Difference between pages "Tools:Visualization" and "Tools:Data Recovery"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
m (Research Groups)
 
(Carving)
 
Line 1: Line 1:
Although not strictly for forensic purposes, '''visualization tools''' such as the ones discussed here can be very useful for visualizing large data sets. As forensic practitioners need to process more and more data, it is likely that some of the techniques implemented by these tools will need to be adopted.
+
= Partition Recovery =
  
==Programming Languages and Developer Toolkits==
+
*[http://www.ptdd.com/index.htm Partition Table Doctor]
If you are building forensic tools, you probably want to start with one of these:
+
: Recover deleted or lost partitions (FAT16/FAT32/NTFS/NTFS5/EXT2/EXT3/SWAP).
; Java and Swing
+
: Advantage: Portable and lots of good documentation out there.
+
: Disadvantage: Programs are a bit verbose, and only offers about 1/2 the performance of C
+
  
; Python with tkinter
+
*[http://www.diskinternals.com/ntfs-recovery/ NTFS Recovery]
: Advantage: Portable
+
: DiskInternals NTFS Recovery is a fully automatic utility that recovers data from damaged or formatted disks.
: Disadvantage: Python is one of the slowest modern languages around.
+
  
; Python with wxWidgets
+
*[http://www.stud.uni-hannover.de/user/76201/gpart/ gpart]
: Advantage: Portable and a better development environment than tkiner
+
: Gpart is a tool which tries to guess the primary partition table of a PC-type hard disk in case the primary partition table in sector 0 is damaged, incorrect or deleted.
: Disadvantage: wxWidgets is not installed by default, so you'll need to get it installed. Not as well documented as Tkinter
+
  
; processing.org
+
*[http://www.cgsecurity.org/wiki/TestDisk TestDisk]
: Advantage: Programming language specifically developed for visualization; compiles to java byte code
+
: [[TestDisk]] is an OpenSource software and is licensed under the GNU Public License (GPL).
: Disadvantage: Very oddball
+
  
; JavaFX - Java's version of Flash
+
*[http://www.stellarinfo.com/partition-recovery.htm Partition Recovery Software]
 +
: Partition Recovery software for NTFS & FAT system that examines lost windows partition of damaged and corrupted hard drive.
  
; Flash
+
== See Also ==
  
 +
* [http://support.microsoft.com/?kbid=166997 Using Norton Disk Edit to Backup Your Master Boot Record]
  
 +
== Notes ==
  
== Open Source ==
+
* "fdisk /mbr" restores the boot code in the [[Master Boot Record]], but not the partition itself. On newer versions of Windows you should use fixmbr, bootrec, mbrfix, or [[MBRWizard]]. You can also extract a copy of the specific standard MBR code from tools like bootrec.exe and diskpart.exe in Windows (from various offsets) and copy it to disk with dd (Use bs=446 count=1). For Windows XP SP2 c:\%WINDIR%\System32\diskpart.exe the MBR code is found between offset 1b818h and 1ba17h.
=== Visualization Toolkits and Libraries ===
+
* [http://csbi.sourceforge.net/index.html Graph Interface Library (GINY)] - Java
+
* [http://www.gravisto.org/ Gravisto: Graph Visualization Toolkit] - An editor and toolkit for developing graph visualization algorithms.
+
*  [http://hypergraph.sourceforge.net/ HyperGraph] - Hyperbolic trees, in Java. Check out the home page. Try clicking on the logo...
+
* [http://ivtk.sourceforge.net/ InfoViz Toolkit] - Java, originally developed at [[INRA]].
+
* [https://jdigraph.dev.java.net/ Jdigrah] - Java Directed Graphs.
+
* [http://jgrapht.sourceforge.net/ JGraphT] - A Java visualization kit designed to be simple and extensible.  
+
* [http://www.softwaresecretweapons.com/jspwiki/Wiki.jsp?page=LinguineMaps Linguine Maps] - An open-source Java-based system for visualizing software call maps.
+
* [http://prefuse.sourceforge.net/ Perfuse] - A Java-based toolkit for building interactive information visualization applications
+
* [http://www.gnu.frb.br:8080/rox Rox Graph Theory Framework] - An open-source plug-in framework for graph theory visualization.
+
* [http://touchgraph.sourceforge.net/ TouchGraph] - Library for building graph-based interfaces.
+
* [http://www.ssec.wisc.edu/~billh/visad.html#intro VisAD] - A Java component library for interactive and collaborative visualization.
+
* [http://public.kitware.com/VTK/ The Visualization Toolkit] - C++ multi-platform with interfaces available for Tcl/Tk, Java and Python. Professional support provided by [http://www.kitware.com/ Kitware].
+
* [http://zvtm.sourceforge.net/index.html Zoomable Visual Transformation Machine] - Java. Originally started at Xerox Research Europe.
+
* [http://processing.org/ Processing.org] - A new language for doing graphics and visualization.
+
  
