Windows Forensics: The Field Guide for Corporate Computer Investigations
| | ||
| | ||
| | ||
Refer to the following list for additional resources:
-
Bootdisks
-
http://www.bootdisk.com
-
-
dd For Windows from George Garner
-
http://www.users.erols.com/gmgarner/forensics/
-
-
Helix Forensic Environment (includes dd-gnu)
-
http://www.e-fense.com/helix/
-
-
NetCat for Windows
-
http://www.vulnwatch.org/netcat/
-
-
Norton Ghost
-
http://www. symantec .com/home_homeoffice/products/backup_ recovery/ghost10/
-
-
NTFSDOS Drivers from SysInternals
-
http://www.sysinternals.com/ntw2k/freeware/ntfsdos.shtml
-
-
PDBlock Software Write Blocker
-
http://www.digitalintelligence.com/software/disoftware/pdblock/
-
-
PSExec from SysInternals
-
http://www.sysinternals.com/utilities/psexec.html
-
-
SF-5000 Disk Duplicator from Logicube
-
http://www.logicube.com/products/hd_duplication/sf5000.asp
-
-
Ultrablock and Firefly Hardware Write Blockers
-
http://www.digitalintelligence.com/forensicwriteblockers.php
-
-
Universal Network Boot Disk from TeleData
-
http://www.softpedia.com/get/System/Boot-Manager-Disk/Universal-Network-Boot-Disk.shtml
-
| | ||
| | ||
| | ||