Chapter 25: Generalized Editors and Viewers

OVERVIEW

Despite the growing popularity and acceptance of tool suites produced by Guidance, Paraben, AccessData, and ASR Data, it is still important for the investigator to understand the internals of the automated operations these tool suites have built in. Corollaries for why can be drawn from everything from pharmaceuticals to reactor operations. Having operated reactors for more than half a dozen years , this author can attest that a monkey can do the job. Except for when things go wrong and they do. Amazingly, things go wrong during investigations, too. And if that's not enough, you'll be questioned about and expected to explain file carving, deleted files, file slack , unallocated space, sectors, clusters, etc. As you use and understand these tools, these definitions will become second nature.

Note 

New Technologies Incorporated (NTI) is one of many online resources for learning about these terms and other forensic concepts. Their web site is located at http://www.forensics-intl.com/define.html. A Google search will yield several results, but be careful what you read. Stick to information from trade web sites, respectable vendor web sites, and web sites of respected individuals in the field. Collaborate everything you read with another resource.

An investigator could come to an incorrect conclusion without the means to view suspicious files properly. For example, imagine an analyst who depends on an image viewer to provide the proper results for a file named image.tiff. If the file image.tiff is actually an MP3 music file, it won't be displayed correctly in an image viewer or rendered correctly inside of Windows Explorer. Therefore, a more powerful viewer must be utilized. Lucky for the analyst, such viewers are available.

This chapter is dedicated to the editors and viewers used during a typical forensic analysis. These viewers are defined as generic in the sense that they support many different file types. Some of the viewers presented will even support an unlimited number of file formats. Moreover, even though "editing" is not typically performed during an investigation, this chapter will illustrate that editors, too, can add powerful features to the analyst's tool kit.



Anti-Hacker Tool Kit
Anti-Hacker Tool Kit, Third Edition
ISBN: 0072262877
EAN: 2147483647
Year: 2006
Pages: 175

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net