forensic

PhotoSeek - Forensic Analysis Tool 1
PhotoSeek - Forensic Analysis Tool is a utility equipped with the ability to identify similar images, even images which are resized, compressed, or changed to other formats like bmp, jpg, and gif. more>>
PhotoSeek - Forensic Analysis Tool 1 is a utility equipped with the ability to identify similar images, even images which are resized, compressed, or changed to other formats like bmp, jpg, and gif. . Proventsure develops software to search computers for sensitive and confidential information based on algorithms used by molecular biologists to map DNA, as well as many custom developed algorithms for decoding files and data to ID information and clustering file owners. Some of this research has applications in other areas, as is the case with PhotoSeek. This application is useful for law enforcement personal since it can identify similar photos, without the need for cryptographic file hashes, which are very frequently inaccurate at detecting image files. Images are easy to change without visible detection to the human eye, yet completely defeat file hash detection mechanisms.
First Response 1.1
security incident response management more>> MANDIANT First Response is Incident Response management software intended for information security staff, investigators and forensic professionals that respond to computer security incidents. MANDIANT recognizes the importance of investigating any potential computer security incident, and we created MANDIANT First Response to foster diligent, effective and efficient response to these incidents.<<less
Sound Restoration 1.0
Sound Restoration and Audio Forensics information at the click of a mouse! more>> Learn about Sound Restoration and Audio Forensics techniques via this custom search toolbar brought to you by http://www.SoundScrubbers.com and Rob Knebe. I created this toolbar initially just for personal use, but realized it can be helpful to other Sound Restoration specialists doing research and searching the net for Forensic Audio info.<<less
TotalRecall 1.1
Forensic analysis tools to reconstruct Internet Explorer and users activity more>> A lot of different information about a users activity is kept within the personal computer. Usually the user does not know about its existence. TotalRecall is a free forensic analysis tool to reconstruct Microsoft Internet Explorer (MS IE) activity and some users activity on the computer. IE caches URLs which were visited by users. MS IE stores its Internet activity in index.dat files. These files are binary database files, which are used by Microsoft as the file type for storing several different sets of information. Included among these files are user data, Internet cookies, and Internet history storage. These files are found scattered throughout the users profile folders. Because browser activity files are in binary form, special tools are required to read them. Now, our program investigates: IE activity, IE history, IE cookie, IE favorites and users activity (recent files and folders, not erased temporary files). After processing, the information from the source is loaded into the appropriate table (all information for the current user may be completed automatically). It is possible to open the file by the program with which it is associated just by double clicking on a selected line of a table. When you select the image from the table its thumbnail is shown at the bottom right corner and it helps you preview the pictures using a built-in viewer. Any table may be sorted by columns in any order. Find-command locates the row of a table containing the regular occurrence of the search string. The table context menu provides quick access to useful commands (Open, Open with? Open Folder, Copy/Move to? etc.). The contents of any table may be exported to an .XML or a .TXT file. The program allows collecting data for all tables or for some tables depending upon the criteria set. The program determines the language of your installation of Windows and sets the working language in accordance with corresponding language file (if it exists) then sets it as default.<<less
Forensic analysis tools to reconstruct Internet Explorer and users activity. TotalRecall investigates: MS IE activity, MS IE history, MS IE cookie, MS IE favoritesLicense:Freeware

FirePasswordViewer 1.2.2
FirePasswordViewer is designed as a useful popular FirePassword tool which can help you easily decrypt sign-on secrets stored by Firefox. more>>
FirePasswordViewer 1.2.2 is designed as a useful popular FirePassword tool which can help you easily decrypt sign-on secrets stored by Firefox. Firefox records the login details such as username and password for every website authorized by the user and stores them in the sign-on database file in encrypted format.
Major Features:
- FirePasswordViewer tool can decrypt and display these secrets on the same lines as the Firefox built-in password manager.
- The main advantage of FirePasswordViewer is that it does not require Firefox to be running. This is very useful in recovering the sign-on details when Firefox fails to function properly.
- Also FirePasswordViewer can be used to display sign-on secrets from different profile (other than current profile) as well as from the different operating system (such as Linux, Mac etc) altogether. This greatly helps forensic investigators who can copy the relevant files from the target system to test machine and view the credentials offline without affecting the target environment.
