<?xml version="1.0" encoding="UTF-8" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>win4n6 at Yahoo! Groups</title>
    <link>http://tech.groups.yahoo.com/group/win4n6/</link>
    <description>Windows Forensic Analysis</description>

    <item>
      <title>SQL Server Forensics</title>
      <pubDate>Tue, 05 Jan 2010 18:44:57 GMT</pubDate>
      <dc:creator>Tony Rodrigues</dc:creator>
      <link>http://tech.groups.yahoo.com/group/win4n6/message/1487</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/win4n6/message/1487</guid>
      <description>Folks, I was reading Kevvie Fowler SANS GCFA Gold Paper &quot;Forensic Analysis of a SQL Server 2005 Database Server&quot; and I thought it would be useful to write a</description>
    </item>
    <item>
      <title>Re: Re Browser Stuff</title>
      <pubDate>Tue, 05 Jan 2010 12:18:05 GMT</pubDate>
      <dc:creator>keydet89</dc:creator>
      <link>http://tech.groups.yahoo.com/group/win4n6/message/1486</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/win4n6/message/1486</guid>
      <description>... Very cool! Did you see what Paul posted: https://docs.google.com/fileview?id=0B3oC9uB5ETAbMDY2NGNlNTAtYWNiNy00NDkxLWE1OTEtZGY0YmNhNDAxN2Ji&amp;hl=en</description>
    </item>
    <item>
      <title>Re: Re Browser Stuff</title>
      <pubDate>Tue, 05 Jan 2010 12:16:04 GMT</pubDate>
      <dc:creator>keydet89</dc:creator>
      <link>http://tech.groups.yahoo.com/group/win4n6/message/1485</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/win4n6/message/1485</guid>
      <description>Darren, ... ;-) I originally kept rip.exe around because I was using it to test each new plugin I wrote, but then I found that hey, I can write a batch file</description>
    </item>
    <item>
      <title>Re: Re Browser Stuff</title>
      <pubDate>Tue, 05 Jan 2010 06:56:22 GMT</pubDate>
      <dc:creator>darren_q@...</dc:creator>
      <link>http://tech.groups.yahoo.com/group/win4n6/message/1484</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/win4n6/message/1484</guid>
      <description>Oh, for those that are interested; I created the folder; &quot;c:\reg\&quot; and put regripper and rip.exe in there. Created a batch file in &quot;c:\reg&quot;, with the following</description>
    </item>
    <item>
      <title>Re: Re Browser Stuff</title>
      <pubDate>Tue, 05 Jan 2010 04:58:08 GMT</pubDate>
      <dc:creator>darren_q@...</dc:creator>
      <link>http://tech.groups.yahoo.com/group/win4n6/message/1483</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/win4n6/message/1483</guid>
      <description>Never mind, did it with a simple batch file pointing rip.exe to the folder containing the reg files, processes each one in turn... simple really.</description>
    </item>
    <item>
      <title>Re Browser Stuff</title>
      <pubDate>Tue, 05 Jan 2010 04:16:50 GMT</pubDate>
      <dc:creator>darren_q@...</dc:creator>
      <link>http://tech.groups.yahoo.com/group/win4n6/message/1482</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/win4n6/message/1482</guid>
      <description>Re Browser Stuff ( http://windowsir.blogspot.com/2010/01/browser-stuff.html ) Extracting the Registry Files is the first thing I do, then whilst other</description>
    </item>
    <item>
      <title>Re: Why CIRTs should fail</title>
      <pubDate>Mon, 04 Jan 2010 17:55:29 GMT</pubDate>
      <dc:creator>Sean McLinden</dc:creator>
      <link>http://tech.groups.yahoo.com/group/win4n6/message/1481</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/win4n6/message/1481</guid>
      <description>Well, you do have: http://www.databreaches.net/ http://www.idtheftcenter.org/ http://www.datalossdb.org/ But, of course, these are only the reported incidents</description>
    </item>
    <item>
      <title>Re: Why CIRTs should fail</title>
      <pubDate>Mon, 04 Jan 2010 17:33:56 GMT</pubDate>
      <dc:creator>Ron McGill</dc:creator>
      <link>http://tech.groups.yahoo.com/group/win4n6/message/1480</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/win4n6/message/1480</guid>
      <description>Other forensic fields share information or have databases--CODIS, NIBIN, etc.  Too bad there is not a database or system to tell CFEs what is going on in the</description>
    </item>
    <item>
      <title>Re: Why CIRTs should fail</title>
      <pubDate>Mon, 04 Jan 2010 15:26:50 GMT</pubDate>
      <dc:creator>Sean McLinden</dc:creator>
      <link>http://tech.groups.yahoo.com/group/win4n6/message/1479</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/win4n6/message/1479</guid>
      <description>... I&#39;m not so sure, from my professional experience, that the intelligence community is that much farther along. Remember that a significant portion of the</description>
    </item>
    <item>
      <title>Re: Why CIRTs should fail</title>
      <pubDate>Mon, 04 Jan 2010 15:16:41 GMT</pubDate>
      <dc:creator>Greg Kelley</dc:creator>
      <link>http://tech.groups.yahoo.com/group/win4n6/message/1478</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/win4n6/message/1478</guid>
      <description>I think the biggest issue when someone admits a mistake is what potential liability that person is admitting for their company. I know that internally, we do</description>
    </item>
    <item>
      <title>Re: Why CIRTs should fail</title>
      <pubDate>Mon, 04 Jan 2010 14:44:43 GMT</pubDate>
      <dc:creator>Nick Anthis</dc:creator>
      <link>http://tech.groups.yahoo.com/group/win4n6/message/1477</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/win4n6/message/1477</guid>
      <description>All this insight is great, but it certainly highlights that this arena is in the same boat that the intelligence community was before 9/11.  Not enough</description>
    </item>
    <item>
      <title>Re: Why CIRTs should fail</title>
      <pubDate>Mon, 04 Jan 2010 14:32:35 GMT</pubDate>
      <dc:creator>Sean McLinden</dc:creator>
      <link>http://tech.groups.yahoo.com/group/win4n6/message/1476</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/win4n6/message/1476</guid>
      <description>... Harlan: I understand, as well. I was simply trying amplify your point by illustrating just how big a problem it is. The shear number of people out there</description>
    </item>
    <item>
      <title>Re: Why CIRTs should fail</title>
      <pubDate>Mon, 04 Jan 2010 14:18:53 GMT</pubDate>
      <dc:creator>keydet89</dc:creator>
      <link>http://tech.groups.yahoo.com/group/win4n6/message/1475</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/win4n6/message/1475</guid>
      <description>Sean, ... Understood, but my point was that the bad guys do it, and I think that in some ways, the good guy&#39;s inability to do something similar (with respect</description>
    </item>
    <item>
      <title>Re: Why CIRTs should fail</title>
      <pubDate>Mon, 04 Jan 2010 14:07:19 GMT</pubDate>
      <dc:creator>Sean McLinden</dc:creator>
      <link>http://tech.groups.yahoo.com/group/win4n6/message/1474</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/win4n6/message/1474</guid>
      <description>... Right on! There are &quot;social&quot; networks out there where tools and techniques are bartered, or shared, outright.  I can go onto a BB and issue a &quot;bid&quot; for</description>
    </item>
    <item>
      <title>Re: Why CIRTs should fail</title>
      <pubDate>Sun, 03 Jan 2010 23:15:50 GMT</pubDate>
      <dc:creator>keydet89</dc:creator>
      <link>http://tech.groups.yahoo.com/group/win4n6/message/1473</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/win4n6/message/1473</guid>
      <description>John, ... While I do appreciate the point of view, I too often feel that it&#39;s an excuse.  I think that the concern folks have is that if they let out what they</description>
    </item>

  </channel>
</rss>
<!-- wr1.grp.sp2.yahoo.com uncompressed/chunked Tue Jan  5 18:58:43 PST 2010 -->
