Difference between pages "Tools:Visualization" and "Category:Disk imaging"

From Forensics Wiki
(Difference between pages)
Jump to: navigation, search
m (Visualization Toolkits and Libraries)
 
(Unix-based imagers)
 
Line 1: Line 1:
Although not strictly for forensic purposes, '''visualization tools''' such as the ones discussed here can be very useful for visualizing large data sets. As forensic practitioners need to process more and more data, it is likely that some of the techniques implemented by these tools will need to be adopted.
+
<div style="margin-top:0.5em; border:2px solid #ff0000; padding:0.5em 0.5em 0.5em 0.5em; background-color:#dddddd; align:center;">
 +
'''Note:''' We're trying to use the same [[tool template]] for all devices. Please use this if possible.
 +
</div>
  
== Open Source ==
+
'''TODO: Not all of the following are tools, most are simply company names. The tools should have their own articles...'''
=== Visualization Toolkits and Libraries ===
+
* [http://csbi.sourceforge.net/index.html Graph Interface Library (GINY)] - Java
+
* [http://www.gravisto.org/ Gravisto: Graph Visualization Toolkit] - An editor and toolkit for developing graph visualization algorithms.
+
* [http://ivtk.sourceforge.net/ InfoViz Toolkit] - Java, originally developed at [[INRA]].
+
* [http://jgrapht.sourceforge.net/ JGraphT] - A Java visualization kit designed to be simple and extensible.
+
* [http://www.softwaresecretweapons.com/jspwiki/Wiki.jsp?page=LinguineMaps Linguine Maps] - An open-source Java-based system for visualizing software call maps.
+
* [http://prefuse.sourceforge.net/ Perfuse] - A Java-based toolkit for building interactive information visualization applications
+
* [http://www.gnu.frb.br:8080/rox Rox Graph Theory Framework] - An open-source plug-in framework for graph theory visualization.
+
* [http://touchgraph.sourceforge.net/ TouchGraph] - Library for building graph-based interfaces.
+
* [http://www.ssec.wisc.edu/~billh/visad.html#intro VisAD] - A Java component library for interactive and collaborative visualization.
+
* [http://public.kitware.com/VTK/ The Visualization Toolkit] - C++ multi-platform with interfaces available for Tcl/Tk, Java and Python. Professional support provided by [http://www.kitware.com/ Kitware].
+
* [http://zvtm.sourceforge.net/index.html Zoomable Visual Transformation Machine] - Java. Originally started at Xerox Research Europe.
+
* [http://processing.org/ Processing.org] - A new language for doing graphics and visualization.
+
  
===Graph Drawing Applications===
+
= Hardware imagers =
* [http://www.graphviz.org/ Graphviz] - Originally developed by the [http://public.research.att.com/areas/visualization/ AT&T Information Visualization Gorup], designed for drawing connected graphs of nodes and edges. Neato is a similar system but does layout based on a spring model. Can produce output as [[PostScript]], [[PNG]], [[GIF]], or as an annotated graph file with the locations of all of the objects &mdash; ideal for drawing in a GUI. Runs from the command line on [[Unix]], [[Windows]] and [[Mac]], although there is also a [http://www.pixelglow.com/graphviz/ MacOS GUI version].
+
;[[Data Compass]]
* [http://graphexploration.cond.org/ Guess: The Graph Exploration System] - Originally developed at HP, this is a large Jython/Java-based system that you can use for building your own applications. Distributed under GPL.
+
:A hardware and software tool by [[SalvationDATA]] that can image data from bad sectors, unstable heads and other drives.
 +
; [[DeepSpar Disk Imager]]
 +
: Handles Data Recovery Imaging issues, drive instability, and bad sectors. http://www.deepspar.com/products-ds-disk-imager.html  - Data Sheet and Whitepaper available for download from product web page.
 +
; [[ICS Solo3]]
 +
: Supports USB, Firewire and SCSI drives. http://www.icsforensic.com/
 +
; [[Logicube Talon]]
 +
: Supports USB
 +
; [[PSIClone]]
 +
: Built-in PATA, SATA, USB and write blocker. http://www.thepsiclone.com/
 +
: Enhanced Error Handling and Logging
 +
; [[Voom HardCopy III]]
 +
: Allows destination drive to be formatted in NTFS.
  
