<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Praetorian Prefect &#187; Forensics</title>
	<atom:link href="http://praetorianprefect.com/archives/category/forensics/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Thu, 19 Jan 2012 03:59:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>The Anonymous PR Guy and a Greece Connection</title>
		<link>http://praetorianprefect.com/archives/2010/12/the-anonymous-pr-guy-and-a-greece-connection/</link>
		<comments>http://praetorianprefect.com/archives/2010/12/the-anonymous-pr-guy-and-a-greece-connection/#comments</comments>
		<pubDate>Sun, 12 Dec 2010 00:39:54 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[Anonymous]]></category>
		<category><![CDATA[didier]]></category>
		<category><![CDATA[pdf]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=4812</guid>
		<description><![CDATA[The PDF's raw creation date further points to the Anonymous Press Release from yesterday being created in Greece, which happens to be the homeland of a graphic artist with the same name as the pdf's author field, Alex Tapanaris.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/12/the-anonymous-pr-guy-and-a-greece-connection/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>WinPE 3.0 &amp; Forensics</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/</link>
		<comments>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/#comments</comments>
		<pubDate>Mon, 12 Apr 2010 22:46:49 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[post-wide]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608</guid>
		<description><![CDATA[It is a common task for an investigator to boot a machine using bootable media in the form of DVD or USB and there are countless options available. This tutorial is not intended to replace your favorite Helix CD or preferred method, but you may find this analysis interesting if you are a Windows expert performing a forensics analysis.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/feed/</wfw:commentRss>
		<slash:comments>19</slash:comments>
		</item>
		<item>
		<title>Reactivating DECAF in Two Minutes</title>
		<link>http://praetorianprefect.com/archives/2009/12/reactivating-decaf-in-two-minutes/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/reactivating-decaf-in-two-minutes/#comments</comments>
		<pubDate>Sat, 19 Dec 2009 02:51:33 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[cofee]]></category>
		<category><![CDATA[decaf]]></category>
		<category><![CDATA[post-wide]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2574</guid>
		<description><![CDATA[The misinformation on DECAF being shut down and a hoax is alarming and the quality of reporting on this security topic actually worse than usual. Earlier tonight we noticed <a href="http://twitter.com/slashdot/status/6805917206">this update</a> from @slashdot on Twitter: "DECAF Was Just a Stunt, Now Over", along with this: "Anti-COFEE tool taken down &#38; d/l'ed copies disabled.". Ok, fair enough, releasing DECAF was a stunt according to its two creators. But then we saw <a href="http://blog.seattlepi.com/microsoft/archives/188706.asp">this train wreck of an article by Nick Eaton</a>, the Microsoft Reporter over at the Seattle PI Blogs. So now we're going to respond, because the incorrect DECAF as a big hoax story, a tool that supposedly never worked, is propagating through the Intertubes. DECAF was a working tool that can be easily re-enabled, because the shut down appears to only be a call back to decafme.org that is now disabled, but is easily spoofed, and we'll demonstrate how.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/reactivating-decaf-in-two-minutes/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>Forensics: Beverages Aside, A Look at Incident Response Tools</title>
		<link>http://praetorianprefect.com/archives/2009/12/forensics-beverages-aside-a-look-at-incident-response-tools/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/forensics-beverages-aside-a-look-at-incident-response-tools/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 00:57:57 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[cofee]]></category>
		<category><![CDATA[decaf]]></category>
		<category><![CDATA[FTK]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2333</guid>
		<description><![CDATA[In November, Microsoft's forensics tool called COFEE (Computer Online Forensic Evidence Extractor) was leaked on torrents for download. The news coverage was <a href="http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/">much hype about nothing</a>, as many free tools already out there exceed COFEE in features and functionality.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/forensics-beverages-aside-a-look-at-incident-response-tools/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Regular or Decaf? Tool launched to combat COFEE</title>
		<link>http://praetorianprefect.com/archives/2009/12/regular-or-decaf-tool-launched-to-combat-cofee/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/regular-or-decaf-tool-launched-to-combat-cofee/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 01:21:34 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[anti-forensics]]></category>
		<category><![CDATA[cofee]]></category>
		<category><![CDATA[decaf]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2250</guid>
		<description><![CDATA[

About a month ago, there was much news about the release of COFEE into the torrent wild. I even gave my two cents about the much hyped forensics toolkit which is provided to law enforcement for the purposes of easily capturing volatile data from personal computers during evidence collection. A tool to counter COFEE, aptly [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/regular-or-decaf-tool-launched-to-combat-cofee/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Taxonomy of Forensics Geeks</title>
		<link>http://praetorianprefect.com/archives/2009/11/taxonomy-of-forensics-geeks/</link>
		<comments>http://praetorianprefect.com/archives/2009/11/taxonomy-of-forensics-geeks/#comments</comments>
		<pubDate>Wed, 11 Nov 2009 22:12:25 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Forensics]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1601</guid>
		<description><![CDATA[Have you met these types in the forensics forums, lurking in your blog comments, or anywhere else on the Intertubes: The Back-Door Man who knows that MSFT has stealth back doors in Windows, or the Man of Few Words with his pithy &#8220;One word: TrueCrypt&#8221; style comments?  Happy as a Monkey breaks it all [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/11/taxonomy-of-forensics-geeks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More COFEE Please, on Second Thought&#8230;</title>
		<link>http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/</link>
		<comments>http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 17:24:49 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[hype]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/</guid>
		<description><![CDATA[The forensics tool provided to law enforcement officials created by Microsoft called COFEE&#160; (Computer Online Forensic Evidence Extractor) has been leaked on torrents last week, and this has caused quite a bit of excitement.&#160; Let’s see if the big deal is warranted.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
	</channel>
</rss>

