取证的简单小工具

[1]Nigilant32: a Windows GUI Incident Response Tool (currently beta)
http://www.agilerm.net/publications_4.html

[2]Paul Bakker released a new version of his searchtools patch for sleuthkit 2.04
http://brainspark.nl/tools#searchtools_patch

Protected Storage Explorer是一款轻便小巧的取证工具,查看各被保存的数据, 包括Microsoft Outlook密码, , MSN, 电话号码, 信用卡号码, 网电子邮件, 搜索引擎询问, 网页用户名和密码,和要求认证站点的被贮藏的注册证件(包括FTP 站点。) 绿色软件(50KB),虽然功能不是很强大。

[3]Protected Storage Explorer
http://www.forensicideas.com/tools.html

[4]Having come across this website i thought i'd share a website offering
Forensic Acquisition Utilities :
http://users.erols.com/gmgarner/forensics/

1.dd.exe: A modified version of the popular GNU dd utility program
2.md5lib.dll: A modified version of Ulrich Drepper's MD5 checksum implementation in Windows DLL format.
3.md5sum.exe: A modified version of Ulrich Drepper's MD5sum utility.
4.Volume_dump.exe: An original utility to dump volume information
5.wipe.exe: An original utility to sterilize media prior to forensic duplication.
6.zlibU.dll: A modified version of Jean-loup Gailly and Mark
Adler's zlib library based on zlib-1.1.4.
7.nc.exe: A modified version of the netcat utility by Hobbit.
8.getopt.dll: An implementation of the POSIX getopt function in a Windows DLL format.

Please excuse the post if this has already been posted / shared.
Original link was obtained from here :
http://www.ntsecurity.nu/onmymind/2006/2006-06-01.html

相关详细看连接就明了

工具都很简单,使用也方便,虽然功能不是很强大! 
  • 0
    点赞
  • 2
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值