<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IR and forensic talk &#187; Timeline analysis</title>
	<atom:link href="http://blog.kiddaland.net/category/forensics/timeline-analysis/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kiddaland.net</link>
	<description>Some useless talk mixed with hopefully interesting points every now and then</description>
	<lastBuildDate>Wed, 30 Jun 2010 13:14:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>log2timeline Version 0.50 Released</title>
		<link>http://blog.kiddaland.net/2010/06/log2timeline-version-0-50-released/</link>
		<comments>http://blog.kiddaland.net/2010/06/log2timeline-version-0-50-released/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 11:57:57 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[new version]]></category>
		<category><![CDATA[sans forensics summit]]></category>
		<category><![CDATA[timestamp]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=275</guid>
		<description><![CDATA[Well, I&#8217;ve finally decided to release version 0.50 of log2timeline.  Lot of things have changed since version 0.43, although there is only one new input module introduced to the tool, we will get to that later.  I just wanted to go over some of the changes made to the tool. First of all the verification [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/06/log2timeline-version-0-50-released/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Timeline Analysis 101</title>
		<link>http://blog.kiddaland.net/2010/05/timeline-analysis-101/</link>
		<comments>http://blog.kiddaland.net/2010/05/timeline-analysis-101/#comments</comments>
		<pubDate>Fri, 28 May 2010 15:12:48 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[guide]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[sleuthkit]]></category>
		<category><![CDATA[super timeline]]></category>
		<category><![CDATA[timescanner]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=251</guid>
		<description><![CDATA[I recently got the question of how to start with your timeline analysis.  And usually when someone finally asks you the question, you know that there are quite a lot of others that have absolutely no idea how to go about such analysis yet somehow don&#8217;t have the guts to ask.  Therefore for those that [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/05/timeline-analysis-101/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>timescanner and IE history</title>
		<link>http://blog.kiddaland.net/2010/04/timescanner-and-ie-history/</link>
		<comments>http://blog.kiddaland.net/2010/04/timescanner-and-ie-history/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 12:43:13 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[Windows Analysis]]></category>
		<category><![CDATA[index.dat]]></category>
		<category><![CDATA[internet explorer history]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[timestamps]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=249</guid>
		<description><![CDATA[There has been some discussion lately about some limitations to timescanner in regards to the reading of timestamps in various index.dat files.  More precisely Windows decided that it would store timestamps using different timezones depending on the location of the index.dat, instead of sticking with the good old UTC format.  So for instance the history [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/04/timescanner-and-ie-history/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SANS EU forensics summit and log2timeline</title>
		<link>http://blog.kiddaland.net/2010/04/sans-eu-forensics-summit-and-log2timeline/</link>
		<comments>http://blog.kiddaland.net/2010/04/sans-eu-forensics-summit-and-log2timeline/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 12:35:33 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[new release]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[sans eu summit]]></category>
		<category><![CDATA[slides]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=243</guid>
		<description><![CDATA[Well&#8230; I was supposed to give a talk at the SANS EU forensics summit about log2timeline but due to our lovely volcano in Eyjafjallajökull (which some people might have heard mentioned lately, although few can really pronounce it correctly) there were no flights to the UK&#8230; meaning that although the airport here in Iceland was [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/04/sans-eu-forensics-summit-and-log2timeline/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Easier installation of log2timeline</title>
		<link>http://blog.kiddaland.net/2010/03/easier-installation-of-log2timeline/</link>
		<comments>http://blog.kiddaland.net/2010/03/easier-installation-of-log2timeline/#comments</comments>
		<pubDate>Wed, 31 Mar 2010 07:06:54 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[cert forensic tool repository]]></category>
		<category><![CDATA[fedora repository]]></category>
		<category><![CDATA[installation of log2timeline]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[repository]]></category>
		<category><![CDATA[ubuntu repository]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=235</guid>
