Skip to content

Commit 934fe8c

Browse files
committed
cleanup_wip
1 parent c4b1769 commit 934fe8c

15 files changed

+640
-10714
lines changed

docs/anti_forensic_techniques.md

Lines changed: 6 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -24,8 +24,7 @@ like any [tool](tools.md) they can be abused.
2424

2525
### Secure Data Deletion
2626

27-
[Secure Deletion](secure_data_deletion.md) data, so that it
28-
cannot be restored with forensic methods.
27+
Secure Deletion data, so that it cannot be restored with forensic methods.
2928

3029
Overwriting programs typically operate in one of three modes:
3130

@@ -75,11 +74,10 @@ could not be reliably constructed.
7574

7675
For example, [Timestomp](timestomp.md) will overwrite
7776
[NTFS](ntfs.md) “create,” “modify,” “access,” and “change”
78-
timestamps ([metasploit](metasploi.md). [The Defiler’s
79-
Toolkit](the_defiler’s_toolkit.md) can overwrite inode
77+
timestamps (metasploit). The Defiler’s Toolkit can overwrite inode
8078
timestamps and deleted directory entries on many Unix systems;
8179
timestamps on allocated files can also be modified using the Unix touch
82-
command ([The Grugq](the_grugq.md).
80+
command ([The Grugq](the_grugq.md)).
8381

8482
### Preventing Data Creation
8583

@@ -206,11 +204,11 @@ to that by destroying evidence, for example.
206204

207205
### Casper
208206

209-
![](Grml.png "Grml.png") mounted root file system on the [hard drive](hard_drive.md)
207+
Grml mounted root file system on the [hard drive](hard_drive.md)
210208
[Casper](http://bromavilleherald.com/index.php/Casper_boot_process) is a
211209
set of scripts used to enable Linux-based distributions to boot from
212210
removable media. Casper scripts will search for the root file system
213-
(typically [SquashFS](squashfs.md) on the local data storage
211+
(typically SquashFS on the local data storage
214212
media during the boot, mount it, and execute */sbin/init* program on
215213
mounted root. Most forensic Linux distributions based on
216214
[Ubuntu](ubuntu.md) and Debian lack of
@@ -239,10 +237,6 @@ Henrique, G. Wendel, Anti Forensics: Making computer forensics hard,
239237
Code Breakers III, São Paulo, Brazil, Setember 2006.
240238
[3](http://ws.hackaholic.org/slides/AntiForensics-CodeBreakers2006-Translation-To-English.pdf)
241239

242-
## See also
243-
244-
- [Anti-forensics tools](antiforensics_tools.md)
245-
246240
## Externals Links
247241

248242
* [Anti-Forensics: The Next Step in Digital Forensics Tool Testing](https://www.digitrace.de/veroeffentlichung-2/fachliteratur/84-anti-forensics-the-next-step-in-digital-forensics-tool-testing),
@@ -258,7 +252,7 @@ Code Breakers III, São Paulo, Brazil, Setember 2006.
258252
Little over 3hr of video on the subject of anti-forensic techniques
259253
* [Linux for computer forensic investigators: problems of booting trusted operating system](http://www.computer-forensics-lab.org/pdf/Linux_for_computer_forensic_investigators_2.pdf)
260254
* [Low Down and Dirty: Anti-forensic Rootkits](https://www.blackhat.com/presentations/bh-jp-06/BH-JP-06-Bilby-up.pdf),
261-
by [Darren Bilby](darren_bilby.md), Blackhat Japan 2006
255+
by Darren Bilby, Blackhat Japan 2006
262256
* [One-byte Modification for Breaking Memory Forensic Analysis](https://media.blackhat.com/bh-eu-12/Haruyama/bh-eu-12-Haruyama-Memory_Forensic-Slides.pdf),
263257
by Takahiro Haruyama, Hiroshi Suzuki, March 14-16, 2012
264258

docs/data_storage_media.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ different properties regarding forensic investigation.
77

88
## Media
99

10-
- [Caches](cache.md)
10+
- Caches
1111
- RAM, ROM, Flash
1212
- Floppy Disks
1313
- Optical media: CDs, DVDs, CD-RWs, ...

docs/fat.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -269,7 +269,7 @@ used in electronic devices with miniature hard drives.
269269
Examples of devices in which FAT is utilized include:
270270

271271
* [USB](usb.md) thumb drives
272-
* [Digital cameras](digital_camera.md)
272+
* Digital cameras
273273
* Digital camcorders
274274
* Portable audio and video players
275275
* Multifunction [printers](printers.md)
@@ -687,13 +687,13 @@ object.
687687
* [Wikipedia: ExFAT](https://en.wikipedia.org/wiki/ExFAT)
688688
* [exFAT File System](http://www.active-undelete.com/xfat_volume.htm)
689689
* [Reverse Engineering the Microsoft exFAT File System](https://www.sans.org/white-papers/33274/),
690-
by [Robert Shullich](robert_shullich.md), December 1, 2009
690+
by Robert Shullich, December 1, 2009
691691
* [Extended FAT file system](https://paradigmsolutions.files.wordpress.com/2009/12/exfat-excerpt-1-4.pdf),
692-
by [Jeff Hamm](jeff_hamm.md), December 2009
692+
by Jeff Hamm, December 2009
693693
* [Demystifying the Microsoft Extended FAT File System (exFAT)](https://www.slideshare.net/overcertified/demystifying-the-microsoft-extended-fat-file-system-exfat),
694-
by [Robert Shullich](robert_shullich.md), September 20, 2010
694+
by Robert Shullich, September 20, 2010
695695
* [Windows Phone 7 : Implications For Digital Forensic Investigators](http://aut.researchgateway.ac.nz/bitstream/handle/10292/4123/LeY.pdf),
696-
by [Yung Anh Le](yung_anh_le.md), 2012
696+
by Yung Anh Le, 2012
697697

698698
### textFAT
699699

docs/file_carving_bibliography.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -94,7 +94,7 @@ of sector-scanning forensic tools.",
9494

9595
## Evaluations
9696

97-
* [Measuring and Improving the Quality of File Carving Methods](media:kloet_2007.pdf.md),
97+
* [Measuring and Improving the Quality of File Carving Methods](https://github.com/libyal/documentation/blob/main/Thesis%20-%20Measuring%20and%20Improving%20the%20Quality%20of%20File%20Carving%20Methods.pdf)
9898
by S.J.J. Kloet , Master's thesis, Eindhoven University of Technology, August 2007
9999

100100
## See also

0 commit comments

Comments
 (0)