Hello Reader,
If you still haven't seen my file system forensics talk you'll get another chance next weekend at Bsides San Antonio. I wasn't originally planning to go to Bsides San Antonio but once I got the opportunity I couldn't say no, to tacos. You can read more about the event here:
http://bsidestexas.com/
There is a fun selection of talks this year and I'm looking forward to spreading the good word of file system journaling and the triforce. So if you are in the south/central texas area I hope to see you there!
Hello Reader,
I had a great time today at Bsides Austin. When I come to conferences that are primarily information security focused I feel like an ambassador to the world of DFIR. I always try to explain to them what lead me out of the infosec world and into DFIR and why I feel its a better place long term. I gave the same talk here that I did at Bsides DFW but to tell the truth, I didn't stick to the slides very much. I took the time to explain whats possible with filesystem journal forensics and then extend that with other operating system artifacts for NTFS/HFS+ and EXT3 so they could understand what possible now.
I was very encouraged the majority of the audience identified themselves as doing some kind of incident response and got the concepts I was going over. I also didn't get the 'how would you defeat truecrypt if someone says they forgot their password' question until the last 5 minutes, you know you are 'that guy'! So with all of that being said I hope that some people are interested into joining the ranks of DFIR professionals as we all know we need more of us! Here is a link to download today's slides for those of you who wanted to focus more on the data structures I didn't cover.
https://drive.google.com/file/d/0B_mjsPB8uKOAdlJKd19Zc1MybVE/edit?usp=sharing
And here is the signup form for the last month of the Triforce beta:
https://docs.google.com/forms/d/1GzOMe-QHtB12ZnI4ZTjLA06DJP6ZScXngO42ZDGIpR0/viewform
Bonjour Reader,
Have you wanted to:
a) Go to a DFIR conference, but they are expensive
b) Eat a lot of really good food
Then you should consider Bsides NOLA. They just put up their agenda with all of their chosen speakers, you can find it here: http://www.securitybsides.com/w/page/71231585/BsidesNola2014.
If you haven't head of Security Bsides before its a pretty huge movement within the community to create local conferences with good speakers at a low cost to the attendee. I've attended Bsides DFW and Bsides Las Vegas, I hope to attend Bsides San Francisco this month.
What I like about Bsides NOLA compared to the other ones, and that makes it worth traveling to, is that it is unique in its focus of DFIR. Go take a look at the agenda and you'll see many familiar DFIR names speaking about a range of topics from memory analysis, APT response, to Mac Malware and information security topics. It's a great collection of good speakers and I wish I could be there myself.
Maybe next year!
Hello Reader,
With another presentation done here are my slides from PFIC, where I again presented on Anti Anti Forensics. This is a similar presentation to the one I did at Bsides DFW but with more details on the actual structure of $logfile records and more information.
Slides can be found here: Slides
We are getting close to the official release of ANJP (Advanced NTFS Journal Parser) as we write up our official blog post to put up on the SANS blog. Until then, if you would like a copy of the version 1 free tool please email me dcowen@g-cpartners.com so I can get you going. Our goal is to get the community access to our research as quickly as possible!
I'm looking for conferences to spread the good word on journaled file system forensics for next year, so if you are looking for advanced content please let me know!