about expanding RegRipper and similar projects, I suggest reading &lt;/span&gt;&lt;span class="author"&gt;&lt;span class="fn"&gt;&lt;span style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;Corey Harrell's blog post, &lt;/span&gt;&lt;a href="http://journeyintoir.blogspot.com/2011/05/triaging-my-way.html" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;Triaging my way&lt;/a&gt;&lt;span style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-9011055662033840517?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/9011055662033840517/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2011/06/basic-groundwork-for-cmd-line-scripting.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/9011055662033840517'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/9011055662033840517'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2011/06/basic-groundwork-for-cmd-line-scripting.html' title='Basic Groundwork for cmd line Scripting Computer Forensic Tasks + VIDEO BONUS'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-4538072487213342950</id><published>2011-03-28T15:55:00.000-07:00</published><updated>2011-03-28T15:55:27.572-07:00</updated><title type='text'>cHECK oUT Microsoft’s Audit Object Access Policy for Forensic Evidence!</title><content type='html'>Let's say client XYZ maintains sensitive budget information within a select folder on one particular Windows fileserver.  When originally created, the folder was restricted to specific AD users. At some point, everyone was granted access to the folder. Is there any available trail of activity in Windows to tell who accessed what and when?!?!&lt;br /&gt;&lt;br /&gt;YES (if it's turned on)... !!!!!&lt;br /&gt;&lt;br /&gt;I learned today that Microsoft’s audit object access policy handles auditing access to all objects outside AD. It is disabled by default, but IF enabled you can audit access to almost any kind of Windows object including files, folders, registry keys, printers, and services. &lt;br /&gt;&lt;br /&gt;Pretty cool. I see this as a useful source of information for many investigations so I thought I would share.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc776774%28WS.10%29.aspx"&gt;http://technet.microsoft.com/en-us/library/cc776774%28WS.10%29.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If it's not turned on, I believe enabling Audit Object Access either within GPO or the local server policy should do the trick.  Please note that depending on how many files/folders you have this auditing, disk space may be an issue. You really need a SIEM to go alongside this to parse and alert on anomalies if you want to use this as a true real-time investigate tool.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-4538072487213342950?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/4538072487213342950/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2011/03/check-out-microsofts-audit-object.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/4538072487213342950'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/4538072487213342950'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2011/03/check-out-microsofts-audit-object.html' title='cHECK oUT Microsoft’s Audit Object Access Policy for Forensic Evidence!'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-4010139275480260413</id><published>2010-08-18T12:36:00.001-07:00</published><updated>2010-08-20T20:15:59.382-07:00</updated><title type='text'>FTK Imager (for OS X) to the Rescue</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;meta content="text/html; charset=utf-8" http-equiv="Content-Type"&gt;&lt;/meta&gt;&lt;meta content="Word.Document" name="ProgId"&gt;&lt;/meta&gt;&lt;meta content="Microsoft Word 12" name="Generator"&gt;&lt;/meta&gt;&lt;meta content="Microsoft Word 12" name="Originator"&gt;&lt;/meta&gt;&lt;link href="file:///C:%5CUsers%5CNIDES%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml" rel="File-List"&gt;&lt;/link&gt;&lt;link href="file:///C:%5CUsers%5CNIDES%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_editdata.mso" rel="Edit-Time-Data"&gt;&lt;/link&gt;&lt;link href="file:///C:%5CUsers%5CNIDES%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx" rel="themeData"&gt;&lt;/link&gt;&lt;link href="file:///C:%5CUsers%5CNIDES%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml" rel="colorSchemeMapping"&gt;&lt;/link&gt;    &lt;m:smallfrac m:val="off"&gt;    &lt;m:dispdef&gt;    &lt;m:lmargin m:val="0"&gt;    &lt;m:rmargin m:val="0"&gt;    &lt;m:defjc m:val="centerGroup"&gt;    &lt;m:wrapindent m:val="1440"&gt;    &lt;m:intlim m:val="subSup"&gt;    &lt;m:narylim m:val="undOvr"&gt;   &lt;/m:narylim&gt;&lt;/m:intlim&gt; &lt;/m:wrapindent&gt;&lt;style&gt;&lt;!-- /* Font Definitions */ @font-face	{font-family:Wingdings;	panose-1:5 0 0 0 0 0 0 0 0 0;	mso-font-charset:2;	mso-generic-font-family:auto;	mso-font-pitch:variable;	mso-font-signature:0 268435456 0 0 -2147483648 0;}@font-face	{font-family:"Cambria Math";	panose-1:2 4 5 3 5 4 6 3 2 4;	mso-font-charset:0;	mso-generic-font-family:roman;	mso-font-pitch:variable;	mso-font-signature:-1610611985 1107304683 0 0 415 0;}@font-face	{font-family:Calibri;	panose-1:2 15 5 2 2 2 4 3 2 4;	mso-font-charset:0;	mso-generic-font-family:swiss;	mso-font-pitch:variable;	mso-font-signature:-520092929 1073786111 9 0 415 0;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal	{mso-style-unhide:no;	mso-style-qformat:yes;	mso-style-parent:"";	margin-top:0in;	margin-right:0in;	margin-bottom:10.0pt;	margin-left:0in;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}a:link, span.MsoHyperlink	{mso-style-priority:99;	color:blue;	mso-themecolor:hyperlink;	text-decoration:underline;	text-underline:single;}a:visited, span.MsoHyperlinkFollowed	{mso-style-noshow:yes;	mso-style-priority:99;	color:purple;	mso-themecolor:followedhyperlink;	text-decoration:underline;	text-underline:single;}tt	{mso-style-noshow:yes;	mso-style-priority:99;	font-family:"Courier New";	mso-ascii-font-family:"Courier New";	mso-fareast-font-family:"Times New Roman";	mso-hansi-font-family:"Courier New";	mso-bidi-font-family:"Courier New";}p.MsoNoSpacing, li.MsoNoSpacing, div.MsoNoSpacing	{mso-style-priority:1;	mso-style-unhide:no;	mso-style-qformat:yes;	mso-style-parent:"";	margin:0in;	margin-bottom:.0001pt;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph	{mso-style-priority:34;	mso-style-unhide:no;	mso-style-qformat:yes;	margin-top:0in;	margin-right:0in;	margin-bottom:10.0pt;	margin-left:.5in;	mso-add-space:auto;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParagraphCxSpFirst	{mso-style-priority:34;	mso-style-unhide:no;	mso-style-qformat:yes;	mso-style-type:export-only;	margin-top:0in;	margin-right:0in;	margin-bottom:0in;	margin-left:.5in;	margin-bottom:.0001pt;	mso-add-space:auto;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, div.MsoListParagraphCxSpMiddle	{mso-style-priority:34;	mso-style-unhide:no;	mso-style-qformat:yes;	mso-style-type:export-only;	margin-top:0in;	margin-right:0in;	margin-bottom:0in;	margin-left:.5in;	margin-bottom:.0001pt;	mso-add-space:auto;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}p.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, div.MsoListParagraphCxSpLast	{mso-style-priority:34;	mso-style-unhide:no;	mso-style-qformat:yes;	mso-style-type:export-only;	margin-top:0in;	margin-right:0in;	margin-bottom:10.0pt;	margin-left:.5in;	mso-add-space:auto;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}p.style12, li.style12, div.style12	{mso-style-name:style12;	mso-style-unhide:no;	mso-margin-top-alt:auto;	margin-right:0in;	mso-margin-bottom-alt:auto;	margin-left:0in;	mso-pagination:widow-orphan;	font-size:12.0pt;	font-family:"Times New Roman","serif";	mso-fareast-font-family:"Times New Roman";}span.body1	{mso-style-name:body1;	mso-style-unhide:no;}span.style18	{mso-style-name:style18;	mso-style-unhide:no;}span.style9	{mso-style-name:style9;	mso-style-unhide:no;}.MsoChpDefault	{mso-style-type:export-only;	mso-default-props:yes;	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}.MsoPapDefault	{mso-style-type:export-only;	margin-bottom:10.0pt;	line-height:115%;}@page Section1	{size:8.5in 11.0in;	margin:1.0in 1.0in 1.0in 1.0in;	mso-header-margin:.5in;	mso-footer-margin:.5in;	mso-paper-source:0;}div.Section1	{page:Section1;} /* List Definitions */ @list l0	{mso-list-id:73093956;	mso-list-type:hybrid;	mso-list-template-ids:2024053732 329263308 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}@list l0:level1	{mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;	mso-ansi-font-weight:normal;}@list l0:level2	{mso-level-number-format:alpha-lower;	mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;}@list l1	{mso-list-id:490558579;	mso-list-type:hybrid;	mso-list-template-ids:180251542 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}@list l1:level1	{mso-level-number-format:bullet;	mso-level-text:;	mso-level-tab-stop:none;	mso-level-number-position:left;	margin-left:1.0in;	text-indent:-.25in;	font-family:Symbol;}@list l2	{mso-list-id:638456650;	mso-list-type:hybrid;	mso-list-template-ids:-718348286 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}@list l2:level1	{mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;}@list l3	{mso-list-id:665518112;	mso-list-type:hybrid;	mso-list-template-ids:108563858 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}@list l3:level1	{mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;}@list l3:level2	{mso-level-number-format:alpha-lower;	mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;}@list l4	{mso-list-id:965547807;	mso-list-type:hybrid;	mso-list-template-ids:474261592 -575794814 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}@list l4:level1	{mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;	mso-ansi-font-size:10.0pt;	mso-bidi-font-size:10.0pt;	font-family:"Arial","sans-serif";}@list l4:level2	{mso-level-number-format:alpha-lower;	mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;}@list l5	{mso-list-id:1093820964;	mso-list-type:hybrid;	mso-list-template-ids:-936496090 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}@list l5:level1	{mso-level-tab-stop:none;	mso-level-number-position:left;	margin-left:.75in;	text-indent:-.25in;}@list l5:level2	{mso-level-number-format:alpha-lower;	mso-level-tab-stop:none;	mso-level-number-position:left;	margin-left:1.25in;	text-indent:-.25in;}@list l6	{mso-list-id:1143615414;	mso-list-type:hybrid;	mso-list-template-ids:1124369436 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}@list l6:level1	{mso-level-number-format:bullet;	mso-level-text:;	mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;	font-family:Symbol;}@list l7	{mso-list-id:1610237658;	mso-list-type:hybrid;	mso-list-template-ids:584582454 67698703 67698703 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}@list l7:level1	{mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;}@list l7:level2	{mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;}@list l8	{mso-list-id:2080133721;	mso-list-type:hybrid;	mso-list-template-ids:-1150126098 67698703 67698689 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}@list l8:level1	{mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;}@list l8:level2	{mso-level-number-format:bullet;	mso-level-text:;	mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;	font-family:Symbol;}ol	{margin-bottom:0in;}ul	{margin-bottom:0in;}--&gt;&lt;/style&gt;      &lt;/m:defjc&gt;&lt;/m:rmargin&gt;&lt;/m:lmargin&gt;&lt;/m:dispdef&gt;&lt;/m:smallfrac&gt;&lt;br /&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;So you have been tasked with acquiring an Apple Macbook Air. There you are, it’s just you and the laptop and you’re losing; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: Symbol; font-size: 10pt;"&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Your favorite Linux distribution disk won’t boot, &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: Symbol; font-size: 10pt;"&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;You spent hours taking the laptop apart only to discover the internal hard drive has a ZIFF or LIF interface and you don’t have an adapter, &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: Symbol; font-size: 10pt;"&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;The Firewire and Ethernet ports are missing, &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: Symbol; font-size: 10pt;"&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;there is only one USB port,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: Symbol; font-size: 10pt;"&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;and the laptop won’t boot from your USB hub.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;meta content="text/html; charset=utf-8" http-equiv="Content-Type"&gt;&lt;/meta&gt;&lt;meta content="Word.Document" name="ProgId"&gt;&lt;/meta&gt;&lt;meta content="Microsoft Word 12" name="Generator"&gt;&lt;/meta&gt;&lt;meta content="Microsoft Word 12" name="Originator"&gt;&lt;/meta&gt;&lt;link href="file:///C:%5CUsers%5CNIDES%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml" rel="File-List"&gt;&lt;/link&gt;&lt;link href="file:///C:%5CUsers%5CNIDES%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx" rel="themeData"&gt;&lt;/link&gt;&lt;link href="file:///C:%5CUsers%5CNIDES%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml" rel="colorSchemeMapping"&gt;&lt;/link&gt;    &lt;m:smallfrac m:val="off"&gt;    &lt;m:dispdef&gt;    &lt;m:lmargin m:val="0"&gt;    &lt;m:rmargin m:val="0"&gt;    &lt;m:defjc m:val="centerGroup"&gt;    &lt;m:wrapindent m:val="1440"&gt;    &lt;m:intlim m:val="subSup"&gt;    &lt;m:narylim m:val="undOvr"&gt;   &lt;/m:narylim&gt;&lt;/m:intlim&gt; &lt;/m:wrapindent&gt;&lt;style&gt;&lt;!-- /* Font Definitions */ @font-face	{font-family:"Cambria Math";	panose-1:2 4 5 3 5 4 6 3 2 4;	mso-font-charset:0;	mso-generic-font-family:roman;	mso-font-pitch:variable;	mso-font-signature:-1610611985 1107304683 0 0 415 0;}@font-face	{font-family:Calibri;	panose-1:2 15 5 2 2 2 4 3 2 4;	mso-font-charset:0;	mso-generic-font-family:swiss;	mso-font-pitch:variable;	mso-font-signature:-520092929 1073786111 9 0 415 0;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal	{mso-style-unhide:no;	mso-style-qformat:yes;	mso-style-parent:"";	margin-top:0in;	margin-right:0in;	margin-bottom:10.0pt;	margin-left:0in;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}p.MsoBodyText, li.MsoBodyText, div.MsoBodyText	{mso-style-unhide:no;	mso-style-link:"Body Text Char";	margin-top:0in;	margin-right:0in;	margin-bottom:6.0pt;	margin-left:0in;	mso-pagination:widow-orphan;	font-size:12.0pt;	font-family:"Times New Roman","serif";	mso-fareast-font-family:"Times New Roman";}span.BodyTextChar	{mso-style-name:"Body Text Char";	mso-style-unhide:no;	mso-style-locked:yes;	mso-style-link:"Body Text";	mso-ansi-font-size:12.0pt;	mso-bidi-font-size:12.0pt;	font-family:"Times New Roman","serif";	mso-ascii-font-family:"Times New Roman";	mso-fareast-font-family:"Times New Roman";	mso-hansi-font-family:"Times New Roman";	mso-bidi-font-family:"Times New Roman";}.MsoChpDefault	{mso-style-type:export-only;	mso-default-props:yes;	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}.MsoPapDefault	{mso-style-type:export-only;	margin-bottom:10.0pt;	line-height:115%;}@page Section1	{size:8.5in 11.0in;	margin:1.0in 1.0in 1.0in 1.0in;	mso-header-margin:.5in;	mso-footer-margin:.5in;	mso-paper-source:0;}div.Section1	{page:Section1;}--&gt;&lt;/style&gt;  &lt;/m:defjc&gt;&lt;/m:rmargin&gt;&lt;/m:lmargin&gt;&lt;/m:dispdef&gt;&lt;/m:smallfrac&gt;&lt;br /&gt;&lt;div class="MsoBodyText"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;This documentation specifically applies to Apple’s Macbook Air models. However, the procedures outlined here should be applicable to &lt;i&gt;all&lt;/i&gt; Intel-based Macs. When acquiring Macbook Airs traditional acquisition methods can often be challenged by the lack of external media interfaces and software compatibility issues.&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoBodyText"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;SO…WHAT’S NEXT?!?! In April 2010, Access Data released Command Line (CLI) versions of its popular FTK Imager tool. Supported by one of the versions are Intel-based Mac OS versions 10.5 and 10.6x. I have found this tool to be a strong candidate for Mac collections. This article will explore two collection techniques that exercise this tool:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;(Live Collection)&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt; – Acquisition of a targeted system in a live (booted) state. FTK CLI tool is executed from target’s system and image is written to external USB hard drive. This method is frequently used to acquire systems that cannot be taken offline or when encryption is involved. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;2.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;(Secondary-boot Collection) &lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;– Acquisition of a targeted system from a secondary-boot device. Target’s system is booted from a bootable external USB hard drive containing OS X and pre-installed with the FTK CLI tool. Once booted FTK CLI imager is executed from this device and image is written to the same USB hard drive in a separate partition FAT32 partition.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Note: As a forensic practitioner, you should weigh the pros and cons of the two collection techniques and use discretion to what method (if any) suits the requirements and needs of your engagement.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Approach 1: Live Collection – Preparation:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;OS X does not natively support writing to NTFS or EXT volumes. Therefore, you will need to prepare a HSFS or FAT32 formatted hard drive to write your image too. I prefer FAT32 over HFS because it is readily accessible from Windows. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;If you decide to go the HFS route, there is a tool called MacDrive that will allow full read/write to HFS from Windows (&lt;/span&gt;&lt;a href="http://www.mediafour.com/products/macdrive6/"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;http://www.mediafour.com/products/macdrive6/&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span class="style18"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;2.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Download and extract “&lt;span class="style18"&gt;ImagerCLI 2.9.0_Mac.zip”&lt;/span&gt; from Access Data onto the external device:&lt;span class="style18"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="style12" style="margin: 0in 0in 0.0001pt 1in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="style12" style="margin: 0in 0in 0.0001pt 1in;"&gt;&lt;span class="style18"&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;File&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span class="style18"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;: Mac/FTK ImagerCLI 2.9.0_Mac.zip&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="style12" style="margin: 0in 0in 0.0001pt 1in;"&gt;&lt;span class="style18"&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Link&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span class="style18"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;a href="http://accessdata.com/downloads/current_releases/imager/FTK%20ImagerCLI%202.9.0_Fedora.tar.gz"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;http://accessdata.com/downloads/current_releases/imager/FTK%20ImagerCLI%202.9.0_Fedora.tar.gz&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;i&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt; font-style: normal;"&gt;Supports:&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;i&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt; font-style: normal;"&gt; Mac OS 10.5 and 10.6x&lt;/span&gt;&lt;/i&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;br /&gt;&lt;span class="style9"&gt;&lt;b&gt;MD5&lt;/b&gt;&lt;/span&gt;&lt;span class="body1"&gt;: 5b33f0ec0c6d5096371f07d19cc698de&lt;/span&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Approach 1: Live Collection – Getting Started:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;If applicable, power on the device and log in.