Notifications
Clear all

Open source tools:

6 Posts
4 Users
0 Reactions
608 Views
(@kenweed)
New Member
Joined: 19 years ago
Posts: 4
Topic starter  

Hi everyone, can some one recommend me an open source forensic tool that has equal functionality with the likes of encase, FTK, winhex etc.


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Sure…PyFlag, TSK/Autopsy…


   
ReplyQuote
az_gcfa
(@az_gcfa)
Estimable Member
Joined: 19 years ago
Posts: 116
 

Helix is not necessary like Encase and FTK but provides a CD based option for creating forensic images and performing Incident Response tasks. Plus - it is free and is based on open source. It even has windows utilities to assist in performing IR functions on running windows systems.


   
ReplyQuote
(@farmerdude)
Estimable Member
Joined: 20 years ago
Posts: 242
 

Kenweed,

You didn't state what your definition of "open source forensic tool" is (IE, free, or runs on Linux), so here are a few others;

SMART for Linux
www.asrdata.com
www.smartforensics.net

THE FARMER'S BOOT CD (FBCD)
www.forensicbootcd.com

Both are commercial, both run on Linux, have some level of functionality, and afford you the capability to type or point-and-click.

regards,

farmerdude


   
ReplyQuote
(@kenweed)
New Member
Joined: 19 years ago
Posts: 4
Topic starter  

Well thank you guys for your contribution…My definition for an open source tool was one whose binary and source code can be accessed freely and if possible the tool can run on both linux and windows (not a must though!).


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Kenweed,

I think we all understand that part…I believe the question is, with regards to the "forensic tool that has equal functionality with the likes of encase, FTK, winhex etc." What functionality are you asking for? Imaging/acquistion? Analysis? Presentation?


   
ReplyQuote
Share: