Difference between pages "File:BBManager4 6 Backup1.JPG" and "SANS Investigative Forensic Toolkit Workstation"
From Forensics Wiki
(Difference between pages)
Mlevendoski (Talk | contribs) (uploaded a new version of "Image:BBManager4 6 Backup1.JPG") |
m (Fixed up volatility link) |
||
| Line 1: | Line 1: | ||
| + | '''The SANS SIFT Workstation''' is a [[VMware]] Appliance that is preconfigured with all the necessary tools to perform a forensic examination. It is compatible with [[Encase | Expert Witness Format]] (E01), Advanced Forensic Format ([[AFF]]), and raw (dd) evidence formats. | ||
| + | == Overview == | ||
| + | |||
| + | SIFT Workstation is based on Fedora. | ||
| + | |||
| + | Software Includes: | ||
| + | |||
| + | # [[The Sleuth Kit]] | ||
| + | # [[ssdeep]] & [[md5deep]] | ||
| + | # [[Foremost]]/[[Scalpel]] | ||
| + | # [[Wireshark]] | ||
| + | # HexEditor | ||
| + | # [[Vinetto]] ([[thumbs.db]] examination) | ||
| + | # Pasco | ||
| + | # Rifiuti | ||
| + | # [[Volatility Framework]] | ||
| + | # DFLabs PTK (GUI Front-End for [[Sleuthkit]]) | ||
| + | # [[Autopsy]] (GUI Front-End for [[Sleuthkit]]) | ||
| + | |||
| + | The SIFT Workstation will allow evidence to be viewed from a Windows workstation. The /images directory and the evidence mount point, the /mnt/hack directory, can be viewed from the local windows operation system. | ||
| + | |||
| + | == Links == | ||
| + | |||
| + | * [http://forensics.sans.org/community/downloads/ Computer Forensics and e-Discovery downloads] | ||
Revision as of 13:51, 15 January 2009
The SANS SIFT Workstation is a VMware Appliance that is preconfigured with all the necessary tools to perform a forensic examination. It is compatible with Expert Witness Format (E01), Advanced Forensic Format (AFF), and raw (dd) evidence formats.
Overview
SIFT Workstation is based on Fedora.
Software Includes:
- The Sleuth Kit
- ssdeep & md5deep
- Foremost/Scalpel
- Wireshark
- HexEditor
- Vinetto (thumbs.db examination)
- Pasco
- Rifiuti
- Volatility Framework
- DFLabs PTK (GUI Front-End for Sleuthkit)
- Autopsy (GUI Front-End for Sleuthkit)
The SIFT Workstation will allow evidence to be viewed from a Windows workstation. The /images directory and the evidence mount point, the /mnt/hack directory, can be viewed from the local windows operation system.
Links
File history
Click on a date/time to view the file as it appeared at that time.
| Date/Time | Thumbnail | Dimensions | User | Comment | |
|---|---|---|---|---|---|
| current | 22:43, 18 March 2013 | 650 × 412 (142 KB) | Maintenance script (Talk) | Importing image file |
- You cannot overwrite this file.
- Edit this file using an external application (See the setup instructions for more information)
File usage
The following page links to this file: