152 Cyber Forensics
; — i
5.2.4 Computer Forensics Investigations .
Cybercrime investigation works in phases. In the first phase, the forensic investigator does a preliminary analysis
and gathers information from the crime scene. In the second phase, he/she works on forensic copy acquisition
and recovery, and in the third phase he/she performs a detailed analysis and prepares a comprehensive report,
This is shown in Fig. 5.2. For doing these, the forensic investigator should possess extensive knowledge in this
area and highly specialized skills. The evidence in the case of a cybercrime has to be gathered from ECDs.
copy
acquisition,
a recovery,
©. Preliminary and
analysis extraction
Fig.5.2 Phases of cybercrime investigations
5.2.5 Steps in Forensic Investigation
Cyber forensic investigation should ensure the integrity of the evidence while handling and analysing so that
the evidence is admissible in court. The steps in forensic investigation are explained here, and is shown as a
flowchart in Fig. 5.3. !
1. The investigation starts when a crime is reported or a complaint is received.
2. In response to the complaint, the following are made;
(a) If evidence has to be gathered from a third party, a notice is served to preserve it.
(b) If it is a criminal offence, a first information report (FIR) is filed.
(c) A search warrant (if required) is obtained from the court.
3. First responder or computer emergency response team (CERT) procedures are performed (Boxes 5.1 and
Pe 4&
4. Evidence is seized from the crime scene. This includes photographing the scene and marking the evidence.
Necessary documentation is also done. Witnesses present during the seizure of evidence and the suspect
himself/herself can be interviewed. If there are any complications in evidence collection, or if the investi-
gating officer (IO) does not possess evidence collection expertise, a third-party expertise may be called in.
Evidence involving a third party must also be collected. The chain of custody has to be documented.
Box 5.1 First Responder
The first responder is the person who first reports to the crime scene and assesses the ECD present
at the crime scene. He/She can be a network administrator, a law enforcement officer, an investi-
gating officer, or a person from the forensic lab. He/She is responsible for protecting, integrating,
and preserving the evidence from a crime scene. The first responder should be competent enougt
to handle the forensic investigation procedures. He/She has to collect evidence in a forensically
secure manner and ensure the admissibility of the evidence.
—————————CSC~—<“<;‘“‘~*~*:C:*:*SCSCSCintroduction
to Cyber Forensics 153
Box 5.2 Computer Emergency Response Team
The CERTis an expert group that handles computer security incidents. It is also called computer
security incident response team (CSIRT). It was first formed in 1988, when worms and viruses
hit the Internet at Carnegie Mellon University, under the US government contract so as to handle
computer security incidents. Now CERT/CSIRT is an integral and essential component of any
organization taking care of information security operations.
Complaint
received
Criminal Decision making
offence? OSION. MAKING©on
the process of law
Issue notices to
Register FIR external agencies to
preserve data
Carry out Identification
and
documentation
Photography/ Seek
Evidence
Videography/ collection
No _| forensic/expertise/ Collection and
Notes technical help imaging of evidence
expertise
from third party
service providers
Interviewing Evidence External/Third-party
witnesses/ collection/ service provider to
accused Packing collect evidence
Forensic analysis Reporting and
request analysis
Collect reports and
information
Forensic reports
Final report
Consider statements, forensic reports, and
external third party
evidences and prepare final report
Fig.5.3 Flowchart of cyber forensic investigation
5. The collected evidence is numbered and securely transported to the forensic laboratory for analysis.
6. The following are done at the forensic lab:
154 CyberForensics
(a) Two bit stream copies of the evidence are created. The hash values of the original and forensic copies
are verified.
(b) Chain of custody is maintained.
(c) The original evidence is stored in a secured location.
(d) The forensic copy is analysed for evidence.
(ec) A forensic report is prepared stating the methods and the recovery tools used, the potential evidence,
and the findings.
(f) The report is presented to the client.
