<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Anti-Forensics &#187; Hex Editing</title>
	<atom:link href="http://www.anti-forensics.com/category/general-topics/hex-edit/feed" rel="self" type="application/rss+xml" />
	<link>http://www.anti-forensics.com</link>
	<description>Rendering computer investigations irrelevant</description>
	<lastBuildDate>Thu, 15 Dec 2011 07:57:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Windows Hibernation and hiberfil.sys</title>
		<link>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing</link>
		<comments>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing#comments</comments>
		<pubDate>Mon, 01 Feb 2010 17:17:32 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Featured Articles]]></category>
		<category><![CDATA[Hex Editing]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[hiberfil]]></category>
		<category><![CDATA[hiberfil.sys]]></category>
		<category><![CDATA[hibernate]]></category>
		<category><![CDATA[hibernation]]></category>
		<category><![CDATA[hxd]]></category>
		<category><![CDATA[windows hibernation]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=704</guid>
		<description><![CDATA[Did you know that by putting your computer into "hibernation" mode you are essentially creating a snapshot of the contents of your computers RAM? Learn the risks of using Windows Hibernation mode and how to disable the hiberfil.sys on a Windows system. Learn this anti-forensics technique and more.
Related posts:<ol>
<li><a href='http://www.anti-forensics.com/leave-no-artifacts-behind-linux-live-cds' rel='bookmark' title='Leave No Artifacts Behind &#8211; Linux Live CDs'>Leave No Artifacts Behind &#8211; Linux Live CDs</a> <small>There are a few main reasons to use Linux Live...</small></li>
<li><a href='http://www.anti-forensics.com/disable-thumbnail-caching-and-wipe-thumbsdb-files-on-a-windows-xp-system' rel='bookmark' title='Disable Thumbnail Caching and Wipe Thumbs.db files on a Windows XP System'>Disable Thumbnail Caching and Wipe Thumbs.db files on a Windows XP System</a> <small>The thumbs.db file on a Windows XP system can be...</small></li>
<li><a href='http://www.anti-forensics.com/full-disk-encryption-with-truecrypt-on-windows-xp' rel='bookmark' title='Full Disk Encryption With TrueCrypt on Windows XP'>Full Disk Encryption With TrueCrypt on Windows XP</a> <small>TrueCrypt is a piece of amazing, free and open-source encryption...</small></li>
</ol>]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Beat EnCase File Signature Analysis on a Windows System</title>
		<link>http://www.anti-forensics.com/beat-encase-file-signature-analysis-on-a-windows-system</link>
		<comments>http://www.anti-forensics.com/beat-encase-file-signature-analysis-on-a-windows-system#comments</comments>
		<pubDate>Mon, 14 Sep 2009 07:28:24 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[EnCase]]></category>
		<category><![CDATA[Hex Editing]]></category>
		<category><![CDATA[file signature analysis]]></category>
		<category><![CDATA[hex editing]]></category>
		<category><![CDATA[hex editor]]></category>
		<category><![CDATA[timestomp]]></category>
		<category><![CDATA[winrar]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=564</guid>
		<description><![CDATA[Use a hex editor to modify the file signature of a WinRAR archive to that of an executable file to beat the EnCase forensic software's file signature analysis.
