<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>DFRWS on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/dfrws/</link>
    <description>Recent content in DFRWS on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 06 Sep 2017 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/dfrws/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>DFRWS USA 2017</title>
      <link>https://insinuator.net/2017/09/dfrws-usa-2017/</link>
      <pubDate>Wed, 06 Sep 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/09/dfrws-usa-2017/</guid>
      <description>&lt;p&gt;As mentioned in my last &lt;a href=&#34;https://insinuator.net/2017/07/release-of-glibc-heap-analysis-plugins-for-rekall/&#34;&gt;blogpost&lt;/a&gt;, I had the pleasure to participate in this years DFRWS USA and present our paper. The paper and presentation can be freely viewed and downloaded &lt;a href=&#34;https://www.dfrws.org/conferences/dfrws-usa-2017/sessions/linux-memory-forensics-dissecting-user-space-process-heap&#34;&gt;here&lt;/a&gt; or &lt;a href=&#34;https://authors.elsevier.com/sd/article/S1742287617301895&#34;&gt;here&lt;/a&gt;. Note that there is also an extended version of the paper, which can be downloaded &lt;a href=&#34;https://opus4.kobv.de/opus4-fau/frontdoor/index/index/docId/8340&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The keepassx, zsh and heap analysis plugins are now also part of the &lt;a href=&#34;https://github.com/google/rekall/releases/tag/v1.7.0rc1&#34;&gt;Rekall release candidate 1.7.0RC1&lt;/a&gt;, so it’s easier to get started.&lt;/p&gt;&#xA;&lt;p&gt;The conference had some great talks and workshops, which I’m going to briefly sum up.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DFRWS EU 2016 Summary</title>
      <link>https://insinuator.net/2016/03/dfrws-eu-2016-summary/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/dfrws-eu-2016-summary/</guid>
      <description>&lt;p&gt;In this article, I want to provide a concise sum-up of the (to me) most interesting talks of this year’s DFRWS EU (&lt;a href=&#34;http://www.dfrws.org/2016eu/&#34;&gt;http://www.dfrws.org/2016eu/&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;Eoghan Casey, one of most famous pioneers in digital forensics, and David-Olivier Jaquet-Chiffelle, professor in police science at University of Lausanne, gave a keynote that emphasized the need for theoretical fundamental basis research in the field of digital forensics, which I fully agreed on, as this was exactly what I addressed in some of my former research.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Generic RAID Reassembly using Block-Level Entropy</title>
      <link>https://insinuator.net/2016/03/generic-raid-reassembly-using-block-level-entropy/</link>
      <pubDate>Wed, 30 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/generic-raid-reassembly-using-block-level-entropy/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/03/FullSizeRender-209x300.jpg&#34; alt=&#34;DFRWS EU 2016 Talk Forensic Raid Recovery&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;DFRWS EU 2016 Talk Forensic Raid Recovery&lt;/p&gt;&#xA;&lt;p&gt;We just presented our Paper “&lt;em&gt;Generic RAID Reassembly using Block-Level Entropy&lt;/em&gt;” at the &lt;em&gt;DFRWS EU 2016&lt;/em&gt; digital forensics conference (&lt;a href=&#34;http://www.dfrws.org/&#34;&gt;http://www.dfrws.org/&lt;/a&gt;). The article is about a new approach that we developed for forensic RAID recovery. Our technique calculates block-wise entropy all over the disks and uses generic heuristics on those to detect all the relevant RAID parameters such as stripe size, stripe map, disk order, and RAID type, that are needed to reassemble the RAID and make the data accessible again for forensic investigations (or just for data recovery).&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
