Call trans opt: receveid. 9-18-99 14:32:31 REC:log>
WARNING: carrier anomaly
Trace program: running
> Welcome
38.107.191.97
18.03.2010 - 00:47 (23:47 GMT)
5orry, you have... NO MAIL.
Computer Forensics: The Complete Documentation
- This category contains 15 Tools
- The last tool was added on 2007-02-12 (YYYY-MM-DD)
- Use the Source Lucie!!! >:)
AIR (Automated Image & Restore) -v1.2.3beta3
Published on 2003-06-25 - by Steve Gibson, ©Steve Gibson.
AIR (Automated Image & Restore) is a GUI front-end to dd/dcfldd designed for easily creating forensic bit images. Supports verification via MD5/SHA1, SCSI tape drives, imaging over a TCP/IP network, and complete session logging.
- Changelog:
- Download: http://tools.l0t3k.net/Forensic/air-1.2.3-beta3.tar.gz
- Home: http://sourceforge.net/projects/air-imager/
- License: GNU General Public License
- MD5SUM: ef8f9fa84efa87fcb150282cdf99f10b
- Platform(s): Linux
Autopsy -v2.00
Published on 2004-03-19 - by Brian Carrier, ©Brian Carrier.
The Autopsy Forensic Browser is a graphical interface to the command line digital forensic analysis tools in The Sleuth Kit. Together, The Sleuth Kit and Autopsy provide many of the same features as commercial digital forensics tools for the analysis of Windows and UNIX file systems (NTFS, FAT, FFS, EXT2FS, and EXT3FS).
- Changelog: http://www.sleuthkit.org/autopsy/index.php
- Download: http://tools.l0t3k.net/Forensic/autopsy-2.00.tar.gz
- Home: http://www.sleuthkit.org/
- License: GNU General Public License
- MD5SUM: 73873b4af937cf11354f681b0c269f50
- Platform(s): FreeBSD, Linux, MacOS X, OpenBSD, Solaris
BIEW -v5.61
Published on 2004-03-31 - by Nick Kurshev, ©Nick Kurshev.
BIEW- is multiplatform portable viewer of binary files with built-in editor in binary, hexadecimal and disassembler modes. It uses native Intel syntax for disassemble. Highlight AVR/Java/Athlon64/Pentium 4/K7-Athlon disassembler, russian codepages convertor, full preview of formats - MZ, NE, PE, NLM, coff32, elf partial - a.out, LE, LX, PharLap; code navigator and more over.
- Changelog:
- Download: http://tools.l0t3k.net/Forensic/biew561.tar.bz2
- Home: http://biew.sourceforge.net/
- License: GNU General Public License
- MD5SUM: ea62710ca6aa14fadfc6bd99fcb0a695
- Platform(s): MS-DOS, Windows, OS/2, Other OS, FreeBSD, Linux
bsed : binary stream editor -v1.0
Published on 2001-07-01 - by dwd, ©dwd.
bsed searches for a binary string in a file. If a replace string is given, bsed copies infile to outfile, replacing all instances of the search string with the replace string.
- Changelog:
- Download: http://tools.l0t3k.net/Forensic/bsed.tar.gz
- Home: http://www1.bell-labs.com/project/wwexptools/bsed/
- License: GNU General Public License
- MD5SUM: b1fa58fd4a1f52f0a2875bbb967679e1
- Platform(s):
Coreography -v1.0a
Published on - by coreography, ©Coreography.
Coreography is an open source utility for browsing memory images. Originally, it was intended as a tool for assisting in the analysis of core dumps. However, the tool has been expanded to parse any ELF based memory image, including core dumps and ELF libraries, object files, and executables, and even live processes.
- Changelog:
- Download: http://tools.l0t3k.net/Forensic/coreography-1a.tgz
- Home: http://www.engination.com/coreography/
- License: ©copyright
- MD5SUM:
- Platform(s):
Fenris -v0.07-m
Published on 2002-06-25 - by Michal Zalewski, ©Michal Zalewski.
Fenris is a multipurpose tracer, GUI debugger, stateful analyzer and partial decompiler intended to simplify bug tracking, security audits, code, algorithm, protocol analysis and computer forensics - providing a structural program trace, interactive debugging capabilities, general information about internal constructions, execution path, memory operations, I/O, conditional expressions and much more. Because it does not require sources or any particular compilation method, this multi-component project can be very helpful for black-box tests and evaluations - but it will also be a great tool for open-source project audits, as an unmatched real-time reconnaissance tool - especially when sources are too complex or too badly written to be analyzed by hand in a reliable way and reasonable time. Fenris does not rely on GNU libbfd for any critical tasks, and because of that, it is possible and feasible to trace and analyze binaries modified to fool debuggers, crypted, or otherwise tweaked. Fenris components also support other, independent debuggers or disassemblers, thanks to its capabilities to reconstruct symbol tables for stripped, static binaries with no debugging or symbol information whatsoever.
- Changelog:
- Download: http://tools.l0t3k.net/Forensic/fenris.tgz
- Home: http://razor.bindview.com/tools/fenris/
- License: GNU Public License, version 2
- MD5SUM: 14c1fe47e00fd5fc1f7e72f12c056334
- Platform(s):
Gpart -v0.1h
Published on 2001-02-15 - by Michail Brzitwa, ©Michail Brzitwa.
Gpart is a tool which tries to guess the primary partition table of a PC-type hard disk in case the primary partition table in sector 0 is damaged, incorrect or deleted. The guessed table can be written to a file or device.
- Changelog:
- Download: http://tools.l0t3k.net/Forensic/gpart-0.1h.tar.gz
- Home: http://www.stud.uni-hannover.de/user/76201/gpart/
- License: ©copyright
- MD5SUM: ee3a2d2dde70bcf404eb354b3d1ee6d4
- Platform(s):
mac-robber -v1.00
Published on - by @stake Inc., @stake Inc..
mac-robber is a forensics and incident response program that collects Modified, Access, and Change (MAC) times from files. Its output can be used as input to the 'mactime' tool in The @stake Sleuth Kit (TASK) to make a time line of file activity. mac-robber is similar to running the 'grave-robber' tool from The Coroner's Toolkit with the '-m' flag, except this is written in C and not Perl.
- Changelog:
- Download: http://www.l0t3k.org/tools/Forensic/mac-robber-1.00.tar.gz
- Home:
- License:
- MD5SUM: 4fa05cf85dd0d28c2780b6151b74f9f0
- Platform(s): UNIX
memfetch -
Published on - by Michal Zalewski, ©Michal Zalewski.
memfetch is a handy utility for dumping the memory of a running process (either immediately or on fault). It is a quite valuable addition to the shell command armory of an average hacker, helping you recover information that would otherwise be lost, and making it easier to check the integrity or internals of a running process. Most debuggers are good at accessing small portions of memory at once, whereas memfetch is a quick way of getting it all, ready to be processed in any way you like.
- Changelog:
- Download: http://tools.l0t3k.net/Forensic/memfetch.tgz
- Home: http://lcamtuf.coredump.cx/
- License: ©copyright
- MD5SUM: cda6080b905436c11ec996e19c4a5563
- Platform(s):
PyFlag -v0.60
Published on 2004-03-15 - by David Collett, ©David Collett.
FLAG was designed to simplify the process of log file analysis and forensic investigations. Often, when investigating a large case, a great deal of data needs to be analysed and correlated. Flag uses a database as a backend to assist in managing the large volumes of data. This allows flag to remain responsive and expedite data manipulation operations.
- Changelog:
- Download: http://tools.l0t3k.net/Forensic/pyflag-0.60.tar.bz2
- Home: http://pyflag.sourceforge.net/
- License: GNU General Public License
- MD5SUM: 966f890470a5d3b9a73dd4300d783e7d
- Platform(s): Linux
RDA - Remote Data Acquisition utility -v0.2.1c
Published on - by Chris Boubalos and Stefanos Koutsoutos, ©Chris Boubalos and Stefanos Koutsoutos.
rda is a command line Linux tool to remotely acquire data (like disk cloning or disk/partition imaging) and verify the transfer using md5 and/or crc32 checksums. The program is both the server and the client.
- Changelog:
- Download: http://tools.l0t3k.net/Forensic/rda-0.2.1c.tgz
- Home: http://md5sa.com/downloads/rda/index.htm
- License: GNU General Public License
- MD5SUM: 3b4ec72812e40d92c54ca7e242d83881
- Platform(s): Linux
Sleuth Kit -v1.69
Published on 2004-04-20 - by Brian Carrier, ©Brian Carrier.
The Sleuth Kit (previously known as TASK) is a collection of UNIX-based command line file system and media management forensic analysis tools. The file system tools allow you to examine NTFS, FAT, FFS, EXT2FS, and EXT3FS file systems of a suspect computer in a non-intrusive fashion. The tools have a layer-based design and can extract data from the internal file system structures. Because the tools do not rely on the operating system to process the file systems, deleted and hidden content is shown.
- Changelog: http://www.sleuthkit.org/sleuthkit/index.php
- Download: http://tools.l0t3k.net/Forensic/sleuthkit-1.69.tar.gz
- Home: http://www.sleuthkit.org/
- License: IBM Public License
- MD5SUM: 3479168ca94a3f75bbe545fae3d97ca6
- Platform(s): FreeBSD, Linux, MacOS X, OpenBSD, Solaris
TCTutils -v1.01
Published on - by Brian Carrier, ©Brian Carrier.
TCTUTILs is a collection of utilities that adds functionality to The Coroners Toolkit (TCT).
- Changelog:
- Download: http://www.l0t3k.org/tools/Forensic/tctutils-1.01.tar.gz
- Home:
- License:
- MD5SUM: 3b15db23cf6ecfbf4070891826f2a1a0
- Platform(s): Linux, OpenBSD, Solaris
TestDisk -v5.2
Published on - by Christophe Grenier, ©Christophe Grenier.
TestDisk was primarily designed to help recover lost partitions and/or make non-booting disks bootable again when these symptoms are caused by faulty software, certain types of viruses or human error (such as accidentally erasing your Partition Table).
- Changelog:
- Download: http://tools.l0t3k.net/Forensic/testdisk-5.2.tar.gz
- Home: http://www.cgsecurity.org/
- License: GNU Public License
- MD5SUM: f31ee06d2040e1d610a5891b57a86f65
- Platform(s):
The Coroner's Toolkit (TCT) -v1.11
Published on - by Dan Farmer and Wietse Venema, ©Dan Farmer and Wietse Venema.
TCT is a collection of programs by Dan Farmer and Wietse Venema for a post-mortem analysis of a UNIX system after break-in. The software was presented first in a Computer Forensics Analysis class in August 1999 (handouts can be found here). Examples of using TCT can also be found on-line in a series of columns in the Doctor Dobb's Journal.
- Changelog:
- Download: http://www.l0t3k.org/tools/Forensic/tct-1.11.tar.gz
- Home:
- License:
- MD5SUM: 2b2aafd08a1d3d6accc64063b9e7fad3
- Platform(s): FreeBSD, Linux, OpenBSD, Solaris