The Experts below are selected from a list of 21 Experts worldwide ranked by ideXlab platform

Philip Craiger - One of the best experts on this subject based on the ideXlab platform.

  • Mac Forensics: Mac OS X and the HFS+ File System
    2011
    Co-Authors: Philip Craiger, Paul K. Burke
    Abstract:

    There are few resources that describe a Forensics analysis of an Apple Mac computer. The purpose of this paper is describe procedures to conduct a Forensics examination of an Apple Mac running the newest operating system, Mac OS X, and its default file system, the Hierarchical File System Plus (HFS+). Our chapter is divided into four sections. In the first we demonstrate Target Disk Mode to create a Forensic Duplicate of a Mac hard drive and an on-site preview of a suspect’s computer. In the second we describe the HFS+ file system and describe the data structures used to represent files and are important in the recovery of deleted files. In the third section we describe several procedures one can use to recover evidence at a physical level to recover evidence from unallocated, slack space, and virtual memory. Finally, we describe methods to recover trace evidence from Mac OS X default email, web browser, and instant messaging applications, as well as Forensic procedures to recover commands issued from a terminal window

  • IFIP Int. Conf. Digital Forensics - Forensic Analysis of Xbox Consoles
    Advances in Digital Forensics III, 2007
    Co-Authors: Paul Burke, Philip Craiger
    Abstract:

    Microsoft’s Xbox game console can be modified to run additional operating systems, enabling it to store gigabytes of non-game related files and run various computer services. Little has been published, however, on procedures for determining whether or not an Xbox console has been modified, for creating a Forensic Duplicate, and for conducting a Forensic investigation. Given the growing popularity of Xbox systems, it is important to understand how to identify, image and examine these devices while reducing the potential of corrupting the media. This paper discusses Xbox Forensics and provides a set of Forensically-sound procedures for analyzing Xbox consoles.

  • IFIP Int. Conf. Digital Forensics - Mac OS X Forensics
    IFIP Advances in Information and Communication Technology, 2006
    Co-Authors: Philip Craiger, Paul Burke
    Abstract:

    This paper describes procedures for conducting Forensic examinations of Apple Macs running Mac OS X. The target disk mode is used to create a Forensic Duplicate of a Mac hard drive and preview it. Procedures are discussed for recovering evidence from allocated space, unallocated space, slack space and virtual memory. Furthermore, procedures are described for recovering trace evidence from Mac OS X default email, web browser and instant messaging applications, as well as evidence pertaining to commands executed from a terminal.

Paul Burke - One of the best experts on this subject based on the ideXlab platform.

  • IFIP Int. Conf. Digital Forensics - Forensic Analysis of Xbox Consoles
    Advances in Digital Forensics III, 2007
    Co-Authors: Paul Burke, Philip Craiger
    Abstract:

    Microsoft’s Xbox game console can be modified to run additional operating systems, enabling it to store gigabytes of non-game related files and run various computer services. Little has been published, however, on procedures for determining whether or not an Xbox console has been modified, for creating a Forensic Duplicate, and for conducting a Forensic investigation. Given the growing popularity of Xbox systems, it is important to understand how to identify, image and examine these devices while reducing the potential of corrupting the media. This paper discusses Xbox Forensics and provides a set of Forensically-sound procedures for analyzing Xbox consoles.

  • IFIP Int. Conf. Digital Forensics - Mac OS X Forensics
    IFIP Advances in Information and Communication Technology, 2006
    Co-Authors: Philip Craiger, Paul Burke
    Abstract:

    This paper describes procedures for conducting Forensic examinations of Apple Macs running Mac OS X. The target disk mode is used to create a Forensic Duplicate of a Mac hard drive and preview it. Procedures are discussed for recovering evidence from allocated space, unallocated space, slack space and virtual memory. Furthermore, procedures are described for recovering trace evidence from Mac OS X default email, web browser and instant messaging applications, as well as evidence pertaining to commands executed from a terminal.

