last data update: 2011/10/14, 20:14

Website loading time

during the test: 2.23 s

cable connection (average): 2.69 s

DSL connection (average): 3.14 s

modem (average): 27.31 s

HTTP headers

Information about DNS servers

lz333.comA114.80.209.134IN3600
lz333.comSOAns.xinnetdns.comhostmaster.xinnetdns.com10831282443600 1800 604800 7200 IN 3600
lz333.comNSns.xinnet.cnIN3600
lz333.comNSns.xinnetdns.comIN3600
sorenjordansen.comA65.182.187.244IN14400
sorenjordansen.comSOAns1.imwbasbserver.comjohn.merrick.gmail.com201103140286400 7200 3600000 86400 IN 43200
sorenjordansen.comMX0sorenjordansen.comIN14400
sorenjordansen.comNSns1.imwbasbserver.comIN43200
sorenjordansen.comNSns2.imwbasbserver.comIN43200
tuulavaatainen.fiMX10mail.tuulavaatainen.fiIN43200
tuulavaatainen.fiA83.150.78.46IN43200
tuulavaatainen.fiSOAprodns.kotisivut.comhostmaster.prodns.kotisivut.com201005100128800 3600 604800 86400 IN 43200
tuulavaatainen.fiNSprodns4.kotisivut.comIN43200
tuulavaatainen.fiNSprodns.kotisivut.comIN43200
tuulavaatainen.fiNSprodns3.kotisivut.comIN43200
tuulavaatainen.fiNSprodns2.kotisivut.comIN43200
quezorras.com.arSOAns1.parkingcrew.nethostmaster.quezorras.com.ar1318647928800 7200 604800 86400 IN 10800
quezorras.com.arA62.116.181.25IN3600
quezorras.com.arNSns2.parkingcrew.netIN3600
quezorras.com.arNSns1.parkingcrew.netIN3600
kamerun-kamerun.deMX10mx00.udag.deIN14400
kamerun-kamerun.deMX20mx01.udag.deIN14400
kamerun-kamerun.deSOAns.udagdns.nethostmaster.united-domains.de110800 3600 604800 3600 IN 43200
kamerun-kamerun.deA109.234.218.132IN3600
kamerun-kamerun.deNSns.udagdns.deIN43200
kamerun-kamerun.deNSns.udagdns.netIN43200
k2m.com.plA195.114.1.119IN43200
k2m.com.plSOAns1.aidahosting.comdnsadmin.s119.superhost.pl201004212086400 7200 3600000 86400 IN 43200
k2m.com.plTXTv=spf1 a mx ip4:83.19.2.246/29 ip4:83.143.40.246 -allArrayIN43200
k2m.com.plMX20mail3.k2m.com.plIN43200
k2m.com.plMX0mail.k2m.com.plIN43200
k2m.com.plMX10mail2.k2m.com.plIN43200
k2m.com.plNSns2.aidahosting.comIN43200
k2m.com.plNSns1.aidahosting.comIN43200
hvoquerido.nlMX20mx2.wpod.netIN43200
hvoquerido.nlMX20mx1.wpod.netIN43200
hvoquerido.nlA194.109.39.116IN43200
hvoquerido.nlSOAns.xs4all.nlhostmaster.xs4all.nl201103080121600 7200 604800 86400 IN 43200
hvoquerido.nlNSns.xs4all.nlIN43200
hvoquerido.nlNSns2.xs4all.nlIN43200
goonlines.comTXTv=spf1 a mx -allArrayIN600
goonlines.comMX10smtp.goonlines.comIN600
goonlines.comA94.141.22.66IN600
goonlines.comSOAns1.netsons.comadmin.netsons.com3640 300 604800 600 IN 640
goonlines.comNSns2.netsons.comIN600
goonlines.comNSns1.netsons.comIN600
orvajrarei.comTXTv=spf1 a mx +allArrayIN600
orvajrarei.comTXTv=spf1 a mx -allArrayIN600
orvajrarei.comMX10smtp.orvajrarei.comIN600
orvajrarei.comA94.141.22.20IN600
orvajrarei.comSOAns1.netsons.comadmin.netsons.com3640 300 604800 600 IN 640
orvajrarei.comNSns1.netsons.comIN600
orvajrarei.comNSns2.netsons.comIN600
play.clA190.98.219.19IN14400
play.clSOAdns1.powerhost.clmax.petit.breuilh.gmail.com201103270386400 7200 3600000 86400 IN 43200
play.clMX0play.clIN14400
play.clNSdns3.powerhost.clIN43200
play.clNSdns1.powerhost.clIN43200
play.clNSdns4.powerhost.clIN43200
play.clNSdns2.powerhost.clIN43200
hoppels.comA188.40.112.252IN43200
hoppels.comSOAns1.issociate.dedomains.issociate.de201103100139940 7200 604800 86400 IN 43200
