This forum is in archive mode. You will not be able to post new content.

Author Topic: Mantaray forensics  (Read 323 times)

0 Members and 1 Guest are viewing this topic.

Offline ram1r3z0

  • Serf
  • *
  • Posts: 29
  • Cookies: 2
    • View Profile
Mantaray forensics
« on: September 22, 2015, 01:45:36 PM »
Boring forensics stuff is over :|)
Tool for automatizing forensics

http://mantarayforensics.com/downloads/

Offline blindfuzzy

  • VIP
  • Peasant
  • *
  • Posts: 86
  • Cookies: 34
    • View Profile
Re: Mantaray forensics
« Reply #1 on: September 22, 2015, 06:18:02 PM »
Pft, since when has forensics been boring?

Offline ram1r3z0

  • Serf
  • *
  • Posts: 29
  • Cookies: 2
    • View Profile
Re: Mantaray forensics
« Reply #2 on: September 22, 2015, 06:29:01 PM »
Well, I wrote a lot of scripts to do what Mantaray already do :) because running script after script is a lot of boring until you come to some interesting stuff :D

Offline blindfuzzy

  • VIP
  • Peasant
  • *
  • Posts: 86
  • Cookies: 34
    • View Profile
Re: Mantaray forensics
« Reply #3 on: September 22, 2015, 06:33:25 PM »
Well, I wrote a lot of scripts to do what Mantaray already do :) because running script after script is a lot of boring until you come to some interesting stuff :D

What do you usually use to do your forensics? Yeah, I understand but for a while it is interesting writing different scripts for what you are trying to get accomplished. I'm wondering if they'll be at the conference I am going to soon...might have to get in their training program while I'm there.

Offline ram1r3z0

  • Serf
  • *
  • Posts: 29
  • Cookies: 2
    • View Profile
Re: Mantaray forensics
« Reply #4 on: September 22, 2015, 06:37:29 PM »
It depends if I analyze disk or memory.

In case of memory I use most volatility and some some own scripts which do carving with respect to memory.

In case of disks I use Encase and enscripts :). Of course SleuthKit, DFF and lot of more. It actually very depends on tasks needed to complete. In lot of cases Encase is enough. :)

Offline blindfuzzy

  • VIP
  • Peasant
  • *
  • Posts: 86
  • Cookies: 34
    • View Profile
Re: Mantaray forensics
« Reply #5 on: September 22, 2015, 06:42:16 PM »
It depends if I analyze disk or memory.

In case of memory I use most volatility and some some own scripts which do carving with respect to memory.

In case of disks I use Encase and enscripts :). Of course SleuthKit, DFF and lot of more. It actually very depends on tasks needed to complete. In lot of cases Encase is enough. :)

Have you tried FTK imager? Or any of the FTK tools for that matter.
What you use is what WE all use for forensics in the field haha. I use Autopsy a lot of the time with a module we scripted to map out a network of data sent/received...etc. It's pretty handy when turning in our findings.

Offline ram1r3z0

  • Serf
  • *
  • Posts: 29
  • Cookies: 2
    • View Profile
Re: Mantaray forensics
« Reply #6 on: September 26, 2015, 04:10:41 PM »
I use FTK imager daily. FTK not ... it  is too expensive :(

 



Want to be here? Contact Ande, Factionwars or Kulverstukas on the forum or at IRC.