====Tree Maps====
+
= Data Recovery =
[http://www.cs.umd.edu/hcil/treemap-history/index.shtml Treemaps] are a visualization technique developed at the University of Maryland for visualizing large amounts of multi-dimensional data. There is a GPLed implementation of treemaps written in C. You can find a copy of in it:
+
The term "Data Recovery" is frequently used to mean forensic recovery, but the term really should be used for recovering data from damaged media.  
* [http://www.derlien.com/ Disk Inventory X]
+
* [http://kdirstat.sourceforge.net/ KDirStat]
+
  
===Graph Drawing Applications===
+
*[http://www.salvationdata.com/data-recovery-equipment/hd-doctor.htm HD Doctor Suite]
* [http://www.graphviz.org/ Graphviz] - Originally developed by the [http://public.research.att.com/areas/visualization/ AT&T Information Visualization Gorup], designed for drawing connected graphs of nodes and edges. Neato is a similar system but does layout based on a spring model. Can produce output as [[PostScript]], [[PNG]], [[GIF]], or as an annotated graph file with the locations of all of the objects — ideal for drawing in a GUI. Runs from the command line on [[Unix]], [[Windows]] and [[Mac]], although there is also a [http://www.pixelglow.com/graphviz/ MacOS GUI version].
+
: HD Doctor Suite is a set of professional tools used to fix firmware problem
* [http://graphexploration.cond.org/ Guess: The Graph Exploration System] - Originally developed at HP, this is a large Jython/Java-based system that you can use for building your own applications. Distributed under GPL.
+
* [http://sourceforge.net/projects/ivc/ InfoVis Cyberinfrastructure] - Another graph drawing system written in Java.
+
* [http://jung.sourceforge.net/ Java Universal Network/Graph Framework (JUNG)] - Graphing, [[data mining]], [[social network]] analysis, and other stuff.
+
* [http://www.andrew.cmu.edu/user/krack/krackplot.shtml Krackplot] - "KrackPlot is a program for network visualization designed for social network analysts."
+
* [http://bioinformatics.icmb.utexas.edu/lgl/ Large Graph Layout (LGL)] - A bioinformatics system from University of Texas. They really mean Large.
+
* [http://www.sfu.ca/~richards/Multinet/Pages/multinet.htm MultiNet] - A data analysis package for drawing conventional data and graph data.
+
* [http://www.analytictech.com/netdraw.htm NetDraw] - "a free program written by Steve Borgatti for visualizing both 1-mode and 2-mode social network data."
+
* [http://web.mit.edu/bshi/Public/nv2d/ NetVis 2D] - Another graph visualization and layout tool written in Java.
+
* [http://www.opendx.org/ OpenDX] - Based on [[IBM]]'s Visualization Data Explorer, runs on [[Unix]]/X11/Motif.
+
* [http://vlado.fmf.uni-lj.si/pub/networks/pajek/ Pajek] - Windows program for drawing large networks.
+
* [http://sourceforge.net/projects/sonia/ Social Network Image Animator (SoNIA)] - Originally developed at Stanford. Written in Java. Makes movies.
+
* [http://www.informatik.uni-bremen.de/uDrawGraph/en/uDrawGraph/uDrawGraph.html uDrawGraph]
+
* [http://wilma.sourceforge.net/ WilmaScope] - Real-time animations of dynamic graph structures. Written in Java. Sophisticated force model with strings and attraction.
+
* [http://www.caida.org/tools/visualization/walrus/ Walrus] - A 3-d graph network exploration tool. Employs 3D hyperbolic displays and layout based on a user-supplied spanning tree.
+
  
== Geographical Drawing Programs ==
+
*[http://www.salvationdata.com SalvationDATA]
 +
: Claims to have a program that can read the "bad blocks" of Maxtor drives with proprietary commands.
  