hoppels.comMX50mail0.issociate.netIN300
hoppels.comMX20mail.hoppels.comIN300
hoppels.comMX30mail3.issociate.netIN300
hoppels.comMX40mail4.issociate.netIN300
hoppels.comNSns2.issociate.deIN43200
hoppels.comNSns4.issociate.deIN43200
hoppels.comNSns3.issociate.deIN43200
hoppels.comNSns1.issociate.deIN43200
work-shoe.netTXTv=spf1 ip4:66.96.128.0/18 ?allArrayIN3600
work-shoe.netMX30mx.work-shoe.netIN3600
work-shoe.netSOAns1.ipage.comdnsadmin.ipage.com201009117310800 3600 604800 3600 IN 3600
work-shoe.netA66.96.147.108IN3600
work-shoe.netNSns1.ipage.comIN3600
work-shoe.netNSns2.ipage.comIN3600
megauploadbay.comA74.117.180.228IN43200
megauploadbay.comMX30ASPMX5.GOOGLEMAIL.comIN43200
megauploadbay.comMX10ASPMX.L.GOOGLE.comIN43200
megauploadbay.comMX20ALT1.ASPMX.L.GOOGLE.comIN43200
megauploadbay.comMX20ALT2.ASPMX.L.GOOGLE.comIN43200
megauploadbay.comMX30ASPMX2.GOOGLEMAIL.comIN43200
megauploadbay.comMX30ASPMX3.GOOGLEMAIL.comIN43200
megauploadbay.comMX30ASPMX4.GOOGLEMAIL.comIN43200
megauploadbay.comSOAns1.megauploadbay.comroot.photonhost.com200811250128800 7200 604800 86400 IN 43200
megauploadbay.comNSns1.megauploadbay.comIN43200
megauploadbay.comNSns2.megauploadbay.comIN43200
calmug.orgMX10mx.calmug.orgIN21600
calmug.orgSOAdns.technorail.comhostmaster.technorail.com186400 7200 2592000 86400 IN 21600
calmug.orgA62.149.128.151IN21600
calmug.orgA62.149.128.154IN21600
calmug.orgA62.149.128.157IN21600
calmug.orgA62.149.128.160IN21600
calmug.orgA62.149.128.163IN21600
calmug.orgA62.149.128.166IN21600
calmug.orgA62.149.128.72IN21600
calmug.orgA62.149.128.74IN21600
calmug.orgNSdns2.technorail.comIN21600
calmug.orgNSdns.technorail.comIN21600
infoexpressba.com.brMX1ghs.google.comIN43200
infoexpressba.com.brIN43200
infoexpressba.com.brIN43200
infoexpressba.com.brIN43200
infoexpressba.com.brIN900
infoexpressba.com.brIN43200
infoexpressba.com.brIN900
infoexpressba.com.brIN43200
infoexpressba.com.brSOAa.sec.dns.brhostmaster.registro.br201128500086400 900 604800 900 IN 43200
infoexpressba.com.brIN3600
infoexpressba.com.brIN3600
infoexpressba.com.brNSb.sec.dns.brIN43200
infoexpressba.com.brNSa.sec.dns.brIN43200
kastenopmaat.nlMX400mx2.vuurwerk.nlIN3600
kastenopmaat.nlMX100mx.vuurwerk.nlIN3600
kastenopmaat.nlMX103as-2.mail.vuurwerk.netIN3600
kastenopmaat.nlMX104as-1.mail.vuurwerk.netIN3600
kastenopmaat.nlMX105as-3.mail.vuurwerk.netIN3600
kastenopmaat.nlSOAns.vuurwerk.nlpostmaster.vuurwerk.nl200702040628800 7200 86400 300 IN 3600
kastenopmaat.nlNSns2.vuurwerk.netIN3600
kastenopmaat.nlNSns3.vuurwerk.netIN3600
kastenopmaat.nlNSns.vuurwerk.nlIN3600
tennisseite.deA62.75.177.24IN43200
tennisseite.deSOAns10.nameserverservice.dehostmaster.ns10.nameserverservice.de200811220140000 20000 1500000 86400 IN 2560
tennisseite.deMX10mail.tennisseite.deIN43200
tennisseite.deNSns9.nameserverservice.deIN43200
tennisseite.deNSns10.nameserverservice.deIN43200
couponover.comSOAns1.mediatemple.netdnsadmin.mediatemple.net201106150110800 3600 1209600 43200 IN 43200
couponover.comA205.186.141.73IN43200
couponover.comMX20ALT1.ASPMX.L.GOOGLE.comIN43200
couponover.comMX20ALT2.ASPMX.L.GOOGLE.comIN43200
couponover.comMX30ASPMX2.GOOGLEMAIL.comIN43200
couponover.comMX30ASPMX3.GOOGLEMAIL.comIN43200
couponover.comMX30ASPMX4.GOOGLEMAIL.comIN43200
