<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IR and forensic talk &#187; log2timeline</title>
	<atom:link href="http://blog.kiddaland.net/tag/log2timeline/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kiddaland.net</link>
	<description>Some useless talk mixed with hopefully interesting points every now and then</description>
	<lastBuildDate>Sat, 01 Oct 2011 01:06:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Very quick update &#8211; new release</title>
		<link>http://blog.kiddaland.net/2011/10/very-quick-update-new-release/</link>
		<comments>http://blog.kiddaland.net/2011/10/very-quick-update-new-release/#comments</comments>
		<pubDate>Sat, 01 Oct 2011 01:06:05 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[new release]]></category>
		<category><![CDATA[update to log2timeline]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=344</guid>
		<description><![CDATA[I know I haven&#8217;t been really active on the blog lately (really not written a thing) but I wanted to talk about the new release of log2timeline. So version 0.61 was released few days ago. It mostly contains some bug fixes (at least on my behalf). The only real changes that I did was to [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2011/10/very-quick-update-new-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Quick update</title>
		<link>http://blog.kiddaland.net/2011/05/quick-update/</link>
		<comments>http://blog.kiddaland.net/2011/05/quick-update/#comments</comments>
		<pubDate>Thu, 05 May 2011 19:32:05 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[leftovers]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[new version]]></category>
		<category><![CDATA[release]]></category>
		<category><![CDATA[sans]]></category>
		<category><![CDATA[summit]]></category>
		<category><![CDATA[talk]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=342</guid>
		<description><![CDATA[It&#8217;s been a while since my last post, and several things have happened since then&#8230;. for instance the release of version 0.52 of log2timeline.  I will publish another blog post detailing the difference between version 0.51 and 0.52, such as the use of l2t_process a new tool released alongside log2timeline. I will also be talking [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2011/05/quick-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Timeline Analysis 201 &#8211; review the timeline</title>
		<link>http://blog.kiddaland.net/2011/02/timeline-analysis-201-review-the-timeline/</link>
		<comments>http://blog.kiddaland.net/2011/02/timeline-analysis-201-review-the-timeline/#comments</comments>
		<pubDate>Tue, 22 Feb 2011 10:06:15 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[csv]]></category>
		<category><![CDATA[excel]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[mactime]]></category>
		<category><![CDATA[sleuthkit]]></category>
		<category><![CDATA[timeline]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=302</guid>
		<description><![CDATA[In this second post in my short series of timeline analysis I&#8217;m going to discuss the use of the CSV output module.  In my previous post I discussed a bit about the different modules there are in log2timeline, at least the version that was released then, and the meaning of each entry within the mactime [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2011/02/timeline-analysis-201-review-the-timeline/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SANS summit and gold paper</title>
		<link>http://blog.kiddaland.net/2010/08/sans-summit-and-gold-paper/</link>
		<comments>http://blog.kiddaland.net/2010/08/sans-summit-and-gold-paper/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 09:49:44 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[gcfa]]></category>
		<category><![CDATA[gold paper]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[sans eu forensics summit]]></category>
		<category><![CDATA[summit]]></category>
		<category><![CDATA[Timeline analysis]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=290</guid>
		<description><![CDATA[Well, its been quite a while since my last post, summer vacation coupled with paternity leave gave me a pleasant absence from the computer screen. But I&#8217;m back now, and surprisingly my gold paper got finally been published.  The title of the paper is &#8220;Mastering the Super Timeline With log2timeline&#8221;, and for those that carefully [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/08/sans-summit-and-gold-paper/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>log2timeline Version 0.50 Released</title>
		<link>http://blog.kiddaland.net/2010/06/log2timeline-version-0-50-released/</link>
		<comments>http://blog.kiddaland.net/2010/06/log2timeline-version-0-50-released/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 11:57:57 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[new version]]></category>
		<category><![CDATA[sans forensics summit]]></category>
		<category><![CDATA[timestamp]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=275</guid>
