Version 4.97 - Clean up BE output - Corrected section 11 output (thanks to Onno Heitmeijer) Version 4.96 - Changes for Slackware 15.0 - Changes for updated software (bulk_extractor, etc) - Added terminal configuration section (bash files) - General corrections, updates and fixes (thanks to Bárður Christiansen) Version 4.95.1 - Maintenance release to fix various typos. Version 4.94 - NEW Chapter: Added chapter for basic networking - NEW Chapter: Added short chapter for basic network investigation tools - Minor typo corrections - removed references to kpartx in favor of losetup -P Version 4.93 - Minor corrections (Special thanks to Lars Van Dijk) - reordered section 3 to more sane sequence. Version 4.92 - Corrected the table of contents. Not enough pdflatex runs, apparently. - fixed minor typos Version 4.91 - Changed to using Latex rather than OO. (maintaining the format in OO was becoming a bear) - updated some device handling. - updated distribution section. - expanded vi section a bit. - updated command output and versions of included software. Version 4.33 - incorporate edits from Henning Sietz - fixed some typos and formatting Version 4.32 - incorporate edits from Laurent Pierroz email Version 4.31 - Fixed typos Version 4.30 -Installation -Updated descriptions ofdistributions -device handling and auto mounting -This section is updated in general terms only. -Linux Disks, Partitions and the File System -Disk naming conventions and desktop mounting -The Linux Boot Sequence (Simplified) -Updated command output/service start up scripts. -Basic Linux Commands -Updated command output -Command line mathematics evaluation -Shell arithmetic expansion -Added section on file attributes -Editing with Vi -Expanded command reference -Configuring a Forensic Workstation -Added to provide the reader OS knowledge/function. -The following sub-sections are added: -Securing the Workstation -Configuring Services -Host Based Access Control -Host Based Firewall with iptables -Adding a Normal User -Updating the Operating System -Installing and Updating External Software -Compiling From Source -Using Distribution Packages -Building Packages SlackBuilds -Using the Automated Package Tool sbotools -Linux and Forensics -Complete reorganization -The sections are organized by process -acquisition -mounting -basic review -Added new tools for media information and enumeration -Expanded loop mounting section with additional tools -Added additional fuse file system use -Added Anti-Virus scanning of evidence -Advanced (Beginner) Forensics -Updated image files and updated output for commands. -fuse filesystem utilities are covered -Advanced Analysis Tools -The Layer Strategy is clarified. -Sleuthkit section and exercises are updated -New version -New installation method -Older exercises on ext2 (able2.dd) remain -perfect vehicle for teaching the Sleuthkit tools -Modern ext4 images and exercises have been added -New NTFS image -New NTFS physical searching and allocation exercise -Bulk Extractor Comprehensive Searching -Physical Carving: -Scalpel -photorec -fdupes: Comparing and de-duplicating carve output -Integrating Linux with Your Work -Application of Linux forensics in a laboratory -validation or cross verification tool Version 3.78 -Moved Alternative Imaging tools section to "Advanced Forensics" -added detail on the output of some TSK tools (by request). -reorganized the Sleuthkit NTFS examination sections to account for changes in TSK 3 (orphan files). Exercise on NTFS deleted files was removed, since TSK 3 makes it moot. -added material to NTFS section on more detailed file analysis. -changed unallocated examination exercise to account for change in tool names from d* to blk* in TSK 3. -cleaned up the section on getting help (last page). Version 3.65 -Switched to 2.6 kernel install in intro (Slackware 12.1). -Added brief section on device detection (by request). -updated details for recent versions of Linux tools. -updated Sleuthkit and libewf section to account for changes in install for TSK > 2.50 (autotools build design). -moved libewf before TSK to account for lib install. -added section on alternative imaging tools (dc3dd,ddrescue) -added dls exercises by request (TSK). -added brief exercise on sigfind (TSK). Version 3.20 -added compression on the fly exercise (for dd). -added dd over the wire (network acquisition). -added more detailed Sleuthkit section (commands) -added TSK NTFS exercises (ADS, deleted files,sorter) -added deleted file allocation determination and recovery exercise (TSK/EXT2) -removed support for Autopsy (I just don't use it anymore-I'll add it back if enough people request it). -added libewf section. -removed reference to NASA loopback (unsupported) -added SMART filtering section using NTFS (classroom exercise) -added SMART search section using EXT (classroom exercise). -added section on configuring Slackware if a 2.6 kernel version is used (12.x). Version 2.55 -added a changelog ;-) -Document is now Slackware centric -updated to Sleuthkit 2.0x (full disk images and split support) -updated to Autopsy 2.0x (for use with new TSK) -formatting changes for readability