<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-6190359025102133687</atom:id><lastBuildDate>Wed, 13 Sep 2017 22:33:36 +0000</lastBuildDate><category>Chat</category><category>Disk image</category><category>EnCase</category><category>EnCase Software</category><category>Instant messaging</category><category>NTFS</category><category>Tips</category><category>Tutorials</category><category>Yahoo Messenger</category><category>mount</category><title>EnCase 101</title><description>Tips and tutorials for using EnCase Forensic software.  Updated as often as I have time. (Some of these tips will work in any forensic software.)</description><link>http://encase101.blogspot.com/</link><managingEditor>noreply@blogger.com (Larry E. Daniel, DFCP, EnCE, BCE)</managingEditor><generator>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6190359025102133687.post-7968391079427645958</guid><pubDate>Tue, 31 May 2011 23:52:00 +0000</pubDate><atom:updated>2011-05-31T16:52:21.208-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">mount</category><category domain="http://www.blogger.com/atom/ns#">NTFS</category><title>Overcoming Security on Mounted Drive Images</title><description>In many cases, you will need to mount the Encase forensic image you are examining in order to run antivirus against the data, or run some other forensic tool like Drive Prophet or NetAnalysis.&lt;br /&gt;&lt;br /&gt;One of the issues you must overcome to get access to all of the areas of the hard drive, if it is an NTFS drive, is the security that prevents you from accessing the users&#39; data area on the drive.&lt;br /&gt;&lt;br /&gt;To get access to the areas protected by the NTFS security, you must take ownership of the drive by changing the security settings.&amp;nbsp; However, you cannot change security on a read-only drive.&lt;br /&gt;&lt;br /&gt;Here is how you can overcome this in Encase without having to purchase another drive mounting tool.&amp;nbsp; This does require that you have the option to mount drives as emulated disks in Encase.&lt;br /&gt;&lt;br /&gt;First, in Encase, right click on the drive letter you need to mount and select &quot;Mount as Emulated Disk&quot;&lt;br /&gt;&lt;br /&gt;Then click on he Client Info tab and uncheck disable caching.&amp;nbsp; Browse to a location for the temporary cache.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-WkOoEOgDDGw/TeV9DsEdnII/AAAAAAAAAa0/L31ohjeGAoA/s1600/Mount.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;http://3.bp.blogspot.com/-WkOoEOgDDGw/TeV9DsEdnII/AAAAAAAAAa0/L31ohjeGAoA/s320/Mount.PNG&quot; width=&quot;269&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Now, the operating system on your examination computer will believe that the drive is writable and will allow you to take ownership of the drive.&lt;br /&gt;&lt;br /&gt;You can take ownership through the properties dialog by right clicking on the drive letter of the mounted drive and going to advanced properties.&lt;br /&gt;&lt;br /&gt;Once it has completed the process of changing the ownership of the files and folders, you can navigate through the dive like any other hard drive on your computer. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;zemanta-pixie&quot; style=&quot;height: 15px; margin-top: 10px;&quot;&gt;&lt;a class=&quot;zemanta-pixie-a&quot; href=&quot;http://www.zemanta.com/&quot; title=&quot;Enhanced by Zemanta&quot;&gt;&lt;img alt=&quot;Enhanced by Zemanta&quot; class=&quot;zemanta-pixie-img&quot; src=&quot;http://img.zemanta.com/zemified_e.png?x-id=c0019e9d-b657-4ae4-9a26-e036c5fb63d6&quot; style=&quot;border: medium none; float: right;&quot; /&gt;&lt;/a&gt;&lt;/div&gt;</description><link>http://encase101.blogspot.com/2011/05/overcoming-security-on-mounted-drive.html</link><author>noreply@blogger.com (Larry E. Daniel, DFCP, EnCE, BCE)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-WkOoEOgDDGw/TeV9DsEdnII/AAAAAAAAAa0/L31ohjeGAoA/s72-c/Mount.PNG" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6190359025102133687.post-6022339000389095023</guid><pubDate>Mon, 