ATTENTION: The new home of the Digital Forensics Wiki is at https://forensicswiki.xyz/. Yeah, it's a silly name, but it was cheap.
This wiki will be going offline permanently in the near future. An exact date will be announced soon. Thank you for being a part of this community.
If you wish to work on the new forensicswiki, please join the Google Group forensicswiki-reborn
Difference between revisions of "Jesse Kornblum"
|(4 intermediate revisions by 2 users not shown)|
|Line 1:||Line 1:|
Jesse Kornblum is a computer forensics author, researcher and engineer. You can read
Jesse Kornblum is a computer forensics author, researcher and engineer. You can read his [http://jessekornblum.com/ official web site]. His [http://jessekornblum.com/kornblum-cv.pdf Curriculum Vitae] has a current list of his papers.
== Tools ==
== Tools ==
Latest revision as of 14:08, 9 November 2012
md5deep and hashdeep - Cross platform recursive hashing and auditing programs, respectively. Computes MD5, SHA-1, SHA-256, Tiger and Whirlpool hashes. Can also match against sets of known hashes. The latter program uses multihashing to conduct a computer forensics audit.
FRED - The First Responder's Evidence Disk
Miss Identify - Program to identify Win32 executables that don't have an executable extension. Can also identify all executables.