Wednesday, August 8, 2012

Updates and status

Hello Reader!,
                       It's been awhile since we've talked. Things here at G-C have been pretty busy, the legal sector at least appears to be in a full recovery (knock on wood). While I haven't had time to write up a full blog post on some of the new things we've found over the summer, I did want to take the time to show you how our NTFS $logfile parser is coming. For those of you who attended my CEIC session on 'anti-anti forensics' or who downloaded the labs I posted afterwords you know that we had a rough parser and tests to recover the names of wiped files before.

I'm happy to say we've come a long way since then. The initial proof of concept parser was shown to validate the artifact and divide up the pieces into something we could then further understand. We now have a parser, that is still in development, that can go even further creating CSVs of human readable data extracted from those $logfile segments.

What does that mean? Well it means:
1. We can recover the names of deleted files and their metadata, even if its been purged out of the MFT. This includes the metadata associated with the file (directory, creation, modification and acess times).
2. We can recover the complete rename operation showing cleanly which file became which file. Including parsing out the directory, creation, modification and access times before and after the operation. This essentially will allow you to undo what a wiper has done (except for recover the contents of the file itself).
3. We can determine if files were written to other drives, and an approximation of how many. (This is not in the current version of the parsers and will require ist own blog post).
4. We can recover the original metadata of a file when it was created
5. We should be able to recover timestamps that have been altered

It's all written in perl (woo!) and we are going to release the source and documentation as soon as its ready (tm). In the mean time check out this awesome screenshot showing the parser recovering the metadata from 22 files that were wiped with eraser:




If you are need of this tool for a case immediately drop me a line and I'll see what we can do to help you out!

2 comments:

  1. Pengen yang lebih seru ...
    Ayo kunjungi www.asianbet77.com
    Buktikan sendiri ..

    Real Play = Real Money

    - Bonus Promo Red Card pertandingan manapun .
    - Bonus Mixparlay .
    - Bonus Tangkasnet setiap hari .
    - New Produk Sabung Ayam ( minimal bet sangat ringan ) .
    - Referal 5 + 1 % ( seumur hidup ) .
    - Cash Back up to 10 % .
    - Bonus Royalty Rewards setiap bulan .

    Untuk Informasi lebih jelasnya silahkan hubungi CS kami :
    - YM : op1_asianbet77@yahoo.com
    - EMAIL : melasian77cs@gmail.com
    - WHATSAPP : +63 905 213 7234
    - WECHAT : asianbet_77
    - SMS CENTER : +63 905 209 8162
    - PIN BB : 2B4BB06A / 28339A41

    Salam Admin ,
    asianbet77.com

    Download Disini

    ReplyDelete
    Replies
    1. SAYA SANGAT BERSYUKUR ATAS REJEKI YANG DIBERIKAN KEPADA SAYA DAN INI TIDAK PERNAH TERBAYANKAN OLEH SAYA KALAU SAYA BISA SEPERTI INI,INI SEMUA BERKAT BANTUAN MBAH RAWA GUMPALA YANG TELAH MEMBANTU SAYA MELALUI NOMOR TOGEL DAN DANA GHAIB,KINI SAYA SUDAH BISA MELUNASI SEMUA HUTANG-HUTANG SAYA BAHKAN SAYA JUGA SUDAH BISA MEMBANGUN HOTEL BERBINTANG DI DAERAH SOLO DAN INI SEMUA ATAS BANTUAN MBAH RAWA GUMPALA,SAYA TIDAK AKAN PERNAH MELUPAKA JASA BELIAU DAN BAGI ANDA YANG INGIN DIBANTU OLEH RAWA GUMPALA MASALAH NOMOR ATAU DANA GHAIB SILAHKAN HUBUNGI SAJA BELIAU DI 085 316 106 111 SEKALI LAGI TERIMAKASIH YAA MBAH DAN PERLU ANDA KETAHUI KALAU MBAH RAWA GUMPALA HANYA MEMBANTU ORANG YANG BENAR-BANAR SERIUS,SAYA ATAS NAMA PAK JUNAIDI DARI SOLO DAN INI BENAR-BENAR KISAH NYATA DARI SAYA.BAGI YANG PUNYA RUM TERIMAKASIH ATAS TUMPANGANNYA.. BUKA DANA GHAIB MBAH RAWA GUNPALA

      Delete