If my work with Volume Shadow Copies has taught me one thing it is that I don’t know anything. I have often said the more I learn, the less I know. Everything that we learn about computer investigations leads to more learning. It never ends. Anyone that thinks they know everything there is to know […]
Here it is. The presentation I was due to give at the SANS EU Forensic Summit. Hope you find it useful. Bare in mind you’ll have to have iTunes or Quicktime installed to watch this. I’ll work on getting it into other formats later. Enjoy!
A brand new episode for your listening pleasure.
Lee Whitfield gives insight into Microsoft Volume Shadow Copies and shows how to extract meaningful data by manually deconstructing these files.
We’re coming back!
We have a new URL shortening service
I appeared on the recent Sans webcast about computer forensics
Rob Lee spent some time talking with me this last week. Hear the conversation here.
I’m focussing my attentions elsewhere for a few weeks.