<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: More on EnCase Portable</title>
	<atom:link href="http://forensic4cast.com/2009/06/20/more-on-encase-portable/feed/" rel="self" type="application/rss+xml" />
	<link>http://forensic4cast.com/2009/06/20/more-on-encase-portable/</link>
	<description>Welcome to our podcast discussing issues relating to digital forensics</description>
	<lastBuildDate>Thu, 29 Jul 2010 15:00:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: JOHN</title>
		<link>http://forensic4cast.com/2009/06/20/more-on-encase-portable/comment-page-1/#comment-399</link>
		<dc:creator>JOHN</dc:creator>
		<pubDate>Wed, 31 Mar 2010 13:10:20 +0000</pubDate>
		<guid isPermaLink="false">http://4cast.whitfields.org/?p=254#comment-399</guid>
		<description>I used Spada last week to retrieve images. I crashed when trying to axcess deleted images and data. Anybody had this happen before and would it affect our evidence gathering and subsequent court matters.

jh</description>
		<content:encoded><![CDATA[<p>I used Spada last week to retrieve images. I crashed when trying to axcess deleted images and data. Anybody had this happen before and would it affect our evidence gathering and subsequent court matters.</p>
<p>jh</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric MacIntosh</title>
		<link>http://forensic4cast.com/2009/06/20/more-on-encase-portable/comment-page-1/#comment-346</link>
		<dc:creator>Eric MacIntosh</dc:creator>
		<pubDate>Tue, 22 Sep 2009 21:36:54 +0000</pubDate>
		<guid isPermaLink="false">http://4cast.whitfields.org/?p=254#comment-346</guid>
		<description>Has any body tried Encase Portable? If so can you clearify what it can and can&#039;t do.</description>
		<content:encoded><![CDATA[<p>Has any body tried Encase Portable? If so can you clearify what it can and can&#8217;t do.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://forensic4cast.com/2009/06/20/more-on-encase-portable/comment-page-1/#comment-292</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Fri, 03 Jul 2009 17:25:09 +0000</pubDate>
		<guid isPermaLink="false">http://4cast.whitfields.org/?p=254#comment-292</guid>
		<description>A lot of details left out of the video:

   - Note minimal reference to the system having to be &quot;off&quot; (even though his demo machine is on) at the time of &quot;data&quot; extraction.
   - Repeated use of the the term &quot;data&quot; vice evidence.
   - Does the size of the repository USB device indicate estaimated amount of extracted &quot;data&quot;.
   - No mention on the form this data would be extracted in.
   - No mention of collection of system metadata associated with extraction.
   - But to name a few ... issues ....</description>
		<content:encoded><![CDATA[<p>A lot of details left out of the video:</p>
<p>   &#8211; Note minimal reference to the system having to be &#8220;off&#8221; (even though his demo machine is on) at the time of &#8220;data&#8221; extraction.<br />
   &#8211; Repeated use of the the term &#8220;data&#8221; vice evidence.<br />
   &#8211; Does the size of the repository USB device indicate estaimated amount of extracted &#8220;data&#8221;.<br />
   &#8211; No mention on the form this data would be extracted in.<br />
   &#8211; No mention of collection of system metadata associated with extraction.<br />
   &#8211; But to name a few &#8230; issues &#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ron</title>
		<link>http://forensic4cast.com/2009/06/20/more-on-encase-portable/comment-page-1/#comment-288</link>
		<dc:creator>Ron</dc:creator>
		<pubDate>Mon, 29 Jun 2009 02:40:01 +0000</pubDate>
		<guid isPermaLink="false">http://4cast.whitfields.org/?p=254#comment-288</guid>
		<description>Other comments...

If the target PC is not USB bootable, then you have to use the CD.  All of this kind of takes away from the &#039;stealthiness&quot; aspect of the tool.

Likewise, I am guessing that there some sort of write blocking going on through the device or software, but is that guaranteed?

Finally, once  you get the data, is it in some bizarro Encase only format that you need Encase enterprise to analyze?</description>
		<content:encoded><![CDATA[<p>Other comments&#8230;</p>
<p>If the target PC is not USB bootable, then you have to use the CD.  All of this kind of takes away from the &#8216;stealthiness&#8221; aspect of the tool.</p>
<p>Likewise, I am guessing that there some sort of write blocking going on through the device or software, but is that guaranteed?</p>
<p>Finally, once  you get the data, is it in some bizarro Encase only format that you need Encase enterprise to analyze?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ron</title>
		<link>http://forensic4cast.com/2009/06/20/more-on-encase-portable/comment-page-1/#comment-287</link>
		<dc:creator>Ron</dc:creator>
		<pubDate>Mon, 29 Jun 2009 02:36:58 +0000</pubDate>
		<guid isPermaLink="false">http://4cast.whitfields.org/?p=254#comment-287</guid>
		<description>Seems like they are competing against COFEE.  I disagree with the arguments that somehow this is going to let untrained folks mess with computer evidence-anymore than any other tool.

Plus, since it is from Guidance.  You just know it is going to cost several thousands bucks for the kit, then several thousand knicker to keep up with the license.</description>
		<content:encoded><![CDATA[<p>Seems like they are competing against COFEE.  I disagree with the arguments that somehow this is going to let untrained folks mess with computer evidence-anymore than any other tool.</p>
<p>Plus, since it is from Guidance.  You just know it is going to cost several thousands bucks for the kit, then several thousand knicker to keep up with the license.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marian</title>
		<link>http://forensic4cast.com/2009/06/20/more-on-encase-portable/comment-page-1/#comment-285</link>
		<dc:creator>Marian</dc:creator>
		<pubDate>Wed, 24 Jun 2009 08:14:11 +0000</pubDate>
		<guid isPermaLink="false">http://4cast.whitfields.org/?p=254#comment-285</guid>
		<description>From one site it is commercial preasure to create &quot;simple and widely used&quot; tool for not-trained people, but crucial in forensic examination is to gather data properly. Once you have not enough data, you are not able to do correct forensic exanination. EnCase Portable seems to be more appropriate for quick search, where you need first information if there is something or not (for border points, intelligence, etc.).
...but we have not enough information for such conclusions yet.</description>
		<content:encoded><![CDATA[<p>From one site it is commercial preasure to create &#8220;simple and widely used&#8221; tool for not-trained people, but crucial in forensic examination is to gather data properly. Once you have not enough data, you are not able to do correct forensic exanination. EnCase Portable seems to be more appropriate for quick search, where you need first information if there is something or not (for border points, intelligence, etc.).<br />
&#8230;but we have not enough information for such conclusions yet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Pearson</title>
		<link>http://forensic4cast.com/2009/06/20/more-on-encase-portable/comment-page-1/#comment-282</link>
		<dc:creator>Rob Pearson</dc:creator>
		<pubDate>Mon, 22 Jun 2009 13:11:23 +0000</pubDate>
		<guid isPermaLink="false">http://4cast.whitfields.org/?p=254#comment-282</guid>
		<description>Eh..Been there..  This is just a Commercial version of Forensic Boot CD&#039;s have been around for awhile.  It just makes things &quot;EASIER&quot; for the lay person.  But if you are a newb...would you even know what you are looking for??   For this I will stick with SPADA, Helix, 10-23 or whatever flavor Linux Boot CD I can find at the time..  Gotta save money for EnCase 7!!</description>
		<content:encoded><![CDATA[<p>Eh..Been there..  This is just a Commercial version of Forensic Boot CD&#8217;s have been around for awhile.  It just makes things &#8220;EASIER&#8221; for the lay person.  But if you are a newb&#8230;would you even know what you are looking for??   For this I will stick with SPADA, Helix, 10-23 or whatever flavor Linux Boot CD I can find at the time..  Gotta save money for EnCase 7!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lee</title>
		<link>http://forensic4cast.com/2009/06/20/more-on-encase-portable/comment-page-1/#comment-281</link>
		<dc:creator>lee</dc:creator>
		<pubDate>Sun, 21 Jun 2009 13:39:48 +0000</pubDate>
		<guid isPermaLink="false">http://4cast.whitfields.org/?p=254#comment-281</guid>
		<description>Someone still has to do the investigation at the other end. However can you imagine having a case thrown out because someone asked their secretary to get the data?</description>
		<content:encoded><![CDATA[<p>Someone still has to do the investigation at the other end. However can you imagine having a case thrown out because someone asked their secretary to get the data?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jan Collie</title>
		<link>http://forensic4cast.com/2009/06/20/more-on-encase-portable/comment-page-1/#comment-280</link>
		<dc:creator>Jan Collie</dc:creator>
		<pubDate>Sun, 21 Jun 2009 13:36:11 +0000</pubDate>
		<guid isPermaLink="false">http://4cast.whitfields.org/?p=254#comment-280</guid>
		<description>Is this the start of F**k-wit Forensics?  No knowledge needed?</description>
		<content:encoded><![CDATA[<p>Is this the start of F**k-wit Forensics?  No knowledge needed?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
