Top 20 Free Digital Forensic Investigation Tools for SysAdmins Digital forensics tools come in many categories, so the exact choice of tool depends on where and how you want to use it. Here are some broad categories to give you an idea of the variety that comes under the umbrella of digital forensics tools: Database forensicsEmail analysisAudio/video forensicsInternet browsing analysisNetwork forensicsMemory forensicsFile analysisDisk and data captureComputer forensicsDigital image forensics While this is not an exhaustive list, it gives you a picture of what constitutes digital forensics tools and what you can do with them. Also, it is important to note that these categories can get blurred at times depending on the skill set of the staff, the lab conditions, availability of equipment, existing laws, and contractual obligations. But regardless of these variations, what is important is that digital forensics tools offer a vast amount of possibilities to gain information during an investigation. Choosing the right tool Skill level Output Cost Focus 17 HxD
Tools:Memory Imaging The physical memory of computers can be imaged and analyzed using a variety of tools. Because the procedure for accessing physical memory varies between operating systems, these tools are listed by operating system. Once memory has been imaged, it is subjected to memory analysis to ascertain the state of the system, extract artifacts, and so on. One of the most vexing problems for memory imaging is verifying that the image has been created correctly. Memory Imaging Techniques Crash Dumps When configured to create a full memory dump, Windows operating systems will automatically save an image of physical memory when a bugcheck (aka blue screen or kernel panic) occurs. LiveKd Dumps The Sysinternals tool LiveKd can be used to create an image of physical memory on a live machine in crash dump format. Hibernation Files Windows 98, 2000, XP, 2003, and Vista support a feature called hibernation that saves the machine's state to the disk when the computer is powered off. Firewire Memory Imaging Tools
UNIX System Administration: Solaris, AIX, HP-UX, Tru64, BSD.: Digital Forensic Tools: Imaging, Virtualization, Cryptanalysis, Steganalysis, Data Recovery, Data Carving, Reverse Engineering "Jrypbzr gb gur bgure fvqr." Computer Forensics is a science and an art. And to perform it, you need tools to identify, acquisition, preserve and analyze data in a clean, safe, non-destructive manner. Lots of tools. Everything from data acquisition to virtualization and steganalysis. A list of more or less free tools (mostly open source or freeware, but I have included some relevant commercial products) no digital forensics expert should be without: Data acquisition, enumeration, imaging and forensics tools: Toolkits and utilities. The Sleuth Kit and Autopsy Browser. Password recovery tools: You may often need to recover keys and passwords. "This text has been encrypted twice... for double protection!" Ophcrack is a very efficient Windows password cracker based on rainbow tables. Steganalysis and stenography: how to detect hidden data using stenography.