General Forensic Tools

You can access forensic software for General Forensic Tools

Agent Ransack

Highly efficient search algorithms mean that you spend less time waiting for results.Indexes can be created for instant searching through GB of data. Documents, images, and source code can be reviewed quickly using unique data navigation functionality. It can be search through emails, contacts, calendar items over multiple PST files in one go.

Computer Forensic Reference Data Sets

NIST is developing Computer Forensic Reference Data Sets (CFReDS) for digital evidence. These reference data sets (CFReDS) provide to an investigator documented sets of simulated digital evidence for examination. 

Nuix Evidence Mover

Nuix Evidence Mover is designed to copy evidence file images from one storage location to another. It creates a hash of the files before and after moving to ensure the data has been copied accurately, and to maintain the chain of custody.

FastCopy

FastCopy is the fastest copy and backup software on Windows. It supports UNICODE and over MAX_PATH (260 characters) file pathnames. Because it uses multi-threads for Read/Write/Verify, Overlapped I/O, Direct I/O, so it brings out the best speed of devices. It runs fast and does not hog resources, because MFC is not used.

File Signatures

The  File Signatures Web site searches a database based upon file extension or file signature.

HexBrowser

Hexbrowser is a tool that can identify more than 1000 different file formats, by looking for signatures inside the files. HexBrowser is freeware. HexBrowser works on all Windows versions that can run .NET 2.0.

HashMyFiles

HashMyFiles is small utility that allows you to calculate the MD5 and SHA1 hashes of one or more files in your system. You can easily copy the MD5/SHA1 hashes list into the clipboard, or save them into text/html/xml file. You can also be launched from the context menu of Windows Explorer, and display the MD5/SHA1 hashes of the selected file or folder.

MobaLiveCD

MobaLiveCD is a freeware that will run your Linux LiveCD on Windows thanks to the excellent emulator called “Qemu”. MobaLiveCD allows you to test your LiveCD with a single click : after downloading the ISO image file of your favorite LiveCD, you just have to start it in MobaLiveCD and here you are, without the need to burn a CD-Rom or to reboot your computer.

Notepad ++

Notepad++ is a free. Running in the MS Windows environment, its use is governed by GPL License. Notepad++ is written in C++ and uses pure Win32 API and STL which ensures a higher execution speed and smaller program size.

    wpChatIcon