<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Software Archives - Compute Forensics LTD London Computer &amp; Mobile Phone Forensic Expert Witness Investigation Services</title>
	<atom:link href="https://compute-forensics.com/tag/software/feed/" rel="self" type="application/rss+xml" />
	<link>https://compute-forensics.com/tag/software/</link>
	<description></description>
	<lastBuildDate>Thu, 09 Aug 2018 17:36:31 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://compute-forensics.com/wp-content/uploads/2018/06/cropped-cropped-CF-1-32x32.png</url>
	<title>Software Archives - Compute Forensics LTD London Computer &amp; Mobile Phone Forensic Expert Witness Investigation Services</title>
	<link>https://compute-forensics.com/tag/software/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Free Cloud Based eDiscovery Tool</title>
		<link>https://compute-forensics.com/free-cloud-based-ediscovery-tool/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Tue, 05 Jun 2018 08:23:48 +0000</pubDate>
				<category><![CDATA[Legal]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[eDiscovery]]></category>
		<category><![CDATA[Free]]></category>
		<category><![CDATA[Free Software]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1755</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid vc_custom_1459507906849"><div class="wpb_column vc_column_container vc_col-sm-12 vc_col-lg-9 vc_col-md-9"><div class="vc_column-inner vc_custom_1452702342137"><div class="wpb_wrapper"><div class="vc_custom_heading no_stripe text_align_left" ><h2 style="color: #111111;text-align: left" class="consulting-custom-title">Free Cloud Based eDiscovery Tool</h2></div><div class="post_details_wr ">
    
<div class="stm_post_info">
	<div class="stm_post_details clearfix">
		<ul class="clearfix">
			<li class="post_date">
				<i class="fa fa fa-clock-o"></i>
				05/06/2018			</li>
			<li class="post_by">Posted by:				<span>Alistair Ewing</span>
			</li>
			<li class="post_cat">Categories:				<span>Legal, Software, Uncategorized</span>
			</li>
		</ul>
		<div class="comments_num">
			<a href="https://compute-forensics.com/free-cloud-based-ediscovery-tool/#respond"><i class="fa fa-comment-o"></i>No Comments </a>
		</div>
	</div>
			<div class="post_thumbnail">
			<img fetchpriority="high" decoding="async" width="1110" height="550" src="https://compute-forensics.com/wp-content/uploads/2018/06/9-1110x550.jpg" class="attachment-consulting-image-1110x550-croped size-consulting-image-1110x550-croped wp-post-image" alt="" />		</div>
	</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1528114098937" >
		<div class="wpb_wrapper">
			<p>Thanks for browsing to this article. If you require global forensic imaging or any other of our litigation services, please don’t hesitate to <a href="https://compute-forensics.com/contact-us/">contact us</a>!</p>
<h3>The Current Market</h3>
<p>eDiscovery tools <a href="https://accessdata.com/products-services/summation">Summation</a>, <a href="https://www.relativity.com">Relativity</a>, <a href="https://www.vound-software.com">Intella</a> and <a href="https://www.nuix.com">Nuix</a> all have their place in the litigation support arena. As a technology agnostic myself I tend to try and find the best tool for my client in terms dependent on the size of the case and other factors such as if the data involves more than just documents and emails.</p>
<p>I was discouraged to discover that there was no solution for small to medium-sized cases. The answers I found would not cope with additional reviewers, more data and other factors.</p>
<h3>GoldFynch eDiscovery Tool</h3>
<p>A few weeks ago I came across <a href="https://goldfynch.com">Goldfynch</a> and thought I would review some of the features involved in the tool. The <a href="https://goldfynch.com">website</a> promises <strong>Cloud-based eDiscovery, Bank Grade Security, OCR processing, Pay as you go pricing (averages $6/GB/month), No contracts, no commitments</strong> and<strong> Unlimited users</strong>. I started to wonder if it also did the review for my clients too! The company slogan is “If you can use a search engine you can use GoldFynch.” Interestingly GoldFynch is owned by firm search engine firm Mazira who built the tool from the ground up to be intuitive.</p>
<p>GoldFynch is <strong>free</strong> to trial for the first case limited to <strong>512mb</strong> of data. This means reviewers can train using this tool before the case being initiated and pricing is scalable.</p>
<h3>Limitations as of 2018</h3>
<p>Unfortunately, at the time of writing <strong>AD1, XWF, E01, AFF</strong> and other forensic container formats were not supported. These formats are used so a litigator can be sure of the integrity and original path of the files has been preserved when the items were captured at the source.  The collection, documentation and preparation of the ESI, therefore, requires a computer forensic expert to prepare the dataset before upload. Additionally, if you have ESI in more exotic formats such as NSF Lotus Notes or Android Mobile SQL Emails the files may need to be converted which takes some time and skill.</p>
