<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Network Forensics Puzzle #3 Finalist!</title>
	<atom:link href="http://www.mcgrewsecurity.com/2010/03/04/network-forensics-puzzle-3-finalist/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mcgrewsecurity.com/2010/03/04/network-forensics-puzzle-3-finalist/</link>
	<description></description>
	<lastBuildDate>Tue, 07 Sep 2010 14:09:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Wesley McGrew</title>
		<link>http://www.mcgrewsecurity.com/2010/03/04/network-forensics-puzzle-3-finalist/comment-page-1/#comment-50038</link>
		<dc:creator>Wesley McGrew</dc:creator>
		<pubDate>Mon, 08 Mar 2010 16:32:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.mcgrewsecurity.com/2010/03/04/network-forensics-puzzle-3-finalist/#comment-50038</guid>
		<description>Certain kinds of network and file activity can show that someone was there.  How that contradicts or corroborates what the suspect is saying in interviews, or how it relates to non-digital evidence varies from case to case.

You&#039;ve hit the nail on the head though:  One of the biggest difficulties in digital forensics is &quot;putting a butt in a chair&quot;.  You have to tie it together with other forms of forensics and investigations.  I suppose other types of forensics have the same problem: if my fingerprints are on a knife, it doesn&#039;t prove I stabbed someone with it.  It&#039;s up to investigators and legal teams to bring it all together into something that makes sense for that case.</description>
		<content:encoded><![CDATA[<p>Certain kinds of network and file activity can show that someone was there.  How that contradicts or corroborates what the suspect is saying in interviews, or how it relates to non-digital evidence varies from case to case.</p>
<p>You&#8217;ve hit the nail on the head though:  One of the biggest difficulties in digital forensics is &#8220;putting a butt in a chair&#8221;.  You have to tie it together with other forms of forensics and investigations.  I suppose other types of forensics have the same problem: if my fingerprints are on a knife, it doesn&#8217;t prove I stabbed someone with it.  It&#8217;s up to investigators and legal teams to bring it all together into something that makes sense for that case.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: thefixer</title>
		<link>http://www.mcgrewsecurity.com/2010/03/04/network-forensics-puzzle-3-finalist/comment-page-1/#comment-50017</link>
		<dc:creator>thefixer</dc:creator>
		<pubDate>Mon, 08 Mar 2010 02:01:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.mcgrewsecurity.com/2010/03/04/network-forensics-puzzle-3-finalist/#comment-50017</guid>
		<description>just because a users account was logged in does not prove that he was there.</description>
		<content:encoded><![CDATA[<p>just because a users account was logged in does not prove that he was there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wesley McGrew</title>
		<link>http://www.mcgrewsecurity.com/2010/03/04/network-forensics-puzzle-3-finalist/comment-page-1/#comment-49963</link>
		<dc:creator>Wesley McGrew</dc:creator>
		<pubDate>Sun, 07 Mar 2010 01:12:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.mcgrewsecurity.com/2010/03/04/network-forensics-puzzle-3-finalist/#comment-49963</guid>
		<description>A lot of digital forensic techniques that don&#039;t look useful on the surface can come in handy with some cases.

Even if it&#039;s not directly related to the crime in question, being able to show that someone was in a household and using computers (or other devices) there at a given time can punch holes in alibis or whatever story a suspect might come up with when interviewed.</description>
		<content:encoded><![CDATA[<p>A lot of digital forensic techniques that don&#8217;t look useful on the surface can come in handy with some cases.</p>
<p>Even if it&#8217;s not directly related to the crime in question, being able to show that someone was in a household and using computers (or other devices) there at a given time can punch holes in alibis or whatever story a suspect might come up with when interviewed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: thefixer</title>
		<link>http://www.mcgrewsecurity.com/2010/03/04/network-forensics-puzzle-3-finalist/comment-page-1/#comment-49889</link>
		<dc:creator>thefixer</dc:creator>
		<pubDate>Fri, 05 Mar 2010 08:58:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.mcgrewsecurity.com/2010/03/04/network-forensics-puzzle-3-finalist/#comment-49889</guid>
		<description>cops have no business learning this, they outta spend time writing  tickets and catching killers and crack dealers, pimps and, maybe child porno, you know, people who really need to be in prison,   id sleep better at night  knowing that boss hawg and his high and mighty judge croneys, and the privatized prisons who make a capitolist mockery of justice, sleeping soundly knowing they  dont have the power to put me away for a few petty keystrokes because impotence and anus cancer  has got them afraid the bad man might sleep with their women. bwhahaha.</description>
		<content:encoded><![CDATA[<p>cops have no business learning this, they outta spend time writing  tickets and catching killers and crack dealers, pimps and, maybe child porno, you know, people who really need to be in prison,   id sleep better at night  knowing that boss hawg and his high and mighty judge croneys, and the privatized prisons who make a capitolist mockery of justice, sleeping soundly knowing they  dont have the power to put me away for a few petty keystrokes because impotence and anus cancer  has got them afraid the bad man might sleep with their women. bwhahaha.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
