Loading ...
Sorry, an error occurred while loading the content.

Messages List

9831

Fw: important message

Hello! New message, please read tcguy@...
rsiemp
Feb 2
#9831
 
9830

[SOLVED]RE: Gaps in Event Logs and MFT

I was able to recreate this behavior with restoring an image (dd to the rescue) that was created in December, boot up the machine, give it a few minutes, and
Lay, James
Feb 1
#9830
 
9829

Re: Gaps in Event Logs and MFT

there is a major difference between turning off logging and altering event logs. unless things have changed and there are some new wizbang tools out there,
Eric Zimmerman
Jan 30
#9829
 
9828

SYSMON for security monitoring

I have been thinking about different ways to ensure certain activity is recorded to assist with forensic environments. Specifically, I am considering the
corey_harrell@...
Jan 29
#9828
 
9827

Re: Gaps in Event Logs and MFT

If you have a gap in records such that you have record numbers of 1, 2, 3, 8, 9, 10, 14, 15, 16, etc., you likely have something other than the event log being
Greg Kelley
Jan 29
#9827
 
9826

Call For Papers - ICDF2C 2016 - Manhattan, NY

... I was asked to post this on behalf of Dr. Ibrahim Baggili; if you have questions about this conference, please contact him directly using contact info
Baker, Dave
Jan 29
#9826
 
9825

CALL FOR PAPERS - DFRWS USA 2016 - One Week Notice

ONLY ONE WEEK LEFT TO SUBMIT YOUR PAPERS! http://dfrws.org/2016/cfp.shtml The DFRWS digital forensics conference brings together leading researchers,
Baker, Dave
Jan 29
#9825
 
9824

Re: Gaps in Event Logs and MFT

Thank you. Yea in this case the school of thought is that either a) the drive was imaged at the start of the gap time and restored much later, or b) a
Lay, James
Jan 28
#9824
 
9823

Re: Gaps in Event Logs and MFT

Pretty broad question. By gaps I'm assuming you don't mean the computer was turned off therefore no entries? Maybe the event logging was stopped: sc config
frederic.stonesifer@...
Jan 28
#9823
 
9822

Gaps in Event Logs and MFT

Hey All, Trying to determine what exactly would cause a gap in all event logs and even the mft entries? I am suspecting a Windows Restore or something like
Lay, James
Jan 28
#9822
 
9821

IR Position in Amazon Dublin

Hello, My team has opened a position for an Incident Response Engineer in Dublin, Ireland. We are looking for engineers experienced in web applications
Hugo Gabignon
Jan 27
#9821
 
9820

Re: Fw: important message

13 Eric? Really? LOL Made my morning...wtf we gonna do w/ Jimmy retiring man? You ready to come up and take over? You have to have 20 with the Bureau by now.
Robin Jackson
Jan 26
#9820
 
9819

Re: Fw: important message

Good job, Eric! I hope you used the results as a learning experience. You know, for the tools... 😁 Frank Frank McClain Sent from Vic20 over 1G On Jan 25,
Frank McClain
Jan 25
#9819
 
9818

Re: Fw: important message

yea, its THAT important. I clicked the link 13 times! ... -- Eric Zimmerman 801-514-4064 The opinions stated, unless clearly indicated otherwise, are my own
SA Eric Zimmerman
Jan 25
#9818
 
9817

Re: Fw: important message

He's still on this list? Really? Robin Jackson Security+, CISSP, ITIL (406) 465-0354 On Sun, Jan 24, 2016 at 7:46 AM, tcguy@... [win4n6]
Robin Jackson
Jan 24
#9817
 
View First Topic Go to View Last Topic
Loading 1 - 15 of total 9,831 messages