C4All X-Tension for CETS users




Re-posted with permission (more info at: http://www.forensicfocus.com/Forums/viewtopic/t=11868/):


Default C4All X-Tension for CETS users






This is the same as version 3.5.12.k except adds the function to create a CETS manifest XML needed for those using CETS.

Arnold will post information for CETS users regarding changes needed to properly use the X-Tension.

C4All X-Tension CETS compatible version 3.5.13.a
http://1drv.ms/1pajcsb


For use with CETS:
1. This will provide a generic "CETS Media Manifest.xml" file

2. This generic file will not include the digital signature InvestigationID, ManifestID, or CategorizationID. However, the CategorizationID can be added manually.

3. With the CETS Media Uploader you can "re-sign" the manifest file if you use "adminmode" of the CETS Media Uploader.


To enter into Admin Mode:
1. Right Click on "CETSMediaUploader.exe"
2. Select: Sent To, Desktop (create shortcut)
3. Locate the shortcut on your desktop
4. Right Click on the shortcut and select : Properties
5. In the Target Field append to the end of the line(after the closing "): -adminmode
6. Double click the edited Short Cut

When you launch the CETS Media Uploader in Admin Mode you will a new button to "Sign Manifest" file.
Clicking on the button will bring up a dialogue window to manually select a user and the related investigation.

Keep in mind, that you must manually cut and paste your Categorization settings into the XML file.

Arnold Guerin
Canadian Police Centre for
Missing and Exploited Children.






649 Hits

WinFE Taught in Australia

Neat to see WinFE being taught everywhere, as in, everywhere by many.  Wish I could have been there for this presentation (mostly because I'd have to be in Australia to see it...).winfe

[slideshare id=37866964&doc=winfe-thealmostperfecttriagetool-140811062324-phpapp01]

 

Tags:
968 Hits

BlockHasher for XWF

Yet another cool XWF utility!

 

BlockHasher

 

 

http://d-forensik.de/download/

[caption id="attachment_630" align="aligncenter" width="700" class=" "]blockhash

 

 

BlockHasher helps you creating Block-HashSets for X-Ways Forensics

- Select Directory, directory-mode is atomatically activated
- Click 'with sub-folders' if you need recursive hashing
- Alternatively select some files, file-mode is atomatically activated
- you can switch everytime between both modes
- Choose your Entropy
- If you need to find a part of a single file use 'one input - one output' mode
- If you need to find a part of a bulk of files use 'all in one' mode
- Add 'MD5'-Header is necessary for X-Ways Forensics

Start hashing now. A Logfile ist automatically generated.

BlockHasher is Freeware.
If you need source send mail to This email address is being protected from spambots. You need JavaScript enabled to view it.

 

735 Hits

X-Ways MD5 Hash Manipulator

Another cool utility for X-Ways!

 

X-Ways MD5 Hash Manipulator

 

 

hash

 

 

 

 

 

A program to manipulate your Hash sets from X-Ways.
It will allow you to Add hashes, Remove hashes, Compare hashes and remove the duplicates, create hash set of excluded files, and be in the proper format to quickly import to X-Ways.

 

 

This will allow users to maintain their hash sets and create small diff files if needed to distribute when hashes are added/removed from database.
It works on the basis of add or removing records, indicating duplicates and also the '-' prefix implemented in X-ways. files with '-' prefix can be anywhere in set, not at the beginning.

 

 

 

 

 

Thanks to X-Tension author Steve Frawley (who is also the author of the C4All X-Tension) and thanks to beta tester Derek Frawley.

 

 

 

 

 

instructions

 

 

file

 

1171 Hits

SEARCH High-Tech Crime Trainers to Debut WinFE as a new topic

Super cool.  From SEARCH.


"The team will debut a new course topic in Dallas: Introduction to Windows Forensic Environment (WinFE). In this lab and lecture, investigators will learn how to create a bootable forensic environment on a thumb drive. Using this thumb drive, investigators can then conduct previews of suspect computers in the field, looking for information that indicates whether the computer contains potential evidence in a case. The ability to conduct on-scene triage such as this is very important to investigators, as it gives immediate information about suspects and their devices."

 

Tags:
1793 Hits

Free WinFE course

WinFE course to be updatedwinfe


The WinFE online course will be updated sooner with a few neat things that are coming up with WinFE.  Until then, there have been over 2,000 registrations for the course and more every day.

I'm impressed that there are so many users interested in using WinFE, but then again, not really.   It's still a really neat tool to have in your toolbox alongside the Linux forensics boot OSs. If you haven't taken a look at WinFE, give it a try.  This course will remain online, free, and updated when there are updates to make.

I am checking out WTE and so far, WTE represents a great enhancement on making WinFE more user friendly in appearance and use.  I'll post my thoughts on WTE sometime in the future after I really take a look at WTE in more detail.

 

Advanced Internet Investigations Course with Google Hacks!


Speaking of online courses, if you regularly "google" people for investigations, backgrounds, pre-employment checks, internal investigations, or need to find someone as a witness (or suspect, or victim), take a look at my Advanced  Internet Investigations Course with Google Hacks.  If you register with this link (or this code: winfe50), you get 50% tuition.  The half off discount is for the first 50 people, then regular price of $195.  The course is a tad over 4.5 hours and covers enough information where you can practically find anyone online, and in the physical world.  Google operators, syntax, and hacks are covered including automated searching utilities (free software!).

[caption id="attachment_1262" align="alignleft" width="700"]AII Half price for the first 50 WinFE blog readers.

 

Tags:
864 Hits

Cool work at the Windows Triage Environment

Oh my.   This is very pretty and impressive.  Take a look at the Windows Triage Environment if you haven't done so yet.  It is nice to see work continually being done to improve upon WinFE.

WTE

 

 

WTE

Tags:
858 Hits

Last day of discounted X-Ways Forensics online course

I'm sure there are a few more people left to register for the X-Ways Forensics online course (XWF I) with the discount code of "xwf1". That's 25% off, plus includes free tuition to the X-Ways Forensics II online course. XWF I is introductory, XWF II is more indepth, quite a bit longer, and will be released in August. XWF III, a shorter course will be released sometime after August.

Everyone registering by midnight tonight (Pacific time) for XWF I, gets access to XWF II and XWF III when published without cost. Otherwise, it's a separate tuition payment for each course.  From July 18, the XWF I is back to $195, XWF II will be $299, and XWF III will be $75.   Each class is lifetime access, on demand training, including updates to the courses when XWF is substantially updated (should be a course update once a year).

Details on XWF II are here: http://xwaysforensics.wordpress.com/2014/07/05/x-ways-forensics-practitioners-guide-online-ii/

Register for X-Ways Forensics Practitioner's Guide online course here:  http://courses.dfironlinetraining.com/x-ways-forensics-practitioners-guide

xwfii
907 Hits

Thanks to Ken Pryor for his kind review of the WinFE online course

Ken Pryor wrote a kind review of the WinFE online course.  Take a look at his blog for details..  http://digiforensics.blogspot.com/2014/07/windows-forensic-environment-training.html

Don't forget, the WinFE online course is just like WinFE...it's FREE!

review

Tags:
1586 Hits

X-Ways Forensics Practitioner's Guide Online II

For all  XWF I registrations prior to July 17, 2014, you will receive a code for 100% off the XWF II course shown below at the email you registered.  The deadline to register in order to receive the 100% discount code for XWF II is July 17, 2014, after which, the course is available for purchase without a discount.

These are on-demand courses and you have lifetime access to both courses (XWF I and XWF II).  There will be an XWF III course released during the summer, all who register before July 17, 2014 will receive another 100% off discount code for XWF III.  So, for the purchase of XWF I by July 17, you will have lifetime access to XWF I, XWF II and XWF III.

XWF II will be released after the discount codes currently given have expired in a few weeks.  The general discount code for 25% off is:   xwf1

Members of HTCC, IACIS, and CTIN have received a 30% discount code in their e-mail.  If you are a member and did not receive the code, check your e-mail, it should be there.  If you belong to a high tech crime group not listed, This email address is being protected from spambots. You need JavaScript enabled to view it. and I can send a 30% code to your association.  Otherwise, feel free to use the 25% discount code.

xwfii

1034 Hits