Extending the advanced forensic format to accommodate multiple data sources, logical evidence, arbitrary information and forensic workflow M Cohen, S Garfinkel, B Schatz digital investigation 6, S57-S68, 2009 | 106 | 2009 |
BodySnatcher: Towards reliable volatile memory acquisition by software B Schatz digital investigation 4, 126-134, 2007 | 104 | 2007 |
A correlation method for establishing provenance of timestamps in digital evidence B Schatz, G Mohay, A Clark digital investigation 3, 98-107, 2006 | 74 | 2006 |
Rich event representation for computer forensics B Schatz, G Mohay, A Clark Proceedings of the Fifth Asia-Pacific Industrial Engineering and Management …, 2004 | 56 | 2004 |
Rich event representation for computer forensics B Schatz, G Mohay, A Clark Proceedings of the Fifth Asia-Pacific Industrial Engineering and Management …, 2004 | 56 | 2004 |
Digital evidence: representation and assurance BL Schatz Queensland University of Technology, 2007 | 44 | 2007 |
An open architecture for digital evidence integration B Schatz, A Clark Proceedings of the AusCERT Asia Pacific Information Technology Security …, 2006 | 44 | 2006 |
Hash based disk imaging using AFF4 M Cohen, B Schatz digital investigation 7, S121-S128, 2010 | 35 | 2010 |
Generalising event forensics across multiple domains B Schatz, G Mohay, A Clark 2nd Australian Computer Networks Information and Forensics Conference, 136-144, 2004 | 33 | 2004 |
A framework for detecting network-based code injection attacks targeting Windows and UNIX S Andersson, A Clark, G Mohay, B Schatz, J Zimmermann 21st Annual Computer Security Applications Conference (ACSAC'05), 10 pp.-58, 2005 | 25 | 2005 |
Integrity verification of user space code A White, B Schatz, E Foo Digital Investigation 10, S59-S68, 2013 | 23 | 2013 |
Conducting digital investigations E Casey, B Schatz Digital Evidence and Computer Crime: Forensic Science, Computers and the …, 2011 | 18 | 2011 |
Surveying the user space through user allocations A White, B Schatz, E Foo Digital Investigation 9, S3-S12, 2012 | 17 | 2012 |
Advances in volatile memory forensics B Schatz, M Cohen Digital Investigation 100 (20), 1, 2017 | 13 | 2017 |
Wirespeed: Extending the AFF4 forensic container format for scalable acquisition and live analysis BL Schatz Digital Investigation 14, S45-S54, 2015 | 9 | 2015 |
Digital evidence and computer crime. Waltham, MA E Casey, B Schatz Academic Press (Elsevier), 2011 | 8 | 2011 |
AFF4-L: a scalable open logical evidence container BL Schatz Digital Investigation 29, S143-S149, 2019 | 5 | 2019 |
A visual approach to interpreting NAND flash memory BL Schatz Digital Investigation 11 (3), 214-223, 2014 | 4 | 2014 |
Refining evidence containers for Provenance and accurate data Representation B Schatz, M Cohen Advances in Digital Forensics VI: Sixth IFIP WG 11.9 International …, 2010 | 4 | 2010 |
Recent developments in volatile memory forensics B Schatz, E Director URL: http://www. schatzforensic. com/presentations/BSchatz-CERT-CSD2007. pdf, 2007 | 3 | 2007 |