Craiger Philip - One of the best experts on this subject based on the ideXlab platform.

  • Forensic Analysis of Xbox Consoles
    Scholarly Commons, 2007
    Co-Authors: Burke Paul, Craiger Philip
    Abstract:

    Microsoft’s Xbox game console can be modified to run additional operating systems, enabling it to store gigabytes of non-game related files and run various computer services. Little has been published, however, on procedures for determining whether or not an Xbox console has been modified, for creating a Forensic Duplicate, and for conducting a Forensic investigation. Given the growing popularity of Xbox systems, it is important to understand how to identify, image and examine these devices while reducing the potential of corrupting the media. This paper discusses Xbox Forensics and provides a set of Forensically-sound procedures for analyzing Xbox consoles

  • Forensic Analysis of Xbox Consoles
    Springer Nature (Firm), 2007
    Co-Authors: Burke P., Craiger Philip
    Abstract:

    This paper, published in International Federation for Information Processing, volume 242, discusses how Microsoft's Xbox game console can be modified to store non-game related files and run various computer services. Xbox modification creates unique challenges for evidence recovery operations during criminal investigations, and this paper explains how to identify, examine, and Duplicate information on modified Xbox device(s). Forensic procedures include: Initial assessment, preparing an analysis machine, creating a Forensic Duplicate, Xbox memory units, and physical and logical analysis.Â

  • Mac OS X Forensics
    SelectedWorks, 2006
    Co-Authors: Craiger Philip, Burke Paul
    Abstract:

    This paper describes procedures for conducting Forensic examinations of Apple Macs running Mac OS X. The target disk mode is used to create a Forensic Duplicate of a Mac hard drive and preview it. Procedures are discussed for recovering evidence from allocated space, unallocated space, slack space and virtual memory. Furthermore, procedures are described for recovering trace evidence from Mac OS X default email, web browser and instant messaging applications, as well as evidence pertaining to commands executed from a terminal

Burke Paul - One of the best experts on this subject based on the ideXlab platform.

  • Forensic Analysis of Xbox Consoles
    Scholarly Commons, 2007
    Co-Authors: Burke Paul, Craiger Philip
    Abstract:

    Microsoft’s Xbox game console can be modified to run additional operating systems, enabling it to store gigabytes of non-game related files and run various computer services. Little has been published, however, on procedures for determining whether or not an Xbox console has been modified, for creating a Forensic Duplicate, and for conducting a Forensic investigation. Given the growing popularity of Xbox systems, it is important to understand how to identify, image and examine these devices while reducing the potential of corrupting the media. This paper discusses Xbox Forensics and provides a set of Forensically-sound procedures for analyzing Xbox consoles

  • Mac OS X Forensics
    SelectedWorks, 2006
    Co-Authors: Craiger Philip, Burke Paul
    Abstract:

    This paper describes procedures for conducting Forensic examinations of Apple Macs running Mac OS X. The target disk mode is used to create a Forensic Duplicate of a Mac hard drive and preview it. Procedures are discussed for recovering evidence from allocated space, unallocated space, slack space and virtual memory. Furthermore, procedures are described for recovering trace evidence from Mac OS X default email, web browser and instant messaging applications, as well as evidence pertaining to commands executed from a terminal

Burke P. - One of the best experts on this subject based on the ideXlab platform.

  • Forensic Analysis of Xbox Consoles
    Springer Nature (Firm), 2007
    Co-Authors: Burke P., Craiger Philip
    Abstract:

    This paper, published in International Federation for Information Processing, volume 242, discusses how Microsoft's Xbox game console can be modified to store non-game related files and run various computer services. Xbox modification creates unique challenges for evidence recovery operations during criminal investigations, and this paper explains how to identify, examine, and Duplicate information on modified Xbox device(s). Forensic procedures include: Initial assessment, preparing an analysis machine, creating a Forensic Duplicate, Xbox memory units, and physical and logical analysis.Â