Skip to content

Commit c40d0c9

Browse files
committed
cleanup9
1 parent 308c70f commit c40d0c9

28 files changed

+59
-281
lines changed

docs/apple_safari.md

Lines changed: 5 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -69,22 +69,17 @@ named **LastSession.plist** in the user directory.
6969

7070
The Safari cache is stored in **Cache.db** in the cache directory.
7171

72-
This file uses the [SQLite database
73-
format](sqlite_database_format.md).
72+
This file uses the [SQLite database format](sqlite_database_format.md).
7473

7574
## External Links
7675

77-
- [Official website](https://www.apple.com/macos/ventura/)
78-
- [Safari Cache
79-
Revisited](http://www.appleexaminer.com)
76+
* [Safari Cache Revisited](http://www.appleexaminer.com)
8077
by Sean Cavanaugh
81-
- [Analyzing Apple Safari
82-
Artifacts](http://www.appleexaminer.com),
78+
* [Analyzing Apple Safari Artifacts](http://www.appleexaminer.com),
8379
by Selena Ley
84-
- [iOS / macOS - Tracking Downloads from Safari Without Downloads](https://blog.d204n6.com/2021/05/ios-macos-tracking-downloads-from.html)
80+
* [iOS / macOS - Tracking Downloads from Safari Without Downloads](https://blog.d204n6.com/2021/05/ios-macos-tracking-downloads-from.html)
8581
by Scott Vance, Friday, 28 May 2021
8682

8783
## Tools
8884

89-
- [J.A.F.A.T. Archive of Forensics Analysis
90-
Tools](https://jafat.sourceforge.net/) home of Safari Forensic Tools (SFT)
85+
* [J.A.F.A.T. Archive of Forensics Analysis Tools](https://jafat.sourceforge.net/) home of Safari Forensic Tools (SFT)

docs/bloom_filters.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ tags:
55
---
66
# References
77

8-
- [Network Applications of Bloom Filters: A Survey](https://www.tandfonline.com/toc/uinm20/current),
8+
- [Network Applications of Bloom Filters: A Survey](https://www.eecs.harvard.edu/~michaelm/postscripts/im2005b.pdf),
99
Andrei Broder and Michael Mitzenmacher, Internet Mathematics Vol. 1,
1010
No 4: 485--509
1111

docs/caine_live_cd.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -154,7 +154,7 @@ the project Caine since the 1.0 release to date that has arrived at
154154
version 4.0 (18-March-2013) and achieving praise from law enforcements
155155
of several foreign nations.
156156

157-
November 24, 2012 The Caine 3.0 was presented at the [Opens Source Day 2012](https://www.opensourceday.org/2012/?mid=20)
157+
November 24, 2012 The Caine 3.0 was presented at the Opens Source Day 2012
158158
at the University of Udine.
159159

160160
## Bibliography

docs/carver_2.0_planning_page.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -921,9 +921,10 @@ Possible file structure validator libraries
921921

922922
Input support
923923

924-
- AFF (http://www.afflib.org/)
924+
- [AFF](aff.md)
925925
- [libewf](libewf.md)
926-
- TSK device & raw & split raw (http://www.sleuthkit.org/)
926+
- raw and split raw
927+
- device
927928

928929
Volume/Partition support
929930

docs/department_of_justice_computer_crime_and_intellectual_property_section.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,4 +45,4 @@ protected by copyright, trademark, or trade-secret designation.
4545

4646
## External Links
4747

48-
- [Official website](https://www.justice.gov/criminal-ccips)
48+
- [Official website](https://www.justice.gov/criminal/criminal-ccips)

docs/forensic_accounting.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -64,6 +64,5 @@ the final examination needs to be completed.
6464

6565
## External links
6666

67-
- [Times of India Article on CFAP](https://epaper.timesgroup.com/Repository/ml.asp?Ref=VE9JQkcvMjAwOS8wNS8wNCNBcjAzMjAx)
6867
- [CFAP Information Powerpoint](https://www.slideshare.net/indiaforensic/certified-forensic-accounting-professional)
6968
- [Certification programs offered by Indiaforensic](https://www.indiaforensic.com/education/)

docs/how_to_set_up_a_disk_imaging_station.md

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -81,9 +81,7 @@ Note that the order you do this matters: Sleuth Kit won't compile with
8181
AFFLIB support unless AFFLIB is installed on your system.
8282

