<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://www.forensicswiki.org/w/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://www.forensicswiki.org/w/api.php?action=feedcontributions&amp;user=Cmihai&amp;feedformat=atom</id>
		<title>Forensics Wiki - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="http://www.forensicswiki.org/w/api.php?action=feedcontributions&amp;user=Cmihai&amp;feedformat=atom"/>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Special:Contributions/Cmihai"/>
		<updated>2013-05-23T17:15:21Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.20.3</generator>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User_talk:Simsong</id>
		<title>User talk:Simsong</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User_talk:Simsong"/>
				<updated>2008-01-08T08:12:33Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Bot issues&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Categories ==&lt;br /&gt;
&lt;br /&gt;
As a Wikipedia user, I have noticed that none of your articles have categories. Did you know that categories exist in MediaWiki? If yes, is there a reason? I would like to start work on it. [[Special:Categories]], http://meta.wikimedia.org/wiki/Help:Category --[[User:Midnightcomm|Midnightcomm]] 01:09, 23 April 2006 (EDT)&lt;br /&gt;
&lt;br /&gt;
:Woah, I don't know much about Categories. How would I add them? What are they for?&lt;br /&gt;
&lt;br /&gt;
::[http://en.wikipedia.org/wiki/Wikipedia:Categorization Categories] are used to help organize pages. I also see that there are no help articles, in the absance if them, I will be using the Wikipedia [http://en.wikipedia.org/wiki/Wikipedia:Manual_of_Style style guides]. --[[User:Midnightcomm|Midnightcomm]] 01:09, 23 April 2006 (EDT) &lt;br /&gt;
::&amp;lt;nowiki&amp;gt;[[Category:File Systems]]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
:::Sounds good to me. We welcome your contributions.&lt;br /&gt;
&lt;br /&gt;
:::Yay! I'm all for categories. I've started adding some (tools, licenses, OSes, ...), feel free to add more and categorize the articles. --[[User:Uwe Hermann|Uwe Hermann]] 15:03, 23 April 2006 (EDT)&lt;br /&gt;
&lt;br /&gt;
::::How do you add categories? --SImson&lt;br /&gt;
&lt;br /&gt;
::::: Usually you just add &amp;lt;nowiki&amp;gt;[[Category:Foobar]]&amp;lt;/nowiki&amp;gt; somewhere at the bottom of the page, more info [http://meta.wikimedia.org/wiki/Help:Category here]. For the tools, I have incorporated the category into the Infobox, see [[dd]] for an example. It looks a bit stupid in the wiki source, but keeps the wiki category and the &amp;quot;Genre:&amp;quot; classification in one place, which is important IMHO. Btw, you can sign your &amp;quot;posts&amp;quot; with &amp;quot;&amp;lt;nowiki&amp;gt;--~~~~&amp;lt;/nowiki&amp;gt;&amp;quot; which will expand to username and date, just like on this post. --[[User:Uwe Hermann|Uwe Hermann]] 21:45, 2 May 2006 (EDT)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Hi. We have some spambots advertising &amp;quot;Chinese antique furniture&amp;quot; on the wiki. Could also be real people, since they've gotten over the captcha, but I doubt they understand plain English. How do you generally deal with such people here? Or better said, is there someone we're supposed to notify when something like this happens like flag the article as spam or something?&lt;br /&gt;
&lt;br /&gt;
Well, I guess you'll see it when you log in anyway, just thought I'd give you a heads up before it gets indexed and all that.&lt;br /&gt;
--[[User:Cmihai|cmihai]] 00:12, 8 January 2008 (PST)&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Tools:Data_Recovery</id>
		<title>Tools:Data Recovery</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Tools:Data_Recovery"/>
				<updated>2008-01-07T22:19:22Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Added Magic Rescue File Carver and MBR extraction info.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Partition Recovery =&lt;br /&gt;
&lt;br /&gt;
*[http://www.ptdd.com/index.htm Partition Table Doctor]&lt;br /&gt;
: Recover deleted or lost Partitions (FAT16/FAT32/NTFS/NTFS5/EXT2/EXT3/SWAP).&lt;br /&gt;
&lt;br /&gt;
*[http://www.diskinternals.com/ntfs-recovery/ NTFS Recovery]&lt;br /&gt;
: DiskInternals NTFS Recovery is a fully automatic utility that recovers data from damaged or formatted disks.&lt;br /&gt;
&lt;br /&gt;
*[http://www.stud.uni-hannover.de/user/76201/gpart/ gpart]&lt;br /&gt;
: Gpart is a tool which tries to guess the primary partition table of a PC-type hard disk in case the primary partition table in sector 0 is damaged, incorrect or deleted.&lt;br /&gt;
&lt;br /&gt;
*[http://www.cgsecurity.org/wiki/TestDisk Testdisk]&lt;br /&gt;
: TestDisk is OpenSource software and is licensed under the GNU Public License (GPL). &lt;br /&gt;
&lt;br /&gt;
== See Also ==&lt;br /&gt;
&lt;br /&gt;
* [http://support.microsoft.com/?kbid=166997 Using Norton Disk Edit to Backup Your Master Boot Record]&lt;br /&gt;
&lt;br /&gt;
== Notes ==&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;fdisk /mbr&amp;quot; restores the boot code in the [[Master boot record]], but not the partition itself. On newer versions of Windows you should use fixmbr, bootrec or mbrfix. You can also extract a copy of the specific standard MBR code from tools like bootrec.exe and diskpart.exe in Windows (from various offsets) and copy it to disk with dd (Use bs=446 count=1). For Windows XP SP2 c:\%WINDIR%\System32\diskpart.exe the MBR code is found between offset 1b818h and 1ba17h.&lt;br /&gt;
&lt;br /&gt;
= Data Recovery =&lt;br /&gt;
&lt;br /&gt;
*[http://www.toolsthatwork.com/bringback.htm BringBack] &lt;br /&gt;
: BringBack offers easy to use, inexpensive, and highly successful data recovery for Windows and Linux (ext2) operating systems and digital images stored on memory cards, etc.&lt;br /&gt;
&lt;br /&gt;
*[http://www.runtime.org/raid.htm RAID Reconstructor]&lt;br /&gt;
: Runtime Software's RAID Reconstructor will reconstruct RAID Level 0 (Striping) and RAID Level 5 drives.&lt;br /&gt;
&lt;br /&gt;
*[http://www.salvationdata.com Salvation Data]&lt;br /&gt;
: Claims to have a program that can read the &amp;quot;bad blocks&amp;quot; of Maxtor drives with proprietary commands.&lt;br /&gt;
&lt;br /&gt;
* [http://www.e-rol.com/en/ e-ROL]&lt;br /&gt;
: Erol allows you to recover through the internet files erased by mistake. Recover your files online for free.&lt;br /&gt;
&lt;br /&gt;
* [http://www.recuva.com/ Recuva]&lt;br /&gt;
: Recuva is a freeware Windows tool that will recover accidentally deleted files.&lt;br /&gt;
&lt;br /&gt;
* [http://www.snapfiles.com/get/restoration.html Restoration]&lt;br /&gt;
: Restoration is a freeware Windows software that will allow you to recover deleted files&lt;br /&gt;
&lt;br /&gt;
* [http://www.undelete-plus.com/ Undelete Plus]&lt;br /&gt;
: Undelete Plus is a free deleted file recovery tool that works for all versions of Windows (95-Vista), FAT12/16/32, NTFS and NTFS5 filesystems and can perform recovery on various solid state devices.&lt;br /&gt;
&lt;br /&gt;
* [http://www.data-recovery-software.net/ R-Studio]&lt;br /&gt;
: R-Studio is a data recovery software suite that can recover files from FAT(12-32), NTFS, NTFS 5, HFS/HFS+, FFS, UFS/UFS2 (*BSD, Solaris), Ext2/Ext3 (Linux) and so on.&lt;br /&gt;
&lt;br /&gt;
=Carving=&lt;br /&gt;
*[http://www.datalifter.com/products.htm DataLifter® - File Extractor Pro]&lt;br /&gt;
: Data carving runs on multiple threads to make use of modern processors &lt;br /&gt;
&lt;br /&gt;
*[http://foremost.sourceforge.net/ Foremost]&lt;br /&gt;
: Foremost is a console program to recover files based on their headers, footers, and internal data structures. &lt;br /&gt;
&lt;br /&gt;
*[http://www.digitalforensicssolutions.com/Scalpel/ Scalpel]&lt;br /&gt;
: Scalpel is a fast file carver that reads a database of header and footer definitions and extracts matching files from a set of image files or raw device files. Scalpel is filesystem-independent and will carve files from FATx, NTFS, ext2/3, or raw partitions.&lt;br /&gt;
&lt;br /&gt;
*[[EnCase]]&lt;br /&gt;
: EnCase comes with some eScripts that will do carving.&lt;br /&gt;
&lt;br /&gt;
*[http://ocfa.sourceforge.net/libcarvpath/ CarvFs]&lt;br /&gt;
: A virtual filesystem (fuse) implementation that can provide carving tools with the posibility to do recursive multi tool zero-storage carving (also called in-place carving). Patches and scripts for scalpel and foremost are provided. Works on raw and encase images.&lt;br /&gt;
&lt;br /&gt;
*[http://ocfa.sourceforge.net/libcarvpath/ LibCarvPath]&lt;br /&gt;
: A shared library that allows carving tools to use zero-storage carving on carvfs virtual files.&lt;br /&gt;
&lt;br /&gt;
*[http://www.cgsecurity.org/wiki/PhotoRec PhotoRec]&lt;br /&gt;
: PhotoRec is file data recovery software designed to recover lost files including video, documents and archives from Hard Disks and CDRom and lost pictures (thus, its 'Photo Recovery' name) from digital camera memory.&lt;br /&gt;
&lt;br /&gt;
*[http://www.datarescue.com/photorescue/ PhotoRescue]&lt;br /&gt;
: Datarescue PhotoRescue Advanced is picture and photo data recovery solution made by the creators of IDA Pro. PhotoRescue will undelete, unerase and recover pictures and files lost on corrupted, erased or damaged compact flash (CF) cards, SD Cards, Memory Sticks, SmartMedia and XD cards.&lt;br /&gt;
&lt;br /&gt;
* [https://www.uitwisselplatform.nl/projects/revit RevIt]&lt;br /&gt;
: RevIt (Revive It) is an experimental carving tool, initially developed for the DFRWS 2006 carving challenge. It uses 'file structure based carving'. Note that RevIt currently is a work in progress.&lt;br /&gt;
&lt;br /&gt;
* [http://jbj.rapanden.dk/magicrescue/ Magic Rescue]&lt;br /&gt;
: Magic Rescue is a file carving tool that uses &amp;quot;magic bytes&amp;quot; in a file contents to recover data.&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Tools:Network_Forensics</id>
		<title>Tools:Network Forensics</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Tools:Network_Forensics"/>
				<updated>2007-12-21T14:30:17Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: snoop on Solaris&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Network Forensics Packages and Appliances=&lt;br /&gt;
; [[Burst]]&lt;br /&gt;
: http://www.burstmedia.com/release/advertisers/geo_faq.htm&lt;br /&gt;
: Expensive IP geo-location service.&lt;br /&gt;
&lt;br /&gt;
; [[chkrootkit]]&lt;br /&gt;
: http://www.chkrootkit.org&lt;br /&gt;
&lt;br /&gt;
; [[cryptcat]]&lt;br /&gt;
: http://farm9.org/Cryptcat/&lt;br /&gt;
&lt;br /&gt;
; [[Enterasys Dragon]]&lt;br /&gt;
: http://www.enterasys.com/products/advanced-security-apps/index.aspx Instrusion Detection System includes session reconstruction.&lt;br /&gt;
&lt;br /&gt;
; [[MaxMind]]&lt;br /&gt;
: http://www.maxmind.com&lt;br /&gt;
: [[IP geolocation]] services and data provider for off-line geotagging.  Free GeoLite country database. Programmable APIs.&lt;br /&gt;
&lt;br /&gt;
; [[netcat]]&lt;br /&gt;
: http://netcat.sourceforge.net/&lt;br /&gt;
&lt;br /&gt;
; [[netflow]]/[[flowtools]]&lt;br /&gt;
: http://www.cisco.com/warp/public/732/Tech/nmp/netflow/index.shtml&lt;br /&gt;
: http://www.splintered.net/sw/flow-tools/&lt;br /&gt;
: http://silktools.sourceforge.net/&lt;br /&gt;
: http://www.vmware.com/vmtn/appliances/directory/293 Netflow Appliance (vmWare)&lt;br /&gt;
&lt;br /&gt;
; NetIntercept &lt;br /&gt;
: http://www.sandstorm.net/products/netintercept&lt;br /&gt;
: NetIntercept captures whole packets and reassembles up to 999,999 TCP connections at once, reconstructing files that were sent over your network and creating a database of its findings. It recognizes over 100 types of network protocols and file types, including web traffic, multimedia, email, and IM.&lt;br /&gt;
; [[rkhunter]]&lt;br /&gt;
: http://rkhunter.sourceforge.net/&lt;br /&gt;
&lt;br /&gt;
; [[ngrep]]&lt;br /&gt;
: http://ngrep.sourceforge.net/&lt;br /&gt;
&lt;br /&gt;
; [[nslookup]]&lt;br /&gt;
: http://en.wikipedia.org/wiki/Nslookup Name Server Lookup command line tool used to find IP address from domain name&lt;br /&gt;
&lt;br /&gt;
; [[Sguil]]&lt;br /&gt;
: http://sguil.sourceforge.net/&lt;br /&gt;
&lt;br /&gt;
; [[Snort]]&lt;br /&gt;
: http://www.snort.org/&lt;br /&gt;
&lt;br /&gt;
; [[ssldump]]&lt;br /&gt;
: http://ssldump.sourceforge.net/&lt;br /&gt;
&lt;br /&gt;
; [[Tcpdump]] &lt;br /&gt;
