Category Archive: Disk Image

Live View

Live View version 0.7b is a Java-based graphical forensics tool that creates a VMware virtual machine out of a raw (dd-style) disk image or physical disk. This allows the forensic examiner to “boot up” the image or disk and gain an interactive, user-level perspective of the environment, all without modifying the underlying image or disk. …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2014/10/18/live-view/

ProDiscover

ProDiscover® Forensics is a powerful computer security tool that enables computer professionals to find all the data on a computer disk while protecting evidence and creating evidentiary quality reports for use in legal proceedings. Features and Benefits: Create Bit-Stream copy of disk to be analyzed, including hidden HPA section (patent pending), to keep original evidence …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2014/03/10/prodiscover/

Forensic Toolkit® (FTK®)

FTK is a court-accepted digital investigations platform that is built for speed, analytics and enterprise-class scalability. Known for its intuitive interface, email analysis, customizable data views and stability, FTK lays the framework for seamless expansion, so your computer forensics solution can grow with your organization’s needs. In addition AccessData offers new expansion modules delivering an …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2014/03/03/forensic-toolkit-ftk-commercial-app/

Paraben’s P2 eXplorer

Paraben’s P2 eXplorer allows you to mount almost any forensic image or hard drive and explore it as though it were a drive on your machine while preserving the forensic nature of your evidence. In fact, P2 eXplorer is one of the only programs that mounts images as logical and physical disks. This means all …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2012/10/05/parabens-p2-explorer-2-2/

Paraben's P2 eXplorer

Paraben’s P2 eXplorer allows you to mount almost any forensic image or hard drive and explore it as though it were a drive on your machine while preserving the forensic nature of your evidence. In fact, P2 eXplorer is one of the only programs that mounts images as logical and physical disks. This means all …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2012/10/05/parabens-p2-explorer-2/

HotSwap

HotSwap does the same thing as you can remove device from Device Manager but it provides much friendly user interface as you remove the removable device from the “Safely Remove Hardware” icon in the notification area. It also ensures that all data are written and flushed to the disk before the device to be hot-swapped, …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2012/10/05/hotswap/

guymager

guymager is a free forensic imager for media acquisition. Its main features are: Easy user interface in different languages Runs under Linux Really fast, due to multi-threaded, pipelined design and multi-threaded data compression Makes full usage of multi-processor machines Generates flat (dd), EWF (E01) and AFF images, supports disk cloning Free of charges, completely open …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2012/10/05/guymager/

dd for windows

This version does not actually do any conversion but it allows the flexible copying of data under in a win32 environment. According to Wikipedia dd means the following “In computing, dd is a common Unix program whose primary purpose is the low-level copying and conversion of raw data. According to the manual page for Version …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2012/09/13/dd-for-windows/

Encrypted Disk Detector

Encrypted Disk Detector (EDD) is a command-line tool that checks the local physical drives on a system for TrueCrypt, PGP®, or Bitlocker® encrypted volumes. If no disk encryption signatures are found in the MBR, EDD also displays the OEM ID and, where applicable, the Volume Label for partitions on that drive, checking for Bitlocker® volumes. …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2012/09/11/encrypted-disk-detector/

Paraben's P2 eXplorer

Paraben’s P2 eXplorer allows you to mount almost any forensic image or hard drive and explore it as though it were a drive on your machine while preserving the forensic nature of your evidence. In fact, P2 eXplorer is one of the only programs that mounts images as logical and physical disks. This means all …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2012/09/11/parabens-p2-explorer/

Paraben’s P2 eXplorer

Paraben’s P2 eXplorer allows you to mount almost any forensic image or hard drive and explore it as though it were a drive on your machine while preserving the forensic nature of your evidence. In fact, P2 eXplorer is one of the only programs that mounts images as logical and physical disks. This means all …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2012/09/11/parabens-p2-explorer-3/

Page 1 of 212