sleuthkit-users Mailing List for The Sleuth Kit (Page 7)
Brought to you by:
carrier
You can subscribe to this list here.
2002 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(6) |
Aug
|
Sep
(11) |
Oct
(5) |
Nov
(4) |
Dec
|
---|---|---|---|---|---|---|---|---|---|---|---|---|
2003 |
Jan
(1) |
Feb
(20) |
Mar
(60) |
Apr
(40) |
May
(24) |
Jun
(28) |
Jul
(18) |
Aug
(27) |
Sep
(6) |
Oct
(14) |
Nov
(15) |
Dec
(22) |
2004 |
Jan
(34) |
Feb
(13) |
Mar
(28) |
Apr
(23) |
May
(27) |
Jun
(26) |
Jul
(37) |
Aug
(19) |
Sep
(20) |
Oct
(39) |
Nov
(17) |
Dec
(9) |
2005 |
Jan
(45) |
Feb
(43) |
Mar
(66) |
Apr
(36) |
May
(19) |
Jun
(64) |
Jul
(10) |
Aug
(11) |
Sep
(35) |
Oct
(6) |
Nov
(4) |
Dec
(13) |
2006 |
Jan
(52) |
Feb
(34) |
Mar
(39) |
Apr
(39) |
May
(37) |
Jun
(15) |
Jul
(13) |
Aug
(48) |
Sep
(9) |
Oct
(10) |
Nov
(47) |
Dec
(13) |
2007 |
Jan
(25) |
Feb
(4) |
Mar
(2) |
Apr
(29) |
May
(11) |
Jun
(19) |
Jul
(13) |
Aug
(15) |
Sep
(30) |
Oct
(12) |
Nov
(10) |
Dec
(13) |
2008 |
Jan
(2) |
Feb
(54) |
Mar
(58) |
Apr
(43) |
May
(10) |
Jun
(27) |
Jul
(25) |
Aug
(27) |
Sep
(48) |
Oct
(69) |
Nov
(55) |
Dec
(43) |
2009 |
Jan
(26) |
Feb
(36) |
Mar
(28) |
Apr
(27) |
May
(55) |
Jun
(9) |
Jul
(19) |
Aug
(16) |
Sep
(15) |
Oct
(17) |
Nov
(70) |
Dec
(21) |
2010 |
Jan
(56) |
Feb
(59) |
Mar
(53) |
Apr
(32) |
May
(25) |
Jun
(31) |
Jul
(36) |
Aug
(11) |
Sep
(37) |
Oct
(19) |
Nov
(23) |
Dec
(6) |
2011 |
Jan
(21) |
Feb
(20) |
Mar
(30) |
Apr
(30) |
May
(74) |
Jun
(50) |
Jul
(34) |
Aug
(34) |
Sep
(12) |
Oct
(33) |
Nov
(10) |
Dec
(8) |
2012 |
Jan
(23) |
Feb
(57) |
Mar
(26) |
Apr
(14) |
May
(27) |
Jun
(27) |
Jul
(60) |
Aug
(88) |
Sep
(13) |
Oct
(36) |
Nov
(97) |
Dec
(85) |
2013 |
Jan
(60) |
Feb
(24) |
Mar
(43) |
Apr
(32) |
May
(22) |
Jun
(38) |
Jul
(51) |
Aug
(50) |
Sep
(76) |
Oct
(65) |
Nov
(25) |
Dec
(30) |
2014 |
Jan
(19) |
Feb
(41) |
Mar
(43) |
Apr
(28) |
May
(61) |
Jun
(12) |
Jul
(10) |
Aug
(37) |
Sep
(76) |
Oct
(31) |
Nov
(41) |
Dec
(12) |
2015 |
Jan
(33) |
Feb
(28) |
Mar
(53) |
Apr
(22) |
May
(29) |
Jun
(20) |
Jul
(15) |
Aug
(17) |
Sep
(52) |
Oct
(3) |
Nov
(18) |
Dec
(21) |
2016 |
Jan
(20) |
Feb
(8) |
Mar
(21) |
Apr
(7) |
May
(13) |
Jun
(35) |
Jul
(34) |
Aug
(11) |
Sep
(14) |
Oct
(22) |
Nov
(31) |
Dec
(23) |
2017 |
Jan
(20) |
Feb
(7) |
Mar
(5) |
Apr
(6) |
May
(6) |
Jun
(22) |
Jul
(11) |
Aug
(16) |
Sep
(8) |
Oct
(1) |
Nov
(1) |
Dec
(1) |
2018 |
Jan
|
Feb
|
Mar
(16) |
Apr
(2) |
May
(6) |
Jun
(5) |
Jul
|
Aug
(2) |
Sep
(4) |
Oct
|
Nov
(16) |
Dec
(13) |
2019 |
Jan
|
Feb
(1) |
Mar
(25) |
Apr
(9) |
May
(2) |
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2020 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
(1) |
Jun
(3) |
Jul
(2) |
Aug
|
Sep
|
Oct
(5) |
Nov
|
Dec
|
2021 |
Jan
|
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
(4) |
Jul
(1) |
Aug
|
Sep
(1) |
Oct
|
Nov
(1) |
Dec
|
2022 |
Jan
|
Feb
(2) |
Mar
|
Apr
|
May
(2) |
Jun
|
Jul
(3) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2023 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
|
Dec
|
2024 |
Jan
|
Feb
(3) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2025 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: sasitaran - <sa...@pu...> - 2017-08-25 03:22:31
|
Greetings and best regards from Putra Intelek International College (PIIC), a private higher education institution specializing in contemporary, industry driven niche programmes tailored to fulfil the industry demand for competent workforce in public and various economic sectors. We would like to obtain your permission to use the Autopsy Software as the freeware for our students specializing in Digital Security course. We assure that the software shall be used for educational purposes and for the benefits of our students who shall be employed in Cyber Security related jobs in the near future. We would also appreciate if we can be directed to the liaison officer for us to discuss further on this (should there is a need). On our behalf, you may refer to Mr. Pragash @ pr...@pu... for further information or confirmation. Thank you -- *Regards,* *Sasitaran Nadarajan* *IT Executive* *Putra Intelek International College* *Tel. No: **03-89390222 (Ext: 237)* |
From: Brian C. <ca...@sl...> - 2017-08-21 19:17:22
|
Did you have "Recent Activity" module enabled? What browsers are installed on the system? On Mon, Aug 21, 2017 at 12:53 PM, Michael Williams <mwi...@cr...> wrote: > I duplicated a laptop sata drive and was using autopsy 4.41 to search the > drive. Repeatedly, the software won’t list browser history or locate any > temp internet files, even though I know they are there if I do a manual > search. > > > > What am I doing wrong? > > > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > |
From: Michael W. <mwi...@cr...> - 2017-08-21 17:27:57
|
I duplicated a laptop sata drive and was using autopsy 4.41 to search the drive. Repeatedly, the software won't list browser history or locate any temp internet files, even though I know they are there if I do a manual search. What am I doing wrong? |
From: Brian C. <ca...@sl...> - 2017-08-18 01:33:45
|
In the C world, it is stored as the TSK_FS_ATTR_ENC flag in TSK_FS_ATTR flags. But, I don't see that in the database. Where do you see it for compressed files. They are stored in the same flags On Thu, Aug 17, 2017 at 9:19 AM, Luís Filipe Nassif <lfc...@gm...> wrote: > Hi, > > There is any flag for NTFS encrypted files exposed by Autopsy or Sleuthkit > Java Bindings? I searched the documentation of TSK Java Bindings but did > not find it, only for compressed files. > > Thanks, > Luis > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > |
From: Luís F. N. <lfc...@gm...> - 2017-08-17 13:19:51
|
Hi, There is any flag for NTFS encrypted files exposed by Autopsy or Sleuthkit Java Bindings? I searched the documentation of TSK Java Bindings but did not find it, only for compressed files. Thanks, Luis |
From: Brian C. <ca...@sl...> - 2017-08-17 00:59:20
|
I forgot to announce last week that new releases are up. Autopsy 4.4.1 includes: - Beta version of new central repository feature for correlating artifacts across cases; results are displayed using an Interesting Artifacts branch of the Interesting Items tree and an Other Data Sources content viewer. I'll post a blog post about using this later next week. - Results viewer (top right area of desktop application) sorts are persistent and can be applied to either the table viewer or the thumbnail viewer. - Assorted performance improvements, enhancements, and bug fixes. Download here: http://sleuthkit.org/autopsy/download.php The Sleuth Kit 4.4.2 includes: - usnjls tool for NTFS USN log (from noxdafox) - Added index to mime type column in DB - Use local SQLite3 if it exists (from uckelman-sf) - Blackboard Artifacts have a shortDescription metho - Fix for highest HFS+ inum lookup (from uckelman-sf) - Fix ISO9660 crash - various performance fixes and added thread safety checks Download here: http://sleuthkit.org/sleuthkit/download.php thanks, brian |
From: Brian C. <ca...@sl...> - 2017-08-15 01:33:24
|
Circling back on this topic, I think we focus on 001 since that is what FTK Imager starts with. I think the easiest solution is to have Autopsy look for a .000 file when the user chooses a .001 file and use that as the starting image. The risk with this approach is that if someone used a tool that started at 000 and they had only a single image, then it will not be shown by default. But, they can see it by choosing the "Show All Files" option. On Thu, Aug 10, 2017 at 2:54 AM, Nanni Bassetti <dig...@gm...> wrote: > I did not make the image file, it has been made by others using Guymager > (see the .info file) it is a part of an online challenge: > http://www.dfrws.org/dfrws-forensic-challenge > And yes, I did not notice that Autopsy opens .001 by default, indeed using > FTK Imager, I instinctively chose the .000 file and not the .001 and it > worked :-) > Thanks > > 2017-08-10 6:04 GMT+02:00 Barry Grundy <bg...@gm...>: > >> Just food for thought, dc3dd starts with 000 on split files. The ofs= >> parameter takes a format of either 00 or 000, so the splits start with >> that. You cannot specify a start of 001. TSK works fine with 000. >> >> dc3dd is a pretty popular open source imaging tool, so that might should >> be taken into account. It's my primary, but I don't use Autopsy, so I've >> never noticed the issue. >> >> Barry >> >> On Wed, Aug 9, 2017 at 11:10 PM, Brian Carrier <ca...@sl...> >> wrote: >> >>> Hi Nanni, >>> >>> How did you make the image? >>> >>> Autopsy has an assumption that .001 is the first image in a split set of >>> images and doesn't expect 000. The file picker in Autopsy therefore just >>> shows .001 files and hides the rest. When it looks at your .001 file, it >>> isn't happy because it isn't the start of a disk image. >>> >>> Though, as I think about this... 'split' will use .000 as the first >>> file. Does FTK Imager use .001? I'm now wondering how we picked '.001' >>> (and have so many '.001 files in our test data). >>> >>> The options here seem to be: >>> - We decide that .001 is not a common starting number and it should >>> really be 000. Though I"m surprised we haven't gotten more complaints >>> about this over the years. >>> - We add some logic into TSK so that it looks for a .000 if .001 was >>> given and uses that instead as the starting location. >>> >>> >>> >>> >>> On Wed, Aug 9, 2017 at 3:30 PM, Nanni Bassetti <dig...@gm...> >>> wrote: >>> >>>> Yes! it works in that way...but it's a strange behavior :-) >>>> Thank you >>>> >>>> 2017-08-09 21:22 GMT+02:00 Ann Priestman <apr...@ba...>: >>>> >>>>> Sorry what I meant was: >>>>> - go through the Autopsy data source selection >>>>> - when you browse to your folder, it will display the .001 file as the >>>>> only choice >>>>> - change the filter to All files to make it show everything in the >>>>> folder and then select the .000 file >>>>> >>>>> Sent from my iPhone >>>>> >>>>> On Aug 9, 2017, at 3:11 PM, Nanni Bassetti <dig...@gm...> wrote: >>>>> >>>>> Anyway...I tried and nothing to do! :-) >>>>> >>>>> 2017-08-09 21:08 GMT+02:00 Nanni Bassetti <dig...@gm...>: >>>>> >>>>>> >>>>>> 2017-08-09 20:56 GMT+02:00 Ann Priestman <apr...@ba...>: >>>>>> >>>>>>> Hi Nanni, >>>>>>> >>>>>>> On the Autopsy select data source screen, try changing the given >>>>>>> file name "E001SmartTVMMC.001" to "E001SmartTVMMC.000". The file system >>>>>>> loaded for me after that change. >>>>>>> >>>>>> >>>>>> And what have I to do with the original E001SmartTVMMC.000? If I >>>>>> rename the .001 to .000 what's about the .000 file? >>>>>> Thanks >>>>>> >>>>>> >>>>>> >>>>>> -- >>>>>> Dott. Nanni Bassetti >>>>>> http://www.nannibassetti.com >>>>>> CAINE project manager - http://www.caine-live.net >>>>>> >>>>> >>>>> >>>>> >>>>> -- >>>>> Dott. Nanni Bassetti >>>>> http://www.nannibassetti.com >>>>> CAINE project manager - http://www.caine-live.net >>>>> >>>>> >>>> >>>> >>>> -- >>>> Dott. Nanni Bassetti >>>> http://www.nannibassetti.com >>>> CAINE project manager - http://www.caine-live.net >>>> >>>> ------------------------------------------------------------ >>>> ------------------ >>>> Check out the vibrant tech community on one of the world's most >>>> engaging tech sites, Slashdot.org! http://sdm.link/slashdot >>>> _______________________________________________ >>>> sleuthkit-users mailing list >>>> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >>>> http://www.sleuthkit.org >>>> >>>> >>> >>> ------------------------------------------------------------ >>> ------------------ >>> Check out the vibrant tech community on one of the world's most >>> engaging tech sites, Slashdot.org! http://sdm.link/slashdot >>> _______________________________________________ >>> sleuthkit-users mailing list >>> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >>> http://www.sleuthkit.org >>> >>> >> >> >> -- >> ---- >> Barry Grundy >> bg...@gm... >> bg...@li... >> > > > > -- > Dott. Nanni Bassetti > http://www.nannibassetti.com > CAINE project manager - http://www.caine-live.net > |
From: Nanni B. <dig...@gm...> - 2017-08-10 06:54:28
|