: http://www.tcpdump.org&lt;br /&gt;
&lt;br /&gt;
; [[tcpextract]]&lt;br /&gt;
: http://tcpxtract.sourceforge.net/&lt;br /&gt;
&lt;br /&gt;
; [[tcpflow]]&lt;br /&gt;
: http://www.circlemud.org/~jelson/software/tcpflow/&lt;br /&gt;
&lt;br /&gt;
; [[truewitness]]&lt;br /&gt;
: http://www.nature-soft.com/forensic.html&lt;br /&gt;
: Linux/open-source. Based in India.&lt;br /&gt;
&lt;br /&gt;
; [[etherpeek]]&lt;br /&gt;
: http://www.wildpackets.com/products/etherpeek/overview&lt;br /&gt;
&lt;br /&gt;
; [[Whois]]&lt;br /&gt;
: http://en.wikipedia.org/wiki/WHOIS Web service and command line tool to look up registry information for internet domain.&lt;br /&gt;
: http://www.arin.net/registration/agreements/bulkwhois.pdf Bulk WHOIS data request from ARIN&lt;br /&gt;
&lt;br /&gt;
; [[IP Regional Registries]]&lt;br /&gt;
: http://www.arin.net/community/rirs.html &lt;br /&gt;
: http://www.arin.net/index.shtml American Registry for Internet Numbers (ARIN)&lt;br /&gt;
: http://www.afrinic.net/ African Network Information Center (AfriNIC)&lt;br /&gt;
: http://www.apnic.net/ Asia Pacific Network Information Centre (APNIC)&lt;br /&gt;
: http://www.lacnic.net/en/ Latin American and Caribbean IP Address Regional Registry (LACNIC)&lt;br /&gt;
: http://www.ripe.net/ RIPE Network Coordination Centre (RIPE NCC)&lt;br /&gt;
&lt;br /&gt;
; [[Wireshark/Ethereal]]&lt;br /&gt;
: http://www.wireshark.org/&lt;br /&gt;
: Open Source protocol analyzer previously known as ethereal.&lt;br /&gt;
&lt;br /&gt;
=Command-line tools=&lt;br /&gt;
&lt;br /&gt;
[[arp]] - view the contents of your ARP cache&lt;br /&gt;
&lt;br /&gt;
[[ifconfig]] - view your mac and IP address&lt;br /&gt;
&lt;br /&gt;
[[ping]] - send packets to probe remote machines&lt;br /&gt;
&lt;br /&gt;
[[tcpdump]] - capture packets&lt;br /&gt;
&lt;br /&gt;
[[snoop]] - captures packets from the network and displays their contents - [[Solaris]]&lt;br /&gt;
&lt;br /&gt;
[[nemesis]] - create arbitrary packets&lt;br /&gt;
&lt;br /&gt;
[[tcpreplay]] - replay captured packets&lt;br /&gt;
&lt;br /&gt;
[[traceroute]] - view a network path&lt;br /&gt;
&lt;br /&gt;
[[gnetcast]] - GNU rewrite of netcat&lt;br /&gt;
&lt;br /&gt;
[[packit]] - Packet generator&lt;br /&gt;
&lt;br /&gt;
[[nmap]]&lt;br /&gt;
&lt;br /&gt;
==ARP and Ethernet MAC Tools==&lt;br /&gt;
&lt;br /&gt;
[[arping]] - transmit ARP traffic&lt;br /&gt;
&lt;br /&gt;
[[arpdig]] - probe LAN for MAC addresses&lt;br /&gt;
&lt;br /&gt;
[[arpwatch]] - Watch ARP changes&lt;br /&gt;
&lt;br /&gt;
[[arp-sk]] Perform denial of service attacks&lt;br /&gt;
&lt;br /&gt;
[[macof]] CAM table attacks&lt;br /&gt;
&lt;br /&gt;
[[ettercap]] Performs various low-level Ethernet network attacks.&lt;br /&gt;
&lt;br /&gt;
==CISCO Discovery Protocol Tools==&lt;br /&gt;
[[cdpd]] - Transmit and receive CDP announcements; provides forgery capabilities.&lt;br /&gt;
&lt;br /&gt;
==ICMP Layer Tests and Attacks==&lt;br /&gt;
[[icmp-reset]]&lt;br /&gt;
&lt;br /&gt;
[[icmp-quench]]&lt;br /&gt;
&lt;br /&gt;
[[icmp-mtu]]&lt;br /&gt;
&lt;br /&gt;
[[ish]] - ICMP shell (like SSH, but uses ICMP)&lt;br /&gt;
&lt;br /&gt;
[[isnprober]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==IP Layer Tests==&lt;br /&gt;
[[iperf]] - IP multicast test&lt;br /&gt;
&lt;br /&gt;
[[fragtest]]  IP fragment reassembly test&lt;br /&gt;
&lt;br /&gt;
==UDP Layer Tests==&lt;br /&gt;
&lt;br /&gt;
[[udpcast]] - Includes udp-receiver and udp-sender&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==TCP Layer==&lt;br /&gt;
&lt;br /&gt;
[[lft]] http://pwhois.org/lft - TCP tracing&lt;br /&gt;
&lt;br /&gt;
[[etrace]] http://www.bindshell.net/tools/etrace&lt;br /&gt;
&lt;br /&gt;
[[firewalk]] http://www.packetfactory.net&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Tools:File_Analysis</id>
		<title>Tools:File Analysis</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Tools:File_Analysis"/>
				<updated>2007-12-20T16:45:00Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: GnuWin32, SUA&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Image Analysis ==&lt;br /&gt;
; [[SurfRecon LE rapid image analysis tool]], by SurfRecon, Inc.&lt;br /&gt;
: http://www.surfrecon.com&lt;br /&gt;
&lt;br /&gt;
== Open Source Tools ==&lt;br /&gt;
&lt;br /&gt;
; [[file]]&lt;br /&gt;
: The file command determines the file type of a given file, depending on its contents and not on e.g. its extension or filename. In order to do that, it uses a magic configuration file that identifies filetypes.&lt;br /&gt;
&lt;br /&gt;
; [[ldd]]&lt;br /&gt;
: list  dynamic  dependencies  of  executable  files&lt;br /&gt;
&lt;br /&gt;
; [[truss]]&lt;br /&gt;
: Solaris tool used to trace the system/library calls (not user calls) and signals made/received by a new or existing process. It sends the output to stderr.&lt;br /&gt;
: http://docs.sun.com/app/docs/doc/819-2239/truss-1?l=en&amp;amp;a=view&amp;amp;q=truss&lt;br /&gt;
&lt;br /&gt;
; [[ltrace]]&lt;br /&gt;
: Library call tracer&lt;br /&gt;
: http://linux.die.net/man/1/ltrace&lt;br /&gt;
&lt;br /&gt;
; [[strace]]&lt;br /&gt;
: System Call Tracer&lt;br /&gt;
: http://sourceforge.net/projects/strace/&lt;br /&gt;
&lt;br /&gt;
; [[xtrace]]&lt;br /&gt;
: eXtended trace utility, similar to strace, ptrace, truss, but with extended functionality and unique features, such as dumping function calls (dynamically or statically linked), dumping call stack and more.&lt;br /&gt;
: http://sourceforge.net/projects/xtrace/&lt;br /&gt;
&lt;br /&gt;
; [[ktrace]]&lt;br /&gt;
: Enables kernel process tracing on OpenBSD.&lt;br /&gt;
: http://www.openbsd.org/cgi-bin/man.cgi?query=ktrace&amp;amp;apropos=0&amp;amp;sektion=0&amp;amp;manpath=OpenBSD+Current&amp;amp;arch=i386&amp;amp;format=html&lt;br /&gt;
&lt;br /&gt;
; [[Valgrind]]&lt;br /&gt;
: Executes a program under emulation, performing analysis according to one of the many plug-in modules as desired. You can write your own plug-in module as desired.&lt;br /&gt;
: http://valgrind.org/&lt;br /&gt;
&lt;br /&gt;
; [[DTrace]]&lt;br /&gt;
: Comprehensive dynamic tracing framework for Solaris (also ported to MacOS X - XRays and FreeBSD). DTrace provides a powerful infrastructure to permit investigation of the behavior of the operating system and user programs.&lt;br /&gt;
: http://www.sun.com/bigadmin/content/dtrace/&lt;br /&gt;
&lt;br /&gt;
; [[strings]]&lt;br /&gt;
: Strings will print the strings of printable characters in files. It allows choosing different charactersets (ASCII, UNICODE). It is a quick way to browse through files/partitions/... in order to look for words, filenames, keywords etc.&lt;br /&gt;
&lt;br /&gt;
; [[Galleta]]&lt;br /&gt;
: Parses cookie files.  http://www.foundstone.com/resources/proddesc/galleta.htm&lt;br /&gt;
&lt;br /&gt;
; The [[Open Computer Forensics Architecture]]&lt;br /&gt;
: http://ocfa.sourceforge.net/&lt;br /&gt;
&lt;br /&gt;
; [[Pasco]]&lt;br /&gt;
; Parses '''index.dat'' files. http://www.foundstone.com/resources/proddesc/pasco.htm&lt;br /&gt;
&lt;br /&gt;
; [[Rifiuti]]&lt;br /&gt;
; Examines the INFO2 file in the Recycle Bin     http://www.foundstone.com/resources/proddesc/rifiuti.htm&lt;br /&gt;
&lt;br /&gt;
; [[yim2text]]&lt;br /&gt;
; Extracts the 'encrypted' info in yahoo instant messenger log files. http://www.1vs0.com/tools.html&lt;br /&gt;
&lt;br /&gt;
; [[Hachoir]]&lt;br /&gt;
: determines the file type using file header/footer (hachoir-metadata --type), able to list strings in Unicode (hachoir-grep), etc. Support more than 60 file formats.&lt;br /&gt;
&lt;br /&gt;
; [[Cygwin]]&lt;br /&gt;
: http://www.cygwin.com/&lt;br /&gt;
: Linux like environment for Windows&lt;br /&gt;
&lt;br /&gt;
; [[UnxUtils]]&lt;br /&gt;
: http://unxutils.sourceforge.net/&lt;br /&gt;
: Common unix utilities compiled for a Windows environment.&lt;br /&gt;
&lt;br /&gt;
; [[GnuWin32]]&lt;br /&gt;
: http://gnuwin32.sourceforge.net/&lt;br /&gt;
: Common GNU utilities compiled for a Windows Environment.&lt;br /&gt;
&lt;br /&gt;
; [[SUA]]&lt;br /&gt;
: http://www.microsoft.com/windowsserver2003/R2/unixcomponents/webinstall.mspx&lt;br /&gt;
: Microsoft Subsystem for UNIX-based Applications.&lt;br /&gt;
&lt;br /&gt;
== File Sharing Analysis Tools ==&lt;br /&gt;
; [[P2PMarshal|P2P Marshal]]&lt;br /&gt;
: Tools to discover and analyze peer-to-peer files for Windows.&lt;br /&gt;
&lt;br /&gt;
== [[NDA]] and [[scoped distribution]] tools ==&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Tools:File_Analysis</id>
		<title>Tools:File Analysis</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Tools:File_Analysis"/>
				<updated>2007-12-20T16:33:32Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Added ldd, truss, strace, ltrace, ktrace, valgrind, xtrace, DTrace&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Image Analysis ==&lt;br /&gt;
; [[SurfRecon LE rapid image analysis tool]], by SurfRecon, Inc.&lt;br /&gt;
: http://www.surfrecon.com&lt;br /&gt;
&lt;br /&gt;
== Open Source Tools ==&lt;br /&gt;
&lt;br /&gt;
; [[file]]&lt;br /&gt;
: The file command determines the file type of a given file, depending on its contents and not on e.g. its extension or filename. In order to do that, it uses a magic configuration file that identifies filetypes.&lt;br /&gt;
&lt;br /&gt;
; [[ldd]]&lt;br /&gt;
: list  dynamic  dependencies  of  executable  files&lt;br /&gt;
&lt;br /&gt;
; [[truss]&lt;br /&gt;
: Solaris tool used to trace the system/library calls (not user calls) and signals made/received by a new or existing process. It sends the output to stderr.&lt;br /&gt;
: http://docs.sun.com/app/docs/doc/819-2239/truss-1?l=en&amp;amp;a=view&amp;amp;q=truss&lt;br /&gt;
&lt;br /&gt;
; [[ltrace]]&lt;br /&gt;
: Library call tracer&lt;br /&gt;
: http://linux.die.net/man/1/ltrace&lt;br /&gt;
&lt;br /&gt;
; [[strace]]&lt;br /&gt;
: System Call Tracer&lt;br /&gt;
: http://sourceforge.net/projects/strace/&lt;br /&gt;
&lt;br /&gt;
; [[xtrace]]&lt;br /&gt;
: eXtended trace utility, similar to strace, ptrace, truss, but with extended functionality and unique features, such as dumping function calls (dynamically or statically linked), dumping call stack and more.&lt;br /&gt;
: http://sourceforge.net/projects/xtrace/&lt;br /&gt;
&lt;br /&gt;
; [[ktrace]]&lt;br /&gt;
: Enables kernel process tracing on OpenBSD.&lt;br /&gt;
: http://www.openbsd.org/cgi-bin/man.cgi?query=ktrace&amp;amp;apropos=0&amp;amp;sektion=0&amp;amp;manpath=OpenBSD+Current&amp;amp;arch=i386&amp;amp;format=html&lt;br /&gt;
&lt;br /&gt;
; [[Valgrind]]&lt;br /&gt;
: Executes a program under emulation, performing analysis according to one of the many plug-in modules as desired. You can write your own plug-in module as desired.&lt;br /&gt;
: http://valgrind.org/&lt;br /&gt;
&lt;br /&gt;
; [[DTrace]]&lt;br /&gt;
: Comprehensive dynamic tracing framework for Solaris (also ported to MacOS X - XRays and FreeBSD). DTrace provides a powerful infrastructure to permit investigation of the behavior of the operating system and user programs.&lt;br /&gt;
: http://www.sun.com/bigadmin/content/dtrace/&lt;br /&gt;
&lt;br /&gt;
; [[strings]]&lt;br /&gt;
: Strings will print the strings of printable characters in files. It allows choosing different charactersets (ASCII, UNICODE). It is a quick way to browse through files/partitions/... in order to look for words, filenames, keywords etc.&lt;br /&gt;
&lt;br /&gt;
; [[Galleta]]&lt;br /&gt;
: Parses cookie files.  http://www.foundstone.com/resources/proddesc/galleta.htm&lt;br /&gt;
&lt;br /&gt;
; The [[Open Computer Forensics Architecture]]&lt;br /&gt;
: http://ocfa.sourceforge.net/&lt;br /&gt;
&lt;br /&gt;
; [[Pasco]]&lt;br /&gt;
; Parses '''index.dat'' files. http://www.foundstone.com/resources/proddesc/pasco.htm&lt;br /&gt;
&lt;br /&gt;
; [[Rifiuti]]&lt;br /&gt;
; Examines the INFO2 file in the Recycle Bin     http://www.foundstone.com/resources/proddesc/rifiuti.htm&lt;br /&gt;
&lt;br /&gt;
; [[yim2text]]&lt;br /&gt;
; Extracts the 'encrypted' info in yahoo instant messenger log files. http://www.1vs0.com/tools.html&lt;br /&gt;
&lt;br /&gt;
; [[Hachoir]]&lt;br /&gt;
: determines the file type using file header/footer (hachoir-metadata --type), able to list strings in Unicode (hachoir-grep), etc. Support more than 60 file formats.&lt;br /&gt;
&lt;br /&gt;
; [[Cygwin]]&lt;br /&gt;
: http://www.cygwin.com/&lt;br /&gt;
: Linux like environment for Windows&lt;br /&gt;
&lt;br /&gt;
; [[UnxUtils]]&lt;br /&gt;
: http://unxutils.sourceforge.net/&lt;br /&gt;
: Common unix utilities compiled for a Windows environment.&lt;br /&gt;
&lt;br /&gt;
== File Sharing Analysis Tools ==&lt;br /&gt;
; [[P2PMarshal|P2P Marshal]]&lt;br /&gt;
: Tools to discover and analyze peer-to-peer files for Windows.&lt;br /&gt;
&lt;br /&gt;
== [[NDA]] and [[scoped distribution]] tools ==&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Thumbs.db</id>
		<title>Thumbs.db</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Thumbs.db"/>
				<updated>2007-12-20T16:21:27Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Added MiTeC Windos File Analyzer for thumbs.db extraction&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Thumbs.db is a file created by windows when thumbnail view is used.  It is a hidden file not viewed by most users and not updated when files are moved from a folder which images have passed through or deleted.  This gives a secondary chance that someone will leave behind at least partial evidence of an image in their windows folders.&lt;br /&gt;
&lt;br /&gt;
The thumbnails in Thumbs.db are stored in a OLE 2 Compound Document format. It's the same format that MS Office uses. &lt;br /&gt;
&lt;br /&gt;
There is a forensic application developed under the open source project over at sourceforge called vinetto at http://sourceforge.net/projects/vinetto that can extract them.  It does require a python enviornment.  Additionally there are several other java solutions based around the Jakarta project that is apart of Apache.  Additional resources about thumbs.db can be found in a white paper at http://www.accessdata.com/media/en_US/print/papers/wp.Thumbs_DB_Files.en_us.pdf.&lt;br /&gt;
&lt;br /&gt;
MiTeC Windows File Analyzer [http://www.mitec.cz/wfa.html] is a tool for forensic analysis of Thumbnail Databases, Prefetch files, shortcuts, IExplore Index.DAT files and Recycle Bin contents on a Windows system. It will print a report of analyzed files.&lt;br /&gt;
&lt;br /&gt;
=Windows Vista=&lt;br /&gt;
Thumbs.db no longer exists in Vista.  This data has been moved to ''User Profile/Application Data/Microsoft Internet Explorer/Thumbscache32, 96 and 128'''&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Tools:Data_Recovery</id>
		<title>Tools:Data Recovery</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Tools:Data_Recovery"/>
				<updated>2007-12-20T16:16:52Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Links&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Partition Recovery =&lt;br /&gt;
&lt;br /&gt;
*[http://www.ptdd.com/index.htm Partition Table Doctor]&lt;br /&gt;
: Recover deleted or lost Partitions (FAT16/FAT32/NTFS/NTFS5/EXT2/EXT3/SWAP).&lt;br /&gt;
&lt;br /&gt;
*[http://www.diskinternals.com/ntfs-recovery/ NTFS Recovery]&lt;br /&gt;
: DiskInternals NTFS Recovery is a fully automatic utility that recovers data from damaged or formatted disks.&lt;br /&gt;
&lt;br /&gt;
*[http://www.stud.uni-hannover.de/user/76201/gpart/ gpart]&lt;br /&gt;
: Gpart is a tool which tries to guess the primary partition table of a PC-type hard disk in case the primary partition table in sector 0 is damaged, incorrect or deleted.&lt;br /&gt;
&lt;br /&gt;
*[http://www.cgsecurity.org/wiki/TestDisk Testdisk]&lt;br /&gt;
: TestDisk is OpenSource software and is licensed under the GNU Public License (GPL). &lt;br /&gt;
&lt;br /&gt;
== See Also ==&lt;br /&gt;
&lt;br /&gt;
* [http://support.microsoft.com/?kbid=166997 Using Norton Disk Edit to Backup Your Master Boot Record]&lt;br /&gt;
&lt;br /&gt;
== Notes ==&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;fdisk /mbr&amp;quot; restores the boot code in the [[Master boot record]], but not the partition itself. On newer versions of Windows you should use fixmbr, bootrec or mbrfix.&lt;br /&gt;
&lt;br /&gt;
= Data Recovery =&lt;br /&gt;
&lt;br /&gt;
*[http://www.toolsthatwork.com/bringback.htm BringBack] &lt;br /&gt;
: BringBack offers easy to use, inexpensive, and highly successful data recovery for Windows and Linux (ext2) operating systems and digital images stored on memory cards, etc.&lt;br /&gt;
&lt;br /&gt;
*[http://www.runtime.org/raid.htm RAID Reconstructor]&lt;br /&gt;
: Runtime Software's RAID Reconstructor will reconstruct RAID Level 0 (Striping) and RAID Level 5 drives.&lt;br /&gt;
&lt;br /&gt;
*[http://www.salvationdata.com Salvation Data]&lt;br /&gt;
: Claims to have a program that can read the &amp;quot;bad blocks&amp;quot; of Maxtor drives with proprietary commands.&lt;br /&gt;
&lt;br /&gt;
* [http://www.e-rol.com/en/ e-ROL]&lt;br /&gt;
: Erol allows you to recover through the internet files erased by mistake. Recover your files online for free.&lt;br /&gt;
&lt;br /&gt;
* [http://www.recuva.com/ Recuva]&lt;br /&gt;
: Recuva is a freeware Windows tool that will recover accidentally deleted files.&lt;br /&gt;
&lt;br /&gt;
* [http://www.snapfiles.com/get/restoration.html Restoration]&lt;br /&gt;
: Restoration is a freeware Windows software that will allow you to recover deleted files&lt;br /&gt;
&lt;br /&gt;
* [http://www.undelete-plus.com/ Undelete Plus]&lt;br /&gt;
: Undelete Plus is a free deleted file recovery tool that works for all versions of Windows (95-Vista), FAT12/16/32, NTFS and NTFS5 filesystems and can perform recovery on various solid state devices.&lt;br /&gt;
&lt;br /&gt;
* [http://www.data-recovery-software.net/ R-Studio]&lt;br /&gt;
: R-Studio is a data recovery software suite that can recover files from FAT(12-32), NTFS, NTFS 5, HFS/HFS+, FFS, UFS/UFS2 (*BSD, Solaris), Ext2/Ext3 (Linux) and so on.&lt;br /&gt;
&lt;br /&gt;
=Carving=&lt;br /&gt;
*[http://www.datalifter.com/products.htm DataLifter® - File Extractor Pro]&lt;br /&gt;
: Data carving runs on multiple threads to make use of modern processors &lt;br /&gt;
&lt;br /&gt;
*[http://foremost.sourceforge.net/ Foremost]&lt;br /&gt;
: Foremost is a console program to recover files based on their headers, footers, and internal data structures. &lt;br /&gt;
&lt;br /&gt;
*[http://www.digitalforensicssolutions.com/Scalpel/ Scalpel]&lt;br /&gt;
: Scalpel is a fast file carver that reads a database of header and footer definitions and extracts matching files from a set of image files or raw device files. Scalpel is filesystem-independent and will carve files from FATx, NTFS, ext2/3, or raw partitions.&lt;br /&gt;
&lt;br /&gt;
*[[EnCase]]&lt;br /&gt;
: EnCase comes with some eScripts that will do carving.&lt;br /&gt;
&lt;br /&gt;
*[http://ocfa.sourceforge.net/libcarvpath/ CarvFs]&lt;br /&gt;
: A virtual filesystem (fuse) implementation that can provide carving tools with the posibility to do recursive multi tool zero-storage carving (also called in-place carving). Patches and scripts for scalpel and foremost are provided. Works on raw and encase images.&lt;br /&gt;
&lt;br /&gt;
*[http://ocfa.sourceforge.net/libcarvpath/ LibCarvPath]&lt;br /&gt;
: A shared library that allows carving tools to use zero-storage carving on carvfs virtual files.&lt;br /&gt;
&lt;br /&gt;
*[http://www.cgsecurity.org/wiki/PhotoRec PhotoRec]&lt;br /&gt;
: PhotoRec is file data recovery software designed to recover lost files including video, documents and archives from Hard Disks and CDRom and lost pictures (thus, its 'Photo Recovery' name) from digital camera memory.&lt;br /&gt;
&lt;br /&gt;
*[http://www.datarescue.com/photorescue/ PhotoRescue]&lt;br /&gt;
: Datarescue PhotoRescue Advanced is picture and photo data recovery solution made by the creators of IDA Pro. PhotoRescue will undelete, unerase and recover pictures and files lost on corrupted, erased or damaged compact flash (CF) cards, SD Cards, Memory Sticks, SmartMedia and XD cards.&lt;br /&gt;
&lt;br /&gt;
* [https://www.uitwisselplatform.nl/projects/revit RevIt]&lt;br /&gt;
: RevIt (Revive It) is an experimental carving tool, initially developed for the DFRWS 2006 carving challenge. It uses 'file structure based carving'. Note that RevIt currently is a work in progress.&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Tools:Data_Recovery</id>
		<title>Tools:Data Recovery</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Tools:Data_Recovery"/>
				<updated>2007-12-20T16:15:36Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: NTFS-Recovery, R-Studio, Undelete Plus, Photorescue, mbrfix, fixmbr, bootrec&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Partition Recovery =&lt;br /&gt;
&lt;br /&gt;
*[http://www.ptdd.com/index.htm Partition Table Doctor]&lt;br /&gt;
: Recover deleted or lost Partitions (FAT16/FAT32/NTFS/NTFS5/EXT2/EXT3/SWAP).&lt;br /&gt;
&lt;br /&gt;
*[http://www.diskinternals.com/ntfs-recovery/]&lt;br /&gt;
: DiskInternals NTFS Recovery is a fully automatic utility that recovers data from damaged or formatted disks.&lt;br /&gt;
&lt;br /&gt;
*[http://www.stud.uni-hannover.de/user/76201/gpart/ gpart]&lt;br /&gt;
: Gpart is a tool which tries to guess the primary partition table of a PC-type hard disk in case the primary partition table in sector 0 is damaged, incorrect or deleted.&lt;br /&gt;
&lt;br /&gt;
*[http://www.cgsecurity.org/wiki/TestDisk Testdisk]&lt;br /&gt;
: TestDisk is OpenSource software and is licensed under the GNU Public License (GPL). &lt;br /&gt;
&lt;br /&gt;
== See Also ==&lt;br /&gt;
&lt;br /&gt;
* [http://support.microsoft.com/?kbid=166997 Using Norton Disk Edit to Backup Your Master Boot Record]&lt;br /&gt;
&lt;br /&gt;
== Notes ==&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;fdisk /mbr&amp;quot; restores the boot code in the [[Master boot record]], but not the partition itself. On newer versions of Windows you should use fixmbr, bootrec or mbrfix.&lt;br /&gt;
&lt;br /&gt;
= Data Recovery =&lt;br /&gt;
&lt;br /&gt;
*[http://www.toolsthatwork.com/bringback.htm BringBack] &lt;br /&gt;
: BringBack offers easy to use, inexpensive, and highly successful data recovery for Windows and Linux (ext2) operating systems and digital images stored on memory cards, etc.&lt;br /&gt;
&lt;br /&gt;
*[http://www.runtime.org/raid.htm RAID Reconstructor]&lt;br /&gt;
: Runtime Software's RAID Reconstructor will reconstruct RAID Level 0 (Striping) and RAID Level 5 drives.&lt;br /&gt;
&lt;br /&gt;
*[http://www.salvationdata.com Salvation Data]&lt;br /&gt;
: Claims to have a program that can read the &amp;quot;bad blocks&amp;quot; of Maxtor drives with proprietary commands.&lt;br /&gt;
&lt;br /&gt;
* [http://www.e-rol.com/en/ e-ROL]&lt;br /&gt;
: Erol allows you to recover through the internet files erased by mistake. Recover your files online for free.&lt;br /&gt;
&lt;br /&gt;
* [http://www.recuva.com/ Recuva]&lt;br /&gt;
: Recuva is a freeware Windows tool that will recover accidentally deleted files.&lt;br /&gt;
&lt;br /&gt;
* [http://www.snapfiles.com/get/restoration.html Restoration]&lt;br /&gt;
: Restoration is a freeware Windows software that will allow you to recover deleted files&lt;br /&gt;
&lt;br /&gt;
* [http://www.undelete-plus.com/]&lt;br /&gt;
: Undelete Plus is a free deleted file recovery tool that works for all versions of Windows (95-Vista), FAT12/16/32, NTFS and NTFS5 filesystems and can perform recovery on various solid state devices.&lt;br /&gt;
&lt;br /&gt;
* [http://www.data-recovery-software.net/]&lt;br /&gt;
: R-Studio is a data recovery software suite that can recover files from FAT(12-32), NTFS, NTFS 5, HFS/HFS+, FFS, UFS/UFS2 (*BSD, Solaris), Ext2/Ext3 (Linux) and so on.&lt;br /&gt;
&lt;br /&gt;
=Carving=&lt;br /&gt;
*[http://www.datalifter.com/products.htm DataLifter® - File Extractor Pro]&lt;br /&gt;
: Data carving runs on multiple threads to make use of modern processors &lt;br /&gt;
&lt;br /&gt;
*[http://foremost.sourceforge.net/ Foremost]&lt;br /&gt;
: Foremost is a console program to recover files based on their headers, footers, and internal data structures. &lt;br /&gt;
&lt;br /&gt;
*[http://www.digitalforensicssolutions.com/Scalpel/ Scalpel]&lt;br /&gt;
: Scalpel is a fast file carver that reads a database of header and footer definitions and extracts matching files from a set of image files or raw device files. Scalpel is filesystem-independent and will carve files from FATx, NTFS, ext2/3, or raw partitions.&lt;br /&gt;
&lt;br /&gt;
*[[EnCase]]&lt;br /&gt;
: EnCase comes with some eScripts that will do carving.&lt;br /&gt;
&lt;br /&gt;
*[http://ocfa.sourceforge.net/libcarvpath/ CarvFs]&lt;br /&gt;
: A virtual filesystem (fuse) implementation that can provide carving tools with the posibility to do recursive multi tool zero-storage carving (also called in-place carving). Patches and scripts for scalpel and foremost are provided. Works on raw and encase images.&lt;br /&gt;
&lt;br /&gt;
*[http://ocfa.sourceforge.net/libcarvpath/ LibCarvPath]&lt;br /&gt;
: A shared library that allows carving tools to use zero-storage carving on carvfs virtual files.&lt;br /&gt;
&lt;br /&gt;
*[http://www.cgsecurity.org/wiki/PhotoRec PhotoRec]&lt;br /&gt;
: PhotoRec is file data recovery software designed to recover lost files including video, documents and archives from Hard Disks and CDRom and lost pictures (thus, its 'Photo Recovery' name) from digital camera memory.&lt;br /&gt;
&lt;br /&gt;
*[http://www.datarescue.com/photorescue/]&lt;br /&gt;
: Datarescue PhotoRescue Advanced is picture and photo data recovery solution made by the creators of IDA Pro. PhotoRescue will undelete, unerase and recover pictures and files lost on corrupted, erased or damaged compact flash (CF) cards, SD Cards, Memory Sticks, SmartMedia and XD cards.&lt;br /&gt;
&lt;br /&gt;
* [https://www.uitwisselplatform.nl/projects/revit RevIt]&lt;br /&gt;
: RevIt (Revive It) is an experimental carving tool, initially developed for the DFRWS 2006 carving challenge. It uses 'file structure based carving'. Note that RevIt currently is a work in progress.&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Tools</id>
		<title>Tools</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Tools"/>
				<updated>2007-12-20T16:08:25Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Added SNARL FreeBSD forensics LiveCD and Penguin Sleuthkit&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is an '''overview of available tools''' for forensic [[investigator]]s. Please click on the name of any tool for more details.&lt;br /&gt;
&lt;br /&gt;
'''Note: This page has gotten too big and is being broken up. See:'''&lt;br /&gt;
* [[Tools:Data Recovery]] (including file carving)&lt;br /&gt;
* [[:Category:Disk Imaging]]&lt;br /&gt;
* [[Tools:File Analysis]]&lt;br /&gt;
* [[Tools:Memory Imaging]]&lt;br /&gt;
* [[:Category:Secure_deletion]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Disk Analysis Tools =&lt;br /&gt;
== Hard Drive Firmware and Diagnostics Tools ==&lt;br /&gt;
; [[PC-3000]], from [[DeepSpar Data Recovery Systems]]&lt;br /&gt;
: http://www.deepspar.com/products-pc-3000-drive.html&lt;br /&gt;
: http://www.pc-3000.com/&lt;br /&gt;
&lt;br /&gt;
== Linux-based Tools ==&lt;br /&gt;
; [[LINReS]], by [[NII Consulting Pvt. Ltd.]]&lt;br /&gt;
: http://www.niiconsulting.com/innovation/linres.html&lt;br /&gt;
&lt;br /&gt;
; [[SMART]], by [[ASR Data]]&lt;br /&gt;
: http://www.asrdata.com&lt;br /&gt;
&lt;br /&gt;
== Macintosh-based Tools ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
; [[Macintosh Forensic Software]], by [[BlackBag Technologies, Inc.]]&lt;br /&gt;
: http://www.blackbagtech.com/software_mfs.html&lt;br /&gt;
&lt;br /&gt;
; [[MacForensicsLab]], by [[Subrosasoft]]&lt;br /&gt;
: [http://www.subrosasoft.com/OSXSoftware/index.php?main_page=product_info&amp;amp;cPath=39&amp;amp;products_id=114 MacForensicLab-Subrosasoft]&lt;br /&gt;
&lt;br /&gt;
== Windows-based Tools ==&lt;br /&gt;
&lt;br /&gt;
; [[BringBack]] by [[Tech Assist, Inc.]]&lt;br /&gt;
: http://www.toolsthatwork.com/bringback.htm&lt;br /&gt;
&lt;br /&gt;
; [[EMail Detective - Forensic Software Tool]] by [[Hot Pepper Technology, Inc]]&lt;br /&gt;
; http://www.hotpepperinc.com/emd&lt;br /&gt;
&lt;br /&gt;
; [[EnCase]], by [[Guidance Software]]&lt;br /&gt;
: http://www.guidancesoftware.com/&lt;br /&gt;
&lt;br /&gt;
; [[fbi (tool)|fbi]], by [[Nuix Pty Ltd]]&lt;br /&gt;
: http://www.nuix.com&lt;br /&gt;
&lt;br /&gt;
; [[Forensic Toolkit]] ([[FTK]]), by [[AccessData]]&lt;br /&gt;
: http://www.accessdata.com/products/ftk/&lt;br /&gt;
&lt;br /&gt;
; [[ILook Investigator]], by [[Elliot Spencer]] and [[Internal Revenue Service|U.S. Dept of Treasury, Internal Revenue Service - Criminal Investigation]] (IRS)&lt;br /&gt;
: http://www.ilook-forensics.org/&lt;br /&gt;
&lt;br /&gt;
; [[OnLineDFS]] by [[Cyber Security Technologies]]&lt;br /&gt;
: http://www.cyberstc.com/&lt;br /&gt;
&lt;br /&gt;
; [[P2 Power Pack]] by [[Paraben]]&lt;br /&gt;
: https://www.paraben-forensics.com/catalog/product_info.php?cPath=25&amp;amp;products_id=187&lt;br /&gt;
&lt;br /&gt;
; [[Safeback]] by [[NTI]] and [[Armor Forensics]]&lt;br /&gt;
: http://www.forensics-intl.com/safeback.html&lt;br /&gt;
&lt;br /&gt;
; [[X-Ways Forensics]] by [[X-Ways AG]]&lt;br /&gt;
: http://www.x-ways.net/forensics/index-m.html&lt;br /&gt;
&lt;br /&gt;
; [[Prodiscover]] by [[Techpathways]]&lt;br /&gt;
: http://www.techpathways.com/ProDiscoverWindows.htm&lt;br /&gt;
&lt;br /&gt;
== Open Source Tools ==&lt;br /&gt;
&lt;br /&gt;
; [[AFFLIB]]&lt;br /&gt;
: A library for working with [[disk image]]s. Currently AFFLIB supports raw, [[AFF]], [[AFD]], and [[EnCase]] file formats. Work to support segmented raw, [[iLook]], and other formats is ongoing.&lt;br /&gt;
&lt;br /&gt;
; [[Autopsy]]&lt;br /&gt;
: http://www.sleuthkit.org/autopsy/desc.php&lt;br /&gt;
&lt;br /&gt;
; [[foremost]]&lt;br /&gt;
: http://foremost.sf.net/&lt;br /&gt;
: [[Linux]] based file carving program&lt;br /&gt;
&lt;br /&gt;
; [[Scalpel]]&lt;br /&gt;
: http://www.digitalforensicssolutions.com/Scalpel/&lt;br /&gt;
: [[Linux]] and [[Windows]] file carving program originally based on [[foremost]].&lt;br /&gt;
&lt;br /&gt;
; [[FTimes]]&lt;br /&gt;
: http://ftimes.sourceforge.net/FTimes/index.shtml&lt;br /&gt;
: FTimes is a system baselining and evidence collection tool.&lt;br /&gt;
&lt;br /&gt;
; [[gfzip]]&lt;br /&gt;
: http://www.nongnu.org/gfzip/&lt;br /&gt;
&lt;br /&gt;
; [[gpart]]&lt;br /&gt;
: http://www.stud.uni-hannover.de/user/76201/gpart/&lt;br /&gt;
: Tries to ''guess the primary partition table of a PC-type hard disk in case the primary partition table in sector 0 is damaged, incorrect or deleted''.&lt;br /&gt;
&lt;br /&gt;
; [[magicrescue]]&lt;br /&gt;
: http://jbj.rapanden.dk/magicrescue/&lt;br /&gt;
&lt;br /&gt;
; The [[Open Computer Forensics Architecture]]&lt;br /&gt;
: http://ocfa.sourceforge.net/&lt;br /&gt;
&lt;br /&gt;
; [[pyflag]]&lt;br /&gt;
: http://www.pyflag.net/PyFlagWiki/&lt;br /&gt;
:  web-based, database-backed forensic and log analysis GUI written in Python.&lt;br /&gt;
&lt;br /&gt;
; [[scrounge-ntfs]]&lt;br /&gt;
: http://memberwebs.com/nielsen/software/scrounge/&lt;br /&gt;
&lt;br /&gt;
; [[Sleuthkit]]&lt;br /&gt;
: http://www.sleuthkit.org/&lt;br /&gt;
&lt;br /&gt;
; [[The Coroner's Toolkit]] ([[TCT]])&lt;br /&gt;
: http://www.porcupine.org/forensics/tct.html&lt;br /&gt;
&lt;br /&gt;
; [[Zeitline]] --- Forensic timeline editor&lt;br /&gt;
: http://projects.cerias.purdue.edu/forensics/timeline.php&lt;br /&gt;
: http://sourceforge.net/projects/zeitline/&lt;br /&gt;
&lt;br /&gt;
; [[Hachoir]]&lt;br /&gt;
: A generic framework for binary file manipulation, it supports [[FAT12]], [[FAT16]], [[FAT32]], [[ext2|ext2/ext3]], Linux swap, MSDOS partition header, etc. Recognize file type. Able to find subfiles (hachoir-subfile).&lt;br /&gt;
&lt;br /&gt;
== [[NDA]] and [[scoped distribution]] tools ==&lt;br /&gt;
&lt;br /&gt;
= Enterprise Tools (Proactive Forensics)=&lt;br /&gt;
&lt;br /&gt;
; [[P2 Enterprise Edition]] by [[Paraben]]&lt;br /&gt;
: http://www.paraben-forensics.com/enterprise_forensics.html&lt;br /&gt;
&lt;br /&gt;
; [[LiveWire Investigator 2008]] by [[WetStone Technologies]]&lt;br /&gt;
: http://www.wetstonetech.com/f/livewire2008.html&lt;br /&gt;
&lt;br /&gt;
= Forensics Live CDs =&lt;br /&gt;
&lt;br /&gt;
; [[FCCU Gnu/Linux Boot CD]]&lt;br /&gt;
: A Live CD built on top of [[Knoppix]] with a lot of tools with forensic purpose.&lt;br /&gt;
: It leaves the target devices unaltered (it does not use the swap partitions found on the devices) nor does it automount partitions.&lt;br /&gt;
&lt;br /&gt;
; [[Helix]]&lt;br /&gt;
: A Live CD built on top of [[Knoppix]] with special tools for [[Incident Response|incident response]] and electronic discovery.&lt;br /&gt;
: Its a hybrid CD which also contains a [[Cygwin]] environment for use on a running Windows system (w/o rebooting) including the Sysinternals tools.&lt;br /&gt;
&lt;br /&gt;
; [[SNARL]]&lt;br /&gt;
; A FreeBSD based forensics Bootable ISO (includes Autopsy and Sleuth Kit).&lt;br /&gt;
; http://sourceforge.net/projects/snarl/&lt;br /&gt;
&lt;br /&gt;
; [[Knoppix STD]]&lt;br /&gt;
: A Live CD built on top of [[Knoppix]].&lt;br /&gt;
: http://s-t-d.org/&lt;br /&gt;
&lt;br /&gt;
; [[Penguin Sleuthkit]&lt;br /&gt;
; A Linux LiveCD that includes SleuthKit.&lt;br /&gt;
; http://penguinsleuth.org/&lt;br /&gt;
&lt;br /&gt;
; [[THE FARMER'S BOOT CD]]&lt;br /&gt;
: A [[Linux]] [[Live CD]], designed and optimized for previewing data in a [[forensically sound]] manner. It contains a number of programs forensic practitioners can utilize to preview both [[Windows]] and [[Linux]] systems.&lt;br /&gt;
&lt;br /&gt;
; [[MacQuisition Boot CD]]&lt;br /&gt;
: A forensic [[Live CD]] built for imaging [[Macintosh]] systems.&lt;br /&gt;
&lt;br /&gt;
; [[DEFT Linux]]&lt;br /&gt;
: A Live CD built on top of [[Xubuntu]] with the best tools for computer forensics and incident response.&lt;br /&gt;
: It is very easy to use with a lot of device drivers. The first live CD with [[AFF]] and dhash.&lt;br /&gt;
: http://deft.yourside.it&lt;br /&gt;
&lt;br /&gt;
; [[Recovery Is Possible]]&lt;br /&gt;
: A [[Linux]] [[Live CD]] with a number of recovery applications such as [[TestDisk]], [[PhotoRec]] etc.&lt;br /&gt;
: http://www.tux.org/pub/people/kent-robotti/looplinux/rip/&lt;br /&gt;
&lt;br /&gt;
; [[Ubuntu-Rescue-Remix]]&lt;br /&gt;
: Ubuntu-rescue-remix is a live cd that provides the data recovery expert with an environment equipped with the best free-libre, open source data recovery and forensics tools available. Since many of those libraries and tools are part of the Ubuntu Installer, it makes sense to remix Ubuntu into a lightweight and powerful environment for data recovery.  This project was formerly known as Rescubuntu.&lt;br /&gt;
:http://ubuntu-rescue-remix.org/&lt;br /&gt;
&lt;br /&gt;
= Metadata Extraction Tools =&lt;br /&gt;
&lt;br /&gt;
; [[antiword]]&lt;br /&gt;
: http://www.winfield.demon.nl/&lt;br /&gt;
&lt;br /&gt;
; [[catdoc]]&lt;br /&gt;
: http://www.45.free.net/~vitus/software/catdoc/&lt;br /&gt;
&lt;br /&gt;
; [[jhead]]&lt;br /&gt;
: http://www.sentex.net/~mwandel/jhead/&lt;br /&gt;
: Displays or modifies [[Exif]] data in [[JPEG]] files.&lt;br /&gt;
&lt;br /&gt;
; [[laola]]&lt;br /&gt;
: http://user.cs.tu-berlin.de/~schwartz/pmh/index.html&lt;br /&gt;
&lt;br /&gt;
; [[vinetto]]&lt;br /&gt;
: http://vinetto.sourceforge.net/&lt;br /&gt;
: Examines [[Thumbs.db]] files.&lt;br /&gt;
&lt;br /&gt;
; [[word2x]]&lt;br /&gt;
: http://word2x.sourceforge.net/&lt;br /&gt;
&lt;br /&gt;
; [[wvWare]]&lt;br /&gt;
: http://wvware.sourceforge.net/&lt;br /&gt;
: Extracts metadata from various [[Microsoft]] Word files ([[doc]]). Can also convert doc files to other formats such as HTML or plain text.&lt;br /&gt;
&lt;br /&gt;
; [[xpdf]]&lt;br /&gt;
: http://www.foolabs.com/xpdf/&lt;br /&gt;
: [[pdfinfo]] (part of the [[xpdf]] package) displays some metadata of [[PDF]] files.&lt;br /&gt;
&lt;br /&gt;
; [[Metadata Assistant]]&lt;br /&gt;
: http://www.payneconsulting.com/products/metadataent/&lt;br /&gt;
&lt;br /&gt;
; hachoir-metadata: part of '''[[Hachoir]]''' project&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Personal Digital Device Tools=&lt;br /&gt;
&lt;br /&gt;
== PDA Forensics ==&lt;br /&gt;
; [[Paraben PDA Seizure]]&lt;br /&gt;
; [[Paraben PDA Seizure Toolbox]]&lt;br /&gt;
; [[PDD]]&lt;br /&gt;
&lt;br /&gt;
== Cell Phone Forensics ==&lt;br /&gt;
; [[BitPIM]]&lt;br /&gt;
; [[DataPilot Secure View]]&lt;br /&gt;
; [[GSM .XRY]]&lt;br /&gt;
; [[Fernico ZRT]]&lt;br /&gt;
; [[ForensicMobile]]&lt;br /&gt;
; [[LogiCube CellDEK]]&lt;br /&gt;
; [[MOBILedit!]]&lt;br /&gt;
; [[Oxygen PM II]]&lt;br /&gt;
; [[Paraben Device Seizure]]&lt;br /&gt;
; [[Paraben Device Seizure Toolbox]]&lt;br /&gt;
; [[Serial Port Monitoring]]&lt;br /&gt;
; [[TULP2G]]&lt;br /&gt;
&lt;br /&gt;
== SIM Card Forensics ==&lt;br /&gt;
; [[ForensicSIM]]&lt;br /&gt;
; [[Paraben Device Seizure]]&lt;br /&gt;
; [[SIMCon]]&lt;br /&gt;
&lt;br /&gt;
== Preservation Tools ==&lt;br /&gt;
; [[Paraben StrongHold Bag]]&lt;br /&gt;
; [[Paraben StrongHold Tent]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Other Tools =&lt;br /&gt;
&lt;br /&gt;
; [[VMware]] Player&lt;br /&gt;
: http://www.vmware.com/products/player/&lt;br /&gt;