couponover.comMX30ASPMX5.GOOGLEMAIL.comIN43200
couponover.comMX10ASPMX.L.GOOGLE.comIN43200
couponover.comNSns1.mediatemple.netIN43200
couponover.comNSns2.mediatemple.netIN43200
wine-searcher.comA213.86.174.36IN3600
wine-searcher.comMX1cluster9.us.messagelabs.comIN3600
wine-searcher.comMX2cluster9a.us.messagelabs.comIN3600
wine-searcher.comSOAns1.limitlessnet.comhostmaster.limitless.co.uk201107270114400 3600 604800 3600 IN 3600
wine-searcher.comNSns3.limitlessnet.comIN3600
wine-searcher.comNSns2.limitlessnet.comIN3600
wine-searcher.comNSns1.limitlessnet.comIN3600
vde.comSOAns.vde.comihiepler.vde.com200808223010800 3600 604800 38400 IN 38400
vde.comA194.25.92.137IN38400
vde.comMX180smtp.vdegs.vde.comIN38400
vde.comMX200smtpgs.vde.comIN38400
vde.comMX10relay3.vde.comIN38400
vde.comMX20relay2.vde.comIN38400
vde.comMX100smtp.vde.comIN38400
vde.comNSns23.cinetic21.deIN38400
vde.comNSns.vde.comIN38400
thailandseataste.comSOAns53.chaiyohosting.comsupport.chaiyohosting.com129319258010800 3600 604800 10800 IN 43200
thailandseataste.comA202.57.162.225IN43200
thailandseataste.comMX10mx2.chaiyohosting.comIN43200
thailandseataste.comNSns54.chaiyohosting.comIN43200
thailandseataste.comNSns53.chaiyohosting.comIN43200
mmmgay.comA209.8.25.210IN1200
mmmgay.comMX20mail2.mmmgay.comIN1200
mmmgay.comMX10mail.mmmgay.comIN1200
mmmgay.comSOAns1.kot-server1.comadmin.mmmgay.com119008990621600 3600 691200 38400 IN 1200
mmmgay.comNSns2.kot-server1.comIN1200
mmmgay.comNSns1.kot-server1.comIN1200
skanderupefterskole.dkTXTThis site is hosted by INET-DESIGN ApSArrayIN3600
skanderupefterskole.dkTXTv=spf1 a mx ~allArrayIN3600
skanderupefterskole.dkMX10spam-mx01.inet-design.dkIN3600
skanderupefterskole.dkSOAns1.inetdesign.dkhostmaster.inetdesign.dk73600 600 604800 3600 IN 3600
skanderupefterskole.dkA87.54.41.40IN3600
skanderupefterskole.dkNSns2.inetdesign.dkIN3600
skanderupefterskole.dkNSns1.inetdesign.dkIN3600
amventures.caSOAns206.cawebhosting.comalerts.idig.net201103070386400 7200 3600000 86400 IN 43200
amventures.caMX0amventures.caIN14400
amventures.caA69.90.63.220IN14400
amventures.caNSns207.cawebhosting.comIN43200
amventures.caNSns206.cawebhosting.comIN43200
coinchimp.comA174.120.146.34IN14400
coinchimp.comSOAns1.shiftcode.comandrew.shiftcode.com201105140186400 7200 3600000 86400 IN 43200
coinchimp.comMX0coinchimp.comIN14400
coinchimp.comTXT“v=spf1amx-all”ArrayIN14400
coinchimp.comNSns1.shiftcode.comIN43200
coinchimp.comNSns2.shiftcode.comIN43200
chunichicomics.comA207.45.187.66IN14400
chunichicomics.comSOAdns1.bctn.comdomains.bctn.com20101223027200 7200 1814400 10800 IN 14400
chunichicomics.comMX0chunichicomics.comIN14400
chunichicomics.comTXTv=spf1 ip4:209.51.153.26 a mx ptr a:detroit.securenet-server.net ?allArrayIN14400
chunichicomics.comNSdns2.bctn.comIN14400
chunichicomics.comNSdns1.bctn.comIN14400
fundacionimago.org.coA70.87.126.20IN14400
fundacionimago.org.coSOAns1.colserver.netcarlosrocha.marketingyportales.com201008160086400 7200 3600000 86400 IN 43200
fundacionimago.org.coMX0fundacionimago.org.coIN14400
fundacionimago.org.coTXTv=spf1 a mx include:websitewelcome.com ~allArrayIN14400
fundacionimago.org.coIN43200
fundacionimago.org.coIN43200
fundacionimago.org.coNSns2.colserver.netIN43200
fundacionimago.org.coNSns1.colserver.netIN43200
ifgirls.comA208.99.86.140IN3600