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;2.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Plug in the USB hard drive you have prepared as the destination drive.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;3.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Open the console application located in: &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;tt&gt;&lt;span style="font-size: 10pt;"&gt;/Applications/Utilities/Console&lt;/span&gt;&lt;/tt&gt; &lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="text-indent: 0.25in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;This is a window into the other side of OS X. All commands hereafter will be issued from the console. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;4.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Switch to user “root”: &lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;Ftechs-Mac-mini:~ ftech$&amp;nbsp; Su root&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.25in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Root privileges are needed for FTK CLI to interact with the host device. You will be prompted for the root password.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;*Note 1: The default Mac OS X installation has the "root" account disabled. To enable it, follow the steps here: &lt;/span&gt;&lt;a href="http://www.spy-hill.com/%7Emyers/help/apple/EnableRoot.html"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;http://www.spy-hill.com/~myers/help/apple/EnableRoot.html&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;*Note 2: If you don’t know the root password you can try this to reset it, &lt;/span&gt;&lt;a href="http://www.macosxhints.com/article.php?story=20001217230925152"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;http://www.macosxhints.com/article.php?story=20001217230925152&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;*By following this step you are making substantial changes to the host system. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;5.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;After you have switched users to root, you will need to&amp;nbsp; identify the &lt;i&gt;source&lt;/i&gt; and &lt;i&gt;destination&lt;/i&gt; hard drives for acquisition:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;Ftechs-Mac-mini:~ root$ diskutil list&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;This will query all active disks and their partition layouts:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_xRHNXt3iDHk/TGw2u1n1IhI/AAAAAAAAAm0/MDoFmsI7tVc/s1600/Capture2.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_xRHNXt3iDHk/TGw4vBhkU4I/AAAAAAAAAnA/-rrQEB-9k38/s1600/Capture5.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="113" src="http://3.bp.blogspot.com/_xRHNXt3iDHk/TGw4vBhkU4I/AAAAAAAAAnA/-rrQEB-9k38/s320/Capture5.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;&lt;span style="background: none repeat scroll 0% 0% fuchsia;"&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This information can be interpreted as follows:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;"&lt;/span&gt;&lt;span style="background: none repeat scroll 0% 0% red; font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;/dev/disk0&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;" is representative of the first physical hard drive (attached to the system). It is determined based on size, volume name, and partition layout that this is the hard drive inside of the system. In this example, the physical device, "&lt;/span&gt;&lt;span style="background: none repeat scroll 0% 0% red; font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;/dev/disk0&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;" will be the &lt;b&gt;source&lt;/b&gt; of the acquisition. &amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;“&lt;span style="background: none repeat scroll 0% 0% aqua;"&gt;/dev/disk1&lt;/span&gt;” &lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;is representative of the second physical hard drive (attached to the system). It is determined based on size, volume name, and partition layout that this is &lt;b&gt;destination&lt;/b&gt; hard drive connected via USB to the system. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;On this hard drive there is one volume &lt;span style="background: none repeat scroll 0% 0% fuchsia;"&gt;disk1s1&lt;/span&gt; named &lt;span style="background: none repeat scroll 0% 0% fuchsia;"&gt;Evidence_Drive&lt;/span&gt;. This is the volume we will use to write the acquisition to.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;b&gt;&lt;i&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;However, before you can write to a volume you need to determine what the “mount point” of the volume is. A mount point is the connection the operating system uses to interact with a volume on a hard drive.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;6.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Mac OS will automatically create a mount point (with full read/write permissions) when a device is attached to the system with a recognizable file system. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;The mount point should be consistent with the &lt;span style="background: none repeat scroll 0% 0% fuchsia;"&gt;volume name&lt;/span&gt; appended to /Volumes/. The mount command can be used to verify this:&amp;nbsp; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;Ftechs-Mac-mini:~ root$&amp;nbsp; Mount&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;This will list all volumes mounted on the system:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_xRHNXt3iDHk/TGw4OlltgSI/AAAAAAAAAm8/JDKrpH_viW4/s1600/Capture4.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="74" src="http://1.bp.blogspot.com/_xRHNXt3iDHk/TGw4OlltgSI/AAAAAAAAAm8/JDKrpH_viW4/s320/Capture4.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;We see here that “&lt;/span&gt;&lt;span style="background: none repeat scroll 0% 0% yellow; font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;/Volumes/Evidence_Drive&lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;” &lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;is the full path of the mount point for volume “&lt;/span&gt;&lt;span style="background: none repeat scroll 0% 0% fuchsia; font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;disk1s1&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;” on the destination hard drive “&lt;/span&gt;&lt;span style="background: none repeat scroll 0% 0% aqua; font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;/dev/disk1&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;”. This is the &lt;b&gt;destination mount point.&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;This now establishes that we will be imaging (&lt;b&gt;source&lt;/b&gt;): &lt;/span&gt;&lt;span style="background: none repeat scroll 0% 0% red; font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;/dev/disk0&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt; and writing our acquisition image to (&lt;b&gt;destination mount point&lt;/b&gt;): &lt;/span&gt;&lt;span style="background: none repeat scroll 0% 0% yellow; font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;/Volumes/Evidence_Drive&lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;After you have determined the source and destination mount point, navigate to the destination mount point where the FTK CLI took resides:&lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt; Ftechs-Mac-mini:~ root$ cd &lt;span style="background: none repeat scroll 0% 0% yellow;"&gt;/Volumes/Evidence_Drive&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;7.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Execute the following command and flags to execute FTK CLI. This will acquire the source &lt;/span&gt;&lt;span style="background: none repeat scroll 0% 0% red; font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;/dev/disk0&lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;(physical hard drive inside of the computer) and save to&lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt; &lt;span style="background: none repeat scroll 0% 0% yellow;"&gt;/Volumes/Evidence_Drive&lt;/span&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;(on the destination hard drive volume) in .EO1 format and fragment every 4 GB with no compression&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; line-height: 115%;"&gt;Ftechs-Mac-mini:~ root$ ./ftkimager &lt;span style="background: none repeat scroll 0% 0% red;"&gt;/dev/disk0&lt;/span&gt; &lt;span style="background: none repeat scroll 0% 0% yellow;"&gt;/Volumes/Evidence_Drive/imagename&lt;/span&gt; –e01 –frag 4G –compress 0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;A full list of usage and options can be viewed on the man page. This can accessed from the command by:&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt; Ftechs-Mac-mini:~ root$ ./ftkimager help&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Approach 2: Secondary-boot Collection – Preparation:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Before you start you will need:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: Symbol; font-size: 10pt;"&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;An Intel-based Mac to use (examiner maEV0ne),&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: Symbol; font-size: 10pt;"&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;OS X 10.5.x or later installation DVD,&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: Symbol; font-size: 10pt;"&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;and a large enough external USB hard drive to install both OS X onto and contain the image(s) of the collection (apx. 320 gb +).&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;2.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;You will need to partition the USB hard drive with two volumes:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Volume 1 - Boot: Approximately 16 GBs formatted OS X Extended (Journaled) &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;2.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Volume 2 - Storage Area: Remainder of drive formatted Fat 32&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="center" class="MsoNoSpacing" style="margin-left: 0.5in; text-align: center;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Partition Layout Example:&lt;/span&gt;&lt;/div&gt;&lt;div align="center" class="MsoNoSpacing" style="margin-left: 0.5in; text-align: center;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="center" class="MsoNoSpacing" style="margin-left: 0.5in; text-align: center;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="center" class="MsoNoSpacing" style="margin-left: 0.5in; text-align: center;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="center" class="MsoNoSpacing" style="margin-left: 0.5in; text-align: center;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_xRHNXt3iDHk/TGw2BO7SHkI/AAAAAAAAAmw/KMArs96dAuA/s1600/Capture.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="66" src="http://2.bp.blogspot.com/_xRHNXt3iDHk/TGw2BO7SHkI/AAAAAAAAAmw/KMArs96dAuA/s400/Capture.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: Symbol; font-size: 10pt;"&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;One volume to install OSX which will be the boot partition. The second volume as a storage area that can be used to write your image(s) to.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: Symbol; font-size: 10pt;"&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;I would suggest using Apple’s Disk Utility, located at /Applications/Utilities/, to prepare this drive.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;3.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;To make the USB hard drive bootable it must have ownership enabled.&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="line-height: normal; margin: 0in 0in 0.0001pt 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Locate the 16 GB volume on your Mac desktop, right-click its icon, and select ‘Get Info’ from the pop-up menu. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="line-height: normal; margin: 0in 0in 0.0001pt 1in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="line-height: normal; margin: 0in 0in 0.0001pt 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;2.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;In the Info window that opens, expand the ‘Sharing &amp;amp; Permissions’ section, if it’s not already expanded. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.25in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoListParagraph" style="line-height: normal; margin: 0in 0in 0.0001pt 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;3.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Click the lock icon in the bottom right corner. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.25in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoListParagraph" style="line-height: normal; margin: 0in 0in 0.0001pt 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;4.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Enter your administrator password when asked. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.25in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoListParagraph" style="line-height: normal; margin: 0in 0in 0.0001pt 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;5.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Remove the check mark from ‘Ignore ownership on this volume.’ &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.25in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoListParagraph" style="line-height: normal; margin: 0in 0in 0.0001pt 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;6.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Close the Info panel. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.25in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoListParagraph" style="line-height: normal; margin: 0in 0in 0.0001pt 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;7.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Once you complete, your USB flash drive will be ready for you to install OS X.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;4.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Install OS X - Summarized&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Plug USB hard drive (prepared above) into Mac.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;2.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Put Install DVD in the Mac.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;3.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Reboot.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;4.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Choose to install OS X on the USB hard drive 16 GB partition, OSX Journaled Extended. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;5.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;You may want to customize the software packages that OS X will install to minimize disk space required for the installation.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;5.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;After install, test to make sure the Mac will boot from the secondary boot drive you just created instead of the internal hard drive. At start up hold down the “Option” key and you will be prompted with the boot options menu.&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;6.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Once you are booted to the USB hard drive, the secondary OSX boot drive, you will need to copy over the FTK CLI application onto it. You can use a flash drive to do this or just go online and download it if you are connected to the internet.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;7.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;The default Mac OS X installation has the "root" account disabled. Enable it by following the steps listed here: &lt;/span&gt;&lt;a href="http://www.spy-hill.com/%7Emyers/help/apple/EnableRoot.html"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;http://www.spy-hill.com/~myers/help/apple/EnableRoot.html&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;8.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Your secondary OSX boot drive is now created and has FTK CLI on it.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraph"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Approach 2: Secondary-boot Collection – Getting Started:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Plug the secondary OSX boot drive you created above into the Mac maEV0ne you would like to acquire. &lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;2.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Start the Mac up holding down &lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;the Option key at start up to get to the boot options menu. Select to boot to the external secondary OSX boot drive.&lt;/span&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;3.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Once booted, follow the steps listed above starting in Approach 1.3. In summary:&lt;/span&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;a.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Go to console.&lt;/span&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;b.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Switch to user root.&lt;/span&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;c.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;As illustrated below, identify the physical &lt;span style="background: none repeat scroll 0% 0% red;"&gt;source hard drive&lt;/span&gt; (hard drive inside of the computer)&lt;/span&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;d.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;As illustrated below, identify the destination &lt;span style="background: none repeat scroll 0% 0% aqua;"&gt;hard drive&lt;/span&gt;, &lt;span style="background: none repeat scroll 0% 0% fuchsia;"&gt;volume&lt;/span&gt;, and &lt;span style="background: none repeat scroll 0% 0% yellow;"&gt;mount point&lt;/span&gt; of the FAT32 storage-area volume on the Secondary-boot hard drive.&lt;/span&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Attached disks:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_xRHNXt3iDHk/TGw2u1n1IhI/AAAAAAAAAm0/MDoFmsI7tVc/s1600/Capture2.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="122" src="http://2.bp.blogspot.com/_xRHNXt3iDHk/TGw2u1n1IhI/AAAAAAAAAm0/MDoFmsI7tVc/s320/Capture2.