; [http://hypergraph.sourceforge.net/ HyperGraph]
+
= Unix-based imagers=
: Hyperbolic trees, in Java. Check out the home page. Try clicking on the logo...
+
  
; [http://sourceforge.net/projects/ivc/ InfoVis Cyberinfrastructure]
+
; '''ewfacquire''', '''ewfacquirestream'''
: Another graph drawing system written in Java.
+
: The tools '''ewfacquire''' and '''ewfacquiresteam''' are part of the [[libewf]] library package. They can create evidence files in the [[EnCase]] and [[FTK Imager]] .E0* (EWF-E01) and [[SMART]] .s0* (EWF-S01) formats. '''ewfacquire''' is intended to read from devices and '''ewfacquirestream''' from pipes. Both tools calculate an [[MD5]] hash on default while the data is being acquired. They are able to calculate a [[SHA1]] message digest as well, but because of compatibility with [[EnCase]] they only store the [[SHA1]] hash in the Extended EWF (EWF-X) format. '''ewfacquire''' and '''ewfacquirestream''' provide support for byte swapping of media bytes. This is useful for dealing with big endian media on and little endian architectures and vice versa. It also has intelligent error recovery.
 +
: http://code.google.com/p/libewf/
  
; [https://jdigraph.dev.java.net/ Jdigrah]
+
; [[Adepto]]
: Java Directed Graphs.
+
: http://www.e-fense.com/helix/
  
; [http://bioinformatics.icmb.utexas.edu/lgl/ Large Graph Layout (LGL)]
+
; [[aimage]]
: A bioinformatics system from University of Texas. They really mean Large.
+
: Part of the [[AFF]] system, [[aimage]] can create files is raw, AFF, AFD, or AFM formats. AFF and AFD formats can be compressed or uncompressed. [[aimage]]  can optionally compress and calculate [[MD5]] or [[SHA-1]] hash residues while the data is being copied. It has intelligent error recovery, similar to what is in [[ddrescue]].
  
; [http://www.opendx.org/ OpenDX]
+
; [[AIR]]
: Based on [[IBM]]'s Visualization Data Explorer, runs on [[Unix]]/X11/Motif.
+
: AIR (Automated Image and Restore) is a GUI front-end to dd/dcfldd designed for easily creating forensic bit images.
 +
: http://air-imager.sourceforge.net/
  
; [http://jung.sourceforge.net/ Java Universal Network/Graph Framework (JUNG)]
+
; [[dcfldd]]
: Graphing, [[data mining]], [[social network]] analysis, and other stuff.
+
: A version of [[dd]] created by the [[Digital Computer Forensics Laboratory]]. [[dcfldd]] is an enhanced version of [[GNU]] dd with features useful for forensics and security, such as calculating [[MD5]] or [[SHA-1]] [[hash]]es on the fly and faster disk wiping.
  
; [http://web.mit.edu/bshi/Public/nv2d/ NetVis 2D]
+
; [[dd]]
: Another graph visualization and layout tool written in Java.
+
: A program that converts and copies files, is one of the oldest [[Unix]] programs. I can copy data from any Unix "file" (including a [[raw partition]]) to any other Unix "file" (including a disk file or a raw partition). This is one of the oldest of the imaging tools, and produces [[raw image files]]. Extended into [[dcfldd]].
  
; [http://sourceforge.net/projects/sonia/ Social Network Image Automater (SoNIA)]  
+
; EnCase [[LinEn]]
: Originally developed at Stanford. Written in Java.
+
: Linux-based version of EnCase's forensic imaging tool.
  
; [http://www.informatik.uni-bremen.de/uDrawGraph/en/uDrawGraph/uDrawGraph.html uDrawGraph]
+
; GNU [[ddrescue]]
 +
: http://www.gnu.org/software/ddrescue/ddrescue.html
  
; [http://www.wilmascope.org/ WilmaScope]
+
; [[dd_rescue]]
: Real-time animations of dynamic graph structures. Written in Java. Sophisticated force model with strings and attraction.
+
: http://www.garloff.de/kurt/linux/ddrescue/
 +
: A tool similar to [[dd]], but unlike dd it will continue reading the next sector, if it stumbles over bad sectors it cannot read.
  
; [http://www.caida.org/tools/visualization/walrus/ Walrus]
+
; iLook [[IXimager]]
: A 3-d graph network exploration tool. Employs 3D hyperbolic displays and layout based on a user-supplied spanning tree.
+
: The primary imaging tool for [[iLook]]. It is [[Linux]] based and produces compressed authenticatable [[image file]]s that may only be read in the iLook analysis tool.
  
