NetForce Tools for Network Forensics
NetForce Tools for Network Forensics
NetForce
NetForce
• NetForce is a collection of three tools named NeSA, CyberInvestigator and Email Tracer used for Network Forensics.
– NeSA is used for packet analysis,
– CyberInvestigator is used for log analysis
– Email Tracer is used for email tracing
(A)NeSA (Network Packet Analysis Tool)
• Networks Forensics Tool to capture and analyze network traffic. Data sent through the network can be captured, recreated and
exported using this tool.
Data Reconstruction:
• With the help of flexible and powerful filtering system, data from HTTP, SMTP, POP3 and FTP session can be recreated and
visualized in an analysis friendly manner. The tool has built-in data viewers including a Mailview, to help the analyst to
concentrate on analysis.
Analysis Modes:
• NeSA supports both data level and packet level analysis of network data.
– In data-level analysis mode, the analyst can focus on the actual data being transmitted over the network, such
as email messages, web page content, or file transfers, without needing to understand the underlying network
protocols in detail. This can be helpful in situations where the focus is on content analysis, such as identifying
sensitive or confidential information being transmitted over the network.
– In packet-level analysis mode, the analyst can dive deeper into the network traffic and examine the individual
packets that make up the data. This can be useful for identifying specific network protocols being used,
analyzing traffic patterns, or identifying security threats, such as malware or malicious activity.
Searching and Filtering:
• In NeSA, flexible filter expressions are available for both packet-level and data-level analysis, which can be useful in identifying specific traffic
patterns or behavior.
• The packet-level filters allow the analyst to filter traffic based on various criteria, such as source or destination IP address, protocol type, port
number, or packet size. This can help to isolate specific traffic flows or sessions for closer analysis.
• For data-level analysis, NeSA provides filtering capabilities based on various criteria such as date, time, IP, MAC, and port, which can be useful
for isolating specific network traffic based on these attributes.
• Regular expression-based searching is also supported, which provides the analyst with the full power of regular expressions to search for specific
data patterns within the captured traffic.
• Other Features:
• Loads pcap formatted dump files and rebuilds TCP sessions.
• Reconstructs files from HTTP, FTP, SMTP and POP3 packets.
• Built in Hex, Thumbnail, File and Mail view.
• Powerful filter for filtering TCP sessions and packets.
• Regular expression based search capability.
• Supports port customization and time zone based analysis.
• Loads multiple pcap files.
• Statistics generation.
• IP Tracing.
• Merging and sorting of packets.
• DNS Attack analysis.
• Report generation.
(B)CyberInvestigator (Log Analysis Tool)
o CyberInvestigator is a Network Forensics Tool for log analysis. It involves gathering different kinds of logs
available in machines which were compromised in an attack.
o The analysis involves tracing down the intrusions, usage of network and creating a detailed forensic report.
o Network Forensic analysts should analyze various type of logs such as Linux, Unix and Windows OS Logs,
Web Server Logs, Database Logs, Firewall Logs, IDS Logs, VPN Logs, Router Logs, Proxy Logs, Windows
Domain Logs, Wireless Access Point Logs etc.
o Manual analysis of these logs is very cumbersome and analysts need special tools to efficiently analyze and find
out different types of attacks and other types of criminal activities.
• Features:
• Supports Windows Logs, Linux Logs
• Supports Analysis of wtmp, utmp, secure, mail, message, cron, access and IIS logs
• Investigator friendly User Interface
• Finds out Successful Login & Login Failures
• Finds out the Insertion & Removal of Removable Media Displays Software Installation & Uninstallation details
• Provides Intrusion Analysis
• Provides Web Traffic Analysis
• Customized Reports
•
(C)Email Tracer:
• EmailTracer is a forensic tool to track email sender's identity. It can be used to trace the sender's details of any
email by analyzing its header. The tool is able to analyze email headers collected from web based and local mail
programs. EmailTracer gives details of the sending machine including IP address, which is the key point to find the
culprit. It also gives geographical location of the sender, route traced by the email etc. It can also be used for
retrieving emails and its details from mailbox files of local mail programs like Outlook Express(.dbx), .Microsoft
Outlook(.pst), Eudora(.mbx), Pegasus(.cnm), The Bat(.tbb), Netscape Messenger(.nsm), Incredimail(.imm),
KMail(MailDir), Mozilla(.mbox) and Windows7 Mail(.eml).
• Features:
• Trace IP Address of the machine from which mail is sent
• Analyze email header collected from web based mail program like Yahoo!, Hotmail, Rediff etc.
• Generates detailed analysis report in HTML format
• Detects the city and country IP address location of the sender. Plots route traced by the mail from the sender to the
receiver. Displays the geographic location of the mail in the world map. Whois Search, NS LookUp and IP
TraceBack Facility
• Extract emails from mailbox files of different local mail clients
• Keyword Searching facility on recovered emails
• Facility to extract and save attachments in native format
• Facility to extract embedded mails
• Facility to extract and analyze email header
• CAINE Linux standsCAINE
for Computer AidedINVESTIGATIVE
(COMPUTER AIDED INvestigative Environment) is an
ENVIRONMENT)
• Purpose:
• CAINE is a professional open source forensic platform that integrates software
tools as modules along with powerful scripts in a graphical interface
environment.
• Its operational environment was designed with the intent to provide the forensic
professional all the tools
process (preservation, required
collection, to perform
examination andthe digital forensic investigate
analysis).
• CAINE is a live Linux distribution so it can be booted from removable media
(flash drive) or from an optical disk and run in memory.
• It can also be installed onto a physical or virtual system. In Live mode, CAINE
can operate
operating on data storage objects without having to boot up a supporting
system.
• The latest version 9.0 can boot on UEFI/UEFI+Secure and Legacy BIOS allowing
CAINE
WindowstoNT)be used on information
and newer platformssystems
(Linux,that boot older
Windows 10). operating systems (e.g.
• CAINE offers you:
an interoperable environment that supports the digital investigator during the four phases of the
digital investigation
user-friendly tools (wide range of tools for digital forensics operations)
a user-friendly graphical interface.
Requirements:
• CAINE is based on Ubuntu 16.04 64-bit, using Linux kernel 4.4.0-97. CAINE system requirements to
run as a live disc are similar to Ubuntu 16.04 (2 GHz dual core processor or better; 2 GB system
memory). It can.
• Supported platforms :
• The CAINE Linux distribution has numerous software applications, scripts and libraries that can be
used in a graphical or command line environment to perform forensic tasks.
• CAINE can perform data analysis of data objects created on Microsoft Windows, Linux and some Unix
systems. One of the key forensic features in version 9.0 is that it sets all block devices by default to
read-only mode.
• Write-blocking is a critical methodology to ensure that disks are not subject to writing operations by
the operating system or forensic tools.
• This ensures that attached data objects are not modified, which would negatively impact digital
forensic preservation.
• It run on a physical system or in a virtual machine environment such as VMware Workstation.
• Tools :
• CAINE provides software tools that support database, memory, forensic and network analysis.
File system image analysis of NTFS, FAT/ExFAT, Ext2, Ext3, HFS and ISO 9660 is possible via command
line and through the graphic desktop.[8]Examination of Linux, Microsoft Windows and some Unix
platforms is built-in. CAINE can import disk images in raw (dd) and expert witness/advanced file
format. These may be obtained from using tools that are included in CAINE or from another platform
such as EnCase or the Forensic Tool Kit.
• Some of the tools included with the CAINE Linux distribution include:
The Sleuth Kit – open source command line tools that support forensic inspection of disk volume and
file system analysis.
Autopsy – open source digital forensics platform that supports forensic analysis of files, hash filtering,
keyword search, email and web artifacts. Autopsy is the graphical interface to The Sleuth Kit.
RegRipper – open source tool, written in Perl, extracts/parses information (keys, values, data) from the
Registry database for data analysis.
Tinfoleak – open source tool for collecting detailed Twitter intelligence analysis.
Wireshark – supports interactive collection of network traffic and non real-time analysis of data packet
captures (*.pcap).
PhotoRec – supports recovery of lost files from hard disk, digital camera and optical media.
Fsstat – displays file system statistical information about an image or storage object.
• CAINE: GNU/Linux Live Distribution for Digital Forensics, Windows Forensics & Incident
Response
• CAINE Linux is an open-source digital forensics platform that provides all the tools required to perform
the digital forensic investigate process. It also comes bundled with some impressive and wide range
digital forensics tools, that are precious for digital forensics professionals. It can be used by law
enforcement, military and corporate examiners to investigate what happened on a computer.
•Installation :
•Download the CAINE ISO Image.
After installation, you need to edit the /usr/sbin/rbfstab :
[Link] swapoff -a in swapon -a
[Link] the row swap
Oxygen Forensic
• Oxygen Forensic software offers advanced physical extraction for LG, Motorola, Samsung, MTK,
Spreadtrum and Qualcomm devices.
• This method enables lock screen bypass and requires no root rights. ... The Accounts and Passwords section
displays logins, passwords and tokens extracted mobile devices.
• Oxygen Forensic Detective: Advanced software to extract data from multiple
• Sources:
• Oxygen Forensic Detective is a forensic software solution designed to acquire data from mobile devices,
their backups and images, memory cards, SIM cards, IoT devices, drones, smart watches and cloud storages.
