Windows Forensic Toolchest™ (WFT)



The Windows Forensic Toolchest™ (WFT) is designed to provide a structured and repeatable automated Live Forensic Response, Incident Response, or Audit on a Windows system while collecting security-relevant information from the system. WFT is essentially a forensically enhanced batch processing shell capable of running other security tools and producing HTML based reports in a forensically sound manner.





A knowledgeable security professional can use WFT to help look for signs of an incident, intrusion, or to confirm computer misuse or configuration. WFT produces output that is useful to the admin user, but is also appropriate for use in court proceedings. It provides extensive logging of all its actions along with computing the MD5/SHA1 checksums along the way to ensure that its output is verifiable. The primary benefit of using WFT to perform incident responses or audit is that it provides a simplified way of scripting such activities using a sound methodology for data collection.

I welcome any suggested features or changes or additional tool suggestions. Feedback from users of WFT would be greatly appreciated.



WINDOWS FORENSIC TOOLCHEST™ (WFT) FEATURES



  Windows Forensic Toolchest™ (WFT) Features2.X3.X
Provides Structured And Repeatable Live Forensic Response, Incident Response, Or AuditXX
Generation Of Both Raw Text And HTML ReportsXX
User-Editable Config File Controls ExecutionXX
Ability To Run Locally, Via CD/DVD, Or Thumb DriveXX
Configurable ToolpathXX
Macros Which Expand Dynamically Based On Run-Time ValuesXX
Detailed Run-Time LoggingXX
Verification Of All Executed ToolsXX
Detailed Hashing Of OutputXX
Support For MD5 HashXX
Support For SHA1 HashX
Ability To Verify WFT Config FilesXX
Automatic Updating Of WFT Hash Values For ToolsXX
WFT's Interactive Mode Provides Command-Line AlternativeX
Off-Line Report Generation Saves Time During CollectionX
Ability To Run SysInternals Tools Without ‘-accepteula’X
Color Output Highlights Important InfoX
Automatic OS & Drive DetectionX
Ability To Run Commands Based On Run-Time OSX
Ability To Fetch 3rd-Party ToolsX
Ability To Download Latest WFTX



WFT News
2009-07-02WFT v3.0.04 releasedv3.0.04 download
2008-07-03WFT v3.0.03 released
2007-07-30SANSfire 2007 BOF: What Is New With Windows Forensic Toolchest™ (WFT) v3.0PDF download
2007-06-03WFT v3.0.01 released
2006-06-10WFT presentation presented at the June 10th, 2006 North Texas Snort Users Group meeting.PDF download


轉自http://www.foolmoon.net/security/wft/index.html

0 意見: