Tuesday, March 22, 2016

Autopsy and Sleuth Kit

These are two separate pieces of software that work in tandem. Autopsy is a  GUI based tool that allows you to analyze hard drives on computers or mobile devices. Sleuth Kit works in the background and can restore files. It is open source so its free and used by thousands. However that also means that there is no formal training, but a user forums.
http://www.sleuthkit.org/

Tuesday, March 15, 2016

Registry Recon

Arsenal Recon has developed a registry parser on steroids. Registry Recon is a program that resurrects the full registry, rather then a parser that pieces the registry together.  This makes it much easier for analysts to find any data that someone may have been trying to hide. The cost is steep at $599. But for that you do get tool that some consider the gold standard for registry forensics.

https://arsenalrecon.com/apps/recon/

Use Key History to view a key's values at a particular time

Tuesday, March 8, 2016

X-Ways

X-Ways is a software tool that is produced by a German company. This program can be installed on a USB stick so it is very portable. It runs on Windows OS platforms from XP to 8.1. X-Ways has over 50 standard features and that many specialist features too, making it a very robust cyber forensics tool for forensics examiners. There is a cost to this program but also a certification, extensive user manual , videos and book. http://www.x-ways.net/forensics/

Thursday, March 3, 2016

CAINE

CAINE (Computer Aided Investigative Environment) is built for the Linux environment digital forensics. This open source tool has an organized GUI. It supports digital investigator by providing all the tools in a user-friendly tools. This is an open source software so online support is limited to forums. So many of the experts with this software are self taught. 
The product can be found at: http://www.caine-live.net/