Brett's Ramblings

"Placing the Suspect Behind the Keyboard" discount code
Brett Shavers
Digital Forensics
Cool.  Looks like there is a new discount on my book, "Placing the Suspect Behind the Keyboard".  Plus, it also looks like an entire chapter is available for download.[caption id="1142" align="alignleft" width="266"] Cool. A discount. Get it while you can!I'm also giving a presentation on this book at NOLACON (New Orleans, Louisiana).
Hey look! Now there is a book on FTK.
Brett Shavers
Books
http://amzn.to/O38eWhI previously posted that a book on FTK is sure to come along, since we have the best book of X-Ways and the other book on Encase.  Now comes a book on FTK.  Just like the XWF Guide or the upcoming Encase guide, I wouldn't see any reason for a FTK user to not have a book on FTK.It makes sense to have "the" book on X-Wa...
Network Investigation & Digital Triage by SEARCH.org
Brett Shavers
Digital Forensics
Network Investigation & Digital Triage Very cool.  SEARCH.org teaches WinFE in its Network Investigation & Digital Triage course.[caption id="attachment_1108" align="alignleft" width="700"] http://www.search.org/get-help/training/high-tech-crime-investigations/instructor-led-training/network-investigation-and-digital-triage/
Not X-Ways, but of interest to Encase users
Brett Shavers
Books
Computer Forensics and Digital Investigation with EnCase Forensic http://amzn.to/1eY02wn I know, this has nothing to do with X-Ways Forensics.  But hey, the X-Ways Practitioner's Guide was first...Practically, this seems like a good book for Encase users to park on the shelf (while the X-Ways Practitioner's Guide sits on your desk next to...
WinFE (and of course, XWF)
Brett Shavers
Digital Forensics
Taking WinFE to even another level on a multiboot thumbdrive.  Very cool, but I spread this word to you because there are few things in life neater than a forensically bootable CD/USB with X-Ways Forensics. From Hacking Exposed: Adding the WinFE Image to the Multiboot Thumbdrive Image (Video) http://www.youtube.com/watch?v=Ce9eQ0OG2jAhttp...
From Hacking Exposed: Adding the WinFE Image to the Multiboot Thumbdrive Image (Video)
Brett Shavers
Digital Forensics
Taking WinFE to even another level on a multiboot thumbdrive.  Very cool.http://www.youtube.com/watch?v=Ce9eQ0OG2jAhttp://hackingexposedcomputerforensicsblog.blogspot.com/2014/02/daily-blog-248-adding-winfe-image-to.html
A gathering of the X-Ways users in Australia
Brett Shavers
Digital Forensics
The X-Ways Users Conference is here in a few weeks.  My kind of conference: Australia and fellow X-Ways users!    Maybe next year for me...but it sure would make for a good vacation, I mean, training trip.       http://xways.cbit4n6.com.au/    
Another reason to use, try, or at least just learn about XWF
Brett Shavers
Digital Forensics
Not that many years ago, you would not find a requirement of having experience with X-Ways to apply for a DFIR job.   But now, some jobs recommend it and yet some others require it.  This is not to say the other big players (Encase, Accessdata, etc..) are not needed or useful, just that XWF has made it to the same level at a price po...
Hacking Exposed - Daily Blog #242, How to build WinFE to add to the Multiboot thumbdrive
Brett Shavers
Digital Forensics
David Cowen has a great instruction writeup on adding WinFE to the Multiboot thumbdrive.  I am anxious to see the video he plans to make next week to add this to the multiboot thumbdrive.[caption id="attachment_1091" align="aligncenter" width="683"] http://hackingexposedcomputerforensicsblog.blogspot.com/2014/02/daily-blog-242-how-to-build-winfe-to...
WinFE has some street cred with the Scientific Working Group on Digital Evidence
Brett Shavers
Digital Forensics
Cool.  WinFE is mentioned in a Scientific Working Group on Digital Evidence document. SWGDE UEFI and its Effect on Digital Forensics Imaging https://www.swgde.org/documents/Current%20Documents/2014-02-06%20SWGDE%20UEFI%20Effect%20on%20Digital%20Imaging%20V1
No surprise. XWF does something other tools don't
Brett Shavers
Digital Forensics
From a twitter post, a cool video on imaging with X-Ways noted (13:50) as doing something other tools don't.  The entire video is actually pretty good too.http://youtu.be/zYYCv21I-1I
WFA/4e
Brett Shavers
Books
I'm duplicating this post from another blog because this will probably be the coolest book to come out this year in digital forensics and is a must-have.  The short version as to why the book is a must-have is "duh, it's Harlan's latest book...and Windows 8..."I'll wait to give an "official" review of Harlan's book (Windows Forensic Analysis Toolki...
Windows Forensic Analysis, Fourth Edition
Brett Shavers
Digital Forensics
I'll wait to give an "official" review of Harlan's book (Windows Forensic Analysis Toolkit, Fourth Edition: Advanced Analysis Techniques for Windows 8) only to give others the chance to read it once it becomes available.  But...I'll say that based on my early reading as a tech editor, this is a book that ranks for me in as much anticipation as a ne...
More WinFE work and research!
Brett Shavers
Digital Forensics
It is always nice to find more than a few people work on any project which benefits many others.  This blog (http://gverswijvel.wordpress.com/) shows that effort. Winfe : the forensic winpe made in windows 8 , windows 7 and vista There is quite of bit of information and tips regarding WinFE, all of which is helpful to anyone who uses WinFE.   And n...
Natural Progression for New Users of WinFE
Brett Shavers
Digital Forensics
A new user to WinFE can be a new forensic analyst or a forensic analyst new to WinFE.  Either way, this short post will be helpful to everyone who has not yet taken the time to try WinFE.  To save you frustration, time, and questions, try this natural progression to start using WinFE:1) Start with Mini-WinFE2) Move onto bigger builds (WinFE Lite or...