- The displayed sign-on information can then be saved to a file in standard HTML format which can be used as valuable and quick offline reference.
- FirePasswordViewer is the simple, standalone tool which does not require any installation. Here are the simple steps...
- Launch the FirePasswordViewer. It will automatically detect and fill the current profile directory. Alternatively you can copy the Firefox profile files from other machine and specify that folder path manually.
- Next enter the master password if it is set for that profile. Otherwise leave it blank.
- Once you have entered the profile path and master password details, click on the "Show" button to view the sign-on information as shown in the screenshot 1.
- Finally you can click on "Export" button to save the sign-on details to file in HTML format. This will save it to the specified file and display it using default browser as shown in the screenshot 2.
Enhancements:
- Support for recovering the passwords from Sqlite signon database file used by latest Firefox version 3.5.
This greatly helps forensic investigators who can copy the relevant files from the target system to test machine and view the credentials offline without affecting the target environment
Mobile Phone Inspector 2.0.1.5
gather all useful information about your mobile phone in GUI interface more>> Can fetch SMS stored in SIM and phone memory with all details like status of SMS, date and time of SMS and message text.This application will accurately detect cell phone hardware details, network and memory data. Mobile investigation application program quickly examines cell phone hardware through USB port and fetches data securely. Investigator tool displays PDA cell phone manufacturer name and model number. Forensic software detects signal quality and battery status of mobile phone that connected to pc port. Application tool fetches sim and phone IMSI number. Investigation program shows phonebook entries contact numbers and name. This software will fetch all SMS messages stored on SIM and phone memory with all details such as status of SMS, date and time, and the entire text. Main features: - Software examines the information including phone book contact numbers, SMS memory status, mobile manufacturer, model number, battery status, signal quality and IMEI number. - Software generates the detailed information report in text format for further use. - Software provides the step built help menu for assistance of users. - Easy to use software does not require any technical skill to operate it. - Tool compatible with Nokia, Samsung, Motorola, Sony Ericsson, LG and Spice mobile phones and PDARequirements: - 32 MB RAM - 9 MB Disk Space for installation Whats New in This Release: - Added support for all latest cell phones handsets.<<less
Mobile phone forensic tool shows general mobile phone details inclusive of Battery status; Mobile manufacturer Name, Mobile model number, Sim IMSI number Mobile IMEI number and Signal quality
Breachprobe 1.0
Breachprobe is a free product built for Computer Forensic Investigators. more>> <<less
DriveLook 1.00
DriveLook is a powerful forensic disk investigation tool more>>
DriveLook enables you to:
- index a hard drive for all text that was ever written to it
- browse a list of all words stored on the drive
- search for words or combinations of words
- view the location of words or in a disk editor
- switch between several views, such as hex and text views
- use physical drives or logical drives as an input
- use image files as an input
- access remote drives over serial cable or TCP/IP
DriveLook scans a drive or a partition of a drive for text strings and stores them in a table. After completion of the scan you can browse this table and view the locations where the words have been found. The search function allows you to do fast inquiries for combinations of words.
License name: Runtime Software
License key: BKZSBKFTUPYEK
MetaViewer 1.0
Pinpoint Metaviewer allows users to quickly extract file system metadata, OLE metadata contained in Microsoft Office and hash values. Once the information is retrieved users can paste all or selected more>>
Forensic examiners and litigation support professionals often need to retrieve the metadata for specific files. Pinpoint Metaviewer allows users to quickly extract file system metadata, OLE metadata contained in Microsoft Office Files and hash values all at the click of a mouse. Pinpoint Metaviewer is a right-click send-to utility that places the power of viewing metadata and hash values inside Windows Explorer. Once the information is retrieved users can paste all or selected fields into any application.
<<lessJDAFTS 20091111001
JDAFTS is considered as a convenient-to-use as well as effective suite which includes case data management applications that extend beyond the capabilities of currently-available forensic software applications. more>> <<less
Psychiatrie 1.0
this widget brings you the latest news from www.forensischepsychiatrie.nl more>>
You get information about (forensic) psychiatry, TBS. (Dutch language only.)