* [http://openmap.bbn.com/ OpenMap] -- From [[BBN]].
+
*[http://www.toolsthatwork.com/bringback.htm BringBack]  
 +
: BringBack offers easy to use, inexpensive, and highly successful data recovery for Windows and Linux (ext2) operating systems and digital images stored on memory cards, etc.
  
== Commercial Tools ==
+
*[http://www.runtime.org/raid.htm RAID Reconstructor]
 +
: Runtime Software's RAID Reconstructor will reconstruct RAID Level 0 (Striping) and RAID Level 5 drives.
  
* [http://www.aisee.com/ aiSee Graph Layout Software] - Supports 15 layout algorithms, recursive graph nesting, and easy printing. Runs on [[Windows]], [[Linux]], [[Solaris]], [[NetBSD]], and [[MacOS]]. 30-day trial and free registered versions available. Academic pricing available.
+
* [http://www.e-rol.com/en/ e-ROL]
*  [http://www.geomantics.com/ Geomantics] - Geographical, Visualization and Graphics software. Runs on [[Windows]].
+
: Erol allows you to recover through the internet files erased by mistake. Recover your files online for free.
* [http://www.kylebank.com/ Graphis 2D and 3D graphing software] - Runs on [[Windows]]. Free 30-day evaluation copy available.
+
* [http://www.openviz.com/ OpenViz] and  [http://www.powerviz.com/ PowerViz] - Both from Advanced Visual Systems, super high-end visualization toolkits. $$$$
+
* [http://www.tomsawyer.com/ Tom Sawyer Software] Analysis, Visualizaiton, and Layout programs. - Heavy support for drawing graphs. Beautiful gallery. ActiveX, Java, C++ and .NET editions.
+
* [http://www.netminer.com/ NetMiner] - "One of the most comprehensive and usable software tools for Social Network Analysis in the world." Runs on Winodws, with a Linux version under development. $35 for "Express" student version, $250 for "Professional" student version, $950 for "Normal" "Professional" version.
+
* [http://www.analytictech.com/ucinet.htm UCINET] - A comprehensive package for the analysis of social network data as well as other 1-mode and 2-mode data.
+
  
= Other Resources =
+
* [http://www.recuva.com/ Recuva]
==Journals and Conferences==
+
: Recuva is a freeware Windows tool that will recover accidentally deleted files.
* [http://www.palgrave-journals.com/ivs/index.html Information Visualization Journal]
+
 
* [http://rw4.cs.uni-sb.de/~diehl/softvis/seminar/index.php?goto=seminar ACM Symposium on Software Visualization]
+
* [http://www.snapfiles.com/get/restoration.html Restoration]
==Link Farms==
+
: Restoration is a freeware Windows software that will allow you to recover deleted files
* [http://www-static.cc.gatech.edu/gvu/ii/resources/infovis.html GVU's Information Visualization Resources link farm]
+
 
* [http://directory.google.com/Top/Science/Math/Combinatorics/Software/Graph_Drawing/ Google Directory of Graph Drawing Software]
+
* [http://www.undelete-plus.com/ Undelete Plus]
* [http://directory.fsf.org/science/visual/ GNU Free Software directory of scientific visualization software]
+
: Undelete Plus is a free deleted file recovery tool that works for all versions of Windows (95-Vista), FAT12/16/32, NTFS and NTFS5 filesystems and can perform recovery on various solid state devices.
* [http://www.manageability.org/blog/stuff/open-source-graph-network-visualization-in-java/view Open Source Graph Network Visualization in Java]
+
 
* [http://www.insna.org/INSNA/soft_inf.html INSNA's web page of Computer Programs for Social Network Analysis]
+
* [http://www.data-recovery-software.net/ R-Studio]
==Research Groups==
+
: R-Studio is a data recovery software suite that can recover files from FAT(12-32), NTFS, NTFS 5, HFS/HFS+, FFS, UFS/UFS2 (*BSD, Solaris), Ext2/Ext3 (Linux) and so on.
===Berkeley===
+
 
* [http://bailando.sims.berkeley.edu/infovis.html Bailando Visualization]
+
* [http://www.stellarinfo.com/ Stellar Phoenix]
* [http://vis.berkeley.edu/ Berkeley Visualization Lab]
+
: Data recovery software services & tools to recover lost data from hard drive.
===Brown===
+
 
* [http://www.cs.brown.edu/people/rt/gd.html Roberto Tamassia's resources on Graph Drawing]
+
* [http://www.deepspar.com/ DeepSpar Disk Imager]
===Stanford===
+
: DeepSpar Disk Imager is a dedicated disk imaging device built to handle disk-level problems and to recover bad sectors on a hard drive.
* [http://window.stanford.edu/projects/rivet/ Rivet Project] (Visualization complex systems)
+
 
===UNM===
+
* [http://digital-assembly.com/products/adroit-photo-recovery/ Adroit Photo Recovery]
* [http://www.msi.umn.edu/user_support/scivis/scivis-list.html Scientific Visualization at the Supercomputing Institute]
+
: Adroit Photo Recovery is a photo recovery tool that uses validated carving and is able to recover fragmented photos. Adroit Photo Recovery is able
 +
: to recover high definition RAW images from Canon, Nikon etc.
 +
 
 +
See also [[Data Recovery Stories]]
 +
 
 +
=Carving=
 +
*[http://www.datalifter.com/products.htm DataLifter® - File Extractor Pro]
 +
: Data carving runs on multiple threads to make use of modern processors
 +
 
 +
*[http://www.simplecarver.com/ Simple Carver Suite]
 +
: Simple Carver Suite is a collection of unique tools designed for a number of purposes including data recovery, forensic computing and eDiscovery. The suite was originally designed for data recovery and has since expanded to include unique file decoding, file identification and file classification.
 +
 
 +
*[http://foremost.sourceforge.net/ Foremost]
 +
: Foremost is a console program to recover files based on their headers, footers, and internal data structures.
 +
 
 +
*[http://www.digitalforensicssolutions.com/Scalpel/ Scalpel]
 +
: Scalpel is a fast file carver that reads a database of header and footer definitions and extracts matching files from a set of image files or raw device files. Scalpel is filesystem-independent and will carve files from FATx, NTFS, ext2/3, or raw partitions.
 +
 
 +
*[[EnCase]]
 +
: EnCase comes with some enScripts that will do carving.
 +
 
 +
*[[CarvFs]]
 +
: A virtual file system (fuse) implementation that can provide carving tools with the possibility to do recursive multi tool zero-storage carving (also called in-place carving). Patches and scripts for scalpel and foremost are provided. Works on raw and encase images.
 +
 
 +
*[[LibCarvPath]]
 +
: A shared library that allows carving tools to use zero-storage carving on carvfs virtual files.
 +
 
 +
*[http://www.cgsecurity.org/wiki/PhotoRec PhotoRec]
 +
: PhotoRec is file data recovery software designed to recover lost files including video, documents and archives from Hard Disks and CDRom and lost pictures (thus, its 'Photo Recovery' name) from digital camera memory.
 +
 
 +
*[http://www.datarescue.com/photorescue/ PhotoRescue]
 +
: Datarescue PhotoRescue Advanced is picture and photo data recovery solution made by the creators of IDA Pro. PhotoRescue will undelete, unerase and recover pictures and files lost on corrupted, erased or damaged compact flash (CF) cards, SD Cards, Memory Sticks, SmartMedia and XD cards.
 +
 
 +
* [https://www.uitwisselplatform.nl/projects/revit RevIt]
 +
: RevIt (Revive It) is an experimental carving tool, initially developed for the DFRWS 2006 carving challenge. It uses 'file structure based carving'. Note that RevIt currently is a work in progress.
 +
 
 +
* [http://jbj.rapanden.dk/magicrescue/ Magic Rescue]
 +
: Magic Rescue is a file carving tool that uses "magic bytes" in a file contents to recover data.
 +
 
 +
* [[FTK]]
 +
: FTK2 includes some file carvers
 +
 
 +
* [[X-Ways Forensic]]
 +
: X-Ways Forensic provides a robust list of file types as well as the ability to specific custom file headers/trailers.  File types are available for carving, identification and filtering.
 +
 
 +
*[[Adroit Photo Forensics]]
 +
: Adroit Photo Forensics supports data carving of popular image formats. Also supports fragmented carving using [[File_Carving:SmartCarving|SmartCarving]] and [[File_Carving:GuidedCarving|GuidedCarving]].

