|
| Title:Event Log Parser
|
Author:Jamie French
|
| Description:
A PHP script to parse through Windows event logs.
|
| Website:
http://www.whitehats.ca/main/members/Malik/malik_eventlogs/malik_eventlogs.html
|
| Source:
http://www.whitehats.ca/main/members/Malik/malik_eventlogs/malik_eventlogs.html
|
|
| Title: Galleta
|
Author: Keith Jones
|
| Description:
Galleta, the Spanish word meaning "cookie", was developed to examine
the contents of the cookie files. Galleta will parse the information
in a Cookie file and output the results in a field delimited manner
so that it may be imported into your favorite spreadsheet program.
Galleta is built to work on multiple platforms and will execute on
Windows (through Cygwin), Mac OS X, Linux, and *BSD platforms.
|
| Website:
http://www.foundstone.com/resources/proddesc/galleta.htm
|
| Source:
http://sourceforge.net/project/showfiles.php?group_id=78332&release_id=152412
|
|
| Title: libpff
|
Author: Joachim Metz
|
Description:
The libpff package contains a shared library and tooling to analyse Microsoft Outlook Personal Folder Files (PAB, PST and OST). PFF files are used to store e-mails, appointments, contacts, notes, tasks, etc. libpff provides:
- pffexport to export PFF items
- pffinfo to provide basic information about PFF files
- pffrecover to recover and export PFF items
|
| Website:
http://libpff.sourceforge.net
|
|
| Title:
md5deep |
Author:
Jesse Kornblum |
| Description:
md5deep is an MD5 program that can compute recursively, compare
hashes with a database, and estimates the time to completion.
|
| Website:
http://md5deep.sourceforge.net/
|
| Source:
http://md5deep.sourceforge.net/
|
|
| Title: MD5summer
|
Author: Luke Pascoe
|
| Description:
MD5summer is an application for Microsoft Windows 9x, NT, ME, 2000
and XP which generates and verifies md5 checksums. Its output file
is compatible with the output of the Linux GNU MD5Sum and it will
also read Linux generated files.
|
| Website:
http://www.md5summer.org/
|
| Source:
http://www.md5summer.org/download.html
|
|
| Title: Outport
|
Author: chief1ic
|
| Description:
Outport provides a means of migrating information from Microsoft Outlook to Ximian Evolution and several standard data formats.
|
| Website:
http://outport.sourceforge.net/
|
| Source:
http://outport.sourceforge.net/
|
|
| Title: Pasco
| Author: Keith Jones
|
| Description:
Pasco, the latin word meaning "browse", was developed to examine
the contents of Internet Explorer's cache files. Pasco will parse
the information in an index.dat file and output the results in a
field delimited manner so that it may be imported into your favorite
spreadsheet program. Pasco is built to work on multiple platforms
and will execute on Windows (through Cygwin), Mac OS X, Linux, and
*BSD platforms.
|
| Website:
http://www.foundstone.com/resources/proddesc/pasco.htm
|
| Source:
http://sourceforge.net/project/showfiles.php?group_id=78332&release_id=152387
|
|
| Title:
ProDiscover DFT |
Author:
Technology Pathways LLC |
| Description:
ProDiscover DFT offers forensics examiners a completely integrated
Windows application for the collection, analysis, management and
reporting of computer disk evidence at an affordable price.
|
| Website:
www.techpathways.com
|
| Source:
www.techpathways.com (Requires the purchase of an Enterprise License)
|
|
| Title: RegRipper
|
Author: Harlan Carvey
|
| Description:
The RegRipper is an open-source application for extracting, correlating, and displaying specific information from
Registry hive files from the Windows NT (2000, XP, 2003, Vista) family of operating systems.
|
| Website:
http://windowsir.blogspot.com/2008/04/updated-regripper.html
|
|
| Title: Rifiuti
|
Author: Keith Jones
|
| Description:
Rifiuti, the Italian word meaning "trash", was developed to examine
the contents of the INFO2 file in the Recycle Bin. Rifiuti will
parse the information in an INFO2 file and output the results in
a field delimited manner so that it may be imported into your
favorite spreadsheet program. Rifiuti is built to work on multiple
platforms and will execute on Windows (through Cygwin), Mac OS X,
Linux, and *BSD platforms.
|
| Website:
http://www.foundstone.com/resources/proddesc/rifiuti.htm
|
| Source:
http://sourceforge.net/project/showfiles.php?group_id=78332&release_id=152410
|
|