Builds a tool for Linux. Coming soon is an "ultra-portable attack box".
File Systems Understood
File Search Facilities
Can it build timelines and search by creation date?
Offers power regex searches.
Can it search? Does it build an index? Can it focus on file types or particular kinds of metadata?
- Uses SHA1, MD5 and CRC.
Can it create hashes of files and/or blocks? Can it compare these hash values to any databases? What sort of hash functions does it use?
Evidence Collection Features
- "Just about everything you do is logged in SMART. You can selectively export these log events into a simple HTML report."
Commercial, although it runs on Linux.
EnCase Homepage - http://www.guidancesoftware.com/lawenforcement/ef_index.asp