<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Anti-Forensics &#187; Hex Editing</title>
	<atom:link href="http://www.anti-forensics.com/category/general-topics/hex-edit/feed" rel="self" type="application/rss+xml" />
	<link>http://www.anti-forensics.com</link>
	<description>Rendering computer investigations irrelevant</description>
	<lastBuildDate>Thu, 12 Aug 2010 04:04:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>The Risks of Windows Hibernation &#8211; The hiberfil.sys and Web Browsing</title>
		<link>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing</link>
		<comments>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing#comments</comments>
		<pubDate>Mon, 01 Feb 2010 17:17:32 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Hex Editing]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[hiberfil]]></category>
		<category><![CDATA[hiberfil.sys]]></category>
		<category><![CDATA[hibernate]]></category>
		<category><![CDATA[hibernation]]></category>
		<category><![CDATA[hxd]]></category>
		<category><![CDATA[windows hibernation]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=704</guid>
		<description><![CDATA[You can use Windows Hibernate to conserve batteries, electricity, save the environment, the world and the polar bears. However, did you know that by putting your computer into "hibernation" mode that you are essentially creating a snapshot of the contents of your computers RAM which is then saved to the root of the hard drive as "hiberfil.sys"?]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Beat EnCase File Signature Analysis on a Windows System</title>
		<link>http://www.anti-forensics.com/beat-encase-file-signature-analysis-on-a-windows-system</link>
		<comments>http://www.anti-forensics.com/beat-encase-file-signature-analysis-on-a-windows-system#comments</comments>
		<pubDate>Mon, 14 Sep 2009 07:28:24 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[EnCase]]></category>
		<category><![CDATA[Hex Editing]]></category>
		<category><![CDATA[file signature analysis]]></category>
		<category><![CDATA[hex editing]]></category>
		<category><![CDATA[hex editor]]></category>
		<category><![CDATA[timestomp]]></category>
		<category><![CDATA[winrar]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=564</guid>
		<description><![CDATA[Use a hex editor to modify the file signature of a WinRAR archive to that of an executable file to beat the EnCase forensic software's file signature analysis.]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/beat-encase-file-signature-analysis-on-a-windows-system/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Modify NTFS Timestamps and Cover Your Tracks With Timestomp.exe</title>
		<link>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp</link>
		<comments>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp#comments</comments>
		<pubDate>Thu, 05 Mar 2009 22:08:36 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Anti-Forensics Software]]></category>
		<category><![CDATA[Hex Editing]]></category>
		<category><![CDATA[compression]]></category>
		<category><![CDATA[hex editor]]></category>
		<category><![CDATA[packing]]></category>
		<category><![CDATA[timestomp]]></category>
		<category><![CDATA[timestomp.exe]]></category>
		<category><![CDATA[upx]]></category>
		<category><![CDATA[windows xp]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=125</guid>
		<description><![CDATA[There have been a million articles written on using timestomp.exe. However, the goal of this article is to give some ideas on how to use timestomp and avoid leaving evidence behind that would point to its use.]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Modify TrueCrypt Encryption Boot Loader Strings</title>
		<link>http://www.anti-forensics.com/modify-truecrypt-encryption-boot-loader-strings</link>
		<comments>http://www.anti-forensics.com/modify-truecrypt-encryption-boot-loader-strings#comments</comments>
		<pubDate>Sun, 01 Mar 2009 10:16:23 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Hex Editing]]></category>
		<category><![CDATA[hex editing]]></category>
		<category><![CDATA[TrueCrypt]]></category>
		<category><![CDATA[winhex]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=159</guid>
		<description><![CDATA[In a previous post I mentioned that TrueCrypt leaves behind a string in its boot loader (that identifies it as a TrueCrypt boot loader) when using the full disk encryption feature. As you can see in the screenshot below I have modified the original "TrueCrypt Boot Loader" string to read "Windows Boot Loader."]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/modify-truecrypt-encryption-boot-loader-strings/feed</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
	</channel>
</rss>