ifgirls.comSOAns1.scbih.comhostmaster.scbih.com20110905027200 7200 604800 86400 IN 3600
ifgirls.comNSns2.scbih.comIN3600
ifgirls.comNSns1.scbih.comIN3600
ssb.beSOAns.be.hostbasket.comhostmaster.ssb.be201110090186400 7200 3600000 900 IN 3600
ssb.beA85.24.159.4IN43200
ssb.beMX10smtp.ssb.beIN43200
ssb.beMX100mail2.rack66.comIN43200
ssb.beNSns.be.hostbasket.comIN43200
ssb.beNSns.nl.hostbasket.comIN43200
ssb.beNSns.fr.hostbasket.comIN43200
jpdisco.seMX100mail.jpdisco.seIN3600
jpdisco.seA195.249.40.62IN3600
jpdisco.seSOAns1.cliche.seAdministrator.cliche.se20030710013600 600 86400 3600 IN 3600
jpdisco.seIN7200
jpdisco.seIN7200
jpdisco.seNSns2.cliche.seIN3600
jpdisco.seNSns1.cliche.seIN3600
myapartistanbul.comA91.227.4.11IN14400
myapartistanbul.comSOAns1.nsgnc.comenesgenc.gmail.com201107200086400 7200 3600000 86400 IN 43200
myapartistanbul.comMX0myapartistanbul.comIN14400
myapartistanbul.comNSns2.nsgnc.comIN43200
myapartistanbul.comNSns1.nsgnc.comIN43200
touslespodcasts.comMX100ns3bis.telecharger.comIN33200
touslespodcasts.comMX10ns2.telecharger.comIN33200
touslespodcasts.comA213.186.34.70IN33200
touslespodcasts.comSOAns1.mailclub.frdomaines.mailclub.fr201008020928800 14400 3600000 33200 IN 33200
touslespodcasts.comNSns2.mailclub.frIN33200
touslespodcasts.comNSns1.mailclub.frIN33200
ingv.itMX20apocalisse.ingv.itIN600
ingv.itMX10genesi.ingv.itIN600
ingv.itSOAdns1.ingv.itsir.ingv.it201109290121600 3600 1209600 86400 IN 600
ingv.itNSdns2.ingv.itIN600
ingv.itNSdns3.ingv.itIN600
ingv.itNSdns1.ingv.itIN600
accidentsinnews.comMX10mx1.diamondsinnews.comIN10800
accidentsinnews.comSOAns1.diamondsinnews.comroot.accidentsinnews.com200701011110800 3600 604800 3600 IN 10800
accidentsinnews.comA88.214.207.27IN10800
accidentsinnews.comNSns2.diamondsinnews.comIN10800
accidentsinnews.comNSns1.diamondsinnews.comIN10800
teenzaur.comMX10teenzaur.comIN30
teenzaur.comA78.140.143.101IN30
teenzaur.comSOAns1.webazilla.comhostmaster.webazilla.com100203060 30 604800 30 IN 30
teenzaur.comNSns2.webazilla.comIN30
teenzaur.comNSns3.webazilla.comIN30
teenzaur.comNSns1.webazilla.comIN30
boutique.rsr.chCNAMEboutique.rts.chIN43200
designers-avenue.comSOAns1.amen.frroot.amen.fr201006020221600 3600 604800 300 IN 10800
designers-avenue.comA62.193.229.145IN43200
designers-avenue.comMX20mx2.designers-avenue.comIN43200
designers-avenue.comMX10mx1.designers-avenue.comIN43200
designers-avenue.comNSns1.amen.frIN43200
designers-avenue.comNSns2.amen.frIN43200
sambaepaixao.comA66.147.240.152IN14400
sambaepaixao.comMX0sambaepaixao.comIN14400
sambaepaixao.comTXTv=spf1 a mx ptr include:hostmonster.com ?allArrayIN14400
sambaepaixao.comSOAns1.hostmonster.comroot.host352.hostmonster.com201109200786400 7200 3600000 300 IN 43200
sambaepaixao.comNSns1.hostmonster.comIN43200
sambaepaixao.comNSns2.hostmonster.comIN43200
yourbargaintravelers.comA174.122.2.92IN14400
yourbargaintravelers.comSOAns2385.hostgator.comdnsadmin.gator1193.hostgator.com201108160086400 7200 3600000 86400 IN 43200
yourbargaintravelers.comMX0yourbargaintravelers.comIN14400
yourbargaintravelers.comTXTv=spf1 a mx include:websitewelcome.com ~allArrayIN14400
yourbargaintravelers.comNSns2385.hostgator.comIN43200
yourbargaintravelers.comNSns2386.hostgator.comIN43200
windowsir.blogspot.comCNAMEblogspot.l.google.comIN3600