8383
1. Download and install [libewf](libewf.md) if you want EnCase support.
84-
2. Download and install [AFFLIB](aff.md) from <https://www.afflib.org/>
84+
2. Download and install [AFFLIB](aff.md
8585
3. Download and install [The Sleuth Kit](the_sleuth_kit.md) from
8686
<http://www.sleuthkit.org/>
87-
4. Download and install [fiwalk](fiwalk.md) from
88-
<https://www.afflib.org/>
89-
87+
4. Download and install [fiwalk](fiwalk.md)

docs/ios.md

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -43,12 +43,10 @@ Podcasts, Recordings and Pictures/Videos taken
4343
There are several tools available to extract information out of iOS
4444
operating systems (listed alphabetically):
4545

46-
* Aceso by Radio Tactics
47-
[1](https://radio-tactics.com)
46+
* [Aceso by Radio Tactics](https://radio-tactics.com)
4847
* [Nuix Desktop](nuix_desktop.md) and [Proof Finder](proof_finder.md) by
4948
[Nuix](nuix.md).
50-
* Oxygen Forensic Suite by Oxygen Software
51-
[4](https://www.oxygen-forensic.com/en/)
49+
* [Oxygen Forensic Suite](oxygen_forensic_suite.md)
5250
* UFED and Physical Analyzer by Cellebrite
5351
[5](https://cellebrite.com/en/home/)
5452
* XRY by [Micro Systemation](https://www.msab.com/)

