RSS 6 projects tagged "Forensics"

Download No website Updated 01 Mar 2013 Digital Forensics Framework

Screenshot
Pop 142.67
Vit 4.90

DFF (Digital Forensics Framework) is a simple but powerful tool with a flexible module system which will help you in your digital forensics works, including file recovery due to error or crash, evidence research and analysis, etc. DFF provides a robust architecture and some handy modules.

Download No website Updated 14 Jan 2010 FileExtractor

Screenshot
Pop 29.56
Vit 39.53

FileExtractor is a tool for recovering files from a binary data source. It is useful when sources such as digital cameras, partitions, hard drives, memory sticks, or floppy disks are corrupted, deleted, or formatted by mistake.

Download Website Updated 20 Jun 2011 GrokEVT

Screenshot
Pop 108.08
Vit 5.28

GrokEVT is a collection of scripts built for reading Windows® NT/2K/XP/2K3 event log files. The scripts work together on one or more mounted Windows partitions to extract all information needed (registry entries, message templates, and log files) to convert the logs to a human-readable format.

No download Website Updated 02 Oct 2011 RegLookup

Screenshot
Pop 133.87
Vit 7.22

The RegLookup project is devoted to direct analysis of Windows NT-based registry files. RegLookup provides command line tools, a C API, and a Python module for accessing registry data structures. The project has a focus on providing tools for digital forensic examiners (though it is useful for many purposes), and includes algorithms for retrieving deleted data structures from registry hives.

Download Website Updated 19 Mar 2009 dc3dd

Screenshot
Pop 68.35
Vit 1.81

dc3dd is a patched version of GNU dd to include a number of features useful for computer forensics.

Download No website Updated 06 Dec 2013 gpart

Screenshot
Pop 71.11
Vit 1.59

Gpart is a small tool which tries to guess which partitions are on a PC harddisk in case the primary partition table was damaged. It works by scanning through the device (or file) given on the commandline on a sector basis. Each guessing module is asked if it thinks a filesystem it knows about could start at a given sector. Several filesystem guessing modules are built in, and others can be added dynamically.

Screenshot

Project Spotlight

PeRKy

A tool for managing software requirements.

Screenshot

Project Spotlight

Polipo

A lightweight caching Web proxy.