DIGITAL FORENSIC TOOLS
DIGITAL FORENSIC TOOLS
TOOOLS
EnCase
• Retrieves evidence from handheld devices
• Forensic, eDiscovery, and security investigation
• Conducts top to bottom records investigation
• Automatic data collection and recording to Android device
• Contains different viewing perspectives of information
• Ability to acquire data from other devices while
maintaining integrity of all evidences
• User friendly; built-in reporting functionalities
• Built in encryption support, Very expensive; compatibility
with other forensic devices, Processing time is lengthy
WinHex
• Examine any level of digital evidence
• Verify results of other tools
• Create forensic image of stored data
• Interprets correct date/time of system files
• Calculates MD5 hash value
• Recovers deleted files
• Effective on NTFS/FAT file system/EXT2 & EXT3 Linux
• Useful in learning about file partition & file data structure
• Enables low-level data analysis, Inability to make logical
search-only physical search, Displays improper error
messages during copying
FTK (Forensic Tool Kit)
• Complete hard drive examination
• Finds deleted emails
• Scans the disk for content strings
• Incorporates independent disk imaging program
• Contains different viewing perspectives of information
• Computes MD5 hash values; affirms document integrity
• Simple user interface; Advance search/password access
• Supports EFS encryption; Significant bookmarking
ability, No multi-tasking capabilities, No progress bar to
estimate time remaining
X-Ways Forensics
• Commercial computer forensic asset
• New file container format widely compatible
• Incorporates 22 languages
• Extensive list of functionalities
• Access to disk, RAIDS over 2TB
• Analyze remote computers
• Customizable evidence processing options
• Portable; continually checks for updates, Complex user
interface, No Bit locker support; dongle-based software
• Oxygen Forensic Suite
• Commercial computer forensic asset
• New file container format widely compatible
• Incorporates 22 languages
• Extensive list of functionalities
• Access to disk, RAIDS over 2TB
• Analyze remote computers
• Customizable evidence processing options
• Portable; continually checks for updates, Complex user
interface, No Bit locker support; dongle-based software