Difference between pages "Paul Ohm" and "Tools:File Analysis"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
m
 
m (New page: = Open Source Tools = ; file : The file command determines the file type of a given file, depending on its contents and not on e.g. its extension or filename. In order to do that, it ...)
 
Line 1: Line 1:
{{expand}}
+
= Open Source Tools =
  
'[[File:paulohm.jpg|200px|thumb|right|Paul Ohm]] ''Paul Ohm''' is a professor at the University of Colorado Law School. He specializes in computer crime law, information privacy, criminal procedure, and intellectual property. He has also written several papers related to the law and computer forensics.  
+
; [[file]]
 +
: The file command determines the file type of a given file, depending on its contents and not on e.g. its extension or filename. In order to do that, it uses a magic configuration file that identifies filetypes.
  
== External Links ==
+
; [[ldd]]
* [http://paulohm.com/ Official web site]
+
: ...
  
[[Category:People]]
+
; [[ltrace]]
 +
: ...
 +
 
 +
; [[strace]]
 +
: ...
 +
 
 +
; [[strings]]
 +
: Strings will print the strings of printable characters in files. It allows choosing different charactersets (ASCII, UNICODE). It is a quick way to browse through files/partitions/... in order to look for words, filenames, keywords etc.
 +
 
 +
; [[Galleta]]
 +
: Parses cookie files.  http://www.foundstone.com/resources/proddesc/galleta.htm
 +
 
 +
; The [[Open Computer Forensics Architecture]]
 +
: http://ocfa.sourceforge.net/
 +
 
 +
; [[Pasco]]
 +
; Parses '''index.dat'' files. http://www.foundstone.com/resources/proddesc/pasco.htm
 +
 
 +
; [[Rifiuti]]
 +
; Examines the INFO2 file in the Recycle Bin    http://www.foundstone.com/resources/proddesc/rifiuti.htm
 +
 
 +
; [[yim2text]]
 +
; Extracts the 'encrypted' info in yahoo instant messenger log files. http://www.1vs0.com/tools.html
 +
 
 +
; [[Hachoir]]
 +
: determines the file type using file header/footer (hachoir-metadata --type), able to list strings in Unicode (hachoir-grep), etc. Support more than 60 file formats.
 +
 
 +
; [[Cygwin]]
 +
: http://www.cygwin.com/
 +
: Linux like environment for Windows
 +
 
 +
; [[UnxUtils]]
 +
: http://unxutils.sourceforge.net/
 +
: Common unix utilities compiled for a Windows environment.
 +
 
 +
= [[NDA]] and [[scoped distribution]] tools =

Revision as of 23:14, 13 June 2007

Open Source Tools

file
The file command determines the file type of a given file, depending on its contents and not on e.g. its extension or filename. In order to do that, it uses a magic configuration file that identifies filetypes.
ldd
...
ltrace
...
strace
...
strings
Strings will print the strings of printable characters in files. It allows choosing different charactersets (ASCII, UNICODE). It is a quick way to browse through files/partitions/... in order to look for words, filenames, keywords etc.
Galleta
Parses cookie files. http://www.foundstone.com/resources/proddesc/galleta.htm
The Open Computer Forensics Architecture
http://ocfa.sourceforge.net/
Pasco
Parses 'index.dat files. http://www.foundstone.com/resources/proddesc/pasco.htm
Rifiuti
Examines the INFO2 file in the Recycle Bin http://www.foundstone.com/resources/proddesc/rifiuti.htm
yim2text
Extracts the 'encrypted' info in yahoo instant messenger log files. http://www.1vs0.com/tools.html
Hachoir
determines the file type using file header/footer (hachoir-metadata --type), able to list strings in Unicode (hachoir-grep), etc. Support more than 60 file formats.
Cygwin
http://www.cygwin.com/
Linux like environment for Windows
UnxUtils
http://unxutils.sourceforge.net/
Common unix utilities compiled for a Windows environment.

NDA and scoped distribution tools