Chip_DFIR

Chip_DFIR

I am Chip (Aka Dale) and I work in the DFIR arena for a large UK CERT. Happily married to my wife Colleen I enjoy rugby , F1 and anything computer related has always peaked my interest!

20 posts
RSS

New Home For My Blog

Just a quick blog post for the reasoning behind moving my blog. There were several reasons for the move, the main one being the relocation to the techanarchy.net domain. The techanarchy blog

Timestamp Anomalies - $MFT

Timestamp Anomalies - $MFT

Going through my SANS 508 material I decided to have a closer look at some of the material on the Master File Table ($MFT) in the NTFS file system and how the analysis

Grep and icat

Grep and icat

Just a very brief blog post regarding the power of grep and icat in relation to forensic images.  I am currently revising for my GCFA certification and as part of this revision was