: http://en.wikipedia.org/wiki/VMware#VMware_Workstation&lt;br /&gt;
: A free player for [[VMware]] [[virtual machine]]s that will allow them to &amp;quot;play&amp;quot; on either [[Windows]] or [[Linux]]-based systems.&lt;br /&gt;
&lt;br /&gt;
; [[VMware]] Server&lt;br /&gt;
: http://www.vmware.com/products/server/&lt;br /&gt;
: The free server product, for setting up/configuring/running [[VMware]] [[virtual machine]].Important difference being that it can run 'headless', i.e. everything in background.&lt;br /&gt;
&lt;br /&gt;
; Computer Forensics Toolkit&lt;br /&gt;
: http://computer-forensics.privacyresources.org&lt;br /&gt;
: This is a collection of resources, most of which are informational, designed specifically to guide the beginner, often in a procedural sense.&lt;br /&gt;
&lt;br /&gt;
; Webtracer&lt;br /&gt;
: http://www.forensictracer.com&lt;br /&gt;
: Software for forensic analysis of internet resources (IP address, e-mail address, domain name, URL, e-mail headers, log files...)&lt;br /&gt;
&lt;br /&gt;
; Live View&lt;br /&gt;
: http://liveview.sourceforge.net/&lt;br /&gt;
: Live View is a graphical forensics tool that creates a [[VMware]] [[virtual machine]] out of a dd disk image or physical disk. &lt;br /&gt;
&lt;br /&gt;
; Parallels VM&lt;br /&gt;
: http://www.parallels.com/&lt;br /&gt;
: http://en.wikipedia.org/wiki/Parallels_Workstation&lt;br /&gt;
&lt;br /&gt;
; Microsoft Virtual PC&lt;br /&gt;
: http://www.microsoft.com/windows/products/winfamily/virtualpc/default.mspx&lt;br /&gt;
: http://en.wikipedia.org/wiki/Virtual_PC&lt;br /&gt;
&lt;br /&gt;
; The Onion Router (TOR)&lt;br /&gt;
: http://tor.eff.org/&lt;br /&gt;
: http://en.wikipedia.org/wiki/Tor_(anonymity_network)&lt;br /&gt;
: Network anonymizer designed to make traffic analysis difficult.&lt;br /&gt;
&lt;br /&gt;
== Hex Editors ==&lt;br /&gt;
&lt;br /&gt;
; [[biew]]&lt;br /&gt;
: http://biew.sourceforge.net/en/biew.html&lt;br /&gt;
&lt;br /&gt;
; [[hexdump]]&lt;br /&gt;
: ...&lt;br /&gt;
&lt;br /&gt;
; [[HexFiend]]&lt;br /&gt;
: A hex editor for Apple OS X&lt;br /&gt;
: http://ridiculousfish.com/hexfiend/&lt;br /&gt;
&lt;br /&gt;
; [[Hex Workshop]]&lt;br /&gt;
: A hex editor from [[BreakPoint Software, Inc.]]&lt;br /&gt;
: http://www.bpsoft.com&lt;br /&gt;
&lt;br /&gt;
; [[khexedit]]&lt;br /&gt;
: http://docs.kde.org/stable/en/kdeutils/khexedit/index.html&lt;br /&gt;
&lt;br /&gt;
; [[WinHex]]&lt;br /&gt;
: Computer forensics software, data recovery software, hex editor, and disk editor from [[X-Ways]].&lt;br /&gt;
: http://www.x-ways.net/winhex&lt;br /&gt;
&lt;br /&gt;
; [[xxd]]&lt;br /&gt;
: ...&lt;br /&gt;
&lt;br /&gt;
= Telephone Scanners/War Dialers =&lt;br /&gt;
&lt;br /&gt;
;PhoneSweep&lt;br /&gt;
:http://www.sandstorm.net/products/phonesweep/&lt;br /&gt;
:PhoneSweep is a commercial grade multi-line wardialer used by many security auditors to run telephone line scans in their organizations. PhoneSweep Gold is the distributed-access add-on for PhoneSweep, for organizations that need to run scans remotely.&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Blogs</id>
		<title>Blogs</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Blogs"/>
				<updated>2007-12-20T16:02:02Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Added unixsadm&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Computer forensics]] related '''blogs'''.&lt;br /&gt;
&lt;br /&gt;
= English-Language Blogs =&lt;br /&gt;
&lt;br /&gt;
== Forensic Blogs ==&lt;br /&gt;
&lt;br /&gt;
* [http://computer.forensikblog.de/en/ Andreas Schuster - Computer Forensics Blog]&lt;br /&gt;
* [http://www.niiconsulting.com/checkmate/ Checkmate - e-zine on Digital Forensics and Incident Response]&lt;br /&gt;
* [http://www.infosecinstitute.com/blog/ethical_hacking_computer_forensics.html Jack Koziol - Ethical Hacking and Computer Forensics]&lt;br /&gt;
* [http://fleet.typepad.com/lukeup/ SecurityBros.com - Hacking, Forensics &amp;amp; Security]&lt;br /&gt;
* [http://windowsir.blogspot.com/ Windows Incident Response Blog] by [[Harlan Carvey]]&lt;br /&gt;
* [http://geschonneck.com/ Alexander Geschonneck - Computer Forensics Blog]&lt;br /&gt;
* [http://forensicblog.org/ Michael Murr - Computer Forensics Blog]&lt;br /&gt;
* [http://forenshick.blogspot.com/ Jordan Farr - Forensic news, Technology, TV, and more]&lt;br /&gt;
* [http://unixsadm.blogspot.com/ Criveti Mihai - UNIX, OpenVMS and Windows System Administration, Digital Forensics, High Performance Computing, Clustering and Distributed Systems]&lt;br /&gt;
&lt;br /&gt;
== Related Blogs ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.c64allstars.de C64Allstars Blog]&lt;br /&gt;
* [http://www.emergentchaos.com/ Adam Shostack - Emergent Chaos]&lt;br /&gt;
* [http://jeffjonas.typepad.com/ Jeff Jonas - Inventor of NORA discusses privacy and all things digital]&lt;br /&gt;
* [http://www.cs.uno.edu/~golden/weblog Digital Forensics, Coffee, Benevolent Hacking] - Written by [[Golden G. Richard III]]&lt;br /&gt;
&lt;br /&gt;
= Non-English Language =&lt;br /&gt;
&lt;br /&gt;
=== French ===&lt;br /&gt;
&lt;br /&gt;
* [http://forensics-dev.blogspot.com Forensics-dev] ([http://translate.google.com/translate?u=http%3A%2F%2Fforensics-dev.blogspot.com%2F&amp;amp;langpair=fr%7Cen&amp;amp;hl=en&amp;amp;ie=UTF-8&amp;amp;oe=UTF-8&amp;amp;prev=%2Flanguage_tools Google translation])&lt;br /&gt;
&lt;br /&gt;
=== German ===&lt;br /&gt;
&lt;br /&gt;
* [http://computer.forensikblog.de/ Andreas Schuster - Computer Forensik Blog Gesamtausgabe] ([http://computer.forensikblog.de/en/ English version])&lt;br /&gt;
* [http://computer-forensik.org Alexander Geschonneck - computer-forensik.org] ([http://translate.google.com/translate?u=http%3A%2F%2Fwww.computer-forensik.org&amp;amp;langpair=de%7Cen&amp;amp;hl=en&amp;amp;ie=UTF-8&amp;amp;oe=UTF-8&amp;amp;prev=%2Flanguage_tools Google translation])&lt;br /&gt;
* [http://henrikbecker.blogspot.com Henrik Becker - Digitale Beweisführung] ([http://translate.google.com/translate?u=http%3A%2F%2Fhenrikbecker.blogspot.com&amp;amp;langpair=de%7Cen&amp;amp;hl=en&amp;amp;ie=UTF-8&amp;amp;oe=UTF-8&amp;amp;prev=%2Flanguage_tools Google translation])&lt;br /&gt;
&lt;br /&gt;
=== Spanish ===&lt;br /&gt;
&lt;br /&gt;
* [http://www.forensic-es.org/blog forensic-es.org] ([http://translate.google.com/translate?u=http%3A%2F%2Fwww.forensic-es.org%2Fblog&amp;amp;langpair=es%7Cen&amp;amp;hl=en&amp;amp;ie=UTF-8&amp;amp;oe=UTF-8&amp;amp;prev=%2Flanguage_tools Google translation])&lt;br /&gt;
* [http://www.inforenses.com Javier Pages - InForenseS] ([http://translate.google.com/translate?u=http%3A%2F%2Fwww.inforenses.com&amp;amp;langpair=es%7Cen&amp;amp;hl=es&amp;amp;ie=UTF-8&amp;amp;oe=UTF-8&amp;amp;prev=%2Flanguage_tools Google translation])&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Solaris</id>
		<title>Solaris</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Solaris"/>
				<updated>2007-12-20T15:22:28Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Links, FS&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Solaris''' is a highly scalable enterprise grade [[UNIX]] Operating System from [[Sun Microsystems]]. Solaris is known to run on [[SPARC]] and x86/x86-64 architectures, although it has also been ported to [[PowerPC]] and IBM [[zSeries]] [[mainframes]] in a joint effort with [[IBM]].&lt;br /&gt;
&lt;br /&gt;
Commonly used filesystems and / or volume managers on the Solaris Operating System are [[UFS]], [[ZFS]], [[SAMFS]], [[QFS]], Veritas [VxFS] and Veritas [VxVM], [[AVS]] as well as the Solaris Volume Manager ([[Solstice]]).&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.sun.com/solaris Sun Solaris homepage]&lt;br /&gt;
* [http://www.sun.com/blueprints/0405/819-2262.pdf Sun Blueprints - Using Computer Forensics When Investigating System Attacks]&lt;br /&gt;
* [http://www.opensolaris.org The OpenSolaris project]&lt;br /&gt;
* [http://www.phptr.com/content/images/0131482092/samplechapter/mcdougall_ch15.pdf Solaris Internals - The UFS File System - specifications, on disk layout]&lt;br /&gt;
* [http://www.solarisinternals.com/si/reading/sunworldonline/swol-05-1999/swol-05-filesystem.html Solaris Internals - Getting to know the Solaris filesystems]&lt;br /&gt;
&lt;br /&gt;
[[Category:Operating systems]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Solaris</id>
		<title>Solaris</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Solaris"/>
				<updated>2007-12-20T15:20:47Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Filesystems, Links&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Solaris''' is a highly scalable enterprise grade [[UNIX]] Operating System from [[Sun Microsystems]]. Solaris is known to run on [[SPARC]] and x86/x86-64 architectures, although it has also been ported to [[PowerPC]] and IBM [[zSeries]] [[mainframes]] in a joint effort with [[IBM]].&lt;br /&gt;
&lt;br /&gt;
Commonly used filesystems and / or volume managers on the Solaris Operating System are [[UFS]], [[ZFS]], [[SAMFS]], [[QFS]], Veritas [VxFS] and Veritas [VxVM], [[AVS]] as well as the Solaris Volume Manager ([[Solstice]]).&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.sun.com/solaris Sun Solaris homepage]&lt;br /&gt;
* [http://www.sun.com/blueprints/0405/819-2262.pdf Sun Blueprints - Using Computer Forensics When Investigating System Attacks]&lt;br /&gt;
* [http://www.opensolaris.org The OpenSolaris project]&lt;br /&gt;
* [http://www.phptr.com/content/images/0131482092/samplechapter/mcdougall_ch15.pdf Solaris Internals - The UFS File System - specifications, on disk layout]&lt;br /&gt;
&lt;br /&gt;
[[Category:Operating systems]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Solaris</id>
		<title>Solaris</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Solaris"/>
				<updated>2007-12-20T15:18:06Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Solaris, Sun Blueprints Forensics documents&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Solaris''' is a highly scalable enterprise grade [[UNIX]] Operating System from [[Sun Microsystems]]. Solaris is known to run on [[SPARC]] and x86/x86-64 architectures, although it has also been ported to [[PowerPC]] and IBM [[zSeries]] [[mainframes]] in a joint effort with [[IBM]].&lt;br /&gt;
&lt;br /&gt;
Commonly used filesystems and / or volume managers on the Solaris Operating System are [[UFS]], [[ZFS]], [[SAMFS]], [[QFS]], Veritas [VxFS] and Veritas [VxVM], [[AVS]] as well as the Solaris Volume Manager ([[Solstice]]).&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [www.sun.com/solaris Sun Solaris homepage]&lt;br /&gt;
* [www.sun.com/blueprints/0405/819-2262.pdf Sun Blueprints - Using Computer Forensics When Investigating System Attacks]&lt;br /&gt;
* [http://www.opensolaris.org The OpenSolaris project]&lt;br /&gt;
&lt;br /&gt;
[[Category:Operating systems]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User_talk:Jessek</id>
		<title>User talk:Jessek</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User_talk:Jessek"/>
				<updated>2007-12-20T08:49:30Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Hello&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Mutt Header Format corrections ==&lt;br /&gt;
&lt;br /&gt;
Thank you for your corrections, i'm not realy good with english :( if you wont to jabber me try: fishor.bug.track # gmail # com&lt;br /&gt;
: My pleasure! [[User:Jessek|Jessek]] 09:16, 8 August 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
== Hello ==&lt;br /&gt;
&lt;br /&gt;
Just wanted to drop by and say &amp;quot;Hello&amp;quot;. That, and to see who the people maintaining and editing this wiki are and all that, you know. :-). Anyway, I've enjoyed using Foremost so thanks for that too.&lt;br /&gt;
-[[User:Cmihai|cmihai]] 00:49, 20 December 2007 (PST)&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Ext2</id>
		<title>Ext2</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Ext2"/>
				<updated>2007-12-20T08:39:39Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Ext2&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''ext2''' or the '''second extended file system''' is a [[Linux]] filesystem designed as a replacement for ext. Note that [[ext3]] is mostly compatible with ext2.&lt;br /&gt;
&lt;br /&gt;
The [[SleuthKit]] and [[R-Studio]] can be used to perform recovery of data from the EXT2 filesystem. Various data carving tools like [[Foremost]] and [[Scalpel]] also support the ext2 filesystem.&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Ext2 Wikipedia article on EXT2]&lt;br /&gt;
