Digital Forensics

Cyber forensics is a process of extracting data as proof for a crime (that involves electronic devices) while following proper investigation rules to nab the culprit by presenting the evidence to the court. Cyber forensics is also known as computer forensics. The main aim of cyber forensics is to maintain the thread of evidence and documentation to find out who did the crime digitally.

Cyber forensics can do the following:

  • It can recover deleted files, chat logs, emails, etc
  • It can also get deleted SMS, Phone calls.
  • It can get recorded audio of phone conversations.
  • It can determine which user used which system and for how much time.
  • It can identify which user ran which program.

This involves the recovery and analysis of data stored on computers and other digital devices, such as hard drives, flash drives, and memory cards. The goal is to uncover hidden or deleted files, recover lost or damaged data, and preserve evidence for use in criminal or civil investigations.

Tools:

NamePlatformLicenseVersionDescription
AutopsyWindowsmacOSLinuxGPL4.20A digital forensics platform and GUI to The Sleuth Kit
Cellebrite InspectorWindows/macOSproprietary10.4Analyze computer data volumes and memory from Windows-based and Mac computers to shed light on user actions and surface leads.
COFEEWindowsproprietaryn/aA suite of tools for Windows developed by Microsoft
Digital Forensics FrameworkUnix-like/WindowsGPL1.3Framework and user interfaces dedicated to digital forensics
Elcomsoft Premium Forensic BundleWindows, macOSproprietary1435Set of tools for encrypted systems & data decryption and password recovery
E3: Universal SoftwareWindowsproprietary3.1E3:Universal by Paraben Corporation is an end-to-end DFIR solution that can work through ALL types of digital data: computers, email, internet data, smartphones, & IoT devices.
EnCaseWindowsproprietary21.1 CEDigital forensics suite created by Guidance Software
FTKWindowsproprietary7.6Multi-purpose tool, FTK is a court-cited digital investigations platform built for speed, stability and ease of use.
IsoBusterWindowsproprietary5.1Essential light weight tool to inspect any type data carrier, supporting a wide range of file systems, with advanced export functionality.
LLIMAGERmacOSproprietary3.7macOS forensic imager.
Magnet AXIOMWindowsproprietary6.XMagnet AXIOM can recover and analyze digital evidence from the most sources, including Windows and Mac devices, Linux systems, and Chromebooks, all in one case file.
Netherlands Forensic Institute / Xiraf[4] / HANSKEN[5]n/aproprietaryn/aComputer-forensic online service.
NTFSToolWindowsMIT License1.7Complete forensics tool for NTFS volumes (Imaging, parsing, artefact extraction with support of Bitlocker and Encrypted File System (EFS).
Open Computer Forensics ArchitectureLinuxLGPL/GPL2.3.0Computer forensics framework for CF-Lab environment
OSForensics[6][7]Windowsproprietary8Multi-purpose forensic tool
Oxygen Forensic® DetectiveWindowsmacOsLinuxproprietary14.3Oxygen Forensic® Detective can also find and extract a vast range of artifacts, system files as well as credentials from Windows, macOS, and Linux machines.
PTK ForensicsLAMPproprietary2.0GUI for The Sleuth Kit
SANS Investigative Forensics Toolkit – SIFTUbuntu2.1Multi-purpose forensic operating system
SPEKTOR Forensic IntelligenceUnix-likeproprietary6.xEasy to use, comprehensive forensic tool used worldwide by LE/Military/Agencies/Corporates – includes rapid imaging and fully automated analysis.
The Coroner’s ToolkitUnix-likeIBM Public License1.19A suite of programs for Unix analysis
The Sleuth KitUnix-like/WindowsIPLCPLGPL4.12.0A library of tools for both Unix and Windows
Windows To Gon/aproprietaryn/aBootable operating system

Hardware

Tableau Forensic Imager
Logicube Forensic Falcon NEO
CRU WiebeTech Forensic Field Kit
Deepspar Disk Imager
Atola Insight Forensic
Logicube Forensic Duplicators
Magnet Forensics IEF
Voom HardCopy 3P