I did not make the image file, it has been made by others using Guymager (see the .info file) it is a part of an online challenge: http://www.dfrws.org/dfrws-forensic-challenge And yes, I did not notice that Autopsy opens .001 by default, indeed using FTK Imager, I instinctively chose the .000 file and not the .001 and it worked :-) Thanks 2017-08-10 6:04 GMT+02:00 Barry Grundy <bg...@gm...>: > Just food for thought, dc3dd starts with 000 on split files. The ofs= > parameter takes a format of either 00 or 000, so the splits start with > that. You cannot specify a start of 001. TSK works fine with 000. > > dc3dd is a pretty popular open source imaging tool, so that might should > be taken into account. It's my primary, but I don't use Autopsy, so I've > never noticed the issue. > > Barry > > On Wed, Aug 9, 2017 at 11:10 PM, Brian Carrier <ca...@sl...> > wrote: > >> Hi Nanni, >> >> How did you make the image? >> >> Autopsy has an assumption that .001 is the first image in a split set of >> images and doesn't expect 000. The file picker in Autopsy therefore just >> shows .001 files and hides the rest. When it looks at your .001 file, it >> isn't happy because it isn't the start of a disk image. >> >> Though, as I think about this... 'split' will use .000 as the first >> file. Does FTK Imager use .001? I'm now wondering how we picked '.001' >> (and have so many '.001 files in our test data). >> >> The options here seem to be: >> - We decide that .001 is not a common starting number and it should >> really be 000. Though I"m surprised we haven't gotten more complaints >> about this over the years. >> - We add some logic into TSK so that it looks for a .000 if .001 was >> given and uses that instead as the starting location. >> >> >> >> >> On Wed, Aug 9, 2017 at 3:30 PM, Nanni Bassetti <dig...@gm...> >> wrote: >> >>> Yes! it works in that way...but it's a strange behavior :-) >>> Thank you >>> >>> 2017-08-09 21:22 GMT+02:00 Ann Priestman <apr...@ba...>: >>> >>>> Sorry what I meant was: >>>> - go through the Autopsy data source selection >>>> - when you browse to your folder, it will display the .001 file as the >>>> only choice >>>> - change the filter to All files to make it show everything in the >>>> folder and then select the .000 file >>>> >>>> Sent from my iPhone >>>> >>>> On Aug 9, 2017, at 3:11 PM, Nanni Bassetti <dig...@gm...> wrote: >>>> >>>> Anyway...I tried and nothing to do! :-) >>>> >>>> 2017-08-09 21:08 GMT+02:00 Nanni Bassetti <dig...@gm...>: >>>> >>>>> >>>>> 2017-08-09 20:56 GMT+02:00 Ann Priestman <apr...@ba...>: >>>>> >>>>>> Hi Nanni, >>>>>> >>>>>> On the Autopsy select data source screen, try changing the given file >>>>>> name "E001SmartTVMMC.001" to "E001SmartTVMMC.000". The file system loaded >>>>>> for me after that change. >>>>>> >>>>> >>>>> And what have I to do with the original E001SmartTVMMC.000? If I >>>>> rename the .001 to .000 what's about the .000 file? >>>>> Thanks >>>>> >>>>> >>>>> >>>>> -- >>>>> Dott. Nanni Bassetti >>>>> http://www.nannibassetti.com >>>>> CAINE project manager - http://www.caine-live.net >>>>> >>>> >>>> >>>> >>>> -- >>>> Dott. Nanni Bassetti >>>> http://www.nannibassetti.com >>>> CAINE project manager - http://www.caine-live.net >>>> >>>> >>> >>> >>> -- >>> Dott. Nanni Bassetti >>> http://www.nannibassetti.com >>> CAINE project manager - http://www.caine-live.net >>> >>> ------------------------------------------------------------ >>> ------------------ >>> Check out the vibrant tech community on one of the world's most >>> engaging tech sites, Slashdot.org! http://sdm.link/slashdot >>> _______________________________________________ >>> sleuthkit-users mailing list >>> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >>> http://www.sleuthkit.org >>> >>> >> >> ------------------------------------------------------------ >> ------------------ >> Check out the vibrant tech community on one of the world's most >> engaging tech sites, Slashdot.org! http://sdm.link/slashdot >> _______________________________________________ >> sleuthkit-users mailing list >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >> http://www.sleuthkit.org >> >> > > > -- > ---- > Barry Grundy > bg...@gm... > bg...@li... > -- Dott. Nanni Bassetti http://www.nannibassetti.com CAINE project manager - http://www.caine-live.net |
From: Barry G. <bg...@gm...> - 2017-08-10 04:04:42
|
Just food for thought, dc3dd starts with 000 on split files. The ofs= parameter takes a format of either 00 or 000, so the splits start with that. You cannot specify a start of 001. TSK works fine with 000. dc3dd is a pretty popular open source imaging tool, so that might should be taken into account. It's my primary, but I don't use Autopsy, so I've never noticed the issue. Barry On Wed, Aug 9, 2017 at 11:10 PM, Brian Carrier <ca...@sl...> wrote: > Hi Nanni, > > How did you make the image? > > Autopsy has an assumption that .001 is the first image in a split set of > images and doesn't expect 000. The file picker in Autopsy therefore just > shows .001 files and hides the rest. When it looks at your .001 file, it > isn't happy because it isn't the start of a disk image. > > Though, as I think about this... 'split' will use .000 as the first > file. Does FTK Imager use .001? I'm now wondering how we picked '.001' > (and have so many '.001 files in our test data). > > The options here seem to be: > - We decide that .001 is not a common starting number and it should really > be 000. Though I"m surprised we haven't gotten more complaints about this > over the years. > - We add some logic into TSK so that it looks for a .000 if .001 was given > and uses that instead as the starting location. > > > > > On Wed, Aug 9, 2017 at 3:30 PM, Nanni Bassetti <dig...@gm...> wrote: > >> Yes! it works in that way...but it's a strange behavior :-) >> Thank you >> >> 2017-08-09 21:22 GMT+02:00 Ann Priestman <apr...@ba...