<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Breaking Forensic Images Booted as a Virtual Machine</title>
	<atom:link href="http://www.anti-forensics.com/breaking-forensic-images-booted-as-a-virtual-machine/feed" rel="self" type="application/rss+xml" />
	<link>http://www.anti-forensics.com/breaking-forensic-images-booted-as-a-virtual-machine</link>
	<description>Rendering computer investigations irrelevant</description>
	<lastBuildDate>Wed, 01 Sep 2010 22:00:29 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: KenTheFurry</title>
		<link>http://www.anti-forensics.com/breaking-forensic-images-booted-as-a-virtual-machine/comment-page-1#comment-218</link>
		<dc:creator>KenTheFurry</dc:creator>
		<pubDate>Wed, 14 Apr 2010 12:24:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=228#comment-218</guid>
		<description>Wouldn&#039;t this also mess up the chain of evidence?
If they decided to remove the program so they could look around and they got evidence from their &quot;edited&quot; copy, couldn&#039;t a good lawyer say they added what ever they found themself&#039;s because of the modified hash?

But it probably wouldn&#039;t be that hard for them to explain them selfs; all it takes is one juror.</description>
		<content:encoded><![CDATA[<p>Wouldn&#8217;t this also mess up the chain of evidence?<br />
If they decided to remove the program so they could look around and they got evidence from their &#8220;edited&#8221; copy, couldn&#8217;t a good lawyer say they added what ever they found themself&#8217;s because of the modified hash?</p>
<p>But it probably wouldn&#8217;t be that hard for them to explain them selfs; all it takes is one juror.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yar</title>
		<link>http://www.anti-forensics.com/breaking-forensic-images-booted-as-a-virtual-machine/comment-page-1#comment-41</link>
		<dc:creator>Yar</dc:creator>
		<pubDate>Fri, 20 Mar 2009 03:12:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=228#comment-41</guid>
		<description>Sure Bob. LinEn is the free Linux acquisition tool from Guidance. The HELIX3 distribution does contain it but I believe HELIX3 has just gone to a paid monthly subscription. 

You can download LinEn itself from here: http://www.guidancesoftware.com/support/LinEn_LicenseAgreement.aspx

Then you can run it from a terminal in a Linux environment.</description>
		<content:encoded><![CDATA[<p>Sure Bob. LinEn is the free Linux acquisition tool from Guidance. The HELIX3 distribution does contain it but I believe HELIX3 has just gone to a paid monthly subscription. </p>
<p>You can download LinEn itself from here: <a href="http://www.guidancesoftware.com/support/LinEn_LicenseAgreement.aspx">http://www.guidancesoftware.com/support/LinEn_LicenseAgreement.aspx</a></p>
<p>Then you can run it from a terminal in a Linux environment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Bolin</title>
		<link>http://www.anti-forensics.com/breaking-forensic-images-booted-as-a-virtual-machine/comment-page-1#comment-38</link>
		<dc:creator>Bob Bolin</dc:creator>
		<pubDate>Fri, 20 Mar 2009 00:45:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=228#comment-38</guid>
		<description>Can anyone suggest where I can download a copy of the Encase LinEn iso for free?  Just for research, I&#039;m not a forensics man after tools on the cheap! :D</description>
		<content:encoded><![CDATA[<p>Can anyone suggest where I can download a copy of the Encase LinEn iso for free?  Just for research, I&#8217;m not a forensics man after tools on the cheap! <img src='http://www.anti-forensics.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Doe</title>
		<link>http://www.anti-forensics.com/breaking-forensic-images-booted-as-a-virtual-machine/comment-page-1#comment-29</link>
		<dc:creator>John Doe</dc:creator>
		<pubDate>Tue, 17 Mar 2009 20:28:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=228#comment-29</guid>
		<description>Nice article! Thanks for the source, will play around with it a bit :)

Currently looking into anti-vm techniques. Here an interesting document: 
http://handlers.sans.org/tliston/ThwartingVMDetection_Liston_Skoudis.pdf</description>
		<content:encoded><![CDATA[<p>Nice article! Thanks for the source, will play around with it a bit <img src='http://www.anti-forensics.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Currently looking into anti-vm techniques. Here an interesting document:<br />
<a href="http://handlers.sans.org/tliston/ThwartingVMDetection_Liston_Skoudis.pdf">http://handlers.sans.org/tliston/ThwartingVMDetection_Liston_Skoudis.pdf</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yar</title>
		<link>http://www.anti-forensics.com/breaking-forensic-images-booted-as-a-virtual-machine/comment-page-1#comment-15</link>
		<dc:creator>Yar</dc:creator>
		<pubDate>Tue, 10 Mar 2009 23:45:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=228#comment-15</guid>
		<description>Hey PC646, thanks for the encouragement :]

If you are using the free FTK imager to image your drives then they&#039;ll be in DD or raw format. This is what LiveView requires in conjunction with an installation of VMWare. 

You can use the free VMWare server or Workstation. I have used the free server version but prefer workstation with live view as it seems to be less buggy.

LiveView is free and can be downloaded here: http://liveview.sourceforge.net/

It supports:
Windows 2008, Vista, 2003, XP, 2000, NT, Me, 98
Linux (limited support)

There are other products, one being Mount Image Pro which works great and supports EnCase format disk images as well (.E0*) that you would get using Linen or Encase to do your acquisition.

LiveView is very easy to use once you mess around with it a bit. It&#039;s basically just: 
1. Add all images to path
2. Create directory for VMWare and LiveView temp files
3. Set RAM to desired level
4. Start it

I&#039;ve used both LiveView and MountImagePro a lot and I have to say I love both.</description>
		<content:encoded><![CDATA[<p>Hey PC646, thanks for the encouragement :]</p>
<p>If you are using the free FTK imager to image your drives then they&#8217;ll be in DD or raw format. This is what LiveView requires in conjunction with an installation of VMWare. </p>
<p>You can use the free VMWare server or Workstation. I have used the free server version but prefer workstation with live view as it seems to be less buggy.</p>
<p>LiveView is free and can be downloaded here: <a href="http://liveview.sourceforge.net/">http://liveview.sourceforge.net/</a></p>
<p>It supports:<br />
Windows 2008, Vista, 2003, XP, 2000, NT, Me, 98<br />
Linux (limited support)</p>
<p>There are other products, one being Mount Image Pro which works great and supports EnCase format disk images as well (.E0*) that you would get using Linen or Encase to do your acquisition.</p>
<p>LiveView is very easy to use once you mess around with it a bit. It&#8217;s basically just:<br />
1. Add all images to path<br />
2. Create directory for VMWare and LiveView temp files<br />
3. Set RAM to desired level<br />
4. Start it</p>
<p>I&#8217;ve used both LiveView and MountImagePro a lot and I have to say I love both.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PC646</title>
		<link>http://www.anti-forensics.com/breaking-forensic-images-booted-as-a-virtual-machine/comment-page-1#comment-14</link>
		<dc:creator>PC646</dc:creator>
		<pubDate>Tue, 10 Mar 2009 22:21:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=228#comment-14</guid>
		<description>I use FTK imager for my own copies, but how do I convert an image file into a functioning os on vmware? Can you point me in the right direction. Love your site, keep up the good work.</description>
		<content:encoded><![CDATA[<p>I use FTK imager for my own copies, but how do I convert an image file into a functioning os on vmware? Can you point me in the right direction. Love your site, keep up the good work.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
