2013-12-05_tcpflow-and-BE-update
2013-12-05_tcpflow-and-BE-update
2013-12-05_tcpflow-and-BE-update
- No tags were found...
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
The big picture:using low-probability data for high-outcome correlation.bulk_extractor was created to find low-probably, high-value information.• “low-probability” means does not occur by chance; not part of the background.• Examples:—email addresses—Credit card numbers—Evidence of specific executables (prefetch files; PE headers)Once found, the goal was to enable:• Multi-drive correlation—Find all drives with a specific identifier—“Blind correlation” between multiple drives to find identifiers in commonWe now have more sources of low-probability data:• Fragments from ZIP & RAR files• Ethernet MAC addresses66