Protected Storage Explorer 2.0.0.12
Protected Storage Explorer is a powerful tool that allows you to view all sorts of saved data from the Protected Storage Service more>>
Main features:
- Easy to and intuitive to use
- Tree view for deep navigation of the Protected Storage
- Powerful HEX/ASCII viewer
- Toolbar buttons for easy location of Internet Explorer and Outlook Express passwords.
- Copy/Paste functionality
- Save to file option saves a snapshot of the Protected Storage to a file
- Small, fast download: PSESetup.zip (50Kb)
- Does not require install (does not make any modifications to host computer and leaves no traces)
- Tool could be used for password recovery or digital investigation. It?s a handy tool for any ?digital locksmith? or digital investigator to have
- Protected Storage Explorer is a free tool and contains no advertisements or spyware!
- Featured on Microsoft Windows XP Inside Out (Microsoft Press)
SharePoint Anti-Keylogger 1.0
SharePoint Anti-Keylogger scans, detects and removes keyloggers. more>>
Keyloggers are becoming commonplace methods for intruders to gain access to unauthorized systems by recording user keystrokes as they occur on the arbitrary machine, or in our case, our SharePoint Portal or Windows SharePoint Services server. Protecting your server from keyloggers is a fairly crucial measure in any security structure, ensuring your full control of your machines without worrying about compromising it to hackers.
Keyloggers can exist on two different levels, both on a hardware and software level. There are a range of available hardware keyloggers, ranging from those which are fairly easily to detect such as those that attach inline between the keyboard cable and those which bind to a port where the keyboard is installed, or those which are placed directly into the keyboard or laptop machine. Retrieving the data from the target machine can vary heavily depending on the application used, which has its own implications.
The most common way is to slip a trojan or other remote access application that allows the user direct access to the machine to query the log generated by the keylogger. Because SharePoint machines are often hooked into MS exchange servers, typically the information can automatically be sent via using email, which is slightly more elegant than the former technique because it lessens the trail detection and gives less evidence to forensic computer analysts.
Securing your SharePoint environment for keylogger is as important as web and network layer security. The SPS AKL is composed of two main modules that help you harden your SharePoint environment, one for detection and another for management. The central processing portions are kept as a windows service that will need to be installed.
Darik's Boot and Nuke for floppy disks and USB 1.0.7
Dariks Boot and Nuke for floppy disks and USB is familiar among lots of users as a self-contained boot disk that securely wipes the hard disks of most computers. more>>
Darik's Boot and Nuke for floppy disks and USB 1.0.7 is familiar among lots of users as a self-contained boot disk that securely wipes the hard disks of most computers. DBAN will automatically and completely delete the contents of any hard disk that it can detect, which makes it an appropriate utility for bulk or emergency data destruction.
DBAN is a means of ensuring due diligence in computer recycling, a way of preventing identity theft if you want to sell a computer, and a good way to totally clean a Microsoft Windows installation of viruses and spyware. DBAN prevents or thoroughly hinders all known techniques of hard disk forensic analysis.
This version of Darik's Boot And Nuke is for use on floppy disks and USB flash drives.
Dariks Boot and Nuke 2007042900 Beta
Dariks Boot and Nuke ( more>>
DBAN is a means of ensuring due diligence in computer recycling, a way of preventing identity theft if you want to sell a computer, and a good way to totally clean a Microsoft Windows installation of viruses and spyware. DBAN prevents or thoroughly hinders all known techniques of hard disk forensic analysis.
Usage:
Double-click the exe program to install DBAN to a floppy disk or USB flash device.
You must use an account with full hardware access to create the DBAN boot media. This means that you must be a member of the administrators group or have similar privileges on your Microsoft Windows computer. Virus scanners and domain policies can prevent you from creating the DBAN boot media.
The USB booting capabilities of many computers are incomplete or broken. Most computers capable of booting from a USB device require that it report a removable media type, and that it be unpartitioned and smaller than two gigabytes (so that the BIOS can boot it like a floppy disk).
If the drive letter of your USB device does not appear in WinImage drive list, then it is an unsupported media type. In particular, most USB+IDE bridge implementations are unrecognized, which means that a 2.5 inch hard disk in an external USB enclosure is incompatible.
DBAN prevents or thoroughly hinders all known techniques of hard disk forensic analysis. The development and support of the DBAN software project is funded in part by GEEP International. GEEP- Page: 1 of 2
- 1
- 2