• The program has played a significant role in criminal and other investigations all over the world and is used
by Law Enforcement units, Police Departments, army, customs and tax services and other government
authorities .
• Oxygen Forensic Detective allows to import and parse data from various device backups and images (Apple
iOS, Android OS, Windows Phone OS, BlackBerry OS, and Nokia) as well as iOS and Android images
made by other forensic tools.
• Oxygen Forensic Detective supports USB cable and Bluetooth (Microsoft, Widcomm) connections.
• The software works under 32-bit or 64-bit versions of Windows 10,Windows 8, and Windows 7.
Purpose
• • extract all mobile device information including contacts, calls, messages, file system,
passwords and tokens, geo locations, deleted data and data from all popular
• applications
• • retrieve data from SIM and memory cards
• • extract data from smartwatches based on MTK chipset
• • acquire data from 60+ various cloud sources that include iCloud, Google, Microsoft,Huawei,
Samsung, Mi Cloud, E-Mail (IMAP) Server, FitBit, etc.
• • extract data from IoT devices - Amazon Alexa and Google Home
• • retrieve flight history with metadata, images and videos from drones, drone mobile apps,
drone logs and drone cloud (DJI Cloud, SkyPixel)
• • analyze extracted data in the built-in analytical sections, like Timeline, Social Graph, Key
Evidence, Aggregated Contacts
• • search data using various methods that include regular expressions, keyword lists,Project
VIC and other hash sets, etc.
• • export evidence to various file formats, like PDF, XLS, RTF, etc.
• O.S which supports Oxygen Forensic Detective:
• The current version supports 24,900+ mobile devices running different OS: Android,
• Bada, Blackberry, iOS, MTK, Spreadtrum and Qualcomm chipsets, Symbian, Windows Mobile 5/6,
Windows Phone 8, feature phones, etc.
• Installation :
• 1. Oxygen Forensic Detective USB dongle license must be used with a USB dongle
• that is bundled with your Oxygen Forensic Detective package.
• 2. For this license, no Internet connection is required. After Oxygen Forensic® Detective installation
please insert a USB dongle into the USB port, wait till the driver initialization, and start the main program.
• 4. Please note that USB dongle should be inserted the whole time during your work with Oxygen Forensic
Detective. You are given the following options during the software installation which allow you to select
the destination folder for Oxygen Forensic Detective, create desktop and quick launch icons, the desired
program
• language.
• 5. Lastly, read carefully and accept the license agreement, if you agree. After all
• options have been selected, click the Install button to start the installation:
1. When the installation is complete, you can choose to download driver pack required for device
connection or immediately launch Oxygen Forensic Detective.
2. Connecting a mobile device :
• To work with a phone, make sure it is supported by the current version of the software and all
corresponding drivers were installed.
• To start the extraction, connect the device to a PC with the installed program.
• If you use a cable connection, attach the cable to the device.
• For Bluetooth connection, activate it on the device and make sure it is visible and accessible.
• Clicking the Connect new device button in the Oxygen Forensic Detective interface will launch Oxygen
Forensic Extractor.
• Select “Device Acquisition” to automatically detect a single device connected via a cable or “Manual device
selection” to connect several devices one by one.
• Bluetooth connection is also available.
• The list of available connection types depends on the mobile device capabilities and hardware installed on
your computer.
• To bypass the screen lock and perform physical data extraction on supported Android OS
devices, choose “Physical data acquisition”.
• These methods will allow to bypass passcodes on the supported devices: LG, Motorola,
Samsung as well as devices with MTK, Spreadtrum, Qualcomm chipsets.
• To use this option, click the required device hyperlink. Then you’ll be redirected to the
appropriate screen with the instructions on how to prepare the selected Android device.
• Once the extraction option is chosen, Oxygen Forensic® Extractor will begin searching for the device:
The Sleuth Kit (TSK)
• Basic Concepts:
• • The Sleuth Kit (TSK) is a library and collection of command line tools that allow
you to investigate disk images.
• • The core functionality of TSK allows you to analyze volume and file system data.
• • The library can be incorporated into larger digital forensics tools and the command
line tools can be directly used to find evidence.
• • The Sleuth Kit (TSK) is a library and collection of Unix- and Windows-based
utilities to facilitate the forensic analysis of computer systems.
• • It was written and is maintained primarily by digital investigator Brian Carrier.
• • The Sleuth Kit is capable of parsing NTFS, FAT/ExFAT, Ext2, Ext3,Ext4, HFS, ISO
9660 and YAFFS2 file systems either separately or within disk images stored in raw (
dd ), Expert Witness or AFF formats.
• • The Sleuth Kit can be used to examine most Microsoft Windows, most Apple
Macintosh OSX, many Linux and some other UNIX computers.
• • The original part of Sleuth Kit is a C library and collection of command line file and
• The file system tools allow you to examine file systems of a suspect computer in a
non-intrusive fashion. Because the tools do not rely on the operating system to
process the file systems, deleted and hidden content is shown.
• • It runs on Windows and Unix platforms.
• • The volume system (media management) tools allow you to examine the layout of
disks and other media. The Sleuth Kit supports DOS partitions, BSD partitions (disk
labels), Mac partitions, Sun slices (Volume Table of Contents), and GPT disks.
• • With these tools, you can identify where partitions are located and extract them so
that they can be analyzed with file system analysis tools.
• • When performing a complete analysis of a system, we all know that command line
tools can become tedious.
• • Autopsy is a graphical interface to the tools in The Sleuth Kit, which allows you to
more easily conduct an investigation.
• • Autopsy provides case management, image integrity, keyword searching, and other
automated operations.
Uses
• The Sleuth Kit can be used:
1. Via the included command line tools; or As a library embedded within a separate digital
forensic tool such as Autopsy or log2timeline/plaso.
2. The Sleuth Kit is a free, open-source suite that provides a large number of specialized
command-line based utilities. It is based on The Coroner's Toolkit, and is the
official successor platform.
The Sleuth Kit has been tested on:
Linux
Mac OS X
Windows (Visual Studio and mingw)
CYGWIN
Open & FreeBSD
Solaris
• 1. Volume and File System Analysis in Sleuth Kit
• Input Data
• Analyzes raw (i.e. dd), Expert Witness (i.e. EnCase) and AFF file system
and
• disk images.
• Supports the NTFS, FAT, ExFAT, UFS 1, UFS 2, EXT2FS, EXT3FS, Ext4,
HFS,
• ISO 9660, and YAFFS2 file systems (even when the host operating system
does
• not or has a different endian ordering).
• Tools can be run on a live Windows or UNIX system during Incident
Response.
• These tools will show files that have been " hidden" by rootkits
and will not modify the Time of files that are viewed.
• Search Techniques:
• List allocated and deleted ASCII and Unicode file names.
• Display the details and contents of all NTFS attributes (including all Alternate
• Data Streams).
• Display file system and meta-data structure details.
• Create time lines of file activity, which can be imported into a spread sheet to
• create graphs and reports.
• Lookup file hashes in a hash database, such as the NIST NSRL, Hash Keeper,
• and custom databases that have been created with the 'md5sum' tool.
• Organize files based on their type .
• Pages of thumbnails can be made of graphic images for quick analysis.
• Tools in Sleuth Kit:
• 1. Fully Automated Tools
• These tools integrate the volume and file system functionality. Instead of analyzing only
• a single file system, these tools take a disk image as input and identify the volumes and
• tsk_comparedir: Compares a local directory hierarchy with the contents of raw device (or disk
image). This can be used to detect rootkits.
• tsk_gettimes: Extracts all of the temporal data from the image to make a timeline. Equivalent
to running fls with the '-m' option.
• tsk_loaddb: Loads the metadata from an image into a SQLite database. This allows
• other tools to be easily written in a variety of languages and give them access to the image
contents.
• tsk_recover: Extracts the unallocated (or allocated) files from a disk image to a local directory.
• File System Layer Tools
• These file system tools process general file system data, such as the layout, allocation
• structures, and boot blocks
• fsstat: Shows file system details and statistics including layout, sizes, and labels.
• File Name Layer Tools
• These file system tools process the file name structures, which are typically located in
• the parent directory.
• ffind: Finds allocated and unallocated file names that point to a given meta data
• structure.
• Meta Data Layer Tools
• These file system tools process the meta data structures, which store the details about
• a file. Examples of this structure include directory entries in FAT, MFT entries in NTFS,
• and inodes in ExtX and UFS.
• icat: Extracts the data units of a file, which is specified by its meta data address
• (instead of the file name).
• ifind: Finds the meta data structure that has a given file name pointing to it or the
• meta data structure that points to a given data unit.
• ils: Lists the meta data structures and their contents in a pipe delimited format.
• istat: Displays the statistics and details about a given meta data structure in an easy
• to read format.
• Data Unit Layer Tools:
• These file system tools process the data units where file content is stored. Examples of
• this layer include clusters in FAT and NTFS and blocks and fragments in ExtX and UFS.
• blkcat: Extracts the contents of a given data unit.
• blkls: Lists the details about data units and can extract the unallocated space of the
• file system.
• blkstat: Displays the statistics about a given data unit in an easy to read format.
• blkcalc: Calculates where data in the unallocated space image (from blkls ) exists in
• the original image. This is used when evidence is found in unallocated space.
• File System Journal Tools:
• These file system tools process the journal that some file systems have.
• The journal records the metadata (and sometimes content) updates that are made. This could help recover
recently deleted data. Examples of file systems with journals include Ext3 and NTFS.
• jcat: Display the contents of a specific journal block.
• jls: List the entries in the file system journal.
• Volume System Tools
• These tools take a disk (or other media) image as input and analyze its partition structures. Examples
include DOS partitions, BSD disk labels, and the Sun Volume Table of Contents (VTOC).
• These can be used find hidden data between partitions and to identify the file system offset for The Sleuth
Kit tools.
• The media management tools support DOS partitions, BSD disk labels, Sun VTOC, and Mac partitions.
• mmls: Displays the layout of a disk, including the unallocated spaces.
• mmstat: Display details about a volume system (typically only the type).
• mmcat: Extracts the contents of a specific volume to STDOUT.
• Image File Tools:
• This layer contains tools for the image file format. For example, if the image format is a
• split image or a compressed image.
• img_stat: tool will show the details of the image format
• img_cat: This tool will show the raw contents of an image file.
• Disk Tools:
• These tools can be used to detect and remove a Host Protected Area (HPA) in an disk.
• A HPA could be used to hide data so that it would not be copied during an acquisition.
• These tools are currently Linux-only.
• disk_sreset: This tool will temporarily remove a HPA if one exists. After the disk is
• reset, the HPA will return.
• disk_stat: This tool will show if an HPA exists.
Win-LiFT
• Win-LiFT v3.0 is a Windows Live Forensics Tool consisting of 1. Win-
• LiFTImagerBuilder and 2. WinLiFTAnalyzer.
• • Live Forensics involves acquisition of volatile data from the Suspect’s machine
• and analysis of the acquired data.
• • Win-LiFT enables volatile data acquisition using Win-LiFTImager and analysis of the same using
Win-LiFTAnalyzer.
• Win-LiFTImageBuilder - Tool for building Win-LiFTImager
• • Win-LiFTImagerBuilder, which runs in the Investigator’s machine, builds Win- LiFTImager tool.
• Features :
• • Facility to enter crime details
• • Facility to select / deselect the list of volatile artifacts to be collected from the
• Suspect’s system.
• • Facility to select USB/Hard Disk drive to which tool is to be built.
• Win-LiFTImager - Forensic Volatile Data Acquisition Tool
• Win-LiFTImager is a USB based tool for Live Forensics Data Acquisition from Suspect’s
• machine.
• Features:
• Capturing following volatile artifacts from the Suspect’s machine to the Win-
• LiFTImager USB.
• • Running Processes
• • Network Status System Information
• • Open Files
• • Network Neighbors
• • Process Port Connections
• • Shared Resources
• • Services List
• • Clipboard Content
• • System Users
• Facility to dump Physical Memory content from Windows Systems.
• Facility to capture Snapshot of Desktop Screen from the Suspect’s
machine
• Acquires Registry Files and Browser Files from Windows
Systems.
• Acquisition of Event Log files.
• MD5 hashing of all acquired files.
• Log and Report Generation.
• Win-LiFTAnalyzer -Forensic Volatile Data Analysis Tool
• Win-LiFTAnalyzer analyses the data collected by the Win-
LiFTImager and creates a
• detailed report after analysis.
• • Registry Analysis to retrieve forensically relevant information.
• • Event Log Analysis.
• • Browser Forensics Advanced Memory Analysis for Running Process Details,
• Network Information, Internet Evidence and MFT Records Collection.
• Executable Reconstruction from Physical memory and PE File Analysis
• • Keyword searching facility.
• • Detailed Report Generation
• • Handling multiple case files simultaneously.
• • Bookmarking and Appending to report facility
• • Facility to save partially/fully analyzed cases.
• • Facility to save and print report.
• • Facility to Load Windows Memory dump files
• • Load and analyze Registry separately
• Other Features:
• • Display forensic evidence acquired in List/Tree/Summary View.
• • Gallery View of the screenshot & clipboard images.
• • Text-Hex View of raw files with built in search and go to facility.
• • Tree view of the Running process
• Win Win-LiFTAnalyzer v3.0 (Forensic Volatile Data Analysis Tool)
• • Win-LiFTAnalyzer analyses the data collected by the Win-LiFTImager and
• creates a detailed report after analysis.
X-Ways Forensics: Integrated Computer
Forensics Software
• X-Ways Forensics is an advanced work environment for computer forensic examiners.
• • Runs under Windows XP/2003/Vista/2008/7/8/8.1/2012/10*, 32 Bit/64 Bit,
standard/PE/FE.
