Category Archive: Digital Forensic

regshot

Regshot is an open-source (LGPL) registry compare utility that allows you to quickly take a snapshot of your registry and then compare it with a second one – done after doing system changes or installing a new software product. http://sourceforge.net/projects/regshot/

Permanent link to this article: http://www.darknessgate.com/2014/11/11/regshot/

Registry Decoder

Accurate, efficient analysis of the Windows registry Registry Decoder provides a single tool in which to perform browsing, searching, analysis, and reporting of registry hive contents. All functionality is exposed through an intuitive GUI interface and accommodates even novice investigators. Registry Decoder also acts as a great resource for new research and experimenting within the …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2014/11/11/registry-decoder/

ForensicUserInfo

ForensicUserInfo will extract the following information: RID Login Name Name Description User Comment LM Hash NT Hash Last Login Date Password Reset Date Account Expiry Date Login Fail Date Login Count Failed Logins Profile Path Groups http://www.woanware.co.uk/forensics/forensicuserinfo.html

Permanent link to this article: http://www.darknessgate.com/2014/11/11/forensicuserinfo/

Volatility Interface & Extensions

This project aims to develop a software to extend the use and simplify the handling of the Volatility Framework . Objectives of VOLIX: Simplify the handling of Volatility Provide a more intuitive GUI handling Reduce complex command sequences to a single click Improving usability Increase analysis speed (no tedious typing of commands) Make comparison and correlation of results easier Offer assistance / examples Provide new functions Automated search for malware and analysis of the findings by VirusTotal Detecting of hidden …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2014/11/11/volatility-interface-extensions/

MDD

MDD is a physical memory acquisition tool for imaging Windows based computers created by the innovative minds at ManTech International Corporation. MDD is capable of acquiring memory images from Win2000, XP, Vista and Windows Server. Download MDD

Permanent link to this article: http://www.darknessgate.com/2014/11/10/mdd/

Permanent link to this article: http://www.darknessgate.com/2014/11/06/exiv2/

Permanent link to this article: http://www.darknessgate.com/2014/11/05/exiftags/

Permanent link to this article: http://www.darknessgate.com/2014/11/04/exif-viewer/

Permanent link to this article: http://www.darknessgate.com/2014/11/03/exif-tag-parsing-library/

Permanent link to this article: http://www.darknessgate.com/2014/11/01/exif-jpeg-header-manipulation-tool/

Permanent link to this article: http://www.darknessgate.com/2014/10/31/exiftool/

Page 4 of 9« First...23456...Last »