		<description><![CDATA[I decided to make the installation of log2timeline a bit easier, since I know that the installation of all those Perl libraries can be a burden sometimes, especially since most packaging systems don&#8217;t have all of the libraries in their repositories.  So I started out creating an Ubuntu repository that contains not only log2timeline but [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/03/easier-installation-of-log2timeline/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Timelines, again</title>
		<link>http://blog.kiddaland.net/2010/03/timelines-again/</link>
		<comments>http://blog.kiddaland.net/2010/03/timelines-again/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 09:45:31 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[aftertime]]></category>
		<category><![CDATA[log2timeline]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=233</guid>
		<description><![CDATA[I forgot to mention Aftertime in my last blog post, which is a new tool to create and analyse timelines.  Rob pointed this tool to me the other day, and I&#8217;ve done some limited testing on it.  It is very easy to create the timeline, just add the image file and let it crunch through [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/03/timelines-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Timeline analysis, links and discussion</title>
		<link>http://blog.kiddaland.net/2010/03/timeline-analysis-links-and-discussion/</link>
		<comments>http://blog.kiddaland.net/2010/03/timeline-analysis-links-and-discussion/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 23:04:38 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[super timeline]]></category>
		<category><![CDATA[timeline]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=230</guid>
		<description><![CDATA[Timeline analysis has been getting a lot of press lately.  Harlan discussed some of the sources and usability of timeline analysis in a recent blog post. And then you&#8217;ve got few posts that describe how to create timelines, both from a live Windows machine, and from registry files. Rob Lee also posted a blog about [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/03/timeline-analysis-links-and-discussion/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>log2timeline updated</title>
		<link>http://blog.kiddaland.net/2010/03/log2timeline-updated-2/</link>
		<comments>http://blog.kiddaland.net/2010/03/log2timeline-updated-2/#comments</comments>
		<pubDate>Sat, 06 Mar 2010 16:19:34 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[sans eu forensics summit]]></category>
		<category><![CDATA[sift]]></category>
		<category><![CDATA[summit]]></category>
		<category><![CDATA[update to log2timeline]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=226</guid>
		<description><![CDATA[I&#8217;ve just released a new version of log2timeline, version 0.42.  The new version includes two new input modules, one for extracting timestamps from PDF metadata and another one from McAfee anti-virus log files.  The new version also includes several bug fixes, the full changelog can be read here. The development focus will be to move [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/03/log2timeline-updated-2/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Small updates</title>
		<link>http://blog.kiddaland.net/2010/02/small-updates/</link>
		<comments>http://blog.kiddaland.net/2010/02/small-updates/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 14:23:48 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[flash cookies]]></category>
		<category><![CDATA[local shared object]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[lso]]></category>
		<category><![CDATA[mactime]]></category>
		<category><![CDATA[private browsing]]></category>
		<category><![CDATA[standard for timeline analysis]]></category>
		<category><![CDATA[tln]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=223</guid>
		<description><![CDATA[Just recently saw a post at Slashdot about Adobe implementing private browsing in their Flash Player.  That means that when the user starts private browsing mode in their web browsers LSO files will not be stored on disk.  This is implemented in the way that during the private browser session all Flash cookies are stored [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/02/small-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Version 0.41 of log2timeline published</title>
		<link>http://blog.kiddaland.net/2010/01/version-0-41-of-log2timeline-published/</link>
		<comments>http://blog.kiddaland.net/2010/01/version-0-41-of-log2timeline-published/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 10:39:32 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[new release]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=190</guid>
		<description><![CDATA[I&#8217;ve just published version 0.41 of log2timeline, for a full list of the changes read the changelog.  This upgrade is a recommended upgrade since it contains several bug fixes as well as enhancements to the tool.  I&#8217;ve added new input modules for: Google&#8217;s Chrome History, Opera History, Firefox Bookmarks, and Windows Event Logs (EVTX). I&#8217;ve [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/01/version-0-41-of-log2timeline-published/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
