Thursday, May 13, 2010

Defcon 18 Presentation

Good news, Sam and I got an announcement this morning that we have been accepted by Defcon for our presentation "A New Approach to Forensic Methodology - !!BUSTED!! case studies".  We are pretty excited and always love Vegas - it is the bomb.

The presentation is shaping up nicely and Sam is working on the software component that will really demonstrate our practical methodology.  Again, very excited.  Buzz me if you want some up front information, but I'll probably hold off on posting some of the more interesting details until we get most of the work behind us.

Ok, a completely different topic.  I am loving my setup for my primary system at home.  A quick review:
Intel i7 chip, custom cooling, overclocked to i7-965 using the Easy Tune app from Gigabyte MB.  Stress tested with Prime95 keeping the CPU / system temp under 80C at full load, 43C and 46C typical load.  Windows 7 64-bit, 8GB of mem, 4 1TB drive, 1 1.5 TB drive, ESATA for Thermaltake BlackX.

Ok, the part I like:  I have become a big fan of Sun VirtualBox.  I can't put my finger on it, but my total experience is that it seems less invasive that VMware and gives me everything I want.  VMs have 1GB ram and different levels of CPU cores assigned.  VM's include DeveloperXP, Ubuntu-64 (developer and workstation), Forensic XP, SIFT Workstation imported from VMware, Dirty XP (checking out dubious sites and software), and Georgetown XP.  I also have a separated malware XP and Ubuntu systems with additional protections.

Best news, it runs like a champ - I don't feel any pain when running VMs and AV / Secunia PSI.  I can schedule snapshots and file them away.  Da Bomb-bay!

BTW, see you in Vegas for Defcon and BlackHat - I love the vendor parties!!!

.

No comments: