Difference between revisions of "P2PMarshal"

From Forensics Wiki
Jump to: navigation, search
m (Fix typo)
m (typo)
 
(One intermediate revision by one user not shown)
Line 4: Line 4:
 
   os = {{Windows}} |
 
   os = {{Windows}} |
 
   genre = {{File forensics}} |
 
   genre = {{File forensics}} |
   license = Commercial (free to law enforcement) |
+
   license = Commercial (free to US law enforcement) |
 
   website = [http://p2pmarshal.com p2pmarshal.com] |
 
   website = [http://p2pmarshal.com p2pmarshal.com] |
 
}}
 
}}
Line 10: Line 10:
 
P2P Marshal is a program that helps an investigator discover and analyze [[file sharing]] software on a disk.
 
P2P Marshal is a program that helps an investigator discover and analyze [[file sharing]] software on a disk.
  
P2P Marshal operates on a logically mounted drive (i.e., a restored image of a disk, mounted as D:, E:, etc.) or a subdirectory (e.g., unzipped or untarred archive).  It is designed to run under Windows, though as a Java-based program, it should be able to run on other platforms.
+
The Forensic Edition of P2P Marshal operates on a logically mounted drive (i.e., a restored image of a disk, mounted as D:, E:, etc. or with Mount Image Pro, EnCase's Physical Disk Emulator, or similar).  The Field Edition can also analyze a live computer's diskP2P Marshal is designed to run under Windows, though as a Java-based program, it should be able to run on other platforms.  
  
 
When run, it first detects the presence of P2P client programs.  Then, for each program detected, it presents various information, such as downloaded and shared files, peer servers, and log messages.  For some clients, additional  information may be displayed, such as host ID numbers, total runtime, and other parameters tracked by the client.  P2P Marshal displays the information either on a per-user basis or for all users.  It also provides an extensive search capability, produces customizable summary reports in PDF, HTML, and RTF formats, and maintains an audit log of all actions performed by the investigator.
 
When run, it first detects the presence of P2P client programs.  Then, for each program detected, it presents various information, such as downloaded and shared files, peer servers, and log messages.  For some clients, additional  information may be displayed, such as host ID numbers, total runtime, and other parameters tracked by the client.  P2P Marshal displays the information either on a per-user basis or for all users.  It also provides an extensive search capability, produces customizable summary reports in PDF, HTML, and RTF formats, and maintains an audit log of all actions performed by the investigator.
  
It currently supports LimeWire and several BitTorrent clients, Ares, and Hello, and detects the presence of KaZaA.
+
The Forensic Edition must be installed on a computer; the Field Edition runs from a USB drive.  
  
As of January 2008, the 1.0 will be available at no cost to US law enforcement, with a commercial version available to non-law enforcement.
+
It currently supports LimeWire and several BitTorrent clients, and Ares, and detects the presence of KaZaA.
 +
 
 +
As of March 2010, the 2.1.1 version is current.  The Forensic Edition of P2P Marshal is available to US law enforcement at no cost.  ATC-NY distributes the tools to US law enforcement and for educational use.  Cyber Security Technology distributes the tool commercially.
  
 
=Authors=
 
=Authors=
P2P Marhsal was developed by ATC-NY through a US National Institute of Justice (NIJ) grant.  The project was originally named File Marshal.  
+
P2P Marshal was developed by ATC-NY through a US National Institute of Justice (NIJ) grant.  The project was originally named File Marshal.  
  
 
= External Links =  
 
= External Links =  

Latest revision as of 23:03, 15 March 2010

P2P Marshal
Maintainer: ATC-NY
OS: Windows
Genre: Template:File forensics
License: Commercial (free to US law enforcement)
Website: p2pmarshal.com

P2P Marshal is a program that helps an investigator discover and analyze file sharing software on a disk.

The Forensic Edition of P2P Marshal operates on a logically mounted drive (i.e., a restored image of a disk, mounted as D:, E:, etc. or with Mount Image Pro, EnCase's Physical Disk Emulator, or similar). The Field Edition can also analyze a live computer's disk. P2P Marshal is designed to run under Windows, though as a Java-based program, it should be able to run on other platforms.

When run, it first detects the presence of P2P client programs. Then, for each program detected, it presents various information, such as downloaded and shared files, peer servers, and log messages. For some clients, additional information may be displayed, such as host ID numbers, total runtime, and other parameters tracked by the client. P2P Marshal displays the information either on a per-user basis or for all users. It also provides an extensive search capability, produces customizable summary reports in PDF, HTML, and RTF formats, and maintains an audit log of all actions performed by the investigator.

The Forensic Edition must be installed on a computer; the Field Edition runs from a USB drive.

It currently supports LimeWire and several BitTorrent clients, and Ares, and detects the presence of KaZaA.

As of March 2010, the 2.1.1 version is current. The Forensic Edition of P2P Marshal is available to US law enforcement at no cost. ATC-NY distributes the tools to US law enforcement and for educational use. Cyber Security Technology distributes the tool commercially.

Authors

P2P Marshal was developed by ATC-NY through a US National Institute of Justice (NIJ) grant. The project was originally named File Marshal.

External Links