Free Computer Forensic Tools

Free Computer Forensic Tools

The table below lists a selection of free software which may be of use to professional computer forensic practitioners. It is the end user's responsibility to check the licensing agreements of each one before use.

Each download link goes directly to the producer's web site - the exception is for Ubuntu which links to a ‘how to’ guide. The version numbers and links are correct as of 16 May 2010. Forensic Control provides no support or warranties for their use.


Disk Tools
NameVersionFromNotes Download
FAT32 Format 1.05 Ridgecrop Enables large disks to be formatted as FAT32 http://bit.ly/97MNOv
FTK Imager 2.90 AccessData Imaging tool and disk viewer http://bit.ly/8pcIpW
CaseNotes1.2.2010.3QCCContemporaneous notes recorderhttp://bit.ly/amRjw8
Tableau Imager 1.10 Tableau Imaging tool for use with Tableau imaging products http://bit.ly/5LnKM1
Live View 0.7b CERT Allows examiner to boot dd images in VMware http://bit.ly/cZvXj3
Email Analysis
NameVersionFromNotes Download
Mail Viewer1.5.2MiTeCViewer for Outlook Express, Windows Mail/Windows Live Mail,
 Mozilla Thunderbird message databases and single EML files
http://bit.ly/9t116y
General
NameVersionFromNotes Download
CaseNotes1.2.2010.3QCCContemporaneous notes recorderhttp://bit.ly/amRjw8
File Signatures 10/05/2010 Gary Kessler Table of file signatures http://bit.ly/9TUevt
HashMyFiles1.65NirsoftCalculate MD5 and SHA1 hasheshttp://bit.ly/diG02W
Mouse Jiggler1.1Arkane SystemsAutomatically moves mouse pointer stopping screen saver,
 hibernation etc
http://bit.ly/axWizs
Notepad ++5.6.8Notepad ++Advanced Notepad replacementhttp://bit.ly/bQw7k9
NSRL2.28NISTHash sets of 'known' (ignorable) fileshttp://bit.ly/cfQs4W
File & Data Analysis
NameVersionFromNotes Download
DCode 4.02a Digital Detective Converts various data types to date/time values http://bit.ly/5lHVgO
Exif Reader 3.00 Ryuuji Yoshimoto Extracts exif data from digital photographs http://bit.ly/9L2NsW
PsTools 7/1/2009 Microsoft Suite of command-line Windows utilities http://bit.ly/cKgdgC
Shadow Explorer0.7Shadow ExplorerBrowse and extract files from shadow copies
SkypeLogView1.12NirsoftView Skype calls and chatshttp://bit.ly/c8atFG
Strings2.41MicrosoftCommand-line tool for text searcheshttp://bit.ly/bzxYZu
Structred Storage Viewer3.3.1MiTecView and manage MS OLE Structured Storage based fileshttp://bit.ly/cgFgaH
TimeLord0.1.5.6Paul TewTime utility; timezones, BIOS times, decode computer time formatshttp://bit.ly/blCI9S
Windows File Analyzer1MiTeCAnalyse thumbs.db, Prefetch, INFO2 and .lnk fileshttp://bit.ly/dayWCd
File Viewers
NameVersionFromNotes Download
Fragview1.2.5.3QCCView recursive HTML, jpg and Flash fileshttp://bit.ly/amRjw8
IrfanView 4.27 IrfanView Graphics viewer. Plug-ins available http://bit.ly/cZiCht
Microsoft Excel 2007 Viewer 1.00 Microsoft View Excel spreadsheets http://bit.ly/9x2AVL
Microsoft PowerPoint 2007 Viewer 1.00 Microsoft View PowerPoint presentations http://bit.ly/aDj99g
Microsoft Visio 2007 Viewer 1.00 Microsoft View Visio diagrams http://bit.ly/dcE3DZ
Microsoft Word 2007 Viewer 1.00 Microsoft View Word documents http://bit.ly/ccUykb
VideoTriage1.2.5.1805QCCProduces thumbnails of video files so that the whole
 video doesn't need to be watched
http://bit.ly/amRjw8
Internet History Analysis
NameVersionFromNotes Download
ChromeAnalysis1.0.1forensic-softwareAnalysis of internet history data generated using Google Chromehttp://bit.ly/dcv7vw
FoxAnalysis1.4.2forensic-softwareAnalysis of internet history data generated using Mozilla Firefox 3http://bit.ly/dcv7vw
Registry Analysis
NameVersionFromNotes Download
Process Monitor 2.90 Microsoft Examine Windows processes and registry threads in real time http://bit.ly/9xVWDT
RegRipper20080909Harlan CarveyRegistry data extraction and correlation toolhttp://bit.ly/cq0FQF
Regshot1.8.2RegshotTakes snapshots of the registry allowing comparisons e.g.,
 show registry changes after installing software
http://bit.ly/c7cIKM
USBDeview1.67NirsoftDetails previously attached USB deviceshttp://bit.ly/dj2x2f
UserAssist2.4.3Didier StevensDisplays list of programs run, with run count and
 last run date and time
http://bit.ly/dgFvn7

轉自http://www.forensiccontrol.com/fcresources.php

0 意見: