It is currently Sun May 19, 2013 1:10 am

All times are UTC - 8 hours




Post new topic Reply to topic  [ 1 post ] 
Author Message
 Post subject: TZWorks Forensics/Monitoring Tools
PostPosted: Wed Dec 07, 2011 5:24 pm 
Offline
User avatar

Joined: Thu Aug 07, 2008 4:51 am
Posts: 2581
Quote:
Below are various tools that cover a wide range of Windows digital computer forensic analysis.

Artifact Analysis
•Windows Prefetch Parser
•Windows 'index.dat' Parser
•Windows LNK Parsing Utility
•Windows USB Storage (USBSTOR) Parser

Registry and Event Log Analysis
•Yet Another Registry Utility (yaru)
•Windows Event Log Viewer
•Windows ShellBag Parser

NTFS Filesystem Analysis
•Windows Journal Parser (for NTFS change logs)
•NTFS Directory Enumerator
•NTFS File Copy Utility
•Windows NTFS Metadata Extractor Utility

Network Support Utilities
•DNS Query Utility
•Packet Capture (pcap) ICMP Carver
•Network Xfer Client/Server Utility

Portable Executable Utilities
•Windows Portable Executable (PE) Viewer
•Portable Executable (PE) Scanner

Miscellaneous Tools
•Windows Symbol Fetch Utility



Info @ http://tzworks.net/prototypes.php
Download @ http://tzworks.net/download_links.php

_________________
bəʊɡɪ bəəs


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 1 post ] 

All times are UTC - 8 hours


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  

Protected by Anti-Spam ACP Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group