"Digital Forensics Case Leads: MBR Parser, VSC Toolset GUI, Memory Forensics Cheat Sheet & other goodness......"
Updated: 2012-04-28 01:25:05
In this week's SANS Case Leads, we have a python script for parsing the Master Boot Record, a question of USB drive serial number uniqueness, some VSC goodness and some other stuff ;-)If you have an item you'd like to contribute to Digital Forensics CaseLeads, please send it to caseleads@sans.orgTools: Jamie Levy (@gleeda) posted a script that she wrote that parses the MBR in order to help find MBR infectors. Read Jamie's Blog post. Grab the script here. Jason Hale came up with a GUI front-end for Corey Harrell's batch scripts used to rip/examine Volume Shadow Copies, called VSC Toolset DEFT Linux 7.1 was released earlier this month. Read the

Through May 14, 2012 you will receive a 11" 64GB MacBook Air when you register and pay for a qualifying vLive course.To get your MacBook Air: Register for a qualifying vLive long course. Enter discount code 0424_MBAIR when you check out.Would you rather save some money than receive a MacBook Air? Take $850 off any qualifying course instead! Just follow the steps above and enter discount code 0424_850 at check out.Qualifying SANS vLive courses include:
I recently wrote on my personal blog about some of the new updates to the SANS Forensics 508 course and included a link to a new memory forensics cheat sheet. By popular request, I am posting a PDF versionof the cheat sheet here on the SANS blog. Feedback is appreciated!Chad ...