ILook

From ForensicsWiki
Revision as of 10:53, 31 March 2006 by Uwe Hermann (Talk | contribs)

Jump to: navigation, search

ILook is an all-in-one computer forensics suite currently maintained by the Internal Revenue Service (IRS). It is available free of charge to law enforcement agencies and certain US government agencies. iLook is not available to the general public.

The suite consists of the ILook External Imager (IXimager), an analysis program, and a few utilities. IXimager is a Linux-based custom boot CD that produces forensically authenticatable compressed output. The imager is generated from a licensed copy of iLook. Version 8 is the currently distributed version of iLook.

Features

File Systems Understood

File Search Facilities

  • Lists allocated and unallocated files.
  • Sorts files by type.
  • Searches for keywords.
  • Works with compressed zip files.

Historical Reconstruction

Can it build timelines and search by creation date?

Searching Abilities

  • Searches for keywords.
  • Builds an index.

Hash Databases

Evidence Collection Features

History

  • Originally developed by (NAME), ILook was taken over by the IRS in (YEAR).

License Notes

External Reviews

External Links