>: >> >>> Sorry what I meant was: >>> - go through the Autopsy data source selection >>> - when you browse to your folder, it will display the .001 file as the >>> only choice >>> - change the filter to All files to make it show everything in the >>> folder and then select the .000 file >>> >>> Sent from my iPhone >>> >>> On Aug 9, 2017, at 3:11 PM, Nanni Bassetti <dig...@gm...> wrote: >>> >>> Anyway...I tried and nothing to do! :-) >>> >>> 2017-08-09 21:08 GMT+02:00 Nanni Bassetti <dig...@gm...>: >>> >>>> >>>> 2017-08-09 20:56 GMT+02:00 Ann Priestman <apr...@ba...>: >>>> >>>>> Hi Nanni, >>>>> >>>>> On the Autopsy select data source screen, try changing the given file >>>>> name "E001SmartTVMMC.001" to "E001SmartTVMMC.000". The file system loaded >>>>> for me after that change. >>>>> >>>> >>>> And what have I to do with the original E001SmartTVMMC.000? If I >>>> rename the .001 to .000 what's about the .000 file? >>>> Thanks >>>> >>>> >>>> >>>> -- >>>> Dott. Nanni Bassetti >>>> http://www.nannibassetti.com >>>> CAINE project manager - http://www.caine-live.net >>>> >>> >>> >>> >>> -- >>> Dott. Nanni Bassetti >>> http://www.nannibassetti.com >>> CAINE project manager - http://www.caine-live.net >>> >>> >> >> >> -- >> Dott. Nanni Bassetti >> http://www.nannibassetti.com >> CAINE project manager - http://www.caine-live.net >> >> ------------------------------------------------------------ >> ------------------ >> Check out the vibrant tech community on one of the world's most >> engaging tech sites, Slashdot.org! http://sdm.link/slashdot >> _______________________________________________ >> sleuthkit-users mailing list >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >> http://www.sleuthkit.org >> >> > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > -- ---- Barry Grundy bg...@gm... bg...@li... |
From: Brian C. <ca...@sl...> - 2017-08-10 03:10:15
|
Hi Nanni, How did you make the image? Autopsy has an assumption that .001 is the first image in a split set of images and doesn't expect 000. The file picker in Autopsy therefore just shows .001 files and hides the rest. When it looks at your .001 file, it isn't happy because it isn't the start of a disk image. Though, as I think about this... 'split' will use .000 as the first file. Does FTK Imager use .001? I'm now wondering how we picked '.001' (and have so many '.001 files in our test data). The options here seem to be: - We decide that .001 is not a common starting number and it should really be 000. Though I"m surprised we haven't gotten more complaints about this over the years. - We add some logic into TSK so that it looks for a .000 if .001 was given and uses that instead as the starting location. On Wed, Aug 9, 2017 at 3:30 PM, Nanni Bassetti <dig...@gm...> wrote: > Yes! it works in that way...but it's a strange behavior :-) > Thank you > > 2017-08-09 21:22 GMT+02:00 Ann Priestman <apr...@ba...>: > >> Sorry what I meant was: >> - go through the Autopsy data source selection >> - when you browse to your folder, it will display the .001 file as the >> only choice >> - change the filter to All files to make it show everything in the folder >> and then select the .000 file >> >> Sent from my iPhone >> >> On Aug 9, 2017, at 3:11 PM, Nanni Bassetti <dig...@gm...> wrote: >> >> Anyway...I tried and nothing to do! :-) >> >> 2017-08-09 21:08 GMT+02:00 Nanni Bassetti <dig...@gm...>: >> >>> >>> 2017-08-09 20:56 GMT+02:00 Ann Priestman <apr...@ba...>: >>> >>>> Hi Nanni, >>>> >>>> On the Autopsy select data source screen, try changing the given file >>>> name "E001SmartTVMMC.001" to "E001SmartTVMMC.000". The file system loaded >>>> for me after that change. >>>> >>> >>> And what have I to do with the original E001SmartTVMMC.000? If I rename >>> the .001 to .000 what's about the .000 file? >>> Thanks >>> >>> >>> >>> -- >>> Dott. Nanni Bassetti >>> http://www.nannibassetti.com >>> CAINE project manager - http://www.caine-live.net >>> >> >> >> >> -- >> Dott. Nanni Bassetti >> http://www.nannibassetti.com >> CAINE project manager - http://www.caine-live.net >> >> > > > -- > Dott. Nanni Bassetti > http://www.nannibassetti.com > CAINE project manager - http://www.caine-live.net > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > |
From: Ann P. <apr...@ba...> - 2017-08-09 19:50:48
|
Sorry what I meant was: - go through the Autopsy data source selection - when you browse to your folder, it will display the .001 file as the only choice - change the filter to All files to make it show everything in the folder and then select the .000 file Sent from my iPhone > On Aug 9, 2017, at 3:11 PM, Nanni Bassetti <dig...@gm...> wrote: > > Anyway...I tried and nothing to do! :-) > > 2017-08-09 21:08 GMT+02:00 Nanni Bassetti <dig...@gm...>: >> >> 2017-08-09 20:56 GMT+02:00 Ann Priestman <apr...@ba...>: >>> Hi Nanni, >>> >>> On the Autopsy select data source screen, try changing the given file name "E001SmartTVMMC.001" to "E001SmartTVMMC.000". The file system loaded for me after that change. >> >> And what have I to do with the original E001SmartTVMMC.000? If I rename the .001 to .000 what's about the .000 file? >> Thanks >> >> >> >> -- >> Dott. Nanni Bassetti >> http://www.nannibassetti.com >> CAINE project manager - http://www.caine-live.net > > > > -- > Dott. Nanni Bassetti > http://www.nannibassetti.com > CAINE project manager - http://www.caine-live.net |
From: Nanni B. <dig...@gm...> - 2017-08-09 19:30:34
|
Yes! it works in that way...but it's a strange behavior :-) Thank you 2017-08-09 21:22 GMT+02:00 Ann Priestman <apr...@ba...>: > Sorry what I meant was: > - go through the Autopsy data source selection > - when you browse to your folder, it will display the .001 file as the > only choice > - change the filter to All files to make it show everything in the folder > and then select the .000 file > > Sent from my iPhone > > On Aug 9, 2017, at 3:11 PM, Nanni Bassetti <dig...@gm...> wrote: > > Anyway...I tried and nothing to do! :-) > > 2017-08-09 21:08 GMT+02:00 Nanni Bassetti <dig...@gm...>: > >> >> 2017-08-09 20:56 GMT+02:00 Ann Priestman <apr...@ba...>: >> >>> Hi Nanni, >>> >>> On the Autopsy select data source screen, try changing the given file >>> name "E001SmartTVMMC.001" to "E001SmartTVMMC.000". The file system loaded >>> for me after that change. >>> >> >> And what have I to do with the original E001SmartTVMMC.000? If I rename >> the .001 to .000 what's about the .000 file? >> Thanks >> >> >> >> -- >> Dott. Nanni Bassetti >> http://www.nannibassetti.com >> CAINE project manager - http://www.caine-live.net >> > > > > -- > Dott. Nanni Bassetti > http://www.nannibassetti.com > CAINE project manager - http://www.caine-live.net > > -- Dott. Nanni Bassetti http://www.nannibassetti.com CAINE project manager - http://www.caine-live.net |
