Menu
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact

Brett Shavers | Ramblings

Brett's Ramblings

Subscribe to blog
Unsubscribe from blog
Settings
Sign In
If you are new here, Register
  • Forget Username
  • Reset Password

By accepting you will be accessing a service provided by a third-party external to https://brettshavers.com/

direct link
APR
20
0

Case Studies

Posted by Brett Shavers
in  Digital Forensics

Here are some of the case studies we are working on for our current and last chapter:

Image

  • Electronic Discovery (IP theft, document collection, contract antedating)
  • Consent Searches (triage/preview)
  • Parole Searches (triage/preview)
  • Malicious Software
  • Intrusion
  • Fraud
  • Child Pornography
  • Cell phone analysis

Several of these are being submitted by contributors, and all are to be detailed using XWF and suggested case flow processes.  Contributors to be duly noted (as much as they allow).

  2861 Hits
Tags:
X-Ways Forensics X-Ways Forensics Practitioner's Guide
Tweet
Share on Pinterest
2861 Hits
APR
16
0

Multiple File Finder X-Tension for X-Ways Forensics

Posted by Brett Shavers
in  Digital Forensics

Here is a new X-Tension for XWF that does a few neat things, such as searching for specific files and adding them to the report table, and exporting files for external analysis: http://www.gaijin.at/en/xtmultifilefinder.php

 

  3216 Hits
Tags:
X-Ways Forensics
Tweet
3216 Hits
APR
14
3

Starting the last chapter!

Posted by Brett Shavers
in  Digital Forensics

We are starting the last chapter (Case Studies) and have a few contributors already for case examples.  We'll gladly take more as we want to have a wide range of case studies using X-Ways.

Image

For everyone waiting, we are finishing the book much earlier than we had planned, only because it has been a smooth process with the authors (Brett and Eric), the Tech Editor (Jimmy), and publisher (agreeing to push up the schedule to keep up with us!).

We've also had offers of translating the book into other languages, and are visiting that topic.  So far, maybe French...suggestions for others?

  2447 Hits
Tags:
X-Ways Forensics Practitioner's Guide
Tweet
Share on Pinterest
Recent Comments
Guest — René
Hello! What's about a german translation including german screenshots? I might try it. I'm using x-ways for several years (in the... Read More
Sunday, 14 April 2013 19:44
Guest — Denny
From the x-ways.net website: "Sales-wise (software only), the majority of our customers reside in the USA (34%) and Germany (33%)... Read More
Monday, 15 April 2013 00:03
Guest — Brett Shavers
We have passed the information to the publisher and hope this can happen.
Tuesday, 16 April 2013 03:05
2447 Hits
APR
14
0

Starting the last chapter!

Posted by Brett Shavers
in  Digital Forensics
Be sure to keep up on the progress of my second book (X-Ways Forensics Practitioner's Guide) at https://xwaysforensics.wordpress.com/.  Eric Zimmerman and I are on the last chapter!

After the book is done, I have a few new things to test and post about WinFE to update the old, bring in the new.
  1891 Hits
Tweet
1891 Hits
APR
10
0

WinFE and UEFI Secure Boot!

Posted by Brett Shavers
in  Digital Forensics

Don't get excited, there isn't a solution to Windows RT or Secure Boot and WinFE (yet!).  But for those working on it, here are two links of interest that help explain a few of the technical details.

 http://www.uefi.org/learning_center/

The UEFI secure boot specification is owned by the UEFI consortium, not Microsoft, so the consortium documentation and specification sets out the real rules of the road for working with UEFI.

http://noggin.intel.com/content/the-flow-of-booting-an-intel-architecture-system

This information was sent to me by the Yoda of WinFE.

  2037 Hits
Tweet
2037 Hits
APR
07
0

Case Studies with X-Ways

Posted by Brett Shavers
in  Books
We are WAY ahead of our planned writing schedule, mostly because of the XWF Guide writing and editing team are getting things done, fast.

