<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IR and forensic talk &#187; kiddi</title>
	<atom:link href="http://blog.kiddaland.net/author/kiddi/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kiddaland.net</link>
	<description>Some useless talk mixed with hopefully interesting points every now and then</description>
	<lastBuildDate>Sat, 01 Oct 2011 01:06:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Very quick update &#8211; new release</title>
		<link>http://blog.kiddaland.net/2011/10/very-quick-update-new-release/</link>
		<comments>http://blog.kiddaland.net/2011/10/very-quick-update-new-release/#comments</comments>
		<pubDate>Sat, 01 Oct 2011 01:06:05 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[new release]]></category>
		<category><![CDATA[update to log2timeline]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=344</guid>
		<description><![CDATA[I know I haven&#8217;t been really active on the blog lately (really not written a thing) but I wanted to talk about the new release of log2timeline. So version 0.61 was released few days ago. It mostly contains some bug fixes (at least on my behalf). The only real changes that I did was to [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2011/10/very-quick-update-new-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Quick update</title>
		<link>http://blog.kiddaland.net/2011/05/quick-update/</link>
		<comments>http://blog.kiddaland.net/2011/05/quick-update/#comments</comments>
		<pubDate>Thu, 05 May 2011 19:32:05 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[leftovers]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[new version]]></category>
		<category><![CDATA[release]]></category>
		<category><![CDATA[sans]]></category>
		<category><![CDATA[summit]]></category>
		<category><![CDATA[talk]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=342</guid>
		<description><![CDATA[It&#8217;s been a while since my last post, and several things have happened since then&#8230;. for instance the release of version 0.52 of log2timeline.  I will publish another blog post detailing the difference between version 0.51 and 0.52, such as the use of l2t_process a new tool released alongside log2timeline. I will also be talking [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2011/05/quick-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Timeline Analysis 201 &#8211; review the timeline</title>
		<link>http://blog.kiddaland.net/2011/02/timeline-analysis-201-review-the-timeline/</link>
		<comments>http://blog.kiddaland.net/2011/02/timeline-analysis-201-review-the-timeline/#comments</comments>
		<pubDate>Tue, 22 Feb 2011 10:06:15 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[csv]]></category>
		<category><![CDATA[excel]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[mactime]]></category>
		<category><![CDATA[sleuthkit]]></category>
		<category><![CDATA[timeline]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=302</guid>
		<description><![CDATA[In this second post in my short series of timeline analysis I&#8217;m going to discuss the use of the CSV output module.  In my previous post I discussed a bit about the different modules there are in log2timeline, at least the version that was released then, and the meaning of each entry within the mactime [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2011/02/timeline-analysis-201-review-the-timeline/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Updating log2timeline on the SIFT workstation</title>
		<link>http://blog.kiddaland.net/2010/11/updating_sift_to_use_apt/</link>
		<comments>http://blog.kiddaland.net/2010/11/updating_sift_to_use_apt/#comments</comments>
		<pubDate>Fri, 12 Nov 2010 08:47:58 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=295</guid>
		<description><![CDATA[One of the things I did to make updating and maintaining log2timeline easier was to create an apt repository so that the tool could be easily installed using apt-get. However I hadn&#8217;t done so prior to the release of the SIFT workstation, so SIFT was released using a source installation of the tool.  That also [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/11/updating_sift_to_use_apt/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>SANS summit and gold paper</title>
		<link>http://blog.kiddaland.net/2010/08/sans-summit-and-gold-paper/</link>
		<comments>http://blog.kiddaland.net/2010/08/sans-summit-and-gold-paper/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 09:49:44 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[gcfa]]></category>
		<category><![CDATA[gold paper]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[sans eu forensics summit]]></category>
		<category><![CDATA[summit]]></category>
		<category><![CDATA[Timeline analysis]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=290</guid>
		<description><![CDATA[Well, its been quite a while since my last post, summer vacation coupled with paternity leave gave me a pleasant absence from the computer screen. But I&#8217;m back now, and surprisingly my gold paper got finally been published.  The title of the paper is &#8220;Mastering the Super Timeline With log2timeline&#8221;, and for those that carefully [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/08/sans-summit-and-gold-paper/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>log2timeline Version 0.50 Released</title>
