Re: NTFS forensic analysis on Unix platform

From: Michael D. Barwise, BSc, IEng, MIIE (mikeat_private)
Date: Fri Jul 27 2001 - 10:18:11 PDT

  • Next message: Frank Knobbe: "RE: NTFS forensic analysis on Unix platform"

    The best tool in my opinion is still NTFSDOS, though the full version is not 
    "open source".
    
    Michael D. Barwise BSc, IEng, MIIE
    Computer Security Awareness
    
    "Addressing the Human Equation in Information Security"
    
    >  Hi.
    > 
    >  I have taken 2 disk images from a compromised IIS system. 
    > These images are in NTFS format, and I was wondering if 
    > anyone knows of an open source tool which is capable of 
    > accessing these partitions. The Unix platform that I have 
    > available is OpenBSD; so I can't mount the NTFS partitions.
    > 
    >  In the past I've used tct; but unrm doesn't currently 
    > support ntfs filesystems.   
    > 
    >  Any advice would be greatly appreciated. 
    > 
    > thanks,
    > Marty. 
    > 
    > -----------------------------------------------------------------
    > This list is provided by the SecurityFocus ARIS analyzer service.
    > For more information on this free incident handling, management 
    > and tracking system please see: http://aris.securityfocus.com
    
    
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Sun Jul 29 2001 - 09:14:03 PDT