Lined Notebook

디지털 포렌식 Tools

by Gerberaa

통합 포렌식 도구 (Integrated Forensics Tools)

NameInterfacePlatformManufacturerLicence
EnCase ForensicGUIWindowsGuidance SoftwareCommercial
FTK (Forensic Toolkit)GUIWindowsAccessDataCommercial
Forensic ExplorerGUIWindowsGetDataCommercial
X-Ways ForensicsGUIWindowsX-Way Software Technology AGCommercial
Mac Marshal Forensic Edition™GUIMacintoshArchitecture TechnologyCommercial
BlackLightGUIAnywhereBlackBag TechnologiesCommercial
AutopsyGUIAnywhereBrian CarrierOpensource



라이브 CD/VM (Live CD/VM)

NameInterfacePlatformManufacturerLicence
SIFTSANSFreeware
PALADINSAMURIFreeware
DEFTDEFT StaffFreeware
Helixe-fenseCommercial
BackTrackBackTrack LinuxFreeware
C.A.IN.ECaineFreeware



라이브 포렌식 (Live Forensics)

NameInterfacePlatformManufacturerLicence
FPLive_winCLIWindowsJK KimFreeware
FRED (First Responder’s Evidence Disk)GUIWindowsDark Particle LabsFreeware
WFT (Windows Forensic Toolchest)CLIWindowsFoolMoonFree/Comm
Dual Purpose Volatile Data Collection ScriptCLIWindowsCorey HarrellOpensource
IRCR (Incident Response Collection Report)CLIWindowsmcleodjpOpensource
COFEE (Computer Online Forensic Evidence Extractor)CLIWindowsMicrosoftonly Law enforcement
MIR (MANDIANT Intelligent Response)GUIWindowsMandiantCommercial
OnLineDFS (OnLine Digital Forensic Suite)CLIWindowsCSTCommercial
MacResponse LE™GUIMacintoshAISOpensource



이미징 하드웨어 (Imaging Hardware)

NameInterfacePlatformManufacturerLicence
Image MASSter SeriesIntelligent Computer Solutions, Inc.Commercial
Dossier & FalconLogicubeCommercial
TD3TableauCommercial
MagicubeDataExpertCommercial



이미징 소프트웨어 (Imaging Software)

NameInterfacePlatformManufacturerLicence
FTK Imager (Lite)
CLI FTK Imager for Debian, Ubuntu, Fedora, RedHat, Mac OS.
GUIWindowsAccessDataFreeware
Tableau ImagerGUIWindowsTABLEAUFreeware
(need Tableau W/B)
X-Ways ImagerGUIWindowsX-Ways Software Technology AGCommercial
EnCase Forensic
Imager
GUIWindowsGuidance SoftwareFreeware
FAU DDCLIWindowsGeorge M. Garner Jr.Freeware
ODINGUIWindowsJensHOpensource
OSFCloneCLIWindowsPassMark SoftwareOpensource
ewfacquire, ewfacquirestreamCLIUnix-basedJoachim MetzOpensource
GuymagerGUILinuxvogu00Freeware
dcflddCLIUnix-basedNick HarbourOpensource
MacQuisitionCLIMacintoshBlackBag TechnologiesOpensource



쓰기방지장치 (Write Blocker)

NameInterfacePlatformManufacturerLicence
Tableau Forensic BridgeTableauCommercial
Wiebetech DockWiebetechCommercial



이미지 마운트 (Image Mounting)

NameInterfacePlatformManufacturerLicence
Arsenal Image MounterGUIWindowsArsenal ReconFreeware
Mount Image ProGUIWindowsGetDataCommercial
OSFMountGUIWidowsPassMark SoftwareFreeware
VHD toolCLIWindowsMicrosoftFreeware
LiveViewGUIWin & LinCMU/td>

Freeware
raw2vmdkGUIAnywhereZapotek/td>

Freeware
FTK ImagerGUIWindowsAccessDataFreeware
P2 eXplorerGUIWidowsParabenFreeware
ImDiskGUIWindowsLTRDATAOpensource



원격 포렌식 (Remote Forensics)

NameInterfacePlatformManufacturerLicence
F-Response SeriesGUIAnywhereF-ResponseCommercial



메모리 획득 (Memory Acquisition)

NameInterfacePlatformManufacturerLicence
DumpItCLIWindowsMoonSolsFreeware
win(32/64)ddCLIWindowsMoonSolsFree/Comm
FastDump ProCLIWindowsHBGaryCommercial
mddCLIWindowsManTechOpensource
Memorize (for Mac)GUIWindowsMandiantFreeware
FTK Imager (Lite)
CLI FTK Imager for Debian, Ubuntu, Fedora, RedHat, Mac OS.
GUIWindowsAccessDataFreeware
WinPmemCLIWindowsMichael CohenFreeware
fmemCLILinuxniekt0Freeware
LiMECLILinuxJoe SylveFreeware
Second Look® Linux Memory AcquisitionCLILinuxRaytheon PikewerksCommercial
Mac Memory Reader™CLIMacintoshMac Marshal™Freeware
OSXPMemCLIMacintoshMichael CohenFreeware



