Remote Forensic Dat...
 
Notifications
Clear all

Remote Forensic Data Collection

6 Posts
4 Users
1 Reactions
3,103 Views
(@panamabay12)
Active Member
Joined: 3 years ago
Posts: 7
Topic starter  

Are there any tools that can collection in EO1 or Forensic 7zip that doesn't require hardware or installed software?


   
Quote
UnallocatedClusters
(@unallocatedclusters)
Honorable Member
Joined: 13 years ago
Posts: 576
 

Passmark's OSForensics can perform remote forensic imaging without the need to install any software locally or remotely.


   
ReplyQuote
drkaan
(@darthpiper)
New Member
Joined: 3 years ago
Posts: 2
 

Hi, you can also use FEX Imager and GetData Network Agent. The agent is a single executable. https://youtu.be/spUQre_9xUk

This post was modified 3 years ago by drkaan

   
ReplyQuote
(@panamabay12)
Active Member
Joined: 3 years ago
Posts: 7
Topic starter  

@darthpiper do you need physical access?


   
ReplyQuote
drkaan
(@darthpiper)
New Member
Joined: 3 years ago
Posts: 2
 

@panamabay12 the network agent is a single executable, you can try executing it remotely with MS Sysinternal's tools if you have necessary rights.


   
ReplyQuote
JimC
 JimC
(@jimc)
Estimable Member
Joined: 9 years ago
Posts: 86
 

You can serve a disk or filesystem to a remote client with my DMSERVER tool. For example, to publish on port 8080:

DMSERVER /PORT:8080 \\.\PhysicalDrive3

You can image a remote target to E01 using the DMIMAGE tool. For example, with the previous example:

DMIMAGE /CREATE:example.e01  http://targetpc:8080 

 

The software is a work-in-progress. It is available free-of-charge to bona fide forensic practitioners and researchers. If this is you, please drop me a message.

Jim

www.forensicinternals.com


   
ReplyQuote
Share: