<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://www.forensicswiki.org/w/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://www.forensicswiki.org/w/api.php?action=feedcontributions&amp;user=Mkucenski&amp;feedformat=atom</id>
		<title>Forensics Wiki - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="http://www.forensicswiki.org/w/api.php?action=feedcontributions&amp;user=Mkucenski&amp;feedformat=atom"/>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Special:Contributions/Mkucenski"/>
		<updated>2013-05-20T16:06:19Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.20.3</generator>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Affuse</id>
		<title>Talk:Affuse</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Affuse"/>
				<updated>2007-05-31T20:01:46Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Simson, &lt;br /&gt;
This is a very cool idea and use of Fuse.  Looking forward to using the feature.&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Affuse</id>
		<title>Talk:Affuse</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Affuse"/>
				<updated>2007-05-31T20:00:47Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: New page: Simson this is a very cool idea and use of Fuse.  Looking forward to using the feature.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Simson this is a very cool idea and use of Fuse.  Looking forward to using the feature.&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/LNK</id>
		<title>LNK</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/LNK"/>
				<updated>2006-09-28T15:47:23Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Microsoft Windows Shortcut Files&lt;br /&gt;
&lt;br /&gt;
== File Format ==&lt;br /&gt;
&lt;br /&gt;
* TODO&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
* Three date/time stamps that relate to the last time the target was accessed by the given shortcut file.  (More testing needs to be done to determine exactly how these date/time stamps relate to the target.)&lt;br /&gt;
* The size of the target when it was last accessed.&lt;br /&gt;
* Serial number of the local volume where the target was stored.&lt;br /&gt;
* Network volume share name&lt;br /&gt;
* Read-only, hidden, system, volume label, encryption, sparse, compressed, offline and several other target attributes.&lt;br /&gt;
* TODO&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://mitec.cz/wfa.htm Free tool that is capable of reading and reporting on Windows shortcut files]&lt;br /&gt;
* [http://www.i2s-lab.com/Papers/The_Windows_Shortcut_File_Format.pdf Details of the Windows shortcut file format]&lt;br /&gt;
&lt;br /&gt;
[[Category:File Formats]]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/LNK</id>
		<title>LNK</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/LNK"/>
				<updated>2006-09-27T22:17:24Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Microsoft Windows Shortcut Files&lt;br /&gt;
&lt;br /&gt;
== File Format ==&lt;br /&gt;
&lt;br /&gt;
* TODO&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
* Three date/time stamps that relate to the last time the target was accessed by the given shortcut file.  (More testing needs to be done to determine exactly how these date/time stamps relate to the target.)&lt;br /&gt;
* The size of the target when it was last accessed.&lt;br /&gt;
* Serial number of the local volume where the target was stored.&lt;br /&gt;
* Network volume share name&lt;br /&gt;
* Read-only, hidden, system, volume label, encryption, sparse, compressed, offline and several other target attributes.&lt;br /&gt;
* TODO&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://mitec.cz/wfa.htm Free tool that is capable of reading on reporting on Windows shortcut files]&lt;br /&gt;
* [http://www.i2s-lab.com/Papers/The_Windows_Shortcut_File_Format.pdf Details of the Windows shortcut file format]&lt;br /&gt;
&lt;br /&gt;
[[Category:File Formats]]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/LNK</id>
		<title>LNK</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/LNK"/>
				<updated>2006-09-27T22:16:10Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Wikify}}&lt;br /&gt;
&lt;br /&gt;
Microsoft Windows Shortcut Files&lt;br /&gt;
&lt;br /&gt;
== File Format ==&lt;br /&gt;
&lt;br /&gt;
* TODO&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
* Three date/time stamps that relate to the last time the target was accessed by the given shortcut file.  (More testing needs to be done to determine exactly how these date/time stamps relate to the target.)&lt;br /&gt;
* The size of the target when it was last accessed.&lt;br /&gt;
* Serial number of the local volume where the target was stored.&lt;br /&gt;
* Network volume share name&lt;br /&gt;
* Read-only, hidden, system, volume label, encryption, sparse, compressed, offline and several other target attributes.&lt;br /&gt;
* TODO&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://mitec.cz/wfa.htm Free tool that is capable of reading on reporting on Windows shortcut files]&lt;br /&gt;
* [http://www.i2s-lab.com/Papers/The_Windows_Shortcut_File_Format.pdf Details of the Windows shortcut file format]&lt;br /&gt;
&lt;br /&gt;
[[Category:File Formats]]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/LNK</id>
		<title>LNK</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/LNK"/>
				<updated>2006-09-27T22:15:13Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Wikify}}&lt;br /&gt;
&lt;br /&gt;
MS Windows Shortcut Files&lt;br /&gt;
&lt;br /&gt;
== File Format ==&lt;br /&gt;
&lt;br /&gt;
* TODO&lt;br /&gt;
&lt;br /&gt;
== Metadata ==&lt;br /&gt;
&lt;br /&gt;
* Three date/time stamps that relate to the last time the target was accessed by the given shortcut file.  (More testing needs to be done to determine exactly how these date/time stamps relate to the target.)&lt;br /&gt;
* The size of the target when it was last accessed.&lt;br /&gt;
* Serial number of the local volume where the target was stored.&lt;br /&gt;
* Network volume share name&lt;br /&gt;
* Read-only, hidden, system, volume label, encryption, sparse, compressed, offline and several other target attributes.&lt;br /&gt;
* TODO&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://mitec.cz/wfa.htm Free tool that is capable of reading on reporting on Windows shortcut files]&lt;br /&gt;
* [http://www.i2s-lab.com/Papers/The_Windows_Shortcut_File_Format.pdf Details of the Windows shortcut file format]&lt;br /&gt;
&lt;br /&gt;
[[Category:File Formats]]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/LNK</id>
		<title>LNK</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/LNK"/>
				<updated>2006-09-27T22:13:32Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Wikify}}&lt;br /&gt;
&lt;br /&gt;
MS Windows Shortcut Files&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In addition the target file, Windows shortcut files contain several interesting pieces of information that include:&lt;br /&gt;
&lt;br /&gt;
* Three date/time stamps that relate to the last time the target was accessed by the given shortcut file.  (More testing needs to be done to determine exactly how these date/time stamps relate to the target.)&lt;br /&gt;
* The size of the target when it was last accessed.&lt;br /&gt;
* Serial number of the local volume where the target was stored.&lt;br /&gt;
* Network volume share name&lt;br /&gt;
* Read-only, hidden, system, volume label, encryption, sparse, compressed, offline and several other target attributes.&lt;br /&gt;
&lt;br /&gt;
== File Format ==&lt;br /&gt;
&lt;br /&gt;
* TODO&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://mitec.cz/wfa.htm Free tool that is capable of reading on reporting on Windows shortcut files]&lt;br /&gt;
* [http://www.i2s-lab.com/Papers/The_Windows_Shortcut_File_Format.pdf Details of the Windows shortcut file format]&lt;br /&gt;
&lt;br /&gt;
[[Category:File Formats]]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/LNK</id>
		<title>LNK</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/LNK"/>
				<updated>2006-09-27T22:12:38Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Wikify}}&lt;br /&gt;
&lt;br /&gt;
MS Windows Shortcut Files&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In addition the target file, Windows shortcut files contain several interesting pieces of information that include:&lt;br /&gt;
&lt;br /&gt;
* Three date/time stamps that relate to the last time the target was accessed by the given shortcut file.  (More testing needs to be done to determine exactly how these date/time stamps relate to the target.)&lt;br /&gt;
* The size of the target when it was last accessed.&lt;br /&gt;
* Serial number of the local volume where the target was stored.&lt;br /&gt;
* Network volume share name&lt;br /&gt;
* Read-only, hidden, system, volume label, encryption, sparse, compressed, offline and several other target attributes.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://mitec.cz/wfa.htm Free tool that is capable of reading on reporting on Windows shortcut files]&lt;br /&gt;
* [http://www.i2s-lab.com/Papers/The_Windows_Shortcut_File_Format.pdf Details of the Windows shortcut file format]&lt;br /&gt;
&lt;br /&gt;
[[Category:File Formats]]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/LNK</id>
		<title>LNK</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/LNK"/>
				<updated>2006-09-27T22:12:12Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Wikify}}&lt;br /&gt;
&lt;br /&gt;
