<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://www.forensicswiki.org/w/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://www.forensicswiki.org/w/api.php?action=feedcontributions&amp;user=KPryor&amp;feedformat=atom</id>
		<title>Forensics Wiki - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="http://www.forensicswiki.org/w/api.php?action=feedcontributions&amp;user=KPryor&amp;feedformat=atom"/>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Special:Contributions/KPryor"/>
		<updated>2013-05-21T12:47:24Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.20.3</generator>

	<entry>
		<id>http://www.forensicswiki.org/wiki/SAFE_Boot_Disk</id>
		<title>SAFE Boot Disk</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/SAFE_Boot_Disk"/>
				<updated>2010-01-29T07:56:36Z</updated>
		
		<summary type="html">&lt;p&gt;KPryor: Fixed broken link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Infobox_Software |&lt;br /&gt;
  name = SAFE Boot Disk |&lt;br /&gt;
  maintainer = [[ForensicSoft]] |&lt;br /&gt;
  os = {{Windows}} |&lt;br /&gt;
  genre = {{Live CD}} |&lt;br /&gt;
  license = {{Commercial}} |&lt;br /&gt;
  website = [http://www.forensicsoft.com/catalog/products.php http://www.forensicsoft.com/catalog/products.php] |&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
The '''System Acquisition Forensic Environment (SAFE) Boot Disk''' is the first and only commercially available forensically sound Windows Boot disk by [[ForensicSoft]]. SAFE is a fully licensed version of Windows PE protected that is protected by the proven [[SAFE Block XP]] software write blocking technology.&lt;br /&gt;
&lt;br /&gt;
'''SAFE Boot Disk''' now allows you to boot any x86-based computer without the need to remove the drives or worry about the need for special adapters or controller cards. Because '''SAFE Boot Disk''' is based on Windows PE it includes built in driver support as well as the ability to easily install any drivers that may be missing. This also means the '''Safe Boot Disk''' includes built in support for the NTFS file system without the need for third party tools and has the ability to write to NTFS and NTFS compressed file systems, taking advantage of larger partition sizes, larger file size limits and the advantage of native NTFS compression.&lt;br /&gt;
&lt;br /&gt;
In order to ensure the '''SAFE Boot Disk''' is a forensically sound Live CD it has the proven write blocking technology used by [[SAFE Block XP]] built in to ensure that upon booting every attached disk and flash device are automatically blocked without any required user interaction. Unlike some of the Linux Live CD's this is true write blocking and not just mounting read-only or not auto-mounting. &lt;br /&gt;
&lt;br /&gt;
Finally '''SAFE Boot Disk''' provides access to Host Protected Areas (HPAs) and Device Configuration Overlay (DCOs) on IDE (PATA and SATA) disks, has built in Case Logging and built in tools for exploration, viewing, and simple forensics functions.&lt;/div&gt;</summary>
		<author><name>KPryor</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/ILook</id>
		<title>ILook</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/ILook"/>
				<updated>2008-08-15T03:48:19Z</updated>
		
