Monday, July 14, 2008

Flesh Colored Mole On Head

0.2 beta released PTK PTK

After two months of work has been released the second beta version of PTK. Development activities focused on the keyword search that has been integrated with the Live search form . PTK is therefore now able to search either on the basis of indexed (Garat results in real time), you ain sull'evidence imported live mode. The live search warrant the identification of strings within the slack space or portions of fragmented files. PTK has successfully passed all the tests proposed by DFTT in terms of search strings on NTFS, FAT and EXT3.

New enhancements were also introduced for the installation part. Now in fact the user can install PTK using a convenient Web interface without having to worry about the configuration of the instrument. The new installation process addresses several compatibility issues that may arise through the use of different Linux distrubution.

To download, please refer to the project page on Source Forge: http://sourceforge.net/projects/ptk-forensics/

to install the necessary steps are now only 3: 1

- Remove within the archive directory for apache. (/ Var / www /, / var / www / htdocs, / var / www / localhost /)

2 - Using the browser open the following link http://localhost/ptk/install.php

3 - Fill in the fields to finish the installation process


Wednesday, July 9, 2008

Ankle Hurt Woodland Shoe

7 July 2008 submitted to Digital Investigations ISSA 2008 Conference, Johannesburg SA, PTK

Topic of presentation:
Advances in Digital Investigations: Research
, open source and commercial tools.

The version presented is the PTK beta 2, filled with many additional features including the system of keyword searching, now completed and fully functional. The research section of PTK has passed all the tests of DFTT keyword searching and allows you to get results in a very short time thanks to the pre-processing the image.

The second beta will be released July 15 and, in addition to keyword search system, contains many other features such as new optimized and fully automated installer, new features of bookmarking and analysis.

The new presentation is available here .

Tuesday, July 1, 2008

Ford Laser Stereo Wiring Diagram

and Digital Forensics Tool Testing Image (# 2)

FAT Keyword Search ( passed )

The test this week rigurda keyword searches within a FAT file system. Obviously the 20 questions posed by DFTT provide for detection of strings in these situations:
  • space allocated
  • unallocated space
  • crossed two lines (of file allocated and unallocated)
  • within the slack space (allocated and unallocated files)
  • searches using regular expressions.
PTK solve all the 20 tests making use of both features of indexed search, very useful for content allocated, both the Live Search instead complete the research where the indexed does not come. Both types of research provide the opportunity to work with regular expressions, it is obvious that research on the basis provides response times indexed in almost real-time even on high volumes of data.
offer an example of searching using regular expression in relation to Question # 17: