The Experts below are selected from a list of 21 Experts worldwide ranked by ideXlab platform
Philip Craiger - One of the best experts on this subject based on the ideXlab platform.
-
Mac Forensics: Mac OS X and the HFS+ File System
2011Co-Authors: Philip Craiger, Paul K. BurkeAbstract:There are few resources that describe a Forensics analysis of an Apple Mac computer. The purpose of this paper is describe procedures to conduct a Forensics examination of an Apple Mac running the newest operating system, Mac OS X, and its default file system, the Hierarchical File System Plus (HFS+). Our chapter is divided into four sections. In the first we demonstrate Target Disk Mode to create a Forensic Duplicate of a Mac hard drive and an on-site preview of a suspect’s computer. In the second we describe the HFS+ file system and describe the data structures used to represent files and are important in the recovery of deleted files. In the third section we describe several procedures one can use to recover evidence at a physical level to recover evidence from unallocated, slack space, and virtual memory. Finally, we describe methods to recover trace evidence from Mac OS X default email, web browser, and instant messaging applications, as well as Forensic procedures to recover commands issued from a terminal window
-
IFIP Int. Conf. Digital Forensics - Forensic Analysis of Xbox Consoles
Advances in Digital Forensics III, 2007Co-Authors: Paul Burke, Philip CraigerAbstract:Microsoft’s Xbox game console can be modified to run additional operating systems, enabling it to store gigabytes of non-game related files and run various computer services. Little has been published, however, on procedures for determining whether or not an Xbox console has been modified, for creating a Forensic Duplicate, and for conducting a Forensic investigation. Given the growing popularity of Xbox systems, it is important to understand how to identify, image and examine these devices while reducing the potential of corrupting the media. This paper discusses Xbox Forensics and provides a set of Forensically-sound procedures for analyzing Xbox consoles.
-
IFIP Int. Conf. Digital Forensics - Mac OS X Forensics
IFIP Advances in Information and Communication Technology, 2006Co-Authors: Philip Craiger, Paul BurkeAbstract:This paper describes procedures for conducting Forensic examinations of Apple Macs running Mac OS X. The target disk mode is used to create a Forensic Duplicate of a Mac hard drive and preview it. Procedures are discussed for recovering evidence from allocated space, unallocated space, slack space and virtual memory. Furthermore, procedures are described for recovering trace evidence from Mac OS X default email, web browser and instant messaging applications, as well as evidence pertaining to commands executed from a terminal.
Paul Burke - One of the best experts on this subject based on the ideXlab platform.
-
IFIP Int. Conf. Digital Forensics - Forensic Analysis of Xbox Consoles
Advances in Digital Forensics III, 2007Co-Authors: Paul Burke, Philip CraigerAbstract:Microsoft’s Xbox game console can be modified to run additional operating systems, enabling it to store gigabytes of non-game related files and run various computer services. Little has been published, however, on procedures for determining whether or not an Xbox console has been modified, for creating a Forensic Duplicate, and for conducting a Forensic investigation. Given the growing popularity of Xbox systems, it is important to understand how to identify, image and examine these devices while reducing the potential of corrupting the media. This paper discusses Xbox Forensics and provides a set of Forensically-sound procedures for analyzing Xbox consoles.
-
IFIP Int. Conf. Digital Forensics - Mac OS X Forensics
IFIP Advances in Information and Communication Technology, 2006Co-Authors: Philip Craiger, Paul BurkeAbstract:This paper describes procedures for conducting Forensic examinations of Apple Macs running Mac OS X. The target disk mode is used to create a Forensic Duplicate of a Mac hard drive and preview it. Procedures are discussed for recovering evidence from allocated space, unallocated space, slack space and virtual memory. Furthermore, procedures are described for recovering trace evidence from Mac OS X default email, web browser and instant messaging applications, as well as evidence pertaining to commands executed from a terminal.
Craiger Philip - One of the best experts on this subject based on the ideXlab platform.
-
Forensic Analysis of Xbox Consoles
Scholarly Commons, 2007Co-Authors: Burke Paul, Craiger PhilipAbstract:Microsoft’s Xbox game console can be modified to run additional operating systems, enabling it to store gigabytes of non-game related files and run various computer services. Little has been published, however, on procedures for determining whether or not an Xbox console has been modified, for creating a Forensic Duplicate, and for conducting a Forensic investigation. Given the growing popularity of Xbox systems, it is important to understand how to identify, image and examine these devices while reducing the potential of corrupting the media. This paper discusses Xbox Forensics and provides a set of Forensically-sound procedures for analyzing Xbox consoles
-
Forensic Analysis of Xbox Consoles
Springer Nature (Firm), 2007Co-Authors: Burke P., Craiger PhilipAbstract:This paper, published in International Federation for Information Processing, volume 242, discusses how Microsoft's Xbox game console can be modified to store non-game related files and run various computer services. Xbox modification creates unique challenges for evidence recovery operations during criminal investigations, and this paper explains how to identify, examine, and Duplicate information on modified Xbox device(s). Forensic procedures include: Initial assessment, preparing an analysis machine, creating a Forensic Duplicate, Xbox memory units, and physical and logical analysis.Â
-
Mac OS X Forensics
SelectedWorks, 2006Co-Authors: Craiger Philip, Burke PaulAbstract:This paper describes procedures for conducting Forensic examinations of Apple Macs running Mac OS X. The target disk mode is used to create a Forensic Duplicate of a Mac hard drive and preview it. Procedures are discussed for recovering evidence from allocated space, unallocated space, slack space and virtual memory. Furthermore, procedures are described for recovering trace evidence from Mac OS X default email, web browser and instant messaging applications, as well as evidence pertaining to commands executed from a terminal
Burke Paul - One of the best experts on this subject based on the ideXlab platform.
-
Forensic Analysis of Xbox Consoles
Scholarly Commons, 2007Co-Authors: Burke Paul, Craiger PhilipAbstract:Microsoft’s Xbox game console can be modified to run additional operating systems, enabling it to store gigabytes of non-game related files and run various computer services. Little has been published, however, on procedures for determining whether or not an Xbox console has been modified, for creating a Forensic Duplicate, and for conducting a Forensic investigation. Given the growing popularity of Xbox systems, it is important to understand how to identify, image and examine these devices while reducing the potential of corrupting the media. This paper discusses Xbox Forensics and provides a set of Forensically-sound procedures for analyzing Xbox consoles
-
Mac OS X Forensics
SelectedWorks, 2006Co-Authors: Craiger Philip, Burke PaulAbstract:This paper describes procedures for conducting Forensic examinations of Apple Macs running Mac OS X. The target disk mode is used to create a Forensic Duplicate of a Mac hard drive and preview it. Procedures are discussed for recovering evidence from allocated space, unallocated space, slack space and virtual memory. Furthermore, procedures are described for recovering trace evidence from Mac OS X default email, web browser and instant messaging applications, as well as evidence pertaining to commands executed from a terminal
Burke P. - One of the best experts on this subject based on the ideXlab platform.
-
Forensic Analysis of Xbox Consoles
Springer Nature (Firm), 2007Co-Authors: Burke P., Craiger PhilipAbstract:This paper, published in International Federation for Information Processing, volume 242, discusses how Microsoft's Xbox game console can be modified to store non-game related files and run various computer services. Xbox modification creates unique challenges for evidence recovery operations during criminal investigations, and this paper explains how to identify, examine, and Duplicate information on modified Xbox device(s). Forensic procedures include: Initial assessment, preparing an analysis machine, creating a Forensic Duplicate, Xbox memory units, and physical and logical analysis.Â