05 Jul 2010 02:25:00 +0000</pubDate><atom:updated>2010-07-04T19:25:48.728-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Disk image</category><category domain="http://www.blogger.com/atom/ns#">EnCase</category><title>How To Load DD Images into EnCase</title><description>Version used: &lt;a class=&quot;zem_slink freebase/guid/9202a8c04000641f8000000000dc0a97&quot; href=&quot;http://en.wikipedia.org/wiki/EnCase&quot; rel=&quot;wikipedia nofollow&quot; title=&quot;EnCase&quot;&gt;EnCase&lt;/a&gt; 6.16.2&lt;br /&gt;&lt;br /&gt;If you are dealing with a forensic hard drive copy that is in DD format, it is a simple but not intuitive process to load that drive image into EnCase.&lt;br /&gt;&lt;br /&gt;Here’s how you do it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Step 1:&amp;nbsp; From the File Menu, Select Add Raw Image&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/_rc35_0eNjMA/TDE-fY66q0I/AAAAAAAAAYI/n_cRnnPIDWs/s1600/Menu.JPG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;327&quot; src=&quot;http://2.bp.blogspot.com/_rc35_0eNjMA/TDE-fY66q0I/AAAAAAAAAYI/n_cRnnPIDWs/s400/Menu.JPG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Step 2: Select the type of image you need to load.&amp;nbsp; Is this example I am going to load a &lt;a class=&quot;zem_slink freebase/guid/9202a8c04000641f8000000000091fbf&quot; href=&quot;http://en.wikipedia.org/wiki/Disk_image&quot; rel=&quot;wikipedia nofollow&quot; title=&quot;Disk image&quot;&gt;Disk Image&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/_rc35_0eNjMA/TDE-fESKTvI/AAAAAAAAAX4/EOgNKT3W-FA/s1600/Add+Raw+Dialog.JPG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;280&quot; src=&quot;http://3.bp.blogspot.com/_rc35_0eNjMA/TDE-fESKTvI/AAAAAAAAAX4/EOgNKT3W-FA/s320/Add+Raw+Dialog.JPG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Step 3: Right click in the Component Files area and Select New&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/_rc35_0eNjMA/TDE-k7LVFUI/AAAAAAAAAYQ/2DjkMn4yei4/s1600/Right+Click+and+select+Add+New.JPG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;http://4.bp.blogspot.com/_rc35_0eNjMA/TDE-k7LVFUI/AAAAAAAAAYQ/2DjkMn4yei4/s400/Right+Click+and+select+Add+New.JPG&quot; width=&quot;292&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Step 4: Browse to the folder containing the images and sort them in ascending order.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/_rc35_0eNjMA/TDE-ff1KgOI/AAAAAAAAAYA/bQR7O6St6ro/s1600/DD+Image+Parts.JPG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;151&quot; src=&quot;http://4.bp.blogspot.com/_rc35_0eNjMA/TDE-ff1KgOI/AAAAAAAAAYA/bQR7O6St6ro/s400/DD+Image+Parts.JPG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Step 5:&amp;nbsp; Select all of the parts of the DD image.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/_rc35_0eNjMA/TDE-fJf4zNI/AAAAAAAAAX8/MQ92ww0iIFs/s1600/All+Parts+Selected.JPG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;146&quot; src=&quot;http://3.bp.blogspot.com/_rc35_0eNjMA/TDE-fJf4zNI/AAAAAAAAAX8/MQ92ww0iIFs/s400/All+Parts+Selected.JPG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Step 6: Click OK to load the image parts into the Component Files dialog.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/_rc35_0eNjMA/TDE-fVBThYI/AAAAAAAAAYE/MPXjlIPAoNA/s1600/Dialog+Showing+Components.JPG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;http://2.bp.blogspot.com/_rc35_0eNjMA/TDE-fVBThYI/AAAAAAAAAYE/MPXjlIPAoNA/s400/Dialog+Showing+Components.JPG&quot; width=&quot;292&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Step 7: Click OK again to load the parts into Encase&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/_rc35_0eNjMA/TDE-k4Ow0HI/AAAAAAAAAYM/oIE47MIHMdI/s1600/Mounted+Drive.JPG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;342&quot; src=&quot;http://2.bp.blogspot.com/_rc35_0eNjMA/TDE-k4Ow0HI/AAAAAAAAAYM/oIE47MIHMdI/s400/Mounted+Drive.JPG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;You should now see the drive image correctly mounted in EnCase.