All,
I've posted my GMU2005 presentations
http//
H. Carvey
"Windows Forensics and Incident Recovery"
http//
http//windowsir.blogspot.com
Really good work, especially liked the work on the Event Logs, I'll have a play with your findings.
Thanks for sharing with the community.
Nick
Ditto…
I'm partial to the usb information and can see it especially useful with the proliferation of (as you mentined) ipods….
The event viewer findings I will also play with but on one of my "clearer headed" days.
Thanks.
Andrew-
Good stuff! Thanks for sharing.
Excellent work.
All,
Thanks for your comments.
I've updated the archive…click on the link in my first post…to include another presentation I got to give, plus some Perl scripts mentioned in the presentations.
Thanks,
H. Carvey
"Windows Forensics and Incident Recovery"
http//
http//windowsir.blogspot.com