Forensics Community

White Papers are an excellent source for information gathering, problem-solving and learning. Below is a list of White Papers written by forensic practitioners seeking GCFA Gold . SANS attempts to ensure the accuracy of information, but papers are published "as is".

Errors or inconsistencies may exist or may be introduced over time. If you suspect a serious error, please contact webmaster@sans.org.



Order by: Most Recent -- Title -- Author

Featured Papers


Paper Author
Analysis of tar2d2 as a Forensic Tool Adelstein, Frank
Techniques and Tools for Recovering and Analyzing Data from Volatile Memory Amari, Kristine
Compromised Redhat Linux 7.2 Honeypot Analysis Anderson, Jason
Report on the Forensic Analysis of a recovered Floppy Disk Armstrong, Steve
Open Source Forensic Analysis - Windows 2000 Server - Arnes, Andre
Forensic Analysis of Camouflage and Validation of X-Ways Forensics Tool Aylor, Michael
Forensic Analysis of a MUD Gaming/Development Server Banghart, John
Validation of a Modified UNIX "script" Command to Monitor Shell Sessions Barnett, Ryan
Analyze an Unknown Image and Forensic Tool Validation: Sterilize Becker, Steven
Forensic Analysis of Suplused system hard drives Bellamy, Jr., William
Forensic Analysis of a USB Flash Drive Bennie, Norrie
Forensic Analysis of a Windows 2000 server with IIS and Oracle Binde, Beth
Review of Foundstone Vision as a forensic tool Bingham, Bil
Forensic Analysis Think pad 600 laptop running Windows 2000 server Bowers, Brad
Use of SSH as a forensic tool Bro, Layne
Validation of Restorer 2000 Pro v1.1 (Build 110621) Brooker, Denis
Validation of Norton Ghost 2003 Brozycki, John
Analysis on a compromised Linux RedHat 8.0 Honeypot Bryner, Jeff
Forensic Analysis on acquired EBay Hard Drives Bunnell, Richard
Analyzing a Binary File and File Partitions for Forensic Evidence Butler, James
Validation of GNU tar v1.13.19 & v1.13.25 and GNU cpio v2.4.2 & v2.5 Calabrese, Chris
Forensic analysis/process for a Windows 2000 SP2 Pro with IIS installed Callahan, Jennie
An Exercise In Practical Computer Forensic Analysis Campaign, Adam
Computer Forensic Analysis of an Unknown Binary and The Complete Computer Forensic Investigation of a Hard Drive Capellini, Brian
Forensic Examination of a home firewall and network services system Carlson, Brian
Forensic Analysis: Leila Conlay versus Robert Lawrence, Harassment Case Carpenter, Matthew
Forensic Analysis on a Windows 2000 Server Cassidy, Regis
Analysis of a USB Flashdrive Chablais, Christian
Analysis of a 64MB Lexar Media USB JumpDrive Chen, Joseph
Analysis of a Software Write Blocker - That Works? Chevalier, Suzanne
Forensic Analysis of a Sun Ultra System Chmielarski, Tom
Steganography for spies and spybots for hackers Christensen, Andrew
Infected or Owned? Chuvakin, Anton
Ironically , Some Targets Are Harder Than Others Clarkson, Michael
Validation of Process Accounting Records Clausing, Jim
Ex-Tip: An Extensible Timeline Analysis Framework in Perl Cloppert, Michael
Analysis of a Windows 2000 corporate web server Cordeschi, Carlo
Forensic Analysis on a Windows 2000 Pro Workstation Cragg, David
Forensic Analysis of a Discarded University Computer System Craiger, Philip
Forensic analysis of a compromised RedHat Linux 7.0 system Cunningham, Jacob