메모리 분석 (Memory Analysis)

NameInterfacePlatformManufacturerLicence
RedlineGUIWindowsMandiantFreeware
VolatilityCLIAnywhereVolatile SystemsOpensource
Memorize & Audit ViewerGUIWindowsMandiantFreeware
Responder ProGUIWindowsHBGaryCommercial
Second Look® Linux Memory AnalysisCLILinuxRaytheon PikewerksCommercial
VolafoxCLIMac OSn0fateOpensource
VolafunxCLIFreeBSDn0fateOpensource



타임라인 분석 (Timeline Analysis)

NameInterfacePlatformManufacturerLicence
log2timelineCLILinux & MacKristinn GudjonssonFreeware
plasoCLIWin & MacKristinn GudjonssonFreeware
4n6timeGUIWin & MacKristinn GudjonssonFreeware
TimelinerGLIWindowsWoanwareFreeware/Opensource
Timeline ReportGUIEnCase-BasedGeoff BlackOpensource



레지스트리 분석 (Registry Analysis)

NameInterfacePlatformManufacturerLicence
REGA(REGistry Analyzer)GUIWindows4&6techCommercial
Registry ReconGUIWindowsArsenal ReconCommercial
Registry WorkshopGUIWindowsTorchSoftCommercial
RegRipperCLIWindowsHarlan CarveyOpensource
UserAssistGUIWindowsDidier StevensFreeware
Registry Binary ParserGUIWindowswoanwareFreeware/Opensource
RegRipperRunnerGUIWindowswoanwareFreeware/Opensource
ForensicUserInfoGUIWindowswoanwareFreeware/Opensource
USBDeviceForensicsGUIWindowswoanwareFreeware/Opensource
Windows USB Storage Parser (usp)CLIWindowsTZWorksFreeware/Commercial
Yet Another Registry Utility (yaru)CLIWindowsTZWorksFreeware/Commercial
Windows ShellBag Parser (sbag)CLIWindowsTZWorksFreeware/Commercial
Computer Account Forensic Artifact Extractor (cafae)CLIWindowsTZWorksFreeware/Commercial



파일시스템 메타데이터 (Filesystem Metadata)

NameInterfacePlatformManufacturerLicence
mft2csvGUIWindowsjoakimFreeware
anlyzeMFTCLIAnywhereDavid KovarOpensource
MFTViewGUIWindowsSanderson ForensicsFreeware
NTFS Directory EnumeratorCLIWindowsTZWorksFreeware/Commercial
Windows $MFT and NTFS Metadata Extractor ToolCLIWindowsTZWorksFreeware/Commercial
Windows INDX Slack ParserCLIWindowsTZWorksFreeware/Commercial
Graphical Engine for NTFS Analysis (gena)CLIWindowsTZWorksFreeware/Commercial



바로가기 파일 분석 (LNK Analysis)

NameInterfacePlatformManufacturerLicence
Windows LNK Parsing Utility (lp)CLIWindowsTZWorksFreeware/Commercial
lnkanalyserCLIWindowsWoanwareFreeware



로그 분석 (Log Analysis)

NameInterfacePlatformManufacturerLicence
Event Log ExplorerGUIWindowsFSPro LabsCommercial
Log ParserCLIWindowsMicrosoftFreeware
NTFS Log TrackerGUIWindowsblueangelFreeware
NTFS TriForceCLIWindowsDavid CowenFreeware
Windows Journal Parser (jp)GUIWindowsTZWorksFreeware/Commercial
Windows Event Log ViewerGUIWindowsTZWorksFreeware/Commercial
Windows Event Log ParserGUIWindowsTZWorksFreeware/Commercial
UsnJrnl2CsvCLIWindowsjoakimFreeware
LogFile ParserCLIWindowsjoakimFreeware



악성코드 분석 (Malware Analysis)

NameInterfacePlatformManufacturerLicence
PeStudioGUIWindowsMarc OchsenmeierFreeware
PEViewGUIWindowsWayne J. RadburnFreeware
AutomaterCLIWin & LinTEKDEFENSEOpenSource
NoribenCLIWindowsRurikOpenSource



프리패치 분석 (Prefetch Analysis)

NameInterfacePlatformManufacturerLicence
WinPrefetchViewGUIWindowsNirSoftFreeware
PrefetchForensicsGUIWindowswoanwareFreeware
APFA(Advanced Prefetch File Analyzer)GUIWindowsAllan S HayFreeware
Prefetch ParserCLIWindowsSANSFreeware
Windows Prefetch ParserCLIAnywhereTZWorksFreeware/Commercial



