DQ7A 200- 250 words max
The number of computer-based forensic tools has been on the rise over the last 10 years, making it extremely difficult to select the right tool for the job. Cost is an additional factor too, as many of these tools are expensive and can break a budget. Research four computer-based forensic tools. List each tool and the type of data that it searches for, its features, and costs. Which would you recommend? If you could only select one of these tools, which one would it be? Why?
Reply to responses 75-100 words max
i Hayden
The first tool that I found was the Autopsy/The Sleuth Kit which are designed to analyze disk images, file systems, and a multiple other features. These tools are open source so they are available to download from a website. The second tool that I found is Bulk Extractor that scans disk images, file or directory of files to extract information. This tool ignores file system structure so it is faster than similar tools, and it can be downloaded from a website. The third tool that I found is Wireshark. Wireshark analyzes live network traffic and can then be saved for review, allowing one to view individual packets of information. Wireshark has a free download on their website. The forth tool that I found was Xplico; this toll is an open-source network forensic analysis tool that can pull data from applications using internet and network protocols. This tool is also open-source so it can be downloaded from their website. I recommend these tools especially due to their open-source nature, or free availability, as after one becomes confident in which tools they need they can then choose more tools if the open-source ones are not good enough for the current business. It is hard to recommend just one of these tools as they have different uses, therefor it would be wise to choose the tool that the company or individual currently needs.
Poston, H. (2021, May 27). Popular Computer Forensics Top 19 Tools [updated 2021]. Infosec Resources. Retrieved February 15, 2022, from https://resources.infosecinstitute.com/topic/computer-forensics-tools/
REPLY
Ii Justin
With so many options out there for Digital Forensic tools, I can see how it can be confusing to choose one. There are free and open-source options out there and then there are options that can add on support for 3000-4,000 dollars a year and then there are options that cost upwards of 10,000-35,000 a year.The Sleuth Kit and Autopsy are free open-source digital investigation tools that have proven to be reliable. The Sleuth Kit enables the user to investigate disk images via a command library. Autopsy is the GUI that helps accelerate TSK capabilities.If you are looking to recover evidence from multiple devices and introduce automation The company Opentext under its security suite has introduced Encase. The cost for this service is about 3,500 a year and that includes support.There is a company out there called Exterro and they have a product line called FTK (Forensic Tool Kit). Where you Create full-disk forensic images and process a wide range of data types from many sources, from hard drive data to mobile devices, network data, and Internet storage, all in a centralized, secure database. This product is about 4,000 a year with yearly support costing around 1,100.
There is a company that is based in Hyderbad India called Prodiscover. ProDiscover Forensic is a computer security tool that enables computer professionals to locate all of the data on a computer disk and at the same time protect evidence and create quality evidentiary reports for use in legal proceedings. The cost is around 7,000 a year.With all of the options that are available one must do the research to find out what tools are best for the business. Many of these companies that charge offer free trials. If you have someone on your team that is able to use the free tools I would try those. But for more complex issues one of the paid services that offer support might be the way to go.