		<summary type="html">&lt;p&gt;KPryor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Leonly}}&lt;br /&gt;
{{Infobox_Software |&lt;br /&gt;
  name = ILook |&lt;br /&gt;
  maintainer = [[Internal Revenue Service|IRS-CI]] |&lt;br /&gt;
  os = {{Windows}} |&lt;br /&gt;
  genre = {{Analysis}} |&lt;br /&gt;
  license = [http://www.ilook-forensics.org/iLookv8eula.html EULA] |&lt;br /&gt;
  website = [http://www.ilook-forensics.org/ ilook-forensics.org] |&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
'''ILook''' is an all-in-one [[computer forensics]] suite originally created by Elliot Spencer and currently maintained by the U.S. Department of Treasury [[Internal Revenue Service]] Criminal Investigation Division (IRS-CI) Electronic Crimes Program. It was made available at no cost to law enforcement agencies and US government agencies at the discretion of the IRS-CI, but is not available to the general public.&lt;br /&gt;
&lt;br /&gt;
Elliot Spencer publicly announced on May 9, 2008, via the ILook users Yahoo! group, the end of ILook.  Due to the end of federal funding for continued development, the currently released ILook 8.0.18 is the final version.  Spencers company, Perlustro, is developing a new commercial version of ILook, but no further updates of the free version will be forthcoming.  Currently licensed users will still be able to renew their licenses for the foreseeable future, but no new ILook licenses will be issued.&lt;br /&gt;
&lt;br /&gt;
The ILook Investigator © Forensic Software is a comprehensive suite of computer forensics tools used to acquire and analyze digital media.  ILook Investigator © products include the ILook v8 forensic application and the [[IXimager]] which are both designed to follow forensics best practices.  &lt;br /&gt;
&lt;br /&gt;
ILook can support a wide variety of file systems, including [[FAT]] 12/16/32, [[NTFS]], [[NTFS Compressed]], [[HFS]], [[HFS+]], [[Ext2]], [[Ext3]], [[ReiserFS]] 1, 2, and 3, [[SysV-AFS]], [[SysV-EAFS]], [[SysV-HTFS]], [[NWFS]], [[NWFS Compressed]], [[VMWare Drive Mount Disk Drives]], [[Microsoft]] [[Virtual PC]] disks. It can also process CDs in [[CDFS]], [[ISO 9660]], [[ISO 9660]], and [[UDF]].&lt;br /&gt;
&lt;br /&gt;
==Search Facilities==&lt;br /&gt;
* Lists allocated and unallocated files.&lt;br /&gt;
* Sorts files by type (signature and extension).&lt;br /&gt;
* Searches for keywords.&lt;br /&gt;
* Works with compressed zip files.&lt;br /&gt;
&lt;br /&gt;
==Searching Abilities==&lt;br /&gt;
* Searches for keywords.&lt;br /&gt;
* Builds an index.&lt;br /&gt;
&lt;br /&gt;
==Hash Databases==&lt;br /&gt;
&lt;br /&gt;
Hashes and compares using custom hash sets as well as the [[Hashkeeper]] [[hash database]] and [[National Software Reference Library|NIST]] [[hash library]] using [[MD5]] and [[FIPS 180-2]] compliant algorithms (e.g. [[SHA-1]]). &lt;br /&gt;
&lt;br /&gt;
== External links ==&lt;br /&gt;
* [http://www.ilook-forensics.org/ Official website]&lt;br /&gt;
* [http://www.ilook-forensics.org/iLookv8eula.html EULA]&lt;br /&gt;
&lt;br /&gt;
[[Category:Disk imaging]]&lt;/div&gt;</summary>
		<author><name>KPryor</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/ILook</id>
		<title>ILook</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/ILook"/>
				<updated>2008-08-15T03:46:59Z</updated>
		
