<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Anti-Forensics &#187; Operating Systems</title>
	<atom:link href="http://www.anti-forensics.com/category/operating-systems/feed" rel="self" type="application/rss+xml" />
	<link>http://www.anti-forensics.com</link>
	<description>Rendering computer investigations irrelevant</description>
	<lastBuildDate>Thu, 15 Dec 2011 07:57:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Disk Wiping with dcfldd</title>
		<link>http://www.anti-forensics.com/disk-wiping-with-dcfldd</link>
		<comments>http://www.anti-forensics.com/disk-wiping-with-dcfldd#comments</comments>
		<pubDate>Sun, 03 Jul 2011 20:56:12 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Data Destruction]]></category>
		<category><![CDATA[Featured Articles]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[dcfldd]]></category>
		<category><![CDATA[dd]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=1003</guid>
		<description><![CDATA[Did you know that a real ninja was once employed by the Defense Computer Forensics Laboratory or DCFL for short? During Nick's employment at DCFL, he coded "dcfldd", an enhanced version of the "dd" program found in GNU Core Utilities (GNU coreutils).

dcfldd is still used quite often when imaging digital evidence.Not only is it used by DCFL and other alphabet soup but by individuals working in the private sector.
Related posts:<ol>
<li><a href='http://www.anti-forensics.com/disk-wiping-one-pass-is-enough' rel='bookmark' title='Disk Wiping &#8211; One Pass is Enough'>Disk Wiping &#8211; One Pass is Enough</a> <small>Many people are under the impression that hard drives need...</small></li>
<li><a href='http://www.anti-forensics.com/disk-wiping-one-pass-is-enough-part-2-this-time-with-screenshots' rel='bookmark' title='Disk Wiping &#8211; One Pass is Enough &#8211; Part 2 (this time with screenshots)'>Disk Wiping &#8211; One Pass is Enough &#8211; Part 2 (this time with screenshots)</a> <small>It seems that there are still many people who do...</small></li>
</ol>]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/disk-wiping-with-dcfldd/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>WhisperCore Partition Encryption for Nexus S</title>
		<link>http://www.anti-forensics.com/whispercore-partition-encryption-for-nexus-s</link>
		<comments>http://www.anti-forensics.com/whispercore-partition-encryption-for-nexus-s#comments</comments>
		<pubDate>Wed, 16 Mar 2011 17:54:51 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Anti-Forensics News]]></category>
		<category><![CDATA[Encryption]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=1032</guid>
		<description><![CDATA[WhisperCore uses AES 256 to encrypt the data partition on the Nexus S (the Nexus S has 16GB of internal memory) and contains an option to encrypt the SD card.
Related posts:<ol>
<li><a href='http://www.anti-forensics.com/whispercore-update-and-release-of-whisperyaffs' rel='bookmark' title='WhisperCore Update and Release of WhisperYAFFS'>WhisperCore Update and Release of WhisperYAFFS</a> <small>Whisper Systems has released an update to WhisperCore and released...</small></li>
<li><a href='http://www.anti-forensics.com/freedom-almighty-and-the-redphone-application-for-android' rel='bookmark' title='Freedom Almighty and the RedPhone Application for Android'>Freedom Almighty and the RedPhone Application for Android</a> <small>Freedom Almighty and the RedPhone application by Whisper Systems. True...</small></li>
<li><a href='http://www.anti-forensics.com/full-disk-encryption-with-truecrypt-on-windows-xp' rel='bookmark' title='Full Disk Encryption With TrueCrypt on Windows XP'>Full Disk Encryption With TrueCrypt on Windows XP</a> <small>TrueCrypt is a piece of amazing, free and open-source encryption...</small></li>
</ol>]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/whispercore-partition-encryption-for-nexus-s/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Freedom Almighty and the RedPhone Application for Android</title>
		<link>http://www.anti-forensics.com/freedom-almighty-and-the-redphone-application-for-android</link>
		<comments>http://www.anti-forensics.com/freedom-almighty-and-the-redphone-application-for-android#comments</comments>
		<pubDate>Fri, 10 Dec 2010 06:48:02 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[redphone]]></category>
		<category><![CDATA[whisper systems]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=931</guid>
		<description><![CDATA[Freedom Almighty and the RedPhone application by Whisper Systems. True story.
