<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Forensic 4cast</title>
	<atom:link href="http://www.forensic4cast.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.forensic4cast.com</link>
	<description>Welcome to our podcast discussing issues relating to digital forensics</description>
	<lastBuildDate>Tue, 17 Apr 2012 18:06:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<copyright>Copyright © Forensic 4cast 2011 </copyright>
	<managingEditor>lee@whitfields.org (Lee Whitfield)</managingEditor>
	<webMaster>lee@whitfields.org (Lee Whitfield)</webMaster>
	<category>Tech News</category>
	<ttl>1440</ttl>
	<image>
		<url>http://www.forensic4cast.com/4small.jpg</url>
		<title>Forensic 4cast</title>
		<link>http://www.forensic4cast.com</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:new-feed-url>http://www.forensic4cast.com/?feed=podcast</itunes:new-feed-url>
	<itunes:subtitle>Forensic 4cast</itunes:subtitle>
	<itunes:summary>Welcome to the wonderful world of digital and computer forensics.  In each episode Lee will have guests on the show to discuss the latest news in the field, tell stories from the real world, and much more.</itunes:summary>
	<itunes:keywords>digital, computer, forensics, forensic, legal, law, cyber, crime</itunes:keywords>
	<itunes:category text="Technology">
		<itunes:category text="Tech News" />
	</itunes:category>
	<itunes:author>Lee Whitfield</itunes:author>
	<itunes:owner>
		<itunes:name>Lee Whitfield</itunes:name>
		<itunes:email>lee@whitfields.org</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.forensic4cast.com/4.jpg" />
		<item>
		<title>Forensic 4cast Magazine</title>
		<link>http://www.forensic4cast.com/2012/04/forensic-4cast-magazine/</link>
		<comments>http://www.forensic4cast.com/2012/04/forensic-4cast-magazine/#comments</comments>
		<pubDate>Tue, 17 Apr 2012 18:06:35 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.forensic4cast.com/?p=929</guid>
		<description><![CDATA[A few months ago I decided to look into creating an online magazine. This was to be a place where forensics professionals (and aspiring professionals) could contribute and learn together. Sadly the time wasn&#8217;t right and life through up a few complications. However I am now ready to pursue this idea more doggedly. I have [...]]]></description>
			<content:encoded><![CDATA[<p>A few months ago I decided to look into creating an online magazine. This was to be a place where forensics professionals (and aspiring professionals) could contribute and learn together. Sadly the time wasn&#8217;t right and life through up a few complications. However I am now ready to pursue this idea more doggedly.</p>
<p>I have decided to create the Forensic 4cast Magazine. This will be a quarterly digital-only magazine that discusses various topics from the fields of digital forensics and incident response. The magazine will be completely free for anyone to read/download on several different platforms including iOS and Android. I also hope to make it a good mix of text and video, with a bit of interactivity thrown in.</p>
<p>My aim is to get the first issue published no later then June but, in order to meet that target, I&#8217;m going to need your help. Obviously I can not write all of the content for a magazine by myself so I&#8217;m asking for assistance from you. If you have something to say, I want to hear it. At this point I have not ruled out anything (except for the suggestion of  a &#8220;Lee&#8221; photoshopping section). I have a few suggestions but please feel free to add your own:</p>
<ul>
<li>Case Studies</li>
<li>Research</li>
<li>Events</li>
<li>Book Reviews</li>
<li>Software Reviews</li>
<li>Hardware Reviews</li>
<li>Interviews</li>
<li>Interesting Artifacts</li>
<li>Hints and Tips</li>
<li>News</li>
</ul>
<p>These are just a few of my own suggestions, but you are going to be reading this publication. You tell me what things you&#8217;d like to see.</p>
<p>If you&#8217;re interested in submitting an article, a calendar event, some news, a suggestion, or something else of interest please contact me at <a href="mailto:lee@forensic4cast.com">lee@forensic4cast.com</a>. Please note that I&#8217;m happy to have either new submissions or maybe something that may have been published elsewhere. As long as you retain the copyright, I&#8217;m happy to consider it for the magazine.</p>
<p>Just to give you a taster of how the magazine will look I&#8217;ve included some demo screens:</p>
<p><a href="http://www.forensic4cast.com/wp-content/uploads/2012/04/cover.jpg" target="_blank"><img class="alignnone  wp-image-931" title="Cover Design" src="http://www.forensic4cast.com/wp-content/uploads/2012/04/cover-225x300.jpg" alt="" width="180" height="240" /></a><a href="http://www.forensic4cast.com/wp-content/uploads/2012/04/contents.jpg" target="_blank"><img class="alignnone  wp-image-930" title="Contents Page" src="http://www.forensic4cast.com/wp-content/uploads/2012/04/contents-225x300.jpg" alt="" width="180" height="240" /></a><a href="http://www.forensic4cast.com/wp-content/uploads/2012/04/edit.jpg" target="_blank"><img class="alignnone  wp-image-932" title="Editorial" src="http://www.forensic4cast.com/wp-content/uploads/2012/04/edit-225x300.jpg" alt="" width="180" height="240" /></a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.forensic4cast.com/2012/04/forensic-4cast-magazine/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Strange Artifacts &#8211; Wubi</title>
		<link>http://www.forensic4cast.com/2012/04/strange-artifacts-wubi/</link>
		<comments>http://www.forensic4cast.com/2012/04/strange-artifacts-wubi/#comments</comments>
		<pubDate>Sat, 07 Apr 2012 00:11:29 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[Technical Articles]]></category>

		<guid isPermaLink="false">http://www.forensic4cast.com/?p=928</guid>
		<description><![CDATA[I don&#8217;t speak French. I learned it at school and don&#8217;t use it much but, if it was a pinch, I could probably remember enough to get by. The same goes for using linux. I know a lot of the basic commands and how to set things up so that it is usable, but I&#8217;m [...]]]></description>
			<content:encoded><![CDATA[<p>I don&#8217;t speak French. I learned it at school and don&#8217;t use it much but, if it was a pinch, I could probably remember enough to get by. The same goes for using linux. I know a lot of the basic commands and how to set things up so that it is usable, but I&#8217;m not about to go recompiling kernel source code (sorry Hal). I&#8217;m pretty sure that owning a Mac, and using Macs at work have helped me learn the basics.</p>
<p>Having said that, I recently rekindled my love affair with linux, well, Ubuntu. I was looking for a Windows solution to a specific problem only to find that I would have to spend a good sum of money in attempting to solve the issue. As I was researching a solution I found that linux was equipped to deal with the situation at no cost and a small learning curve. My only issue was that I didn&#8217;t want to repartition my hard drive. I kinda have things set up the way I like them.</p>
<p>Enter Wubi (<a title="Wubi" href="http://www.ubuntu.com/download/ubuntu/windows-installer" target="_blank">http://www.ubuntu.com/download/ubuntu/windows-installer</a>).</p>
<p>Wubi is short for &#8220;Windows Ubuntu Installer&#8221;. You download the software inside Windows and run the installer. There is no partitioning, and the installation is quick and painless. Now, when you reboot, you are presented with an option to boot Windows or Ubuntu. This is all handled by the Windows loader, not a single mention of grub anywhere.</p>
<p>Once loaded you are presented with a complete installation of Ubuntu. But where is it installed?</p>
<p>I booted back into Windows and did some digging. In the directory &#8220;C:\ubuntu\disks&#8221; I found two files. One of which was named &#8220;root.disk&#8221;. I decided to throw caution to the wind and throw the file into FTK Imager as an image file&#8230;</p>
<p>It worked!</p>
<p>Before me I saw the complete Ext3 file system for my Ubuntu installation. Outstanding, but also a little scary. Still a little something to watch for when conducting your next investigation.</p>
<p>There is also something similar for linux called &#8220;lubi&#8221;. But I&#8217;m not sure I could bring myself to use a product with that particular name.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.forensic4cast.com/2012/04/strange-artifacts-wubi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Digital Forensic Examiner of the Year</title>
		<link>http://www.forensic4cast.com/2012/04/digital-forensic-examiner-of-the-year/</link>
		<comments>http://www.forensic4cast.com/2012/04/digital-forensic-examiner-of-the-year/#comments</comments>
		<pubDate>Tue, 03 Apr 2012 13:29:52 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.forensic4cast.com/?p=924</guid>
		<description><![CDATA[I&#8217;ve been asked to explain why, specifically, people chose to nominate the three forensicators below. I have posted some of the comments made by those who nominated them. Personally I&#8217;m torn. All three are fully deserving of the award this year (yes, even Cindy). Kristinn Gudjonsson &#8220;Kristinn is long overdue for some public recognition for [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been asked to explain why, specifically, people chose to nominate the three forensicators below. I have posted some of the comments made by those who nominated them. Personally I&#8217;m torn. All three are fully deserving of the award this year (yes, even Cindy).</p>
<h3>Kristinn Gudjonsson</h3>
<p>&#8220;Kristinn is long overdue for some public recognition for his log2timeline tool work. Log2timeline was a breakthrough for the digital forensics community and it made the creation of timelines quick and easy for all digital forensics examiners. Kristinn&#8217;s tool has made what was previously a very tedious manual process easy to create for examiners of all skill levels. His contribution to the community has been invaluable and should be recognized.&#8221;</p>
<p>&#8220;His contributions have been astounding.&#8221;</p>
<p>&#8220;Kristinn is a unsung hero in digital forensics. I mean&#8230; he can move half-way across the world without anyone knowing&#8230; Kristinn has unselfishly given so much to the digital forensic community. Log2timeline says it all!!&#8221;</p>
<h3>Cindy Murphy</h3>
<p>&#8220;I&#8217;m nominating Cindy Murphy because she&#8217;s always been consistently one of the brightest, most helpful and kindest members of the community, often going out of her way to help those who ask. This past year she completed her MSc, the culmination of which was a needed dissertation for investigators of child pornography; she has already been invited to present it both at conferences and in a noted textbook. In addition, Cindy teaches digital forensics part time, continues to contribute to the field of mobile device forensics, and is a Board member of the Consortium of Digital Forensics Specialists &#8212; all while continuing full time casework.&#8221;</p>
<p>&#8220;It’s about time you have a female forensicator nominated for this award! Detective Cindy Murphy from Madison, WI Police Department has over 13 years of experience in digital forensics. She has worked tirelessly over those years, not only full time on criminal case work, but also as an extremely active member of the digital forensics community. She has collaborated with NIST on various documetns and projects, shares policy, procedure, and go-by documents that she has developed with the community, she teaches Digital Forensics part time at MATC, presents her work and research at numerous conferences, serves on the boards of WACCI and CDFS, writes and reviews articles and white papers, contributes to podcasts and blogs, etc. She is a well known and respected figure in the DF community, and also just earned her Master&#8217;s in Forensic Computing &amp; Cybercrime from University College in Dublin, Ireland. She&#8217;d be a great candidate for your Digital Forensic Examiner of the Year!&#8221;</p>
<p>&#8220;She made Lee go a bright shade of red at the DoD conference. Anyone who does that deserves an award&#8221; The person who wrote this has since been banned from nominating/voting <img src='http://www.forensic4cast.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<h3>Corey Harrell</h3>
<p>&#8220;Corey&#8217;s work over the past year, not only in exposing VSCs to the masses of examiners, but also in documenting exploit artifacts and the process he used to expose them, have been significant and valuable contributions.&#8221;</p>
