<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IR and forensic talk</title>
	<atom:link href="http://blog.kiddaland.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kiddaland.net</link>
	<description>Some useless talk mixed with hopefully interesting points every now and then</description>
	<lastBuildDate>Sat, 06 Mar 2010 16:21:47 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>log2timeline updated</title>
		<link>http://blog.kiddaland.net/2010/03/log2timeline-updated-2/</link>
		<comments>http://blog.kiddaland.net/2010/03/log2timeline-updated-2/#comments</comments>
		<pubDate>Sat, 06 Mar 2010 16:19:34 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[sans eu forensics summit]]></category>
		<category><![CDATA[sift]]></category>
		<category><![CDATA[summit]]></category>
		<category><![CDATA[update to log2timeline]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=226</guid>
		<description><![CDATA[I&#8217;ve just released a new version of log2timeline, version 0.42.  The new version includes two new input modules, one for extracting timestamps from PDF metadata and another one from McAfee anti-virus log files.  The new version also includes several bug fixes, the full changelog can be read here. The development focus will be to move [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/03/log2timeline-updated-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Small updates</title>
		<link>http://blog.kiddaland.net/2010/02/small-updates/</link>
		<comments>http://blog.kiddaland.net/2010/02/small-updates/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 14:23:48 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[flash cookies]]></category>
		<category><![CDATA[local shared object]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[lso]]></category>
		<category><![CDATA[mactime]]></category>
		<category><![CDATA[private browsing]]></category>
		<category><![CDATA[standard for timeline analysis]]></category>
		<category><![CDATA[tln]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=223</guid>
		<description><![CDATA[Just recently saw a post at Slashdot about Adobe implementing private browsing in their Flash Player.  That means that when the user starts private browsing mode in their web browsers LSO files will not be stored on disk.  This is implemented in the way that during the private browser session all Flash cookies are stored [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/02/small-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SANS EU Forensics Summit</title>
		<link>http://blog.kiddaland.net/2010/01/sans-eu-forensics-summit/</link>
		<comments>http://blog.kiddaland.net/2010/01/sans-eu-forensics-summit/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 21:34:08 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[sans]]></category>
		<category><![CDATA[summit]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=212</guid>
		<description><![CDATA[I just wanted to write a short post about the upcoming SANS European Digital Forensics and and Incident Response Summit that will take place in London on the 19th and 20th of April.  I encourage everyone that has the chance to attend since there are some very interesting talks, such as; Jesse Kornblum&#8217;s talk about [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/01/sans-eu-forensics-summit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Version 0.41 of log2timeline published</title>
		<link>http://blog.kiddaland.net/2010/01/version-0-41-of-log2timeline-published/</link>
		<comments>http://blog.kiddaland.net/2010/01/version-0-41-of-log2timeline-published/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 10:39:32 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[new release]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=190</guid>
		<description><![CDATA[I&#8217;ve just published version 0.41 of log2timeline, for a full list of the changes read the changelog.  This upgrade is a recommended upgrade since it contains several bug fixes as well as enhancements to the tool.  I&#8217;ve added new input modules for: Google&#8217;s Chrome History, Opera History, Firefox Bookmarks, and Windows Event Logs (EVTX). I&#8217;ve [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/01/version-0-41-of-log2timeline-published/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Updates to log2timeline</title>
		<link>http://blog.kiddaland.net/2010/01/updates-to-log2timeline/</link>
		<comments>http://blog.kiddaland.net/2010/01/updates-to-log2timeline/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 19:20:12 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=181</guid>
		<description><![CDATA[I&#8217;ve been working on a new version of log2timeline, which according to the roadmap is a &#8220;web history add-on&#8221;.  I started by creating an input module to parse the simple format of Opera browser.  Opera browser maintains two main history files, the &#8220;Opera Global History&#8221; and the &#8220;Opera Direct History&#8221;, which are both in a [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/01/updates-to-log2timeline/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Finally a new version of log2timeline</title>
		<link>http://blog.kiddaland.net/2009/11/finally-a-new-version-of-log2timeline/</link>
		<comments>http://blog.kiddaland.net/2009/11/finally-a-new-version-of-log2timeline/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 14:40:52 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[new release]]></category>
		<category><![CDATA[update]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=178</guid>
		<description><![CDATA[I&#8217;ve been working on a new version for log2timeline for a while now, and I finally managed to complete some testing on the new code.  There are some significant changes to the way that log2timeline works in the new version, 0.40. Some of them are:

All timestamps are now normalized to UTC
The GUI, glog2timeline, has been [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2009/11/finally-a-new-version-of-log2timeline/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Second Network Forensics Contest</title>
		<link>http://blog.kiddaland.net/2009/11/second-network-forensics-contest/</link>
		<comments>http://blog.kiddaland.net/2009/11/second-network-forensics-contest/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 10:00:04 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Network Analysis]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[artifact analysis]]></category>
		<category><![CDATA[artifacts]]></category>
		<category><![CDATA[contest]]></category>
		<category><![CDATA[extract from pcap]]></category>
		<category><![CDATA[network forensics]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[puzzle]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=151</guid>
		<description><![CDATA[I just wanted to go over my solution to the second network forensics contest.
First of all a little disclaimer, since this is a competition where scripting is encouraged I decided beforehand to write a script and not rely on any available tools to complete this task (or at least to minimize usage of previous tools).
To [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2009/11/second-network-forensics-contest/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Malware analysis</title>
		<link>http://blog.kiddaland.net/2009/11/malware-analysis/</link>
		<comments>http://blog.kiddaland.net/2009/11/malware-analysis/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 11:50:47 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Windows Analysis]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[pdf]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=158</guid>
		<description><![CDATA[I decided to to some malware analysis as a part of some presentation I had to do.  And since I went through the process, I decided to post it here if anyone is interested.
To begin with, I needed to find some malware to analyze.  And a great place to find live links to active malware [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2009/11/malware-analysis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Small update</title>
		<link>http://blog.kiddaland.net/2009/10/small-update/</link>
		<comments>http://blog.kiddaland.net/2009/10/small-update/#comments</comments>
		<pubDate>Fri, 16 Oct 2009 17:47:04 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=146</guid>
		<description><![CDATA[It&#8217;s been a while since I last posted a blog, so a little update.  There is a new network forensic contest published, I&#8217;ve already submitted my solution (will post it on the site after the deadline).  I encourage people to try it out, always fun to play with challenges like these, if you have the [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2009/10/small-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Network Forensics Puzzle</title>
		<link>http://blog.kiddaland.net/2009/09/network-forensics-puzzle/</link>
		<comments>http://blog.kiddaland.net/2009/09/network-forensics-puzzle/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 09:49:15 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Network Analysis]]></category>
		<category><![CDATA[contest]]></category>
		<category><![CDATA[extract from pcap]]></category>
		<category><![CDATA[network forensics]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[puzzle]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=114</guid>
		<description><![CDATA[Update 1
The winner has been announced, see further detail here.  And despite all odds, it seems that I won the challenge this time despite both very different and really good solutions from other finalists. So here is my answer again, in little bit more detail than the posted solution.
&#160;
There was a very interesting network forensics [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2009/09/network-forensics-puzzle/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