A Search for the Origin of a September 2001 Bomb Threat Curd, Bill
Forensic Analysis and process of a Mandrake Linux 9.1 system Da Cruz, Dennis
Validation of The Coroner's Toolkit v1.11 mactime Dalton, Matthew
Forensic Studies in the Digital World de Jong, Mark
Analysis on a compromised RedHat 8.0 machine Deline, Jessica
Validation of GNU strings v2.11.90.0.8 Desai, Neil
Validation of ISObuster v1.0 Dietz, Steven
Forensic Investigation of USB Flashdrive Image for CC Terminals Diggs, Rhonda
Analysis of WinHex Dillinger, Jessica
CC Terminals Computer Forensics Analysis Report Do, George
Validation of NTLast v3.0 Dolak, John
Forensic analysis of a seized USB Flashdrive image Doyle, Ben
CC Terminals, Inc.Forensic Examination Report: Examination of a USB Hard Drive Duckworth, Brent
Analysis of a Suspect Windows 2000 Server SP3 Running IIS Faber, Sid
CC Terminals Harassment Case Farrington, Dean
Forensic analysis of a Windows XP SP1 Ferrill, Rob
Analysis of a Suspect Windows 95 SR2 System Filiberto, James
Analysis of a compromised RedHat 6.2 web server running Apache Filmer, Bradley
Forensic Tool Evaluation-MiTeC Registry File Viewer Fiscus, Kevin
Analyses of Italian Malware, Romanian Rootkits, and United States Computer Law Ford, Michael
Forensic Analysis of a SQL Server 2005 Database Server Fowler, Kevvie
Forensic analysis of a Compromised Windows 2000 workstation Fraser, Charles
Sys Admins and Hackers/Analysis of a hacked system Fresen, Lars
Analysis of a Suspect Red Hat Linux 6.1 System Fung, James
Validaton of icat and ils for Forensic Use Gabler, David
Logic Models for Computer Forensics Garrett, Jim
Loki & the Honeypot: Forensic Analyses Geiger, Matthew
Forensic Analysis of a Windows 2000 Server Ghavalas, Byrne
Validation of TASK v1.50 fsstat and dstat Ginski, Richard
A Touch of Superiority in Linux Griffin, Slade
NTLast as a Forensic Tool Grime, Richard
Analysis of a Compromised Honeypot-VMware/Linux7.3 Hall, Stephen
If it quacks like a duck, is it really a duck? Hall, Andrew
Forensic analysis of a Fedora Core 3 Notebook Halm, Michael
Forensic Analysis of a Compromised Windows NT4 workstation Hammill, Adrian
Analysis of a FAT16 formatted image using Linux, TSK and Autopsy Hansen, Ove
Eavaluation of Linux ext2 file system debugger/debugfs for forensic use Harvey, Michael
Forensic Analysis on a Windows 2000 system Hayday, John
Analysis of a Virus Infected Windows 98 SE System Hayler, Richard
Forensic Image Analysis of a USB Flashdrive Heerwagen, Howard
Forensic Analysis on a compromised Windows 2000 Honeypot Hewitt, Peter
Evaluation of Forensics SF-5000u as forensic Hardware Hickey, Steven
Analysis of an unknown USB JumpDrive image Hiew, Roger
Analysis of a Linux Honeypot Hudak, Tyler
Forensics and Incident Response : Three Investigations Hutson, Brian
Evaluation of The Forensic Toolkit Kamoshida, Akiteru
Forensic Analysis of Shared Workstation Kerr, Michael
EasyRecovery Professional (ER Pro) Khalid, Kamarul Baharin
Forensic Investigation of a Hacked Redhat 7.1 System Khedekar, Nihar
A Forensic Investigation Plan and Cookbook King, Gerald
Analysis of an IRC-bot compromised Microsoft Windows system Kolde, Jennifer
Analysis of LOKI2, Using mtree as a Forensic Tool, and Sharing Data with Law Enforcement Korty, Andrew
Forensic Analysis of an unfamiliar Windows 2000 system Kurasiewicz, Jeff
A Forensic Primer for Usenet Evidence Lachniet, Mark
Romanian Winter-Forensic Analysis of a Linux system Ladstaetter, Garnot
A Proposal for a Binary Comparison Technique Lamastra, Gerardo
Forensic Tool Evaluation-Pasco Larabee, Rick
Forensic Analysis of a Compromised System Lee, Richard
Analysis of a Suspect Red Hat Linux 7.2 System Running Apache v1.3.22 Lee, Christopher
Analysis of a Potentially Misused Windows 95 System Leibolt, Gregory
Forensic Analysis of Another Honeypot Lisman, Jarrad
Forensic Analysis of a Windows 2000 Web Server Liu, Yi-Chung
Analysis of a Compromised Windows NT 4.0 Server Running MS SQL Server 7.0 Lukacs, Steven
Forensic Analysis of a compromised Sun Ultra 5 workstation Madzelan, Carl
Becoming a Forensic Investigator/Use of Forensic Toolkit Maher, Mark
Forensic Analysis on a compromised Linux Web Server Malone, Jeri
Camouflaged and Attacked? Marasky, Bertha
Mobile Device Forensics Martin, Andrew
An Examination of a Compromised Solaris Honeypot, an Unknown Binary, and the Legal Issues Surrounding Incident Investigations Mccauley, Robert
Evaluation of Windows Forensic Toolchest McDougal, Monty
Forensic Analysis Procedures of a Compromised system using Encase McGurk, Jeffrey
Discovery Of A Rootkit: A simple scan leads to a complex solution Melvin, John
Data carving Concepts Merola, Antonio
Forensic analysis of a compromised Linux RedHat 7.3 system Miller, Kevin
Analysis of an Unknown Mac OS X Public Beta System Using Mac OS X 10.2 Miller, Roland
Analysis of a Honeypot running Red Hat Linux 6.2 Murphy, Keven
Digging covert tunnels Analysis of an unknown binary Murr, Michael
Analysis of a Commercial Keylogger installed on multiple systems Namuth, Merlin
Taking advantage of Ext3 journaling file system in a forensic investigation Narvaez, Gregorio
Forensic Analysis on a compromised Windows 2000 system Ng, George
Piping a Shell in a ICMP Tunnel-A Forensic Study of Malicious Code Noakes, Robert
Forensic event with a Microsoft Windows 2000 Server Nolin, Norbert
Careless Crackers kill Computers O'Brien, Conall
Forensic Analysis of a Compromised Intranet Server Obialero, Roberto
Forensic Analysis of a Honeypot Redhat 6.2 system Olensky, Sven
Forensic with Open-Source Tools and Platform: USB Flash Drive Image Forensic Analysis Ong, Leonard
Forensic Analysis of dual bootable Operating System (OS) running a default Red Hat 6.2 Linux server installation and Windows 98 Othman, Mohd Shukri
Analysis and Comparison of Red Hat Linux 6.2 Honeypots With & Without LIDS-enabled Kernels Owen, Greg
Forensic Analysis of an Apple iBook G4 Partida, Alberto
Perform Forensic Analysis on a Red Hat Linux release 7.1.2 Server Pawar, Pramod
Evaluation of a Honeypot Windows 2000 Server with an IIS Web/FTP Server Pearlstein, Kenneth
Analyze an image and Perform Forensic Pecorella, Francisco
Analysis of an Unknown Red Hat Linux 7.3 System Pedersen, Stephen
Hidden Data Is Evidence Too/Metadata Assistant tool Evaluation Pelcher, Bob
Forensic analysis of a provided image Pereira, Rudolph
Safe at Home? Perez, David
Forensic Tool Validation of Compromised Computer Inventory System Perry, James
Forensics under Brazilian Legislation(HoneyPot evaluation) Piccolini, Jacomo
Analysis of a Compromised Red Hat Linux 7.2 System Pierce, Jerry
Google Desktop Search as an Analysis Tool Poldervaart, Chris