MS Windows Shortcut Files&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In addition the target file, Windows shortcut files contain several interesting pieces of information that include:&lt;br /&gt;
&lt;br /&gt;
* Three date/time stamps that relate to the last time the target was accessed by the given shortcut file.  (More testing needs to be done to determine exactly how these date/time stamps relate to the target.)&lt;br /&gt;
* The size of the target when it was last accessed.&lt;br /&gt;
* Serial number of the local volume where the target was stored.&lt;br /&gt;
* Network volume share name&lt;br /&gt;
* Read-only, hidden, system, volume label, encryption, sparse, compressed, offline and several other target attributes.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://mitec.cz/wfa.htm Free tool that is capable of reading on reporting on Windows shortcut files]&lt;br /&gt;
* [http://www.i2s-lab.com/Papers/The_Windows_Shortcut_File_Format.pdf Details of Windows shortcut file format]&lt;br /&gt;
&lt;br /&gt;
[[Category:File Formats]]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/LNK</id>
		<title>LNK</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/LNK"/>
				<updated>2006-09-27T22:11:47Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Wikify}}&lt;br /&gt;
&lt;br /&gt;
MS Windows Shortcut Files&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In addition the target file, Windows shortcut files contain several interesting pieces of information that include:&lt;br /&gt;
&lt;br /&gt;
* Three date/time stamps that relate to the last time the target was accessed by the given shortcut file.  (More testing needs to be done to determine exactly how these date/time stamps relate to the target.)&lt;br /&gt;
* The size of the target when it was last accessed.&lt;br /&gt;
* Serial number of the local volume where the target was stored.&lt;br /&gt;
* Network volume share name&lt;br /&gt;
* Read-only, hidden, system, volume label, encryption, sparse, compressed, offline and several other target attributes.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://mitec.cz/wfa.htm Free tool that is capable of reading on reporting on Windows shortcut files]&lt;br /&gt;
Specific can be found here:&lt;br /&gt;
* [http://www.i2s-lab.com/Papers/The_Windows_Shortcut_File_Format.pdf Details of Windows shortcut file format]&lt;br /&gt;
&lt;br /&gt;
[[Category:File Formats]]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/LNK</id>
		<title>LNK</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/LNK"/>
				<updated>2006-09-27T22:10:19Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Wikify}}&lt;br /&gt;
&lt;br /&gt;
MS Windows Shortcut Files&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In addition the target file, Windows shortcut files contain several interesting pieces of information that include:&lt;br /&gt;
&lt;br /&gt;
* Three date/time stamps that relate to the last time the target was accessed by the given shortcut file.  (More testing needs to be done to determine exactly how these date/time stamps relate to the target.)&lt;br /&gt;
* The size of the target when it was last accessed.&lt;br /&gt;
* Serial number of the local volume where the target was stored.&lt;br /&gt;
* Network volume share name&lt;br /&gt;
* Read-only, hidden, system, volume label, encryption, sparse, compressed, offline and several other target attributes.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
* [http://mitec.cz/wfa.htm Free tool that is capable of reading on reporting on Windows shortcut files]&lt;br /&gt;
Specific details of .lnk shortcut files can be found here:&lt;br /&gt;
[http://www.i2s-lab.com/Papers/The_Windows_Shortcut_File_Format.pdf Windows Shortcut File Format]&lt;br /&gt;
&lt;br /&gt;
[[Category:File Formats]]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/LNK</id>
		<title>LNK</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/LNK"/>
				<updated>2006-09-27T22:08:33Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Wikify}}&lt;br /&gt;
&lt;br /&gt;
MS Windows Shortcut Files&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In addition the target file, Windows shortcut files contain several interesting pieces of information that include:&lt;br /&gt;
&lt;br /&gt;
* Three date/time stamps that relate to the last time the target was accessed by the given shortcut file.  (More testing needs to be done to determine exactly how these date/time stamps relate to the target.)&lt;br /&gt;
* The size of the target when it was last accessed.&lt;br /&gt;
* Serial number of the local volume where the target was stored.&lt;br /&gt;
* Network volume share name&lt;br /&gt;
* Read-only, hidden, system, volume label, encryption, sparse, compressed, offline and several other target attributes.&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
Specific details of .lnk shortcut files can be found here:&lt;br /&gt;
[http://www.i2s-lab.com/Papers/The_Windows_Shortcut_File_Format.pdf Windows Shortcut File Format]&lt;br /&gt;
&lt;br /&gt;
[[Category:File Formats]]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Windows_Registry</id>
		<title>Windows Registry</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Windows_Registry"/>
				<updated>2006-04-21T14:25:47Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* [http://www.answers.com/topic/win-registry Windows Registry Information]&lt;br /&gt;
* [http://groups.yahoo.com/group/urfg/ Yahoo Group on using the Windows Registry in Forensics]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Windows_Registry</id>
		<title>Windows Registry</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Windows_Registry"/>
				<updated>2006-04-21T14:25:25Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* [http://www.answers.com/topic/win-registry Windows Registry Information]&lt;br /&gt;
* [http://groups.yahoo.com/group/urfg/ Yahoo Groups on using the Windows Registry in Forensics]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Windows_Registry</id>
		<title>Windows Registry</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Windows_Registry"/>
				<updated>2006-04-21T14:25:08Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: Documenting a couple of good links on this subject until someone has time to write a more detailed entry.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.answers.com/topic/win-registry Windows Registry Information]&lt;br /&gt;
[http://groups.yahoo.com/group/urfg/ Yahoo Groups on using the Windows Registry in Forensics]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Windows</id>
		<title>Windows</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Windows"/>
				<updated>2006-04-21T14:23:11Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: Changed registry link to clarify that it is the *Windows* registry we are talking about.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Windows''' is a widely-spread [[operating system]] from [[Microsoft]].&lt;br /&gt;
&lt;br /&gt;
== Forensics ==&lt;br /&gt;
&lt;br /&gt;
=== Filesystems ===&lt;br /&gt;
&lt;br /&gt;
[[FAT]], [[NTFS]], ...&lt;br /&gt;
&lt;br /&gt;
=== Registry ===&lt;br /&gt;
&lt;br /&gt;
The [[Windows Registry]] of a system is a database of keys and values that provides a wealth of information to forensic [[investigator]]s.&lt;br /&gt;
&lt;br /&gt;
=== Thumbs.db Files ===&lt;br /&gt;
&lt;br /&gt;
[[Thumbs.db]] files can be found on many Windows systems. They contain thumbnails of images or documents and can be of great value for the [[investigator]].&lt;br /&gt;
&lt;br /&gt;
=== Browser Cache ===&lt;br /&gt;
&lt;br /&gt;
=== Browser History ===&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Microsoft_Windows Wikipedia: Microsoft Windows]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Locard%27s_exchange_principle</id>
		<title>Locard's exchange principle</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Locard%27s_exchange_principle"/>
				<updated>2006-03-30T19:28:21Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://en.wikipedia.org/wiki/Locard's_exchange_principle Locard's exchange principle]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Mkucenski</id>
		<title>User:Mkucenski</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Mkucenski"/>
				<updated>2006-03-24T15:01:59Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== About ==&lt;br /&gt;
Name: Matt Kucenski&lt;br /&gt;
&lt;br /&gt;
Email: mkucenski_at_mac.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== License ==&lt;br /&gt;
I hereby license all my contributions to this wiki (before and after March 19th, 2006) under the [http://creativecommons.org/licenses/by-sa/2.5/ Creative Commons Attribution-ShareAlike 2.5] license.&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Mkucenski</id>
		<title>User:Mkucenski</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Mkucenski"/>
				<updated>2006-03-24T15:01:07Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== About ==&lt;br /&gt;
Matt Kucenski&lt;br /&gt;
&lt;br /&gt;
mkucenski_at_mac.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== License ==&lt;br /&gt;
I hereby license all my contributions to this wiki (before and after March 19th, 2006) under the [http://creativecommons.org/licenses/by-sa/2.5/ Creative Commons Attribution-ShareAlike 2.5] license.&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Mkucenski</id>
		<title>User:Mkucenski</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Mkucenski"/>
				<updated>2006-03-24T15:00:16Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Matt Kucenski&lt;br /&gt;