7. In some situations, the forensic investigator may even be called to testify in court as an expert witness.
The skills and expertise of the forensic investigator play a vital role in cyber forensic investigation. The tasks
performed by him/her are as follows:
(a) Determine the extent of crime and the damage caused due to it.
(b) Recover the data to be investigated from ECDs.
(c) Collect the evidence from ECDs in a forensically sound manner.
(d) Ensure the integrity of the evidence.
(e) Analyse the evidence.
(f) Consider all possible conclusions of investigations so as to be free from bias.
(g) Prepare a forensic report.
‘(h) Testify in court if required.
5.2.6 Forensic Examination Process
Computer forensics encompasses the following steps: acquisition, preservation, identification, extraction,
evaluation, interpretation, and presentation. These steps are carried out for the reconstruction of the technical
aspects of data and to analyse computer usage to prove a crime, examine residual data, and to authenticate data
by technical analysis.
Identification ‘This attempts to determine the evidence present, where it is stored, and how it is stored. The
context of the evidence present may be either physical in the disk drive as hardware and software components
or logical as location (address) of the evidence in the drive. The procedure used to locate the evidence should
be documented.
Acquisition Acquisition of evidence may be necessary for an incident that has already occurred or for one
that is in progress. On the basis of this, and also on the type of information on an ECD and its format, the
tools and the strategy used for acquisition will vary. However, the chain of custody of the evidence is accounted
for, from this stage.
Extraction After the identification of evidence, a forensic investigator must extract data from it. Volatile data
can be lost at any point of time and so a copy of it is made from the original evidence and compared with the
extracted one.
Preservation ‘The integrity of the original evidence has to be preserved by the forensic investigator. This is
ensured with the creation of a forensic copy of the original evidence for analysis.
Evaluation ‘This stage attempts to ascertain and analyse if the evidence identified is relevant to the case by
the forensic investigator. Any irrelevant information may be filtered out at this stage so as to avoid confusion
to the jury.
Interpretation ‘The forensic examiner should interpret what is found during analysis in an easily understand-
able manner.
Presentation ‘The FE presents the suitability of the evidence with respect to the case before the court. Doc-
umentation related to evidence should be prepared—chain of custody and evidence analysis. He/She has to
DIGITAL EVIDENCE
——_____——_—_—____—— Learning Objectives —
This chapter provides an overview of digital evidence, the collection procedure, and
the obstacles to the collection process. The objective of this chapter is to provide an
introduction to digital evidence, a deeper insight into the sources of evidences, namely
various operating systems and their artifacts, the Windows registry, and various file
systems. The chapter briefly explains the disk structure. Besides this, the chapter also
talks about the sources of digital evidence in mobile devices and the Internet. Finally it
elaborates on the challenges associated with digital evidence. The reader will be familiar
with the following after studying the chapter:
Evidence collection procedure
The sources of evidence in computer systems
The sources of evidence in mobile devices and on the Internet
The challenges and obstacles in the digital evidence collection process
SE A ORR a N
6.1 INTRODUCTION TO DIGITAL EVIDENCE AND EVIDENCE
COLLECTION PROCEDURE
Digital evidence is defined as information and data that is stored, received, or transmitted by an electronic device
and is of value to an investigation. It can be found on a computer hard drive, a thumb drive, a mobile phone, a
personal digital assistant (PDA), a CD, floppy disk, DVD, flash card in a digital camera, memory stick, memory/
SIM cards, fax machines, answering machines, cordless phones, pagers, caller-ID, scanners, printers, copiers, and
CCTYV equipment, among other places. Thus evidence can be found on the Internet, on standalone computers,
or electronic communication devices (ECDs) and mobile devices. It is acquired when electronic devices are
seized and secured for examination. Digital evidence is in binary form. Even though digital evidence stored
in ECDs is in the binary form (machine language) and not understandable by humans, it should be presented
in human readable form so as to be relied upon in court. It is very different from physical evidence. Figure 6.1
compares and contrasts digital and physical evidence.
6.1.1 Types of Digital Evidence
Digital evidence may exist in two forms:
Volatileevidence It refers to the frequently changing information (e.g., information about running processes
or network, contents on the clipboard and some data in memory which are usually lost when the power for
the ECD is turned off).
Non-volatile evidence _ It refers to the contents that can be recovered from an ECD even if it is not powered on.
Some examples of both the forms are presented in Fig. 6.2.
Digital Evidence 185
Digital Physical
evidence evidence
It can be duplicated and the duplicated copy
C can be used in the place of the original. It cannot be duplicated like digital evidence.
Any tampering or modification of its contents
can be identified in comparison with the C Any tampering or modification cannot be
C original using appropriate software. identified.
It cannot be deleted easily and can be | C
recovered even if oteeah 4 It cannot be recovered if it is deleted.
9 Itcan be reproduced if the duplicated copy C It cannot be reproduced if it is destroyed
C is destroyed intentionally. intentionally.
It is less tangible in nature. | C It is more tangible in nature. |
Fig.6.1 Comparison between digital evidence and physical evidence
» Volatile
\ evidenc
~. Temporary files
ee Swap space
Data on hard disk
Cache memory
Log files
Fig.6.2 Types of digital evidence
6.1.2 Evidence Collection Procedure «
Evidence collection involves five phases which are explained here. This is shown in Fig. 6.3.
Identification of Evidence
Evidence has to be found by determining exactly ee Identification of evidence
where it is stored in the ECD. This necessitates
distinguishing between the actual evidence and =e Preservation of evidence
junk data. Identification implies what the infor-
mation available in the data is, where it is located, Evidence collection ide Analysis of evidence
and how it is stored. Consequent to this, it has to —
be ascertained if the evidence is relevant to the = Presentation of evidence
offence committed or the case. The order of vol- 5 Archival of evidence
atility of evidence is important to determine the
order of gathering the evidence and to minimize Fig.6.3 Evidence collection procedure
any loss of data relevant to the case or corruption
of the same. Evidence should be collected using the right tools and by a person who has expertise in it and is
legally entitled to.
168 CyberForensics
. Return path (can be easily spoofed)
. Recipient’s email address
. Type of sending email service
_ IP address of the server from where the mail has been sent
. Name of the email server
. Unique message number
. Date and time at which the mail has been sent
WN
Lh
MN . Information related to attached files
CONAKD
The email headers can be viewed differently with different clients and some of these are listed here:
1. Hotmail
(a) Login and select ‘Options’.
(b) Select ‘Preferences’ and scroll down the list to ‘Message headers’.
(c) Select ‘Advanced’.
(d) Scroll up or down and select ‘OK’.
2. Yahoo
(a) Login and select ‘Options’.
(b) Select “Mail preferences’.
_ (c) Scroll down and select ‘All’ at the ‘Message headers’ option.
(d) Scroll up or down and select ‘Save’.
3. Outlook 2000
(a) Open the email and click ‘View’ in the menu bar and select ‘Options’ in the drop-down list.
(b) The header is displayed at the bottom of the window that opens up.
4. Outlook Express 5.5
(a) Open or select the email.
(b) Select ‘File’ and choose ‘Properties’.
(c) Select the ‘Details’ tab to view the header.
5. Netscape Communicator 4.77
(a) Open the email.
(b) Select ‘View’ in the menu bar, choose ‘Headers’ in the drop-down list, and select ‘All’.
5.10.8 Examining Additional Email Files
Email messages usually get saved on the client side at the server. For example, Microsoft Outlook saves them in
.pst and .ost files where the former includes sent, received, deleted, and draft messages and the latter contains
offline files. Besides this, the personal address book also provides valuable information for investigation.
