OSForensics: Free Computer Investigation Tool
OSForensics is a new digital investigation tool which lets
you extract forensic data or uncover hidden information from computers.
OSForensics has a number of unique features which make the discovery of
relevant forensic data even faster, such as high-performance deep file
searching and indexing, e-mail and e-mail archive searching and the ability to
analyze recent system activity and active memory. OSForensics can build and let
you view an events timeline which shows you the context and time of activities.
You can even recover data and files that have been deleted by users.
OSForensics comes with a built-in file viewer which lets you examine a file
contents, properties and meta-data, as well as an e-mail viewer which is
compatible with most popular mail client formats.
Search within Files
If the basic file search functionality is not enough,
OSForensics can also create an index of the files on a hard disk. This allows
for lightning fast searches for text contained inside the documents. Powered by
the technology behind Wrensoft's acclaimed Zoom Search Engine.
Search for Emails
An additional feature of being able to search within files
is the ability to search email archives. The indexing process can open and read
most popular email file formats (including pst) and identify the individual
messages.
This allows for a fast text content search of any emails
found on a system
Recover Deleted Files
After a file has been deleted, even once removed from the
recycling bin, it often still exists until another new file takes its place on
the hard drive. OSForensics can track down this ghost file data and attempt to
restore it back to useable state on the hard drive.
Uncover Recent
Activity
Find out what users have been up to. OSForensics can uncover
the user actions performed recently on the system, including but not limited
to:
* Opened Documents
* Web Browsing History
* Connected USB Devices
* Connected Network Shares
Collect System
Information
Find out what's inside the computer. Detailed information
about the hardware a system is running on:
* CPU type and number of CPUs
* Amount and type of RAM
* Installed Hard Drives
* Connected USB devices
* and much more.
View Active Memory
Look directly at what is currently in the systems main
memory. Attempt to uncover passwords and other sensitive information that would
otherwise be inaccessible.
Select from a list of active processes on the system to
inspect. OSF can also dump their memory to a file on disk for later inspection.
Extract Logins and
Passwords
Recover usernames and passwords from recently accessed
websites in common web browsers, including Internet Explorer, Firefox, Chrome
and Opera.
Price
* Feature restricted edition: Free
* Professional edition: US$499
Free Version Limitations
* Web browser
screen capture: Image is watermarked
* List and Search
for Alternate File Streams: N/A
* Sort Files by
Color: N/A
* Multi-core
acceleration for file decryption: N/A
* Customizable
System Information Gathering: N/A
* Import / Export
Hash Sets: N/A
* Manage Cases: Limited
to 3 cases at a time
* Disk indexing
and searching: Limited to 200,000 files or EMails
* Restore Deleted
Files: Limited to one file at a time.
Screenshots
Review: FCPortables
Developers’ website: http://www.osforensics.com/osforensics.html
0 comments:
Post a Comment