Friday, September 30, 2011

Forensic software tools for Windows

Software Description  Licence Homepage
dd for Windows dd but for Windows. GPL Download Page 
Encase 4 EnCase 4 is a complete forensic toolkit that covers much of the work that the I&TM Forensic Analysts carry out.
Encase is the Primary I&TM forensic tool
Commercial Download Page
FTK The AccessData Forensic Toolkit (FTK) is another complete forensic toolkit.
FTK is recognized as one of the leading forensic tool to perform e-mail analysis.
Commercial Download Page
MD5 Toast MD5 Hashing algorithm GPL Download Page
ISOBuster IsoBuster is a CD/DVD and (Disk) Image File data recovery tool, that can read and extract files, tracks and sessions from CD-i, VCD, SVCD, CD-ROM, CD-ROM XA, DVD, DVCD and others. It also supports the following image file formats: *.DAO (Duplicator), *.TAO (Duplicator), *.ISO (Nero, BlindRead, Creator), *.BIN (CDRWin), *.IMG (CloneCD), *.CIF (Creator), *.FCD (Uncompressed), *.NRG (Nero), *.GCD (Prassi), *.P01 (Toast), *.C2D (WinOnCD), *.CUE (CDRWin), *.CIF (DiscJuggler), *.CD (CD-i OptImage) and *.GI (Prassi PrimoDVD). The program uses several retry-mechanisms to aid you in getting the data, even if Windows is not able to do so. Additional features include Mpg (*.dat) Extraction, support for file system properties, CDText support and much more. The vast majority of the features available are free; however some advanced features like UDF support are only available in a registered version. You can choose at install time, which version to use. Shareware Download Page
MD5 & Hashing Utilities MD5 hashing algorithm Shareware Download Page
P2 Power Pack This product currently contains the following items from Paraben Forensics:
  • Case Agent Companion v1.0;
  • Decryption Collection Enterprise v2.5;
  • E-mail Examiner v4.01;
  • Forensic Replicator v3.1;
  • Forensic Sorter v1.0;
  • Network E-mail Examiner v1.9;
  • PDA Seizure v3.0.1.35;
  • Text Searcher v1.0;
  • Chat Examiner v1.0.
Commercial Download Page
Paraben Case Agent Companion Paraben’s Case Agent Companion is designed to optimize both the time of the examiner and the agent working the case. Built in viewers for over 225 file formats and compatible with Paraben’s P2. Commercial Download Page
Paraben Email Examiner Paraben's E-mail Examiner is one of the most comprehensive e-mail examination tools available. E-mail Examiner claims to recover more active and deleted mail messages than the leading competitor. Commercial Download Page
Paraben Network Email Examiner Network E-mail Examiner allows the user to thoroughly examine a variety of network e-mail archives. Network E-mail Examiner is designed to work hand-in-hand with E-mail Examiner and all output is compatible and can easily be loaded for more complex tasks. Commercial Download Page
Paraben Forensic Replicator Replicate exact copies of drives and media. Paraben’s Forensic Replicator can acquire a wide range of electronic media from a floppy to a hard disk. Forensic Replicator images can be compressed and segmented and easily read into the most popular forensic analysis programs. Commercial Download Page
Paraben Forensic Sorter Manage your data effectively and efficiently. Forensic Sorter classifies data into over 14 different categories, recovers deleted files, and filters out common hashes (FOCH), making examinations easier to manage, faster to process, and easier to find what you’re looking for. Commercial Download Page
Paraben NetAnalysis Interrogates internet cache and history with powerful searching, filtering and evidence identification. Commercial Download Page
Paraben Text Searcher 
Paraben's Text Searcher is a fast, comprehensive, and feature-rich text searching tool. Commercial Download Page
SafeBack SafeBack is used to create mirror-image (bit-stream) backup files of hard disks or to make a mirror-image copy of an entire hard disk drive or partition. Commercial Download Page
SHA verify SHA verify is a hashing program which will calculate the MD5 (128 bit), SHA1 (160 bit), SHA2 (256 bit), SHA2 (384 bit), and SHA2 (512 bit) hashes of files.
A 2004 enhancement is that if you have a number of dd (flat) images, it can perform the hashes on the entire set of files and provides a single hash as if it was a single file. This is useful for confirming the hash of a physical drive against the set of dd files.
Freeware Download Page
UTK The Ultimate Toolkit is the complete AccessData Software Kit.
This contains the FTK, DNA and PRTK.
Commercial Download Page
WinHex WinHex is a universal hexadecimal editor.
WinHex is often used in forensic examinations
Freeware Download Page

0 comments to “Forensic software tools for Windows”

Post a Comment

New Hacks to Your Mail - Follow by Email

Related Posts Plugin for WordPress, Blogger...

Popular posts


Computer Hack World Copyright © 2011 -- Template created by O Pregador -- Powered by Blogger