Revision as of 16:52, 12 September 2010

Partition Recovery

Recover deleted or lost partitions (FAT16/FAT32/NTFS/NTFS5/EXT2/EXT3/SWAP).
DiskInternals NTFS Recovery is a fully automatic utility that recovers data from damaged or formatted disks.
Gpart is a tool which tries to guess the primary partition table of a PC-type hard disk in case the primary partition table in sector 0 is damaged, incorrect or deleted.
TestDisk is an OpenSource software and is licensed under the GNU Public License (GPL).
Partition Recovery software for NTFS & FAT system that examines lost windows partition of damaged and corrupted hard drive.

See Also

Notes

  • "fdisk /mbr" restores the boot code in the Master Boot Record, but not the partition itself. On newer versions of Windows you should use fixmbr, bootrec, mbrfix, or MBRWizard. You can also extract a copy of the specific standard MBR code from tools like bootrec.exe and diskpart.exe in Windows (from various offsets) and copy it to disk with dd (Use bs=446 count=1). For Windows XP SP2 c:\%WINDIR%\System32\diskpart.exe the MBR code is found between offset 1b818h and 1ba17h.

Data Recovery

The term "Data Recovery" is frequently used to mean forensic recovery, but the term really should be used for recovering data from damaged media.

HD Doctor Suite is a set of professional tools used to fix firmware problem
Claims to have a program that can read the "bad blocks" of Maxtor drives with proprietary commands.
BringBack offers easy to use, inexpensive, and highly successful data recovery for Windows and Linux (ext2) operating systems and digital images stored on memory cards, etc.
Runtime Software's RAID Reconstructor will reconstruct RAID Level 0 (Striping) and RAID Level 5 drives.
Erol allows you to recover through the internet files erased by mistake. Recover your files online for free.
Recuva is a freeware Windows tool that will recover accidentally deleted files.
Restoration is a freeware Windows software that will allow you to recover deleted files
Undelete Plus is a free deleted file recovery tool that works for all versions of Windows (95-Vista), FAT12/16/32, NTFS and NTFS5 filesystems and can perform recovery on various solid state devices.
R-Studio is a data recovery software suite that can recover files from FAT(12-32), NTFS, NTFS 5, HFS/HFS+, FFS, UFS/UFS2 (*BSD, Solaris), Ext2/Ext3 (Linux) and so on.
Data recovery software services & tools to recover lost data from hard drive.
DeepSpar Disk Imager is a dedicated disk imaging device built to handle disk-level problems and to recover bad sectors on a hard drive.
Adroit Photo Recovery is a photo recovery tool that uses validated carving and is able to recover fragmented photos. Adroit Photo Recovery is able
to recover high definition RAW images from Canon, Nikon etc.

See also Data Recovery Stories

Carving

Data carving runs on multiple threads to make use of modern processors
Simple Carver Suite is a collection of unique tools designed for a number of purposes including data recovery, forensic computing and eDiscovery. The suite was originally designed for data recovery and has since expanded to include unique file decoding, file identification and file classification.
Foremost is a console program to recover files based on their headers, footers, and internal data structures.
Scalpel is a fast file carver that reads a database of header and footer definitions and extracts matching files from a set of image files or raw device files. Scalpel is filesystem-independent and will carve files from FATx, NTFS, ext2/3, or raw partitions.
EnCase comes with some enScripts that will do carving.
A virtual file system (fuse) implementation that can provide carving tools with the possibility to do recursive multi tool zero-storage carving (also called in-place carving). Patches and scripts for scalpel and foremost are provided. Works on raw and encase images.
A shared library that allows carving tools to use zero-storage carving on carvfs virtual files.
PhotoRec is file data recovery software designed to recover lost files including video, documents and archives from Hard Disks and CDRom and lost pictures (thus, its 'Photo Recovery' name) from digital camera memory.
Datarescue PhotoRescue Advanced is picture and photo data recovery solution made by the creators of IDA Pro. PhotoRescue will undelete, unerase and recover pictures and files lost on corrupted, erased or damaged compact flash (CF) cards, SD Cards, Memory Sticks, SmartMedia and XD cards.
RevIt (Revive It) is an experimental carving tool, initially developed for the DFRWS 2006 carving challenge. It uses 'file structure based carving'. Note that RevIt currently is a work in progress.
Magic Rescue is a file carving tool that uses "magic bytes" in a file contents to recover data.
FTK2 includes some file carvers
X-Ways Forensic provides a robust list of file types as well as the ability to specific custom file headers/trailers. File types are available for carving, identification and filtering.
Adroit Photo Forensics supports data carving of popular image formats. Also supports fragmented carving using SmartCarving and GuidedCarving.