<p>The server location may be relevant in multijurisdictional cases, and the cloud processing server is based in the USA currently. I have conversed with <strong>GoldFynch,</strong> and they are looking at opening servers some other jurisdictions including Europe as the firm develops.</p>
<h3>Platform Review</h3>
<p>I signed up for GoldFynch cloud platform free 512mb trial and decided to try my hand at processing a sample case with public domain data. The sample dataset included <strong>PST, PDF, TIFF, OFFICE </strong>and <strong>JPG</strong> files. The website states, at the time of writing, that <strong>PDF, PST, MBOX, MSG, EML, DOC, DOCX, RTF, XLS, XLSX, PPT, PPTX, POTX, ODT, TIFF, JPEG, ZIP</strong> and<strong> RAR</strong> files are supported. In fact, I discovered that GoldFynch supports 7z (7zip) and a plethora of other data types not listed.</p>
<p>The datasets were compressed as <strong>Zip </strong>and <strong>7zip</strong> file types. Uploading the data was as easy as selecting an ‘Upload Now’ button in the ‘Files’ tab of the web-based interface.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><img decoding="async" class="aligncenter wp-image-1757" src="https://compute-forensics.com/wp-content/uploads/2018/06/3-300x156.jpg" alt="" width="600" height="311" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/3-300x156.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/3-768x398.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/3-1024x531.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/3-600x311.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/3.jpg 1877w" sizes="(max-width: 600px) 100vw, 600px" /></p>
<p>The upload on my enterprise 50mb broadband connection for the dataset took about 20 minutes. Processing took just under an hour to complete for <strong>556.5 MB</strong> of data or <strong>11,861</strong> files. This performance isn’t bad if you factor in the wasted time of software setup, tweaking and moving data to a physical data centre.</p>
<p>If you want to add or remove users, this can be done instantly using the ‘Sharing’ tab. The number of users that can be added to the case is <strong>unlimited.</strong>  The user is sent a registration email when a valid address is entered. There are three types of user Owner, Admin or User each with their own set of permissions which the new user can be assigned as to avoid unintentional modifications to the case by a reviewer.</p>
<p>When the files are uploading <strong>PDF’s</strong> and images are automatically <strong>OCR’d</strong> (made searchable), assigned unique Bate’s numbers and scanned for issues. In the test, <strong>GoldFynch’s</strong> scanning engine identified seven attachments that required passwords to open and previously non-OCR’d documents were flagged in the search.</p>
<p><strong>Decrypting</strong> these files is as comfortable as adding passwords to a bulk <strong>password list</strong> before or after processing event. These could also be exported out and cracked by a <a href="https://compute-forensics.com/" rel="noopener">computer forensic examiner</a>.</p>
<p><img decoding="async" class="aligncenter wp-image-1758" src="https://compute-forensics.com/wp-content/uploads/2018/06/4-300x154.jpg" alt="" width="600" height="308" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/4-300x154.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/4-768x394.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/4-1024x525.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/4-600x308.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/4.jpg 1872w" sizes="(max-width: 600px) 100vw, 600px" />The ‘Overview’ tab displays a chart as so you can see how much data has been uploaded to a case and the status of the processing of the items.  The Activity sub-tab allows the reviewer to go through the changes regarding tagging the reviewers of the case have made.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-1759" src="https://compute-forensics.com/wp-content/uploads/2018/06/1-300x155.jpg" alt="" width="600" height="310" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/1-300x155.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/1-768x397.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/1-1024x529.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/1-600x310.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/1.jpg 1872w" sizes="auto, (max-width: 600px) 100vw, 600px" />The ‘Search’ tab allows examiners to run keyword searches against the dataset. The right-hand column provides for reviewers to filter by file type and date as to quickly find the responsive data. Data can be tagged as <strong>CONFIDENTIAL, IMPORTANT, IRRELEVANT, NON-RESPONSIVE</strong> or <strong>PRIVILEGED.</strong> Admin users can easily assign their own bespoke tags.</p>
<p><img loading="lazy" decoding="async" class="wp-image-1760 aligncenter" src="https://compute-forensics.com/wp-content/uploads/2018/06/5-300x158.jpg" alt="" width="600" height="317" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/5-300x158.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/5-768x405.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/5-1024x540.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/5-600x317.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/5.jpg 1852w" sizes="auto, (max-width: 600px) 100vw, 600px" /></p>