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;&lt;span style="background: none repeat scroll 0% 0% fuchsia;"&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Mounted devices:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_xRHNXt3iDHk/TGw3SQi4SPI/AAAAAAAAAm4/eoWRTEy1Eww/s1600/Capture3.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="86" src="http://1.bp.blogspot.com/_xRHNXt3iDHk/TGw3SQi4SPI/AAAAAAAAAm4/eoWRTEy1Eww/s320/Capture3.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;e.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;Navigate to the location of the FTK CLI tool and execute the command with the proper usage and flags.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 1in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: 0.75in;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; line-height: 115%;"&gt;Ftechs-Mac-mini:~ root$ ./ftkimager &lt;span style="background: none repeat scroll 0% 0% red;"&gt;/dev/disk0&lt;/span&gt; &lt;span style="background: none repeat scroll 0% 0% yellow;"&gt;/Volumes/EV0-09027_F/imagename &lt;/span&gt;–e01 –frag 4G –compress 0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-4010139275480260413?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/4010139275480260413/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/08/ftk-imager-for-os-x-to-rescue.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/4010139275480260413'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/4010139275480260413'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/08/ftk-imager-for-os-x-to-rescue.html' title='FTK Imager (for OS X) to the Rescue'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_xRHNXt3iDHk/TGw4vBhkU4I/AAAAAAAAAnA/-rrQEB-9k38/s72-c/Capture5.PNG' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-6776789405012327650</id><published>2010-06-29T08:10:00.000-07:00</published><updated>2010-08-19T11:37:46.300-07:00</updated><title type='text'>MacBook Air Fun</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_xRHNXt3iDHk/TCoNNTOzmoI/AAAAAAAAAmo/p6NGJejvmUI/s1600/Untitled.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="191" src="http://1.bp.blogspot.com/_xRHNXt3iDHk/TCoNNTOzmoI/AAAAAAAAAmo/p6NGJejvmUI/s200/Untitled.gif" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;I had a small window of time the other day to image a Apple Macbook Air. It was like “my first time” so I felt it would be appropriate to do a little research about “how to turn it on” and “what buttons to press” to make sure things didn’t get sloppy ;-p&lt;br /&gt;&lt;br /&gt;I can’t emphasize how important it is to go into situations with more than one option. It’s like the old sang, “Why carry a tool box if you only have one tool in it?” After a little research, I came up with a Plan A and Plan B. Not talking about the &lt;a href="http://www.planbonestep.com/"&gt;Plan B - One-Step&lt;/a&gt; here :-)&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Before I jump into my procedures, let me note a few things: &lt;/b&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;   I knew ahead of time that this Macbook Air did not have an Apple Super Drive (external CD/DVD drive). I do not have an external CD/DVD drive or Apple Super Drive in my forensic kit. Maybe I need to get one!! Furthermore it is reported&amp;nbsp; that not all USB CD/DVD drives are compatible.The Macbook Air only has one USB port. This USB port is buried in the shell so not all thumb drives will physically fit into it. Yes, I had this problem… What can I say, Dav Nads has a BIG USB thumb drive!!&amp;nbsp; &lt;/li&gt;&lt;li&gt;Similar to the external CD/DVD drive issue, it is reported that some USB hubs do not let you let you boot from them. The one I tried was a Belkin Desktop Hub (Model F4U016) which comes with an external power supply to power the USB ports.&lt;/li&gt;&lt;li&gt;The Macbook Air does not have a Firewire port. Therefore, you CANNOT acquire using Targeted Disk Mode.&lt;/li&gt;&lt;li&gt;There is no eSata port, ethernet port, or PCMCIA slot &lt;/li&gt;&lt;/ul&gt;&lt;b&gt;Here’s what I tried:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;A) Forensic Linux Boot Disk to Acquire:&lt;br /&gt;&lt;br /&gt;We have an in-house Linux variant comparable to Helix, Knopix, Raptor that we use for boot acquisitions. Note that since I did not have an external CD/DVD drive it was a requirement that I load the Boot Disk into RAM since the laptop only has one USB port. I needed the one and only USB port free so I could plug in an external USB hard drive as a destination to save the image to. Our boot disk has  a “Load to RAM” option which allowed me to do this. I believe others do as well.&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Boot to Forensic Linux from USB thumb drive. &lt;/li&gt;&lt;li&gt;Load into RAM. Some boot disks have this option as noted above. &lt;/li&gt;&lt;li&gt;Remove USB thumb drive and plug USB storage hard drive in.&lt;/li&gt;&lt;li&gt;Image away.&lt;/li&gt;&lt;/ol&gt;Unfortunately, the specific chipset in the Macbook Air I was acquiring from was not compatible with my Linux boot disk. I found this interesting because it worked for a colleague a few months ago on an earlier MacBook Air model which was also Intel-based. Regardless, it was on to Plan B. I will note here that I have heard &lt;a href="http://forwarddiscovery.com/Raptor"&gt;Raptor &lt;/a&gt;works well booting in Mac environments. However, I did not have time to try it in the field and I do not think it has the option to load into RAM.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Here is what I did:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;B) Remove Hard Drive:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: inherit;"&gt;Before you get started note that for Rev A Macbook's I would expect you would find a PATA ZIF hard drive. For Rev B&amp;amp;C, you should find a SATA LIF hard drive. &lt;br /&gt;&lt;br /&gt;Unfortunately, I have not found a adapter yet for LIF interfaces. So stop reading here if you know that is what your working with. The only place I have seen an adapter advertised for purchase is here, but it has always been out of stock. I recently told that LIF adapters could also be purchased here but I have not personally verified this. If you don't have a adapter to interface with LIF and now looking for a plan C, check back for my next post on FTK's CLI tool for OSX.&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Times,'Times New Roman',serif; line-height: 15px;"&gt;&lt;update&gt;&lt;span style="font-family: inherit; font-size: small;"&gt; &lt;/span&gt;&lt;update&gt;&lt;br /&gt;&lt;/update&gt;&lt;/update&gt;&lt;/span&gt;&lt;ol&gt;&lt;li&gt;There is an excellent tutorial, written by Lee Whitfield, on Forensic 4cast documenting how to remove the hard drive from a Macbook Air. This can be found &lt;a href="http://forensic4cast.com/?p=135"&gt;here&lt;/a&gt;. Alternatively, there are a number of videos on YouTube. &lt;a href="http://www.youtube.com/watch?v=flNwzqIm6J8"&gt;This &lt;/a&gt;is the one I watched. &lt;/li&gt;&lt;li&gt;Whenever I take something a part, I like to draw a picture of where I extracted each piece/screw from. Something that may come in handy when putting it back together! It's also not a bad idea to tape the screws to the piece of paper. I actually had an experience were a person knocked the screws over once and I had to be real creative about putting the laptop back together. Live and learn LOL.&lt;/li&gt;&lt;li&gt;If the laptop has a SSD hard drive you will need a ZIF adapter. I recommend the one that &lt;a href="http://www.tableau.com/"&gt;Tableau&lt;/a&gt; sells (now owned by Guidance Software). If you use this one, it must be connected this way: To image a Samsung 1.8" drive, connect the Tableau TC20-3-2 ZIF cable to the adapter label face-up. Then connect the cable to the Samsung 1.8" drive, positioning the drive label face-up&lt;/li&gt;&lt;li&gt;Image the hard drive externally using hard drive duplicator or your tool of choice.&lt;/li&gt;&lt;li&gt;Put it back together!!&lt;/li&gt;&lt;/ol&gt;I will note that it has been reported that some Linux boot disks may temporary disable or render the one USB Port inactive. To reset the USB port, make sure the Mac is turned off.  Press and hold the following keys on the keyboard:  Shift, Control, Option (all on the bottom left side of the keyboard) and Press and hold the Power button (top right of the keyboard).  Hold for about 5 seconds and then release them all.  You will not see indication of anything.  Try to boot from the External Drive again.&lt;br /&gt;&lt;br /&gt;&lt;update&gt; I will document another collection option using FTK Imager CLI for OSX in my next post.&lt;update&gt; &lt;/update&gt;&lt;/update&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-6776789405012327650?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/6776789405012327650/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/06/mac-book-air-fun.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/6776789405012327650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/6776789405012327650'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/06/mac-book-air-fun.html' title='MacBook Air Fun'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_xRHNXt3iDHk/TCoNNTOzmoI/AAAAAAAAAmo/p6NGJejvmUI/s72-c/Untitled.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-3969773911512878321</id><published>2010-06-01T21:10:00.000-07:00</published><updated>2010-06-02T07:22:54.587-07:00</updated><title type='text'>Incident Response Questions</title><content type='html'>&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;meta content="text/html; charset=utf-8" http-equiv="Content-Type"&gt;&lt;/meta&gt;&lt;meta content="Word.Document" name="ProgId"&gt;&lt;/meta&gt;&lt;meta content="Microsoft Word 12" name="Generator"&gt;&lt;/meta&gt;&lt;meta content="Microsoft Word 12" name="Originator"&gt;&lt;/meta&gt;&lt;link href="file:///C:%5CUsers%5CNIDES%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml" rel="File-List"&gt;&lt;/link&gt;&lt;link href="file:///C:%5CUsers%5CNIDES%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx" rel="themeData"&gt;&lt;/link&gt;&lt;link href="file:///C:%5CUsers%5CNIDES%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml" rel="colorSchemeMapping"&gt;&lt;/link&gt;&lt;style&gt;&lt;!-- /* Font Definitions */ @font-face	{font-family:"Cambria Math";	panose-1:2 4 5 3 5 4 6 3 2 4;	mso-font-charset:1;	mso-generic-font-family:roman;	mso-font-format:other;	mso-font-pitch:variable;	mso-font-signature:0 0 0 0 0 0;}@font-face	{font-family:Calibri;	panose-1:2 15 5 2 2 2 4 3 2 4;	mso-font-charset:0;	mso-generic-font-family:swiss;	mso-font-pitch:variable;	mso-font-signature:-520092929 1073786111 9 0 415 0;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal	{mso-style-unhide:no;	mso-style-qformat:yes;	mso-style-parent:"";	margin-top:0in;	margin-right:0in;	margin-bottom:10.0pt;	margin-left:0in;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}p	{mso-style-noshow:yes;	mso-style-priority:99;	mso-margin-top-alt:auto;	margin-right:0in;	mso-margin-bottom-alt:auto;	margin-left:0in;	mso-pagination:widow-orphan;	font-size:12.0pt;	font-family:"Times New Roman","serif";	mso-fareast-font-family:"Times New Roman";}p.MsoNoSpacing, li.MsoNoSpacing, div.MsoNoSpacing	{mso-style-priority:1;	mso-style-unhide:no;	mso-style-qformat:yes;	mso-style-parent:"";	margin:0in;	margin-bottom:.0001pt;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph	{mso-style-priority:34;	mso-style-unhide:no;	mso-style-qformat:yes;	margin-top:0in;	margin-right:0in;	margin-bottom:10.0pt;	margin-left:.5in;	mso-add-space:auto;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParagraphCxSpFirst	{mso-style-priority:34;	mso-style-unhide:no;	mso-style-qformat:yes;	mso-style-type:export-only;	margin-top:0in;	margin-right:0in;	margin-bottom:0in;	margin-left:.5in;	margin-bottom:.0001pt;	mso-add-space:auto;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, div.MsoListParagraphCxSpMiddle	{mso-style-priority:34;	mso-style-unhide:no;	mso-style-qformat:yes;	mso-style-type:export-only;	margin-top:0in;	margin-right:0in;	margin-bottom:0in;	margin-left:.5in;	margin-bottom:.0001pt;	mso-add-space:auto;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}p.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, div.MsoListParagraphCxSpLast	{mso-style-priority:34;	mso-style-unhide:no;	mso-style-qformat:yes;	mso-style-type:export-only;	margin-top:0in;	margin-right:0in;	margin-bottom:10.0pt;	margin-left:.5in;	mso-add-space:auto;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}.MsoChpDefault	{mso-style-type:export-only;	mso-default-props:yes;	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}.MsoPapDefault	{mso-style-type:export-only;	margin-bottom:10.0pt;	line-height:115%;}@page Section1	{size:8.5in 11.0in;	margin:1.0in 1.0in 1.0in 1.0in;	mso-header-margin:.5in;	mso-footer-margin:.5in;	mso-paper-source:0;}div.Section1	{page:Section1;} /* List Definitions */ @list l0	{mso-list-id:70548561;	mso-list-type:hybrid;	mso-list-template-ids:373986162 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}@list l0:level1	{mso-level-tab-stop:none;	mso-level-number-position:left;	margin-left:.75in;	text-indent:-.25in;}@list l0:level2	{mso-level-number-format:alpha-lower;	mso-level-tab-stop:none;	mso-level-number-position:left;	margin-left:1.25in;	text-indent:-.25in;}@list l0:level3	{mso-level-number-format:roman-lower;	mso-level-tab-stop:none;	mso-level-number-position:right;	margin-left:1.75in;	text-indent:-9.0pt;}@list l1	{mso-list-id:191502412;	mso-list-type:hybrid;	mso-list-template-ids:8422642 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}@list l1:level1	{mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;}@list l2	{mso-list-id:233589889;	mso-list-type:hybrid;	mso-list-template-ids:2098222014 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}@list l2:level1	{mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;}@list l3	{mso-list-id:359473248;	mso-list-type:hybrid;	mso-list-template-ids:-1720038070 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}@list l3:level1	{mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;}@list l3:level2	{mso-level-number-format:alpha-lower;	mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;}@list l3:level3	{mso-level-number-format:roman-lower;	mso-level-tab-stop:none;	mso-level-number-position:right;	text-indent:-9.0pt;}@list l4	{mso-list-id:1001157709;	mso-list-type:hybrid;	mso-list-template-ids:461779288 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}@list l4:level1	{mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;}@list l5	{mso-list-id:1442410821;	mso-list-type:hybrid;	mso-list-template-ids:8422642 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}@list l5:level1	{mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;}@list l6	{mso-list-id:1573737383;	mso-list-type:hybrid;	mso-list-template-ids:1554283104 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}@list l6:level1	{mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;}ol	{margin-bottom:0in;}ul	{margin-bottom:0in;}--&gt;&lt;/style&gt;  &lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/_7xIX2GAysXA/R1PkxT5N_mI/AAAAAAAAAAM/T_R8Zz0YPyA/s1600-R/waterboarding.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="200" src="http://4.bp.blogspot.com/_7xIX2GAysXA/R1PkxT5N_mI/AAAAAAAAAAM/T_R8Zz0YPyA/s200-R/waterboarding.jpg" width="160" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;The next time your network gets p'owned&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt; don't choke your suspects with USB cables, just ask the same questions Dav Nads would!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="font-family: inherit; line-height: 200%;"&gt;&lt;span style="font-size: small;"&gt;&lt;u&gt;&lt;span style="line-height: 200%;"&gt;Understand the Nature of the Incident’s Background&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;1.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;What is the nature of the problem(s), as it has been observed so far?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;2.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;How was the problem(s) detected initially? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;3.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;When was it detected and by whom (build time line and list stake holders)?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;4.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Who is aware of the incident? What are their names and affiliation to the organization? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;5.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;What groups or people are internally affected or targeted by the incident? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;6.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Were other security incidents observed in the affected environment or the organization recently?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;7.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Is there any history of similar situations or patterns?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;8.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Who is designated as the primary incident response coordinator?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;9.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Who is authorized to make business decisions regarding the affected operations of the IT infrastructure?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;10.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;What theories exist for how the initial compromise occurred?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;11.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Are we aware of compliance or legal obligations tied to the incident? (e.g., PCI, breach notification laws, etc.)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit; line-height: 200%;"&gt;&lt;span style="font-size: small;"&gt;&lt;u&gt;&lt;span style="line-height: 200%;"&gt;Review the Initial Incident Survey’s Results&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;1.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;What analysis actions were taken during the initial survey when qualifying the incident?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;2.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;What commands or tools were executed on the affected systems as part of the initial survey?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;3.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;What measures were taken to contain the scope of the incident? (e.g. disconnected from the network)?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;4.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;What alerts were generated by the existing security infrastructure compromise (e.g. IDS , anti-virus, etc.)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;5.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;If logs were reviewed, what suspicious entries were found? What additional suspicious events or state information, was observed?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;u&gt;&lt;span style="line-height: 115%;"&gt;Technical Assessment to Determine Scope&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;i&gt;&lt;span style="line-height: 115%;"&gt;Infrastructure&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;1.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;The affected IT infrastructure components are physically located where?