From: Ann P. <apr...@ba...> - 2017-08-09 19:29:23
|
Hi Nanni, On the Autopsy select data source screen, try changing the given file name "E001SmartTVMMC.001" to "E001SmartTVMMC.000". The file system loaded for me after that change. On Wed, Aug 9, 2017 at 1:40 PM, Nanni Bassetti <dig...@gm...> wrote: > Hi guys, > I tried to open the image of the SmartTV-Raspberry > https://nas.cybercrimetech.com/owncloud/s/0uYLgzmvyQZ8CDW > > 001-SmartTV-RaspberryPi.zip > > Autopsy 4.4.1 in Windows 10 64-bit does not open it because: > "Errors occurred while ingesting image 1. Cannot determine file system > type (Sector offset: 0) " > > But, with FTK Imager Lite V. 3.1.1.8 I can see all files and I can mount > the image file. > > Please check it. :-) > Thanks > > -- > Dott. Nanni Bassetti > http://www.nannibassetti.com > CAINE project manager - http://www.caine-live.net > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > |
From: Nanni B. <dig...@gm...> - 2017-08-09 19:11:44
|
Anyway...I tried and nothing to do! :-) 2017-08-09 21:08 GMT+02:00 Nanni Bassetti <dig...@gm...>: > > 2017-08-09 20:56 GMT+02:00 Ann Priestman <apr...@ba...>: > >> Hi Nanni, >> >> On the Autopsy select data source screen, try changing the given file >> name "E001SmartTVMMC.001" to "E001SmartTVMMC.000". The file system loaded >> for me after that change. >> > > And what have I to do with the original E001SmartTVMMC.000? If I rename > the .001 to .000 what's about the .000 file? > Thanks > > > > -- > Dott. Nanni Bassetti > http://www.nannibassetti.com > CAINE project manager - http://www.caine-live.net > -- Dott. Nanni Bassetti http://www.nannibassetti.com CAINE project manager - http://www.caine-live.net |
From: Nanni B. <dig...@gm...> - 2017-08-09 19:09:04
|
2017-08-09 20:56 GMT+02:00 Ann Priestman <apr...@ba...>: > Hi Nanni, > > On the Autopsy select data source screen, try changing the given file name > "E001SmartTVMMC.001" to "E001SmartTVMMC.000". The file system loaded for me > after that change. > And what have I to do with the original E001SmartTVMMC.000? If I rename the .001 to .000 what's about the .000 file? Thanks -- Dott. Nanni Bassetti http://www.nannibassetti.com CAINE project manager - http://www.caine-live.net |
From: Nanni B. <dig...@gm...> - 2017-08-09 17:40:19
|
Hi guys, I tried to open the image of the SmartTV-Raspberry https://nas.cybercrimetech.com/owncloud/s/0uYLgzmvyQZ8CDW 001-SmartTV-RaspberryPi.zip Autopsy 4.4.1 in Windows 10 64-bit does not open it because: "Errors occurred while ingesting image 1. Cannot determine file system type (Sector offset: 0) " But, with FTK Imager Lite V. 3.1.1.8 I can see all files and I can mount the image file. Please check it. :-) Thanks -- Dott. Nanni Bassetti http://www.nannibassetti.com CAINE project manager - http://www.caine-live.net |
From: Hoyt H. <hoy...@gm...> - 2017-07-20 14:22:58
|
There's a Sleuth Kit forum user asking about screen readers and Java's access bridge. Accessibility for forensic tools is a topic of interest for me, so I thought I'd ask about this here. In the forum post, the user mentions that he/she is using the NVDA screen reader, but it doesn't seem to be picking up anything from Autopsy. What sort of development goals for accessibility are there for TSK/Autopsy? Has there been compatibility testing with accessibility tools (i.e. screen readers, magnifiers, etc.) and are there any recommendations for one or more tools over others? I'm just curious at this point more than anything. -- Hoyt ----------------- There are 11 kinds of people - those who think binary jokes are funny, those who don't, ...and those who don't know binary. |
From: Jon S. <JSt...@St...> - 2017-07-14 22:28:03
|
Travis CI can be a useful tool for checking Linux builds. It has good GitHub integration, so a push to GitHub can trigger a new build of a branch and then GitHub will display whether the build is working on the PR screen. I use Jenkins in a similar manner to manage my projects, but Travis CI is a good lightweight solution, and it's free for open source projects. IMNSHO, it's essential to use automated tooling like this when working with nontrivial cross-platform builds. Jon > -----Original Message----- > From: Hoyt Harness [mailto:hoy...@gm...] > Sent: Friday, July 14, 2017 5:41 PM > To: Adam Dershowitz <de...@al...> > Cc: Brian Carrier <ca...@sl...>; sleuthkit-users <sleuthkit- > us...@li...> > Subject: Re: [sleuthkit-users] Linux Autopsy and Packaging > > For those not aware of the issues... > > Autopsy still sometimes exhibits compile errors depending on which > branches were used as source for both Autopsy and The Sleuth Kit. So > far, no one really understands why as far as I know, but the master > branches of each one seem to work together and correctly compile more > often than the develop branches. I'll need to review my emails from > Richard to remember what the latest status of this is. > > Getting Autopsy to consistently compile on Linux or Mac is only part of > the challenge. Some of the included dependencies, such as Photorec, are > Windows binaries. To also include *NIX binaries increases installer > bloat since everyone gets everything, whether you need it or not. It's > pretty big at it is. Making those binaries additional downloads at > installation time changes how the Windows installation works currently, > which might upset folks who depend on that part remaining the same. > > The best option in my mind is to leave the Windows install routine alone > and trigger the prerequisite downloads/installs of the *NIX dependencies > when the deb/rpm/dmg install file runs. One problem there is insuring > the right version of those dependencies. Older versions of some might be > tricky or impossible to get for various reasons, which would result in a > failed or broken install. If the dependencies are ok, Autopsy has to > call those and not the ones for a Windows environment. Java logic to > determine the client OS is already there, so a little code in the right > places to choose the OS-specific binary based on that is all that's > needed. > > It's just not a straightforward proposition unfortunately and the > solution can't introduce regressions. Then again, challenges are what > makes life fun. Also, I'm not with Basis. I've just spent a lot of time > on this. > > On Jul 14, 2017 12:21 PM, "Adam Dershowitz" <de...