Tool for decoding w...
 
Notifications
Clear all

Tool for decoding web-browser caches for forensic analysis

14 Posts
8 Users
0 Reactions
3,420 Views
 timj
(@timj)
New Member
Joined: 19 years ago
Posts: 1
Topic starter  

Cache View is a Windows tool for decoding web-browser caches. Cyber-crime investigators from around the world are using this tool for fast analysis of suspect web-browsing activity.

Visit the Cache View homepage http//www.webcacheview.com/

It supports all the major browsers Internet Explorer, Netscape, Firefox, and Opera.

Cache View extracts the following information about cached files
URL, filename in cache, Size (in bytes), MIME Type, last modified date, date the file was downloaded, expiry date, and the HTTP header data, where available.

It is released as shareware, and can be registered for only $15.


   
Quote
 Andy
(@andy)
Reputable Member
Joined: 21 years ago
Posts: 357
 

Does it detect and extract deleted internet history records from unallocated? And can it be used with extracted index.dat files from an image?

Cyber-crime investigators from around the world are using this tool for fast analysis of suspect web-browsing activity

Are they? Who exactly….?


   
ReplyQuote
(@jimmyw)
Trusted Member
Joined: 20 years ago
Posts: 64
 

NetAnalysis, http//www.digital-detective.co.uk, while quite a bit more costly, will extract and correctly parse all of the MSIE index records. It also features a tool named HistEx, which can retrieve index records from u/c.


   
ReplyQuote
arashiryu
(@arashiryu)
Estimable Member
Joined: 20 years ago
Posts: 122
 

I have been very satisfied with Netanalysis.

Free tool Pasco from foundstone is good as well.


   
ReplyQuote
(@farmerdude)
Estimable Member
Joined: 20 years ago
Posts: 242
 

Quietly mentioning Delve on THE FARMER'S BOOT CD has the capability to parse Internet Explorer, Opera, and Mozilla web cache (cookies and histories) as well. A simple point-and-click GUI on a truly designed and optimized for forensics Linux boot CD. www.forensicbootcd.com

cheers!

farmerdude


   
ReplyQuote
(@zyborski)
Active Member
Joined: 20 years ago
Posts: 12
 

As part of my MSc project year I wrote and tested a tool to rebuild web pages found within the MSIE cache. The tool will parse the Index.dat file and show all relevant forensic data, it also will attempt to rebuild the page using the contents of the extracted cache. The tool is currently in final beta and can be downloaded from
Download FIX Beta

The output of the tool has been tested, however it is still beta!

Kind Regards

Paul Slater


   
ReplyQuote
arashiryu
(@arashiryu)
Estimable Member
Joined: 20 years ago
Posts: 122
 

Tried out Delve. Excellent tool and output.


   
ReplyQuote
(@colsanders)
Active Member
Joined: 19 years ago
Posts: 8
 

Tried out Delve. Excellent tool and output.

\

Do you have a link handy? My Google-fu is weak today.

Thanks.


   
ReplyQuote
arashiryu
(@arashiryu)
Estimable Member
Joined: 20 years ago
Posts: 122
 

Colsanders,
Delve is on the farmerdude boot cd. It has come in very handy for internal corporate audits. Definetly sped up our processing of laptops coming in for service.

I don't believe it is available for download for free though.


   
ReplyQuote
(@mindsmith)
Estimable Member
Joined: 20 years ago
Posts: 174
 

Snapview from www. digital-detective.co.uk is a nice free tool for reconstructing the contents of IE cache.


   
ReplyQuote
Page 1 / 2
Share: