Disk Tools and Data Capture: Name From Description
Disk Tools and Data Capture: Name From Description
Disk Tools and Data Capture: Name From Description
EnCase Forensic Create EnCase evidence files and EnCase logical evidence files [direct
Imager Guidance Software download link]
Encrypted Disk Checks local physical drives on a system for TrueCrypt, PGP, or
Detector Magnet Forensics Bitlocker encrypted volumes
EWF MetaEditor 4Discovery Edit EWF (E01) meta data, remove passwords (Encase v6 and earlier)
Forensics
Acquisition of Web Content Protection
Websites Association Browser designed to forensically capture web pages
FTK Imager AccessData Imaging tool, disk viewer and image mounter
Network analysis tool. Detects OS, hostname and open ports of network
NetworkMiner Hjelmvik hosts through packet sniffing/PCAP parsing
OSFMount Passmark Software Mounts a wide range of disk images. Also allows creation of RAM disks
EDB Viewer Lepide Software Open and view (not export) Outlook EDB files without an Exchange server
Open and view (not export) Outlook OST files without connecting to an
OST Viewer Lepide Software Exchange server
PST Viewer Lepide Software Open and view (not export) Outlook PST files without needing Outlook
General
Agent Ransack Mythicsoft Search multiple files using Boolean operators and Perl Regex
Computer Forensic
Reference Data
Sets NIST Collated forensic images for training, practice and validation
EvidenceMover Nuix Copies data between locations, with file comparison, verification, logging
HexBrowser Peter Fiskerstrand Identifies over 1000 file types by examining their signatures
MobaLiveCD Mobatek Run Linux live CDs from their ISO image without having to boot to them
Mouse Jiggler Arkane Systems Automatically moves mouse pointer stopping screen saver, hibernation etc.
A Linux & Windows GUI for individual and recursive SHA1 hashing of
Quick Hash Ted Technology files
USB Write Blocker Sécurité Multi-Secteurs Software write blocker for Windows XP through to Windows 8
Volix FH Aachen Application that simplifies the use of the Volatility Framework
Windows Forensic
Environment Troy Larson Guide by Brett Shavers to creating and working with a Windows boot CD
Advanced Prefetch
Analyser Allan Hay Reads Windows XP,Vista and Windows 7 prefetch files
Parses the MFT from an NTFS file system allowing results to be analysed
analyzeMFT David Kovar with other tools
Defraser Various Detects full and partial multimedia files in unallocated space
ExifTool Phil Harvey Read, write and edit Exif data in a large number of file types
Drag and drop web-browser JavaScript tool for identification of over 2000
File Identifier Toolsley.com file types
Forensic Image View various picture formats, image enhancer, extraction of embedded
Viewer Sanderson Forensics Exif, GPS data
Highlighter Mandiant Examine log files using text, graphic or histogram views
LiveContactsView Nirsoft View and export Windows Live Messenger contact details
PlatformAuditProb Command Line Windows forensic/ incident response tool that collects
e AppliedAlgo many artefacts. Manual
RSA Netwitness
Investigator EMC Network packet capture and analysis
Acquire and/or analyse RAM images, including the page file on live
Memoryze Mandiant systems
MFTview Sanderson Forensics Displays and decodes contents of an extracted MFT file
Lists EXIF, and where available, GPS data for all photographs present in a
PictureBox Mike’s Forensic Tools directory. Export data to .xls or Google Earth KML format
Shadow Explorer Shadow Explorer Browse and extract files from shadow copies
Structured Storage
Viewer MiTec View and manage MS OLE Structured Storage based files
Windows File
Analyzer MiTeC Analyse thumbs.db, Prefetch, INFO2 and .lnk files
Mac OS tools
Audit Twocanoes Software Audit Preference Pane and Log Reader for OS X
Blackbag
Epoch Converter Technologies Converts epoch times to local time and UTC
Lists items connected to the computer (e.g., SATA, USB and FireWire
Blackbag Drives, software RAID sets). Can locate partition information, including
IORegInfo Technologies sizes, types, and the bus to which the device is connected
Blackbag Displays the physical partitioning of the specified device. Can be used to
PMAP Info Technologies map out all the drive information, accounting for all used sectors
Extracts phone model and software version and created date and GPS data
ivMeta Robin Wood from iPhone videos.
SAFT SignalSEC Corp Obtain SMS Messages, call logs and contacts from Android devices
Backtrack Backtrack Penetration testing and security audit with forensic boot capability
Caine Nanni Bassetti Linux based live CD, featuring a number of analysis tools
Digital Forensics Analyses volumes, file systems, user and applications data, extracting
Framework ArxSys metadata, deleted and hidden items
Forensic Scanner Harlan Carvey Automates ‘repetitive tasks of data collection’. Fuller description here
Paladin Sumuri Ubuntu based live boot CD for imaging and analysis
Volatility
Framework Volatile Systems Collection of tools for the extraction of artefacts from RAM
File viewers
View E01 files to view messages within email EDB, PST and OST and
E01 Viewer SysTools search for file names
Microsoft
PowerPoint 2007
Viewer Microsoft View PowerPoint presentations
VLC VideoLAN View most multimedia files and DVD, Audio CD, VCD, etc.
Internet analysis
Browser History Captures history from Firefox, Chrome and Internet Explorer web
Capturer Foxton Software browsers running on a Windows computer
Browser History Extract, view and analyse internet history from Firefox, Chrome and
Viewer Foxton Software Internet Explorer web browsers
Chrome Session Python module for performing off-line parsing of Chrome session files
Parser CCL Forensics (“Current Session”, “Last Session”, “Current Tabs”, “Last Tabs”)
Name From Description
Reads the cache folder of Google Chrome Web browser, and displays the
ChromeCacheView Nirsoft list of all files currently stored in the cache
Facebook Profile
Saver Belkasoft Captures information publicly available in Facebook profiles.
Extracts search queries made with popular search engines (Google, Yahoo
MyLastSearch Nirsoft and MSN) and social networking sites (Twitter, Facebook, MySpace)
Extracts the user names and passwords stored by Mozilla Firefox Web
PasswordFox Nirsoft browser
Reads the cache folder of Opera Web browser, and displays the list of all
OperaCacheView Nirsoft files currently stored in the cache
OperaPassView Nirsoft Decrypts the content of the Opera Web browser password file, wand.dat
Reviews list of URLs stored in the history files of the most commonly
Web Historian Mandiant used browsers
Extracts user information from the SAM, SOFTWARE and SYSTEM hives
ForensicUserInfo Woanware files and decrypts the LM/NT hashes from the SAM file
Process Monitor Microsoft Examine Windows processes and registry threads in real time
US National Institute of
Justice, Digital
Registry Decoder Forensics Solutions For the acquisition, analysis, and reporting of registry contents
USB Device
Forensics Woanware Details previously attached USB devices on exported registry hives
USB Historian 4Discovery Displays 20+ attributes relating to USB device use on Windows systems
User Assist Extracts SID, User Names, Indexes, Application Names, Run Counts,
Analysis 4Discovery Session, and Last Run Time Attributes from UserAssist keys
UserAssist Didier Stevens Displays list of programs run, with run count and last run date and time
Windows Registry
Recovery MiTec Extracts configuration settings and other information from the Registry
Application analysis
Dropbox Decrypts the Dropbox filecache.dbx file which stores information about files
Decryptor Magnet Forensics that have been synced to the cloud using Dropbox
Google Maps Tile Magnet Forensics Takes x,y,z coordinates found in a tile filename and downloads surrounding
Name From Description
KaZAlyser Sanderson Forensics Extracts various data from the KaZaA application
LiveContactsView Nirsoft View and export Windows Live Messenger contact details
For Reference
Safely remove SATA disks similar to the “Safely Remove Hardware” icon
HotSwap Kazuyuki Nakayama in the notification area
iPhone Backup
Browser Rene Devichi View unencrypted backups of iPad, iPod and iPhones
Ubuntu guide How-To Geek Guide to using an Unbuntu live disk to recover partitions, carve files, etc.
WhatsApp
Forensics Zena Forensics Extract WhatApp messages from iOS and Android backups