In case of UNIX, email groups can be created by an administrator where all the members can read the same
messages. In such a situation, the investigator can be added as a member in the suspect’s group so as to have
the same access as the suspect. This will help in the investigation of crime.
With web-based client applications such as AOL and Hotmail, history, cookies, cache, and temp files provide
evidence as well. A string search may be employed to gather evidence from such files. Besides this, specialized
software, for example, a cookie reader can be employed to gather evidence from the cookies file.
5.10.9 Tracing Email Messages
‘The following are the steps in tracing an email:
1. Given a suspicious email, it has to be read to determine whether any crime/violation has been committed.
It has to be checked for any opened attachments. The header is examined and the IP address of the sender
is recorded.
2. The server through which the email is sent is obtained from the email header and has to be contacted.
The domain names point of contact can be used to gather information about the server, for example, the
—SC—CSC‘“CS;SC—C;*~C—C—CSCSCCCSC____ntroductionn
to. Cyber Forensics 174
(a) FINALeMAIL is a tool that scans email database files and can recover deleted emails.
(b) FTK is an all-purpose tool that filters and finds files specific to email clients and servers.
5.10.12 Tracking Emails
Tracking email can be done by services such as Readnotify, DidTheyReadIt, and getnotify.
For example, tracking can be done with Readnotify as follows:
1. The investigator has to register an email ID for tracking with Readnotify at [Link].
2. An email to be sent to the recipient is created and .[Link] is added at the end of the recipient's
email address (this cannot be seen by the recipient).
3. When the recipient opens the sent mail, a tracking report is sent to the registered mail ID of the investi-
gator. The report is also available at the server which can be accessed when the investigator signs in to his/
her readnotify account.
Case studies on email forensics are presented in Box 5.6.
Box 5.6 Case Studies on Email Forensics
Case 1: Email investigation for extortion
Pranab Mitra, a former executive of Gujarat Ambuja Cement, posed as a woman, Rit Basu, and
created a fake email ID through which he contacted one V.R. Ninawe, an Abu Dhabi-based
businessman. According to the FIR, Mitra trapped Ninawe online and sent emotional messages,
thereby indulging in online sex. Later, Mitra sent an email stating that ‘she’ would commit suicide
if Ninawe ended the relationship. He also gave him another friend Ruchira Sengupta’s email ID
which was in fact his second bogus address. When Ninawe sent a mail to the other ID, he was
shocked to learn that Mitra had died. Then Mitra began emotionally blackmailing him by calling
Abu Dhabi to say that the police here were searching for Ninawe. Ninawe panicked on hearing
the news and asked Mitra to arrange for a good advocate for his defence. Ninawe even deposited
a few lakhs in the bank as advocate fees. Mitra even sent emails as high court and police officials
to extort more money, thereby managing to extort Rs96 lakh from him. Ninawe finally came down
to Mumbai to lodge a police case. Email investigation was used to prove the case and Mitra was
booked for cheating, impersonation, blackmail, and extortion under Sections 420, 465, 467, 471,
and 474 of the IPC, read with the newly formed Information Technology Act.
Case 2: Email investigation to prove defamation
X, the sales manager of Company A, gave a four-week notice, and left soon after. Soon after,
Company A received notification from a number of clients stating that they had received emails
from an unknown Hotmail account containing defamatory information about Company A.
Investigation of email received by the clients necessitated a search for evidence on X’s PC, as the
emails originated from this location.
Examination of the PC also provided evidence of confidential data having been copied to remov-
able external media during the preceding four weeks. Acquisition of data from X’s hard disk and.
an analysis of data that was deleted, as well as the system files that were recovered, showed that
email data was created at the date and time that X was known to be operating the PC.
Detailed analysis also showed that confidential data of Company A was copied to a USB drive.
The files and detailed report enabled company A to take legal action against X.