docs/list_of_cyberspeak_podcast_interviews.md

Lines changed: 2 additions & 141 deletions
Original file line numberDiff line numberDiff line change
@@ -19,82 +19,49 @@ below.
1919
- 18 Jan 2006: Simple Nomad
2020
- 21 Jan 2006: Johnny Long
2121
- 28 Jan 2006: [Kevin Mandia](kevin_mandia.md)
22-
23-
<!-- -->
24-
2522
- 4 Feb 2006: [Brian Carrier](brian_carrier.md)
2623
- 11 Feb 2006: [Jesse Kornblum](jesse_kornblum.md)
2724
- 18 Feb 2006: Bruce Potter of the Shmoo Group
2825
- 25 Feb 2006: [Kris Kendall](kris_kendall.md) speaks about malware analysis
29-
30-
<!-- -->
31-
3226
- 4 Mar 2006: Dave Merkel
3327
- 11 Mar 2006: James Wiebe of Wiebe Tech
3428
Also Todd Bellows of [LogiCube](logicube.md) about CellDek
3529
- 18 Mar 2006: [Kris Kendall](kris_kendall.md)
3630
- 25 Mar 2006: (No interview)
37-
38-
<!-- -->
39-
4031
- 1 Apr 2006: [Harlan Carvey](harlan_carvey.md), creator of the
4132
[Forensic Server Project](forensic_server_project.md)
4233
- 8 Apr 2006: (No interview)
4334
- 15 Apr 2006: (No interview), but first to mention the [ForensicsWiki](index.md)!
4435
- 22 Apr 2006: Jaime Florence about Mercury, a text indexing product
45-
46-
<!-- -->
47-
4836
- 6 May 2006: Mark Rache and Dave Merkel
4937
- 13 May 2006: Steve Bunting
5038
- 21 May 2006: Mike Younger
5139
- 29 May 2006: Mike Younger
52-
53-
<!-- -->
54-
5540
- 3 Jun 2006: [Jesse Kornblum](jesse_kornblum.md) about [Windows Memory Analysis](windows_memory_analysis.md)
5641
- 10 Jun 2006: (No interview)
5742
- 17 Jun 2006: Mike Younger
5843
- 24 Jun 2006: (No interview)
59-
60-
<!-- -->
61-
6244
- 1 Jul 2006: (No interview)
6345
- 9 Jul 2006: Johnny Long
6446
- 18 Jul 2006: Dark Tangent
6547
- 30 Jul 2006: [Jesse Kornblum](jesse_kornblum.md) about
6648
[ssdeep](ssdeep.md) and [Fuzzy Hashing](context_triggered_piecewise_hashing.md)
67-
68-
<!-- -->
69-
7049
- 10 Aug 2006: Brian Contos discusses his book *Insider Threat: Enemy at the Watercooler*
7150
- 13 Aug 2006: Richard Bejtlich discusses his book *Real Digital Forensics*
7251
- 27 Aug 2006: David Farquhar
73-
74-
<!-- -->
75-
7652
- 3 Sep 2006: [Keith Jones](keith_jones.md)
7753
- 10 Sep 2006: (No Interview)
7854
- 17 Sep 2006: (No Interview)
7955
- 24 Sep 2006: (No Interview)
80-
81-
<!-- -->
82-
8356
- 1 Oct 2006: Brian Kaplan, author of [LiveView](liveview.md)
8457
- 8 Oct 2006: Tom Gallagher discusses his book *Hunting Security Bugs*
8558
- 15 Oct 2006: (No Interview)
8659
- 29 Oct 2006: (No Interview)
87-
88-
<!-- -->
89-
9060
- 12 Nov 2006: [Jesse Kornblum](jesse_kornblum.md) discusses his
9161
paper *Exploiting the Rootkit Paradox with Windows Memory Analysis*
9262
- 19 Nov 2006: [Kris Kendall](kris_kendall.md) discusses
9363
unpacking binaries when conducting malware analysis
9464
- 26 Nov 2006: (No Interview)
95-
96-
<!-- -->
97-
9865
- 3 Dec 2006: Brian Dykstra
9966
- 10 Dec 2006: Mike Younger
10067
- 17 Dec 2006: Mike Younger and Geoff Michelli
@@ -104,108 +71,57 @@ below.
10471
- 7 Jan 2007: Jamie Butler
10572
- 17 Jan 2007: Chad McMillan
10673
- 28 Jan 2007: [Jesse Kornblum](jesse_kornblum.md)
107-
108-
<!-- -->
109-
11074
- 11 Feb 2007: [Scott Moulton](scott_moulton.md)
11175
- 18 Feb 2007: Phil Zimmerman, creator of PGP discussing
11276
his new Zfone
11377
- 25 Feb 2007: Mark Menz and Jeff Moss
114-
115-
<!-- -->
116-
11778
- 4 Mar 2007: No show due to technical difficulties
11879
- 12 Mar 2007: Trevor Fairchild of
11980
[Ontario Provincial Police Department](ontario_provincial_police_department.md)
12081
discussing C4P and C4M, both add-ons to [EnCase](encase.md)
12182
- 18 Mar 2007: Tony Hogeveen of [DeepSpar](deepspar.md) Date Recovery Systems
12283
- 25 Mar 2007: Shmoocon broadcast
123-
124-
<!-- -->
125-
12684
- 1 Apr 2007: Kevin Smith from LTU Technologies about Image Seeker
12785
- 15 Apr 2007: [Jim Christy](jim_christy.md) from the
12886
[Defense Cyber Crime Center](defense_cyber_crime_center.md)
12987
- 22 Apr 2007: [Jesse Kornblum](jesse_kornblum.md) all about the
13088
[Forensics Wiki](index.md)!
13189
- 29 Apr 2007: [Harlan Carvey](harlan_carvey.md) discusses his
13290
new book
133-
134-
<!-- -->
135-
13691
- 13 May 2007: Russell Yawn
13792
- 20 May 2007: No interview
138-
139-
<!-- -->
140-
14193
- 2 June 2007: No interview
14294
- 10 June 2007: [Paul Ohm](paul_ohm.md)
14395
- 17 June 2007: No interview
14496
- 24 June 2007: No interview
145-
146-
<!-- -->
147-
14897
- 1 July 2007: No interview
14998
- 22 July 2007: Didier Stevens about the UserAssist Windows
15099
Registry key parser
151100
- 29 July 2007: No interview
152-
153-
<!-- -->
154-
155101
- 23 Sep 2007: No interview
156102
- 30 Sep 2007: No interview
157-
158-
<!-- -->
159-
160103
- 15 Oct 2007: No interview
161-
162-
<!-- -->
163-
164104
- 12 Nov 2007: No interview
165-
166-
<!-- -->
167-
168105
- 21 Dec 2007: No interview
169106

170107
### 2008
171108

172109
- 14 Jan 2008: No interview
173-
174-
<!-- -->
175-
176110
- 10 Feb 2008: No interview
177111
- 17 Feb 2008: Unknown
178-
179-
<!-- -->
180-
181112
- 8 Mar 2008: [Dr. Simson Garfinkel](simson_l_garfinkel.md)
182113
about the [Advanced Forensic Format](aff.md)
183114
- 16 Mar 2008: No interview
184115
- 31 Mar 2008: No interview
185-
186-
<!-- -->
187-
188116
- 13 Apr 2008: No interview
189117
- 27 Apr 2008: No interview
190-
191-
<!-- -->
192-
193118
- 10 May 2008: Al Lewis from Subrosasoft about the Mac Lockpick
194-
195-
<!-- -->
196-
197119
- 1 Jun 2008: Mark McKinnon from Red Wolf Computer Forensics about his CSC
198120
Parser.
199121
- 15 Jun 2008: No interview
200122
- 28 Jun 2008: No interview
201-
202-
<!-- -->
203-
204123
- 6 Sep 2008: [Jesse Kornblum](jesse_kornblum.md) about fun
205124
tricks with computer memory
206-
207-
<!-- -->
208-
209125
- 28 Sep 2008: [Kevin Mandia](kevin_mandia.md) about incident
210126
response
211127

@@ -214,104 +130,49 @@ below.
214130
- 3 Jan 2010: [Amber Schroader](amber_schroader.md) about
215131
[Paraben](https://paraben.com/) and what we have to look forward
216132
to!
217-
218-
<!-- -->
219-
220133
- 17 Jan 2010: Didier Stevens about some of his recent
221134
[forensic tools and research](https://blog.didierstevens.com/), including
222135
the changes to the UserAssist registry keys in Windows 7 and his malicious
223136
PDF tools.
224-
225-
<!-- -->
226-
227137
- 31 Jan 2010: Robert Botcheck, founder and owner of Tableau
228138
talks about new Tableau Imager (TIM)
229-
230-
<!-- -->
231-
232139
- 28 Feb 2010: Christa Miller about the need for law enforcement and digital
233140
forensics specialists to manage their online resumes.
234-
235-
<!-- -->
236-
237141
- 21 Mar 2010: Joe Seanor, a former Senior AOL Investigator. Joe has developed
238142
the [Internet Predator Tracker](http://www.internetpredatortracker.com/)
239143
software.
240-
241-
<!-- -->
242-
243144
- 4 Apr 2010: [Kristinn Guðjónsson](kristinn_gudjonsson.md)
244145
update on Timeline Analysis and [Log2Timeline](log2timeline.md)
245146
- 19 Apr 2010: Nick Ferneau, developer of
246147
Skypx, a free utility that recovers Skype artifacts from RAM images.
247-
248-
<!-- -->
249-
250-
- 24 May 2010: Sam Guttman President of the
251-
[Digital Forensics Certification Board](https://www.ncfs.org/), an
252-
international vendor neutral computer forensic certification
148+
- 24 May 2010: Sam Guttman President of the Digital Forensics Certification
149+
Board, an international vendor neutral computer forensic certification
253150
authority.
254-
255-
<!-- -->
256-
257151
- 18 Jul 2010: [Kristinn Guðjónsson](kristinn_gudjonsson.md)
258152
about Timeline Analysis and [Log2Timeline](log2timeline.md)
259-
260-
<!-- -->
261-
262153
- 25 Oct 2010: Sean Morrisey about iOS forensics and Katana Forensics
263-
264-
<!-- -->
265-
266154
- 16 Nov 2010: Jeff Nash about LACE image and video categorization software and
267155
[BlueBear Law Enforcement Services](https://bb-les.ca/)
268-
269-
<!-- -->
270-
271156
- 1 Nov 2010: Raphael Bousquet about [ADF Triage](https://www.adfsolutions.com/triage-investigator)
272157

273158
### 2011
274159

275160
- 16 Jan 2011: Mark Wade about Prefetch forensics
276-
277-
<!-- -->
278-
279161
- 5 Apr 2011: [Scott Moulton](scott_moulton.md) about Solid
280162
State Hard Drives Forensics
281-
282-
<!-- -->
283-
284163
- 26 Jun 2011: [Josh Goldfoot](josh_goldfoot.md) about The Physical Computer
285164
and the 4th Amendment
286165
- 30 Jun 2011: [Cindy Murphy](cindy_murphy.md): about the launch
287166
of the CDFS
288-
289-
<!-- -->
290-
291167
- 18 Jul 2011: George Starcher about password cracking using Access Data’s
292168
DNA and Amazon’s Elastic Compute Cloud.
293-
294-
<!-- -->
295-
296169
- 18 Aug 2011: [Keith Jones](keith_jones.md) about Do's and
297170
Don'ts of Testifying
298-
299-
<!-- -->
300-
301171
- 21 Aug 2011: [Drew Fahey](drew_fahey.md), VP of Products at
302172
Blackbag Technologies.
303-
304-
<!-- -->
305-
306173
- 28 Aug 2011: Chris Pogue also known as Mr. Sniper Forensics
307-
308-
<!-- -->
309-
310174
- 26 Sep 2011: Andrew Case, one of the developers of Registry Decoder,
311175
a National Institute of Justice sponsored application.
312-
313-
<!-- -->
314-
315176
- 1 Dec 2011: [Ken Privette](ken_privette.md) with NUIX about
316177
their new tool release this morning called Proof Finder.
317178

0 commit comments

Comments
 (0)