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;2.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Request/ Review Network Topology diagram. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;3.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Does an automated IT Asset Discovery tool exist? If not, account for all IT assets related to the compromise in the infrastructure &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;4.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Identify each Host by Name, network address (internal and external), O/S, and purpose, asset #, make, model, version, build, etc.)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;5.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Understand how the network functions: Firewalls, Domains, VPN, DMZ, Gateways, Access Points, Intrusion Detection systems, Intrusion Prevention systems, Proxy, Anti-Virus, Domain Controllers, Data Storage, E-mail systems, ERP systems, and etc. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;6.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Service provider, DNS, Internal IP Ranges, and external facing IP ranges.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;i&gt;&lt;span style="line-height: 115%;"&gt;Logging&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;1.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;What assets have the ability to log? What is turned on and what is off?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;a.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Network:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1.5in; text-indent: -1.5in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;i.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;&amp;nbsp;Firewall, &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1.5in; text-indent: -1.5in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;ii.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Routers, &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1.5in; text-indent: -1.5in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;iii.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Wireless Access Points,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1.5in; text-indent: -1.5in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;iv.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Domain Controller, &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1.5in; text-indent: -1.5in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;v.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;AV,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1.5in; text-indent: -1.5in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;vi.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;ID and/or IP Systems (IDPS),&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1.5in; text-indent: -1.5in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;vii.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Systems, &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1.5in; text-indent: -1.5in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;viii.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Network appliances, &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1.5in; text-indent: -1.5in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;ix.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;File Servers,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1.5in; text-indent: -1.5in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;x.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Backups,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1.5in; text-indent: -1.5in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;xi.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;b.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Physical: &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1.5in; text-indent: -1.5in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;i.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Building entry / exit, &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1.5in; text-indent: -1.5in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;ii.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Video surveillance, etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;2.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Are logs backed up or written over? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit; line-height: 200%;"&gt;&lt;span style="font-size: small;"&gt;&lt;i&gt;&lt;span style="line-height: 200%;"&gt;Security&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;1.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;What is the security posture of the affected IT infrastructure components? How recently, if ever, was it assessed for vulnerabilities?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;2.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;What security infrastructure components exist in the affected environment? (e.g., firewall, anti-virus, etc.) &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;3.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;How are the security components configured (Wireless, Firewall, DMZ, Segmentation, etc)?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;4.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Do computers have standard images/builds? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;a.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;OS versions and service patches?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;b.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Local and network policies?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;5.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Do servers have standard images/builds?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;a.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;OS versions and service patches?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;b.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Local and network policies?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;6.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;IDPS Systems Network and/or Host based? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;a.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;What kind? Version?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;b.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Passive or Reactive?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;7.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Anti-virus Network and/or Host based? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;a.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;What kind? Version? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;b.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Definition updating policies?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;8.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Password policies / account audits?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;9.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Wireless Access Point Security type (i.e. Authentication, encryption, etc.)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;10.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;E-mail Server and Security (i.e. Attachments Scanned, dumpster, retention)?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;11.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;File Servers? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;a.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Type? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;b.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Share permissions? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;c.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;File System? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;d.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Achieved/Backed up?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;12.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Guest and Remote access?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;13.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Backup Policies, routines, documentation, continuity plans, data storage?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit; line-height: 200%;"&gt;&lt;span style="font-size: small;"&gt;&lt;u&gt;&lt;span style="line-height: 200%;"&gt;Users&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraph" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;1.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Active Directory or eDirectory Listing: Active or Departed?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit; line-height: 200%;"&gt;&lt;span style="font-size: small;"&gt;&lt;u&gt;&lt;span style="line-height: 200%;"&gt;Prepare for Next Incident Response Steps&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;1.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Does the affected group or organization have specific incident response instructions or guidelines?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;2.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Does the affected group or organization wish to proceed with live analysis, or does it wish to start formal forensic examination?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;3.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;What tools are available to us for monitoring network or host-based activities in the affected environment?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;4.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;What backup-restore capabilities are in place to assist in recovering from the incident?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;5.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Who will be leading this effort from the Organization? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit; line-height: 200%;"&gt;&lt;span style="font-size: small;"&gt;&lt;u&gt;&lt;span style="line-height: 200%;"&gt;Communication Parameters&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraph" style="font-family: inherit; line-height: 200%; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;6.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;Communication mechanisms will be defined to communicate when handling incident. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; line-height: 200%; margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;7.&lt;span style="font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small; line-height: 200%;"&gt;What is your availability to schedule external regular progress updates? Who is responsible for leading them?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit; margin-left: 0.25in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraph" style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-3969773911512878321?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/3969773911512878321/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/06/incident-response-questions.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/3969773911512878321'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/3969773911512878321'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/06/incident-response-questions.html' title='Incident Response Questions'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_7xIX2GAysXA/R1PkxT5N_mI/AAAAAAAAAAM/T_R8Zz0YPyA/s72-Rc/waterboarding.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-4559022852658872621</id><published>2010-05-25T17:08:00.000-07:00</published><updated>2010-06-01T20:53:44.527-07:00</updated><title type='text'>DAV NADS @ CEIC IN VEGAS!!!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_xRHNXt3iDHk/S_xj1cclcUI/AAAAAAAAAmg/-z9wel_tnU8/s1600/untitled.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" gu="true" height="162" src="http://1.bp.blogspot.com/_xRHNXt3iDHk/S_xj1cclcUI/AAAAAAAAAmg/-z9wel_tnU8/s200/untitled.JPG" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Dav Nads is tweeting from the&amp;nbsp;CEIC conference in Las Vegas this week!! Holla @ me if your reading and check back for updates!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-4559022852658872621?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/4559022852658872621/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/05/dav-nads-ceic-in-vegas.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/4559022852658872621'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/4559022852658872621'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/05/dav-nads-ceic-in-vegas.html' title='DAV NADS @ CEIC IN VEGAS!!!'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_xRHNXt3iDHk/S_xj1cclcUI/AAAAAAAAAmg/-z9wel_tnU8/s72-c/untitled.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-5990182920823918291</id><published>2010-05-18T14:31:00.001-07:00</published><updated>2010-05-18T14:33:15.285-07:00</updated><title type='text'>Dav Nads gets Certified!!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_xRHNXt3iDHk/S_MHH-1EljI/AAAAAAAAAmY/aH6JSxC83iQ/s1600/davnads.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://1.bp.blogspot.com/_xRHNXt3iDHk/S_MHH-1EljI/AAAAAAAAAmY/aH6JSxC83iQ/s200/davnads.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;I have always been eager to learn and challenge myself to further develop intellectually.&amp;nbsp; Over the last 3 months, I challenged myself to obtain 3 professional certifications. Dav Nads is now EnCE, EnCEP, and ACE certified, Bit%hes!!&lt;br /&gt;&lt;br /&gt;Sorry it's been awhile.. I been working hard on my smarts. Dav Nads is BACK!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-5990182920823918291?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/5990182920823918291/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/05/dav-nads-gets-certified.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/5990182920823918291'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/5990182920823918291'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/05/dav-nads-gets-certified.html' title='Dav Nads gets Certified!!'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_xRHNXt3iDHk/S_MHH-1EljI/AAAAAAAAAmY/aH6JSxC83iQ/s72-c/davnads.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-811622392293818982</id><published>2010-02-11T13:46:00.000-08:00</published><updated>2010-02-11T13:47:48.379-08:00</updated><title type='text'>Dav Nads &amp; USB protection</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_xRHNXt3iDHk/S3R6ZlyhUeI/AAAAAAAAAlc/vS0AU3d3-k0/s1600-h/Untitled.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="111" src="http://2.bp.blogspot.com/_xRHNXt3iDHk/S3R6ZlyhUeI/AAAAAAAAAlc/vS0AU3d3-k0/s200/Untitled.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;The Windows operating system has a Registry setting that can add USB write protection to a computer system. It is like a switch that can be enabled to make use of the write protection or disabled to allow write processes. Check it out:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;ON!!&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\StorageDevicePolicies]&lt;br /&gt;&lt;br /&gt;"WriteProtect"=dword:00000001&lt;br /&gt;&lt;br /&gt;&lt;b&gt;OFF!!&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\StorageDevicePolicies]&lt;br /&gt;&lt;br /&gt;"WriteProtect"=dword:00000000&lt;br /&gt;&lt;br /&gt;Always write-blocking, never cock-blocking,&lt;br /&gt;&lt;br /&gt;Dav Nads&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-811622392293818982?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/811622392293818982/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/02/dav-nads-usb-protection.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/811622392293818982'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/811622392293818982'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/02/dav-nads-usb-protection.html' title='Dav Nads &amp; USB protection'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_xRHNXt3iDHk/S3R6ZlyhUeI/AAAAAAAAAlc/vS0AU3d3-k0/s72-c/Untitled.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-464192776751886764</id><published>2010-02-08T08:16:00.000-08:00</published><updated>2010-02-08T13:18:05.980-08:00</updated><title type='text'>GroupWise .. Who the F#$% knew this...??!!</title><content type='html'>I was out and about doing some "Live" GroupWise E-mail collections. For the living sake of me, I could not figure out how the #$% to "log out" of one users mailbox and log into another, from the client application.&lt;br /&gt;&lt;br /&gt;It ends up GroupWise has commands that you can use when you start the client. Quoted from &lt;a href="http://www.novell.com/documentation/gw6/?page=/documentation/gw6/gw6_userguide/data/aaqu6vm.html"&gt;Novell &lt;/a&gt;itself,&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;"Some of them are for your convenience, while others are necessary to run GroupWise on your particular hardware."&amp;nbsp;&lt;/blockquote&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_xRHNXt3iDHk/S3A6VBkFhWI/AAAAAAAAAlU/Re5peNLZ7Mk/s1600-h/groupwise_img.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xRHNXt3iDHk/S3A6VBkFhWI/AAAAAAAAAlU/Re5peNLZ7Mk/s320/groupwise_img.jpg" /&gt;&lt;/a&gt;Well if it was for my #$%#$% convince, why the hell wouldn't you just make a button somewhere or put this in the options box??? I didn't know you needed to be a freaking rocket scientist to administer the system.&lt;br /&gt;&lt;br /&gt;Well anyways, if you have the pleasure of logging into GroupWise this may come in handy. The switch you will need to use to re-activate the  login dialog box is: /@u-?&lt;br /&gt;&lt;br /&gt;A list of the other switches can be found in &lt;a href="http://www.novell.com/documentation/gw6/?page=/documentation/gw6/gw6_userguide/data/aaqu6vm.html"&gt;Novell's Documentation&lt;/a&gt;.&lt;br /&gt;&lt;h3 class="HEAD-TITLE"&gt;Using a GroupWise Startup Switch&lt;/h3&gt;&lt;ol class="STEPLIST"&gt;&lt;li class="STEP"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=254295412164493706&amp;amp;postID=464192776751886764" name="aaqukbn"&gt;&lt;/a&gt; Right-click the GroupWise icon on the desktop &amp;gt; click Properties.  &lt;/li&gt;&lt;li class="STEP"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=254295412164493706&amp;amp;postID=464192776751886764" name="aaqukdy"&gt;&lt;/a&gt; Click the Shortcut tab.  &lt;/li&gt;&lt;li class="STEP"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=254295412164493706&amp;amp;postID=464192776751886764" name="aaqukf8"&gt;&lt;/a&gt; In the Target text box, after the GroupWise executable, type a space, type the startup switch(es), then click OK.&lt;br /&gt;&lt;br /&gt;&lt;div class="STEP"&gt;&lt;br /&gt;&lt;/div&gt;&lt;ol class="STEPLIST"&gt;&lt;li class="STEP"&gt;Separate multiple startup switches with a space, like this:&lt;br /&gt;&lt;br /&gt;&lt;pre class="CODESAMPLENARROW"&gt;J:\GRPWISE.EXE /ph-&lt;i class="VARIABLE"&gt;pathname&lt;/i&gt; /@u-?&lt;/pre&gt;&lt;div class="STEP"&gt;In this example, /ph- is the startup switch to specify the path to the post office. The &lt;i class="VARIABLE"&gt;pathname&lt;/i&gt; is the path to the post office. The /@u-? switch is used to display a login dialog box a user can supply with login information whenever he or she opens GroupWise. This switch is useful when two or more users share a workstation but have separate GroupWise Mailboxes.