I downloaded SIFT and got it up and running in VMWare Workstation (you can use VMPlayer) in no time.
The VMWare appliance also comes with PTK from DFLabs already set up and ready to run. Rob also provided a neat little "cheat sheet" that you can download and keep nearby and handy when you're logged into and working in the appliance.
I know that this isn't specifically about Windows IR or forensics, but it does allow you to easily use the Linux (in this case, Fedora) platform to perform some modicum of analysis.
Don't forget about the SANS Forensic Summit in Oct, in Vegas!
No comments:
Post a Comment