		<description><![CDATA[Well, I&#8217;ve finally decided to release version 0.50 of log2timeline.  Lot of things have changed since version 0.43, although there is only one new input module introduced to the tool, we will get to that later.  I just wanted to go over some of the changes made to the tool. First of all the verification [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/06/log2timeline-version-0-50-released/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Timeline Analysis 101</title>
		<link>http://blog.kiddaland.net/2010/05/timeline-analysis-101/</link>
		<comments>http://blog.kiddaland.net/2010/05/timeline-analysis-101/#comments</comments>
		<pubDate>Fri, 28 May 2010 15:12:48 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[guide]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[sleuthkit]]></category>
		<category><![CDATA[super timeline]]></category>
		<category><![CDATA[timescanner]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=251</guid>
		<description><![CDATA[I recently got the question of how to start with your timeline analysis.  And usually when someone finally asks you the question, you know that there are quite a lot of others that have absolutely no idea how to go about such analysis yet somehow don&#8217;t have the guts to ask.  Therefore for those that [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/05/timeline-analysis-101/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>timescanner and IE history</title>
		<link>http://blog.kiddaland.net/2010/04/timescanner-and-ie-history/</link>
		<comments>http://blog.kiddaland.net/2010/04/timescanner-and-ie-history/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 12:43:13 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[Windows Analysis]]></category>
		<category><![CDATA[index.dat]]></category>
		<category><![CDATA[internet explorer history]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[timestamps]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=249</guid>
		<description><![CDATA[There has been some discussion lately about some limitations to timescanner in regards to the reading of timestamps in various index.dat files.  More precisely Windows decided that it would store timestamps using different timezones depending on the location of the index.dat, instead of sticking with the good old UTC format.  So for instance the history [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/04/timescanner-and-ie-history/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SANS EU forensics summit and log2timeline</title>
		<link>http://blog.kiddaland.net/2010/04/sans-eu-forensics-summit-and-log2timeline/</link>
		<comments>http://blog.kiddaland.net/2010/04/sans-eu-forensics-summit-and-log2timeline/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 12:35:33 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[new release]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[sans eu summit]]></category>
		<category><![CDATA[slides]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=243</guid>
		<description><![CDATA[Well&#8230; I was supposed to give a talk at the SANS EU forensics summit about log2timeline but due to our lovely volcano in Eyjafjallajökull (which some people might have heard mentioned lately, although few can really pronounce it correctly) there were no flights to the UK&#8230; meaning that although the airport here in Iceland was [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/04/sans-eu-forensics-summit-and-log2timeline/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Easier installation of log2timeline</title>
		<link>http://blog.kiddaland.net/2010/03/easier-installation-of-log2timeline/</link>
		<comments>http://blog.kiddaland.net/2010/03/easier-installation-of-log2timeline/#comments</comments>
		<pubDate>Wed, 31 Mar 2010 07:06:54 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[cert forensic tool repository]]></category>
		<category><![CDATA[fedora repository]]></category>
		<category><![CDATA[installation of log2timeline]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[repository]]></category>
		<category><![CDATA[ubuntu repository]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=235</guid>
		<description><![CDATA[I decided to make the installation of log2timeline a bit easier, since I know that the installation of all those Perl libraries can be a burden sometimes, especially since most packaging systems don&#8217;t have all of the libraries in their repositories.  So I started out creating an Ubuntu repository that contains not only log2timeline but [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/03/easier-installation-of-log2timeline/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Timelines, again</title>
		<link>http://blog.kiddaland.net/2010/03/timelines-again/</link>
		<comments>http://blog.kiddaland.net/2010/03/timelines-again/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 09:45:31 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[aftertime]]></category>
		<category><![CDATA[log2timeline]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=233</guid>
		<description><![CDATA[I forgot to mention Aftertime in my last blog post, which is a new tool to create and analyse timelines.  Rob pointed this tool to me the other day, and I&#8217;ve done some limited testing on it.  It is very easy to create the timeline, just add the image file and let it crunch through [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2010/03/timelines-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

