±Your Account


Nickname
Password


Forgotten password/username?


Membership:
New Today: 2
New Yesterday: 2
Overall: 24170
Visitors: 41

network forensic hardware

Computer forensics discussion. Please ensure that your post is not better suited to one of the forums below (if it is, please post it there instead!)
Reply to topicReply to topic Printer Friendly Page
Forum FAQSearchView unanswered posts
 
  

network forensic hardware

Post Posted: Thu May 10, 2012 12:03 pm

I am intereated, in knowing, which hardware is recommended for network forensic.
thanks you  

sebastianorossi
Senior Member
 
 
  

Re: network forensic hardware

Post Posted: Thu May 10, 2012 4:31 pm

I have used FTK V3 for this. Worked well.  

pizzmor
Newbie
 
 
  

Re: network forensic hardware

Post Posted: Fri May 11, 2012 3:54 am

What exactly are you planning to do;
Do you want to image over a network?
Do you want to conduct a full investigation over a network?

Are you connecting directly (network cross over cable)?
Are you connecting to a network in a different building?  

dill
Member
 
 
  

Re: network forensic hardware

Post Posted: Sun May 13, 2012 2:25 am

Actually I have no job in this field. I was only studying the situation.
My second idea, is to create new software and hardware for network investigations
thanks  

sebastianorossi
Senior Member
 
 
  

Re: network forensic hardware

Post Posted: Sun May 13, 2012 2:25 pm

Actually, there is plenty of hardware and software that works very well. What isn't working very well is the file formats. They are old and do not compress very well.

If you want to contribute to the field, try creating a fileformat that have all the advantages of PCAP but also compresses well. Or find a way to compress PCAP files better. It also has to integrate well with standard tools like Wireshark/Tshark and TCPDump. Digital signatures would be nice too.  

MDCR
Senior Member
 
 
  

Re: network forensic hardware

Post Posted: Mon May 14, 2012 9:36 am

ok thanks, will study about it  

sebastianorossi
Senior Member
 
 
  

Re: network forensic hardware

Post Posted: Mon May 14, 2012 11:24 am

If you want to do network forensics, another thing you can try is to learn how to create & use Virtual Machines (VMs). They will allow you to practice network forensics on one computer.

From there you can install and try out FTK, Encase, F-responce, WireShark and other tools to learn about network forensics.

I suggest you look into some forensic classes that will teach you the basics so you can learn more from there.

good luck.
_________________
------------------------
Jason Pickens, EnCE, EnCEP
New York, NY
@JasonPickens
forensicnewbs.wordpress.com 

jpickens
Member
 
 
Reply to topicReply to topic

Share this forum topic to encourage more replies



Page 1 of 1