== Geographical Drawing Programs ==
+
; [[MacQuisition Boot CD]]
 +
: Provides software to safely image [[Macintosh]] drives.
  
; [http://openmap.bbn.com/ OpenMap]
+
; [[rdd]]
: From [[BBN]].
+
: http://sourceforge.net/projects/rdd
 +
: Rdd is robust with respect to read errors and incorporates several other functions: MD5 and SHA-1 hashing, block hashing, entropy computation, checksumming, network transfer, and output splitting.
  
== Commercial Tools ==
+
; [[sdd]]
 +
: Another [[dd]]-like tool. It is supposed to be faster in certain situations.
  
; [http://www.aisee.com/ aiSee Graph Layout Software]
+
= Windows-based imagers =
: Supports 15 layout algorithms, recursive graph nesting, and easy printing. Runs on [[Windows]], [[Linux]], [[Solaris]], [[NetBSD]], and [[MacOS]]. 30-day trial and free registered versions available. Academic pricing available.
+
  
; [http://www.geomantics.com/ Geomantics]
+
; [[AccessData]]
: Geographical, Visualization and Graphics software. Runs on [[Windows]].
+
: Their ultimate tool lets you "READ, ACQUIRE, DECRYPT, ANALYZE and REPORT (R.A.D.A.R.)."
  
; [http://www.kylebank.com/ Graphis 2D and 3D graphing software]
+
; [[ASR]]
: Runs on [[Windows]]. Free 30-day evaluation copy available.
+
: A tool for [[imaging]] and analyzing disks.
  
; [http://www.openviz.com/ OpenViz] and  [http://www.powerviz.com/ PowerViz]
+
; [[DIBS]]
: Both from Advanced Visual Systems, super high-end visualization toolkits. $$$$
+
: Can image and convert many file formats. Also builds mobile toolkit.
  
; [http://www.tomsawyer.com/ Tom Sawyer Software] Analysis, Visualizaiton, and Layout programs.
+
; [[EnCase]]
: Heavy support for drawing graphs. Beautiful gallery. ActiveX, Java, C++ and .NET editions.
+
: Can image with out dongle plugged in. Only images to E0* file.
  
= Other Resources =
+
; [[FTK Imager]] by [[AccessData]]
 +
: Can image and convert many image formats. Including [[E0*]] (EWF-E01), s0* (EWF-S01) and [[dd]]. Also a free tool.
  
; [http://www.palgrave-journals.com/ivs/index.html Information Visualization Journal]
+
; [[Ghost]]
 +
: FTK can read forensic, uncompressed [[Ghost image]]s.
  
; [http://www-static.cc.gatech.edu/gvu/ii/resources/infovis.html GVU's Information Visualization Resources link farm]
+
; [[iLook]]
 +
: The [[IRS]]'s set of forensic tools and utilities.  iLook V8 can image in Windows.
  
; [http://www.msi.umn.edu/user_support/scivis/scivis-list.html Scientific Visualization at the Supercomputing Institute]
+
; [[Paraben]]
 +
: A complete set of tools for [[Windows]] (and [[handheld]]) products.
  
; [http://directory.google.com/Top/Science/Math/Combinatorics/Software/Graph_Drawing/ Google Directory of Graph Drawing Software]
+
; [[ProDiscovery]]
 +
: Images and searches [[FAT12]], [[FAT16]], [[FAT32]] and all [[NTFS]] files.
  
; [http://rw4.cs.uni-sb.de/~diehl/softvis/seminar/index.php?goto=seminar ACM Symposium on Software Visualization]
+
; [[X-Ways Forensics]]  
: May give you some ideas.
+
: Has some limited imaging capabilities. The output is [[raw format]].
  
; [http://directory.fsf.org/science/visual/ GNU Free Software directory of scientific visualization software]
+
; [[X-Ways Replica]]
 +
: Performs [[hard disk]] [[cloning]] and imaging. The output is [[raw format]].
  
; [http://www.cs.brown.edu/people/rt/gd.html Roberto Tamassia's resources on Graph Drawing]
 
  
; [http://www.manageability.org/blog/stuff/open-source-graph-network-visualization-in-java/view Open Source Graph Network Visualization in Java]
+
[[Category:Tools]]
 +
 
 +
[[Category:Tools]]

Revision as of 14:25, 17 September 2012

Note: We're trying to use the same tool template for all devices. Please use this if possible.