<p>&#8220;He has contributed to the community greatly last year, and continues to add value.&#8221;</p>
<p>&#8220;His commitment to the field is fantastic. His blog is an excellent resource and he continues to produce exceptional work from his research.&#8221;</p>
<p>You can post your votes here: <a title="Forensic 4cast Awards" href="http://www.forensic4cast.com/forensic-4cast-awards/" target="_blank">Forensic 4cast Awards</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.forensic4cast.com/2012/04/digital-forensic-examiner-of-the-year/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Meet the 2012 Nominees</title>
		<link>http://www.forensic4cast.com/2012/04/meet-the-2012-nominees/</link>
		<comments>http://www.forensic4cast.com/2012/04/meet-the-2012-nominees/#comments</comments>
		<pubDate>Tue, 03 Apr 2012 01:54:33 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.forensic4cast.com/?p=923</guid>
		<description><![CDATA[Ladies and gentlemen thank-you for posting your nominations over the last few weeks. Please meet the nominees for the 2012 Forensic 4cast Awards. Voting is open. You can place your votes here: http://www.forensic4cast.com/forensic-4cast-awards/ Computer Forensic Hardware Tool of the Year Tableau TD2 BlackBag Macquisition Hardcopy 3P Digital Forensic Article of the Year Digital Forensics SIFT&#8217;ing: Cheating Timelines [...]]]></description>
			<content:encoded><![CDATA[<p>Ladies and gentlemen thank-you for posting your nominations over the last few weeks. Please meet the nominees for the 2012 Forensic 4cast Awards. Voting is open. You can place your votes here: <a href="http://www.forensic4cast.com/forensic-4cast-awards/" target="_blank">http://www.forensic4cast.com/forensic-4cast-awards/</a></p>
<h3>Computer Forensic Hardware Tool of the Year</h3>
<ul>
<li><a href="http://www.tableau.com/index.php?pageid=products&amp;model=TD2" target="_blank">Tableau TD2</a></li>
<li><a href="https://www.blackbagtech.com/forensics/macquisition/macquisition.html" target="_blank">BlackBag Macquisition</a></li>
<li><a href="http://www.digitalintelligence.com/products/hardcopy3p/" target="_blank">Hardcopy 3P</a></li>
</ul>
<h3>Digital Forensic Article of the Year</h3>
<ul>
<li><a href="http://computer-forensics.sans.org/blog/2011/12/16/digital-forensics-sifting-cheating-timelines-with-log2timeline" target="_blank">Digital Forensics SIFT&#8217;ing: Cheating Timelines with log2timeline &#8211; David Nides</a></li>
<li><a href="http://gutterchurl.blogspot.com/2012/01/brief-overview-of-4-nfats.html" target="_blank">Brief overview of 4 NFATs &#8211; Erika Noerenberg</a></li>
<li><a href="http://integriography.wordpress.com/2011/03/27/fragmentation-of-the-digital-forensics-community/" target="_blank">Fragmentation of the digital forensics community &#8211; David Kovar</a></li>
</ul>
<h3>Phone Forensic Software Tool of the Year</h3>
<ul>
<li><a href="http://cellebrite.com" target="_blank">Cellebrite Physical Analyzer</a></li>
<li><a href="http://msab.com" target="_blank">XRY</a></li>
<li><a href="http://katanaforensics.com/lantern-2/lanternlite" target="_blank">Lantern Lite</a></li>
</ul>
<h3>Digital Forensic Podcast of the Year</h3>
<ul>
<li><a href="http://www.cybercrime101.com/" target="_blank">Cybercrime 101</a></li>
<li><a href="http://cyberspeak.libsyn.com" target="_blank">Cyberspeak</a></li>
<li><a href="http://legaltalknetwork.com/podcasts/digital-detectives/" target="_blank">Digital Detectives Podcast</a></li>
</ul>
<h3>Digital Forensic Book of the Year</h3>
<ul>
<li><a href="http://www.amazon.com/Digital-Forensics-Open-Source-Tools/dp/1597495867" target="_blank">Digital Forensics With Open Source Tools &#8211; Cory Altheide &amp; Harlan Carvey</a></li>
<li><a href="http://www.amazon.com/Windows-Forensic-Analysis-Toolkit-Edition/dp/1597494224/ref=sr_1_3?s=books&amp;ie=UTF8&amp;qid=1333402262&amp;sr=1-3" target="_blank">Windows Registry Forensics: Advanced Digital Forensic Analysis of the Windows Registry &#8211; Harlan Carvey</a></li>
<li><a href="http://www.amazon.com/Malware-Analysts-Cookbook-DVD-Techniques/dp/0470613033/ref=sr_1_1?s=books&amp;ie=UTF8&amp;qid=1333402303&amp;sr=1-1" target="_blank">Malware Analyst&#8217;s Cookbook: Tools and techniques for Fighting Malicious Code &#8211; Michael Hale Ligh, Steven Adair, Blake Hartstein, &amp; Matthew Richard</a></li>