&lt;br /&gt;
mkucenski_at_mac.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
I hereby license all my contributions to this wiki (before and after March 19th, 2006) under the [http://creativecommons.org/licenses/by-sa/2.5/ Creative Commons Attribution-ShareAlike 2.5] license.&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Mkucenski</id>
		<title>User:Mkucenski</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Mkucenski"/>
				<updated>2006-03-24T15:00:02Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Matt Kucenski&lt;br /&gt;
&lt;br /&gt;
mkucenski_at_mac.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 I hereby license all my contributions to this wiki (before and after March 19th, 2006) under the [http://creativecommons.org/licenses/by-sa/2.5/ Creative Commons Attribution-ShareAlike 2.5] license.&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Mkucenski</id>
		<title>User:Mkucenski</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Mkucenski"/>
				<updated>2006-03-24T14:58:56Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Matt Kucenski&lt;br /&gt;
&lt;br /&gt;
mkucenski_at_mac.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
I hereby license all my contributions to this wiki (before and after March 19th, 2006) under the [http://creativecommons.org/licenses/by-sa/2.5/ Creative Commons Attribution-ShareAlike 2.5] license.&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Mkucenski</id>
		<title>User:Mkucenski</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Mkucenski"/>
				<updated>2006-03-24T14:58:45Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Matt Kucenski&lt;br /&gt;
&lt;br /&gt;
mkucenski_at_mac.com&lt;br /&gt;
&lt;br /&gt;
I hereby license all my contributions to this wiki (before and after March 19th, 2006) under the [http://creativecommons.org/licenses/by-sa/2.5/ Creative Commons Attribution-ShareAlike 2.5] license.&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Windows_Event_Log_(EVT)</id>
		<title>Talk:Windows Event Log (EVT)</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Windows_Event_Log_(EVT)"/>
				<updated>2006-03-15T20:31:45Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;ASchuster:  Can you provide the source of your information on the header, cursor, retention, etc?  If MSDN has this information, a link to it should be included in this page.&lt;br /&gt;
&lt;br /&gt;
This information was obtained through extensive testing. As fas as I know the only information available on MSDN is the declaration of the event record. --ASchuster&lt;br /&gt;
&lt;br /&gt;
Well then thank you for your efforts.  I've just been ignoring the header/cursor as an invalid EVENTLOGRECORD and reading all of the rest of the records out. --MKucenski&lt;br /&gt;
&lt;br /&gt;
Does your tool parse a split event record properly? Think of a record in a wrapped log file that starts at the (physical) end and continues near the top (right after the header). There might be even some padding in between of the two fragments. --ASchuster&lt;br /&gt;
&lt;br /&gt;
The tool I am currently using is fairly primitive.  I am basically searching the file for 'LfLe', reading the record out, then searching for the next 'LfLe'.  Is it even possible to split a record?  I have not seen that situation, but also have not been looking for it.  It seems like this would cause havoc, especially for things like the data and string offsets within the record that are relative to the start of the record. --[[User:Mkucenski|Mkucenski]] 15:31, 15 March 2006 (EST)&lt;br /&gt;
&lt;br /&gt;
== WikiMarkup for tables? ==&lt;br /&gt;
&lt;br /&gt;
Is it possible to typeset tables in MediaWiki? I'm only used to DokuWiki and didn't find any information in the help. --ASchuster&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Windows_Event_Log_(EVT)</id>
		<title>Talk:Windows Event Log (EVT)</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Windows_Event_Log_(EVT)"/>
				<updated>2006-03-15T20:31:16Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;ASchuster:  Can you provide the source of your information on the header, cursor, retention, etc?  If MSDN has this information, a link to it should be included in this page.&lt;br /&gt;
&lt;br /&gt;
This information was obtained through extensive testing. As fas as I know the only information available on MSDN is the declaration of the event record. --ASchuster&lt;br /&gt;
&lt;br /&gt;
Well then thank you for your efforts.  I've just been ignoring the header/cursor as an invalid EVENTLOGRECORD and reading all of the rest of the records out. --MKucenski&lt;br /&gt;
&lt;br /&gt;
Does your tool parse a split event record properly? Think of a record in a wrapped log file that starts at the (physical) end and continues near the top (right after the header). There might be even some padding in between of the two fragments. --ASchuster&lt;br /&gt;
&lt;br /&gt;
The tool I am currently using is fairly primitive.  I am basically searching the file for 'LfLe', reading the record out, then searching for the next 'LfLe'.  Is it even possible to split a record?  I have not seen that situation, but also have not been looking for it.  It seems like this would cause havoc, especially for things like the data and string offsets within the record that are relative to the start of the record.&lt;br /&gt;
&lt;br /&gt;
== WikiMarkup for tables? ==&lt;br /&gt;
&lt;br /&gt;
Is it possible to typeset tables in MediaWiki? I'm only used to DokuWiki and didn't find any information in the help. --ASchuster&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Windows_Event_Log_(EVT)</id>
		<title>Talk:Windows Event Log (EVT)</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Windows_Event_Log_(EVT)"/>
				<updated>2006-03-15T18:52:55Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;ASchuster:  Can you provide the source of your information on the header, cursor, retention, etc?  If MSDN has this information, a link to it should be included in this page.&lt;br /&gt;
&lt;br /&gt;
This information was obtained through extensive testing. As fas as I know the only information available on MSDN is the declaration of the event record. --ASchuster&lt;br /&gt;
&lt;br /&gt;
Well then thank you for your efforts.  I've just been ignoring the header/cursor as an invalid EVENTLOGRECORD and reading all of the rest of the records out. --MKucenski&lt;br /&gt;
&lt;br /&gt;
== WikiMarkup for tables? ==&lt;br /&gt;
&lt;br /&gt;
Is it possible to typeset tables in MediaWiki? I'm only used to DokuWiki and didn't find any information in the help. --ASchuster&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Mkucenski</id>
		<title>User:Mkucenski</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Mkucenski"/>
				<updated>2006-03-15T16:34:07Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Matt Kucenski&lt;br /&gt;
&lt;br /&gt;
mkucenski_at_mac.com&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Mkucenski</id>
		<title>User:Mkucenski</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Mkucenski"/>
				<updated>2006-03-15T16:34:00Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Matt Kucenski&lt;br /&gt;
mkucenski_at_mac.com&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Windows_Event_Log_(EVT)</id>
		<title>Talk:Windows Event Log (EVT)</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Windows_Event_Log_(EVT)"/>
				<updated>2006-03-15T15:23:59Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;ASchuster:  Can you provide the source of your information on the header, cursor, retention, etc?  If MSDN has this information, a link to it should be included in this page.&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Windows_Event_Log_(EVT)</id>
		<title>Talk:Windows Event Log (EVT)</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Windows_Event_Log_(EVT)"/>
				<updated>2006-03-15T13:59:57Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;ASchuster:  Can you provide the source of your information on the header, cursor, retention, etc?  I'm not quite clear on how this information is laid out.  If MSDN has this information, a link to it should be included in this page.&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Windows_Event_Log_(EVT)</id>
		<title>Windows Event Log (EVT)</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Windows_Event_Log_(EVT)"/>
				<updated>2006-03-13T19:29:30Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;MS Windows Event Log Files&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Windows typically maintains three event log files: application, system, and security.  They are generally found in C:\Windows\system32\config.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Details of .evt file format can be found in Microsoft's MSDN library under [http://msdn.microsoft.com/library/default.asp?url=/library/en-us/eventlog/base/eventlogrecord_str.asp EVENTLOGRECORD].&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Windows_Event_Log_(EVT)</id>
		<title>Windows Event Log (EVT)</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Windows_Event_Log_(EVT)"/>
				<updated>2006-03-13T19:29:03Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;MS Windows Event Log Files&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Windows typically maintains three event log files: application, system, and security.  They are generally found in C:\Windows\system32\config.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Details of .evt file format can be found in Microsoft's MSDN library under 'EVENTLOGRECORD'&lt;br /&gt;
[http://msdn.microsoft.com/library/default.asp?url=/library/en-us/eventlog/base/eventlogrecord_str.asp EVENTLOGRECORD]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Windows_Event_Log_(EVT)</id>
		<title>Windows Event Log (EVT)</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Windows_Event_Log_(EVT)"/>
				<updated>2006-03-13T19:28:54Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;MS Windows Event Log Files&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Windows typically maintains three event log files: application, system, and security.  They are generally found in C:\Windows\system32\config.&lt;br /&gt;
&lt;br /&gt;
Details of .evt file format can be found in Microsoft's MSDN library under 'EVENTLOGRECORD'&lt;br /&gt;
[http://msdn.microsoft.com/library/default.asp?url=/library/en-us/eventlog/base/eventlogrecord_str.asp EVENTLOGRECORD]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/LNK</id>
		<title>LNK</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/LNK"/>
				<updated>2006-03-13T19:24:50Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;MS Windows Shortcut Files&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In addition the target file, Windows shortcut files contain several interesting pieces of information that include:&lt;br /&gt;
&lt;br /&gt;
* Three date/time stamps that relate to the last time the target was accessed by the given shortcut file.  (More testing needs to be done to determine exactly how these date/time stamps relate to the target.)&lt;br /&gt;
* The size of the target when it was last accessed.&lt;br /&gt;
* Serial number of the local volume where the target was stored.&lt;br /&gt;
* Network volume share name&lt;br /&gt;
* Read-only, hidden, system, volume label, encryption, sparse, compressed, offline and several other target attributes.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Specific details of .lnk shortcut files can be found here:&lt;br /&gt;
[http://www.i2s-lab.com/Papers/The_Windows_Shortcut_File_Format.pdf Windows Shortcut File Format]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/LNK</id>
		<title>LNK</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/LNK"/>
				<updated>2006-03-13T19:24:41Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;MS Windows Shortcut Files&lt;br /&gt;
&lt;br /&gt;
In addition the target file, Windows shortcut files contain several interesting pieces of information that include:&lt;br /&gt;
&lt;br /&gt;
* Three date/time stamps that relate to the last time the target was accessed by the given shortcut file.  (More testing needs to be done to determine exactly how these date/time stamps relate to the target.)&lt;br /&gt;
* The size of the target when it was last accessed.&lt;br /&gt;
* Serial number of the local volume where the target was stored.&lt;br /&gt;
* Network volume share name&lt;br /&gt;
* Read-only, hidden, system, volume label, encryption, sparse, compressed, offline and several other target attributes.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Specific details of .lnk shortcut files can be found here:&lt;br /&gt;
[http://www.i2s-lab.com/Papers/The_Windows_Shortcut_File_Format.pdf Windows Shortcut File Format]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/LNK</id>
		<title>LNK</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/LNK"/>
				<updated>2006-03-13T19:23:50Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;MS Windows Shortcut Files&lt;br /&gt;
&lt;br /&gt;
In addition the target file, Windows shortcut files contain several interesting pieces of information that include:&lt;br /&gt;
&lt;br /&gt;
* Three date/time stamps that relate to the last time the target was accessed by the given shortcut file.  (More testing needs to be done to determine exactly how these date/time stamps relate to the target.)&lt;br /&gt;
* The size of the target when it was last accessed.&lt;br /&gt;
* Serial number of the local volume where the target was stored.&lt;br /&gt;
* Network volume share name&lt;br /&gt;
* Read-only, hidden, system, volume label, encryption, sparse, compressed, offline and several other target attributes.&lt;br /&gt;
&lt;br /&gt;
[http://www.i2s-lab.com/Papers/The_Windows_Shortcut_File_Format.pdf Windows Shortcut File Format]&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Windows_Event_Log_(EVT)</id>
		<title>Windows Event Log (EVT)</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Windows_Event_Log_(EVT)"/>
				<updated>2006-03-13T18:41:21Z</updated>
		
		<summary type="html">&lt;p&gt;Mkucenski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Windows Event Log Files&lt;/div&gt;</summary>
		<author><name>Mkucenski</name></author>	</entry>

	</feed>