The Most/Recent Articles

Showing posts with label what don't we know. Show all posts
Showing posts with label what don't we know. Show all posts

Daily Blog #81: Encyclopedia Forensica

Encyclopedia Forensica by David Cowen - HECF Blog

Hello Reader,
         If you read yesterdays blog post I was trying to understand a system for determining what we don't know. In the comments that followed there was a good conversation that lead to a system that should lead us there.

Step 1. Create a neat project name (Check!)
Step 2. Create a forensic wiki page for it (Check!)
Step 3. Write a blog about it! (Check!)
Step 4. Document every known artifact for each major OS
Step 5. Map artifacts to processes and methodologies for determining answers to questions
Step 6. Determine what questions are left unknown
Step 7. Determine what areas of the system have not been analyzed to find the answers to these questions

So as you can see I'm not 1/3 of the way done! I've decided to dub this project, the Encyclopedia Forensica and have created a wiki page for it here:

http://www.forensicswiki.org/wiki/Encyclopedia_Forensica

My hope is that you will join me in this project and we can divide and conquer our way through the rest of the steps to create a corpus of knowledge that can only benefit all of us. Today in the spare time I find between investigations I plan to start sketching out template pages and seek your input on what you feel needs to documented in order to fully describe what is known.

I really like the idea of doing this on the forensic wiki as I can link to all the already written articles for those artifacts that have been documented. The point of this project is not to reinvent what has already been created but to catalog, create and organize a common body of knowledge to find whats missing.

So if you have been looking for a project either for work, school or hobby I invite you to join this one as all skill levels can participate and I can make cool t-shirts.

Also Read: Daily Blog #80

Daily Blog #80: What don't we know?

by David Cowen - Hacking Exposed Computer Forensics Blog

Hello Reader,
         One of the things we've been talking about through the blog, on twitter and elsewhere is forensic research. Joachim Metz has been nice enough to point out areas where ideas and topics of research that need to be completed have been accumulating and I think that's great. What I keep wondering though is what don't we know?

What do I mean by that? We talk in computer forensics about how applications, operating systems, embedded devices and networks work together and the live and postmortem indications of their usage. We talk at length about what a registry key means, or a log file indicates as we look at systems to try to understand what was done to a system we are investigating. In all this work I think its time we stop and trying to figure out what we do and do not know.

So I'm going to start a page on the forensic wiki, hopefully tomorrow, and start with one version of Windows and lets work together to lay out what we do and don't know about what exists. Most of the time when new forensic research comes out that reveals something new and extraordinary its not because the feature was created the day before but because a forensic researcher realized that some previously unknown or not understood activity was occurring and they put their mind to determining what it was.

What are your thoughts on this? Leave a comment below and lets see if we can map out what we know and don't know about the systems we investigate everyday.