</ul>
<h3>Computer Forensic Software Tool of the Year</h3>
<ul>
<li><a href="http://log2timeline.net" target="_blank">log2timeline</a></li>
<li><a href="https://www.blackbagtech.com/forensics/blacklight/blacklight.html" target="_blank">Blackbag Blacklight</a></li>
<li><a href="http://dfsforensics.blogspot.com" target="_blank">Registry Decoder</a></li>
</ul>
<h3>Digital Forensic Blog of the Year</h3>
<ul>
<li><a href="http://www.ericjhuber.com/" target="_blank">A Fistful of Dongles &#8211; Eric Huber</a></li>
<li><a href="http://girlunallocated.blogspot.com/" target="_blank">Girl, Unallocated &#8211; Melia Kelley</a></li>
<li><a href="http://journeyintoir.blogspot.com/" target="_blank">Journey into Incident Response &#8211; Corey Harrel</a></li>
</ul>
<h3>Phone Forensic Hardware Tool of the Year</h3>
<ul>
<li><a href="http://cellebrite.com" target="_blank">Cellebrite UFED</a></li>
<li><a href="http://msab.com" target="_blank">XRY</a></li>
<li><a href="http://accessdata.com/products/computer-forensics/mobile-phone-examiner" target="_blank">MPE+ Field Tablet</a></li>
</ul>
<h3>Digital Forensic Organization of the Year</h3>
<ul>
<li><a href="http://www.cdfs.org/" target="_blank">Consortium of Digital Forensic Specialists</a></li>
<li><a href="http://google.com" target="_blank">Google Forensic and Incident Response Team</a></li>
<li><a href="http://www.verizonbusiness.com/Products/security/investigative-response/" target="_blank">Verizon Investigative Response</a></li>
</ul>
<h3>Digital Forensic Examiner of the Year</h3>
<ul>
<li><a href="http://www.linkedin.com/profile/view?id=11654251&amp;locale=en_US" target="_blank">Kristinn Gudjonsson</a></li>
<li><a href="http://www.linkedin.com/profile/view?id=32091758&amp;locale=en_US" target="_blank">Cindy Murphy</a></li>
<li><a href="http://www.linkedin.com/profile/view?id=83956359&amp;locale=en_US" target="_blank">Corey Harrell</a></li>
</ul>
<p>You can cast your votes here: <a title="Forensic 4cast Awards" href="http://www.forensic4cast.com/forensic-4cast-awards/" target="_blank">Forensic 4cast awards </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.forensic4cast.com/2012/04/meet-the-2012-nominees/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Lantern Lite Imager</title>
		<link>http://www.forensic4cast.com/2012/03/lantern-lite-imager/</link>
		<comments>http://www.forensic4cast.com/2012/03/lantern-lite-imager/#comments</comments>
		<pubDate>Sat, 24 Mar 2012 02:37:24 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[Reviews]]></category>

		<guid isPermaLink="false">http://www.forensic4cast.com/?p=921</guid>
		<description><![CDATA[I&#8217;m aways happy to give credit where credit is due. This week I had a dilemma. At work we have a license for Cellebrite Physical Analyzer (excellent software) but we needed to have the ability to obtain physical images of several iOS devices at several locations at once. We needed to act quickly and as [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m aways happy to give credit where credit is due.</p>
<p>This week I had a dilemma. At work we have a license for Cellebrite Physical Analyzer (excellent software) but we needed to have the ability to obtain physical images of several iOS devices at several locations at once. We needed to act quickly and as cost-effectively as possible.</p>
<p>It was, at this point, that I was put on to Lantern Lite Imager.</p>
<p>You may be familiar with Lantern. It is used to analyze iOS devices and has a nice little feature that displays everything in a timeline. Very good software.</p>
<p>Lantern Lite Imager, unlike its older brother, is free software that uses the bootloader from the redsn0w jailbreak in order to obtain a full physical image of the iPhone 4 and earlier, and the original iPad. Not only does it obtain a full physical image but it also brute-forces any passcode on the device and decrypts the image.</p>
<p>There are only two negatives that I have discovered:</p>
<p>Even if you already know the passcode there is nowhere to enter it. The software MUST crack the passcode.</p>
