ForensicsWiki will continue to operate as it has before and will not be shutting down. There may be some minor outages as we transition the site to new hardware, but we will try to minimize this as much as possible. Thank you for your continued support of ForensicsWiki.

Jesse Kornblum

From ForensicsWiki
Revision as of 12:08, 17 March 2008 by Jessek (Talk | contribs) (Added hashdeep)

Jump to: navigation, search

Jesse Kornblum is a computer forensics author, researcher and engineer. You can read more about him in his Wikipedia entry or his official web site. His Curriculum Vitae has a current list of his papers. He current works for ManTech.

Tools

md5deep and hashdeep - Cross platform recursive hashing program. Computes MD5, SHA-1, SHA-256, Tiger and Whirlpool hashes. Can also match against sets of known hashes. The latter program uses multihashing to conduct a computer forensics audit.

foremost - File carving program

ssdeep - Usually called Fuzzy Hashing, this program implements Context Triggered Piecewise Hashing.

FRED - The First Responder's Evidence Disk

dc3dd - A patch to add forensics features to GNU dd