Cyber Forensics—The Present and the Future 243
Magnet RAM Capture
Memory analysis [Jamie McQuaid, (2015)] can reveal information about a system and its
users, malware,
incidents of intrusion, and the evidence stored only in memory in [Link] or [Link] but never written
to the hard drive. Running processes and programs, active network connections, registry hives, passwords, keys,
and decrypted files are just a few examples of the evidence that can be found in the memory. Many web apps,
for example, Gmail, store data in the memory meaning that the evidence associated with it cannot be recovered
from the hard disk.
Magnet RAM Capture supports both 32- and 64-bit Windows systems including XP, Vista, 7, 8, 10, 2003,
2008, and 2012. The standalone executable of Magnet RAM Capture can be run from either a USB stick or
from the local machine.
Magnet RAM Capture creates a raw data dump with a .DMP extension. The data dump can be analysed
with any memory analysis tool.
7.7 FORENSIC TOOLS FOR ANALYSIS OF REGISTRY
The following are some of the free and open-source tools available for registry analysis:
Regshot
Regshot is an open-source registry compare utility that helps to quickly take a snapshot of the registry and
compare it with a second one. This is usually done after doing system changes or installing a new software
product. The changes report can be produced in text or HTML format and contains a list of all modifications
that have taken place between the two snapshots. In addition, the folders (with subfolders) that have to be
scanned for changes can be specified.
RegRipper
RegRipper written in Perl is a Windows registry data extraction tool, and is an open-source forensic software
application developed by Harlan Carvey. It is the fastest, the easiest, and the best tool for registry analysis in
forensics examinations. It is not a registry viewer but is used to perform Windows registry hive file analysis. This
tool is specifically intended for Windows 2000, XP, and 2003 hive files.
RegRipper can be customized to the examiner’s needs through the use of available plugins or by users writing
plugins to suit specific needs.
RegRipper bypasses Win32API and uses James McFarlane’s Parse::Win32Registry module to access a
Windows registry hive file in an object-oriented manner. This module is used to locate and access registry key
nodes within the hive file as well as value nodes and their data. When accessing a key node, the LastWrite time
is retrieved, parsed, and translated so that it is readable by an examiner. Data is retrieved in the same manner and
if necessary, the plugin that retrieves the data will also perform translation of that data into something readable.
7.8 FORENSIC TOOLS FOR ENCRYPTION/DECRYPTION
The following are the free and open-source tools available for encrypting the contents in a media or to decrypt
the files:
VeraCrypt
VeraCrypt from IDRIX is an open-source utility used for on-the-fly encryption. It is a free disk encryption
software that is based on TrueCrypt 7. 1a. It can create a virtual encrypted disk within a file or encrypt a partition
or the entire storage device with pre-boot authentication.
VeraCrypt adds enhanced security and makes partitions encryption immune to brute-force attacks. ‘This
enhanced security adds some delay only to the opening of encrypted partitions but without any performance
Acquisition and Handling of Digital Evidence 275
In case the scene of offence is a house, the IO may gather information such as the type
of Internet connection
(wired/wireless), the number of systems, and whether they are connected to
the Internet, details about the
storage media (both permanent and removable), and other peripheral devices.
If the scene of offence is a cyber cafe/organization, the 1O may gather information from CCTV
clippings
or any other management software, in addition to those mentioned earlier. A preservation notice
is usually
served by the IO to prevent digital evidence from being tampered with. The preservation notice may ask
for
stopping further access to the ECD for preserving the log information, stopping access to email to prevent
deletion of emails, etc.
According to the standard operating procedure (SOP), during the investigation of the crime scene, the
following should be done:
* The ECD should be quarantined so that no one can tamper with the data and the data is free from
corruption and damage.
¢ The status of the ECD has to be ascertained and if it is ‘live’, its status should be recorded using photographs.
Turning on a system that is turned off may result in changes being made by the operating system in the
background which will change the evidence.
* The device should be disconnected from the Internet or network at the earliest. However, care should be
taken to ensure that this does not result in any loss of information. This should especially be taken care
of in mobile phones, as it may bring about changes to its internal data, which would otherwise have been
useful to the investigation.