&lt;/div&gt;&lt;div class="STEP"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/li&gt;&lt;li class="STEP"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=254295412164493706&amp;amp;postID=464192776751886764" name="aaquknn"&gt;&lt;/a&gt; Restart GroupWise.&lt;br /&gt;&lt;br /&gt;&lt;div class="STEP"&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;Holla, DNAds &lt;/span&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-464192776751886764?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/464192776751886764/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/02/groupwise-who-f-knew-this.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/464192776751886764'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/464192776751886764'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/02/groupwise-who-f-knew-this.html' title='GroupWise .. Who the F#$% knew this...??!!'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_xRHNXt3iDHk/S3A6VBkFhWI/AAAAAAAAAlU/Re5peNLZ7Mk/s72-c/groupwise_img.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-6750181779807118990</id><published>2010-01-29T11:26:00.000-08:00</published><updated>2010-01-29T12:24:55.987-08:00</updated><title type='text'>Exchange 2007 Collections  ....ugggh!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_xRHNXt3iDHk/S2M9GVqKJzI/AAAAAAAAAlM/Qkx6PMZaW-w/s1600-h/Untitled.gif" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="200" src="http://1.bp.blogspot.com/_xRHNXt3iDHk/S2M9GVqKJzI/AAAAAAAAAlM/Qkx6PMZaW-w/s200/Untitled.gif" width="185" /&gt;&lt;/a&gt;&lt;/div&gt;Once upon a time, DAV NADS was collecting mailboxes from a 64-bit Exchange 2007 server environment (LOL!). I wanted to take a moment to highlight a few things I learned that I hope you may find helpful.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;“ExMerge” no longer exists. As of 2007, this functionality has been integrated into Exchange’s Management Shell Cmdlet’s (available in SP1 and SP2).&lt;br /&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Cmdlets is NOT compatible with 64-bit servers ONLY 32-bit. I will describe a “work-around” I used in detail below.&lt;br /&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;The CMD you will need to know and use is called: Export-Mailbox. &lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;One notable advantage of “Export-Mailbox” over “ExMerge” is it does NOT have issues exporting mailboxes over the 2GB PST limit.&lt;br /&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Export-Mailbox will include “Dumpster” data on Exchange 2007. On Exchange 2010 is does NOT…!&lt;br /&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Just like ExMerge, before you can use Export-Mailbox, you need the proper account rights.&lt;/li&gt;&lt;/ul&gt;&lt;ol&gt;&lt;ol&gt;&lt;li&gt;Local Administrator rights.&lt;/li&gt;&lt;li&gt;Exchange Server Administrator Role on the target Exchange 2007 mailbox server.&lt;/li&gt;&lt;li&gt;Full access to the mailboxes against which the import/export operation is run.&lt;/li&gt;&lt;/ol&gt;&lt;/ol&gt;&lt;ul&gt;&lt;li&gt;It is quite cumbersome, but STILL possible to install Exmerge on a client machine and connect to Exchange 2007 remotely. A tutorial on this procedure is here:&amp;nbsp; www.exchangeinbox.com/article.aspx?i=88&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;The work-around I followed to the 64-bit limitation was quite simple:&lt;br /&gt;&lt;br /&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Because I could not export to PST but still had the ability to export to a mailboxes, we created a “dummy” mailbox and exported to this mailbox. For example, the below command will export ALL e-mail from the “davnads@blogspot.com” identity to the “MyData” folder in the “DummyMailbox”.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Export-Mailbox -Identity davnads@blogspot.com -TargetMailbox DummyMailbox -TargetFolder MyData&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; After we exported the data to a “DummyMailbox” we authenticated to the mailbox with Outlook.&lt;br /&gt;&lt;br /&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Manually created a new&amp;nbsp; “Local” Outlook Data File (PST file).&lt;br /&gt;&lt;br /&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Manually copied over all e-mail from the Exchange “DummyMailbox” to the “Local” PST file.&lt;br /&gt;&lt;br /&gt;Now, if you are working with a 32-bit Exchange server, this is the command you need to use to export the contents of a Exchange mailbox to a local PST file:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Export-Mailbox -Identity &lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;davnads@blogspot.com&lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt; -PSTFolderPath C:\PSTFiles\davnads.pst&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Dav Nads the Exchange Guy.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-6750181779807118990?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/6750181779807118990/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/01/exchange-2007-holla.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/6750181779807118990'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/6750181779807118990'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/01/exchange-2007-holla.html' title='Exchange 2007 Collections  ....ugggh!'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_xRHNXt3iDHk/S2M9GVqKJzI/AAAAAAAAAlM/Qkx6PMZaW-w/s72-c/Untitled.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-3897538660634902462</id><published>2010-01-26T17:34:00.000-08:00</published><updated>2010-01-26T21:33:51.283-08:00</updated><title type='text'>Don't go fishing for server data.. Just ask Dav Nads!!!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;No one likes to go fishing for data, so this is the basic list of information I request from IT administrators before I start cutting data!! If you don't get answers, check out this secret millitarty&amp;nbsp;&lt;a href="http://www.break.com/usercontent/2007/8/Secret-Waterboarding-Instructional-Video-351603.html"&gt;instructional interrogation video&lt;/a&gt; on water boarding. I'm just saying!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_xRHNXt3iDHk/S1_QB3vjcYI/AAAAAAAAAlA/USsdpB6pZYo/s1600-h/Picture+2.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xRHNXt3iDHk/S1_QB3vjcYI/AAAAAAAAAlA/USsdpB6pZYo/s320/Picture+2.jpg" /&gt;&lt;/a&gt;1.) Listing of Active Directory and/or User Names for all Custodians.&lt;br /&gt;&lt;br /&gt;2.) For all Custodians, a Permission listing of all Personal and Group Shares they have write-access to (i.e.: Custodian Dav Nads has write access to directory ABC on the File Server XXX).&lt;br /&gt;&lt;br /&gt;3.) Lotus/Exchange Mailbox name(s) for all custodians (i.e.: DavNadz.nsf) and servers they reside on.&lt;br /&gt;&lt;br /&gt;4.) If possible, Local and Admin&amp;nbsp; Security ID files and passwords to access the respected custodian’s local and server mailboxes.&lt;br /&gt;&lt;br /&gt;Always catching and never fishing,&lt;br /&gt;&lt;br /&gt;DNads&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-3897538660634902462?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/3897538660634902462/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/01/dont-go-fishing-for-server-data-just.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/3897538660634902462'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/3897538660634902462'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/01/dont-go-fishing-for-server-data-just.html' title='Don&apos;t go fishing for server data.. Just ask Dav Nads!!!'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_xRHNXt3iDHk/S1_QB3vjcYI/AAAAAAAAAlA/USsdpB6pZYo/s72-c/Picture+2.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-594854794730510181</id><published>2010-01-25T14:25:00.000-08:00</published><updated>2010-01-26T21:19:12.765-08:00</updated><title type='text'>"Dav" + "Nads" =  "Dav Nads" - Use excel to CONCATENATE!</title><content type='html'>&lt;div style="font-family: inherit;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://futonreport.net/wp-content/uploads/2008/10/87665dude-wtf-posters1z.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="320" src="http://futonreport.net/wp-content/uploads/2008/10/87665dude-wtf-posters1z.jpg" width="208" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;CONCATENATE is the method of joining two or more text strings into one text string.&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;The syntax in Excel 2007 is: CONCATENATE (text1,text2,...)&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;Text1, text2, ...&amp;nbsp;&amp;nbsp; are 2 to 255 text items to be joined into a single text item. The text items can be text strings, numbers, or single-cell references.&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;Always saving time,&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;Dav Nads.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-594854794730510181?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/594854794730510181/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/01/dav-nads-dav-nads-use-excel-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/594854794730510181'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/594854794730510181'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/01/dav-nads-dav-nads-use-excel-to.html' title='&quot;Dav&quot; + &quot;Nads&quot; =  &quot;Dav Nads&quot; - Use excel to CONCATENATE!'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-1325422497646417834</id><published>2010-01-21T16:48:00.000-08:00</published><updated>2010-01-22T19:21:30.090-08:00</updated><title type='text'>Nads does HFSX with Encase</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_xRHNXt3iDHk/S1povnAyApI/AAAAAAAAAkg/5o4VR9oWx5w/s1600-h/osx.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://1.bp.blogspot.com/_xRHNXt3iDHk/S1povnAyApI/AAAAAAAAAkg/5o4VR9oWx5w/s200/osx.jpg" width="173" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;Encase does &lt;b&gt;NOT &lt;/b&gt;support the &lt;a href="http://en.wikipedia.org/wiki/HFS_Plus"&gt;OS X Extended (HFSX) &lt;/a&gt;file system... but it's on the feature request list!! So leave it to Dav Nads to find a workaround. It's not what I would call a forensically sound procedure, but if you document it, this 3 step hack may be what it's worth. &lt;br /&gt;&lt;br /&gt;1. Convert your image over to a RAW format like DD.&lt;br /&gt;2. Fire up a &lt;a href="http://www.x-ways.net/winhex/"&gt;Hex Editor&amp;nbsp;&lt;/a&gt;&lt;br /&gt;3. Modify 2 bytes in the 3rd sector of the HFSX partition by changing the second byte of the sector from a 'x' into a '+' and changing the byte value of the 4th byte from \x05 into \x04. &lt;br /&gt;&lt;br /&gt;Congratulations. You just changed the HFSX partition into a &lt;a href="http://en.wikipedia.org/wiki/HFS_Plus"&gt;HFS Plus (HFS+)&lt;/a&gt; partition... which Encase readily supports :-)&lt;br /&gt;&lt;br /&gt;NOTE this little byte swap is not the only difference between the two files systems! For instance, HFSX supports case sensitivity so Encase may not properly handle file names (i.e.: Evidence.txt vs. evidence.txt). This means proceed with your own Nads.&lt;br /&gt;&lt;br /&gt;Your welcome,&lt;br /&gt;&lt;br /&gt;Dav Nads&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-1325422497646417834?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/1325422497646417834/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/01/nads-does-hfsx-with-encase.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/1325422497646417834'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/1325422497646417834'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/01/nads-does-hfsx-with-encase.html' title='Nads does HFSX with Encase'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_xRHNXt3iDHk/S1povnAyApI/AAAAAAAAAkg/5o4VR9oWx5w/s72-c/osx.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-3270774634377164542</id><published>2010-01-20T15:15:00.000-08:00</published><updated>2010-01-21T12:21:28.055-08:00</updated><title type='text'>Dav the Data Carver Nads (from Carver County, MN)</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://pix.epodunk.com/locatorMaps/mn/MN_20905.gif" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="200" src="http://pix.epodunk.com/locatorMaps/mn/MN_20905.gif" width="200" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-size: large;"&gt;Two &lt;/span&gt;products I wanted to give a shout out to this week are in result to a recent initiative involving the recovery of video fragments from unallocated space. &lt;a href="http://subrosasoft.com/OSXSoftware/index.php?main_page=product_info&amp;amp;products_id=1"&gt;File Salvage&lt;/a&gt; ($89.95) for the Mac's and &lt;a href="http://www.stellarinfo.com/file-recovery.htm"&gt;Stellar Phoenix&lt;/a&gt; ($69.99) for the PC's.&lt;br /&gt;&lt;br /&gt;Overall, I was surprisingly impressed with my experience and results. Both tools were straight forward and simple to use. From a technical perspective, I liked how both products integrated a categorized predefined signatures list into the User Interface. So I was quickly able to identify file signatures pertaining to my request. Additionally, both tools allowed me to preview results and selectively export them.&lt;br /&gt;&lt;br /&gt;On the not so great side, I found there was a few discrepancies between what the manufactures stated on their website and what was provided. For example, it was stated that File Salvage supported (DD, E01, NTFS, HFS, etc..) and actually it only supported whole-disks or mountable DMG files. So I had to use FTK Imager to converter my E01 to DD and then rename the DD to a DMG. Also, note that this does not work on segmented files. &lt;br /&gt;&lt;br /&gt;Another thing I would like to note is when reviewing corrupted and fragmented video files, some viewers work better then others... I had bad luck using the standard &lt;a href="http://www.microsoft.com/windows/windowsmedia/default.mspx"&gt;Windows Media Player&lt;/a&gt;, good luck using &lt;a href="http://download.cnet.com/Media-Player-Classic/3000-2139_4-10518778.html"&gt;Windows Media Player Classic&lt;/a&gt;, and THE BEST luck using &lt;a href="http://www.videolan.org/vlc/index.html"&gt;VNC player&lt;/a&gt;. Using a combination of all three viewers was what I found the ultimate solution.&lt;br /&gt;&lt;br /&gt;Also, something unique pertaining to this request was that file volumes were requested for any recovered data. In respect to files that where “partially” recovered, the file volume (MBs) would be reported on the basis of what could be recovered. In most instances this value can be assumed to be less than the “original”. &lt;br /&gt;&lt;br /&gt;A more precise estimate of the “original” file volume can be calculated based on the meta data value of video length. For instance, a partially recovered video is 2 minutes in length and 10 MB in volume. However, the files meta data value for video length is 20 minutes. Therefore, you could assume 10 MB /2 mins&amp;nbsp; = approximately 5 MB per 1 minute frame. So the actual movie size would be more like 100 MB.&lt;br /&gt;&lt;br /&gt;Enough said,&lt;br /&gt;&lt;br /&gt;Dav Nadsss&lt;br /&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt;"&gt;&lt;span style="color: navy;"&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-3270774634377164542?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/3270774634377164542/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/01/dav-data-carver-nads.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/3270774634377164542'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/3270774634377164542'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/01/dav-data-carver-nads.html' title='Dav the Data Carver Nads (from Carver County, MN)'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-128804746857133985</id><published>2010-01-14T14:54:00.000-08:00</published><updated>2011-08-26T17:14:02.618-07:00</updated><title type='text'>Working with Lotus Notes...</title><content type='html'>&lt;a href="http://www.nsftools.com/misc/NotesCanDoThat.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="113" src="http://www.nsftools.com/misc/NotesCanDoThat.png" width="320" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So let’s start with the BASICS here… &lt;span style="font-size: large;"&gt;what the heck&lt;/span&gt; does a NSF file stand for and &lt;span style="font-size: large;"&gt;what does it DO&lt;/span&gt;? &lt;b&gt;&lt;i&gt;Notes Storage Facilit&lt;/i&gt;y&lt;/b&gt; and it is used primarily for &lt;i&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;E-MAIL (and other stuff)...&lt;/b&gt;!! Kind of like a PST or OST!&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;span style="font-size: large;"&gt;Now &lt;/span&gt;&lt;/u&gt;since we have taken care of that, let’s jump into the common types of security and protection we commonly encounter while handling NSF files in an OFFLINE environment… As outlined below, there are 3 major classifications, Local Security, Local Encryption, and Message Level Encryption.&lt;br /&gt;&lt;br /&gt;The first step is to identify how a NSF file is protected, if protected at all. Now, this sounds like a simple task but it’s actually quite tedious and can be the utmost challenging part… Let’s take a look at the options.&lt;br /&gt;&lt;br /&gt;Common sense says “Hey, let’s just crack open a duplicate/working-copy to see what happens?!” Actually, this is not a bad idea... Based on the error message you receive alone, if any, you can instantly determine how a NSF file is protected! For example;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;"You are not authorized to access that database"&lt;/i&gt;, and fails to open, means you’re dealing with &lt;b&gt;Local Security&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;"This database has local access protection &amp;amp; you are not authorized to access it locally”&lt;/i&gt;, and fails to open, means you’re dealing with &lt;b&gt;Local Encryption&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;Unfortunately, there’s no way to determine if &lt;b&gt;Message Level Encryption&lt;/b&gt; is in place based on opening the NSF file alone. Since it’s the actual message is encrypted vs. the container itself. &lt;br /&gt;&lt;br /&gt;When is this &lt;u&gt;NOT &lt;/u&gt;such a great idea? How about when you have 2,000 NSF files to analyze!! So, there are two alternatives that I’m aware of...&lt;br /&gt;&lt;br /&gt;One, just push all the messages through your “processing tool” of choice and hope to G-d it has intelligence (like Dav Nads!) smart enough to report on exceptions. In other words, what it couldn’t process due to errors or security protection. This can then be analyzed on a file by file, case by case, basis as outlined above. &lt;br /&gt;&lt;br /&gt;The second option is to automate this process with a bit of scripting. Again to my knowledge there are no tools on the shelf that will do this stand alone. But let’s just say I know it can be done pretty easily because I have seen a proof of concept for this. Feel free to ping me for more info but in a nutshell you just need to know how to query the ACL table.