@al... > <mailto:de...@al...> > wrote: > > > That is great news. I am very glad that hear that the Mac version > is not completely gone! I do wish you luck, and look forward to again > having Mac and Linux support. > > > --Adam > > > > > On Jul 14, 2017, at 11:58 AM, Hoyt Harness > <hoy...@gm... <mailto:hoy...@gm...> > wrote: > > I'm definitely working on both Linux and Mac porting. I've > been otherwise occupied lately with retirement coming up fast and > haven't had as much time to work on it. Right now, I'm working on those > WIN binaries and specific scripts (Photorec, RegRipper, etc.). I'll be > testing a debian packaging option (soon I hope) that will pull in those > dependencies instead of requiring them as includes in the Autopsy > package. I stay in touch with both Richard and Jonathan all the way > through. I won't likely have much time until after August 1st and even > then I've got to figure out where my donut money will be coming from. > Regardless, I won't give up and I'd love to work with Barry and anyone > else interested. > > Hoyt > > On Tue, Jul 11, 2017 at 7:57 PM, Barry Grundy > <bg...@gm... <mailto:bg...@gm...> > wrote: > > > I'd love to help out. I package quite a few forensic > programs for Slackware, but I'm not a programmer and I rely a ton on > documentation. But if I can assist, I'd be happy to contribute to the > conversation. > > Barry > > On Tue, Jul 11, 2017 at 4:18 PM, Brian Carrier > <ca...@sl... <mailto:ca...@sl...> > wrote: > > > The topic of getting Autopsy packaged up on a Linux > distro has come up again and I wanted to reach out to see who was > building Autopsy on Linux and who was doing packaging work so that we > can all work together and make this happen. can you let me know if you > can help out in either? > > > I made a github issues > <https://github.com/sleuthkit/autopsy/issues/2938> to track the > development results. > > > thanks, > > brian > > > --------------------------------------------------- > --------------------------- > Check out the vibrant tech community on one of the > world's most > engaging tech sites, Slashdot.org > <http://Slashdot.org> ! http://sdm.link/slashdot > _______________________________________________ > sleuthkit-users mailing list > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> > http://www.sleuthkit.org > <http://www.sleuthkit.org/> > > > > > > > > -- > > ---- > Barry Grundy > bg...@gm... <mailto:bg...@gm...> > bg...@li... <mailto:bg...@li...> > > -------------------------------------------------------- > ---------------------- > Check out the vibrant tech community on one of the > world's most > engaging tech sites, Slashdot.org <http://Slashdot.org> > ! http://sdm.link/slashdot > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit- > users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> > http://www.sleuthkit.org <http://www.sleuthkit.org/> > > > > > > > -- > > Hoyt > ----------------- > There are 11 kinds of people - those who think binary jokes > are funny, those who don't, ...and those who don't know binary. > ------------------------------------------------------------- > ----------------- > Check out the vibrant tech community on one of the world's > most > engaging tech sites, Slashdot.org <http://Slashdot.org> ! > http://sdm.link/slashdot_______________________________________________ > <http://sdm.link/slashdot_______________________________________________ > > > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> > http://www.sleuthkit.org > > |
From: Hoyt H. <hoy...@gm...> - 2017-07-14 21:41:08
|
For those not aware of the issues... Autopsy still sometimes exhibits compile errors depending on which branches were used as source for both Autopsy and The Sleuth Kit. So far, no one really understands why as far as I know, but the master branches of each one seem to work together and correctly compile more often than the develop branches. I'll need to review my emails from Richard to remember what the latest status of this is. Getting Autopsy to consistently compile on Linux or Mac is only part of the challenge. Some of the included dependencies, such as Photorec, are Windows binaries. To also include *NIX binaries increases installer bloat since everyone gets everything, whether you need it or not. It's pretty big at it is. Making those binaries additional downloads at installation time changes how the Windows installation works currently, which might upset folks who depend on that part remaining the same. The best option in my mind is to leave the Windows install routine alone and trigger the prerequisite downloads/installs of the *NIX dependencies when the deb/rpm/dmg install file runs. One problem there is insuring the right version of those dependencies. Older versions of some might be tricky or impossible to get for various reasons, which would result in a failed or broken install. If the dependencies are ok, Autopsy has to call those and not the ones for a Windows environment. Java logic to determine the client OS is already there, so a little code in the right places to choose the OS-specific binary based on that is all that's needed. It's just not a straightforward proposition unfortunately and the solution can't introduce regressions. Then again, challenges are what makes life fun. Also, I'm not with Basis. I've just spent a lot of time on this. On Jul 14, 2017 12:21 PM, "Adam Dershowitz" <de...