* [http://www.nongnu.org./ext2-doc/ext2.html Layout of the EXT2 Filesystem]&lt;br /&gt;
* [http://fedora.linuxsir.org/doc/ext2undelete/Ext2fs-Undeletion.html Linux Ext2fs Undeletion mini-HOWTO]&lt;br /&gt;
* [http://unixsadm.blogspot.com/2007/11/ext2-filesystem-for-linux-and-solaris.html Using ext2 on other systems]&lt;br /&gt;
&lt;br /&gt;
[[Category:Disk file systems]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/FTimes</id>
		<title>FTimes</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/FTimes"/>
				<updated>2007-12-20T07:53:48Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Fixed Infobox, added Limitations, DFRWS challange info.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Infobox_Software |&lt;br /&gt;
  name = FTimes |&lt;br /&gt;
  maintainer = [[Klayton Monroe]] |&lt;br /&gt;
  os = {{Multiplatform}} |&lt;br /&gt;
  genre = [[Evidence collection]] |&lt;br /&gt;
  license = {{BSD}} |&lt;br /&gt;
  website = [http://ftimes.sourceforge.net/ ftimes.sf.net] |&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
'''FTimes''', short for '''File Topography and Integrity Monitoring on an Enterprise Scale''' is a system baselining and evidence collection tool designed for incident response, evidence collection (alternate data streams, hidden files), content integrity monitoring, intrusion analysis and computer forensics.&lt;br /&gt;
&lt;br /&gt;
== Limitations ==&lt;br /&gt;
&lt;br /&gt;
FTimes does not collect all possible attributes on every supported platform.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://ftimes.sourceforge.net/ The FTimes Project Homepage]&lt;br /&gt;
* [http://unixsadm.blogspot.com/2007/11/building-ftimes-on-windows-using-visual.html Building FTimes on Windows using Visual Studio]&lt;br /&gt;
* [http://www.korelogic.com/Resources/Projects/dfrws_challenge_2006/ DFRWS 2006 File Carving Challenge - using FTimes]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/FTimes</id>
		<title>FTimes</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/FTimes"/>
				<updated>2007-12-20T07:43:40Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: FTimes tool&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Infobox_Software |&lt;br /&gt;
  name = FTimes |&lt;br /&gt;
  os = {{Multiplatform} |&lt;br /&gt;
  genre = [[Evidence collection]] |&lt;br /&gt;
  license = {{BSD}} |&lt;br /&gt;
  website = [http://ftimes.sourceforge.net/ ftimes.sf.net] |&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
'''FTimes''', short for '''File Topography and Integrity Monitoring on an Enterprise Scale''' is a system baselining and evidence collection tool designed for incident response, evidence collection (alternate data streams, hidden files), content integrity monitoring, intrusion analysis and computer forensics.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://ftimes.sourceforge.net/ The FTimes Project Homepage]&lt;br /&gt;
* [http://unixsadm.blogspot.com/2007/11/building-ftimes-on-windows-using-visual.html Building FTimes on Windows using Visual Studio]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/MD5</id>
		<title>MD5</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/MD5"/>
				<updated>2007-12-19T23:28:04Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Corrections&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The '''Message-Digest algorithm 5''' ('''MD5''') is a cryptographic [[hash|hash function]] that produces a 128-bit hash value. Originally developed in 1991, much as has been written about this algorithm. As such, this article concentrates only on its application to computer forensics.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
On most [[Unix]] systems the tools [[digest]] -a md5 (Solaris), [[md5]] (BSD) or [[md5sum]] (GNU) can be used to compute the MD5 hash of a file or device. [[md5deep]] can compute MD5 hashes of whole directory trees.&lt;br /&gt;
&lt;br /&gt;
== Weaknesses ==&lt;br /&gt;
&lt;br /&gt;
Recently some cryptographic weaknesses have been found in MD5. Tool developers should avoid using MD5 in new products in favor of other hash functions like [[RIPEMD-160]], [[Tiger]], [[WHIRLPOOL]], [[SHA-256]] or [[SHA-512]]. Host Intrusion Detection systems and hash databases should also use multiple hash algorithms.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Md5 Wikipedia: MD5]&lt;br /&gt;
* [http://deepbyte.com/blog/2006/02/is_the_md5_hash_unreliable.html Is the MD5 hash unreliable?]&lt;br /&gt;
* [http://unixsadm.blogspot.com/2007/11/exploiting-md5-and-other-hashing.html Collection of exploits and weaknesses in MD5]&lt;br /&gt;
&lt;br /&gt;
[[Category:Hashing]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/MD5</id>
		<title>MD5</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/MD5"/>
				<updated>2007-12-19T22:49:36Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Added RIPEMD, Tiger, Whirlpool and SHA-512 references; digest tool&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The '''Message-Digest algorithm 5''' ('''MD5''') is a cryptographic [[hash|hash function]] that produces a 128-bit hash value. Originally developed in 1991, much as has been written about this algorithm. As such, this article concentrates only on its application to computer forensics.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
On most [[Unix]] systems the tools [[digest]] -a md5 (Solaris), [[md5]] (BSD) or [[md5sum]] (GNU) can be used to compute the MD5 hash of a file or device. [[md5deep]] can compute MD5 hashes of whole directory trees.&lt;br /&gt;
&lt;br /&gt;
== Weaknesses ==&lt;br /&gt;
&lt;br /&gt;
Recently some cryptographic weaknesses have been found in MD5. Tool developers should avoid using MD5 in new products in favor of other hash functions like [[RIPEMD-160]], [[Tiger]], [[WHIRLPOOL]], [[SHA-256]] or [[SHA-512]]. Host Intrusion Detection systems and hash databases should also use multiple hash algorithms.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Md5 Wikipedia: MD5]&lt;br /&gt;
* [http://deepbyte.com/blog/2006/02/is_the_md5_hash_unreliable.html Is the MD5 hash unreliable?]&lt;br /&gt;
* [http://unixsadm.blogspot.com/2007/11/exploiting-md5-and-other-hashing.html - Collection of exploits and weaknesses in MD5]&lt;br /&gt;
&lt;br /&gt;
[[Category:Hashing]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/PGPDisk</id>
		<title>PGPDisk</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/PGPDisk"/>
				<updated>2007-12-18T18:02:57Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: PGP Intentional Bypass&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''PGPDisk''' or Pretty Good Privacy [[Whole Disk Encryption]] was a disk encryption solution from the [http://www.pgp.com PGP Corporation]. It has since been rebranded as [[PGP Whole Disk Encryption]].&lt;br /&gt;
&lt;br /&gt;
It provides transparent whole disk encryption with Pre-Boot authentification for Windows. Also supports MacOS X 10.4 (non-boot disks only).&lt;br /&gt;
&lt;br /&gt;
An undocumented encryption bypass feature was found that allowed the drive to be accessed even without the boot-up password.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.pgp.com/products/wholediskencryption/ PGPDisk Official website]&lt;br /&gt;
* [http://securology.blogspot.com/2007/10/pgp-whole-disk-encryption-barely.html PGP Whole Disk Encryption - Barely Acknowledged Intentional Bypass]&lt;br /&gt;
&lt;br /&gt;
[[Category:Encryption]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/DES</id>
		<title>DES</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/DES"/>
				<updated>2007-12-17T16:15:14Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Corrections&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
'''DES''' or '''Data Encryption Standard''' is a cipher selected as an official FIPS (Federal Information Processing Standard) for the United States.&lt;br /&gt;
&lt;br /&gt;
DES is now considered to be insecure due to the 56-bit key size being too small.&lt;br /&gt;
&lt;br /&gt;
== External Links == &lt;br /&gt;
&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Data_Encryption_Standard Wikipedia article on DES]&lt;br /&gt;
* [http://www.copacobana.org/ A FPGA-based Codebreaker for DES and other Ciphers]&lt;br /&gt;
* [http://www.cryptography.com/resources/whitepapers/DES-photos.html DEEP Crack - Hardware DES cracking]&lt;br /&gt;
&lt;br /&gt;
[[Category:Encryption]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/DES</id>
		<title>DES</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/DES"/>
				<updated>2007-12-17T16:14:22Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: DES, DeepCrack, Copacobana FPGA DES cracker&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
'''DES''' or '''Data Encryption Standard''' is a cipher selected as an official FIPS (Federal Information Processing Standard) for the U.S.&lt;br /&gt;
&lt;br /&gt;
DES is now considered to be insecure due to the 56-bit key size being too small.&lt;br /&gt;
&lt;br /&gt;
== External Links == &lt;br /&gt;
&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Data_Encryption_Standard Wikipedia article on DES]&lt;br /&gt;
* [http://www.copacobana.org/ - A FPGA-based Codebreaker for DES and other Ciphers]&lt;br /&gt;
* [http://www.cryptography.com/resources/whitepapers/DES-photos.html - DEEP Crack - Hardware DES cracking]&lt;br /&gt;
&lt;br /&gt;
[[Category:Encryption]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/3DES</id>
		<title>3DES</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/3DES"/>
				<updated>2007-12-17T16:09:03Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Added 3DES&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
'''3DES''' or '''Triple DES''' is a block cipher formed by using the Data Encryption Standard ([[DES]]) cipher three times.&lt;br /&gt;
&lt;br /&gt;
== External Links == &lt;br /&gt;
&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Triple_DES) Wikipedia article on 3DES]&lt;br /&gt;
&lt;br /&gt;
[[Category:Encryption]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/File_Vault</id>
		<title>File Vault</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/File_Vault"/>
				<updated>2007-12-17T15:51:28Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: crypto.nsa.org &amp;quot;VileFault&amp;quot; whitepaper.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;File Vault is the cryptographic file system developed by [http://www.apple.com Apple] and introduced with MacOS 10.3.&lt;br /&gt;
&lt;br /&gt;
File Vault works by storing each user's home directory in an encrypted &amp;quot;[[.sparseimage]]&amp;quot; file. The file is automatically mounted when the user logs in and unmounted when the user logs out. All of the user's files and preferences are stored in this file.  The file's encryption key is stored in the .sparseimage file, but that encryption key is itself encrypted with the user's login password. &lt;br /&gt;
&lt;br /&gt;
There are no known attacks against File Vault other than a brute force attack on the user's password.&lt;br /&gt;
&lt;br /&gt;
As part of the [http://www.apple.com/macosx/features/300.html#security security enhancements] in OS X 10.5 (Leopard) Apple have moved from AES-128 to AES-256 for the encryption used in the disk image.&lt;br /&gt;
&lt;br /&gt;
=== Links ===&lt;br /&gt;
*You can find a good discussion of File Vault's usability shortcomings in [http://www.simson.net/thesis Simson Garfinkel's PhD Thesis].&lt;br /&gt;
*[http://chaosradio.ccc.de/23c3_m4v_1642.html Unlocking FileVault] Talk at [http://events.ccc.de/congress/2006-static/static/2/3/r/23rd_Chaos_Communication_Congress_7c1f.html 23c3] (video)&lt;br /&gt;
*[http://chaosradio.ccc.de/23c3_mp3_1642.html Unlocking FileVault] Talk at [http://events.ccc.de/congress/2006-static/static/2/3/r/23rd_Chaos_Communication_Congress_7c1f.html 23c3] (audio)&lt;br /&gt;
*[http://crypto.nsa.org/vilefault/23C3-VileFault.pdf Unlocking FileVault Whitepaper]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/PGPDisk</id>
		<title>PGPDisk</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/PGPDisk"/>
				<updated>2007-12-17T15:47:12Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: PGPDisk&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''PGPDisk''' or Pretty Good Privacy Whole Disk Encryption is a disk encryption solution from the [http://www.pgp.com PGP Corporation].&lt;br /&gt;