Forensic Investigation, Analysis, Documentation, and Law Prentner, Karl
Legal Issues of Computer Incident Handling Psaila, Helen
Examining an Unknown Image & Analysis of a compromised Honeypot Ramli, Farina
Forensic analysis of a honeypot RedHat Linux 6.2 Read, Mark
Forensic Examination of USB Data storage artifact Reardon, Ben
ANALYSIS OF AN IMAGE PROVIDED FROM THE GIAC WEBSITE Reyes Muņoz, Juan Carlos
Forensic analysis of a Windows 2000 computer literacy training and software development device Richard, Golden
Forensic Analysis on a Linux IPNET challenge syste Rinaldi, Alfredo
Lessons from a Linux Compromise Ritchie, John
Spanish-Forensic Analysis of a Windows 98b system Ruiz, Oscar
Compromise analysis of a University SGI Indy workstation running IRIX Russel, Chris
Analysis of a Windows XP Professional compromised system Santander, Manuel
Analysis of a Compromised Honeypot on a Cable Modem Schlereth, Matthew
Trash and Treasure-Computer Forensics and Public Domain Data (Bmap Tool Analysis) Scott, Michael
Hackers and Trackers(Linux Forensic Analysis) Scott, Andy
Forensic analysis of a Windows 98 system Shenk, Jerry
Forensic analysis of a compromised Solaris server Shepherd, Russell
Forensic Analysis of a Misused System Shettler, David
Analysis of a Red Hat Honeypot Shewmaker, James
Forensic Analysis of a RedHat 7.1 Server with Apache Web Server Sierra, Aaron
HONORS-Analysis of a USB Flashdrive Image Siles, Raul
Analysis of an unknown disk Simsic, Jure
Computer forensics investigation - Image file analysis Spellane, Michael
Use of sg_dd for Computer Forensics Stone, Michael
Analysis of a Suspect Red Hat Linux 6.2 System Strubinger, Ray
System Analysis of a Compromised Windows 2000 Professional System Stuart, Robin
Evaluaton of a Zero-Day Worm Variant at a Health Clinic Taylor, Jonathan
Evaluation of Crocwareis Mount Image Pro as a Forensic Tool Tower-Pierce, Hugh
Analysis of a Suspect Red Hat Linux 6.2 System Van Riper, Ryan
Forensic Analysis of a Compromised NT Server(Phishing) Velazquez, Andres
Unspoken Truths - Forensic Analysis of an Unknown Binary Velocci, Louie
Analysis of a Suspect Red Hat 6.2 Linux Server Venere, Guilherme
Forensic Tool Validation, and Legal Issues of Incident Handling Vera, Christopher
Forensic Analysis of a Red Hat Linux release 7.1 Server VK, Vijaykumar
Analysis of a Suspect Windows XP Professional System Wagner, Dave
Forensic analysis of a Compromised Red Hat 7.2 Web Server Walker, Martin
Analyze an Unknown Image and Perform Forensic Tool Validation Watson, Patricia
Analysis of a USB Flashdrive Image Wenchel, Kevin
Forensic Analysis of an EBay acquired Drive Wesemann, Daniel
An Endeavor Down the Forensic Highway(Windows 2000 Professional) Westphal, Kristy
How not to use a rootkit Wilson, Michael
Forensic Validity of Netcat Worman, Michael
Oracle Database Forensics using LogMiner Wright, Paul
Analysis of a serial based digital voice recorder Wright, Craig
Binary Analysis, Forensics and Legal Issues Wyman, Michael
Mac OS X Malware Analysis Yonts, Joel
Analysis of a seized USB Flashdrive Yuen, Cheuk Wai
"This is awsome! We're seeing details that most people don't even know exist" - John Wright, Info Tech, Inc.
"The class provided in-depth, real world, hands-on information" - Robert Dale Drollinger, General Dynamics
SANS Institute