<?xml version="1.0" encoding="UTF-8"?><rss version="0.92">
<channel>
	<title>Forensic Computing</title>
	<link>http://www.forensicblog.org</link>
	<description>Digital forensics from the view of a computer scientist</description>
	<lastBuildDate>Tue, 06 Apr 2010 08:10:09 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress/3.0" -->

	<item>
		<title>If Apple did computer forensics&#8230;</title>
		<description><![CDATA[This is too funny&#8230; &#8220;The writeblocker, iBlock, would only image at 1 mb/s and would have a non-replacable internal battery with a 12-month lifespan. When everyone who was going to buy one had done so, they’d release an iBlock ’s’ – this writes at a speed approaching the commercial standard but still has the battery [...]]]></description>
		<link>http://www.forensicblog.org/2010/04/06/if-apple-did-computer-forensics/</link>
			</item>
	<item>
		<title>Outlook PST (Personal Folder) File Format Now Available From Microsoft</title>
		<description><![CDATA[Microsoft has decided to publish a copy of the Outlook Personal Folder File format (.PST file).  You can view the specification at: http://msdn.microsoft.com/en-us/library/ff385210.aspx]]></description>
		<link>http://www.forensicblog.org/2010/02/22/outlook-pst-personal-folder-file-format-now-available-from-microsoft/</link>
			</item>
	<item>
		<title>Site Updates</title>
		<description><![CDATA[Recently I&#8217;ve been making some updates to this site.  Here is a brief list: New Theme If you&#8217;re looking at the site right now, you&#8217;ve probably noticed that the theme has changed.  I had been using Andreas Viklund&#8217;s 1024px for a few years, and decided it was time for something new.  I ended up drinking [...]]]></description>
		<link>http://www.forensicblog.org/2009/12/01/site-updates/</link>
			</item>
	<item>
		<title>Microsoft to Release the .PST File Format</title>
		<description><![CDATA[@MicrosoftPress tweet&#8217;d this earlier today: &#8216;Paul Lorimer, Group Manager, MS Office Interoperability: &#8220;&#8230;we will be releasing documentation for the .pst file format.&#8221; http://ow.ly/wHqE&#8216;. It looks like the specification for the Outlook Personal Folder (.PST ) file format will be released under Microsoft&#8217;s OSP.  The original blog post is &#8220;Roadmap for Outlook Personal Folders (.pst) Documentation&#8221; [...]]]></description>
		<link>http://www.forensicblog.org/2009/10/26/microsoft-to-release-the-pst-file-format/</link>
			</item>
	<item>
		<title>Computer Forensic Exam of Najibullah Zazi&#8217;s Laptop</title>
		<description><![CDATA[Earlier today, Jonathan Abolins tweeted about a US DOJ memorandum on detainee Najibullah Zazi.  The memorandum is about the motion the US government filed for a permanent order of detention for Zazi.  Part of the evidence that supports the order of detention, comes from a forensic exam of Zazi&#8217;s laptop.  I found a few pieces [...]]]></description>
		<link>http://www.forensicblog.org/2009/09/25/computer-forensic-exam-of-zazi-najibullahs-laptop/</link>
			</item>
	<item>
		<title>The Meaning of LEAK Records</title>
		<description><![CDATA[I&#8217;ve been pretty quiet lately, largely due to spending time developing LibForensics.  Currently I&#8217;m adding support to read Microsoft Windows Internet cache containers (a.k.a. index.dat files).  If you&#8217;ve ever dealt with index.dat files before, you&#8217;ve probably encountered the mysterious &#8220;LEAK&#8221; record.  The purpose of this blog post is to explain one way that these records [...]]]></description>
		<link>http://www.forensicblog.org/2009/09/10/the-meaning-of-leak-records/</link>
			</item>
	<item>
		<title>The Single Piece of Evidence (SPoE) Myth</title>
		<description><![CDATA[Often a crime-drama television show will have a “single piece of evidence”, which explains the entire crime, and is used to get a guilty conviction. In real life very rarely does this situation arise. Instead typical investigations will uncover many pieces of evidence that are used during trial. Some of the evidence found during an [...]]]></description>
		<link>http://www.forensicblog.org/2009/02/25/the-single-piece-of-evidence-spoe-myth/</link>
			</item>
	<item>
		<title>Sometimes the answers are enough, sometimes they&#8217;re not</title>
		<description><![CDATA[When you watch someone who is new to investigations work a case, one thing that often needs to be explained is the idea that the &#8220;smoking gun&#8221;, by itself, often isn&#8217;t enough. What do I mean by this? Well, Not only am I interested in what you found (which is important in it&#8217;s own right) [...]]]></description>
		<link>http://www.forensicblog.org/2008/04/25/sometimes-the-answers-are-enough-sometimes-theyre-not/</link>
			</item>
	<item>
		<title>The admissibility vs. weight of digital evidence</title>
		<description><![CDATA[There is always a lot of conversation about when digital evidence is and is not admissible. Questions like &#8220;are proxy logs admissible?&#8221; and &#8220;what tools generate admissible evidence?&#8221; are focused on the concept of evidence admissibility. Some of the responses to these questions are correct, and some not really correct. I think the underlying issues [...]]]></description>
		<link>http://www.forensicblog.org/2007/07/30/the-admissibility-vs-weight-of-digital-evidence/</link>
			</item>
	<item>
		<title>CitySec meetup in Los Angeles</title>
		<description><![CDATA[For those of you who haven&#8217;t already seen CitySec, it&#8217;s worth stopping by.  CitySec.org is a site created by Thomas Ptacek (from Matasano Chargen) to facilitate gatherings of information security professionals.  The tone of the meetings appears to be quite relaxed, to quote &#8220;What is a CitySect Meetup?&#8220;: The rule of thumb is, no more [...]]]></description>
		<link>http://www.forensicblog.org/2007/05/24/citysec-meetup-in-los-angeles/</link>
			</item>
</channel>
</rss>

<!-- Dynamic page generated in 0.738 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2010-09-01 14:51:57 -->
