NTFS forensic analysis on Unix platform

From: mat_private
Date: Wed Jul 25 2001 - 06:26:22 PDT

  • Next message: Hasty, Gary : "in-house computer forensics"

     Hi.
    
     I have taken 2 disk images from a compromised IIS system. 
    These images are in NTFS format, and I was wondering if 
    anyone knows of an open source tool which is capable of 
    accessing these partitions. The Unix platform that I have 
    available is OpenBSD; so I can't mount the NTFS partitions.
    
     In the past I've used tct; but unrm doesn't currently 
    support ntfs filesystems.   
    
     Any advice would be greatly appreciated. 
    
    thanks,
    Marty. 
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Wed Jul 25 2001 - 12:07:21 PDT