Received from the first DNS server

Request to the server "windowsir.blogspot.com"
Received 40 bytes from address 121.14.70.5#53 in 263 ms
Request to the server "windowsir.blogspot.com"
You used the following DNS server:
DNS Name: ns.xinnet.cn
DNS Server Address: 121.14.70.5#53
DNS server aliases:

Host windowsir.blogspot.com not found: 2(SERVFAIL)
Received 40 bytes from address 121.14.70.5#53 in 255 ms

Received from the second DNS server

Request to the server "windowsir.blogspot.com"
Received 40 bytes from address 121.14.70.6#53 in 250 ms
Request to the server "windowsir.blogspot.com"
You used the following DNS server:
DNS Name: ns.xinnetdns.com
DNS Server Address: 121.14.70.6#53
DNS server aliases:

Host windowsir.blogspot.com not found: 2(SERVFAIL)
Received 40 bytes from address 121.14.70.6#53 in 259 ms

Subdomains (the first 50)

Typos (misspells)

qindowsir.blogspot.com
aindowsir.blogspot.com
sindowsir.blogspot.com
eindowsir.blogspot.com
3indowsir.blogspot.com
2indowsir.blogspot.com
wundowsir.blogspot.com
wjndowsir.blogspot.com
wkndowsir.blogspot.com
wondowsir.blogspot.com
w9ndowsir.blogspot.com
w8ndowsir.blogspot.com
wibdowsir.blogspot.com
wimdowsir.blogspot.com
wijdowsir.blogspot.com
wihdowsir.blogspot.com
winsowsir.blogspot.com
winxowsir.blogspot.com
wincowsir.blogspot.com
winfowsir.blogspot.com
winrowsir.blogspot.com
wineowsir.blogspot.com
windiwsir.blogspot.com
windkwsir.blogspot.com
windlwsir.blogspot.com
windpwsir.blogspot.com
wind0wsir.blogspot.com
wind9wsir.blogspot.com
windoqsir.blogspot.com
windoasir.blogspot.com
windossir.blogspot.com
windoesir.blogspot.com
windo3sir.blogspot.com
windo2sir.blogspot.com
windowair.blogspot.com
windowzir.blogspot.com
windowxir.blogspot.com
windowdir.blogspot.com
windoweir.blogspot.com
windowwir.blogspot.com
windowsur.blogspot.com
windowsjr.blogspot.com
windowskr.blogspot.com
windowsor.blogspot.com
windows9r.blogspot.com
windows8r.blogspot.com
windowsie.blogspot.com
windowsid.blogspot.com
windowsif.blogspot.com
windowsit.blogspot.com
windowsi5.blogspot.com
windowsi4.blogspot.com
indowsir.blogspot.com
wndowsir.blogspot.com
widowsir.blogspot.com
winowsir.blogspot.com
windwsir.blogspot.com
windosir.blogspot.com
windowir.blogspot.com
windowsr.blogspot.com
windowsi.blogspot.com
iwndowsir.blogspot.com
wnidowsir.blogspot.com
widnowsir.blogspot.com
winodwsir.blogspot.com
windwosir.blogspot.com
windoswir.blogspot.com
windowisr.blogspot.com
windowsri.blogspot.com
wwindowsir.blogspot.com
wiindowsir.blogspot.com
winndowsir.blogspot.com
winddowsir.blogspot.com
windoowsir.blogspot.com
windowwsir.blogspot.com
windowssir.blogspot.com
windowsiir.blogspot.com
windowsirr.blogspot.com

Location

IP: 209.85.175.132

continent: NA, country: United States (USA), city: Mountain View

Website value

rank in the traffic statistics:

There is not enough data to estimate website value.

Basic information

website build using CSS

code weight: 175.54 KB

text per all code ratio: 33 %

title: Windows Incident Response

description:

keywords:

encoding: UTF-8

language: en

Website code analysis

one word phrases repeated minimum three times

PhraseQuantity
to6
of5
the5
Windows4
incident3
and3
is3
information3
Incident3
Response3
in3

two word phrases repeated minimum three times

PhraseQuantity
Windows Incident3
Incident Response3

three word phrases repeated minimum three times

PhraseQuantity
Windows Incident Response3

B tags

Carbon Black

need

Timeliner

Exploit Artifacts

DFF

Community

Tools

Endorsements

Why?

Purpose

Scanner Attributes

Plugins

Deploying the Scanner

What's coming?

will

competitive advantage

must

ADSs

F-Response

Live Forensics

Volatility

AutoRuns Update

iTunes Forensic Analysis

Volatility Updates

NetworkMiner

Registry

NOT

Timelines

U tags

I tags

need

Rootkit Paradox

must

THANKS

exactly

What's new in Windows 7: An analyst's perspective

ACMru

WordWheelQuery

if/then

Endorsements

Flexibility

convertfromraw

Force Multiplier

and

Preservation of Corporate Knowledge

Competitive Advantage

Knowledge Retention

Self-Documenting

Common Format

opendir()

readdir()

closedir()

just

If you didn't document it, it didn't happen.

how do I keep case notes

to what standard do I keep case notes

how

Exhibits

Hours

So, to what standard do you keep case notes?  Most often, I'll say, "...so that you can come back a year later and know what you did."  Too often, however, this provides a lazy analyst with an easy out, because from their perspective, what are the chances that in a year, someone's going to come back and ask them a question?  Well, you don't know until it happens...and it does happen.  The best standard to use when writing your case notes is to assume that at any point, you could "get hit by a bus" and another analyst will have to take your notes and finish the exam.  As such, are your case notes written to a level where another analyst could run the same commands, using the same versions of the tools you used, and replicate your results?  So, in your case notes, do you say, "Checked for ADSs", or do you say "Mounted image with FTK Imager v3.0 as G: volume, scanned for ADSs using LADS v4.0"?  This is important...remember MHL's post on stealth ADSs?  There are more things on heaven and earth than are dreamt of in your philosophy, Horatio