<p>Speed. While the software can image the devices quickly it does not decrypt on-the-fly like Cellebrite does. This means that you have to wait for the image to acquire and then wait again for the image to decrypt.</p>
<p>Aside from that, the software is brilliant and I recommend it to anyone&#8230; as long as you have a Mac. If you don&#8217;t, why not?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.forensic4cast.com/2012/03/lantern-lite-imager/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>SANS 408 Mentoring and Teaching Assistant</title>
		<link>http://www.forensic4cast.com/2012/03/sans-408-mentoring-and-teaching-assistant/</link>
		<comments>http://www.forensic4cast.com/2012/03/sans-408-mentoring-and-teaching-assistant/#comments</comments>
		<pubDate>Wed, 14 Mar 2012 18:57:49 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.forensic4cast.com/?p=920</guid>
		<description><![CDATA[The new job is keeping my mind and body very busy recently so first of all, let me apologize for not being very proactive with posting. Normal service will be resumed soon. Second, I&#8217;m now in the SANS mentoring program. This means that I&#8217;ll be teaching Forensics 408: Computer Forensic Investigations &#8211; Windows In-Depth on a [...]]]></description>
			<content:encoded><![CDATA[<p>The new job is keeping my mind and body very busy recently so first of all, let me apologize for not being very proactive with posting. Normal service will be resumed soon.</p>
<p>Second, I&#8217;m now in the SANS mentoring program. This means that I&#8217;ll be teaching Forensics 408: Computer Forensic Investigations &#8211; Windows In-Depth on a weekly basis starting on Tuesday April 17. The classes will run from 6 &#8211; 8 pm each Tuesday for 10 weeks. The classes will be held at Digital Discovery&#8217;s offices at 8131 LJB Freeway.</p>
<p>Whether you are new to forensics or you are a seasoned veteran, this course has something to offer you.</p>
<p>What&#8217;s more, if you enter the code MGIAC12 when registering you will receive a free attempt at the GCFE exam.</p>
<p>Mentor classes somewhat different that the large classes taught at conferences as they are small groups where participation is strongly encouraged. It also means that everyone in the class has direct access to the mentor if they have questions or concerns.</p>
<p>You can find more information, and register for the class, here: <a href="http://www.sans.org/info/99971" target="_blank">http://www.sans.org/info/99971</a></p>
<p>If you&#8217;re interested in sending multiple employees you may be entitled to a discount. If that is the case please contact <a href="mailto:mentor@sans.org">mentor@sans.org</a></p>
<p>If you live in the Dallas area and you&#8217;re looking for a great class please look into joining us.</p>
<p>Third, GO TEAM PODCAST! OK, it isn&#8217;t a great slogan but Ovie Carroll will be teaching the 408 class at SANS 2012 in Orlando Florida, March 25-30. The extremely cool thing is that I&#8217;m going to be his teaching assistant. Ovie is a great guy and his teaching style is very warm and friendly. If you want to take the class you can register here: <a href="https://www.sans.org/registration/register.php?conferenceid=24458">https://www.sans.org/registration/register.php?conferenceid=24458</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.forensic4cast.com/2012/03/sans-408-mentoring-and-teaching-assistant/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>2012 Award Nominations</title>
		<link>http://www.forensic4cast.com/2012/03/2012-award-nominations/</link>
		<comments>http://www.forensic4cast.com/2012/03/2012-award-nominations/#comments</comments>
		<pubDate>Mon, 12 Mar 2012 16:30:33 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[Podcast Episodes]]></category>

		<guid isPermaLink="false">http://www.forensic4cast.com/?p=918</guid>
		<description><![CDATA[Nominations have been open for some time now but I also understand that you may not read the site, only listen to the podcast. If this is the case, this is especially for you.]]></description>