&lt;br /&gt;&lt;br /&gt;So now before we jump into how to resolve these types of protection and encryption, let’s briefly&lt;span style="font-size: large;"&gt; explore how they work…&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Inside of a NSF file is an &lt;b&gt;Access Control Levels (ACL)&lt;/b&gt; table. These settings control the type of actions a user can perform on the contents of a database and on the database itself. Access levels range from Local Encryption, which encrypts the database, No Access, which prevents a user from opening a database without proper credentials, to Manager, which lets a user read, create, and edit the ACL and all documents in the database. Further details on these setting can be found &lt;a href="http://publib.boulder.ibm.com/infocenter/sametime/v8r0/index.jsp?topic=/com.ibm.help.sametime.802.doc/IMLU/st_adm_security_basicpwdauth_c.html"&gt;at IBM&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;So in summary,&lt;/span&gt; ACLs limit access to the NSF files. The ACL define what actions each type of user is allowed to take.&lt;br /&gt;&lt;br /&gt;Finally, here are the options available to remove these types of protection/security:&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Local Security&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Use the associated ID File and Password to manually remove the ACL permissions protecting the NSF file.&lt;br /&gt;&lt;br /&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; What happens if you don’t have it? Use a Lotus Notes local security removal tool.&amp;nbsp; For instance, Securase,&amp;nbsp; removes local security from NSF files. It's simple to use and helps you save time running around trying to find the correct user id and password to open a local NSF file.&lt;br /&gt;&lt;br /&gt;Again this process, can be automated :-)&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Local Encryption&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Use the associated ID File and Password combination to manually remove the ACL permissions encrypting the NSF file.&lt;br /&gt;&lt;br /&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; What happens if you don’t have the password? Well, here a little trick that works sometimes… when a user is prompted change their password from the default to their personal, it does not change the actual key used for encryption.&lt;br /&gt;&lt;br /&gt;Therefore, the ID file that the admin generated the day the employee started or the local ID file, with the default password of 'password1', or the user's last name, or whatever the admin likes to use, will still decrypt the NSF file that is protected by the new, unknown password. &lt;br /&gt;&lt;br /&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Despite what some tools claim, there are no tools that will “magically” decrypt encrypted Lotus Notes Databases. However, Access Data’s Password Recovery Toolkit will brute-force attack the ID file. I have never successfully accomplished this but in theory it should work. Just might take some time :-)&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Message Level Encryption&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;With the exception of asking for the password or brute-force attacks, I’m not aware of any way to challenge message level encryption . Please help me out with this if you can!!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Yours Truly,&lt;br /&gt;&lt;br /&gt;Dav Nads&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-128804746857133985?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/128804746857133985/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/01/working-with-lotus-notes.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/128804746857133985'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/128804746857133985'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/01/working-with-lotus-notes.html' title='Working with Lotus Notes...'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-6814085161111266654</id><published>2010-01-08T14:51:00.000-08:00</published><updated>2010-01-08T14:56:50.238-08:00</updated><title type='text'>dNADS got BRAINS!!!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_xRHNXt3iDHk/S0e37U1RCJI/AAAAAAAAAkY/X5DYYJ7LbYc/s1600-h/1.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xRHNXt3iDHk/S0e37U1RCJI/AAAAAAAAAkY/X5DYYJ7LbYc/s200/1.jpg" /&gt;&lt;/a&gt;... scored 11/10 on the "Cables, plugs, wires, cords...that connect your TV, audio, computer, and iPod" TEST. If you think you got SMARTS about computer forensics this is where is all starts... LEARN THE SYSTEMS, LEARN THE SOFTWARE, then ya got SYNERGY. The boss once put it like that ;-)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.mentalfloss.com/quiz/quiz.php?q=852"&gt;check it OUT!&amp;nbsp; &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-6814085161111266654?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/6814085161111266654/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/01/dav-nads-is-smarter-then-you.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/6814085161111266654'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/6814085161111266654'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/01/dav-nads-is-smarter-then-you.html' title='dNADS got BRAINS!!!'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_xRHNXt3iDHk/S0e37U1RCJI/AAAAAAAAAkY/X5DYYJ7LbYc/s72-c/1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-3520318130563940805</id><published>2010-01-07T21:54:00.000-08:00</published><updated>2010-01-08T14:44:57.970-08:00</updated><title type='text'>Dear PhotoShop, Thank You for makin the prettiest Dav Nads in the Planet</title><content type='html'>Dear &lt;a href="http://gizmodo.com/5442309/dear-photoshop-thank-you-for-the-prettiest-woman-in-the-planet"&gt;Gizmodo&lt;/a&gt;,&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;These photochop girls look GrEaT! But I'm REALLY looking forward to the sexiest man in the planet contest starring... DAV NADS!!&lt;br /&gt;&lt;br /&gt;"What would happen if Angelina Jolie and Chalize Theron had a baby with Megan Fox, Monica Belucci, and twelve hot actresses? I don't know if this would be the result, but I'd like to&lt;br /&gt;&lt;/div&gt;&lt;div&gt;watch them try." ThiS IS wHAT would HAPpEn...&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_xRHNXt3iDHk/S0e0r1Sfn-I/AAAAAAAAAkQ/6XiMwqyUik8/s1600-h/1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xRHNXt3iDHk/S0e0r1Sfn-I/AAAAAAAAAkQ/6XiMwqyUik8/s320/1.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a class="cssButton" href="javascript:void(0)" id="publishButton" onclick="if (this.className.indexOf(&amp;quot;ubtn-disabled&amp;quot;) == -1) {var e = document['postingForm'].publish;(e.length) ? e[0].click() : e.click(); if (window.event) window.event.cancelBubble = true; return false;}" target=""&gt;&lt;div class="cssButtonOuter"&gt;&lt;div class="cssButtonMiddle"&gt;&lt;div class="cssButtonInner"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-3520318130563940805?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/3520318130563940805/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/01/dear-photoshop-thank-you-for-prettiest.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/3520318130563940805'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/3520318130563940805'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/01/dear-photoshop-thank-you-for-prettiest.html' title='Dear PhotoShop, Thank You for makin the prettiest Dav Nads in the Planet'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_xRHNXt3iDHk/S0e0r1Sfn-I/AAAAAAAAAkQ/6XiMwqyUik8/s72-c/1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-1821922139198710421</id><published>2010-01-05T08:20:00.000-08:00</published><updated>2010-01-05T08:20:47.220-08:00</updated><title type='text'>GodMode</title><content type='html'>By creating a new folder in Windows 7 and renaming it with a certain text string at the end, users are able to have a single place to do everything from changing the look of the mouse pointer to making a new hard-drive partition.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_xRHNXt3iDHk/S0NmmnvjHTI/AAAAAAAAAj4/lB2WZxF4s40/s1600-h/gd.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_xRHNXt3iDHk/S0NmmnvjHTI/AAAAAAAAAj4/lB2WZxF4s40/s200/gd.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;The trick is also said to work in Windows Vista, although some are warning that although it works fine in 32-bit versions of Vista, it can cause 64-bit versions of that operating system to crash.&lt;br /&gt;&lt;br /&gt;To enter "GodMode," one need only create a new folder and then rename the folder to the following:&lt;br /&gt;&lt;blockquote&gt; GodMode.{ED7BA470-8E54-465E-825C-99712043E01C}&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-1821922139198710421?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/1821922139198710421/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/01/godmode.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/1821922139198710421'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/1821922139198710421'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/01/godmode.html' title='GodMode'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_xRHNXt3iDHk/S0NmmnvjHTI/AAAAAAAAAj4/lB2WZxF4s40/s72-c/gd.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-2083047734666411887</id><published>2010-01-03T00:22:00.000-08:00</published><updated>2010-01-07T21:55:55.907-08:00</updated><title type='text'>twenty-ten</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_xRHNXt3iDHk/SxWhAC8lhKI/AAAAAAAAAiY/0Weuj_kVOt0/s1600/ninja.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_xRHNXt3iDHk/SxWhAC8lhKI/AAAAAAAAAiY/0Weuj_kVOt0/s320/ninja.png" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="color: red;"&gt;twistin joysticks, rolling trackballs N' pushing big buttons. my handle is nads and i work the sketch pads. flip that switch, wack that biatch, this aint no computer glitch. im simpimply a boy genious that plays the keyboard...&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;D_NADS&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-2083047734666411887?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/2083047734666411887/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2010/01/twenty-ten.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/2083047734666411887'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/2083047734666411887'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2010/01/twenty-ten.html' title='twenty-ten'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_xRHNXt3iDHk/SxWhAC8lhKI/AAAAAAAAAiY/0Weuj_kVOt0/s72-c/ninja.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-4073210087449832183</id><published>2009-12-22T05:25:00.000-08:00</published><updated>2010-01-02T22:18:22.261-08:00</updated><title type='text'>US airforce p'owned with $26 data carving tool... LOL!!!</title><content type='html'>It was reported last week by a &lt;a href="http://news.google.com/news/search?aq=f&amp;amp;um=1&amp;amp;cf=all&amp;amp;ned=us&amp;amp;hl=en&amp;amp;q=ROVER+video"&gt;number of sources&lt;/a&gt;, that Iraqi insurgents found a way to INTERCEPT airplane (and drone) video feeds with $26.00 SHAREWARE software...LOL!!!! The software in the spotlight is called &lt;a href="http://www.skygrabber.com/en/index.php"&gt;SkyGraber&lt;/a&gt;. Essentially, this is just a little data carving tool... It connects to your satellite connection and carves out known file types from the air. One just happening to be unencrypted video feeds! The best thing to compare it to is a network sniffer.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_xRHNXt3iDHk/SzDM1QuVxDI/AAAAAAAAAjw/I99wX8ITwp4/s1600-h/air.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_xRHNXt3iDHk/SzDM1QuVxDI/AAAAAAAAAjw/I99wX8ITwp4/s400/air.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;The amazingly insecure protocol the government uses is called: Remotely Operated Video Enhanced Receiver (ROVER). This technology was deployed in 2002, "Since then, nearly every airplane in the American fleet - from F-16 and F/A-18 fighters to A-10 attack planes to Harrier jump jets to B-1B bombers has been outfitted with equipment that lets them transmit to ROVERs. Thousands of ROVER terminals have been distributed to troops in Afghanistan and Iraq..." -&lt;a href="http://www.wired.com/dangerroom/2009/12/not-just-drones-militants-can-snoop-on-most-us-warplanes/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+WiredDangerRoom+%28Blog+-+Danger+Room%29"&gt;Wired&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;An encryption package can be added to the ROVER; however, not all troops have the encryption package. The latest ROVER model being tested by the Pentagon comes equipped with two advanced encryption packages. Sources &lt;a href="http://www.armytimes.com/news/2009/12/army_uav_hack_122009w/"&gt;report&lt;/a&gt;, an official document puts a completion date to secure the feeds by 2014 :-/&lt;br /&gt;&lt;br /&gt;...Not to mention, this all came to about, when the military kept finding hours and hours of it's &lt;b&gt;&lt;i&gt;OWN&lt;/i&gt;&lt;/b&gt; surveillance videos from computers it was imaging out in the field... &lt;br /&gt;&lt;br /&gt;YUPPPP!!!!&lt;br /&gt;&lt;br /&gt;-Dav NADS&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-4073210087449832183?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/4073210087449832183/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2009/12/us-airforce-powned-with-26-data-carving.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/4073210087449832183'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/4073210087449832183'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2009/12/us-airforce-powned-with-26-data-carving.html' title='US airforce p&apos;owned with $26 data carving tool... LOL!!!'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_xRHNXt3iDHk/SzDM1QuVxDI/AAAAAAAAAjw/I99wX8ITwp4/s72-c/air.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-2630663008697295069</id><published>2009-12-14T09:57:00.000-08:00</published><updated>2009-12-14T18:09:43.199-08:00</updated><title type='text'>NEW Advanced Format gives ya 11% MORE capacity on your Hard Drive!</title><content type='html'>&lt;a href="http://cache.gawker.com/assets/images/4/2009/12/500x_wdadvancedformat.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="55" src="http://cache.gawker.com/assets/images/4/2009/12/500x_wdadvancedformat.jpg" width="320" /&gt;&lt;/a&gt;Western Digital has a fancy new way to format hard drives. This consists of changing your hard drives sector size to 4KB that uses a pooled Sync/DAM header and ECC blocks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-2630663008697295069?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/2630663008697295069/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2009/12/new-advanced-format-gives-ya-11-more.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/2630663008697295069'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/2630663008697295069'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2009/12/new-advanced-format-gives-ya-11-more.html' title='NEW Advanced Format gives ya 11% MORE capacity on your Hard Drive!'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-3651668221967977126</id><published>2009-12-09T12:43:00.000-08:00</published><updated>2009-12-09T12:47:15.237-08:00</updated><title type='text'>Dav Nad's on Sharing ;-)</title><content type='html'>&lt;div style="font-family: inherit;"&gt;A situation arose yesterday where a deliverable, Microsoft Office Excel workbook, needed to get out the door under a tight deadline. I had a team of 5 resources at my disposal to assist with the project. However, given the nature of the complexity and manual task at hand, it would have just made things more time consuming and convoluted by delegating work out to each resource. So I thought to myself it would be amazing if we could put this workbook in a neutral location where we could all work on this task collectively and see each other’s changes and monitor progress.&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;a href="http://1.bp.blogspot.com/_xRHNXt3iDHk/SyAMAFZOlsI/AAAAAAAAAjA/byXf-WncaLA/s1600-h/default.gif" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_xRHNXt3iDHk/SyAMAFZOlsI/AAAAAAAAAjA/byXf-WncaLA/s320/default.gif" /&gt;&lt;/a&gt;&lt;br /&gt;So I recalled that Microsoft Office 2007 had the capability of doing this. So I took the workbook, placed it on file server that resides on our LAN that everyone has access to. I then “Shared” the workbook to the specified “users” I wanted to delegate “write-access” to and setup the settings associated with how to save and update the changes within the workbook. In all, this process took me about 10 minutes to setup and test.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-family: inherit;"&gt;The end result was this amazing feat&lt;/span&gt;ure allowed me to delegate work efficiently while maintaining a management oversight. Work Smarter not Harder with Sharing!&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit; line-height: normal;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit; line-height: normal;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;o:p&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://office.microsoft.com/en-us/excel/HP100968331033.aspx"&gt;Here is a link to Microsoft's detailed documentation on this feature.&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-3651668221967977126?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/3651668221967977126/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2009/12/dav-nads-on-sharing.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/3651668221967977126'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/3651668221967977126'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2009/12/dav-nads-on-sharing.html' title='Dav Nad&apos;s on Sharing ;-)'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_xRHNXt3iDHk/SyAMAFZOlsI/AAAAAAAAAjA/byXf-WncaLA/s72-c/default.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-5279775454346286737</id><published>2009-12-03T16:18:00.001-08:00</published><updated>2009-12-03T20:41:57.706-08:00</updated><title type='text'>Encase and Windows 7, Server 2008</title><content type='html'>The Remote Desktop Protocol and Encase Forensic do not play well together in Windows 7 and Server 2008. &lt;br /&gt;&lt;br /&gt;The traditional fix to this in XP and Server 2003 was to use the MSTSC command with a /console flag (or /admin for later service packs) to carry out console mode. However this does not work anymore. So I did a little research...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.posterjet.com/_images/dongle.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="135" src="http://www.posterjet.com/_images/dongle.jpg" width="200" /&gt;&lt;/a&gt;&lt;span style="font-family: inherit; font-size: small;"&gt;It's &lt;a href="https://support.guidancesoftware.com/node/1229"&gt;stated &lt;/a&gt;on Guidance's website that&amp;nbsp; "&lt;i&gt;EnCase is &lt;u&gt;not officially supported&lt;/u&gt; running over Remote Desktop due to the manner in which the Remote Login Account is given access to the System devices&lt;/i&gt;". A discussion with one of their support representatives and some messages on their forum in fact further confirmed that Encase has never supported RDP (in any of their releases). &lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt; BUT, Guidance then goes to say in the same article that "&lt;i&gt;IF the RDP configuration does not work the only alternative is to purchase the SAFE NAS (Network Authentication Server) to license EnCase over the network.