Evtim Batchev's Weblog
Efi's Weblog
Archives
« November 2009
MonTueWedThuFriSatSun
      
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
      
Today
Click me to subscribe
Search

Links
 

Today's Page Hits: 7

« Introduction to Live... | Main | Happy New 2008 »
Friday Nov 23, 2007
Proposal - Open Solaris Forensic Toolkit Project

Few days ago after being poked by several people (but mainly by Mark Furner ) I decided to ask the Open Solaris Security Community does the creation of Open Solaris Forensic [Toolkit] Project makes sense.

I personally was pleasantly surprised by the reaction:


PROPOSAL: Open Solaris Fotrensics Tools Project

(one can see that I was pretty excited on posting by looking at the way my fat fingers hit "tr" together  resulting in "Fotrensics" instead of Forensics)

Apparently the Open Solaris Security Community finds this project to be a useful and I hope to count on their sponsorship upon future porject instantiation.

I have been looking trough the Open Solaris Policies inorder to find the process for requesting a new project and I found there the things I need to submit. Some of the requirements are present and other are missing partially. Amongst the mossing ones I still need to compile the following:

  • Security Community - I hope the idea got their attention and the project has at least one sponsor, unless I am very much wrong ! (please be direct with me !)
  • ZFS Community - I think this will be a very interesting sponsorship and collaboration opportunity as on of the main missing pieces in the Solaris  Forensics challenge is a proper ZFS forensics analysis toolkit.
  • Unix File Systems (UFS) - Though many tools exist for UFS forensic data gathering, grave digging and analysis the proper implementation details may require cooperation and possible interest from this group. Comments?
  • Observability Community - getting sponsorship from this group should be considered as a priority because they are providing the tools used in live data gathering or post mortem investigation. I will be contacting them to request sponsorship.
  • Other Suggestions Welcome.

I will get the act together and  will start moving forward after thanksgiving vacation, meanwhile awaiting suggestions, woes or anything you have to say on the subject.

Posted at 03:10PM Nov 23, 2007 by efi in Forensics and Incident Response  | 

Comments:

Post a Comment:
Comments are closed for this entry.