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Note: Some earlier versions of EnCase 6 actually required that you sort the parts in descending order.&amp;nbsp; If you are using EnCase 6.01 - 6.12 and this does not work for you, try the process again with the image parts sorted in descending order.&lt;/i&gt;&lt;br /&gt;&lt;div class=&quot;zemanta-pixie&quot; style=&quot;height: 15px; margin-top: 10px;&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;zemanta-pixie-img&quot; src=&quot;http://img.zemanta.com/pixy.gif?x-id=a7e5e944-2559-4827-afbf-1d33772b2cbb&quot; style=&quot;border: medium none; float: right;&quot; /&gt;&lt;span class=&quot;zem-script more-related more-info pretty-attribution paragraph-reblog&quot;&gt;&lt;script defer=&quot;defer&quot; src=&quot;http://static.zemanta.com/readside/loader.js&quot; type=&quot;text/javascript&quot;&gt;&lt;/script&gt;&lt;/span&gt;&lt;/div&gt;</description><link>http://encase101.blogspot.com/2010/07/how-to-load-dd-images-into-encase.html</link><author>noreply@blogger.com (Larry E. Daniel, DFCP, EnCE, BCE)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_rc35_0eNjMA/TDE-fY66q0I/AAAAAAAAAYI/n_cRnnPIDWs/s72-c/Menu.JPG" height="72" width="72"/><thr:total>3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6190359025102133687.post-6167668281144142117</guid><pubDate>Sat, 03 Jul 2010 11:51:00 +0000</pubDate><atom:updated>2010-07-03T05:10:23.676-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Chat</category><category domain="http://www.blogger.com/atom/ns#">Instant messaging</category><category domain="http://www.blogger.com/atom/ns#">Yahoo Messenger</category><title>Finding Yahoo Messenger Artifacts</title><description>&lt;div class=&quot;zemanta-img&quot; style=&quot;display: block; float: right; margin: 1em; width: 138px;&quot;&gt;&lt;a href=&quot;http://en.wikipedia.org/wiki/File:Yahoo%21_Messenger_logo.png&quot;&gt;&lt;img alt=&quot;Yahoo! Messenger Icon&quot; height=&quot;128&quot; src=&quot;http://upload.wikimedia.org/wikipedia/en/9/96/Yahoo%21_Messenger_logo.png&quot; style=&quot;border: medium none; display: block;&quot; width=&quot;128&quot; /&gt;&lt;/a&gt; &lt;br /&gt;&lt;div class=&quot;zemanta-img-attribution&quot; style=&quot;font-size: 0.8em;&quot;&gt;Image via &lt;a href=&quot;http://en.wikipedia.org/wiki/File:Yahoo%21_Messenger_logo.png&quot;&gt;Wikipedia&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;Sometimes you have to locate &lt;a class=&quot;zem_slink freebase/guid/9202a8c04000641f800000000015a672&quot; href=&quot;http://messenger.yahoo.com/&quot; rel=&quot;homepage nofollow&quot; title=&quot;Yahoo! Messenger&quot;&gt;Yahoo Messenger&lt;/a&gt; artifacts when the program was not set to log anything.&amp;nbsp; When that happens, chances are your only avenue will be to search for artifacts in unallocated space.&lt;br /&gt;&lt;br /&gt;The most likely place to locate these artifacts will be in the &lt;a class=&quot;zem_slink freebase/guid/9202a8c04000641f80000000001c991c&quot; href=&quot;http://en.wikipedia.org/wiki/Paging&quot; rel=&quot;wikipedia nofollow&quot; title=&quot;Paging&quot;&gt;pagefile.sys&lt;/a&gt; and the hiberfile.sys if it exists.&lt;br /&gt;&lt;br /&gt;You will want to create a case level keyword of øÿYMSG as all Yahoo Messenger communications begin with that string.&lt;br /&gt;&lt;br /&gt;When you create the keyword, you can just leave it as ASCII.&amp;nbsp; No need to use &lt;a class=&quot;zem_slink freebase/guid/9202a8c04000641f800000000005ca33&quot; href=&quot;http://en.wikipedia.org/wiki/Grep&quot; rel=&quot;wikipedia nofollow&quot; title=&quot;Grep&quot;&gt;GREP&lt;/a&gt; for this and it is not a whole word search.