		<summary type="html">&lt;p&gt;KPryor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Leonly}}&lt;br /&gt;
{{Infobox_Software |&lt;br /&gt;
  name = ILook |&lt;br /&gt;
  maintainer = [[Internal Revenue Service|IRS-CI]] |&lt;br /&gt;
  os = {{Windows}} |&lt;br /&gt;
  genre = {{Analysis}} |&lt;br /&gt;
  license = [http://www.ilook-forensics.org/iLookv8eula.html EULA] |&lt;br /&gt;
  website = [http://www.ilook-forensics.org/ ilook-forensics.org] |&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
'''ILook''' is an all-in-one [[computer forensics]] suite originally created by Elliot Spencer and currently maintained by the U.S. Department of Treasury [[Internal Revenue Service]] Criminal Investigation Division (IRS-CI) Electronic Crimes Program. It was made available at no cost to law enforcement agencies and US government agencies at the discretion of the IRS-CI, but is not available to the general public.&lt;br /&gt;
&lt;br /&gt;
Elliot Spencer publicly announced on May 9, 2008, via the ILook users Yahoo! group, the end of ILook.  Due to the end of federal funding for continued development, the currently released ILook 8.0.18 is the final version.  Spencers company, Perlustro, is developing a new commercial version of ILook, but no new updates or versions of the free version will be forthcoming.  Currently licensed users will still be able to renew their licenses for the foreseeable future, but no new ILook licenses will be issued.&lt;br /&gt;
&lt;br /&gt;
The ILook Investigator © Forensic Software is a comprehensive suite of computer forensics tools used to acquire and analyze digital media.  ILook Investigator © products include the ILook v8 forensic application and the [[IXimager]] which are both designed to follow forensics best practices.  &lt;br /&gt;
&lt;br /&gt;
ILook can support a wide variety of file systems, including [[FAT]] 12/16/32, [[NTFS]], [[NTFS Compressed]], [[HFS]], [[HFS+]], [[Ext2]], [[Ext3]], [[ReiserFS]] 1, 2, and 3, [[SysV-AFS]], [[SysV-EAFS]], [[SysV-HTFS]], [[NWFS]], [[NWFS Compressed]], [[VMWare Drive Mount Disk Drives]], [[Microsoft]] [[Virtual PC]] disks. It can also process CDs in [[CDFS]], [[ISO 9660]], [[ISO 9660]], and [[UDF]].&lt;br /&gt;
&lt;br /&gt;
==Search Facilities==&lt;br /&gt;
* Lists allocated and unallocated files.&lt;br /&gt;
* Sorts files by type (signature and extension).&lt;br /&gt;
* Searches for keywords.&lt;br /&gt;
* Works with compressed zip files.&lt;br /&gt;
&lt;br /&gt;
==Searching Abilities==&lt;br /&gt;
* Searches for keywords.&lt;br /&gt;
* Builds an index.&lt;br /&gt;
&lt;br /&gt;
==Hash Databases==&lt;br /&gt;
&lt;br /&gt;
Hashes and compares using custom hash sets as well as the [[Hashkeeper]] [[hash database]] and [[National Software Reference Library|NIST]] [[hash library]] using [[MD5]] and [[FIPS 180-2]] compliant algorithms (e.g. [[SHA-1]]). &lt;br /&gt;
&lt;br /&gt;
== External links ==&lt;br /&gt;
* [http://www.ilook-forensics.org/ Official website]&lt;br /&gt;
* [http://www.ilook-forensics.org/iLookv8eula.html EULA]&lt;br /&gt;
&lt;br /&gt;
[[Category:Disk imaging]]&lt;/div&gt;</summary>
		<author><name>KPryor</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Scalpel</id>
		<title>Talk:Scalpel</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Scalpel"/>
				<updated>2008-08-07T14:56:47Z</updated>
		
		<summary type="html">&lt;p&gt;KPryor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Has anyone used this tool yet?&lt;br /&gt;
I have downloaded it and will install it in the near future.&lt;br /&gt;
Thanks,&lt;br /&gt;
&lt;br /&gt;
Redloco&lt;br /&gt;
&lt;br /&gt;
: Yes, I've used it with great success. What would you like to know? [[User:Jessek|Jessek]] 10:40, 7 August 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
: I've used Foremost with success, but haven't tried Scalpel. [[User:KPryor|KPryor]] 14:55, 7 August 2008 (UTC)&lt;/div&gt;</summary>
		<author><name>KPryor</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Scalpel</id>
		<title>Talk:Scalpel</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Scalpel"/>
				<updated>2008-08-07T14:54:38Z</updated>
		
		<summary type="html">&lt;p&gt;KPryor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Has anyone used this tool yet?&lt;br /&gt;
I have downloaded it and will install it in the near future.&lt;br /&gt;
Thanks,&lt;br /&gt;
&lt;br /&gt;
Redloco&lt;br /&gt;
&lt;br /&gt;
: Yes, I've used it with great success. What would you like to know? [[User:Jessek|Jessek]] 10:40, 7 August 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
I've used Foremost with success, but haven't tried Scalpel.&lt;/div&gt;</summary>
		<author><name>KPryor</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:How_To_Set_Up_a_Disk_Imaging_Station</id>
		<title>Talk:How To Set Up a Disk Imaging Station</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:How_To_Set_Up_a_Disk_Imaging_Station"/>
				<updated>2008-05-28T04:13:35Z</updated>
		