웹 브라우저 사용 흔적 (Web Browser Artifacts)

NameInterfacePlatformManufacturerLicence
WEFA(WEb browser Forensic Analyzer)GUIWindows4&6 TechCommercial
Web HistorianGUIWindowsMandiantFreeware
IEF(Internet Evidence Finder)GUIWindowsMagnet ForensicsCommercial
ChromeForensicsGUIWindowswoanwareFreeware
FireFoxForensicsGUIWindowswoanwareFreeware
firefoxsessionstoreextractorGUIWindowswoanwareFreeware
Windows ‘index.dat’ Parser (id)CLIWindowsTZWorksFreeware/Commercial
BrowsingHistoryViewGUIWindowsNirSoftFreeware
IECacheViewGUIWindowsNirSoftFreeware
IECookiesViewGUIWindowsNirSoftFreeware
IEHistoryViewGUIWindowsNirSoftFreeware
ChromeCacheViewGUIWindowsNirSoftFreeware
ChromeHistoryViewGUIWindowsNirSoftFreeware
MozilaCacheViewGUIWindowsNirSoftFreeware
MozilaCookieViewGUIWindowsNirSoftFreeware
MozilaHistoryViewGUIWindowsNirSoftFreeware
SafariCacheViewGUIWindowsNirSoftFreeware
SafariHistoryViewGUIWindowsNirSoftFreeware
OperaCacheViewGUIWindowsNirSoftFreeware
WebBrowserPassViewGUIWindowsNirSoftFreeware
MyLastSearchGUIWindowsNirSoftFreeware



데이터베이스 분석 (Database Analysis)

NameInterfacePlatformManufacturerLicence
Exchange EDB ViewerGUIWindowsLepide SoftwareFreeware
ESEDatabaseViewGUIWindowsNirSoftFreeware
EseDbViewerGUIWindowswoanwareFreeware
SQLite ExpertGUIWindowsBogdan UrecheCommercial
Oxygen SQLite ViewerGUIWindowsOxygen ForensicCommercial
SQLite Database BrowserGUIWin & MacTabuleiroOpensource
OracleForensics Tools



이메일 분석 (Email Analysis)

NameInterfacePlatformManufacturerLicence
E-mail ExaminerGUIWindowsParabenCommercial
Mail ViewerGUIWindowsMiTeCFreeware
Email UtilitiesGUIWindowsStellar Information SystemsCommercial
Email Recovery ToolsGUIWindowsLepide SoftwareCommercial



포맷 분석 (Format Analysis)

NameInterfacePlatformManufacturerLicence
010Editor TemplatesGUIWindowsSweetScape SoftwareCommercial
FileInsightGUIWindowsMcAfeeFreeware
Structed Storage ViewerGUIWindowsMiTeCFreeware
OffVisGUIWindowsMicrosoftFreeware
Windows Portable Executable Viewer (pe_view)GUIWindowsTZWorksFreeware/Commercial
PDF ParserCLIAnywhereDidier StevensFreeware
peedpdfCLIAnywhereJose Miguel EsparzaFreeware
PDF Stream DumperGUIWindowsDavid ZimmerFreeware



복원지점/볼륨섀도복사본 분석 (Restore Point/VSC))

NameInterfacePlatformManufacturerLicence
RP Log TrackerGUIWindowsblueangelFreeware
libvshadowCLIWindowsJoachim MetzFreeware
ShadowExplorerGUIWindowsShadowExplorerFreeware
ShadowKitGUIWindowsDavid DymFreeware
VSC ToolsetGUIWindowsJason HaleFreeware
ReconnoitreGUIWindowsSanderson ForensicsCommercial



자바 IDX 분석 (Java IDX Analysis))

NameInterfacePlatformManufacturerLicence
RP Log TrackerCLIAnywhereBrian BaskinOpenSource
JavaidxCLIWindowsMark WoanOpenSource
IdxparserCLIWindowsHarlan CarveyOpenSource



추가적인 아티팩트 분석 (Any Other Artifacts)

NameInterfacePlatformManufacturerLicence
Windows File AnalyzerGUIWindowsMiTeCFreeware
Windows Jump List Parser (jmp)CLIWindowsTZWorksFreeware/Commercial
Portable Executable Scanner (pescan)CLIWindowsTZWorksFreeware/Commercial
autorunnerGUIWindowswoanwareFreeware
exefinderGUIWindowswoanwareFreeware
JumpListerGUIWindowswoanwareFreeware
shimcacheparserGUIWindowswoanwareFreeware
Windows Search Index ExtractorGUIWindowsFilesig SoftwareCommercial
Thumbnail Database ViewerGUIWindowsIgor TolmacheFreeware
SFP(Simple File Parser)GUIWindowsChris MayhewFreeware



