SANS Digital Forensics and Incident Response Blog

Digital Forensics Case Leads: New versions of Bulk_extractor and FTK, new blogs on malware and forensics, and lost flash drives

In this week's edition of Case Leads we have updates to a couple of tools, Bulk_extractor and FTK as well as two new blogs featuring malware analysis and digital forensics tutorials.

If you have an item you'd like to contribute toDigital Forensics Case Leads, please send it to


  • A new version of Bulk_extractor has been released. This tool scans a disk image, file, or directory and extracts useful information without parsing the file system or file system structures. The tool will also create histograms of the information it finds.
  • A new version of FTK was recently made available. The release notes are available as a PDF.

Good Reads:



Coming Events:

Call For Papers:


Digital Forensics Case Leads is a (mostly) weekly publication of the week's news and events relating to digital forensics. If you have an item you'd like to share, please send it to

Digital Forensics Case Leads for 20110224 was compiled by Ray Strubinger. Ray regularly leads digital forensics and incident response efforts and when the incidents permit, he is involved in aspects of information security ranging from Data Loss Prevention to Risk Analysis.