I need your help please. I have to create a piece of software for my degree which is in Forensics so it has to be Forensics based. I would like you ideas of what software would help you, and what needs looking more into.
I only ask that…
1. You don't give ideas for huge pieces of software i.e make a free version of EnCase I have about 300 hours to spend.
2. It will be wrote it Java so will be cross platform but please stick to Windows as that's what I know and love (although I have an affair with my Mac).
3. If you give an idea please say what you would like the software to do i.e Link Files - software that would extract them and place them in date order or an order of your choice.
I would be very greatful for any ideas, the MORE the BETTER as I can mix it up a little.
I look forward to the challange, I'm sure I will posting a new topic "Forensics degree software, beta testers needed" D
Many thanks in advance
James
Parse the WMI information stores in the system32\wbem folder structure.
That way we can conduct WMI queries against a deadbox.
Would that be a good idea? ?I've already got a WMI application that works across the network using C#. I'm not stealing the idea Niz, just querying
Would that be a good idea? ?I've already got a WMI application that works across the network using C#. I'm not stealing the idea Niz, just querying
That's OK john, the more ideas the better. Can you think of any application that would help you?
Statistical analysis of written digital document to show percent likelihood the document was written by a specific individual
digital image evaluation to show percent of probability of modification or alteration, en masse
digital image comparison using automatic resizing and rotation to original, returning percent probability of match, en masse
Could there be anything to develop for internet investigations?
Hello Nizmon,
I'd like to see something simular as PC On/Off Time http//
Maybe you can implement some more options, like who has been logged in and which applications they possible have used, hibernation time, etc.
Microsoft has some nice information about it. Look at http//
Good luck! Let me know when you need beta testers. No matter what program you gonna develope.
Hello Nizmon,
I'd like to see something simular as PC On/Off Time http//
www.neuber.com/free/pctime/index.html , but in a forensic manner. Its a nice tool, but no save option. Another simular tool is PCUsageViewer http// www.pointstone.com/products/PCUsageViewer/ This one has a save option, but no remote viewing.
Maybe you can implement some more options, like who has been logged in and which applications they possible have used, hibernation time, etc.
Microsoft has some nice information about it. Look at http//www.microsoft.com/ntserver/nts/downloads/management/uptime/default.asp
May I ask what benefit this would be to an investigator? I'm assuming this would be a live forensic application?
Would that be a good idea? ?I've already got a WMI application that works across the network using C#. I'm not stealing the idea Niz, just querying
My post was to conduct WMI analysis against a deadbox.
What do you mean by a deadbox?