Tools commonly used during a forensics investigation
There are many tools within the industry that computer forensics investigators use on a daily basis to help them acquire evidence and analyze large amounts of data at a time, while looking for any suspicious artifacts that relate to an investigation and/or a cyber-crime.
The following are some of the most commonly used forensic tools within the industry:
- AccessData FTK: FTK is a computer forensics software that allows security professionals to acquire both the disk image and the contents of RAM for analysis. These tools also allow a forensic investigator to explore the entire filesystems of an acquired image, create duplicates of the forensic evidence, easily identify and extract various files, extract and read email messages, perform password-cracking techniques on password-protected files, and even generate reports.
- Autopsy: This is an open source computer forensics software that is available for Microsoft Windows...