I've put together a list of some of my favourite free computer forensic software. It's not meant to be definitive, it's rather a list of a personal preferences, though I do hope to add to it over time and so welcome any suggestions. All the links point to the latest versions of the software as of March 16 2010. Check the individual licenses for any restrictions.
http//
Maybe you should put some "separators".
Like "disk tools" (I am failing to see what has to do Ridgecrop's Format 32 with Forensics, BTW), "viewers", "USB tools", etc.
About FAT32, JFYI
http//
And (recovery, NOT "forensics")
http//
BOTH "recovery" and "forensics"
http//
http//
http//
http//
http//
and probably a few more that you may find useful/interesting.
I like the idea of a "list page". )
jaclaz
While not strictly "Forensic"..a tool I find invaluable (and has a hash function)..is Karen's Directory Printer ( http//
Thanks for the effort..
Maybe you should put some "separators".
Like "disk tools" (I am failing to see what has to do Ridgecrop's Format 32 with Forensics, BTW), "viewers", "USB tools", etc.
jaclaz
Separator's are a good idea. You're right regarding Ridgecrop's Fat32Format; I've changed the description on the top of page to "a selection of free software which may be of use to professional computer forensic practitioners." Thanks for the links to the tools too, will check them out later.
While not strictly "Forensic"..a tool I find invaluable (and has a hash function)..is Karen's Directory Printer (
www.karenware.com/powe...dirprn.asp ) .. This functionality should have been built into windows..
Thanks, that's a good one. It's now been added.
Like the train of thought here. A few more I thought of….
RegRipper - http//regripper.net/ - One of the first tools I run on almost every investigation. Quick way to get an overview of a Windows system by having the reg hives parsed to text files. Usually combine all outputs into a PDF and allow everyone on the investigation team to review so we can assess quickly direction of examination.
ConText - http//
FreeDiff v1.1.2 - http//
UVCView - Google It - Similar to USB view but a little more detailed with certain things.
WinDirStat - http//windirstat.info/ - A picture is worth a thousand words. Graphical representation of drive data.
ProDiscover Basic Edition - http//
FILE SIGNATURES TABLE - http//
OLE Deconstruct - http//
TimeLord by Paul Tew – http//
Log 2 Timeline - http//
I just want to point out too that Harlan did a blog post on this same topic within the last year. You could probably get a good starting list from that.
Tom
I released several FREE utilities (most of them encase enscripts) at CEIC yesterday as part of my presentation. Download link below
Scripts
Apple iPhone Backup Extractor
Bag Parser
CSC Extractor
Google Desktop Search Metadata Extractor
Google Desktop Index Data Extractor
Windows Search Index Data Extractor
INDX Extractor
IPD Extractor
Webmail Extractor
Link
http//
I haven't written any documentation on it, other than whats on the website and in my presentation(http//
Yogesh Khatri
42 LLC
Thanks for the comments and suggestions. I've now categorised and expanded the list. http//
Hey, I didn't see any in your list, so I wanted to make you aware that woany has numerous tools on his site http//
Thank you Jonathan for the post.
very nice!