|
| Title:
Forensic Acquisition Utilities |
Author:
George Garner |
| Description:
A collection of Windows tools such as 'dd.exe', 'md5sum.exe',
'wipe.exe', and 'nc.exe'. The version of 'dd' in this package
can also image memory contents in addition to disks.
|
| Website:
http://users.erols.com/gmgarner/forensics/
|
| Source:
http://users.erols.com/gmgarner/forensics/
|
|
| Title:
FTimes |
Author:
Klayton Monroe |
| Description:
FTimes is a system baselining and evidence collection tool. The primary purpose of ftimes is to gather and/or develop information about specified directories and files in a manner conducive to intrusion analysis.
|
| Website:
http://ftimes.sourceforge.net/FTimes/index.shtml
|
| Source:
http://sourceforge.net/project/showfiles.php?group_id=41134
|
|
| Title: liveview
|
Author: CERT
|
| Description: Live View is a Java-based graphical forensics tool that creates a VMware virtual machine out of a raw (dd-style) disk image or physical disk. This allows the forensic examiner to "boot up" the image or disk and gain an interactive, user-level perspective of the environment, all without modifying the underlying image or disk. Because
|
| Website:
http://liveview.sourceforge.net/
|
|
| Title:
netcat |
Author:
hobbit |
| Description:
Netcat has been dubbed the network swiss army knife. It is a simple Unix utility which reads and writes data across network connections, using TCP or UDP protocol. It can be used on a trusted server to save
data from a suspect system and can be used on the suspect system to send
the output of tools to the server instead of writing to the suspect disk.
|
| Website:
http://www.atstake.com/research/tools/network_utilities/
|
| Source:
http://www.atstake.com/research/tools/network_utilities/
|
|
| Title:
pdd |
Author:
Joe Grand |
| Description:
pdd (Palm dd) is a Windows-based tool for memory imaging and
forensic acquisition of data from the Palm OS family of PDAs. pdd
will preserve the crime scene by obtaining a bit-for-bit image or
"snapshot" of the Palm device's memory contents. Such data can be
used by forensic investigators, incident response teams, and
criminal and civil prosecutors.
|
| Website: [no longer exists] |
| Source:
[local copy]
|
|
| Title:
ProDiscover DFT |
Author:
Technology Pathways LLC |
| Description:
ProDiscover DFT offers forensics examiners a completely integrated
Windows application for the collection, analysis, management and
reporting of computer disk evidence at an affordable price.
|
| Website:
www.techpathways.com
|
| Source:
www.techpathways.com (Requires the purchase of an Enterprise License)
|
|
| Title:
psloggedon |
Author:
Mark Russinovich (sysinternals.com) |
| Description:
PsLoggedOn is an applet that displays both the locally logged on users and users logged on via resources for either the local computer, or a remote one.
|
| Website:
http://www.sysinternals.com/ntw2k/freeware/psloggedon.shtml
|
| Source:
http://www.sysinternals.com/ntw2k/freeware/psloggedon.shtml
|
|
| Title:
TULP2G
|
Author:
Netherlands Forensic Institute (NFI)
|
| Description:
TULP2G is a forensic software framework developed to make it easy to extract and decode data from digital devices. Besides the framework, it is distributed along with several plug-ins to read data from digital devices (at this point, mobile phones and SIM cards).
|
| Website:
http://sourceforge.net/projects/tulp2g/
|
| Source:
http://sourceforge.net/project/showfiles.php?group_id=119389
|
|
| Title:
UnxUtils |
Author:
Karl Syring |
Description:
Ports of GNU tools, including 'dd', that do not need special DLLs.
|
| Website:
http://unxutils.sourceforge.net
|
| Source:
http://unxutils.sourceforge.net (via CVS)
|
|
| Title:
Webjob |
Author:
Klayton Monroe |
| Description:
WebJob downloads a program over HTTP/HTTPS and executes it in one unified operation. The output, if any, may be directed to stdout/stderr or a Web resource. WebJob may be useful in incident response and intrusion analysis as it provides a mechanism to run known good diagnostic programs on a potentially compromised system.
|
| Website:
http://webjob.sourceforge.net/WebJob/index.shtml
|
| Source:
http://sourceforge.net/project/showfiles.php?group_id=40788
|
|