- Windows forensics tools help forensic professionals obtain and transfer data.Warzone image by FotoWorx from Fotolia.com
Windows forensic tools are provided to local, state and federal governmental agencies so they may safely and securely collect and transfer crime scene information. While anyone may be able to download most of these tools for free, some tools will require users to contact Microsoft to set up a government account. - The Computer Online Forensic Evidence Extractor, or COFEE, tool was created for law enforcement officials to capture and collect live crime scene evidence that could be downloaded to their computers later. The tool is free to use for first responders and law enforcement personnel anywhere around the world, and Microsoft offers free training on this tool to any interested party. The tool is fully encrypted, reducing the chance that information will be hacked or lost.
- This tool is compatible with the following Windows operating systems: 98, 2000, 2003, Server 2008, NT, Me and Vista. This tool is Java-based program that can convert nearly any type of disk or disk image into a VMware virtual machine. WMware is a company that creates a virtual framework that can host operating systems like Linux and Windows. With the Live View tool, forensic professionals can basically view a virtual copy of an image or disk without ever changing the original image or disk. Changes are made to the image or disk in a separate file, and users can add these changes to the source file they choose.
- The Forensic Acquisition Utilities are a set of tools that allow users to sterilize media so it can be accurately duplicated at a later time. Other features include the ability to find the location of logical volume information--a way to assign space on a mass storage device--and it can also gather information from a workstation or server that is running. The tool also ensures that data is safe and secure, and it reduces the instances of damaging changes to the main drive. This tool must be used in conjunction with a software or hardware write blocker, which allows users to collect information off of the main drive without damaging the drive or files on the drive.
- TULP2G allows users to find and then download information that is stored on different types of digital devices, including cell phones and subscriber identity module, or SIM, cards, which is most often used on mobile devices and stores information about a user, data and media.
previous post
next post