I wonder what tools, other than FTK, might be best (interpret as "easy-to-use" or "automatically parsed and displayed or saved") to use for finding/viewing/carving $I30 files.
Suggestions? (We accept Mastercard, Visa, and Sarcasm at Register 2. wink )
Thank you, in advance, for your thoughtful recommendations.
Top of my head, in no particular order -
The Sleuth Kit
WinHex
EnCase
INDXParse by Willi Balenthin
Hi,
I use "wisp" from TZWORKS, easy and efficient (thanks to them)
Thierry
Top of my head, in no particular order -
The Sleuth Kit
WinHex
EnCase
INDXParse by Willi Balenthin
Thank you for the suggestions, so far. I respect your knowledge and opinions.
I'm not sure I understand why EnCase and WinHex appear on the list. Manually carving the files (which falls short of the criteria of "easy-to-use" or "automatically parsed and displayed or saved") is the only option available in EnCase or WinHex to get the $I30 files. Is there an EnScript or some feature I'm missing in EnCase or WinHex? Would you be so kind as to expound on this?
I like the way FTK automatically parses/indexes and displays the $I30s, which expedites review and exporting. My interest lies in identifying another tool that performs in a similar manner.
I'll take a look at TZWORKS; they have very useful products.
"Easy to use" is a relative term.
There's an "Index Buffer Reader" EnScript floating around. I thought it even shipped with EnCase under the Examples/ folder…
Jon
Hi,
My utility fte supports parsing of INDX record($I30).
fte 1.8
http//
Currently fte supports parsing of general INDX record and slack area within INDX record, but doesn't support from unallocated area. You need to carve INDX record using blkls+scalpel or similar process if you want to examine deleted INDX record from unallocated area.
There's an "Index Buffer Reader" EnScript floating around. I thought it even shipped with EnCase under the Examples/ folder…
Jon
Jon,
Thanks for the suggestion. You are correct–it is part of EnCase. I successfully used it.
kazamiya,
Thank you for your suggestion.
There's an "Index Buffer Reader" EnScript floating around. I thought it even shipped with EnCase under the Examples/ folder…
Jon
Jon,
Thanks for the suggestion. You are correct–it is part of EnCase. I successfully used it.
kazamiya,
Thank you for your suggestion.