		<summary type="html">&lt;p&gt;KPryor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;omg... IMHO, it seems to be &amp;quot;[newbie] howto install freebsd&amp;quot; ;)&lt;br /&gt;
[[User:.FUF|.FUF]] 20:51, 23 May 2008 (UTC)&lt;br /&gt;
:What's wrong with having a newbie HOWTO? Most forensics geeks are not FreeBSD users, so a HOWTO guide is helpful. [[User:Jessek|Jessek]] 17:18, 24 May 2008 (UTC)&lt;br /&gt;
::Honestly, what this wiki needs is more newbie HOWTOs.[[User:Simsong|Simsong]] 07:47, 25 May 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
Agreed.  I am a newbie, so I would be happy to see more how-to's.&lt;/div&gt;</summary>
		<author><name>KPryor</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:How_To_Set_Up_a_Disk_Imaging_Station</id>
		<title>Talk:How To Set Up a Disk Imaging Station</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:How_To_Set_Up_a_Disk_Imaging_Station"/>
				<updated>2008-05-28T04:12:11Z</updated>
		
		<summary type="html">&lt;p&gt;KPryor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;omg... IMHO, it seems to be &amp;quot;[newbie] howto install freebsd&amp;quot; ;)&lt;br /&gt;
[[User:.FUF|.FUF]] 20:51, 23 May 2008 (UTC)&lt;br /&gt;
:What's wrong with having a newbie HOWTO? Most forensics geeks are not FreeBSD users, so a HOWTO guide is helpful. [[User:Jessek|Jessek]] 17:18, 24 May 2008 (UTC)&lt;br /&gt;
::Honestly, what this wiki needs is more newbie HOWTOs.[[User:Simsong|Simsong]] 07:47, 25 May 2008 (UTC)&lt;/div&gt;</summary>
		<author><name>KPryor</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:How_To_Set_Up_a_Disk_Imaging_Station</id>
		<title>Talk:How To Set Up a Disk Imaging Station</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:How_To_Set_Up_a_Disk_Imaging_Station"/>
				<updated>2008-05-28T04:11:30Z</updated>
		
		<summary type="html">&lt;p&gt;KPryor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;omg... IMHO, it seems to be &amp;quot;[newbie] howto install freebsd&amp;quot; ;)&lt;br /&gt;
[[User:.FUF|.FUF]] 20:51, 23 May 2008 (UTC)&lt;br /&gt;
:What's wrong with having a newbie HOWTO? Most forensics geeks are not FreeBSD users, so a HOWTO guide is helpful. [[User:Jessek|Jessek]] 17:18, 24 May 2008 (UTC)&lt;br /&gt;
::Honestly, what this wiki needs is more newbie HOWTOs.[[User:Simsong|Simsong]] 07:47, 25 May 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
Agreed.  I am a newbie, so I would be happy to see more how-to's.&lt;/div&gt;</summary>
		<author><name>KPryor</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/ILook</id>
		<title>ILook</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/ILook"/>
				<updated>2008-05-28T04:06:32Z</updated>
		
		<summary type="html">&lt;p&gt;KPryor: Added info regarding the end of ILook development&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Leonly}}&lt;br /&gt;
{{Infobox_Software |&lt;br /&gt;
  name = ILook |&lt;br /&gt;
  maintainer = [[Internal Revenue Service|IRS-CI]] |&lt;br /&gt;
  os = {{Windows}} |&lt;br /&gt;
  genre = {{Analysis}} |&lt;br /&gt;
  license = [http://www.ilook-forensics.org/iLookv8eula.html EULA] |&lt;br /&gt;
  website = [http://www.ilook-forensics.org/ ilook-forensics.org] |&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
'''ILook''' is an all-in-one [[computer forensics]] suite originally created by Elliot Spencer and currently maintained by the U.S. Department of Treasury [[Internal Revenue Service]] Criminal Investigation Division (IRS-CI) Electronic Crimes Program. It was made available at no cost to law enforcement agencies and US government agencies at the discretion of the IRS-CI, but is not available to the general public.&lt;br /&gt;
&lt;br /&gt;
Elliot Spencer publicly announced on May 9, 2008, via the ILook users Yahoo! group, the end of ILook.  Due to the end of federal funding for continued development, the currently released ILook 8.0.18 is the final version.  Spencers company, Perlustro, is developing new forensic tools for commercial release, but no new updates or versions of ILook will be forthcoming.  Currently licensed users will still be able to renew their licenses for the foreseeable future, but no new ILook licenses will be issued.&lt;br /&gt;
&lt;br /&gt;
The ILook Investigator © Forensic Software is a comprehensive suite of computer forensics tools used to acquire and analyze digital media.  ILook Investigator © products include the ILook v8 forensic application and the [[IXimager]] which are both designed to follow forensics best practices.  &lt;br /&gt;
&lt;br /&gt;
ILook can support a wide variety of file systems, including [[FAT]] 12/16/32, [[NTFS]], [[NTFS Compressed]], [[HFS]], [[HFS+]], [[Ext2]], [[Ext3]], [[ReiserFS]] 1, 2, and 3, [[SysV-AFS]], [[SysV-EAFS]], [[SysV-HTFS]], [[NWFS]], [[NWFS Compressed]], [[VMWare Drive Mount Disk Drives]], [[Microsoft]] [[Virtual PC]] disks. It can also process CDs in [[CDFS]], [[ISO 9660], [[ISO 9660]], and [[UDF]].&lt;br /&gt;
&lt;br /&gt;
==Search Facilities==&lt;br /&gt;
* Lists allocated and unallocated files.&lt;br /&gt;
* Sorts files by type (signature and extension).&lt;br /&gt;
* Searches for keywords.&lt;br /&gt;
* Works with compressed zip files.&lt;br /&gt;
&lt;br /&gt;
==Searching Abilities==&lt;br /&gt;
* Searches for keywords.&lt;br /&gt;
* Builds an index.&lt;br /&gt;
&lt;br /&gt;
==Hash Databases==&lt;br /&gt;
&lt;br /&gt;
Hashes and compares using custom hash sets as well as the [[Hashkeeper]] [[hash database]] and [[National Software Reference Library|NIST]] [[hash library]] using [[MD5]] and [[FIPS 180-2]] compliant algorithms (e.g. [[SHA-1]]). &lt;br /&gt;
&lt;br /&gt;
== External links ==&lt;br /&gt;
* [http://www.ilook-forensics.org/ Official website]&lt;br /&gt;
* [http://www.ilook-forensics.org/iLookv8eula.html EULA]&lt;br /&gt;
&lt;br /&gt;
[[Category:Disk imaging]]&lt;/div&gt;</summary>
		<author><name>KPryor</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:KPryor</id>
		<title>User:KPryor</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:KPryor"/>
				<updated>2007-08-23T17:55:10Z</updated>
		
		<summary type="html">&lt;p&gt;KPryor: New page: I hereby license all my contributions to this wiki (before and after March 19th, 2006) under the Creative Commons Attribution-ShareAlike 2.5 license.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;I hereby license all my contributions to this wiki (before and after March 19th, 2006) under the Creative Commons Attribution-ShareAlike 2.5 license.&lt;/div&gt;</summary>
		<author><name>KPryor</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Md5sum</id>
		<title>Md5sum</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Md5sum"/>
				<updated>2007-08-23T17:21:37Z</updated>
		
		<summary type="html">&lt;p&gt;KPryor: Fixed typo&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Infobox_Software |&lt;br /&gt;
  name = md5sum |&lt;br /&gt;
  maintainer = [[GNU]] |&lt;br /&gt;
  os = [[Linux]], [[Windows]], [[Mac OS X]], [[BSD]], [[Solaris]] |&lt;br /&gt;
  genre = {{Hashing}} |&lt;br /&gt;
  license = {{GPL}} |&lt;br /&gt;
  website = [http://www.gnu.org/software/coreutils/ www.gnu.org] |&lt;br /&gt;
}}&lt;br /&gt;
This [[MD5]] [[hashing]] tool, part of the GNU Coreutils suite, has been a standard in the computer forensics community for some time. It is intended for *nix systems, but has been ported to the [[Windows]] platform. It should be noted that the program has options to read files in &amp;quot;binary&amp;quot; or &amp;quot;text&amp;quot; mode, which can produce different hashes. The text mode is the default on most platforms, which is different from other hashing utilities such as [[md5deep]]. &lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.gnu.org/software/coreutils/ Official web site] for GNU Coreutils&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Md5sum Wikipedia entry on md5sum]&lt;br /&gt;
* [http://www.etree.org/md5com.html md5sum for Windows]&lt;br /&gt;
* [http://unxutils.sourceforge.net/ A slew of ported tools for Windows include md5sum]&lt;/div&gt;</summary>
		<author><name>KPryor</name></author>	</entry>

	</feed>