&lt;/i&gt;" Well, if that's not a contradicting statement, I don't know what is! So they are saying its not supported but if you want to make it work you can BUY something they sell to make it work? As a user this makes me shake my head and as a shareholder, I would be lying if I said I wasen't smiling :-)&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;Some say this is a licensing strategy, a method to prevent multiple users from using multiple instances of encase off of one license. But I don't see how that type of "abuse" is even technically possible under the current limitation of RDP and Encase only working in console mode. So I don't buy that really. I think the reason it does not work in Windows 7 and 2008 server is because of something that has changed in the O/S. I'm not sure what this is but I'm going to look into it.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;So here's a solution I purpose to Guidance. Migrate over to a system like Access Data's License Manager and Code Meter dongle (hold on, did I just say something good about AD?). With Access Data's License Manager system a user has the ability to transfer/update licenses from and to their dongles. Ideally, one could use a dongle normally and then if one wanted to use RDP, they could migrate their license over from the dongle to the NAS Safe. Then vice versa. &lt;/span&gt;&lt;span style="font-size: small;"&gt;Damn I think that is genius! LOL But this would sure make people happy!&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;Well enough of that, here's something good. I have 2 round about workarounds for Win 7 and 2008 Server to get RDP working - &lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;ol style="font-family: inherit;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Disable Fast User Switching, Disable User Account Controls, start up your instance of Encase Forensic, open your case up/start your processing. THEN, remote in using the "mstsc /admin" command and log in as the same user you have an instance of Encase already running under. This works.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Now, you can always use a VNC or PCAnywhere application to accomplish this as well. Works like a charm.&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div style="font-family: inherit;"&gt;But neither of these are practical solutions. Welp, back to XP for me! &lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;Dav Nads&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;- Posted using BlogPress from my iPhone&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-5279775454346286737?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/5279775454346286737/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2009/12/encase-and-windows-7-server-2008.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/5279775454346286737'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/5279775454346286737'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2009/12/encase-and-windows-7-server-2008.html' title='Encase and Windows 7, Server 2008'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-4135940499264981153</id><published>2009-12-03T07:38:00.001-08:00</published><updated>2009-12-03T09:59:02.930-08:00</updated><title type='text'>Did ya know this?</title><content type='html'>In Windows Vista and 7 when using device manager to do a "full format" it will actually zero out the drive. That's a legit REAL wipe! "Quick format" remains the same, it only wacks out the volume boot record.&lt;br /&gt;&lt;br /&gt;Sounds like an easy way to wipe hard drives :-) I'm curious how fast it is?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/941961"&gt;http://support.microsoft.com/kb/941961&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Dav Nads&lt;br /&gt;-from my iPhone&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-4135940499264981153?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/4135940499264981153/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2009/12/did-ya-know-this.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/4135940499264981153'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/4135940499264981153'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2009/12/did-ya-know-this.html' title='Did ya know this?'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-717865864749533948</id><published>2009-12-02T20:52:00.000-08:00</published><updated>2009-12-03T08:02:44.104-08:00</updated><title type='text'>SharePoint Collections can be tricky!</title><content type='html'>&lt;a href="http://pariswells.com/blog/wp-content/uploads/2009/03/deploying-microsoft-office-sharepoint-server-2007-21.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="200" src="http://pariswells.com/blog/wp-content/uploads/2009/03/deploying-microsoft-office-sharepoint-server-2007-21.png" width="200" /&gt;&lt;/a&gt;I had an opportunity to collect data from a Microsoft SharePoint (SP) server yesterday... Sounds ez, right? Sure it should be with all the top-notch vendors out there that have integrated SP connectivity into their e-Discovery products...&amp;nbsp;&amp;nbsp; &lt;a href="http://news.corporate.findlaw.com/prnewswire/20090917/17sep20091037.html"&gt;Kazeon Systems&lt;/a&gt;, &lt;a href="http://blogs.findlaw.com/technologist/2009/09/top-5-latest-ediscovery-developments.html"&gt;KPMG&lt;/a&gt;, &lt;a href="http://www.krollontrack.com/news-releases/?getPressRelease=61218"&gt;Kroll&lt;/a&gt;,&amp;nbsp; &lt;a href="http://www.avepoint.com/landing-page/"&gt;AvePoint&lt;/a&gt;, &lt;a href="http://www.cmswire.com/cms/enterprise-cms/autonomy-supports-ediscovery-with-new-collection-to-the-cloud-solution-006067.php"&gt;Autonomy &lt;/a&gt;to just name a few (click on the links to go their press releases). &lt;br /&gt;&lt;br /&gt;Well what happens when the SP server you are collecting from is not in a live production environment... In fact, it’s just a dusty old’ .E01 (Encase format) image of a system you collected a year ago?&lt;br /&gt;&lt;br /&gt;…Well based on my market research, there's not much out there that’s going to be able to help you. Nonetheless, I can't imagine there even being a demand for this type of one-off collection in the market place. So on that note, here is some food for thought and research about the various collection approaches of SP databases under these unique circumstances.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Approach 1&lt;/b&gt;: Leverage virtualization technology by using Liveview and VMware Server to boot the image natively. Subsequently, start the SP services, and remotely collect site(s) with any one of the widely available tools listed above. Well, hold your horses their speedy!! This sure sounds like a great approach; however, you need to take account for a number of variables that make this approach a tad bit complicated. To name a few:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Does the image consist of a physical or logical acquisition? If it’s logical, yup move onto approach two, can’t boot that up one up. &lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Is it physical? Well is it a RAID..? Yeah, can’t boot that up either without a serious fight, move on to approach two.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Is the image segmented… or in the wrong format? Start merging/converting those files.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Don’t know the password to log into the system? Eh, you can try to crack it.. with a boot CD.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;b&gt;Approach 2&lt;/b&gt;: Extract relevant SP data from the image and implant it into a existing controlled SP environment. First step here is to crack that image open and start identifying some significant information.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;What version of SP and SQL is installed? This can generally be found by looking in the registry or associated “program files” directory.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;What are the SP files I’m looking for? Each SP database is identified by two files: the database file, which has a .mdf filename extension, and the transaction log file, which has a .ldf extension.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Where are the SP files stored? If you have a default Windows SharePoint Services installation, the database files are in the \Program FilesMicrosoft SQL Server\MSSQL$SHAREPOINT\Data directory. You will typically find the following 4 files in that directory:&lt;/li&gt;&lt;/ul&gt;&lt;ol&gt;&lt;ol&gt;&lt;li&gt;STS_Config.mdf&lt;/li&gt;&lt;li&gt;STS_Config_log.LDF&lt;/li&gt;&lt;li&gt;STS_Computer_Name_1.mdf&lt;/li&gt;&lt;li&gt;STS_Computer_Name_1_log.LDF&lt;/li&gt;&lt;/ol&gt;&lt;/ol&gt;Now that you have identified the various databases and configuration files, extract them from the image.&lt;br /&gt;&lt;br /&gt;The next step is to install the same version of SP, SQL, and operating system that is found in the image file on a computer/server in your controlled lab environment. This might be overkill but effective!&lt;br /&gt;&lt;br /&gt;Generally after you get things installed, you will need to turn off SP services, disconnect the default database, copy over the extracted files and do the switchero. Then, start the services back up and connect the database. This process is well documented in Microsoft’s TechNet &lt;a href="http://technet.microsoft.com/en-us/library/cc512725.aspx"&gt;article&lt;/a&gt;. Keep in mind that you may need to repair the database because it may not have been properly detached during the point of collection and in result corrupted.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Approach 3:&lt;/b&gt; Let’s say that neither approach worked out. Well I’m going to assume you successfully extracted the relevant SP data (as outlined in Approach 2) from the image. Given that assumption, download the &lt;a href="http://blog.dreamdevil.com/index.php/category/free-softwares/"&gt;Sharepoint 2003 and 2007 Database Exporter tool&lt;/a&gt;. This tool allows you to point to a SP database, view contents, and export. An alternative tool is called &lt;a href="http://mindsharpblogs.com/james/archive/2005/01/20/189.aspx"&gt;SharePoint Database Explorer and SPExport&lt;/a&gt; which does the same thing. Both solutions are well documented.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Approach 4 - Catch All:&lt;/b&gt; If all else fails, go back to the damn live server and recollect!! &lt;br /&gt;&lt;br /&gt;For all four of the approaches outlined, I strongly suggest to validate and perform quality control testing.&lt;br /&gt;&lt;br /&gt;-Dav Nads&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-717865864749533948?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/717865864749533948/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2009/12/font-definitions-font-face-font.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/717865864749533948'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/717865864749533948'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2009/12/font-definitions-font-face-font.html' title='SharePoint Collections can be tricky!'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-6154843784937606745</id><published>2009-12-01T15:04:00.000-08:00</published><updated>2010-01-07T21:56:14.681-08:00</updated><title type='text'>knock knock</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_xRHNXt3iDHk/SxWhAC8lhKI/AAAAAAAAAiY/0Weuj_kVOt0/s1600/ninja.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;span style="color: lime;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_xRHNXt3iDHk/SxWhAC8lhKI/AAAAAAAAAiY/0Weuj_kVOt0/s320/ninja.png" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="color: lime;"&gt;phish, snort, spoof, tunnel, boom, p'ownd! dav nads is knocking while that firewall trying to be blocking. logged in as root and out with the loot. my intrusions make illusions cause your vulnerabilities compile my&amp;nbsp;credibility's. alwayz leaving traces from outer space, with null to chase, dnads plays hide n go' seek for the geeks :-p&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-6154843784937606745?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/6154843784937606745/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2009/12/knock-knock.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/6154843784937606745'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/6154843784937606745'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2009/12/knock-knock.html' title='knock knock'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_xRHNXt3iDHk/SxWhAC8lhKI/AAAAAAAAAiY/0Weuj_kVOt0/s72-c/ninja.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-5876509911137994177</id><published>2009-11-26T13:36:00.000-08:00</published><updated>2009-11-26T13:39:40.155-08:00</updated><title type='text'>Linux, Mount them segmented DD file Images!!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://static.commentcamarche.net/en.kioskea.net/faq/images/0-UjU8AuT6-linux-online-inc-full-s-.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://static.commentcamarche.net/en.kioskea.net/faq/images/0-UjU8AuT6-linux-online-inc-full-s-.png" width="166" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;To mount split/segmented DD files in Linux you can use the "&lt;a href="http://en.wikipedia.org/wiki/Mdadm"&gt;mdadm&lt;/a&gt;" command along with the "&lt;a href="http://en.wikipedia.org/wiki/Loop_device"&gt;losetup&lt;/a&gt;" command. &amp;nbsp;For example, if I have six split image files in a directory called Images:&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;losetup /dev/loop0 /mnt/Images/image.000&lt;br /&gt;&lt;/div&gt;&lt;div&gt;losetup /dev/loop1 /mnt/Images/image.001&lt;br /&gt;&lt;/div&gt;&lt;div&gt;losetup /dev/loop2 /mnt/Images/image.002&lt;br /&gt;&lt;/div&gt;&lt;div&gt;losetup /dev/loop3 /mnt/Images/image.003&lt;br /&gt;&lt;/div&gt;&lt;div&gt;losetup /dev/loop4 /mnt/Images/image.004&lt;br /&gt;&lt;/div&gt;&lt;div&gt;losetup /dev/loop5 /mnt/Images/image.005&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The command to mount it would look like this: &lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;mdadm --build --auto=part -verbose /dev/md1 --level=linear -n6 /dev/loop[0-5]&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you are mounting a hard drive with two partitions, partition1 is on "/dev/md1p1" and partition2 is on "/dev/md2p2". &lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-Dav Nads &lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-5876509911137994177?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/5876509911137994177/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2009/11/linux-mount-split-dd-file-images.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/5876509911137994177'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/5876509911137994177'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2009/11/linux-mount-split-dd-file-images.html' title='Linux, Mount them segmented DD file Images!!'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-7532134632083209798</id><published>2009-11-22T21:51:00.000-08:00</published><updated>2009-11-23T07:48:21.352-08:00</updated><title type='text'>Call the Paparazzi... COFEE was LeAkEd!!</title><content type='html'>&lt;a href="http://cache.gizmodo.com/assets/images/4/2008/04/cruzerhacks.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="197" src="http://cache.gizmodo.com/assets/images/4/2008/04/cruzerhacks.jpg" width="200" /&gt;&lt;/a&gt;&lt;span style="border-collapse: collapse;"&gt;OMG is right..!! Microsoft's super-secret Computer Online Forensic Evidence Extractor ("COFEE")&amp;nbsp; available to Law Enforcement only, was leaked into the torrents last week... LOL! ABOUT TIME IS ALL THAT I HAVE TO SAY!&lt;br /&gt;&lt;br /&gt;It was about a year ago when I first heard about this tool. The press releases poured COFEE out like this..&lt;br /&gt;&lt;br /&gt;"With COFEE, law enforcement agencies without on-the-scene computer forensics capabilities can now more easily, reliably, and cost-effectively collect volatile live evidence. An officer with even minimal computer experience can be tutored—in less than 10 minutes—to use a pre-configured COFEE device. This enables the officer to take advantage of the same common digital forensics tools used by experts to gather important volatile evidence, while doing little more than simply inserting a USB device into the computer.&lt;br /&gt;&lt;br /&gt;The fully customizable tool allows your on-the-scene agents to run more than 150 commands on a live computer system. It also provides reports in a simple format for later interpretation by experts or as supportive evidence for subsequent investigation and prosecution. And the COFEE framework can be tailored to effectively meet the needs of your particular investigation."&lt;br /&gt;&lt;br /&gt;To say the least, the tool was intellectually intriguing. I WANTED A COPY for Chanukah!! Unfortunately, I couldn't have one because I was not in Law Enforcement and was living in China at the time (without a whole lot to do). So, I decided to do some research and start programming a COFEE of my own :-) Well, that turned into a long drawn out project called BOOP. I'm saving BOOP for a later date and blog entry of its own.&lt;/span&gt;&lt;br /&gt;&lt;span style="border-collapse: collapse;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;div style="margin: 0px;"&gt;&lt;span style="border-collapse: collapse;"&gt;As for COFEE, let's say I saw it!!! My thoughts, It's nothing but a simple GUI wrapper for a # of Microsoft SysInternal, Windows XP, and other misc. freeware&amp;nbsp;command-line&amp;nbsp;tools. It facilitates batch execution of these utilities and customized payloads. It does not even include a tool to dump physical memory. Honestly, looks like a&amp;nbsp;amateur&amp;nbsp;high school programming project. I had dreams of it being stealthy, sexy, ninja like, super secret, high tech, and a ultimate&amp;nbsp;computer forensic swiss army knife. As I'm sure you can tell, I feel really&amp;nbsp;disappointed&amp;nbsp;and let down here. I think the last time I felt this way was when my&amp;nbsp;girlfriend cheated on me. LOL.&amp;nbsp;&lt;span style="border-collapse: separate; font-family: 'Lucida Grande'; font-size: 13px; line-height: 19px;"&gt;&lt;span style="border-collapse: collapse; font-family: Times; font-size: 16px; line-height: normal;"&gt;&lt;span style="background-color: red;"&gt;&lt;span style="color: white;"&gt;15 MB of trash pretty much sums that tool up.&lt;span style="background-color: white;"&gt; &amp;nbsp;&lt;/span&gt;&lt;span style="color: black;"&gt;&lt;span style="background-color: white;"&gt;Thanks Microsoft, for ruining my life. Now, back to whole-disk imaging computers.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;-This one is for my high school programming class .&lt;br /&gt;&lt;br /&gt;Dav Nads&lt;br /&gt;&lt;/div&gt;&lt;span style="border-collapse: collapse;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-7532134632083209798?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/7532134632083209798/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2009/11/omg-is-right.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/7532134632083209798'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/7532134632083209798'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2009/11/omg-is-right.html' title='Call the Paparazzi... COFEE was LeAkEd!!'