USB Devices Redux

Back in 2005, Cory Altheide and I published the first paper on tracking USB storage devices across Windows systems; at the time, the focus was Windows XP. A lot has happened since then…I know, that’s an understatement…as the Windows platform has de… Continue reading USB Devices Redux

Posted in Uncategorized

File Formats

Having an understanding of file formats is an important factor in DFIR work. In particular, analysts should understand what a proper file using a particular format should look like, so that they can see when something is amiss, or when the file itself … Continue reading File Formats

Posted in Uncategorized

LNK (Ab)use

I’ve discussed LNK files a number of times in this blog, and to be honest, I really don’t think that this is a subject that gets the attention it deserves. In my experience, and I humbly bow to collection bias here, LNK files are not as well understood… Continue reading LNK (Ab)use

Posted in Uncategorized