* Other than portable devices, all electronic devices should be powered off and safely shut down.
* All electronic gadgets should be seized along with their power chords.
8.2.3 Search and Seizure
Searches can only be carried out by the IO, who is a competent authority. The Information Technology (IT) Act
2000 allows any police officer who is not below the rank of deputy superintendent of police to investigate any
offence under this Act. Section 80 of the IT Act 2000 (amended 2008) states that any police officer, not below
the rank of a police inspector, or any other officer of the central or state government authorized by the central
government may enter any public place and search and arrest without warrant any person who is reasonably
suspected to having committed, of committing, or of being about to commit any offence or crime under this Act.
The competent authority shall call upon two witnesses to attend and witness the search and may issue
an order in writing for the same. The witnesses should preferably be computer literates in the case that the
evidence to be acquired is digital in nature. The person-in-charge of the premises where the offence occurred
shall be permitted to witness the search.
Any seizure should be justified, appropriate, and proportionate[Marshall, 2008] which means that the ECD
should have evidence related to the crime and that the value of information in it outweighs the seizure. The
seizure process starts with the preservation of digital evidence. It involves seizing the ECD or taking custody of it.
Thus, after the filing of a complaint to the cybercrime cell, investigation begins with search and seizure by a
team headed by the IO in the presence of two witnesses. The IO may seek the support and technical expertise
of the forensic examiner depending on the complexity prevailing during the seizure of evidence.
The IO should perform the sequence of steps shown in Fig. 8.3 during crime scene investigation. These are
listed here:
1. Identification and securing of the crime scene—the IO locates the crime scene once a complaint is received
and takes control of it.
2. Documentation of the crime scene—the IO prepares a report that exactly reflects the crime scene.
3. Collection of evidence—the IO gathers evidences that exist physically such as user manuals, passwords,
or other login credentials available as hard copy and electronic communication devices that hold digital
evidences.
Cyber Forensics—The Present and the Future 241
HashMyFiles
HashMyfFiles is a small utility and freeware from NirSoft which allows the calculation of MDS and SHA1
hashes of one or more files in the system. The MD5/SHA1 hashes list can be copied and saved in text/html/
xml file. It can be launched from the context menu of Windows Explorer, and the MDS and SHA1 of the
selected folder can be viewed.
HashCalc
HashCalc is a calculator program and a free open-source utility developed by SlavaSoft, Inc. It is used for
computing HMACs, messages digests, and checksums for files, text, and hex strings. It allows the calculation
of hash (message digest), checksum, and HMAC values based on the most popular algorithms: MD2, MD4,
MDS, SHA1, SHA2 (SHA256, SHA384, SHA512), RIPEMD160, PANAMA, TIGER, CRC32, ADLER32,
and the hash used in eDonkey (eDonkey2000,ed2k) and eMule tools. It supports three input data formats:
file, text string, and hexadecimal string. It is a very fast, easy-to-use application, and can work with large sized
files and supports file drag-and-drop functionality. HashCalc generates hash, check sum, and HMAC for files
of any type which makes it a valuable utility to test for corruption. This tool can compare music, audio, sound,
video, film, game, image, icon, document, and other files, verify CD and hard drive files, perform checking of
files of .mp3, .mpeg, .mpg, .avi, .ved, .iso, .zip, .gif, jpg, and .doc extensions and other downloads.
‘The following are some of the proprietary tools:
CRCMD5
CRCMDS calculates the CRC-32 checksum for a DOS file or group of files and a 128-bit MD5 digest. Its
syntax is given here:
crcmd5 <options> file 1, file 2..
where options may be /s which means that the files in the current directory and all the files in the subdirectory
that match the stated file specification are included in the calculation. /h means that the output is header less
text that consists of filename lines only.