Related posts:<ol>
<li><a href='http://www.anti-forensics.com/whispercore-partition-encryption-for-nexus-s' rel='bookmark' title='WhisperCore Partition Encryption for Nexus S'>WhisperCore Partition Encryption for Nexus S</a> <small>WhisperCore uses AES 256 to encrypt the data partition on...</small></li>
</ol>]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/freedom-almighty-and-the-redphone-application-for-android/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Windows Hibernation and hiberfil.sys</title>
		<link>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing</link>
		<comments>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing#comments</comments>
		<pubDate>Mon, 01 Feb 2010 17:17:32 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Featured Articles]]></category>
		<category><![CDATA[Hex Editing]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[hiberfil]]></category>
		<category><![CDATA[hiberfil.sys]]></category>
		<category><![CDATA[hibernate]]></category>
		<category><![CDATA[hibernation]]></category>
		<category><![CDATA[hxd]]></category>
		<category><![CDATA[windows hibernation]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=704</guid>
		<description><![CDATA[Did you know that by putting your computer into "hibernation" mode you are essentially creating a snapshot of the contents of your computers RAM? Learn the risks of using Windows Hibernation mode and how to disable the hiberfil.sys on a Windows system. Learn this anti-forensics technique and more.
Related posts:<ol>
<li><a href='http://www.anti-forensics.com/leave-no-artifacts-behind-linux-live-cds' rel='bookmark' title='Leave No Artifacts Behind &#8211; Linux Live CDs'>Leave No Artifacts Behind &#8211; Linux Live CDs</a> <small>There are a few main reasons to use Linux Live...</small></li>
<li><a href='http://www.anti-forensics.com/disable-thumbnail-caching-and-wipe-thumbsdb-files-on-a-windows-xp-system' rel='bookmark' title='Disable Thumbnail Caching and Wipe Thumbs.db files on a Windows XP System'>Disable Thumbnail Caching and Wipe Thumbs.db files on a Windows XP System</a> <small>The thumbs.db file on a Windows XP system can be...</small></li>
<li><a href='http://www.anti-forensics.com/full-disk-encryption-with-truecrypt-on-windows-xp' rel='bookmark' title='Full Disk Encryption With TrueCrypt on Windows XP'>Full Disk Encryption With TrueCrypt on Windows XP</a> <small>TrueCrypt is a piece of amazing, free and open-source encryption...</small></li>
</ol>]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Meta Anti-Forensics (Conference talk by The Grugq)</title>
		<link>http://www.anti-forensics.com/meta-anti-forensics-conference-talk-by-the-grugq</link>
		<comments>http://www.anti-forensics.com/meta-anti-forensics-conference-talk-by-the-grugq#comments</comments>
		<pubDate>Tue, 26 Jan 2010 19:11:54 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Featured Articles]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[The Grugq]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=682</guid>
		<description><![CDATA[Another presentation by The Grugq and his knowledge and contributions to the anti-forensics community during his computer forensic and anti-forensic research. The video below is a presentation The Grugq performed at Hack in the Box 2007 security conference. The Grugq covers anti-forensics techniques as well as the HASH or hacker shell which he developed. Related [...]
Related posts:<ol>
<li><a href='http://www.anti-forensics.com/the-art-of-defiling-defeating-forensic-analysis-on-unix-filesystems-conference-talk-by-the-grugq' rel='bookmark' title='The Art of Defiling: Defeating Forensic Analysis on Unix Filesystems (Conference talk by The Grugq)'>The Art of Defiling: Defeating Forensic Analysis on Unix Filesystems (Conference talk by The Grugq)</a> <small>The Grugq has contributed greatly to the anti-forensics community during...</small></li>
<li><a href='http://www.anti-forensics.com/the-anti-forensics-forum' rel='bookmark' title='The Anti-Forensics Forum'>The Anti-Forensics Forum</a> <small>I've set up a forum for those who would like...</small></li>
<li><a href='http://www.anti-forensics.com/just-an-anti-forensics-com-update' rel='bookmark' title='Just an Anti-Forensics.com Update'>Just an Anti-Forensics.com Update</a> <small>Hey guys, hope you are all doing well. I don&#8217;t...</small></li>
</ol>]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/meta-anti-forensics-conference-talk-by-the-grugq/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>The Art of Defiling: Defeating Forensic Analysis on Unix Filesystems (Conference talk by The Grugq)</title>
		<link>http://www.anti-forensics.com/the-art-of-defiling-defeating-forensic-analysis-on-unix-filesystems-conference-talk-by-the-grugq</link>
		<comments>http://www.anti-forensics.com/the-art-of-defiling-defeating-forensic-analysis-on-unix-filesystems-conference-talk-by-the-grugq#comments</comments>
		<pubDate>Tue, 26 Jan 2010 01:23:19 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[The Grugq]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=677</guid>
		<description><![CDATA[The Grugq has contributed greatly to the anti-forensics community during the course of his of computer forensic and anti-computer forensic research. This must watch presentation on anti-forensics will familiarize you on Unix file system structure, common forensic tools and some theories behind file system anti-forensic attacks.
Related posts:<ol>
<li><a href='http://www.anti-forensics.com/meta-anti-forensics-conference-talk-by-the-grugq' rel='bookmark' title='Meta Anti-Forensics (Conference talk by The Grugq)'>Meta Anti-Forensics (Conference talk by The Grugq)</a> <small>Another presentation by The Grugq and his knowledge and contributions...</small></li>
<li><a href='http://www.anti-forensics.com/breaking-forensic-images-booted-as-a-virtual-machine' rel='bookmark' title='Breaking Forensic Images Booted as a Virtual Machine'>Breaking Forensic Images Booted as a Virtual Machine</a> <small>I've dug around a bit and found some older examples...</small></li>
<li><a href='http://www.anti-forensics.com/beat-encase-file-signature-analysis-on-a-windows-system' rel='bookmark' title='Beat EnCase File Signature Analysis on a Windows System'>Beat EnCase File Signature Analysis on a Windows System</a> <small>Use a hex editor to modify the file signature of...</small></li>
</ol>]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/the-art-of-defiling-defeating-forensic-analysis-on-unix-filesystems-conference-talk-by-the-grugq/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ubuntu Tutorials by KenTheFurry</title>
		<link>http://www.anti-forensics.com/ubuntu-tutorials-kenthefurry</link>
		<comments>http://www.anti-forensics.com/ubuntu-tutorials-kenthefurry#comments</comments>
		<pubDate>Mon, 11 Jan 2010 07:07:41 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Featured Articles]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[kenthefurry]]></category>
		<category><![CDATA[ubuntu]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=964</guid>
		<description><![CDATA[Various Ubuntu tutorials on encryption by KenTheFurry.
No related posts.]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/ubuntu-tutorials-kenthefurry/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Delete USB Device History from the Windows Registry (USBSTOR key) and the setupapi.log</title>
		<link>http://www.anti-forensics.com/delete-usb-device-history-from-the-windows-registry-usbstor-key-and-the-setupapilog</link>
		<comments>http://www.anti-forensics.com/delete-usb-device-history-from-the-windows-registry-usbstor-key-and-the-setupapilog#comments</comments>
		<pubDate>Wed, 22 Apr 2009 07:06:18 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Data Destruction]]></category>
		<category><![CDATA[Featured Articles]]></category>
		<category><![CDATA[Windows Registry]]></category>
		<category><![CDATA[flash drive]]></category>
		<category><![CDATA[setupapi.log]]></category>
		<category><![CDATA[usb thumb drive]]></category>
		<category><![CDATA[USBSTOR]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=506</guid>
		<description><![CDATA[This article covers the USBSTOR registry key and the setupapi.log file and methods to delete them. These two artifacts can contain data regarding USB devices that have been plugged into a system. There are other things you should be aware of as well which are covered in the article. Sometimes just deleting a registry key or file is not enough.
Related posts:<ol>
<li><a href='http://www.anti-forensics.com/how-to-delete-google-history-the-google-toolbar' rel='bookmark' title='How to Delete Google History &#8211; Clear Google Toolbar History'>How to Delete Google History &#8211; Clear Google Toolbar History</a> <small>Google Toolbar DownloadThere are many people who use the popular...</small></li>
<li><a href='http://www.anti-forensics.com/how-to-delete-google-history-google-chrome-artifacts-and-google-chrome-history' rel='bookmark' title='How to Delete Google History &#8211; Google Chrome Artifacts and Google Chrome History'>How to Delete Google History &#8211; Google Chrome Artifacts and Google Chrome History</a> <small>Google Chrome Initial SearchAs of this December in 2009, the...</small></li>
<li><a href='http://www.anti-forensics.com/disable-thumbnail-caching-and-wipe-thumbsdb-files-on-a-windows-xp-system' rel='bookmark' title='Disable Thumbnail Caching and Wipe Thumbs.db files on a Windows XP System'>Disable Thumbnail Caching and Wipe Thumbs.db files on a Windows XP System</a> <small>The thumbs.db file on a Windows XP system can be...</small></li>
</ol>]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/delete-usb-device-history-from-the-windows-registry-usbstor-key-and-the-setupapilog/feed</wfw:commentRss>
		<slash:comments>21</slash:comments>
		</item>
		<item>
		<title>Leave No Artifacts Behind &#8211; Linux Live CDs</title>
		<link>http://www.anti-forensics.com/leave-no-artifacts-behind-linux-live-cds</link>
		<comments>http://www.anti-forensics.com/leave-no-artifacts-behind-linux-live-cds#comments</comments>
		<pubDate>Tue, 24 Feb 2009 21:39:55 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Trail obfuscation]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=128</guid>
		<description><![CDATA[There are a few main reasons to use Linux Live CDs for privacy or your other activities. For example, when you are browsing web pages there are artifacts or evidence of what you've done being cached to the hard drive.
Related posts:<ol>
<li><a href='http://www.anti-forensics.com/how-to-delete-google-history-google-chrome-artifacts-and-google-chrome-history' rel='bookmark' title='How to Delete Google History &#8211; Google Chrome Artifacts and Google Chrome History'>How to Delete Google History &#8211; Google Chrome Artifacts and Google Chrome History</a> <small>Google Chrome Initial SearchAs of this December in 2009, the...</small></li>
</ol>]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/leave-no-artifacts-behind-linux-live-cds/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Disable the LastAccess Timestamp in Windows XP</title>
		<link>http://www.anti-forensics.com/disable-the-lastaccess-timestamp-in-windows-xp</link>
		<comments>http://www.anti-forensics.com/disable-the-lastaccess-timestamp-in-windows-xp#comments</comments>
		<pubDate>Mon, 09 Feb 2009 07:26:58 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Windows Commands]]></category>
		<category><![CDATA[Trail obfuscation]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=17</guid>
		<description><![CDATA[Requirements Administrator account Windows XP Command Summary Login as Administrator Open a command prompt Enter the command: fsutil behavior set disablelastaccess 1 Restart computer Purpose I&#8217;ll come right out and say that this is definitely not a strong anti-forensic technique but it can be helpful. Most forensic examiners already know they can&#8217;t rely heavily on lastaccess [...]
Related posts:<ol>
<li><a href='http://www.anti-forensics.com/disable-thumbnail-caching-and-wipe-thumbsdb-files-on-a-windows-xp-system' rel='bookmark' title='Disable Thumbnail Caching and Wipe Thumbs.db files on a Windows XP System'>Disable Thumbnail Caching and Wipe Thumbs.db files on a Windows XP System</a> <small>The thumbs.db file on a Windows XP system can be...</small></li>
<li><a href='http://www.anti-forensics.com/beat-encase-file-signature-analysis-on-a-windows-system' rel='bookmark' title='Beat EnCase File Signature Analysis on a Windows System'>Beat EnCase File Signature Analysis on a Windows System</a> <small>Use a hex editor to modify the file signature of...</small></li>
<li><a href='http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp' rel='bookmark' title='Modify NTFS Timestamps and Cover Your Tracks With Timestomp.exe'>Modify NTFS Timestamps and Cover Your Tracks With Timestomp.exe</a> <small>There have been a million articles written on using timestomp.exe....</small></li>
</ol>]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/disable-the-lastaccess-timestamp-in-windows-xp/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