With that, we are reaching the Case Studies chapter, where we will give specific case flow and XWF usage by the type of case.  That means, we have a section on "How to Use XWF on a Child Pornography Case" and "How to Use XWF in an Electronic Discovery Case", and more.

case studies

For this chapter to be of most use to the most number of readers, please give us what type of cases you want us to cover.  PLUS, if you have used XWF in a case that worked well, send us your (sanitized) case study and we will add it to the chapter.  Depending on how you'd like credit, we can credit you with the specific case ("case study submitted by ...."), or generically ("so and so" contributed to the case studies chapter), or not at all if you want to remain in the background with a case study.

Don't forget to follow us on Twitter to keep up with the book's progress.  It's going fast and you don't want to miss out.

I can also say that although I felt I was competent XWF user (since 2004!), the research, testing, and delving in XWF for this book opened my eyes to more capabilities of XWF that I never imagined.  You won't be disappointed and after reading this book, you will be using that green XWF dongle a lot!
  2060 Hits
Tweet
Share on Pinterest
2060 Hits
APR
03
0

Table of contents updated!

Posted by Brett Shavers
in  Books
Chapter 4 is wrapping up! We each have one more chapter to go and then we start the case studies.

The table of contents page is updated to reflect the topics of each chapter and, for the completed chapters, the page and word count of each.
  2297 Hits
Tags:
book
Tweet
2297 Hits
APR
02
0

XWFRT updated to 0.4.8

Posted by Brett Shavers
in  Digital Forensics

Several fixes based on user testing in this build to include:


  • Added Undo button to reverse the tweaking process

  • Rearranged GUI to make it less congested

  • Undo tweaking automagically if an error occurs to keep report in a known good state

  • A bunch of processing fixes to allow for tweaking more than one report in a row


  •  


 

 

  2297 Hits
Tags:
X-Ways Forensics
Tweet
2297 Hits
APR
02
0

XWFIM goes International!

Posted by Brett Shavers
in  Digital Forensics

Just released version 0.0.4.8 that includes fixes for international users. The issue had to do with date/time formats and the use of non period decimal separators.

Both should be fixed, but if any of our international friends are having issues, please shoot me an email and I will get it resolved ASAP

  2358 Hits
Tags:
X-Ways Forensics
Tweet
2358 Hits
MAR
29
0

XWFRT and XWFIM updated

Posted by Brett Shavers
in  Digital Forensics

You can let the latest build of XWFIM from the URL in the X-Ways Forums or just use the auto-update feature in the program by looking in the lower right corner of the program after it starts.

XWFRT was also updated recently. again you can auto update or pull a copy from here:

https://www.dropbox.com/s/6labcj537jlxnzz/XWFRT.exe

if you run into any reports that cause XWFRT to throw an error, please zip and email me all of the Report*.html files (not any of the directories which contain files) and i will get the issue resolved ASAP

Enjoy!

  2636 Hits
Tags:
X-Ways Forensics
Tweet
2636 Hits
MAR
29
0

XWFRT 0.0.4.6 released

Posted by Brett Shavers
in  Digital Forensics

New in this version is the ability to attach one or more external files to your report.

This includes things like XWF registry reports (as seen below). You can include any kind of file to the report in this manner. HTML files will be viewable directly in the browser.

The screenshot below shows 2 registry reports being added as external files.

ExternalItem1

And here we see what the report would look like as a result of including the files.

 

 

ExternalItem2

  2200 Hits
Tags:
X-Ways Forensics
Tweet
Share on Pinterest
2200 Hits
MAR
27
1

XWFRT now available

Posted by Brett Shavers
in  Digital Forensics

More to come and i am sure someone will break it, but for now, here it is!

 

https://www.dropbox.com/s/6labcj537jlxnzz/XWFRT.exe

 

kick it around and email me with any bugs or suggestions

  2509 Hits
Tags:
X-Ways Forensics
Tweet
Recent comment in this post
Guest — Eric Zimmerman
Just pushed version 0.0.4.5 that adds paging for each report table. you get one page for every "Max items per page." Make sure the... Read More
Wednesday, 27 March 2013 20:49
2509 Hits
MAR
27
3

Coming soon...X-Ways Forensics Report Tweaker, or XWFRT for short

Posted by Brett Shavers
in  Digital Forensics

Ever generate a report in XWF and ended up with more than one Report*.html page? Ever been stymied by the fact that those handy menus at the top don't link to anything outside the main Report.html page?

Yea, me too, but no more!

This isnt quite done yet, but its close. here is an overview and some screenshots. In my testing, reports get tweaked in less than a second or 2 for a 9 page XWF report.

 

Here is what the main interface looks like. Basically, choose the case file, choose the directory where you exported your report to, set some other option information (like who you are, your agency, a logo), write a narrative (if you want) and TWEAK!

3-27-2013 9-45-40 AM

 

The Narrative is nice because it supports HTML, so if you wanted to get crazy and write up a nice, fancy report with lists and stuff to include in your report, go for it!

The items at the top, like the logo and the agency, arr taken from what you enter in XWFRT

3-27-2013 9-45-51 AM

 

The menu on the left contains items for general case info, all evidence items and, if present, audit trail information. Clicking a menu loads the relevant section into the main part of the window (the General tab is shown below).

3-27-2013 9-45-54 AM

 

 

here we see the evidence items page

3-27-2013 9-45-57 AM

 

 

and finally, clicking on a report table page.

3-27-2013 9-46-02 AM

 

 

I have a bit more polish to put on this thing before i release the first version to include having a setting in the GUI to control the max # of items on a report table page. For example, if you exported 1500 images in report table "Foobar" and set the max per page in XWFRT to 500 items a page, you would get Part 1, Part 2, and Part 3 links under the "Foobar" heading.

 

Oh yea, the entire look and feel is all controlled by CSS, so you can, by editing one simple file, completely change the look and feel of the report to suit your department's needs (colors, layout, borders, EVERYTHING)

 

What else does the community want to see this thing do?

  3193 Hits
Tags:
X-Ways Forensics
Tweet
Share on Pinterest
Recent Comments
Guest — wmarney
Why don't you start pre-order sales for your book? I'm ready to buy. Wayne
Wednesday, 27 March 2013 10:19
Guest — Eric Zimmerman
hehe! That's up to the publisher, not us! =) we will look into when pre-orders will start! Thanks for the interest!
Wednesday, 27 March 2013 10:26
Guest — Eric Zimmerman
When the release drops, you will be able to save multiple narratives so you can load different types of report templates into the ... Read More
Wednesday, 27 March 2013 10:29
3193 Hits
MAR
25
10

XWFIM updated

Posted by Brett Shavers
in  Digital Forensics

Just pushed version 0.4.3 out.

 

This version will now track the last selected version as opposed to always defaulting to the newest available version

I also added a check on startup for any new updates for the last version you selected. That way you will know as soon as you start XWFIM whether there are updates or not.

Finally, i fixed a (stupid) bug related to mplayer install when doing a new or clean install.

 

please report any issues to me here or via email and I will get em fixed ASAP!

  3670 Hits
Tags:
X-Ways Forensics
Tweet
Recent Comments
Guest — Aptegra
Download link?
Monday, 25 March 2013 09:02
Guest — Brett Shavers
The link is available in the XWF support forum so that only registered users of XWF can access it.
Monday, 25 March 2013 09:23
Guest — Aptegra
Thanks. May I suggest this: http://bit.ly/xwfim
Monday, 25 March 2013 09:50
3670 Hits
MAR
23
2

X-Tensions, what would you like to see it do?

Posted by Brett Shavers
in  Digital Forensics

Do you have any ideas for an X-Tensions based plugin in X-Ways? if so, post it in the comments! I have a few ideas for the advanced chapter which includes X-Tensions, but want to hear from the community as well.

  2367 Hits
Tags:
X-Ways Forensics
Tweet
Recent Comments
Guest — Wayne
Mount a Registry Hive like a volume within the case. This will allow you to sort the keys with the files so you can export a comp... Read More
Sunday, 24 March 2013 08:26
Guest — Denny Mleinek
Search files by config-list.. if found create RT entry and extract (both optional by config) Good for registry, p2p i.e.... Read More
Tuesday, 26 March 2013 14:38
2367 Hits
    Previous     Next
14 15 16 17 18 19 20 21 22 23

DFIR Training

Be sure to check out my DFIR Training website for practically the best resources for all things Digital Forensics/Incident Response related.


Brett's blog

© 2022 Brett Shavers