• • X-Ways Forensics is more efficient to use after a while, by far not as resource-
hungry, often runs much faster, finds deleted files and search hits ,it comes at a fraction
of the cost, does not have any ridiculous hardware requirements, does not depend on
setting up a complex database. X-Ways Forensics is fully portable
• and runs off a USB stick on any given Windows system without installation if you
want.
• • Downloads and installs within seconds (just a few MB in size, not GB).
• • X-Ways Forensics is based on the WinHex hex and disk editor and part of an
efficient workflow modelwhere computer forensic examiners share data and
collaborate with investigators that use X-Ways Investigator.
• Features:
• Disk cloning and imaging
• Ability to read partitioning and file system structures inside raw (.dd) image files,
• ISO, VHD, VHDX, VDI, and VMDK images
• Complete access to disks, RAIDs, and images more than 2 TB in size (more than
• 2 32 sectors) with sector sizes up to 8 KB
• Built-in interpretation of JBOD, RAID 0, RAID 5, RAID 5EE, and RAID 6 systems,
• Linux software RAIDs, Windows dynamic disks, and LVM2
• Automatic identification of lost/deleted partitions
• Native support for FAT12, FAT16, FAT32, exFAT, TFAT, NTFS, Ext2, Ext3,
• Ext4, Next3®, CDFS/ISO9660/Joliet, UDF
• Superimposition of sectors, e.g. with corrected partition tables or file system data
• structures to parse file systems completely despite data corruption, without
• altering the original disk or image
• Access to logical memory of running processes
• Various data recovery techniques, lightning fast and powerful file carving
• Well maintained file header signature database based on GREP notation
• Data interpreter, knowing 20 variable types
• Viewing and editing binary data structures using templates
• Hard disk cleansing to produce forensically sterile media
• 1.X-Ways Investigator
• • X-Ways Investigator is a powerful investigation/document analysis/report generation application for law
enforcement, intelligence agencies, and the private sector.
• • It runs under Windows.
• • It was designed for investigators who are specialized in areas such as accounting, building laws, money
laundering, corruption, homicide, child pornography, etc., also for investigative analysts, agents, attorneys,
paralegals,
• prosecutors, internal and external auditors, for the analysis part of computer forensics and electronic discovery.
• X-Ways Investigator is based on X-Ways Forensics and is a subset thereof.
• simplified user interface offers much fewer technical options and less technical functionality than WinHex and
X-Ways Forensics, so that investigators can better concentrate on the matter at hand.
• • It reduces the computer specialists' workload by allowing the investigators to take over much earlier.
• Feature overview:
• Case management, logging
• Automated reports that can be imported and further processed by any other application
that understands HTML, such as MS Word
• File viewer for hundreds of file formats included
• Ability to print documents with all file metadata on a cover page
• Can natively read media/images with these file systems: FAT12/16/32, TFAT, exFAT,
NTFS, Ext2/3/4, Next3?, CDFS, UDF, HFS, HFS+, ReiserFS, Reiser4, UFS, UFS2
• Can interpret raw image files and .e01 evidence files.
• 2. WinHex
• • WinHex is in its core a universal hexadecimal editor, particularly helpful in the realm
of computer forensics, data recovery, low-level data processing, and IT security.
• • An advanced tool for everyday and emergency use: inspect and edit all kinds of files,
recover deleted files or lost data from hard drives with corrupt file systems or from digital
camera cards.
• Features:
• Various data recovery techniques
• RAM editor, providing access to physical RAM and other processes; virtual
memory
• Data interpreter, knowing 20 data types
• Editing data structures using templates (e.g. to repair partition table/boot sector)
• Concatenating and splitting files, unifying and dividing odd and even bytes/words
• Analyzing and comparing files
• Disk cloning (under DOS with X-Ways Replica)
• Drive images & backups (optionally compressed or split into 650 MB archives)
• Programming interface (API) and scripting
• 256-bit AES encryption, checksums, CRC32, hashes (MD5, SHA-1, ...)
• Erase (wipe) confidential files securely, hard drive cleansing to protect your privacy
• 3. X-Ways Imager
• • X-Ways Imager can be run directly for example from a USB device
if desired, without installation.
• • It is fully portable, just like WinHex and X-Ways Forensics.
• • It is suitable for live acquisition but in reality installs itself into the
temp folder of the live system, thereby overwriting ~45 MB of drive
space, and clandestinely removes itself from there after execution.
• Images created by X-Ways Forensics and X-Ways Imager also allow
X-Ways Forensics to treat originally zeroed out disk areas as sparse.
SIMXtractor
• SIMXtractor is a forensic solution for imaging and analysing SIM cards. The tool
suite contains a SIM Card Reader, SIM Imager (Imaging of SIM cards) and SIM
Analyzer (Analysis of SIM cards). The tool works with both GSM and CDMA SIM
cards.
