<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Digital Forensics &#38; Incident Response</title>
	<atom:link href="http://digiforensics.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://digiforensics.wordpress.com</link>
	<description>security</description>
	<lastBuildDate>Tue, 04 Dec 2007 06:34:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='digiforensics.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Digital Forensics &#38; Incident Response</title>
		<link>http://digiforensics.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://digiforensics.wordpress.com/osd.xml" title="Digital Forensics &#38; Incident Response" />
	<atom:link rel='hub' href='http://digiforensics.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Drawing a line between hunches and conclusions</title>
		<link>http://digiforensics.wordpress.com/2007/12/03/drawing-a-line-between-hunches-and-conclusions/</link>
		<comments>http://digiforensics.wordpress.com/2007/12/03/drawing-a-line-between-hunches-and-conclusions/#comments</comments>
		<pubDate>Tue, 04 Dec 2007 06:33:08 +0000</pubDate>
		<dc:creator>digiforensics</dc:creator>
				<category><![CDATA[Teatime Thoughts]]></category>

		<guid isPermaLink="false">http://digiforensics.wordpress.com/2007/12/03/drawing-a-line-between-hunches-and-conclusions/</guid>
		<description><![CDATA[Many times it seems that as forensic engineers, we are put in positions where it is thought full concrete conclusions can be made by analyzing acquired drives and devices. In truth however, it is important to distinguish hunches from full conclusions, an area which seems to be blurred amongst many engineers who feel they either [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digiforensics.wordpress.com&amp;blog=2186628&amp;post=5&amp;subd=digiforensics&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Many times it seems that as forensic engineers, we are put in positions where it is thought full concrete conclusions can be made by analyzing acquired drives and devices. In truth however, it is important to distinguish hunches from full conclusions, an area which seems to be blurred amongst many engineers who feel they either have absolute evidence of a particular activity taking place or enough to justify absolutes in their reports.</p>
<p>For example, so you found a USB device was connected to a system. Bingo! Or not? Does this mean the &#8216;suspect&#8217; transferred that intellectual property that everyone thought they did? Or was it the sysadmin playing detective after the employee left? Better yet, was it just a USB device installed for utilizing Vista&#8217;s ReadyBoost technology and nothing more?</p>
<p>Let&#8217;s take a look at another one:</p>
<p>What makes the suspect a suspect? Is it just because that&#8217;s what the paying customer believes they are? Is the paying customer themselves a suspect framing someone else? Using such a term lightly can make a forensic engineer delve into murky waters fast. Don&#8217;t assume anything as fact!</p>
<p>As forensic engineers, it is our duty to collect, analyze and present data to assist others in a case. We are not psychologists, hence it is not our job to make such conclusions. We are IT professionals looking at and presenting nothing else but data, 0&#8242;s and 1&#8242;s. So next time you write that report, remember!</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/digiforensics.wordpress.com/5/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/digiforensics.wordpress.com/5/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/digiforensics.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/digiforensics.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/digiforensics.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/digiforensics.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/digiforensics.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/digiforensics.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/digiforensics.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/digiforensics.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/digiforensics.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/digiforensics.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/digiforensics.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/digiforensics.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/digiforensics.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/digiforensics.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digiforensics.wordpress.com&amp;blog=2186628&amp;post=5&amp;subd=digiforensics&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://digiforensics.wordpress.com/2007/12/03/drawing-a-line-between-hunches-and-conclusions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0d39fa8973d233ce1c031dddf226e2f1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">digiforensics</media:title>
		</media:content>
	</item>
		<item>
		<title>CEIC 2008 &#8211; Apr 27-30 2008, Las Vegas, NV</title>
		<link>http://digiforensics.wordpress.com/2007/11/26/ceic-2008-apr-27-30-2008-las-vegas-nv/</link>
		<comments>http://digiforensics.wordpress.com/2007/11/26/ceic-2008-apr-27-30-2008-las-vegas-nv/#comments</comments>
		<pubDate>Tue, 27 Nov 2007 06:45:02 +0000</pubDate>
		<dc:creator>digiforensics</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://digiforensics.wordpress.com/2007/11/26/ceic-2008-apr-27-30-2008-las-vegas-nv/</guid>
		<description><![CDATA[Time is running out for the early bird special ($695) to the Computer and Enterprise Investigations Conference&#8230; Nov 30, 2007 is the deadline. From their agenda, it looks as though there is going to be several interesting talks. Unfortunately, the ones I&#8217;m interested in seem to conflict with each other throughout the event! It would [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digiforensics.wordpress.com&amp;blog=2186628&amp;post=4&amp;subd=digiforensics&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Time is running out for the early bird special ($695) to the Computer and Enterprise Investigations Conference&#8230; Nov 30, 2007 is the deadline.</p>
<p>From their agenda, it looks as though there is going to be several interesting talks. Unfortunately, the ones I&#8217;m interested in seem to conflict with each other throughout the event!</p>
<p>It would be great if I could do a dd of myself for times like this!</p>
<p>Jee</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/digiforensics.wordpress.com/4/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/digiforensics.wordpress.com/4/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/digiforensics.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/digiforensics.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/digiforensics.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/digiforensics.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/digiforensics.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/digiforensics.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/digiforensics.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/digiforensics.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/digiforensics.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/digiforensics.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/digiforensics.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/digiforensics.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/digiforensics.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/digiforensics.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digiforensics.wordpress.com&amp;blog=2186628&amp;post=4&amp;subd=digiforensics&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://digiforensics.wordpress.com/2007/11/26/ceic-2008-apr-27-30-2008-las-vegas-nv/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0d39fa8973d233ce1c031dddf226e2f1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">digiforensics</media:title>
		</media:content>
	</item>
		<item>
		<title>Welcome chums!</title>
		<link>http://digiforensics.wordpress.com/2007/11/23/hello-world/</link>
		<comments>http://digiforensics.wordpress.com/2007/11/23/hello-world/#comments</comments>
		<pubDate>Fri, 23 Nov 2007 16:22:17 +0000</pubDate>
		<dc:creator>digiforensics</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[And so it has begun&#8230; the Digital Forensics blog! Perfect timing, as the kettle has just boiled so we can sit down and discuss all things digital forensics!<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digiforensics.wordpress.com&amp;blog=2186628&amp;post=1&amp;subd=digiforensics&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>And so it has begun&#8230; the Digital Forensics blog! Perfect timing, as the kettle has just boiled so we can sit down and discuss all things digital forensics!</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/digiforensics.wordpress.com/1/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/digiforensics.wordpress.com/1/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/digiforensics.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/digiforensics.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/digiforensics.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/digiforensics.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/digiforensics.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/digiforensics.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/digiforensics.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/digiforensics.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/digiforensics.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/digiforensics.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/digiforensics.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/digiforensics.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/digiforensics.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/digiforensics.wordpress.com/1/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digiforensics.wordpress.com&amp;blog=2186628&amp;post=1&amp;subd=digiforensics&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://digiforensics.wordpress.com/2007/11/23/hello-world/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0d39fa8973d233ce1c031dddf226e2f1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">digiforensics</media:title>
		</media:content>
	</item>
	</channel>
</rss>
