Tag: Cyber intelligence


USBDeviceForensics is an application to extract numerous bits of information regarding USB devices. It uses the information from a SANS blog posting to retrieve operating system specific information. It now has the ability to process multiple NTUSER.dat registry hives in one go. It should be noted that whilst the information in the blog posting is …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2014/11/11/usbdeviceforensics/

Windows ShellBag Parser (sbag)

sbag is a Windows registry parser that targets the Shellbag subkeys to pull useful directory and file artifacts to help identify user activity. There are binaries available for Windows, Linux and Mac OS-X. The Windows version allows one to parse hives resident from a live system. As background, the ShellBag information is a set of …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2014/11/11/windows-shellbag-parser-sbag/


Regshot is an open-source (LGPL) registry compare utility that allows you to quickly take a snapshot of your registry and then compare it with a second one – done after doing system changes or installing a new software product. http://sourceforge.net/projects/regshot/

Permanent link to this article: http://www.darknessgate.com/2014/11/11/regshot/

Registry Decoder

Accurate, efficient analysis of the Windows registry Registry Decoder provides a single tool in which to perform browsing, searching, analysis, and reporting of registry hive contents. All functionality is exposed through an intuitive GUI interface and accommodates even novice investigators. Registry Decoder also acts as a great resource for new research and experimenting within the …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2014/11/11/registry-decoder/


ForensicUserInfo will extract the following information: RID Login Name Name Description User Comment LM Hash NT Hash Last Login Date Password Reset Date Account Expiry Date Login Fail Date Login Count Failed Logins Profile Path Groups http://www.woanware.co.uk/forensics/forensicuserinfo.html

Permanent link to this article: http://www.darknessgate.com/2014/11/11/forensicuserinfo/

Volatility Interface & Extensions

This project aims to develop a software to extend the use and simplify the handling of the Volatility Framework . Objectives of VOLIX: Simplify the handling of Volatility Provide a more intuitive GUI handling Reduce complex command sequences to a single click Improving usability Increase analysis speed (no tedious typing of commands) Make comparison and correlation of results easier Offer assistance / examples Provide new functions Automated search for malware and analysis of the findings by VirusTotal Detecting of hidden …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2014/11/11/volatility-interface-extensions/


MDD is a physical memory acquisition tool for imaging Windows based computers created by the innovative minds at ManTech International Corporation. MDD is capable of acquiring memory images from Win2000, XP, Vista and Windows Server. Download MDD

Permanent link to this article: http://www.darknessgate.com/2014/11/10/mdd/


Justniffer is a network protocol analyzer that captures network traffic and produces logs in a customized way, can emulate Apache web server log files, track response times and extract all “intercepted” files from the HTTP traffic. It lets you interactively trace tcp traffic from a live network or from a previously saved capture file. Justniffer’s …

Continue reading »

Permanent link to this article: http://www.darknessgate.com/2014/11/07/justniffer/

Permanent link to this article: http://www.darknessgate.com/2014/11/06/exiv2/

Permanent link to this article: http://www.darknessgate.com/2014/11/05/exiftags/

Permanent link to this article: http://www.darknessgate.com/2014/11/04/exif-viewer/