		<link>http://blog.kiddaland.net/2010/06/log2timeline-version-0-50-released/</link>
		<comments>http://blog.kiddaland.net/2010/06/log2timeline-version-0-50-released/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 11:57:57 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[new version]]></category>
		<category><![CDATA[sans forensics summit]]></category>
		<category><![CDATA[timestamp]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=275</guid>
		<description><![CDATA[Well, I&#8217;ve finally decided to release version 0.50 of log2timeline.  Lot of things have changed since version 0.43, although there is only one new input module introduced to the tool, we will get to that later.  I just wanted to go over some of the changes made to the tool. First of all the verification [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/06/log2timeline-version-0-50-released/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Forensic4cast Awards</title>
		<link>http://blog.kiddaland.net/2010/06/forensic4cast-awards/</link>
		<comments>http://blog.kiddaland.net/2010/06/forensic4cast-awards/#comments</comments>
		<pubDate>Wed, 16 Jun 2010 20:47:49 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[awards]]></category>
		<category><![CDATA[Forensic4Cast]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=268</guid>
		<description><![CDATA[Much to my surprise I got a nomination for this years Forensic4cast awards for &#8220;Outstanding Contribution to Digital Forensics &#8211; Individual&#8221;. I will be joining a group of really talented experts, like Rob Lee, Matt Shannon and Lee Whitfield, which all deserve this so much more than me (at least in my humble opinion).  But [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/06/forensic4cast-awards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Timeline Analysis 101</title>
		<link>http://blog.kiddaland.net/2010/05/timeline-analysis-101/</link>
		<comments>http://blog.kiddaland.net/2010/05/timeline-analysis-101/#comments</comments>
		<pubDate>Fri, 28 May 2010 15:12:48 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[guide]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[sleuthkit]]></category>
		<category><![CDATA[super timeline]]></category>
		<category><![CDATA[timescanner]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=251</guid>
		<description><![CDATA[I recently got the question of how to start with your timeline analysis.  And usually when someone finally asks you the question, you know that there are quite a lot of others that have absolutely no idea how to go about such analysis yet somehow don&#8217;t have the guts to ask.  Therefore for those that [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/05/timeline-analysis-101/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>timescanner and IE history</title>
		<link>http://blog.kiddaland.net/2010/04/timescanner-and-ie-history/</link>
		<comments>http://blog.kiddaland.net/2010/04/timescanner-and-ie-history/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 12:43:13 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[Windows Analysis]]></category>
		<category><![CDATA[index.dat]]></category>
		<category><![CDATA[internet explorer history]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[timestamps]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=249</guid>
		<description><![CDATA[There has been some discussion lately about some limitations to timescanner in regards to the reading of timestamps in various index.dat files.  More precisely Windows decided that it would store timestamps using different timezones depending on the location of the index.dat, instead of sticking with the good old UTC format.  So for instance the history [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/04/timescanner-and-ie-history/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SANS EU forensics summit and log2timeline</title>
		<link>http://blog.kiddaland.net/2010/04/sans-eu-forensics-summit-and-log2timeline/</link>
		<comments>http://blog.kiddaland.net/2010/04/sans-eu-forensics-summit-and-log2timeline/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 12:35:33 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[new release]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[sans eu summit]]></category>
		<category><![CDATA[slides]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=243</guid>
		<description><![CDATA[Well&#8230; I was supposed to give a talk at the SANS EU forensics summit about log2timeline but due to our lovely volcano in Eyjafjallajökull (which some people might have heard mentioned lately, although few can really pronounce it correctly) there were no flights to the UK&#8230; meaning that although the airport here in Iceland was [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/04/sans-eu-forensics-summit-and-log2timeline/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

