DFF (Digital Forensics Framework) is a simple but powerful tool with a flexible module system which will help you in your digital forensics works, including file recovery due to error or crash, evidence research and analysis, etc. DFF provides a robust architecture and some handy modules.
jared (just another registry editor) is a Java library for editing the Windows registry. It reads a registry file into memory and allows modifications and rewriting of the file. It also contains a command line program for mods using a .reg file. The code supports gcj. jared is particularly appropriate for modifying or analyzing registry hives offline.
Hot Copy creates an instant point-in-time snapshot of any block device while the system is running without interrupting applications or requiring the use of LVM. As block level changes are made to the real device, hot copy makes a backup copy of the changed block. The changed blocks are efficiently stored in unused space on your hard disk. These stored changed blocks maintain a point-in-time snapshot and space is only needed when you make changes to the real device. You can even write to your snapshots.
fsarchiver is a system tool that allows you to save the contents of a filesystem to a compressed archive file. The filesystem can be restored on a partition that has a different size, and it can be restored on a different filesystem. Unlike tar/dar, fsarchiver also creates the filesystem when it extracts the data to partitions. Everything is checksummed in the archive in order to protect the data. If the archive is corrupt, you just lose the current file, not the whole archive.
BG-Tiny Linux Bootdisk is a Linux bootdisk that does not use a ramdisk, so it will run on computers with very little RAM. It is basically a somewhat extended fork of Tiny Linux Bootdisk. It is based on Linux 2.4 series, uClibc, and BusyBox. It includes dosfsprogs, e2fsprogs, gpart, lilo, and ms-sys. Supported filesystems are ext2, ext3, iso9660, tmpfs, and vfat.