• SIM Card Reader:
• SIM Card Reader is a hardware based reader with USB support. The hardware utility
has
• Supports USB 2.0
• Support for 5V, 3.3V and 1.8 V SIM cards
• Supports ISO-7816 Standard cards
• PC/SC compatible Card Reader
• Works with all versions of Windows (32 bit and 64 bit)
• SIM Imager
• SIM Imager is a software utility to image the contents of the SIM card. The features of the SIM Imager
are
• Generates an image file of the SIM card contents
• Supports MD5, SHA-1 and SHA-2 hashing methods
• Generates hash values for all files individually and total hash of all files
• Generates a report after seizing process with investigation details
• Write blocking of SIM Cards done
• SIM Analyser
• SIM Analyzer is a software utility to analyze a SIM card image. The main features of SIM Analyzer are
Analyzes Call logs, Contacts, Messages, and Network related information
• Searching facility
• Multiple images can be loaded and Analysed
• Highlights Recovers deleted SMS, Incoming and Outgoing SMS
• Facility to generate custom PDF reports
Cyber Check
• It is a forensic data recovery and analysis tool to enable law
enforcement officers to quickly and efficiently analyze digital
evidence files. The tool has a very simple to use GUI which
can be used by a novice user.
• Data Analysis
• CyberCheck can analyze TrueBack Image, Encase Image and
raw disk dumps. The tool can generate a detailed report on the
analysis findings which is very handy for the investigating
officers to submit it before the court of law. The tool can
extract unallocated and disk slack areas, perform data carving
on the entire image of slack areas and provides options to do
• Powerful Search Facility
• CyberCheck provides a plethora of search options for the investigating officer to ensure that he never
misses any data.
• It has Multiple keyword search, GREP search, file search based on hash values, Unicode search to
find the data in any language and Index-based search to quickly search through the huge data space.
• Features
• Preview support for disks and partitions
• File Data carving from ambient space Picture, Gallery, Timeline and Text/Hex views
• Integrated Mailbox, Internet History and Registry viewers
• Scripting support for automated analysis
• Anti-forensics tools and activities detections
• Supports Analysis of Virtual Disk Images
• VMDK and VHD Report generation.
• Steganography file detection and extraction of hidden message
• Unicode & Indian Language support
• Hibernate File Analysis
• Bit locked drive decryption
Mobile Check
• Mobile Check is a forensics solution for Smart phones, Basic phones, PDAs and GPS
Devices. The tool supports acquisition, analysis and reporting of evidence from mobile
devices.
• The major tools in the solution are Mobile Check Imager and MobileCheck Analyser.
• MobileCheckImager:
• The tool is used to generate forensics images of various types of mobile devices.
• Supports 13000 phone models of various brands Supports logical and physical and backup
acquisition
• Acquisition using boot loader method for Android devices.
• Supports backup generation with APK downgrade in Android devices.
• Generate raw images in the physical acquisition Extracts Device details, Address book, Call
log, Social networking information, SMS/MMS, E-mails, Calendar, Tasks, Web browser
logs, Bluetooth logs, Event logs, Apps Details, File system etc.
• Supports SHA256/MD5 hashing
• Supports Pattern, PIN and Password unlocking of Samsung Android devices
• Supported Devices
• Smart Phones iPhone, Android, Blackberry, Windows Phone, Windows Mobile and Symbian
• Basic phones Nokia, Samsung, Sony Ericsson, Micromax, LG, Motorola, Lava, Huawei, Karbonn and CDMA phones etc
• PDAs WinCE, Palm OS
• GPS Device MapMyIndia,Garmin and TomTom devices
• Memory Cards
• MobileCheck Analyser:
• MobileCheck Analyser enables investigators to perform complete analysis of the
acquired phone image with its various built-in features. The tool supports recovering
evidence from physical/ logical/ backup images of mobile devices and generates a
comprehensive report.
• Major Features:
• Mobile Check File Views
• Multimedia and Web Recovery and display of deleted data logs,
• SMS/MMS, E-mail, File system etc
• Detailed view of Address book, Call Analysis summary
• Social networking Apps analysis:
• Facebook, Skype, Instagram, Snapchat, Kik, Viber, Hangouts,
Telegram , WhatsApp, Evernote, Twitter, Instagram, LinkedIn,
Dropbox, Google Plus, Yahoo Messenger, iMessage, Xender and
ShareIt .
• Visual Analytics
• Link analysis of multiple cases and images with filtering facility.
• Timeline analysis of phone events
• Search Facility
• Keyword search, File search, Internet history Search, Search in file
contents Grid search & Global search
• Keyword search in multiple case images .