@al...> wrote: > That is great news. I am very glad that hear that the Mac version is not > completely gone! I do wish you luck, and look forward to again having Mac > and Linux support. > > --Adam > > > > On Jul 14, 2017, at 11:58 AM, Hoyt Harness <hoy...@gm...> wrote: > > I'm definitely working on both Linux and Mac porting. I've been otherwise > occupied lately with retirement coming up fast and haven't had as much time > to work on it. Right now, I'm working on those WIN binaries and specific > scripts (Photorec, RegRipper, etc.). I'll be testing a debian packaging > option (soon I hope) that will pull in those dependencies instead of > requiring them as includes in the Autopsy package. I stay in touch with > both Richard and Jonathan all the way through. I won't likely have much > time until after August 1st and even then I've got to figure out where my > donut money will be coming from. Regardless, I won't give up and I'd love > to work with Barry and anyone else interested. > > Hoyt > > On Tue, Jul 11, 2017 at 7:57 PM, Barry Grundy <bg...@gm...> wrote: > >> I'd love to help out. I package quite a few forensic programs for >> Slackware, but I'm not a programmer and I rely a ton on documentation. But >> if I can assist, I'd be happy to contribute to the conversation. >> >> Barry >> >> On Tue, Jul 11, 2017 at 4:18 PM, Brian Carrier <ca...@sl...> >> wrote: >> >>> The topic of getting Autopsy packaged up on a Linux distro has come up >>> again and I wanted to reach out to see who was building Autopsy on Linux >>> and who was doing packaging work so that we can all work together and make >>> this happen. can you let me know if you can help out in either? >>> >>> I made a github issues >>> <https://github.com/sleuthkit/autopsy/issues/2938> to track the >>> development results. >>> >>> thanks, >>> brian >>> >>> ------------------------------------------------------------ >>> ------------------ >>> Check out the vibrant tech community on one of the world's most >>> engaging tech sites, Slashdot.org! http://sdm.link/slashdot >>> _______________________________________________ >>> sleuthkit-users mailing list >>> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >>> http://www.sleuthkit.org >>> >>> >> >> >> -- >> ---- >> Barry Grundy >> bg...@gm... >> bg...@li... >> >> ------------------------------------------------------------ >> ------------------ >> Check out the vibrant tech community on one of the world's most >> engaging tech sites, Slashdot.org! http://sdm.link/slashdot >> _______________________________________________ >> sleuthkit-users mailing list >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >> http://www.sleuthkit.org >> >> > > > -- > Hoyt > ----------------- > There are 11 kinds of people - those who think binary jokes are funny, > those who don't, ...and those who don't know binary. > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot______ > _________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > > |
From: Adam D. <de...@al...> - 2017-07-14 17:21:51
|
That is great news. I am very glad that hear that the Mac version is not completely gone! I do wish you luck, and look forward to again having Mac and Linux support. --Adam > On Jul 14, 2017, at 11:58 AM, Hoyt Harness <hoy...@gm...> wrote: > > I'm definitely working on both Linux and Mac porting. I've been otherwise occupied lately with retirement coming up fast and haven't had as much time to work on it. Right now, I'm working on those WIN binaries and specific scripts (Photorec, RegRipper, etc.). I'll be testing a debian packaging option (soon I hope) that will pull in those dependencies instead of requiring them as includes in the Autopsy package. I stay in touch with both Richard and Jonathan all the way through. I won't likely have much time until after August 1st and even then I've got to figure out where my donut money will be coming from. Regardless, I won't give up and I'd love to work with Barry and anyone else interested. > > Hoyt > > On Tue, Jul 11, 2017 at 7:57 PM, Barry Grundy <bg...@gm... <mailto:bg...@gm...>> wrote: > I'd love to help out. I package quite a few forensic programs for Slackware, but I'm not a programmer and I rely a ton on documentation. But if I can assist, I'd be happy to contribute to the conversation. > > Barry > > On Tue, Jul 11, 2017 at 4:18 PM, Brian Carrier <ca...@sl... <mailto:ca...@sl...>> wrote: > The topic of getting Autopsy packaged up on a Linux distro has come up again and I wanted to reach out to see who was building Autopsy on Linux and who was doing packaging work so that we can all work together and make this happen. can you let me know if you can help out in either? > > I made a github issues <https://github.com/sleuthkit/autopsy/issues/2938> to track the development results. > > thanks, > brian > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot <http://sdm.link/slashdot> > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> > http://www.sleuthkit.org <http://www.sleuthkit.org/> > > > > > -- > ---- > Barry Grundy > bg...@gm... <mailto:bg...@gm...> > bg...@li... <mailto:bg...@li...> > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot <http://sdm.link/slashdot> > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> > http://www.sleuthkit.org <http://www.sleuthkit.org/> > > > > > -- > Hoyt > ----------------- > There are 11 kinds of people - those who think binary jokes are funny, those who don't, ...and those who don't know binary. > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot_______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Hoyt H. <hoy...@gm...> - 2017-07-14 15:59:13
|
I'm definitely working on both Linux and Mac porting. I've been otherwise occupied lately with retirement coming up fast and haven't had as much time to work on it. Right now, I'm working on those WIN binaries and specific scripts (Photorec, RegRipper, etc.). I'll be testing a debian packaging option (soon I hope) that will pull in those dependencies instead of requiring them as includes in the Autopsy package. I stay in touch with both Richard and Jonathan all the way through. I won't likely have much time until after August 1st and even then I've got to figure out where my donut money will be coming from. Regardless, I won't give up and I'd love to work with Barry and anyone else interested. Hoyt On Tue, Jul 11, 2017 at 7:57 PM, Barry Grundy <bg...@gm...> wrote: > I'd love to help out. I package quite a few forensic programs for > Slackware, but I'm not a programmer and I rely a ton on documentation. But > if I can assist, I'd be happy to contribute to the conversation. > > Barry > > On Tue, Jul 11, 2017 at 4:18 PM, Brian Carrier <ca...@sl...> > wrote: > >> The topic of getting Autopsy packaged up on a Linux distro has come up >> again and I wanted to reach out to see who was building Autopsy on Linux >> and who was doing packaging work so that we can all work together and make >> this happen. can you let me know if you can help out in either? >> >> I made a github issues <https://github.com/sleuthkit/autopsy/issues/2938> >> to track the development results. >> >> thanks, >> brian >> >> ------------------------------------------------------------ >> ------------------ >> Check out the vibrant tech community on one of the world's most >> engaging tech sites, Slashdot.org! http://sdm.link/slashdot >> _______________________________________________ >> sleuthkit-users mailing list >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >> http://www.sleuthkit.org >> >> > > > -- > ---- > Barry Grundy > bg...@gm... > bg...@li... > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > -- Hoyt ----------------- There are 11 kinds of people - those who think binary jokes are funny, those who don't, ...and those who don't know binary. |
From: Barry G. <bg...@gm...> - 2017-07-12 00:57:18
|
I'd love to help out. I package quite a few forensic programs for Slackware, but I'm not a programmer and I rely a ton on documentation. But if I can assist, I'd be happy to contribute to the conversation. Barry On Tue, Jul 11, 2017 at 4:18 PM, Brian Carrier <ca...@sl...> wrote: > The topic of getting Autopsy packaged up on a Linux distro has come up > again and I wanted to reach out to see who was building Autopsy on Linux > and who was doing packaging work so that we can all work together and make > this happen. can you let me know if you can help out in either? > > I made a github issues <https://github.com/sleuthkit/autopsy/issues/2938> > to track the development results. > > thanks, > brian > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > -- ---- Barry Grundy bg...@gm... bg...@li... |
From: Brian C. <ca...@sl...> - 2017-07-11 20:19:00
|
The topic of getting Autopsy packaged up on a Linux distro has come up again and I wanted to reach out to see who was building Autopsy on Linux and who was doing packaging work so that we can all work together and make this happen. can you let me know if you can help out in either? I made a github issues <https://github.com/sleuthkit/autopsy/issues/2938> to track the development results. thanks, brian |
From: Brian C. <ca...@sl...> - 2017-07-11 20:10:37
|
Hello All, OSDFCon voting ends Friday July 14. If you haven't voted for your favorite talks yet, you can do so here: https://www.surveymonkey.com/r/voteosdfcon brian |
From: Joann H. <joj...@gm...> - 2017-07-04 02:01:40
|
Hi. Mailing list response. On Jul 3, 2017 6:09 AM, <sle...@li...> wrote: > Send sleuthkit-users mailing list submissions to > sle...@li... > > To subscribe or unsubscribe via the World Wide Web, visit > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > or, via email, send a message with subject or body 'help' to > sle...@li... > > You can reach the person managing the list at > sle...@li... > > When replying, please edit your Subject line so it is more specific > than "Re: Contents of sleuthkit-users digest..." > > > Today's Topics: > > 1. Re: Libevtx Prebuilt DLL (Derrick Karpo) > > > ---------------------------------------------------------------------- > > Message: 1 > Date: Sun, 2 Jul 2017 13:43:45 -0600 > From: Derrick Karpo <dk...@gm...> > To: Nick Flower <nic...@gm...> > Cc: "sle...@li..." > <sle...@li...> > Subject: Re: [sleuthkit-users] Libevtx Prebuilt DLL > Message-ID: > <CAMDiSGRj5FT6RHX40CtzDZNxLMpzYM-NEy4SSk7nDHSC1m65-w@mail. > gmail.com> > Content-Type: text/plain; charset="UTF-8" > > I haven't seen any! If you followed Joachim's excellent build > instructions, and it's still giving you issues, I'd fire him off an > email. > > https://github.com/libyal/libevtx/wiki/Building > > Derrick > > > On Sat, Jul 1, 2017 at 5:48 PM, Nick Flower <nic...@gm...> wrote: > > Are there any pre-built Libevtx .dll?s floating around out there? > > > > I can?t get it to build properly on Windows, so I?m hoping a prebuilt one > > will be sufficient. > > > > > > > > I know this is likely the wrong place to ask ? if there?s a better place, > > please let me know. > > > > > > > > > > ------------------------------------------------------------ > ------------------ > > Check out the vibrant tech community on one of the world's most > > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > > _______________________________________________ > > sleuthkit-users mailing list > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > http://www.sleuthkit.org > > > > > > ------------------------------ > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > > ------------------------------ > > Subject: Digest Footer > > _______________________________________________ > sleuthkit-users mailing list > sle...@li... > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > > ------------------------------ > > End of sleuthkit-users Digest, Vol 133, Issue 2 > *********************************************** > |