Инструменты

Многофункциональные инструменты

Name Interface Platform Manufacturer Licence
EnCase Forensic GUI Windows Guidance Software Commercial
FTK (Forensic Toolkit) GUI Windows AccessData Commercial
Forensic Explorer GUI Windows GetData Commercial
X-Ways Forensics GUI Windows X-Way Software Technology AG Commercial
Mac Marshal Forensic Edition™ GUI Macintosh Architecture Technology Commercial
BlackLight GUI Anywhere BlackBag Technologies Commercial
Autopsy GUI Anywhere Brian Carrier Opensource

Живые CD/DVD

Name Interface Platform Manufacturer Licence
SIFT SANS Freeware
PALADIN SAMURI Freeware
DEFT DEFT Staff Freeware
Helix e-fense Commercial
BackTrack BackTrack Linux Freeware
C.A.IN.E Caine Freeware

Блокировка записи

Name Interface Platform Manufacturer Licence
Tableau Forensic Bridge Tableau Commercial
Wiebetech Dock Wiebetech Commercial

Анализ регистра

Name Interface Platform Manufacturer Licence
REGA(REGistry Analyzer) GUI Windows 4&6tech Commercial
Registry Recon GUI Windows Arsenal Recon Commercial
Registry Workshop GUI Windows TorchSoft Commercial
RegRipper CLI Windows Harlan Carvey Opensource
UserAssist GUI Windows Didier Stevens Freeware
Registry Binary Parser GUI Windows woanware Freeware/Opensource
RegRipperRunner GUI Windows woanware Freeware/Opensource
ForensicUserInfo GUI Windows woanware Freeware/Opensource
USBDeviceForensics GUI Windows woanware Freeware/Opensource
Windows USB Storage Parser (usp) CLI Windows TZWorks Freeware/Commercial
Yet Another Registry Utility (yaru) CLI Windows TZWorks Freeware/Commercial
Windows ShellBag Parser (sbag) CLI Windows TZWorks Freeware/Commercial
Computer Account Forensic Artifact Extractor (cafae) CLI Windows TZWorks Freeware/Commercial

Анализ метаданных файловых систем

Name Interface Platform Manufacturer Licence
mft2csv GUI Windows joakim Freeware
anlyzeMFT CLI Anywhere David Kovar Opensource
MFTView GUI Windows Sanderson Forensics Freeware
NTFS Directory Enumerator CLI Windows TZWorks Freeware/Commercial
Windows $MFT and NTFS Metadata Extractor Tool CLI Windows TZWorks Freeware/Commercial
Windows INDX Slack Parser CLI Windows TZWorks Freeware/Commercial
Graphical Engine for NTFS Analysis (gena) CLI Windows TZWorks Freeware/Commercial

Анализ событий

Name Interface Platform Manufacturer Licence
Event Log Explorer GUI Windows FSPro Labs Commercial
Log Parser CLI Windows Microsoft Freeware
NTFS Log Tracker GUI Windows blueangel Freeware
NTFS TriForce CLI Windows David Cowen Freeware
Windows Journal Parser (jp) GUI Windows TZWorks Freeware/Commercial
Windows Event Log Viewer GUI Windows TZWorks Freeware/Commercial
Windows Event Log Parser GUI Windows TZWorks Freeware/Commercial
UsnJrnl2Csv CLI Windows joakim Freeware
LogFile Parser CLI Windows joakim Freeware

Анализ малвари

Name Interface Platform Manufacturer Licence
PeStudio GUI Windows Marc Ochsenmeier Freeware
PEView GUI Windows Wayne J. Radburn Freeware
Automater CLI Win & Lin TEKDEFENSE OpenSource
Noriben CLI Windows Rurik OpenSource

