Banner

Search Products

Product Directory

Who's Online?

We have 65 guests online

Forensic Tools

Forensic Tools
Listings RSS
Add your listing here

pstools

Visit the Product Site

The tools included in the PsTools suite, which are downloadable individually or as a package, are: PsExec - execute processes remotely, PsFile - shows files opened remotely, PsGetSid - display the SID of a computer or a user, PsKill - kill processes by na ...

Vendorsysinternals/Mark Russinovich
Pricing ModelFreeware
Modified2009-03-04

NetAnalysis

Visit the Product Site

NetAnalysis will automatically rebuild HTML web pages from an extracted cache, automatically adding the correct location of the graphics allowing you to view the page as the suspect did. NetAnalysis also allows you to easily view JPEG and other pictures t ...

VendorCraig Wilson
Pricing ModelCOMMERCIAL
Modified2003-04-06

chkrootkit

Visit the Product Site

chkrootkit: shell script that checks system binaries for rootkit modification. 45 rootkits, worms and LKMs are currently detected. The following tests are made: aliens asp bindshell lkm rexedcs sniffer wted scalper slapper z2 amd basename biff chfn chsh ...

VendorPangeia Informatica
Pricing ModelGPL
Modified2003-04-06

Rootkit ID project

Visit the Product Site

The CyberAbuse Rootkit ID project is made of a software and a database which allows a unix user to detect rootkit files on his machine. The software compares SHA1 checksum of the files on the unix machine with the checksum present in our database. If the ...

VendorPhilippe Bourcier
Pricing ModelGPL
Modified2003-04-06

Foremost

Visit the Product Site

Foremost is a Linux program to recover files based on their headers and footers. Foremost can work on image files, such as those generated by dd, Safeback, Encase, etc, or directly on a drive. The headers and footers are specified by a configuration file, ...

VendorSpecial Agent Jesse Kornblum
Pricing ModelGPL
Modified2003-04-06

md5deep

Visit the Product Site

md5deep is a cross-platform program to compute MD5 message digests on an arbitrary number of files. The program is known to run on Windows, Linux, FreeBSD, OS X, Solaris, and should run on most other platforms. md5deep is similar to the md5sum program fou ...

VendorSpecial Agent Jesse Kornblum
Pricing ModelGPL
Modified2003-04-06

PMDump

Visit the Product Site

PMDump is a tool that lets you dump the memory contents of a process to a file without stopping the process. This can be useful in a forensic investigation.

VendorArne Vidstrom
Pricing ModelFREEWARE
Modified2003-04-06

Ontrack PowerControls

Visit the Product Site

Ontrack® PowerControls™ has grown! We've increased the usabilty and functionality of PowerControls making it even easier and quicker to use - saving Exchange and SharePoint® administrators even more time and money! For the successful management of y ...

VendorKroll Ontrack Ltd
Pricing ModelCommercial
Modified2009-03-03

GNU Parted

Visit the Product Site

GNU Parted is a program for creating, destroying, resizing, checking and copying partitions, and the file systems on them. This is useful for creating space for new operating systems, reorganising disk usage, copying data between hard disks and disk imagi ...

VendorFree Software Foundation, Inc
Pricing ModelGPL
Modified2003-04-06

mac-robber

Visit the Product Site

mac-robber is a digital investigation tool that collects data from allocated files in a mounted file system. This is useful during incident response when analyzing a live system or when analyzing a dead system in a lab. The data can be used by the mactime ...

VendorBrian Carrier
Pricing ModelFREEWARE
Modified2006-06-07

WinHex

Visit the Product Site

Features include: Disk editor for hard disks, floppy disks, CD-ROM & DVD, ZIP, Smart Media, Compact Flash memory cards, and more. FAT12, FAT16, FAT32, NTFS, CDFS. RAM editor, providing access to other processes' virtual memory. Data interpreter, knowin ...

VendorX-Ways AG
Pricing ModelFree Trial
Modified2003-04-06

IDA Pro Disassembler

Visit the Product Site

Features include: IDA Pro is programmable through a built-in C like language. IDA offers an open Plugin Architecture. Our PE debugger is nothing more than a plugin! Multiple Processor : same interface and features for dozens of processors. 80x86 Windo ...

VendorDataRescue
Pricing ModelCOMMERCIAL
Modified2003-04-06

OllyDbg

Visit the Product Site

OllyDbg is a 32-bit assembler level analysing debugger for Microsoft Windows. Emphasis on binary code analysis makes it particularly useful in cases where source is unavailable. OllyDbg is a shareware, but you can download and use it for free. Special hig ...

VendorOleh Yuschuk
Pricing ModelSHAREWARE
Modified2003-04-06

OnlineDFS - Online Digital Forensics Suite

Visit the Product Site

OnlineDFS enables network-based, real-time investigations of live, running computer systems. It is ideal for rapid incident response, compliance management and e-discovery in enterprises, and for the needs of law enforcement. OnLineDFS enables the rapid, ...

VendorCyber Security Technologies Corporation
Pricing ModelCommercial
Modified2007-09-10

LinkAlyzer

Visit the Product Site

LinkAlyzer LinkAlyzer LinkAlyzer is a forensic tool that decodes and displays the content of multiple link files (Windows Shortcuts) at the same time. LinkAlyzer Loads multiple (tested on 40,000+) link files into a grid and Displays : • Internal dates (whe ...

VendorSanderson Forensics Ltd.
Pricing ModelCommercial

NetSentry Live New!

Visit the Product Site

NetSentry Live NetSentry Live undetectably monitors network Internet traffic and captures, reconstructs, and stores original content in a searchable database. With its real-time alerts, NetSentry can provide the insight to identify both who and when suspicious or malici ...

VendorNetSentry
Pricing ModelLimited Free Trial
Modified2010-08-18

Cain & Abel

Visit the Product Site

Cain & Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP con ...

VendorMassimiliano Montoro
Pricing ModelFreeware

RevEnge

Visit the Product Site

RevEnge is a fully featured hex viewer designed with Reverse Engineering in mind, hence the name. It comes packed with features not seen in other Hex viewers such as it ability to perform on the fly decompression of ZLib compressed data, display and searc ...

VendorSanderson Forensics Ltd.
Pricing ModelCommercial

PmExplorer

Visit the Product Site

PmExplorer is a forensic software tool for the review and examination of PM files for Nokia mobile telephones. PM files can be obtained with third party hardware and software utilities such as SaraSoft and the SHU box. PmExplorer differs from current m ...

VendorSanderson Forensics Ltd.
Pricing ModelCommercial

VidReport

Visit the Product Site

VidReport VidReport is a tool for the processing and reporting of video files (AVI's, MOV's etc.) VidReport can be used as a 'normal' video player to view the contents of the video, but in addition VidReport can parse the file and display just a selec ...

VendorSanderson Forensics Ltd.
Pricing ModelCommercial
Copyright 2004 through 2010 Computer Network Defence, Ltd.
All rights reserved