<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for IR and forensic talk</title>
	<atom:link href="http://blog.kiddaland.net/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kiddaland.net</link>
	<description>Some useless talk mixed with hopefully interesting points every now and then</description>
	<lastBuildDate>Thu, 03 Mar 2011 21:02:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>Comment on Timeline Analysis 201 &#8211; review the timeline by Ettore Diodati</title>
		<link>http://blog.kiddaland.net/2011/02/timeline-analysis-201-review-the-timeline/comment-page-1/#comment-19362</link>
		<dc:creator>Ettore Diodati</dc:creator>
		<pubDate>Thu, 03 Mar 2011 21:02:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=302#comment-19362</guid>
		<description>I want just to say that some days ago I&#039;ve solved a case of malware infection, not properly recognize by the most of antivirus and where the sysadmin approach wasn&#039;t leading to any way. How? Thanks to your magic tool and to your useful explanation.
I too think that csv format could be more flexible than &quot;classic&quot; timeline method but I also think that Excel, supported by a pretty good hardware, can be easily manages large timeline whitout slow down performance.</description>
		<content:encoded><![CDATA[<p>I want just to say that some days ago I&#8217;ve solved a case of malware infection, not properly recognize by the most of antivirus and where the sysadmin approach wasn&#8217;t leading to any way. How? Thanks to your magic tool and to your useful explanation.<br />
I too think that csv format could be more flexible than &#8220;classic&#8221; timeline method but I also think that Excel, supported by a pretty good hardware, can be easily manages large timeline whitout slow down performance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Office 2007 metadata by pqlaz</title>
		<link>http://blog.kiddaland.net/2009/06/office-2007-metadata/comment-page-1/#comment-18024</link>
		<dc:creator>pqlaz</dc:creator>
		<pubDate>Thu, 06 Jan 2011 16:11:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=29#comment-18024</guid>
		<description>Thanks!</description>
		<content:encoded><![CDATA[<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Updating log2timeline on the SIFT workstation by kiddi</title>
		<link>http://blog.kiddaland.net/2010/11/updating_sift_to_use_apt/comment-page-1/#comment-15658</link>
		<dc:creator>kiddi</dc:creator>
		<pubDate>Wed, 08 Dec 2010 22:20:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=295#comment-15658</guid>
		<description>Hi
Thank you for this comment, I hadn&#039;t checked the availability of autopsy after running the script.... so I appreciate this comment.</description>
		<content:encoded><![CDATA[<p>Hi<br />
Thank you for this comment, I hadn&#8217;t checked the availability of autopsy after running the script&#8230;. so I appreciate this comment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Updating log2timeline on the SIFT workstation by Tom H</title>
		<link>http://blog.kiddaland.net/2010/11/updating_sift_to_use_apt/comment-page-1/#comment-15061</link>
		<dc:creator>Tom H</dc:creator>
		<pubDate>Thu, 02 Dec 2010 20:39:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=295#comment-15061</guid>
		<description>Kristinn - awesome script.  Thanks so much for doing this, it saves a lot of time.  One thing that users may need to be aware of re: SIFT workstation.  The update and install of log2timeline using this script appears to break Autopsy in SIFT, but the fix isn&#039;t too hard:

- at the command line:

# cd /usr/local/src/autopsy
# ./configure

- overwrite the existing config and accept all default answers
- set the &quot;evidence locker&quot; to &quot;/forensics&quot;  (this is the currently set evidence locker in SIFT) ***NOTE - this will overwrite that directory and all its contents.  If you have cases from the old install of autopsy in this dir, they will be overwritten.***
- once the configuration script is done, copy the resulting autopsy script file to &quot;/usr/local/bin&quot; like so:

# sudo cp autopsy /usr/local/bin/.  (say &quot;y&quot; when it asks if you want to overwrite)

That&#039;s it.  Autopsy should work again now.

regards and thanks again for such a great tool!

Tom H</description>
		<content:encoded><![CDATA[<p>Kristinn &#8211; awesome script.  Thanks so much for doing this, it saves a lot of time.  One thing that users may need to be aware of re: SIFT workstation.  The update and install of log2timeline using this script appears to break Autopsy in SIFT, but the fix isn&#8217;t too hard:</p>
<p>- at the command line:</p>
<p># cd /usr/local/src/autopsy<br />
# ./configure</p>
<p>- overwrite the existing config and accept all default answers<br />
- set the &#8220;evidence locker&#8221; to &#8220;/forensics&#8221;  (this is the currently set evidence locker in SIFT) ***NOTE &#8211; this will overwrite that directory and all its contents.  If you have cases from the old install of autopsy in this dir, they will be overwritten.***<br />
- once the configuration script is done, copy the resulting autopsy script file to &#8220;/usr/local/bin&#8221; like so:</p>
<p># sudo cp autopsy /usr/local/bin/.  (say &#8220;y&#8221; when it asks if you want to overwrite)</p>
<p>That&#8217;s it.  Autopsy should work again now.</p>
<p>regards and thanks again for such a great tool!</p>
<p>Tom H</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Updating log2timeline on the SIFT workstation by Tweets that mention IR and forensic talk » Updating log2timeline on the SIFT workstation -- Topsy.com</title>
		<link>http://blog.kiddaland.net/2010/11/updating_sift_to_use_apt/comment-page-1/#comment-13447</link>
		<dc:creator>Tweets that mention IR and forensic talk » Updating log2timeline on the SIFT workstation -- Topsy.com</dc:creator>
		<pubDate>Wed, 17 Nov 2010 17:00:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=295#comment-13447</guid>
		<description>[...] This post was mentioned on Twitter by Nobutaka Mantani, yk. yk said: log2timeline update ref : http://blog.kiddaland.net/2010/11/updating_sift_to_use_apt/ [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Nobutaka Mantani, yk. yk said: log2timeline update ref : <a href="http://blog.kiddaland.net/2010/11/updating_sift_to_use_apt/" rel="nofollow">http://blog.kiddaland.net/2010/11/updating_sift_to_use_apt/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Network Forensics Puzzle by Ubaid</title>
		<link>http://blog.kiddaland.net/2009/09/network-forensics-puzzle/comment-page-1/#comment-12364</link>
		<dc:creator>Ubaid</dc:creator>
		<pubDate>Sat, 06 Nov 2010 09:47:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=114#comment-12364</guid>
		<description>Hello sir, Your work is Really a tremendousness job. i just wanted to know that What Language would be used to run the Script Code You Wrote and Published. 

Thanks in Advance

Regards
Ubaid Ali Jaffery</description>
		<content:encoded><![CDATA[<p>Hello sir, Your work is Really a tremendousness job. i just wanted to know that What Language would be used to run the Script Code You Wrote and Published. </p>
<p>Thanks in Advance</p>
<p>Regards<br />
Ubaid Ali Jaffery</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SANS summit and gold paper by Tweets that mention IR and forensic talk » SANS summit and gold paper -- Topsy.com</title>
		<link>http://blog.kiddaland.net/2010/08/sans-summit-and-gold-paper/comment-page-1/#comment-5773</link>
		<dc:creator>Tweets that mention IR and forensic talk » SANS summit and gold paper -- Topsy.com</dc:creator>
		<pubDate>Mon, 30 Aug 2010 00:38:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=290#comment-5773</guid>
		<description>[...] This post was mentioned on Twitter by yk, A Fistful of Dongles. A Fistful of Dongles said: http://bit.ly/bLYPX8 Kristinn Gudjonsson&#039;s GCFA Gold Paper is out now http://bit.ly/drh1XH [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by yk, A Fistful of Dongles. A Fistful of Dongles said: <a href="http://bit.ly/bLYPX8" rel="nofollow">http://bit.ly/bLYPX8</a> Kristinn Gudjonsson&#039;s GCFA Gold Paper is out now <a href="http://bit.ly/drh1XH" rel="nofollow">http://bit.ly/drh1XH</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SANS summit and gold paper by Chad Tilbury</title>
		<link>http://blog.kiddaland.net/2010/08/sans-summit-and-gold-paper/comment-page-1/#comment-5771</link>
		<dc:creator>Chad Tilbury</dc:creator>
		<pubDate>Sat, 28 Aug 2010 16:53:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=290#comment-5771</guid>
		<description>Congratulations, Kristinn!  You have really pushed the field forward with your excellent work.</description>
		<content:encoded><![CDATA[<p>Congratulations, Kristinn!  You have really pushed the field forward with your excellent work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on log2timeline Version 0.50 Released by Digital Forensics Case Leads: Ann’s Aurora Edition &#124; Portable Digital Video Recorder</title>
		<link>http://blog.kiddaland.net/2010/06/log2timeline-version-0-50-released/comment-page-1/#comment-4330</link>
		<dc:creator>Digital Forensics Case Leads: Ann’s Aurora Edition &#124; Portable Digital Video Recorder</dc:creator>
		<pubDate>Thu, 15 Jul 2010 14:48:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=275#comment-4330</guid>
		<description>[...] Gudjonsson released log2timeline v0.50 on June 30. This release contains a number of improvements. One of the most exciting is the [...]</description>
		<content:encoded><![CDATA[<p>[...] Gudjonsson released log2timeline v0.50 on June 30. This release contains a number of improvements. One of the most exciting is the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on log2timeline Version 0.50 Released by Tweets that mention IR and forensic talk » log2timeline Version 0.50 Released -- Topsy.com</title>
		<link>http://blog.kiddaland.net/2010/06/log2timeline-version-0-50-released/comment-page-1/#comment-4281</link>
		<dc:creator>Tweets that mention IR and forensic talk » log2timeline Version 0.50 Released -- Topsy.com</dc:creator>
		<pubDate>Thu, 01 Jul 2010 18:42:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=275#comment-4281</guid>
		<description>[...] This post was mentioned on Twitter by douglas brush, Masafumi Negishi. Masafumi Negishi said: RT log2timeline Version 0.50 Released - http://j.mp/ckVXMx [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by douglas brush, Masafumi Negishi. Masafumi Negishi said: RT log2timeline Version 0.50 Released &#8211; <a href="http://j.mp/ckVXMx" rel="nofollow">http://j.mp/ckVXMx</a> [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

