TUCOFS - The Ultimate Collection of Forensic Software

A Complete Resource for Cyber Law Enforcement Technologies



Windows XP

Investigative Tools


CryptoSystem Personal
Submit Date: 7/18/2005 10:45:59 AM
License Info:
Price:
Short Description: CryptoSystem Personal is the tool to help you protect your data from unauthorized viewing
Web Link: http://www.sauritus.com/files/csp12.zip
Home Page: http://www.sauritus.com
Rating:
Submitted By:
Information: CryptoSystem Personal is the tool to help you protect your data from unauthorized viewing. It combines easy-to-use interface and seamless Windows integration with the power of Advanced Encryption Standard, which has been adopted by NIST as a Federal Information Processing Standard and is one of the strongest encryption methods available. CryptoSystem Personal allows you: Encrypt single files or combine files and folders into a protected CryptoSystem Archive or CSAR. Create standalone self-decrypting executables Encrypt and decrypt your data without leaving Explorer or drag and drop files from Explorer to CryptoSystem Archive Manager and vice versa. Physically delete confidential data from disk when it is no longer needed without any means of recovering it using special software

Encase 3.0
Submit Date: 12/18/2002 2:16:35 PM
License Info: Commercial
Price: See Website
Short Description: A complete computer forensic solution
Web Link: http://www.guidancesoftware.com/products/software/encaseforensic.shtm
Home Page: http://www.guidancesoftware.com/
Rating:
Submitted By: TUCOFS Referral Service
Information: Award winning and validated by the courts, EnCase allows law enforcement and IT professionals to conduct a powerful, yet completely non-invasive computer forensic investigation. EnCase features a intuitive GUI that enables examiners to easily manage large volumes of computer evidence and view all relevant files, including "deleted" files, file slack and unallocated space. The solution effectively automates core investigative procedures, replacing archaic, time-consuming and cost-prohibitive processes and tools.

Encase 4.0
Submit Date: 12/18/2002 2:18:24 PM
License Info: Commercial
Price: See Website
Short Description: A complete computer forensic solution
Web Link: http://www.guidancesoftware.com/products/software/encaseforensic.shtm
Home Page: http://www.guidancesoftware.com/
Rating:
Submitted By: TUCOFS Referral Service
Information: Now with PST, NTFS file compression, Unix file, and RAID support! Award winning and validated by the courts, EnCase allows law enforcement and IT professionals to conduct a powerful, yet completely non-invasive computer forensic investigation. EnCase features a intuitive GUI that enables examiners to easily manage large volumes of computer evidence and view all relevant files, including "deleted" files, file slack and unallocated space. The solution effectively automates core investigative procedures, replacing archaic, time-consuming and cost-prohibitive processes and tools.

Gargoyle 2.1
Submit Date: 4/15/2005 12:02:13 PM
License Info:
Price:
Short Description: Super Charging Digital Investigations
Web Link: http://www.wetstonetech.com/catalog/item/1104418/620819.htm
Home Page: http://www.wetstonetech.com
Rating:
Submitted By: webmaster
Information: Uncover a Hidden Digital Arsenal. Maximize your time. Streamline your Investigation. Identify nefarious intent. Determine Modus Operandi. Identify Incriminating evidence. Audit User Bahavior. Enforce Corporate Policy.

Inquire
Submit Date: 4/15/2001 11:18:59 AM
License Info: Freeware
Price: n/a
Short Description: Returns ESN for SCSI hard drives
Web Link: http://www.sandersonforensics.co.uk/html/free_utilities.html
Home Page: http://www.sandersonforensics.co.uk
Rating:
Submitted By: Paul Sanderson
Information: Windows Application, which lists all SCSI hard drives accessible through the ASPI interface and their Electronic Serial Numbers

SBRecover
Submit Date: 4/17/2001 10:29:03 AM
License Info: Commercial
Price: See Website
Short Description: A utility to recover data from damaged SafeBack image files.
Web Link: http://www.sandersonforensics.co.uk/html/sbrecover.html
Home Page: http://www.sandersonforensics.co.uk
Rating:
Submitted By: Paul Sanderson
Information: SBrecover works by scanning through a SafeBack image file on disk looking for areas where the checksum computes and extracting these areas to a new image file. The new file is a BIOS dump type image, i.e. there are no internal checksums and this image file must be processed with a utility other than SafeBack (Linux dd, or other utilities, could be used to re-lay the image).

StegAlyzerAS
Submit Date: 7/25/2005 11:26:45 AM
License Info: Single-user
Price:
Short Description: Steganography Analyzer Artifact Scanner
Web Link: http://www.sarc-wv.com/products.aspx
Home Page: http://www.backbonesecurity.com
Rating:
Submitted By: Webmaster
Information: Extend computer forensic examinations to include the search for artifacts and signatures of digital steganography applications. This product includes a license to SAFDB which can also be purchased separately.

StegAlyzerSS
Submit Date: 7/26/2005 3:24:36 PM
License Info: Single-user
Price:
Short Description: Steganography Analyzer Signature Scanner
Web Link: http://www.sarc-wv.com/products.aspx
Home Page: http://www.backbonesecurity.com
Rating:
Submitted By: Webmaster
Information: StegAlyzerSS detects 29 distinct signatures of steganography applications and also includes functions to identify file types that may be potential carrier files (i.e., may contain hidden information). Techniques and procedures available to extract information hidden with each of the 29 applications for which a signature exists. Contact the SARC for details and pricing.

Stego Suite 4.1
Submit Date: 4/15/2005 12:34:25 PM
License Info: See Website
Price: See Website
Short Description: Superb Accurate Detection of Steganography
Web Link: http://www.wetstonetech.com/catalog/item/1104418/619451.htm
Home Page: http://www.wetstonetech.com/f/Stego_Training_Syllabus.pdf
Rating:
Submitted By: Webmaster
Information: Steganography Investigator Training Course Fee: $1795 Includes copies of Stego Suite„· and Gargoyle Investigator„· Standard Edition) Please Call for Law Enforcement, Education and Bundled Training Discounts! Upon completion of this intense two-day course, Investigators will have a complete understanding of the threat posed by the use of steganographic technologies in the current digital environment. Threats posed by criminals exploiting children, terrorists and crime organizations creating covert communication channels, and disgruntled company insiders are some of the topics that will be covered. Students also learn how to conduct a complete steganography investigation from suspicion to detection, analysis, cracking, and finally to recovery of the hidden information. The course includes 6 hours of lecture, 6 hours of practical lab exercises and investigation, and a 2 hour written and practical exam. Students are provided their own laptop with all tools and laboratory exercises installed for the lecture and hands-on portions of the labs. In addition, all students receive complimentary fully licensed copies of WetStone¡¦s Stego Suite and Gargoyle Investigator Standard Edition software products, (including 1 year of software maintenance & updates), the steganography embedding tools used during the class, and a reference CD containing the training materials and lab exercises. All participants are eligible to receive 1.6 CEU credits and a course completion certificate. Those sitting for, and passing WetStone¡¦s written and practical exam, receive a ¡¥Certified Steganography Examiner¡¦ certificate. For WetStone¡¦s training schedule or to register for an upcoming training, please visit us at www.wetstonetech.com.

tcpTrace
Submit Date: 9/25/2001 4:26:11 PM
License Info: see website
Price: see website
Short Description: TCP tunnel between a client and a server
Web Link: http://www.pocketsoap.com/tcptrace/
Home Page: http://www.pocketsoap.com/tcptrace/
Rating:
Submitted By: CERI Labs
Information: CERI Labs: Thumbs Up! Basically you use it as a tunnel between your client & server. Start tcptrace.exe and up comes a dialog box asking for local port, destination server, and destination port(Ignore the logging options for now) Fill these in, click Ok, and that it! For example, say you have a HTTP server at port 80. Configure the tunnel client so that it listens at port 8080. Then configure the tunnel client to forward all traffic to the server at port 80. Now any web client connecting to the host running the tunnel client system will forward all the traffic from localport:8080 to the remote server (and vica versa), dumping the contents in the process.

WetStone Technologies, Inc
Submit Date: 7/15/2005 6:17:05 PM
License Info: See Website
Price: See Website for Pricing
Short Description: Intelligent Solutions for Digital Investigations
Web Link: http://www.wetstonetech.com/catalog/item/1104418/2347979.htm
Home Page: http://www.wetstonetech.com/f/LiveWire_Training_Syllabus.pdf
Rating:
Submitted By: Webmaster
Information: LiveWire Investigator Training Course Fee: $8995 (Includes copies of LiveWire Investigator™, LiveDiscover and Gargoyle Investigator Enterprise Edition) Please Call for Law Enforcement, Education and Bundled Training Discounts! Live digital investigation of a suspect system is the next generation technique for Forensic Examiners, Compliance Auditors, Private Investigators, federal, state and local Law Enforcement Investigators, prosecutors and corporate IT security personnel. LiveWire Investigator and it’s associated suite of products, a commercially available offering borne of DoD research and expert engineering and forensic techniques, provides extensive and comprehensive information regarding information contained on ‘live-running’ networks, computers, servers and network enabled devices. Throughout this intensive LiveWire Training Course, students learn the ‘do’s and don’t’s’ of live evidence collection and preservation, are taught to understand legal precautions and concerns, and also become skilled at the use of those tools necessary to conduct a digital investigation of this magnitude. Students are given simulated situations where they learn how to analyze and tailor the LiveWire Investigator information and reports to determine evidence, malicious software or cyber weapon use activity, or potential insider attack scenarios. The course includes 8 hours of lecture, 8 hours of practical lab exercises and investigation. Students are provided their own laptop with all tools and laboratory exercises installed for the lecture and hands-on portions of the labs. In addition, all students receive complimentary fully licensed copies of LiveWire Investigator, LiveDiscover, Gargoyle Investigator, and a certificate of attendance. Those sitting for, and passing WetStone’s written and practical exam, receive a ‘Certified Live Examiner certificate. For WetStone’s training schedule or to register for an upcoming training, please visit us at www.wetstonetech.com.

WINGREP
Submit Date: 1/3/2002 3:36:21 PM
License Info: see website
Price: see website
Short Description: Searching for strings quickly and painlessly
Web Link: http://www.hurricanesoft.com/prod01.htm
Home Page: http://www.hurricanesoft.com/
Rating:
Submitted By: TUCOFS Referral Service
Information: WinGREP is a utility intended to make searching for strings quick and painless. Regular Expressions are simple and fast to create with no characters to memorize or confuse. Search results can be viewed in your IDE, in the Hurricane Editor, or any other editor you choose. Hierarchical lists and Quick-Preview makes WinGREP fast and easy to use.


Note - The products referenced at this site are provided by parties other than TUCOFS (or its affiliates). TUCOFS makes no representations regarding either the products or any information about the products. Any questions, complaints, or claims regarding the products must be directed to the appropriate author, manufacturer or vendor. Click here to view the usage terms and conditions. By accessing and using this website, you are agreeing to be bound by these terms.


TUCOFS - The Ultimate Collection of Forensic Software. Copyright (c) 1999 - 2010. All rights reserved. Reproduction in whole  or in part in any form or medium without express written permission of  Cyber Enforcement Resources Incorporated is strictly prohibited.  Terms and conditions.