TODO: Not all of the following are tools, most are simply company names. The tools should have their own articles...

Hardware imagers

Data Compass
A hardware and software tool by SalvationDATA that can image data from bad sectors, unstable heads and other drives.
DeepSpar Disk Imager
Handles Data Recovery Imaging issues, drive instability, and bad sectors. http://www.deepspar.com/products-ds-disk-imager.html - Data Sheet and Whitepaper available for download from product web page.
ICS Solo3
Supports USB, Firewire and SCSI drives. http://www.icsforensic.com/
Logicube Talon
Supports USB
PSIClone
Built-in PATA, SATA, USB and write blocker. http://www.thepsiclone.com/
Enhanced Error Handling and Logging
Voom HardCopy III
Allows destination drive to be formatted in NTFS.

Unix-based imagers

ewfacquire, ewfacquirestream
The tools ewfacquire and ewfacquiresteam are part of the libewf library package. They can create evidence files in the EnCase and FTK Imager .E0* (EWF-E01) and SMART .s0* (EWF-S01) formats. ewfacquire is intended to read from devices and ewfacquirestream from pipes. Both tools calculate an MD5 hash on default while the data is being acquired. They are able to calculate a SHA1 message digest as well, but because of compatibility with EnCase they only store the SHA1 hash in the Extended EWF (EWF-X) format. ewfacquire and ewfacquirestream provide support for byte swapping of media bytes. This is useful for dealing with big endian media on and little endian architectures and vice versa. It also has intelligent error recovery.
http://code.google.com/p/libewf/
Adepto
http://www.e-fense.com/helix/
aimage
Part of the AFF system, aimage can create files is raw, AFF, AFD, or AFM formats. AFF and AFD formats can be compressed or uncompressed. aimage can optionally compress and calculate MD5 or SHA-1 hash residues while the data is being copied. It has intelligent error recovery, similar to what is in ddrescue.
AIR
AIR (Automated Image and Restore) is a GUI front-end to dd/dcfldd designed for easily creating forensic bit images.
http://air-imager.sourceforge.net/
dcfldd
A version of dd created by the Digital Computer Forensics Laboratory. dcfldd is an enhanced version of GNU dd with features useful for forensics and security, such as calculating MD5 or SHA-1 hashes on the fly and faster disk wiping.
dd
A program that converts and copies files, is one of the oldest Unix programs. I can copy data from any Unix "file" (including a raw partition) to any other Unix "file" (including a disk file or a raw partition). This is one of the oldest of the imaging tools, and produces raw image files. Extended into dcfldd.
EnCase LinEn
Linux-based version of EnCase's forensic imaging tool.
GNU ddrescue
http://www.gnu.org/software/ddrescue/ddrescue.html
dd_rescue
http://www.garloff.de/kurt/linux/ddrescue/
A tool similar to dd, but unlike dd it will continue reading the next sector, if it stumbles over bad sectors it cannot read.
iLook IXimager
The primary imaging tool for iLook. It is Linux based and produces compressed authenticatable image files that may only be read in the iLook analysis tool.
MacQuisition Boot CD
Provides software to safely image Macintosh drives.
rdd
http://sourceforge.net/projects/rdd
Rdd is robust with respect to read errors and incorporates several other functions: MD5 and SHA-1 hashing, block hashing, entropy computation, checksumming, network transfer, and output splitting.
sdd
Another dd-like tool. It is supposed to be faster in certain situations.

Windows-based imagers

AccessData
Their ultimate tool lets you "READ, ACQUIRE, DECRYPT, ANALYZE and REPORT (R.A.D.A.R.)."
ASR
A tool for imaging and analyzing disks.
DIBS
Can image and convert many file formats. Also builds mobile toolkit.
EnCase
Can image with out dongle plugged in. Only images to E0* file.
FTK Imager by AccessData
Can image and convert many image formats. Including E0* (EWF-E01), s0* (EWF-S01) and dd. Also a free tool.
Ghost
FTK can read forensic, uncompressed Ghost images.
iLook
The IRS's set of forensic tools and utilities. iLook V8 can image in Windows.
Paraben
A complete set of tools for Windows (and handheld) products.
ProDiscovery
Images and searches FAT12, FAT16, FAT32 and all NTFS files.
X-Ways Forensics
Has some limited imaging capabilities. The output is raw format.
X-Ways Replica
Performs hard disk cloning and imaging. The output is raw format.