This site is for material from my formal research work. I have some miscellaneous other stuff on my personal site.
-- Dylan Leigh
Last Updated 17 January 2015
ZFS Timeline Forensics
My Honours(Computer Science) studies at Victoria University, supervised by AProf. Hao Shi.
- 4-page summary of my Honours work (PDF)
- Final Thesis: "Forensic Timeline Analysis of the Zettabyte File System" (111 body pages; 175 total pages) (PDF) Submitted 16 January 2015.
BSDCan 2014 Presentation
This is from the main part of my honours research. "Forensic Timestamp Analysis of ZFS" was presented 14 May 2014 at BSDCan, University of Ottowa, Canada.
- Slides (with overlays and section outlines) (PDF)
- Slides (without overlays etc - for printing) (PDF)
- Proceedings Paper (PDF, 15 Pages)
- ZFS Timeline Forensics Quick Reference v1.0 (PDF)
ZFS ZDB Plaso Parsers
This is a practical implementation of the above research; new parsers for the Plaso super-timeline software to generate events from internal ZFS objects and metadata.
My article "Adding ZFS Events to a Super-Timeline" on the development
and use of these parsers was published in Digital Forensics
Magazine, Issue 20, August 2014.
Also available in BiBTex form.
- Dylan Leigh, Forensic Timeline Analysis of the Zettabyte File System. Honours thesis, College of Engineering and Science, Victoria University, January 2015.
- Dylan Leigh and Hao Shi, Adding ZFS Events to a Super-timeline. Digital Forensics Magazine, (20), August 2014.
- Dylan Leigh and Hao Shi, Forensic Timestamp Analysis of ZFS. In BSDCan 2014. BSDCan, May 2014.
- Dylan Leigh, ZFS Timeline Forensics Quick Reference, May 2014.