Tag Archives: Forensics

USBDeview – Lists Connected USB Devices

USBDeview is a small utility that lists all USB devices that currently connected to your computer, as well as all USB devices that you previously used.

MemGator – Memory Analysis Tool

MemGator is a memory file analysis tool that automates the extraction of data from a memory file and compiles a report for the investigator.

Moloch – PCAP capturing, Indexing and Database System

Moloch augments your current security infrastructure to store and index network traffic in standard PCAP format, providing fast, indexed access.

IECacheView – Internet Explorer Cache Viewer

IECacheView is a small utility that reads the cache folder of Internet Explorer, and displays the list of all files currently stored in the cache.

NTFS Journal Viewer – Tool to Investigate NTFS Changes

NTFS Journal Viewer (JV) is a portable tool that extracts and parses the NTFS change journal ($UsnJrnl) file. The change journal is a file that records when changes are made to files and directories and therefore can provide a wealth

TestDisk – Data Recovery Software

TestDisk is powerful free data recovery software. It was primarily designed to help recover lost partitions and/or make non-booting disks bootable

ShadowExplorer – Tool to Browse Shadow Copies

ShadowExplorer allows you to browse the Shadow Copies created by the Windows Vista / 7 / 8 / 10 Volume Shadow Copy Service.