Tags

forensics

Helix Live CD
RSS feed icon Updates feed
License: Open Source
Added: 2006.09.29
         (3 years ago)
Helix Live CD website
Description: A Linux live CD designed specially for forensic investigations, and incident response. Includes Windows utilities for imaging memory, and inspecting a running Windows computer. Based off of Knoppix.
Comment: Highly recomended. Popular with law enforcement forensic specialist. It has a long way to go to replace EnCase, but it is a very nice tool to have on hand. Gets better with every release. Seems to release about once a year.
Tags: forensics, live cd, security,
| Edit | Report error or broken link
Live View
RSS feed icon Updates feed
License: Open Source
Added: 2006.12.17
         (3 years ago)
Live View website
Description: Create a VMware virtual machine image from a dd (bit for bit) image of a real hard drive.
Comment: Very useful for forensic examinations, or moving an old computer to a virtual machine. Requires Java.
Tags: forensics,
| Edit | Report error or broken link
PhotoRec
RSS feed icon Updates feed
License: Open Source
Added: 2007.01.06
         (3 years ago)
PhotoRec website
Description: Recovers deleted files by recognizing the file format. Supports recovery of more than 80 formats.
Comment:
Tags: forensics, undelete, utility,
| Edit | Report error or broken link
TestDisk
RSS feed icon Updates feed
License: Open Source
Added: 2007.05.03
         (3 years ago)
TestDisk website
Description: Primarily designed to recover lost partitions, TestDisk works on a wide variety of file systems.
Comment:
Tags: forensics,
| Edit | Report error or broken link
VisualHash
RSS feed icon Updates feed
License: Open Source
Added: 2007.01.05
         (3 years ago)
VisualHash website
Description: A nice looking Windows program that generates several different types of hashes. Requires .net
Comment: From the website: "VisualHash supports most of the common hashing and one-way algorithms, including Adler-32, Cksum-32, CRC-16, CRC-16-CCITT, CRC-16-XModem, CRC-32, CRC-32-MPEG2, CRC-64, ELF-32, FCS-16, FNV-32, FNV-64, GOST, MD2, MD4, MD5, PJW-32, SDBM-32, SHA-1, SHA-256, SHA-384, SHA-512, Sum-32, XUM-32 and many more."
Tags: forensics, hash, security,
| Edit | Report error or broken link