How

DOES

blkls

Start with a Process

The Value of Case Notes

you may have to testify a year later

what if you get hit by a bus

should have

competitive advantage

indicators of compromise

WFA 3/e

WFA

Windows Registry Forensics

WFA 2/e

don't

WRF

NOT

not

every

Sniper Forensics

images

file namealternative text

headers

H1

H2

Friday, October 14, 2011

Thursday, October 06, 2011

Wednesday, October 05, 2011

Saturday, October 01, 2011

Wednesday, September 28, 2011

Friday, September 23, 2011

Monday, September 19, 2011

Pages

Subscribe To WindowsIR

WindowsIR Blog List

Blog Archive

H3

Friday, October 14, 2011

Thursday, October 06, 2011

Wednesday, October 05, 2011

Saturday, October 01, 2011

Wednesday, September 28, 2011

Friday, September 23, 2011

Monday, September 19, 2011

Pages

Subscribe To WindowsIR

WindowsIR Blog List

Blog Archive

H4

H5

H6

internal links

addressanchor text
skip to main
skip to sidebar
Links
take a look
forensic scanner
FOSS forensic tools
past
7:03 AM
Links to this post
carbon black
ETCSS
links
NoVA Forensic Meetup
meetup
7:27 AM
Links to this post
NoVA forensics meetup
Forensic Scanner
Jump Lists
8:35 AM
Links to this post
scanner
Documentation
forensic scanner
8:09 AM
Links to this post
Documentation
WFA 3/e update
WFA 3/e
Jump Lists
7:37 AM
Links to this post
WFA
NoVA Forensics Meetup Reminder
Time and location remains the same
5:57 AM
Links to this post
NoVA forensics meetup
Friday Stuff
Jump List analysis
7:12 AM
Links to this post
ADS
F-Response
jump lists
Tools
Links and Updates
posted recently
Jump Lists
creating mini-timelines
6:05 AM
Links to this post
links
Registry
timeline
updates
Older Posts
Home
Posts (Atom)
Home
Little Black Book of Windows Forensic Secrets
Timelines
Books
Malware
NoVA Forensics Meetup
FOSS Tools
2011
October
Links
NoVA Forensic Meetup
Forensic Scanner
Documentation
WFA 3/e update
September
NoVA Forensics Meetup Reminder
Friday Stuff
Links and Updates
Links...and whatnot
NoVA Forensics Meetup Group
HowTo: Mount and Access VSCs
HowTo: File Extension Analysis
HowTo: Creating Mini-Timelines
Growing the NoVA Forensics Meetup
Updates and Links
Jump List Analysis, Pt III
Registry Stuff
Getting Started
Stuff...and whatnot
Friday Updates
August
Updates and Links
Sticky Notes Analysis
Jump List Analysis, pt II
Reconnoitre
More Updates
Carbon Black
Jump List Analysis
Updates and Links
Links and Updates
Friday Updates
Updates and Links
July
WFA 3/e
Updates
Evading Investigators and Analysts
Carbon Black
More Links, Updates
Structure Adds Context
More Links
Links
June
Meetup, Tools and other stuff
Links and Updates
Defining "Forensic Value"
Awards
Links and Updates
Thoughts on IR
OSDFC Follow-up
Updates, Links, Etc.
Updates
Updates
May
NoVA Forensic Meetup
April
March
February
January
2010
December
November
October
September
August
July
June
May
April
March
February
January
2009
December
November
October
September
August
July
June
May
April
March
February
January
2008
December
November
October
September
August
July
June
May
April
March
February
January
2007
December
November
October
September
August
July
June
May
April
March
February
January
2006
December
November
October
September
August
July
June
May
April
March
February
January
2005
December
November
October
September
August
July
June
May
April
March
February
January
2004
December

external links

addressanchor text
img
ETCSS
Carbon Black
Cb Enterprise
Rootkit Paradox
posted
OMFW
Volatility
posted yet another analysis of exploit artifacts
here
available
this
FrostWire
WordWheelQuery
Volatility
controlled by a Registry value
Email This
BlogThis!
Share to Twitter
Share to Facebook
this blog post
Yahoo group
Sniper Forensics
ReverseSpace
Email This
BlogThis!
Share to Twitter
Share to Facebook
Nessus
Digital Forensics Framework
features
ProDiscover
vhdtool.exe
convertfromraw
FTK Imager
ImDisk
F-Response
ntshrui.dll
strings
sigcheck
VirtualBox
Email This
BlogThis!
Share to Twitter
Share to Facebook
Forensic Focus
QCC Forensic CaseNotes
recently posted
Chris
img
stealth ADSs
Email This
BlogThis!
Share to Twitter
Share to Facebook
second edition
Windows Registry Forensics
this article
WFA 2/e
WRF
my Google Code site
Email This
BlogThis!
Share to Twitter
Share to Facebook
Email This
BlogThis!
Share to Twitter
Share to Facebook
recent blog post
this Exploit Monday post
Win32/Stream
img
demonstrated how to use F-Response
Mission Guides
live digital forensics
img
Chris Pogue
Here
malwarereversing blog
Volatility 2.0
Jotti
CERT Linux Forensics Tools Repository
JumpLister
DestList
AppID
ForensicsWiki
XWays
version 11
posted to the HBGary blog
ProcDump
Process Explorer
DFF
available
Email This
BlogThis!
Share to Twitter
Share to Facebook
forensic analysis of an iTunes installation
Volatility site
p4r4ni0d
Morto
new version
very good paper
here
Windows Registry Forensics
documentation
excellent post
Chris Pogue
made available
Email This
BlogThis!
Share to Twitter
Share to Facebook