Skip to content
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe

Friendly reminders are always nice

By Brett Shavers
April 24, 2011
3

Always test your tools (this includes WinFE).  Considering that NIST recently discovered that some Ubuntu based forensic boot discs could make modifications to a booted suspect drive (modifies the $logfile upon booting….),  these sort of news breaks are a friendly reminder to test your tools.  Additionally, when ‘bugs’ are found in forensic tools, it may help to review any cases that may be affected by a past use of a tool.  Even Guidance Software just released a firmware update to a hardware physical write blocker in which writes to the evidence drive were not protected.  How’s that for reassurance with hardware write blockers being known as the absolute write protection tool?

You can’t rely upon someone else’s work, you can’t even rely upon the label of a box of something you buy.  You just have to spend the time to test it personally.

If you’ve not tested a tool that you used and later find that there was a problem with it, how long will you worry about one of those times you relied upon it to come back to haunt you in a past case?

Better that you tested it (“I know it works because I tested it“) rather than rely on someone else to test it (“But the company/website/brochure said it worked...”). 


Discover more from Brett's Ramblings

Subscribe to get the latest posts sent to your email.

Author

Brett Shavers

Follow Me
Other Articles
Previous

How easy (or difficult) is it to build a WinFE with WinBuilder?

Next

Sharing the love with WinFE

3 Comments
  1. Sandro says:
    April 30, 2011 at 11:07

    “Considering that NIST recently discovered that some Ubuntu based forensic boot discs could make modifications to a booted suspect drive (modifies the $logfile upon booting….), ”

    Ciao!

    can you be a little more specific? which Ubuntu based forensic?
    any link to the Publication you refer?

    thanks for your hard work!
    Sandro

    Reply
  2. Brett Shavers says:
    April 30, 2011 at 15:25

    I don’t have the information, but you can contact http://forwarddiscovery.com/ as they updated their Linux boot disc from the NIST findings.

    Reply
  3. Sandro says:
    May 1, 2011 at 05:26

    I will!
    thanks!
    Sandro

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • X
  • LinkedIn
  • Bluesky
  • Instagram
  • Mastodon
  • FACT Attribution Framework
  • https://www.dfir.training
  • https://winfe.wordpress.com
  • https://xwaysforensics.wordpress.com

My recent interview on a really good DFIR podcast (Parsing the Truth).

  • X
  • LinkedIn
  • Instagram
  • Bluesky
  • Facebook
  • Mastodon
  • YouTube
Copyright 2026 — Brett's Ramblings. All rights reserved.