CDR Analyzer
• Advik is a Call Data Record Analyzer which can import and analyze CDR/IPDR logs of
any service provider in India and generates a comprehensive report of frequency statistics
including service provider details and subscriber details (SDR) of CDR Numbers ..
• Features:
• Import CDR/Tower CDR/IMEI CDR/Roaming CDR and IPDR
• Seize and Acquire CDR Logs
• IPDR Analyzis
• Geo Analyzis
• Link Analyzis
• TimeLine Analyzis
• Frequency Analyzis
• New Number Analyzis
• Group Analyzis
• Preliminary CDR Analyzis
• Suspect List
• Filter History
• Create and Manage Filters
• Import and Manage Cell-ID
• Import, Search and Manage SDR
• Fully Customizable Call Flow Visualizer
• Alias for Numbers
• Manage Users and Privileges
• Customizable / single click report
True Imager
• TrueImager is a high speed, light weight, portable disk
imaging hardware solution. The version 4.0 is the latest and
the fastest version with battery backup support. The unit is
capable of performing Hashing, Imaging and Cloning
operations of source storage media and performs Wiping and
Formatting of destination disk.
• TrueImager is a disk forensics tool capable of hashing and
imaging of digital storage media and have all advanced
features of disk imaging tools.
• Features and Technical Specifications:
• User friendly UI with 7" capacitive touch & colour LCD
• Supports disks with IDE, SATA, USB, mini-SATA, SATA interface and memory cards as
source media
• Provides built-in write protection for suspect disks
• Supports SATA and USB media as destination disk
• Supports two modes of Data Capturing: Raw and C-DAC's TrueBack format
• Supports MD5, SHA1 and SHA2 hashing
• Generates report for every operation
• Copies multiple source images to single destination
• Provides write verification for Imaging operation
• Capable of performing upto 4 tasks concurrently.
• Provides disk S.M.A.R.T verification, Disk browsing, Report file exporting
• Have auto shut down facility
• External Power Adapter: 100-230V(Input), 19V-3.4A(Output)
• Net Weight: 1.8kg
• Platform required(if any)
• Standalone unit. Image files generated using the tool can be loaded using windows-based
disk analysis tools.
SANS Investigative Forensics Toolkit
• SIFT Workstation
• The SIFT Workstation is a collection of free and open-source incident
response and forensic tools designed to perform detailed digital
forensic examinations in a variety of settings. It can match any
current incident response and forensic tool suite. SIFT demonstrates
that advanced incident response capabilities and deep-dive digital
forensic techniques can be accomplished using cutting-edge open-
source tools that are freely available and frequently updated.
Bulk extractor
• Bulk_extractor is a computer forensics tool that scans a disk image, a file, or
a directory of files and extracts useful information without parsing the file
system or file system structures.
• Bulk_extractor is distinguished from other forensic tools by its speed and
thoroughness.
• Working:
• Bulk_extractor is a C++ program that scans a disk image, a file, or a
directory of files and extracts useful information without parsing the file
system or file system structures.
• The results are stored in feature files that can be easily inspected, parsed, or
processed with automated tools.
Volatility
• Volatility is one of the best open source software programs for analyzing RAM in 32 bit/64 bit systems.
• It supports analysis for Linux, Windows, Mac, and Android systems. It is based on Python and can be run
Windows, Linux, and Mac systems.
• It can analyze raw dumps, crash dumps, VMware dumps (.vmem), virtual box dumps, and many others.
• Selecting a profile
• For performing analysis using Volatility we need to first set a profile to tell Volatility what operating system
the dump came from, such as Windows XP, Vista, Linux flavors, etc.
• Type ./[Link] imageino –f <Destination of the memory Dump>
• Offered as an open source and free project, the SIFT Workstation is used in the following incident respons
courses at SANS:
• Advanced Incident Response course (FOR508)
• Advanced Network Forensics course (FOR572)
• Cyber Threat Intelligence (FOR578)
• Enterprise-Class Incident Response course (FOR608 - set to debut in 2021)
Internet Evidence Finder (IEF)
• Internet Evidence Finder (IEF) can find and retrieve any and
all supported internet related artifacts, benefitting the
investigation by speeding up the process of parsing the data.
• It provides artifact information for: web browsers (Google
Chrome, Mozilla Firefox, Internet Explorer, etc.); chat
programs (AIM, Google Talk, Yahoo Messenger); email
(Gmail, Hotmail, Yahoo Mail); and torrent programs (Ares,
Frostwire, eMule) among others.
• Internet Evidence Finder (IEF) is a digital forensics solution
that can search a hard drive, live RAM captures or files for
Internet-related evidence. IEF was designed with digital
Thank You