<p>The advanced search allows for multiple queries to be compounded so that you could easily find results containing just the term <strong>‘GUNS’</strong> equal to or after the <strong>01/01/2018</strong> as shown below.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-1761" src="https://compute-forensics.com/wp-content/uploads/2018/06/7-300x155.jpg" alt="" width="600" height="310" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/7-300x155.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/7-768x396.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/7-1024x528.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/7-600x310.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/7.jpg 1863w" sizes="auto, (max-width: 600px) 100vw, 600px" />The ‘Doc Review’ tab has redaction, tagging, download and directory browsing features as found in most review tools. New items are populated fairly quickly, and the interface is intuitive.</p>
<p>The ‘Production’ tab allows the user to export tagged files using a wizard. Paid versions allow export in TIFF, Load File and even Relativity or Concordance formats.</p>
<p>&nbsp;</p>
<h3><img loading="lazy" decoding="async" class="aligncenter wp-image-1762" src="https://compute-forensics.com/wp-content/uploads/2018/06/8-300x151.jpg" alt="" width="600" height="303" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/8-300x151.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/8-768x388.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/8-1024x517.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/8-600x303.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/8.jpg 1853w" sizes="auto, (max-width: 600px) 100vw, 600px" />Summary</h3>
<p><strong>Goldfynch</strong> is a transparently priced tool that could be very useful in small to medium size cases. The power of a cloud-based tool means a forensic expert or IT technician to collect and upload data to the cloud and assign reviewers of that data non-dependant of location. The functionality covers all the fundamental requirements for a review tool and is easy to use.  I am sure new features will be added, without the need for a software upgrade as the service evolves.</p>
<p>Thanks for reading!</p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-3 vc_hidden-sm vc_hidden-xs"><div class="vc_column-inner "><div class="wpb_wrapper">
<div class="stm_sidebar">

            <style type="text/css" scoped>
            .vc_custom_1452056597103{margin-right: 0px !important;margin-bottom: 30px !important;margin-left: 0px !important;}.vc_custom_1451998133493{margin-bottom: 30px !important;}.vc_custom_1452056633692{padding-top: 37px !important;padding-right: 30px !important;padding-bottom: 40px !important;padding-left: 30px !important;}.vc_custom_1527964913946{margin-bottom: 9px !important;}.vc_custom_1527964962623{margin-bottom: 17px !important;}.vc_custom_1527965000155{margin-bottom: 30px !important;}        </style>
        <div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1452056597103"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner vc_custom_1452056633692"><div class="wpb_wrapper"><div class="vc_custom_heading vc_custom_1527964913946 text_align_left" ><div style="font-size: 16px;color: #222222;text-align: left;font-family:Poppins;font-weight:600;font-style:normal" class="consulting-custom-title">Contact Us</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1527964962623" >
		<div class="wpb_wrapper">
			<p><span style="font-size: 13px; line-height: 22px;">Compute Forensics are based in London but are available for contracts and work in the global area. Please don’t hesitate to email us at expert@compute-forensics.com for a free online or call consultation.</span></p>

		</div>
	</div>
<div class="vc_btn3-container vc_btn3-inline vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-sm vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-left vc_btn3-color-white" href="https://compute-forensics.com/contact-us/" title=""><i class="vc_btn3-icon fa fa-phone-square"></i> contacts</a></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid vc_custom_1451998133493"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper"><div class="vc_btn3-container vc_btn3-left vc_custom_1527965000155 vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-lg vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-block vc_btn3-icon-left vc_btn3-color-theme_style_1" href="https://compute-forensics.com/pdf/" title="" target="_blank"><i class="vc_btn3-icon fa fa-file-pdf-o"></i> Computer Forensics Professional Services PDF</a></div></div></div></div></div>
</div>    
</div></div></div></div></div><div data-vc-full-width="true" data-vc-full-width-init="false" class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1459505959648"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper">
<section class="vc_cta3-container" >
    <div class="vc_general vc_cta3 third_bg_color vc_cta3-style-flat vc_cta3-shape-square vc_cta3-align-left vc_cta3-color-classic vc_cta3-icon-size-md vc_cta3-actions-right vc_custom_1530193971059 style=""">
                        <div class="vc_cta3_content-container">
                                    <div class="vc_cta3-content">
                <header class="vc_cta3-content-header">
                    <div class="vc_custom_heading" ><h2 style="font-size: 20px;color: #ffffff;line-height: 24px" class="consulting-custom-title">Are you looking for an eDiscovery Consultant?</h2></div>                                    </header>
                            </div>
                        <div class="vc_cta3-actions"><div class="vc_btn3-container vc_btn3-right vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-md vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-right vc_btn3-color-theme_style_2" href="https://compute-forensics.com/contact-us/" title="">get a quote <i class="vc_btn3-icon fa fa-chevron-right"></i></a></div></div>        </div>
                    </div>
</section></div></div></div></div><div class="vc_row-full-width vc_clearfix"></div>
</div>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How to make a Forensic Image Bootable in VirtualBox for Free</title>
		<link>https://compute-forensics.com/how-to-make-a-forensic-image-bootable-in-virtualbox-for-free/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Tue, 05 Jun 2018 09:22:46 +0000</pubDate>
				<category><![CDATA[Investigative Techniques]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Free Software]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Techniques]]></category>
		<category><![CDATA[Virtualisation]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1765</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid vc_custom_1459507906849"><div class="wpb_column vc_column_container vc_col-sm-12 vc_col-lg-9 vc_col-md-9"><div class="vc_column-inner vc_custom_1452702342137"><div class="wpb_wrapper"><div class="vc_custom_heading no_stripe text_align_left" ><h2 style="color: #111111;text-align: left" class="consulting-custom-title">How to make a Forensic Image Bootable in VirtualBox for Free</h2></div><div class="post_details_wr ">
    
<div class="stm_post_info">
	<div class="stm_post_details clearfix">
		<ul class="clearfix">
			<li class="post_date">
				<i class="fa fa fa-clock-o"></i>
				05/06/2018			</li>
			<li class="post_by">Posted by:				<span>Alistair Ewing</span>
			</li>
			<li class="post_cat">Categories:				<span>Investigative Techniques, Uncategorized</span>
			</li>
		</ul>
		<div class="comments_num">
			<a href="https://compute-forensics.com/how-to-make-a-forensic-image-bootable-in-virtualbox-for-free/#respond"><i class="fa fa-comment-o"></i>No Comments </a>
		</div>
	</div>
			<div class="post_thumbnail">
			<img loading="lazy" decoding="async" width="1016" height="550" src="https://compute-forensics.com/wp-content/uploads/2018/06/Make-a-forensic-image-bootable-1016x550.jpg" class="attachment-consulting-image-1110x550-croped size-consulting-image-1110x550-croped wp-post-image" alt="Make a forensic image bootable in Windows." />		</div>
	</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1533678424687" >
		<div class="wpb_wrapper">
			<p><strong>Thank you for visiting this post hope you find it useful. Please email <a href="mailto:expert@compute-forensics.com">expert@compute-forensics.com</a> for assistance in lab implementation, investigation, data collection, consultancy or anything else.</strong></p>
<p><iframe loading="lazy" src="https://www.youtube.com/embed/Fs_FRxzcVDk?rel=0&amp;showinfo=0" width="560" height="315" frameborder="0" allowfullscreen="allowfullscreen"></iframe></p>
<h3>Introduction</h3>
<p>This ‘how to’ is a simple guide to virtualise your forensic or test disk image file in Windows without converting it, directly with VirtualBox, forensically as not to change the image but to save the IO writes to a temporary location.</p>
<h3>Why would you want to Virtualise a <a href="https://compute-forensics.com/forensic-imaging/">Forensic Image</a>?</h3>
<p>Examining from outside the native operating system and including your image for processing in tools such as Autopsy, FTK and X-ways are all well and good, but it can lead to dreaded ‘scope creep’, and it is always good to observe the operating system as the suspect would see it.</p>
<p>The effectiveness of booting the image in court or using screenshots of a virtualised image to highlight specific examination points such as drug paraphernalia used as Windows wallpaper, for example, can be invaluable in demonstrating a point. The method works for Linux and Windows, the Apple Mac guide for doing this is coming soon!</p>
<h3>Primary reasons for Virtualising a Forensic Image</h3>
<ul>
<li>To provide a better insight into how the accused used the system</li>
<li>To run live forensic tools such as Nirsoft and OSforensics in the Windows environment</li>
<li>To analyse the memory or RAM to see if any Malware or Rootkits only detectable on a live system exists</li>
<li>To display user behaviour and layout of the desktop to clients</li>
<li>To access bespoke tools such as QuickBooks or booking systems in their natural test environment</li>
<li>To decrypt and create a logical image of non-TPM PGP, Bitlockered, Trucrypted or Veracrypted volumes where the password is known or to test techniques where one may have a limited amount of tries</li>
</ul>
<p>In the past, this has been costly or cumbersome. Recently a tool has been released free of charge, from Nanni Bassetti, the creator of <a href="https://www.caine-live.net">Caine</a> live suite of tools, called Imm2Virtual.</p>
<p>The technique relies on three tools, and you need a full forensic image for this to work. This technique is safe as the image, of course, won’t be blocked but also use a working copy to do this, don’t do this with the only copy of the evidence! Using this method <em>all</em> significant forensic image and RAW formats are supported (<strong>AFF, E01, E01x, DD, 001, IMG</strong>.)</p>
<p><strong>WARNING: Make sure you disable internet access on yours or the virtual machine. You do not want to connect to illegal sites or even the suspect’s cloud or private websites. Without a subpoena, you are breaking the law!</strong></p>
<h3>Free Software Tools Needed to Download and Install on your Windows Forensic Machine</h3>
<ol>
<li><a href="https://arsenalrecon.com/weapons/image-mounter/"><strong>Arsenal Image Mounter</strong></a></li>
<li><strong><a href="https://www.virtualbox.org/">VirtualBox</a> </strong></li>
<li><strong><a href="https://github.com/nannib/Imm2Virtual">Imm2Virtual</a></strong></li>
</ol>
<h3>Steps to Making and Booting Your VDMK File</h3>
<ul>
<li>Install or run ‘As Admin’ the items above. It is <em>essential</em><strong> </strong>to run the programs above as admin otherwise disks won’t be visible and you will come across a whole host of other errors.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-1170 size-full" src="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Oracle.jpg?resize=379%2C442&amp;ssl=1" sizes="auto, (max-width: 379px) 100vw, 379px" srcset="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Oracle.jpg?w=379&amp;ssl=1 379w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Oracle.jpg?resize=257%2C300&amp;ssl=1 257w" alt="VMware used in Digital Forensics to Boot an Image" width="377" height="440" data-attachment-id="1170" data-permalink="https://compute-forensics.com/how-to-make-a-computer-forensic-image-forensically-bootable/oracle/" data-orig-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Oracle.jpg?fit=379%2C442&amp;ssl=1" data-orig-size="379,442" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Oracle" data-image-description="" data-medium-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Oracle.jpg?fit=257%2C300&amp;ssl=1" data-large-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Oracle.jpg?fit=379%2C442&amp;ssl=1" /></p>
<ul>
<li>Run Virtual Box as an administrator. Create a new virtual machine, using you suspect image types OS, but do not add a hard disk just yet. Remember to add more RAM to the virtual machine setup. Make a note of the path your VMDK machine was created. The default will be ‘C:\Users\YOURUSERNAME\VirtualBox VMs’.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-1169" src="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Creating-a-forensic-VM.jpg?resize=792%2C585&amp;ssl=1" sizes="auto, (max-width: 792px) 100vw, 792px" srcset="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Creating-a-forensic-VM.jpg?w=792&amp;ssl=1 792w, https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Creating-a-forensic-VM.jpg?resize=300%2C222&amp;ssl=1 300w, https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Creating-a-forensic-VM.jpg?resize=768%2C567&amp;ssl=1 768w" alt="In Virtual Box creating an empty disk" width="790" height="584" data-attachment-id="1169" data-permalink="https://compute-forensics.com/how-to-make-a-computer-forensic-image-forensically-bootable/creating-a-forensic-vm/" data-orig-file="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Creating-a-forensic-VM.jpg?fit=792%2C585&amp;ssl=1" data-orig-size="792,585" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1521131818&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Creating-a-forensic-VM" data-image-description="" data-medium-file="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Creating-a-forensic-VM.jpg?fit=300%2C222&amp;ssl=1" data-large-file="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Creating-a-forensic-VM.jpg?fit=792%2C585&amp;ssl=1" /></p>
<ul>