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-1505107914699749403</id><published>2009-11-17T21:54:00.000-08:00</published><updated>2009-12-06T12:11:33.823-08:00</updated><title type='text'>OSX Mail and E-Discovery ..</title><content type='html'>Whats up NERDZ! Did ya miss me?? Since I wrote about OSX last week, I thought I would keep things in the ROM... LOL! I'm starting to see more and more Macs in the field and less and less "know how" out in the field to deliver! By no means do I claim to be a expert BUT my first computer was a Apple 2E, second was a Performa 410 and third was a power Macintosh 6400. So I'm just saying... Ms. Apple and I have a little history together :-p &lt;br /&gt;&lt;br /&gt;I want to talk about OS X mail here. This is a subject that I feel is not well documented in the community as it pertains to e-Discovery. The fact is I don't know ANY end-to-end e-Discovery appliances/and or solutions that properly handles and processes OSX mail in all variations and native formats. This means I find myself MANUALLY migrating OSX mail to our dear all mighty PST quite frequently. In this blog, I will explore the various common formats of OSX mail and options available to migrate your data to PST format. Ultimately, meeting the requirements and working within the limitations of our e-Discovery software.&lt;br /&gt;&lt;br /&gt;In OS X 10.3 (Panther), all messages for each inbox, are stored in &lt;b&gt;.MBOX&lt;/b&gt; format. All you need to do is identify these and convert to PST with your favorite MBOX to PST migration utility. It's that simple! I suggest using Aid4Mail and exercising the option to "recover deleted items". Remember it's important to preserve file structure during export and migration.&lt;br /&gt;&lt;br /&gt;One of the most compelling reasons to upgrade to OS X 10.4 (Tiger) is because of it's amazing indexing and search features. Apple's Mail.app leveraged this powerful searching ability with Mail 2.0. However, to allow for speedy indexing and searching of e-mails via Spotlight, Apple had to split those large .MBOX files into individual &lt;b&gt;.EMLX&lt;/b&gt; files. So you will find ONE .EMLX file for EVERY e-mail. These EMLX files are stored, by default, in the following location. Note that multiple users may have mail accounts.&lt;br /&gt;&lt;br /&gt;&lt;user&gt;/Library/Mail/&lt;/user&gt;&lt;br /&gt;&lt;br /&gt;Now there are a few options to migrate .EMLX files over to the "other side". The first approach, use a e-mail migration utility of your choice to migrate the data.&amp;nbsp; Again, Aid4Mail does a good job at this. This approach assumes you have already exported your data (maintaining file structure) or mounted the image.&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;The second approach takes into account that some e-Discovery software WILL accept .EML as a valid message type input format. Also, let's be honest, who wants manually convert each extention for every email. Not me!! So lets do this this...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;If your on a Mac: Launch the Terminal, change into the directory the .EMLX files are located (ie. cd ~&lt;user&gt;/Library/Mail/) and execute this command to batch rename all the files:&lt;/user&gt;&lt;br /&gt;&lt;br /&gt;for file in *.emlx ; do mv $file `echo $file | sed 's/\(.*\.\)emlx/\1eml/'` ; done&lt;br /&gt;&lt;br /&gt;If your on a PC: Launch DOS, change into the directory the EMLX file are located, and execute this command to batch rename all the files:&lt;br /&gt;&lt;br /&gt;ren *.emlx *.eml&lt;br /&gt;&lt;br /&gt;.EMLX and .EML are transparent in format because the messages are stored in pure plaintext. Therefore, renaming the file extension, as demonstrated in the above approach, works great if your software supports the .EML format. &lt;br /&gt;&lt;br /&gt;NOW off to the races, what happens if the custodian uses IMAP? In addition to seeing .EMLX files you will see .&lt;b&gt;EMLXPART &lt;/b&gt;and&amp;nbsp;&lt;b&gt; PARTIAL.EMLX&lt;/b&gt; files. That's a total of three file formats that are used to manage IMAP accounts. That means there are now four file formats you need to take account to during your identification phase. Let's examine these two new formats, .EMLXPART and PARTIAL.EMLX.&lt;br /&gt;&lt;br /&gt;An emlxpart file is an attachment, either an image, a document or an HTML version of a message. It doesn’t contain the metadata which is included in an emlx file. This means attachments are stripped from .EMLX files and stored separately as these emlxpart files. It's file name is same number as the corresponding emlx file. For example, Cybergirl223 sends me a picture of her today. Her message is locally cached in my Mail folder as 473.emlx and the attachment as 473.2.emlxpart. Make sense?&lt;br /&gt;&lt;br /&gt;In IMAP accounts, a third file type, partial.emlx,&amp;nbsp; also sometimes appears. This is for partially locally-cached copies messages on the IMAP server, saved for indexing or something.&lt;br /&gt;&lt;br /&gt;Migrating these 3 files is a little more time and resource consuming as some of the other approaches. This consists of two steps; Migrate everything to MBOX and the secondly migrate the MBOX to PST. &lt;br /&gt;&lt;br /&gt;To start, there is only one tool that I'm aware of that entirely migrates .EMLX, EMLXPART, and PARTIAL.EMLX files while persevering folder structure and attachments. This tool is called "Emailchemy" and can be purchased here: http://www.weirdkid.com/products/emailchemy/index.html&lt;br /&gt;&lt;br /&gt;After you have converted to your loose e-mail files to MBOX, then again use your tool of choice (I think you know what mine is by now) to migrate to PST. &lt;br /&gt;&lt;br /&gt;Well that's all I have on this topic. Make sure you account for all four file types discussed; .&lt;b&gt;MBOX, .EMLX, .EMLXPART, and PARTIAL.EMLX&lt;/b&gt;&amp;nbsp; during your identification and/or pre-processing phases - then migrate over accordingly :-) Also, remember the importance of verifying your results when migrating data. I like to tell people if you migrate A to Z you should be able to migrate from Z to A. This is one of simplest&amp;nbsp; forms of logic and basic validation. &lt;br /&gt;&lt;br /&gt;hope u enjoyed, all the best, dnasty&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-1505107914699749403?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/1505107914699749403/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2009/11/osx-mail-and-e-discovery.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/1505107914699749403'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/1505107914699749403'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2009/11/osx-mail-and-e-discovery.html' title='OSX Mail and E-Discovery ..'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-454874090885062491</id><published>2009-11-11T17:14:00.000-08:00</published><updated>2009-11-11T17:25:01.861-08:00</updated><title type='text'>Reminder</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_xRHNXt3iDHk/SvthSuI0WiI/AAAAAAAAAiQ/lfbEZY3hrTE/s1600-h/ninja.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xRHNXt3iDHk/SvthSuI0WiI/AAAAAAAAAiQ/lfbEZY3hrTE/s320/ninja.png" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="color: #cc0000;"&gt;24" inch rims and 240-pin DIMMs. spinning platters and pullin magnetic chatter. flying down the system bus i hit the i7 with thrust. some say i overclock but i know its cause i aint stock. my case flowin liquid and your girl blowin somethin, dav nads be energy efficient while your girl being coefficient. from the circuit boards to the cords, u get outscored. nibble on nads just dropped banner ads!&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-454874090885062491?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/454874090885062491/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2009/11/24-inch-rims-and-240-pin-dimms.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/454874090885062491'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/454874090885062491'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2009/11/24-inch-rims-and-240-pin-dimms.html' title='Reminder'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_xRHNXt3iDHk/SvthSuI0WiI/AAAAAAAAAiQ/lfbEZY3hrTE/s72-c/ninja.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-8868851958789076140</id><published>2009-11-11T09:50:00.000-08:00</published><updated>2009-12-06T11:46:32.296-08:00</updated><title type='text'>Mac Parallels</title><content type='html'>&lt;div style="color: black; font-family: inherit;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_xRHNXt3iDHk/SvsYUd325qI/AAAAAAAAAiI/NI8mtjh10Qw/s1600-h/stuff-white-ppl-like.jpg.jpeg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_xRHNXt3iDHk/SvsYUd325qI/AAAAAAAAAiI/NI8mtjh10Qw/s200/stuff-white-ppl-like.jpg.jpeg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;When i aint speaking dictionary attacks or prefetching unicode on the snatch. I'm actually working on the blog. my bouyie, Christian Lander, got a job too. he's droppin text like "Stuff White People Like" where # 40 is a shout out just for Apple Macs. So, heres one for ya - &lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b style="background-color: lime; color: white;"&gt;E-discovery - HOW tO get my f#$%ing data out of Mac Parallels!!!&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The most "popular" format of virtual storage is VMware's .VMDK format. Encase does a great job at supporting these in native format by automatically mounting em. However, what about the not so cool formats like Parallels? Well Guidance has it on their far future "feature request" list at number 4,332,545 (guessestimate) to support it sometime in the near future.&lt;br /&gt;&lt;br /&gt;Now the big question is how do you get that data out?? Here are my notes on a couple of approaches:&lt;br /&gt;&lt;br /&gt;1.) Manually identify the .HDD and .PVS file extensions associated with the Parallels application in your case. Create a file-ext condition in Encase to accomplish fast and efficiently.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;HDD &lt;/b&gt;ext - During the creation, the virtual machine acquires a virtual hard disk file with the .hdd extension.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;PVS &lt;/b&gt;ext - A virtual machine configuration file that contains information about the virtual machine resources, devices and other settings.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Don't see those, but you are seeing .HDS files? &lt;/b&gt;you can rename these to HDD. &lt;a href="http://kb.parallels.com/en/4680"&gt;Check out this good tutorial.&amp;nbsp;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;2.) Extract relevant Parallels data to your work space while preserving folder structure to avoid file name collisions.&lt;br /&gt;&lt;br /&gt;3.) Install Parallels on your examiner machine.&lt;br /&gt;&lt;br /&gt;A free 30 day demo is available at &lt;a href="http://download.parallels.com/"&gt;http://download.parallels.com&lt;/a&gt;. Don't ask me this voids some EULA bs cause whatever - just saying yo. If all possible, install a version consistent with the custodian's machine. You can check version by analyzing the .PLIST and/or .PDF user manual artifacts found in the Parallels application folder.&lt;br /&gt;&lt;br /&gt;4.) Parallels has developed a special utility for increasing the virtual hard disk capacity and managing its properties - this tool is called &lt;a href="http://download.parallels.net/doc/Parallels_Image_Tool_User_Guide.pdf"&gt;Parallels Image Tool.exe&lt;/a&gt; and is included with a standard install.&lt;br /&gt;&lt;br /&gt;5.) You will need to use this tool to change the properties of your .HDD file. Execute, select "manage..", point to your .HDD file, and convert to plain format.&lt;br /&gt;&lt;br /&gt;...This will change the file from a expandable image format to raw disk type.&lt;br /&gt;&lt;br /&gt;6.) Rename the extension of the .HDD file to a .VMDK and bring into encase as a loose file. Whalaaa you should see data!!? Otherwise you can use a free program like &lt;a href="http://www.ltr-data.se/opencode.html#ImDisk"&gt;ImDisk&lt;/a&gt; to mount the converted hard disk image. This even has support for "read-only" mode.&lt;br /&gt;&lt;br /&gt;FYI - this is just one approach and just like FTK, it does not always work.. Lol! For obvious reasons, there are technical limitations and variables in the above example that will cause issues. Another tool you can use, with newer versions of Parallels disk formats, is the VMware Converter. Similarly, this tool allows to migrate virtual hard drives from one format to another.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;So you have FAILED.. and never want to use a Mac again at this point. Here's another approach soldiers:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1.) Blow out your image to a physical hard drive using the tool of your choice. I like DC3DD whooohoo&lt;br /&gt;&lt;br /&gt;2.) Now attach this external hard drive to your Mac examiner machine as a slave. Boot to this hard drive instead of the primary hard drive. Boot options are made available by holding down the options key at start up.&lt;br /&gt;&lt;br /&gt;3.) So now you just booted into your custodians machine. Sweeeet! The cool thang about Mac's is they don't nearly require the degree of driver support that PC's do upon start up. Mac's have a very transparent set of drivers between all of their products. So you can practically use any Mac machine (at least consistent with chip sets) to boot native.&lt;br /&gt;&lt;br /&gt;4.) Now you may get stuck at the login password because you don't know the custodians password. If this is the case, it doesn't hurt to just ask for it DERRRR! If you need to reset it, then use the OS X restoration DVD. You can figure it out.. just GOOGLE IT! Just beware you will need the OS X recovery disk paired with the installation version.&lt;br /&gt;&lt;br /&gt;5.) Once you get in, boot the virtual machine(s) normally and acquire using a live-image tool. I like throwing FTK imager lite on a thumb drive, adding it as a read-only device into the virtual machine, and porting the image over to a saved network share location or external data source. As always, just document your shiat.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Update (12/6/2009): Just in, thanks to Beatle over at forensicfocus.com, another approach, try &lt;a href="http://www.ufsexplorer.com/do...ad_std.php"&gt;UFS Explorer&lt;/a&gt;&amp;nbsp;. I have not tested, but it is documented that this software will to read into the Parallels image file and allow you to mount the file system locally with read-only access. If you have experience using this software, I would be interested to hear your feedback.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;As always, these are just some of my notes. Test, validate, document, your work!&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-8868851958789076140?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/8868851958789076140/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2009/11/mac-parallels.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/8868851958789076140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/8868851958789076140'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2009/11/mac-parallels.html' title='Mac Parallels'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_xRHNXt3iDHk/SvsYUd325qI/AAAAAAAAAiI/NI8mtjh10Qw/s72-c/stuff-white-ppl-like.jpg.jpeg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-2470400401703756746</id><published>2009-11-10T20:54:00.000-08:00</published><updated>2009-11-11T12:01:13.620-08:00</updated><title type='text'>its good</title><content type='html'>&lt;div style="color: #3d85c6;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_xRHNXt3iDHk/SvsX-es2iLI/AAAAAAAAAiA/C9rMmDne4cY/s1600-h/ninja.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_xRHNXt3iDHk/SvsX-es2iLI/AAAAAAAAAiA/C9rMmDne4cY/s320/ninja.png" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;we aint be airing for 24 n i aready gotz stalkers. girlz be bookmarking n crackers be marking. cut paste copy erase. dnads is a polymorphic strand that aint loosing system command. i'm shootin tripple DES while y'all still bootin 95. nibble, nobble, nads gets in with a snort and out with a port. ya better run update cause dav nads don't procasanate. stay tuned for more stringing accsi&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-2470400401703756746?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/2470400401703756746/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2009/11/stuff-white-people-like.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/2470400401703756746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/2470400401703756746'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2009/11/stuff-white-people-like.html' title='its good'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_xRHNXt3iDHk/SvsX-es2iLI/AAAAAAAAAiA/C9rMmDne4cY/s72-c/ninja.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-254295412164493706.post-248564354179866583</id><published>2009-11-09T22:43:00.000-08:00</published><updated>2009-12-02T16:27:43.096-08:00</updated><title type='text'>ctrl alt del..  P'0wned!!  DAV NADS iz ONLINE!</title><content type='html'>&lt;div style="color: #6aa84f; font-family: inherit;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://cache.gizmodo.com/assets/resources/2007/08/us-powned.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="108" src="http://cache.gizmodo.com/assets/resources/2007/08/us-powned.jpg" width="200" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;Wazzzzzzap! I'm werking on layin down some &lt;span style="font-size: 18px;"&gt;HUGE&lt;/span&gt; tricks fo' my blog project includin: hardddcore digi FORENSICS, e-discovery "where the MONEY is @", reverse engineering for snitching, , reality TV and some NEWS. &lt;br /&gt;&lt;/div&gt;&lt;div style="color: #6aa84f; font-family: inherit;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: #6aa84f; font-family: inherit;"&gt;BUT Rigt' now.. put yo PC on deep freeeeze and MACs 2 sleepz!  cause I'm working! &lt;span style="font-weight: bold;"&gt;spread the word that &lt;span style="font-size: large;"&gt;DAV NADS is ONLINE aND be bloggin' ritee HERE&lt;/span&gt;.  www.&lt;span style="font-weight: normal;"&gt;&lt;span style="font-weight: bold;"&gt;http://davnads.blogspot.com.&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; this the REAL thing y'all!&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span style="font-family: Arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/254295412164493706-248564354179866583?l=davnads.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davnads.blogspot.com/feeds/248564354179866583/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davnads.blogspot.com/2009/11/stay-posted-spread-wordss.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/248564354179866583'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/254295412164493706/posts/default/248564354179866583'/><link rel='alternate' type='text/html' href='http://davnads.blogspot.com/2009/11/stay-posted-spread-wordss.html' title='ctrl alt del..  P&apos;0wned!!  DAV NADS iz ONLINE!'/><author><name>davnads</name><uri>http://www.blogger.com/profile/08531420083973769320</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='25' src='http://3.bp.blogspot.com/_xRHNXt3iDHk/SvjeGfSzFOI/AAAAAAAAAg4/Q3eoktTsISo/S220/n67700668_30532637_2421.jpg'/></author><thr:total>2</thr:total></entry></feed>