Related posts:<ol>
<li><a href='http://www.anti-forensics.com/disable-thumbnail-caching-and-wipe-thumbsdb-files-on-a-windows-xp-system' rel='bookmark' title='Disable Thumbnail Caching and Wipe Thumbs.db files on a Windows XP System'>Disable Thumbnail Caching and Wipe Thumbs.db files on a Windows XP System</a> <small>The thumbs.db file on a Windows XP system can be...</small></li>
<li><a href='http://www.anti-forensics.com/the-art-of-defiling-defeating-forensic-analysis-on-unix-filesystems-conference-talk-by-the-grugq' rel='bookmark' title='The Art of Defiling: Defeating Forensic Analysis on Unix Filesystems (Conference talk by The Grugq)'>The Art of Defiling: Defeating Forensic Analysis on Unix Filesystems (Conference talk by The Grugq)</a> <small>The Grugq has contributed greatly to the anti-forensics community during...</small></li>
<li><a href='http://www.anti-forensics.com/the-rootkit-arsenal-escape-and-evasion-in-the-dark-corners-of-the-system-by-bill-blunden' rel='bookmark' title='The Rootkit Arsenal Escape and Evasion in the Dark Corners of the System by Bill Blunden'>The Rootkit Arsenal Escape and Evasion in the Dark Corners of the System by Bill Blunden</a> <small>The Rootkit Arsenal is primarily focused on rootkits, every aspect...</small></li>
</ol>]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/beat-encase-file-signature-analysis-on-a-windows-system/feed</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Modify NTFS Timestamps and Cover Your Tracks With Timestomp.exe</title>
		<link>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp</link>
		<comments>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp#comments</comments>
		<pubDate>Thu, 05 Mar 2009 22:08:36 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Anti-Forensics Software]]></category>
		<category><![CDATA[Hex Editing]]></category>
		<category><![CDATA[compression]]></category>
		<category><![CDATA[hex editor]]></category>
		<category><![CDATA[packing]]></category>
		<category><![CDATA[timestomp]]></category>
		<category><![CDATA[timestomp.exe]]></category>
		<category><![CDATA[upx]]></category>
		<category><![CDATA[windows xp]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=125</guid>
		<description><![CDATA[There have been a million articles written on using timestomp.exe. However, the goal of this article is to give some ideas on how to use timestomp and avoid leaving evidence behind that would point to its use.
Related posts:<ol>
<li><a href='http://www.anti-forensics.com/modify-truecrypt-encryption-boot-loader-strings' rel='bookmark' title='Modify TrueCrypt Encryption Boot Loader Strings'>Modify TrueCrypt Encryption Boot Loader Strings</a> <small>In a previous post I mentioned that TrueCrypt leaves behind...</small></li>
<li><a href='http://www.anti-forensics.com/beat-encase-file-signature-analysis-on-a-windows-system' rel='bookmark' title='Beat EnCase File Signature Analysis on a Windows System'>Beat EnCase File Signature Analysis on a Windows System</a> <small>Use a hex editor to modify the file signature of...</small></li>
</ol>]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Modify TrueCrypt Encryption Boot Loader Strings</title>
		<link>http://www.anti-forensics.com/modify-truecrypt-encryption-boot-loader-strings</link>
		<comments>http://www.anti-forensics.com/modify-truecrypt-encryption-boot-loader-strings#comments</comments>
		<pubDate>Sun, 01 Mar 2009 10:16:23 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Featured Articles]]></category>
		<category><![CDATA[Hex Editing]]></category>
		<category><![CDATA[hex editing]]></category>
		<category><![CDATA[TrueCrypt]]></category>
		<category><![CDATA[winhex]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=159</guid>
		<description><![CDATA[In a previous post I mentioned that TrueCrypt leaves behind a string in its boot loader (that identifies it as a TrueCrypt boot loader) when using the full disk encryption feature. As you can see in the screenshot below I have modified the original "TrueCrypt Boot Loader" string to read "Windows Boot Loader."
Related posts:<ol>
<li><a href='http://www.anti-forensics.com/full-disk-encryption-with-truecrypt-on-windows-xp' rel='bookmark' title='Full Disk Encryption With TrueCrypt on Windows XP'>Full Disk Encryption With TrueCrypt on Windows XP</a> <small>TrueCrypt is a piece of amazing, free and open-source encryption...</small></li>
<li><a href='http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption' rel='bookmark' title='Using Just Full Disk Encryption is Not Enough'>Using Just Full Disk Encryption is Not Enough</a> <small>So you've installed full disk encryption using TrueCrypt. You also...</small></li>
<li><a href='http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp' rel='bookmark' title='Modify NTFS Timestamps and Cover Your Tracks With Timestomp.exe'>Modify NTFS Timestamps and Cover Your Tracks With Timestomp.exe</a> <small>There have been a million articles written on using timestomp.exe....</small></li>
</ol>]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/modify-truecrypt-encryption-boot-loader-strings/feed</wfw:commentRss>
		<slash:comments>17</slash:comments>
		</item>
	</channel>
</rss>

