Monday, November 10, 2014

Excellent book about Python and digital forensics "Python Forensics"

It is an excellent book, I finally get some time to read it in detail on O'reily web. Perfect one with practical things and how to think about problem attitude. Some time ago while we were preparing taring curriculum for OLAF I've suggested one week training with almost same idea.

I'll definitely include it into net redo of my forensic curriculum on Vsite and Algebra as extension of practicals.

This will bring some more excitement into class and practicals, I've noticed that my teaching becomes a bit dull during last class...

I was thinking earlier about using only "Violent Python" but "Python Forensics" is better suited for pure forensic training while violent one is better for general security issues. 

Wednesday, November 5, 2014

EnCase training last week

Last week I've been doing very pleasant and intense but still very exhausting EnCase training
Forensic 2 and Transition in 7 days in row.  It was for 2 attendees, so more discussion than real training with a lot of time to go trough things, do variations etc.

We have done some scenarios with  USB devices  and processing, very interesting with some surprises :)

It was very challenging and take a lot of from all of us especially since we put effort on solving some practical problems, I finally get confirmation both attendees survived harsh tempo and EnCase peculiarities.

Version we used is v7,10.01 which is last release, more stable than previous but since not as reliable as now almost formally abandoned version 6.  We used processed cases as backup and done real processing during lunch breaks, it was about 1 minute for 1 GB processing time, what is acceptable for small educational images. Caches are now much more stable and indexing is working acceptably, but there are quirks while new views are generated on evidence trough filters and conditions.  Missing conditions in bookmarks and some other views are extremely annoying but as user can't do much.