&lt;br /&gt;
It provides transparent whole disk encryption with Pre-Boot authentification for Windows. Also supports MacOS X 10.4 (non-boot disks only).&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.pgp.com/products/wholediskencryption/ PGPDisk Official website]&lt;br /&gt;
&lt;br /&gt;
[[Category:Encryption]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Vnconfig</id>
		<title>Vnconfig</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Vnconfig"/>
				<updated>2007-12-17T15:43:39Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Corrections&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''vnconfig''' is the [[OpenBSD]] vnode disks for file swapping or pseudo file system configuration tool. Supports encrypting the data using the Blowfish cipher before it is written to disk when the -K flag is specified. Use -s to specify a saltfile.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.openbsd.org/ OpenBSD Official website]&lt;br /&gt;
* [http://www.openbsd.org/cgi-bin/man.cgi?query=vnconfig&amp;amp;sektion=8: OpenBSD Manpages: vnconfig(8)]&lt;br /&gt;
&lt;br /&gt;
[[Category:Encryption]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Vnconfig</id>
		<title>Vnconfig</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Vnconfig"/>
				<updated>2007-12-17T15:42:26Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Encrypted svnd&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''vnconfig''' [[OpenBSD]] vnode disks for file swapping or pseudo file system configuration tool. Supports encrypting the data using the Blowfish cipher before it is written to disk when the -K flag is specified. Use -s to specify a saltfile.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.openbsd.org/ OpenBSD Official website]&lt;br /&gt;
* [http://www.openbsd.org/cgi-bin/man.cgi?query=vnconfig&amp;amp;sektion=8: OpenBSD Manpages: vnconfig(8)]&lt;br /&gt;
&lt;br /&gt;
[[Category:Encryption]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/GELI</id>
		<title>GELI</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/GELI"/>
				<updated>2007-12-17T14:30:04Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: GELI&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''GELI''' - [[FreeBSD]] Cryptographic [[GEOM]] class written by Pawel Jakub Dawidek. Supports various ciphers: [[AES]],[[Blowfish]] and [[3DES]].     Supports hidden volumes and Pre-Boot Authentification.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.freebsd.org FreeBSD official website]&lt;br /&gt;
* [http://www.freebsd.org/cgi/man.cgi?query=geli&amp;amp;sektion=8 FreeBSD Manpage: GELI]&lt;br /&gt;
* [http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/disks-encrypting.html - FreeBSD Handbook - Disk Encryption]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/GBDE Wikipedia: GBDE]&lt;br /&gt;
&lt;br /&gt;
[[Category:Encryption]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/GBDE</id>
		<title>GBDE</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/GBDE"/>
				<updated>2007-12-17T14:21:26Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: GBDE&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''GBDE''' - GEOM Based Disk Encryption - is a [[FreeBSD]] block device-layer disk encryption that uses 128-bit [[AES]] designed and implemented by Poul-Henning Kamp and Network Associates Inc.&lt;br /&gt;
&lt;br /&gt;
A more efficient implementation of [[FreeBSD]] [[GEOM]] based Disk Encryption - [[GELI]] was later written later by Pawel Jakub Dawidek.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.freebsd.org FreeBSD official website]&lt;br /&gt;
* [http://phk.freebsd.dk/pubs/bsdcon-03.gbde.paper.pdf GBDE Whitepaper]&lt;br /&gt;
* [http://www.freebsd.org/cgi/man.cgi?query=gbde&amp;amp;apropos=0&amp;amp;sektion=8&amp;amp;manpath=FreeBSD+6.2-RELEASE&amp;amp;format=html FreeBSD Manpage: GBDE]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/GBDE Wikipedia: GBDE]&lt;br /&gt;
&lt;br /&gt;
[[Category:Encryption]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Encryption</id>
		<title>Encryption</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Encryption"/>
				<updated>2007-12-17T14:04:05Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Category&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Encryption''' is a means to obfuscate data an entity wishes to protect to the point it will take a third party considerable time to access (decrypt) it. The methods of encryption vary from substitution ciphers to more modern methods such as digital ciphers which use an algorithm to obfuscate the data. Once the data is encrypted it is then referred to as cipher text.&lt;br /&gt;
&lt;br /&gt;
[[Category:Encryption]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Category:Encryption</id>
		<title>Category:Encryption</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Category:Encryption"/>
				<updated>2007-12-17T14:03:32Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: New page: Encryption is a means to obfuscate data an entity wishes to protect to the point it will take a third party considerable time to access (decrypt) it. The methods of encryption vary from su...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Encryption is a means to obfuscate data an entity wishes to protect to the point it will take a third party considerable time to access (decrypt) it. The methods of encryption vary from substitution ciphers to more modern methods such as digital ciphers which use an algorithm to obfuscate the data. Once the data is encrypted it is then referred to as cipher text.&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Blowfish</id>
		<title>Blowfish</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Blowfish"/>
				<updated>2007-12-17T13:56:34Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Category, bullets for links&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
'''Blowfish''' is a symmetric block cipher designed by [[Bruce Schneier]]. It uses a 64-bit block cipher and a variable-length key (32 bits to 448 bits).&lt;br /&gt;
&lt;br /&gt;
Blowfish is not subject to patents and is freely available for use.&lt;br /&gt;
&lt;br /&gt;
== External Links == &lt;br /&gt;
&lt;br /&gt;
* [http://www.schneier.com/blowfish.html The Blowfish Encryption Algorithm]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Blowfish_(cipher) Wikipedia article on Blowfish]&lt;br /&gt;
&lt;br /&gt;
[[Category:Encryption]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Serpent</id>
		<title>Serpent</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Serpent"/>
				<updated>2007-12-17T13:56:13Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Category, bullets for links&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
'''Serpent''' is an [[encryption]] algorithm designed by Ross Anderson, Eli Biham and Lars Knudsen as a candidate for the Advanced Encryption Standard [[AES]] competition, where it got second place with 59 votes ([[Rijndael]] got 86 votes, and was selected by [[NIST]] as the [[AES]]).&lt;br /&gt;
&lt;br /&gt;
Serpent uses a block size of 128 bits and supports a key size of 128, 192 or 256 bits.&lt;br /&gt;
&lt;br /&gt;
Serpent and Rijndael are somewhat similar. The main difference is that Rijndael has fewer rounds (10, 12 or 14 (depending on key size) compared to 32 for Serpent), hence it is faster. Arguably, Serpent is more secure.&lt;br /&gt;
&lt;br /&gt;
Serpent is available as public domain, and can be freely used by anyone.&lt;br /&gt;
&lt;br /&gt;
== External Links == &lt;br /&gt;
&lt;br /&gt;
* [http://www.cl.cam.ac.uk/~rja14/serpent.html Serpent Cipher Homepage]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Serpent_(cipher) Wikipedia article on Serpent]&lt;br /&gt;
&lt;br /&gt;
[[Category:Encryption]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Twofish</id>
		<title>Twofish</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Twofish"/>
				<updated>2007-12-17T13:55:45Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Category, bullets for links&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
'''Twofish''' is an [[encryption]] algorithm designed designed by [[Bruce Schneier]], John Kelsey, Doug Whiting, David Wagner, Chris Hall, and Niels Ferguson, Eli Biham and Lars Knudsen as a candidate for the Advanced Encryption Standard [[AES]] competition, where it got third place with 31 votes ([[Rijndael]] got 86 votes, and was selected by [[NIST]] as the [[AES]], and [[Serpent]] got 59 votes).&lt;br /&gt;
&lt;br /&gt;
Twofish is a symmetric key block cipher with a block size of 128 bits and key sizes up to 256 bits. It is related to the earlier [[Blowfish]] block cipher, also designed by [[Bruce Schneier]].&lt;br /&gt;
&lt;br /&gt;
== External Links == &lt;br /&gt;
&lt;br /&gt;
* [http://www.schneier.com/twofish.html Twofish Homepage]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Twofish Wikipedia article on Twofish]&lt;br /&gt;
&lt;br /&gt;
[[Category:Encryption]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/CGD</id>
		<title>CGD</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/CGD"/>
				<updated>2007-12-17T13:54:39Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: CGD&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''CGD''' Cryptographic Device Driver - Provides transparent full disk encryption for [[NetBSD]].&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.netbsd.org/ NetBSD Official website]&lt;br /&gt;
* [http://www.netbsd.org/docs/guide/en/chap-cgd.html: NetBSD Documentation]&lt;br /&gt;
&lt;br /&gt;
[[Category:Encryption]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/NetBSD</id>
		<title>NetBSD</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/NetBSD"/>
				<updated>2007-12-17T13:51:29Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: NetBSD, links&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''NetBSD''' is an open source [[Unix]]-like [[operating system]] derived from the original University of California Berkeley's 4.3BSD release via the Networking/2 and 386BSD releases. It is available on many platforms.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.netbsd.org/ Official website]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/NetBSD Wikipedia: NetBSD]&lt;br /&gt;
&lt;br /&gt;
[[Category:Operating systems]]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Twofish</id>
		<title>Twofish</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Twofish"/>
				<updated>2007-12-17T13:45:28Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Introduction, links, relation to Blowfish.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
'''Twofish''' is an [[encryption]] algorithm designed designed by [[Bruce Schneier]], John Kelsey, Doug Whiting, David Wagner, Chris Hall, and Niels Ferguson, Eli Biham and Lars Knudsen as a candidate for the Advanced Encryption Standard [[AES]] competition, where it got third place with 31 votes ([[Rijndael]] got 86 votes, and was selected by [[NIST]] as the [[AES]], and [[Serpent]] got 59 votes).&lt;br /&gt;
&lt;br /&gt;
Twofish is a symmetric key block cipher with a block size of 128 bits and key sizes up to 256 bits. It is related to the earlier [[Blowfish]] block cipher, also designed by [[Bruce Schneier]].&lt;br /&gt;
&lt;br /&gt;
== External Links == &lt;br /&gt;
&lt;br /&gt;
[http://www.schneier.com/twofish.html Twofish Homepage]&lt;br /&gt;
[http://en.wikipedia.org/wiki/Twofish Wikipedia article on Twofish]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Serpent</id>
		<title>Serpent</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Serpent"/>
				<updated>2007-12-17T13:02:01Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Corrections&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
'''Serpent''' is an [[encryption]] algorithm designed by Ross Anderson, Eli Biham and Lars Knudsen as a candidate for the Advanced Encryption Standard [[AES]] competition, where it got second place with 59 votes ([[Rijndael]] got 86 votes, and was selected by [[NIST]] as the [[AES]]).&lt;br /&gt;
&lt;br /&gt;
Serpent uses a block size of 128 bits and supports a key size of 128, 192 or 256 bits.&lt;br /&gt;
&lt;br /&gt;
Serpent and Rijndael are somewhat similar. The main difference is that Rijndael has fewer rounds (10, 12 or 14 (depending on key size) compared to 32 for Serpent), hence it is faster. Arguably, Serpent is more secure.&lt;br /&gt;