			<content:encoded><![CDATA[<p>Nominations have been open for some time now but I also understand that you may not read the site, only listen to the podcast. If this is the case, this is especially for you.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.forensic4cast.com/2012/03/2012-award-nominations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://forensic4cast.com/wp-content/uploads/2012/03/2012-awards-trailer.mp3" length="1013717" type="audio/mpeg" />
		<itunes:duration>0:01:00</itunes:duration>
		<itunes:subtitle>Nominations have been open for some time now but I also understand that you may not read the site, only listen to the podcast. If this is the case, this is especially for you.</itunes:subtitle>
		<itunes:summary>Nominations have been open for some time now but I also understand that you may not read the site, only listen to the podcast. If this is the case, this is especially for you.</itunes:summary>
		<itunes:author>Lee Whitfield</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>Forensic 4cast Awards 2012 &#8211; Nominations are Open</title>
		<link>http://www.forensic4cast.com/2012/01/forensic-4cast-awards-2012-nominations-are-open/</link>
		<comments>http://www.forensic4cast.com/2012/01/forensic-4cast-awards-2012-nominations-are-open/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 18:36:19 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.forensic4cast.com/?p=916</guid>
		<description><![CDATA[Ladies and gentlemen, we are happy to announce that nominations for the 2012 Forensic 4cast Awards are now open. You can find the nominations page here: http://www.forensic4cast.com/forensic-4cast-awards/ Once again, SANS has invited us back to present the awards at the 2012 Forensic Summit in Austin on June 26 and 27. This year we have streamlined things [...]]]></description>
			<content:encoded><![CDATA[<p>Ladies and gentlemen, we are happy to announce that nominations for the 2012 Forensic 4cast Awards are now open. You can find the nominations page here: <a href="http://www.forensic4cast.com/forensic-4cast-awards/">http://www.forensic4cast.com/forensic-4cast-awards/</a></p>
<p>Once again, SANS has invited us back to present the awards at the 2012 Forensic Summit in Austin on June 26 and 27.</p>
<p>This year we have streamlined things a little and taken the total number of awards down to 10. We have also changed the names of most of the awards. We no proclaim the winner as &#8220;Best&#8230;&#8221; but rather &#8220;&#8230;of the year&#8221;.</p>
<p>Nominations will close on March 31 and voting will open the next day.</p>
<p>Thanks for your participation.</p>
<p>To the eventual nominees:</p>
<p>Please make every effort to get to the summit so that you can collect the award in person, should you win. The event, as a whole, is worth attending regardless. The speakers are fantastic and there is plenty of opportunity to learn and network.</p>
<p>It also guarantees that you&#8217;ll receive your award, as well as any other goodies that may come as part of winning.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.forensic4cast.com/2012/01/forensic-4cast-awards-2012-nominations-are-open/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Call for Volunteers &#8211; Forensic 4cast Awards</title>
		<link>http://www.forensic4cast.com/2011/12/call-for-volunteers-forensic-4cast-awards/</link>
		<comments>http://www.forensic4cast.com/2011/12/call-for-volunteers-forensic-4cast-awards/#comments</comments>
		<pubDate>Wed, 28 Dec 2011 17:04:02 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.forensic4cast.com/?p=912</guid>
		<description><![CDATA[Dear all, It is quickly approaching the awards season. Yes the Oscars, the Grammies, the Golden Globes, and others will be held in the coming months but, most importantly, we will soon be accepting nominations for the Forensic 4cast Awards. Once again SANS has been kind enough to host the event at the Forensic Summit [...]]]></description>
			<content:encoded><![CDATA[<p>Dear all,</p>
<p>It is quickly approaching the awards season. Yes the Oscars, the Grammies, the Golden Globes, and others will be held in the coming months but, most importantly, we will soon be accepting nominations for the Forensic 4cast Awards.</p>
<p>Once again SANS has been kind enough to host the event at the <a href="http://www.sans.org/forensics-incident-response-summit-2012/" target="_blank">Forensic Summit </a>(held at the Omni Hotel in Austin June 26-27 2012) and my new employer, <a href="http://www.digitaldiscoverycorp.com" target="_blank">Digital Discovery</a>, is going to furnish the awards themselves.</p>
<p>For the last two years I have pretty much handled the event myself. This has made the awards ceremony&#8230; interesting at times. For this reason I&#8217;m asking for some volunteers to assist this year. If you&#8217;re going to be attending (and you should be) and you think you could help in any way please let me know via the &#8220;<a title="contact us" href="http://www.forensic4cast.com/contact-us/" target="_blank">Contact Us</a>&#8221; page.</p>
<p>I look forward to hearing from you.</p>
<p>Lee</p>
]]></content:encoded>
			<wfw:commentRss>http://www.forensic4cast.com/2011/12/call-for-volunteers-forensic-4cast-awards/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How F-Response Saved Christmas</title>
		<link>http://www.forensic4cast.com/2011/12/how-f-response-saved-christmas/</link>
		<comments>http://www.forensic4cast.com/2011/12/how-f-response-saved-christmas/#comments</comments>
		<pubDate>Fri, 23 Dec 2011 03:09:47 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.forensic4cast.com/?p=911</guid>
		<description><![CDATA[Those who know me will attest to the fact that I love F-Response but today it really came to the rescue. I&#8217;m doing an imaging job in the Dallas area. The client wants me to image four servers, three of which are business critical and can&#8217;t be out of use between 6am and 7pm. So, [...]]]></description>
			<content:encoded><![CDATA[<p>Those who know me will attest to the fact that I love F-Response but today it really came to the rescue.</p>
<p>I&#8217;m doing an imaging job in the Dallas area. The client wants me to image four servers, three of which are business critical and can&#8217;t be out of use between 6am and 7pm.</p>
<p>So, these servers are so old that they make Ken Pryor look like a teenager&#8230;</p>
<p>At first I tried using FTK Imager (portable version) but that ended up crashing one of the servers (yikes). Thankfully the crash was over night and it was back up in time for the start of the working day.</p>
<p>Next I tried DCFLDD. This worked for two of the servers (bearing in mind that I had to do this over USB 1.1). This was painstakingly slow but it worked. However, the other two servers were simply unable to cope with being imaged. They would continually lock up or lose connectivity to the USB drives.</p>
<p>I tried netcat. No dice.</p>
<p>I exhausted all of my practical possibilities.</p>
<p>Finally we all decided to take the servers offline tonight and tomorrow night. We were going to image a 2TB server with SATA drives (yes, they had both IDE and SATA in their servers, as well as SCSI). If a boot disc wasn&#8217;t going to work I was going to have to image SATA drives (simple enough) and SCSI drives (shoot me in the head) with a Tableau write-blocker. My SATA write-blocker has eSATA so that would go pretty quick, but my SCSI write-blocker is USB. So, a bunch of SCSI drives to image, one at a time mind you. Then would come the painstaking effort of reassembling the RAID in some software tool.</p>
<p>I could see what was going to happen. I was going to spend every evening from now until next week sitting in a cold server room imaging SCSI drives. I was going to cry.</p>
<p>Thankfully the lab is armed with a copy of F-Response &#8211; Consultant Edition.</p>
<p>After a little tinkering I was able to plug a laptop into the network and mount the drives from the problematic servers. Within a couple of hours the worst of the two servers was completely imaged and the largest of the servers was in progress.</p>
<p>Tonight I am sat at home in the company of my gorgeous wife wrapping presents for the kids instead of  sitting in front of a laptop watching a status bar crawl, very slowly, across the screen.</p>
<p>Thanks F-Response.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.forensic4cast.com/2011/12/how-f-response-saved-christmas/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