DiskSig
DiskSig is used to compute CRC checksum and MDS digest for an entire hard drive. The checksum and the
digest include all the data on the hard drive, including erased and unused areas. By default, the boot sector of
the hard drive is not included in this computation.
MD5summer
The MDSsummer is a GUI application for generating and verifying MD5 checksums of files. MDSsummer
generates MDS checksums for multiple files and stores the results in a text file. It can also take a test file and
check the files in it. Entire directory structures can be summed recursively. Input and output files are compatible
with those of the GNU MD5sum application.
7.5 FORENSIC TOOLS FOR DATA RECOVERY
The following are some of the tools available for data recovery:
Recuva
Recuva is a user friendly recovery tool. It can recover accidentally deleted files (pictures, music, documents,
videos, and emails), images, and data in rewriteable media (memory card, external hard drives, and USB sticks).
Recuva has an advanced deep scan mode that searches the disk thoroughly to find any traces of files that have
been deleted. Those files that require permanent deletion are handled by Recuva with a secured overwriting
feature that uses industry- and military-standard deletion techniques to ensure that the files are erased.
244
OO
Cyber Forensics TN
eee
impact to the application use phase. This is acceptable to the legitimate owner but makes it much harder for
an attacker to gain access to the encrypted data.
Encrypted Disk Detector
Encrypted Disk Detector (EDD) is a free command-line tool used to quickly and non-intrusively check for —
encrypted volumes on a computer system during incident response. This could help the forensic investigator
to decide whether a live acquisition needs to be made in order to secure and preserve the evidence that would
otherwise be lost if the plug was pulled.
EDD checks the local physical drives on a system for TrueCrypt, PGP, or Bitlocker encrypted volumes. If
no disk encryption signatures are found in the MBR, EDD also displays the original equipment manufacturer
ID (OEM ID) and, where applicable, the volume label, for partitions on that drive, and checking for Bitlocker
volumes.
7.9 FORENSIC TOOLS FOR PASSWORD RECOVERY
The following are some of the tools that facilitate the recovery of passwords:
Passware Kit Forensic
Passware Kit Forensic is the complete electronic evidence discovery solution that reports all password-protected
items on a computer and decrypts them. It reduces the time spent on recovering passwords, improves recovery
rates, and gets more control over the password recovery process. Some of its features are as follows:
1. Recovers passwords for more than 200 file types and decrypts hard disks providing an all-in-one user
interface
. Scans computers and the network for password-protected files
. Acquires memory images of the seized computers
. Retrieves electronic evidence in a matter of minutes from a Windows desktop search database
. Supports distributed password recovery
NH
BW
Nm. Runs from a USB thumb drive and recovers passwords without installation on a target PC
ElcomSoft
ElcomSoft offers GPU-accelerated password recovery and decryption tools and supplies a range of mobile ex-
traction and analysis tools for iOS, Android, etc. It offers a range of products, which are listed here:
ElcomSoft Password Recovery Bundle (Forensic Edition) comes with all the password recovery tools in a single
value pack. It helps to unlock documents, decrypt archives, and break into encrypted containers.
ElcomSoft Distributed Password Recovery breaks complex passwords, recovers encryption keys, and unlocks
documents in a production environment.
Elcomsoft Mobile Forensic Bundle can perform physical, logical, and over-the-air acquisition of smartphones and
tablets, break mobile backup passwords and decrypt encrypted backups, and view and analyse the information
stored in mobile devices.
Elcomsoft Cloud eXplorer extracts everything from the Google Account, downloads users’ location history,
contacts, Hangouts messages, Google Keep, Chrome browsing history, search history and page transitions,
Calendars, images, etc.
Ophcrack
Ophcrack is a free Windows password cracker based on a time-memory trade-off using rainbow tables. This is
a new variant of Hellman’s original trade-off with better performance. It recovers 99.9% of the alphanumeric
passwords in seconds. It comes with a GUI and can run on multiple platforms.