&lt;br /&gt;
Serpent is available as public domain, and can be freely used by anyone.&lt;br /&gt;
&lt;br /&gt;
== External Links == &lt;br /&gt;
&lt;br /&gt;
[http://www.cl.cam.ac.uk/~rja14/serpent.html Serpent Cipher Homepage]&lt;br /&gt;
[http://en.wikipedia.org/wiki/Serpent_(cipher) Wikipedia article on Serpent]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Serpent</id>
		<title>Serpent</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Serpent"/>
				<updated>2007-12-17T13:01:14Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Introduction, links. Comparison to Rijndael (AES)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
'''Serpent''' [[encryption]] algorithm designed by Ross Anderson, Eli Biham and Lars Knudsen as a candidate for the Advanced Encryption Standard [[AES]] competition, where it got second place with 59 votes ([[Rijndael]] got 86 votes, and was selected by [[NIST]] as the [[AES]]).&lt;br /&gt;
&lt;br /&gt;
Serpent uses a block size of 128 bits and supports a key size of 128, 192 or 256 bits.&lt;br /&gt;
&lt;br /&gt;
Serpent and Rijndael are somewhat similar. The main difference is that Rijndael has fewer rounds (10, 12 or 14 (depending on key size) compared to 32 for Serpent), hence it is faster. Arguably, Serpent is more secure.&lt;br /&gt;
&lt;br /&gt;
Serpent is available as public domain, and can be freely used by anyone.&lt;br /&gt;
== External Links == &lt;br /&gt;
&lt;br /&gt;
[http://www.cl.cam.ac.uk/~rja14/serpent.html Serpent Cipher Homepage]&lt;br /&gt;
[http://en.wikipedia.org/wiki/Serpent_(cipher) Wikipedia article on Serpent]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Blowfish</id>
		<title>Blowfish</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Blowfish"/>
				<updated>2007-12-17T12:51:36Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Details, Schneier homepage&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
'''Blowfish''' is a symmetric block cipher designed by [[Bruce Schneier]]. It uses a 64-bit block cipher and a variable-length key (32 bits to 448 bits).&lt;br /&gt;
&lt;br /&gt;
Blowfish is not subject to patents and is freely available for use.&lt;br /&gt;
&lt;br /&gt;
== External Links == &lt;br /&gt;
[http://www.schneier.com/blowfish.html The Blowfish Encryption Algorithm]&lt;br /&gt;
[http://en.wikipedia.org/wiki/Blowfish_(cipher) Wikipedia article on Blowfish]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/TrueCrypt</id>
		<title>TrueCrypt</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/TrueCrypt"/>
				<updated>2007-12-17T12:45:16Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Keyfiles, plausible deniability.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''TrueCrypt''' is an open source program to create and mount virtual encrypted disks in [[Windows|Windows Vista/XP/2000]] and Linux. It provides two levels of plausible deniability (hidden values / no signatures to make a distinction from random data), on the fly encryption and supports various encryption algorithms (AES-256, Serpent and Twofish).&lt;br /&gt;
&lt;br /&gt;
== Forensic Acquisition ==&lt;br /&gt;
&lt;br /&gt;
If you encounter a system that has a mounted TrueCrypt drive, it is imperative that you capture the contents of the encrypted drive before shutting down the system. Once the system is shutdown, the contents will be inaccessible unless you have the proper encryption key generated by a user's password. You may also need an additional datafile.&lt;br /&gt;
&lt;br /&gt;
==Attacks==&lt;br /&gt;
The only option for acquiring the content of a TrueCrypt drive is to do a brute-force password guessing attack. [[AccessData|AccessData's]] [[Password Recovery Toolkit]] and Distributed Network Attack ([[DNA]]) can both perform such an attack, but DNA is faster.&lt;br /&gt;
&lt;br /&gt;
TrueCrypt also supports keyfiles (it uses the first 1024 kilobytes of any file, but can also use it's PRNG to generate such keys). It is important to look for anything that might be used as a keyfile (such as a 1024k file on a USB stick).&lt;br /&gt;
&lt;br /&gt;
The existence of a FAT volume may be an indication of the existence of hidden volumes (a hidden volume can only be created within a FAT TrueCrypt volume).&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.truecrypt.org/ Official website]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Blowfish</id>
		<title>Blowfish</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Blowfish"/>
				<updated>2007-12-17T07:37:27Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Added Blowfish&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
Blowfish is a symmetric block cipher designed by [[Bruce Schneier].&lt;br /&gt;
Blowfish is not subject to patents and is free to use by anyone.&lt;br /&gt;
&lt;br /&gt;
== External Links == &lt;br /&gt;
&lt;br /&gt;
[http://en.wikipedia.org/wiki/Blowfish_(cipher) Wikipedia article on Blowfish]&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Full_Disk_Encryption</id>
		<title>Full Disk Encryption</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Full_Disk_Encryption"/>
				<updated>2007-12-17T07:32:49Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Added TrueCrypt, FreeBSD GBDE and GELI, NetBSD CGD, OpenBSD vnconfig and PGPdisk.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Full Disk Encryption''' or '''Whole Disk Encryption''' is a phrase that was coined by [[Seagate]] to describe their encrypting [[hard drive]]. Under such a system, the entire contents of a hard drive are encrypted. This is different from [[Full Volume Encryption]] where only certain partitions are encrypted.&lt;br /&gt;
&lt;br /&gt;
Some examples of full disk encryption:&lt;br /&gt;
&lt;br /&gt;
== Hardware Solutions ==&lt;br /&gt;
&lt;br /&gt;
; Seagate FDE &lt;br /&gt;
: http://www.seagate.com/docs/pdf/marketing/PO-Momentus-FDE.pdf&lt;br /&gt;
&lt;br /&gt;
; Network Appliance (Decru)&lt;br /&gt;
: http://www.netapp.com/ftp/decru-fileshredding.pdf&lt;br /&gt;
: http://www.decru.com/products/pdf/dsEseries.pdf (NetApps DataFort)&lt;br /&gt;
: http://www.decru.com/products/ltkm.htm (Decru Lifetime key Management)&lt;br /&gt;
: http://www.forensicswiki.org/images/6/6f/Securing_Storage_White_Paper.pdf (Decru white paper)&lt;br /&gt;
&lt;br /&gt;
; Jetico BestCrypt&lt;br /&gt;
: http://www.jetico.com/&lt;br /&gt;
&lt;br /&gt;
; beCrypt&lt;br /&gt;
: http://www.becrypt.com/our_products/disk_protect.php&lt;br /&gt;
&lt;br /&gt;
; SecureDoc&lt;br /&gt;
: http://www.smart-cardsys.com/security/securedoc.htm&lt;br /&gt;
&lt;br /&gt;
; Securstar driveCrypt DriveCrypt 4.20 - 1344Bit Hard Disk Encryption&lt;br /&gt;
: http://www.securstar.com/products_drivecryptpp.php&lt;br /&gt;
&lt;br /&gt;
; Eracom Technology DiskProtect&lt;br /&gt;
: http://www.eracom-tech.com/drive_encryption.0.html&lt;br /&gt;
&lt;br /&gt;
; Hitachi Bulk Data Encryption&lt;br /&gt;
: http://www.hitachigst.com/tech/techlib.nsf/techdocs/74D8260832F2F75E862572D7004AE077/$file/bulk_encryption_white_paper.pdf&lt;br /&gt;
&lt;br /&gt;
== Software Solutions ==&lt;br /&gt;
&lt;br /&gt;
; [[TrueCrypt]]&lt;br /&gt;
: Transparent full disk encryption for [[Linux]] and [[Windows]. Supports various [[ciphers]]: [[AES]] (256 bit), [[Serpent]] and [[Twofish]].&lt;br /&gt;
: It provides protection from watermarking and inference attacks (volumes cannot be distinguished from random data).&lt;br /&gt;
: Supports hidden volumes within TrueCrypt volumes (plausible deniability).&lt;br /&gt;
: http://www.truecrypt.org/&lt;br /&gt;
&lt;br /&gt;
; [[GBDE]]&lt;br /&gt;
: [[GEOM]] Based Disk Encryption. Provides transparent full disk and swap encryption for [[FreeBSD]]. Supported  [[ciphers]]: [[AES]] (128 bit).&lt;br /&gt;
: Supports hidden volumes and Pre-Boot Authentification.&lt;br /&gt;
: Since data loss can occur on unexpected shutdowns, GELI is recommended instead of GBDE.&lt;br /&gt;
: http://www.freebsd.org/cgi/man.cgi?query=gbde&amp;amp;apropos=0&amp;amp;sektion=8&amp;amp;manpath=FreeBSD+6.2-RELEASE&amp;amp;format=html&lt;br /&gt;
: http://phk.freebsd.dk/pubs/bsdcon-03.gbde.paper.pdf&lt;br /&gt;
&lt;br /&gt;
; [[GELI]]&lt;br /&gt;
: Cryptographic [[GEOM]] class. Provides transparent full disk encryption for [[FreeBSD]]. Supports various [[ciphers]]: [[AES]], [[Blowfish]] and [[3DES]].&lt;br /&gt;
: Supports hidden volumes and Pre-Boot Authentification.&lt;br /&gt;
: http://www.freebsd.org/cgi/man.cgi?query=geli&amp;amp;sektion=8&lt;br /&gt;
&lt;br /&gt;
; [[CGD]]&lt;br /&gt;
: Cryptographic Device Driver. Provides transparent full disk encryption for [[NetBSD]]. &lt;br /&gt;
: Supports various [[ciphers]]: [[AES]] (128 bit blocksize and accepts 128, 192 or 256 bit keys), [[Blowfish]] (64 bit blocksize and accepts 128 bit keys) and [[3DES]] (uses a 64 bit blocksize and accepts 192 bit keys (only 168 bits are actually used for encryption).&lt;br /&gt;
: http://www.netbsd.org/docs/guide/en/chap-cgd.html&lt;br /&gt;
&lt;br /&gt;
; [[vnconfig]]&lt;br /&gt;
: The -K option of [[OpenBSD]] vnconfig(8) associates and encryption key with the svnd device. Supports saltfiles. Supported [[ciphers]]: [[Blowfish]].&lt;br /&gt;
: http://www.openbsd.org/cgi-bin/man.cgi?query=vnconfig&amp;amp;sektion=8&lt;br /&gt;
&lt;br /&gt;
; [[PGPDisk]]&lt;br /&gt;
: Pretty Good Privacy Whole Disk Encryption provides transparent whole disk encryption with Pre-Boot authentification for [[Windows]]. Also supports [[MacOS]] X 10.4 (non-boot disks only).&lt;br /&gt;
: Can use OpenPGP RFC 2440 keys and X.509 keys for authentification.&lt;br /&gt;
: Supports USB Tokens for authentification.&lt;br /&gt;
: Supported [[ciphers]]: [[AES]] (256 bit keys).&lt;br /&gt;
: http://www.pgp.com/products/wholediskencryption/&lt;br /&gt;
&lt;br /&gt;
; [[BitLocker]]&lt;br /&gt;
: Part of Windows Vista that uses [[AES]] 128 or 256 bit encryption&lt;br /&gt;
&lt;br /&gt;
; [[BitArmor]]&lt;br /&gt;
: http://www.bitarmor.com/&lt;br /&gt;
&lt;br /&gt;
; [[dm-crypt]]&lt;br /&gt;
: Transparent [[file system]] and [[swap]] encryption for [[Linux]] using the Linux 2.6 device mapper. Supports various [[ciphers]] and [[LUKS]] (Linux Unified Key Setup).&lt;br /&gt;
: http://www.saout.de/misc/dm-crypt/&lt;br /&gt;
&lt;br /&gt;
; [[loop-AES]]&lt;br /&gt;
: Transparent [[file system]] and [[swap]] encryption for [[Linux]] using the loopback device and [[AES]].&lt;br /&gt;
: http://sourceforge.net/projects/loop-aes/&lt;br /&gt;
&lt;br /&gt;
; [[SafeGuard Easy]]&lt;br /&gt;
: Certified according to [[Common Criteria]] EAL3 and FIPS 140-2&lt;br /&gt;
: Encryption algorithms supported: [[AES]] (128 and 256 bit) and [[IDEA]] (128 bit)&lt;br /&gt;
: Provides complete [[hard drive]] encryption including the boot disk.&lt;br /&gt;
: http://www.utimaco.us/products&lt;br /&gt;
&lt;br /&gt;
; [[PointSec]]&lt;br /&gt;
: http://www.pointsec.com/&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Cmihai</id>
		<title>User:Cmihai</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Cmihai"/>
				<updated>2007-12-17T06:54:37Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Homepage, license&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Criveti Mihai's homepage: http://unixsadm.blogspot.com/&lt;br /&gt;
Forensic tools: http://unixsadm.blogspot.com/2007/10/digital-forensic-tools-imaging.html&lt;br /&gt;
&lt;br /&gt;
License&lt;br /&gt;
&lt;br /&gt;
I hereby license all my contributions to this wiki (before and after March 19th, 2006) under the [http://creativecommons.org/licenses/by-sa/2.5/ Creative Commons Attribution-ShareAlike 2.5] license.&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/PEiD</id>
		<title>PEiD</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/PEiD"/>
				<updated>2007-12-17T06:49:30Z</updated>
		
		<summary type="html">&lt;p&gt;Cmihai: Website has moved to http://www.peid.info/ - changed URL to reflect this.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
{{Infobox_Software |&lt;br /&gt;
  name = PEiD|&lt;br /&gt;
  maintainer = Jibz, Qwerton, snaker, xineohP |&lt;br /&gt;
  os = {{Windows}} |&lt;br /&gt;
  license = ?? |&lt;br /&gt;
  genre = {{Analysis}} |&lt;br /&gt;
  website = http://www.peid.info/ |&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
PEiD is a GUI-based program that runs under Windows which identifies more than 600 different signatures in PE files. It supports external plugins via it's Plugin Interface.&lt;/div&gt;</summary>
		<author><name>Cmihai</name></author>	</entry>

	</feed>