Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Aggregating Temporal Forensic Data Across Archival Digital Media

Aggregating Temporal Forensic Data Across Archival Digital Media

This presentation describes the benefits of aggregating timestamp metadata across multiple floppy disks in a single collection. Presented at the Digital Heritage 2015 conference in Granada, Spain.

Walker Sampson

October 02, 2015
Tweet

More Decks by Walker Sampson

Other Decks in Technology

Transcript

  1. Guymager ∙ dcfldd ∙ cdrdao ∙ bulk_extractor ∙ bulk_extractor Viewer

    ∙ fiwalk ∙ The Sleuth Kit ∙ libewf ∙ AFFLIB ∙ pyExifToolGUI ∙ ClamAV / ClamTK ∙ FSlint ∙ sdhash ∙ HFS Utilities ∙ FITS ∙ readpst ∙ recoll ∙ GTK Hash ∙ GHex ∙ Safe Mount
  2. File System Events 0 500 1000 1500 2000 1980 1984

    1986 1988 1990 1992 1994 1996 1998 2000 2002 2004 2008 2010 2012 Last modified (HFS) Last written Last accessed Created
  3. Conclusions • Often “dormant” data
 • Research usually
 not in

    a legal context
 • Builds on existing
 best practice