Анализ артефактов веб-браузеров

Name Interface Platform Manufacturer Licence
WEFA(WEb browser Forensic Analyzer) GUI Windows 4&6 Tech Commercial
Web Historian GUI Windows Mandiant Freeware
IEF(Internet Evidence Finder) GUI Windows Magnet Forensics Commercial
ChromeForensics GUI Windows woanware Freeware
FireFoxForensics GUI Windows woanware Freeware
firefoxsessionstoreextractor GUI Windows woanware Freeware
Windows ‘index.dat’ Parser (id) CLI Windows TZWorks Freeware/Commercial
BrowsingHistoryView GUI Windows NirSoft Freeware
IECacheView GUI Windows NirSoft Freeware
IECookiesView GUI Windows NirSoft Freeware
IEHistoryView GUI Windows NirSoft Freeware
ChromeCacheView GUI Windows NirSoft Freeware
ChromeHistoryView GUI Windows NirSoft Freeware
MozilaCacheView GUI Windows NirSoft Freeware
MozilaCookieView GUI Windows NirSoft Freeware
MozilaHistoryView GUI Windows NirSoft Freeware
SafariCacheView GUI Windows NirSoft Freeware
SafariHistoryView GUI Windows NirSoft Freeware
OperaCacheView GUI Windows NirSoft Freeware
WebBrowserPassView GUI Windows NirSoft Freeware
MyLastSearch GUI Windows NirSoft Freeware

Анализ баз данных

Name Interface Platform Manufacturer Licence
Exchange EDB Viewer GUI Windows Lepide Software Freeware
ESEDatabaseView GUI Windows NirSoft Freeware
EseDbViewer GUI Windows woanware Freeware
SQLite Expert GUI Windows Bogdan Ureche Commercial
Oxygen SQLite Viewer GUI Windows Oxygen Forensic Commercial
SQLite Database Browser GUI Win & Mac Tabuleiro Opensource
OracleForensics Tools

Анализ электронной почты

Name Interface Platform Manufacturer Licence
E-mail Examiner GUI Windows Paraben Commercial
Mail Viewer GUI Windows MiTeC Freeware
Email Utilities GUI Windows Stellar Information Systems Commercial
Email Recovery Tools GUI Windows Lepide Software Commercial

Сетевая форензика

Name Interface Platform Manufacturer Licence
WireShark GUI Anywhere WireShark Freeware
NetworkMiner GUI Windows NETRESEC Commercial
RSA NetWitness GUI Win & Lin RSA Commercial
Ostinato GUI Anywhere Pstavirs Opensource
Packet Builder GUI Windows Colasoft Freeware
SplitCap CLI Windows NETRESEC Opensource
tshark CLI Anywhere WireShark Freeware
Scapy CLI Anywhere Philippe Biondi Opensource
tcpdump CLI Anywhere Freeware
DNS Query Utility (dqu) CLI Windows TZWorks Freeware/Commercial
Packet Capture ICMP Carver (pic) CLI Windows TZWorks Freeware/Commercial
Network Xfer Client/Server Utility (nx) CLI Windows TZWorks Freeware/Commercial
snorbert CLI Windows Woanware Freeware
SessionViewer CLI Windows Woanware Freeware
enumdotnet CLI Windows Woanware Freeware

Мобильная форензика

Name Interface Platform Manufacturer Licence
MD Series GMDSystem Commercial
Cellebrite Mobile Forensics Cellebrite Commercial
Device Seizure Paraben Commercial
XRY Series Micro Systemation Commercial
Oxygen Forensic® Suite GUI Windows Oxygen Software Commercial
MPE+ GUI Windows Access Data Commercial
Lantern GUI Mac KatanaForensics Commercial
iPhone Backup Browser GUI Windows rene.devichi Commercial

Анализ хэшей

Name Interface Platform Manufacturer Licence
HashTab GUI Win & Mac Implbits Free/Comm
md5deep/hashdeep CLI Anywhere Jesse Kornblum Freeware
ssdeep CLI Anywhere ManTech Freeware
NSRL Hashsets NIST Freeware

Восстановление данных

Name Interface Platform Manufacturer Licence
RMF(Recover My Files) GUI Windows GetData Commercial
R-Studio GUI Anywhere R-Tools Technology Commercial
Power Data Recovery GUI Windows MiniTool® Solution Commercial