네트워크 포렌식 (Network Forensics)

NameInterfacePlatformManufacturerLicence
WireSharkGUIAnywhereWireSharkFreeware
NetworkMinerGUIWindowsNETRESECCommercial
RSA NetWitnessGUIWin & LinRSACommercial
OstinatoGUIAnywherePstavirsOpensource
Packet BuilderGUIWindowsColasoftFreeware
SplitCapCLIWindowsNETRESECOpensource
tsharkCLIAnywhereWireSharkFreeware
ScapyCLIAnywherePhilippe BiondiOpensource
tcpdumpCLIAnywhereFreeware
DNS Query Utility (dqu)CLIWindowsTZWorksFreeware/Commercial
Packet Capture ICMP Carver (pic)CLIWindowsTZWorksFreeware/Commercial
Network Xfer Client/Server Utility (nx)CLIWindowsTZWorksFreeware/Commercial
snorbertCLIWindowsWoanwareFreeware
SessionViewerCLIWindowsWoanwareFreeware
enumdotnetCLIWindowsWoanwareFreeware



패스워드 공격(Password Attack)

NameInterfacePlatformManufacturerLicence
EPRB(ElcomSoft Password Recovery Bundle)GUIWindowsElcomSoftCommercial
PPR(Passware Password Recovery)GUIWindowsPasswareCommercial
SAMInsideGUIWindowsInsideProFreeware
ophcrackGUIAnywhereOBJECTIF SECURITEFreeware
L0PHTCRACKGUIWindowsL0pht HoldingsCommercial



윈도우 패스워드(Windows Password)

NameInterfacePlatformManufacturerLicence
Cain & AbelGUIWindowsMassimiliano MontoroFreeware
Windows Password RecoveryGUIWindowsPasscape SoftwareFreeware
pwdump7CLIWindowsTarascoFreeware
gsecdumpCLIWindowsTruesecFreeware
PWDumpXCLIWindowsReed ArvinFreeware
lsadump2CLIWindowsizarFreeware
creddumpCLIWindowsmooyixOpensource
NTPWEditGUIWindowsVadim DruzhinFreeware
NTPasswordCLIWindowsPogostickFreeware



모바일 포렌식 (Mobile Forensics)

NameInterfacePlatformManufacturerLicence
MD SeriesGMDSystemCommercial
Cellebrite Mobile ForensicsCellebriteCommercial
Device SeizureParabenCommercial
XRY SeriesMicro SystemationCommercial
Oxygen Forensic® SuiteGUIWindowsOxygen SoftwareCommercial
MPE+GUIWindowsAccess DataCommercial
LanternGUIMacKatanaForensicsCommercial
iPhone Backup BrowserGUIWindowsrene.devichiCommercial



헥스 편집기 (Hex Editor)

NameInterfacePlatformManufacturerLicence
010EditorGUIWindowsSweetScapeCommercial
WinHexGUIWindowsX-Ways Software Technology AGCommercial
HexWorkshopGUIWindowsHexWorkshopCommercial
HxDGUIWindowsMael HorzFreeware



해쉬 분석 (Hash Analysis)

NameInterfacePlatformManufacturerLicence
HashTabGUIWin & MacImplbitsFree/Comm
md5deep/hashdeepCLIAnywhereJesse KornblumFreeware
ssdeepCLIAnywhereManTechFreeware
NSRL HashsetsNISTFreeware



완전삭제 (Wipe/Sanitization)

NameInterfacePlatformManufacturerLicence
EraserGUIWindowsThe Eraser ProjectFreeware
BCWipeGUIWin & LinJeticoCommercial
SDeleteCLIWindowsSysinternalsFreeware
Secure EraseCLIWin & LinCMRRFreeware



데이터 복구 (Data Recovery)

NameInterfacePlatformManufacturerLicence
RMF(Recover My Files)GUIWindowsGetDataCommercial
R-StudioGUIAnywhereR-Tools TechnologyCommercial
Power Data RecoveryGUIWindowsMiniTool® SolutionCommercial



그 밖에… (Other Tools)

NameInterfacePlatformManufacturerLicence
HighlighterGUIWindowsMandiantFreeware
BinTextGUIWindowsMcAfeeFreeware
DCodeGUIWindowsDigital DetectiveFreeware
TimeLordGUIWindowsHarry ParsonageFreeware
ArgosDFASGUIWindowsDUZONCommercial



포렌식 도구 사이트 (dForensics Tool Sites)

Site
MiTeC
TZWorks
Software for Computer Forensics
Woanware
NirSoft
CFTT Catalog
mft2csv
Open Source Digital Foresncis
RCE Tool Libary
Sysinternals


출처 : http://forensic-proof.com/tools

블로그의 정보

study

Gerberaa

활동하기