&lt;br /&gt;&lt;br /&gt;For the first pass, run it against just the pagefile.sys.&lt;br /&gt;&lt;br /&gt;You should get search hits that look like the following:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;NOTE: The following is not a conversation between real people.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;øÿYMSG T ûöY5À€bigbadlovindaddyÀ€4À€fluffybunnyfromspaceÀ€14À€ok great&lt;/li&gt;&lt;li&gt;øÿYMSG m ûöY1À€bigbadlovindaddyÀ€5À€fluffybunnyfromspaceÀ€14À€what are you doing now&amp;nbsp;&lt;/li&gt;&lt;li&gt;øÿYMSG f ûöY1À€bigbadlovindaddyÀ€5À€fluffybunnyfromspaceÀ€14À€it is getting late&lt;/li&gt;&lt;li&gt;øÿYMSG B ûöY1À€bigbadlovindaddyÀ€5À€fluffybunnyfromspaceÀ€14À€I think I should go to bed soon&amp;nbsp; &lt;/li&gt;&lt;li&gt;øÿYMSG 6 ûöY5À€bigbadlovindaddyÀ€4À€fluffybunnyfromspaceÀ€14À€why? It aint that late&amp;nbsp;&lt;/li&gt;&lt;li&gt;øÿYMSG ? ûöY5À€bigbadlovindaddyÀ€4À€fluffybunnyfromspaceÀ€14À€I got to work in the morning&amp;nbsp;&lt;/li&gt;&lt;li&gt;øÿYMSG J ûöY1À€bigbadlovindaddyÀ€5À€fluffybunnyfromspaceÀ€14À€ok see you laters&amp;nbsp;&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;You cannot get dates or times from these artifacts.&amp;nbsp; Nor will the artifacts give any indication of the direction of the chat.&lt;br /&gt;&lt;br /&gt;You will also recover artifacts giving you other screen names using this method.&lt;br /&gt;&lt;br /&gt;In a case I did using this method, I was looking for a phone number.&amp;nbsp; No logging was turned on in Yahoo Messenger and no artifacts or saved sessions were available by looking at Yahoo Messenger itself.&lt;br /&gt;&lt;br /&gt;By using this method, I did recover the conversation and the phone number that was needed by law enforcement.&lt;br /&gt;&lt;div class=&quot;zemanta-pixie&quot; style=&quot;height: 15px; margin-top: 10px;&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;zemanta-pixie-img&quot; src=&quot;http://img.zemanta.com/pixy.gif?x-id=6df4514e-3f54-4646-9bf5-f652a173d910&quot; style=&quot;border: medium none; float: right;&quot; /&gt;&lt;span class=&quot;zem-script more-related more-info pretty-attribution paragraph-reblog&quot;&gt;&lt;script defer=&quot;defer&quot; src=&quot;http://static.zemanta.com/readside/loader.js&quot; type=&quot;text/javascript&quot;&gt;&lt;/script&gt;&lt;/span&gt;&lt;/div&gt;</description><link>http://encase101.blogspot.com/2010/07/finding-yahoo-messenger-artifacts.html</link><author>noreply@blogger.com (Larry E. Daniel, DFCP, EnCE, BCE)</author><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6190359025102133687.post-7090511890016929378</guid><pubDate>Fri, 02 Jul 2010 22:28:00 +0000</pubDate><atom:updated>2010-07-02T15:28:38.643-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">EnCase Software</category><category domain="http://www.blogger.com/atom/ns#">Tips</category><category domain="http://www.blogger.com/atom/ns#">Tutorials</category><title>Getting started with something new.</title><description>I have wanted for a long time to start a new blog with tips and tutorials for those folks just getting started with or currently using Encase Forensics software.&lt;br /&gt;&lt;br /&gt;Even if you don&#39;t use EnCase as your forensic software tool, I think you might find some of my tips helpful as they will show you how to find certain types of data in your examinations. &lt;br /&gt;&lt;br /&gt;While my time is limited, I plan to share on this blog as often as I can.&lt;br /&gt;&lt;br /&gt;I plan to get my first post up on EnCase in the next few days so stay tuned. &lt;br /&gt;&lt;br /&gt;If you have suggestions for this blog or would like to see something covered, drop me an email or send me a DM on Twitter.&lt;br /&gt;&lt;br /&gt;Happy forensicing!</description><link>http://encase101.blogspot.com/2010/07/getting-started-with-something-new.html</link><author>noreply@blogger.com (Larry E. Daniel, DFCP, EnCE, BCE)</author><thr:total>0</thr:total></item></channel></rss>