<li>Run Arsenal Image Mounter as an admin. Mount the forensic image to allow temporary writes to the system cache, not the image! Take note of the physical disk number windows allocated to the virtually mounted disk.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-1168 size-full" src="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?resize=887%2C544&amp;ssl=1" sizes="auto, (max-width: 887px) 100vw, 887px" srcset="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?w=887&amp;ssl=1 887w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?resize=300%2C184&amp;ssl=1 300w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?resize=768%2C471&amp;ssl=1 768w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?resize=80%2C50&amp;ssl=1 80w" alt="" width="846" height="519" data-attachment-id="1168" data-permalink="https://compute-forensics.com/how-to-make-a-computer-forensic-image-forensically-bootable/aresenal_image_mounter_forensics/" data-orig-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?fit=887%2C544&amp;ssl=1" data-orig-size="887,544" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1521132334&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Aresenal_Image_Mounter_Forensics" data-image-description="" data-medium-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?fit=300%2C184&amp;ssl=1" data-large-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Aresenal_Image_Mounter_Forensics.jpg?fit=887%2C544&amp;ssl=1" /></p>
<ul>
<li>Select your search bar in Windows and search for CMD. Right-click and run a CMD Window as an administrator. Type DISKPART, then LIST DISK, check the disk number of your mounted disk and type SELECT DISK [INSERT NUMBER]. Now offline the disk by typing OFFLINE DISK.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-1172" src="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/DiskPart_Offilne-Disk-for-Forensic-Purposes.jpg?resize=593%2C518&amp;ssl=1" sizes="auto, (max-width: 593px) 100vw, 593px" srcset="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/DiskPart_Offilne-Disk-for-Forensic-Purposes.jpg?w=593&amp;ssl=1 593w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/DiskPart_Offilne-Disk-for-Forensic-Purposes.jpg?resize=300%2C262&amp;ssl=1 300w" alt="Using DiskPart to Offline your Disk" width="591" height="516" data-attachment-id="1172" data-permalink="https://compute-forensics.com/how-to-make-a-computer-forensic-image-forensically-bootable/diskpart_offilne-disk-for-forensic-purposes/" data-orig-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/DiskPart_Offilne-Disk-for-Forensic-Purposes.jpg?fit=593%2C518&amp;ssl=1" data-orig-size="593,518" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1521134217&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="DiskPart_Offilne-Disk-for-Forensic-Purposes" data-image-description="" data-medium-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/DiskPart_Offilne-Disk-for-Forensic-Purposes.jpg?fit=300%2C262&amp;ssl=1" data-large-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/DiskPart_Offilne-Disk-for-Forensic-Purposes.jpg?fit=593%2C518&amp;ssl=1" /></p>
<ul>
<li>Now run <strong>IMM2VIRTUAL</strong> as an administrator. In the disk-name slot type the exact name that you called your disk and input your physical drive number. In this case, it is ‘5’, and the name was as stated earlier ‘VM1’.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-1173" src="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?resize=1016%2C649&amp;ssl=1" sizes="auto, (max-width: 1016px) 100vw, 1016px" srcset="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?w=1016&amp;ssl=1 1016w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?resize=300%2C192&amp;ssl=1 300w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?resize=768%2C491&amp;ssl=1 768w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?resize=80%2C50&amp;ssl=1 80w" alt="" width="846" height="540" data-attachment-id="1173" data-permalink="https://compute-forensics.com/how-to-make-a-computer-forensic-image-forensically-bootable/im2virtual_screenshot/" data-orig-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?fit=1016%2C649&amp;ssl=1" data-orig-size="1016,649" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1521133522&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="IM2VIRTUAL_Screenshot" data-image-description="" data-medium-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?fit=300%2C192&amp;ssl=1" data-large-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/IM2VIRTUAL_Screenshot.jpg?fit=1016%2C649&amp;ssl=1" /></p>
<ul>
<li>CMD should open a Window with ‘RAW host disk access VMDK file C:\Users\<strong>YOURUSERNAME</strong>\VirtualBox VMs\VM1\VM1.vmdk created successfully.’ If not you probably have the wrong disk number, name, you didn’t know offline the correct disk, or you didn’t run a program as admin.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Now run VirtualBox as admin. Navigate to Settings&gt;Storage. Add the modified VDMK file as a disk. You may need to play around with settings such as disk type, OS and RAM amount to get the virtual disk to boot. After some tinkering, you should be able to boot your image.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-1171" src="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Add-Disk-to-Virtual-Box.jpg?resize=770%2C512&amp;ssl=1" sizes="auto, (max-width: 770px) 100vw, 770px" srcset="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Add-Disk-to-Virtual-Box.jpg?w=770&amp;ssl=1 770w, https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Add-Disk-to-Virtual-Box.jpg?resize=300%2C199&amp;ssl=1 300w, https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Add-Disk-to-Virtual-Box.jpg?resize=768%2C511&amp;ssl=1 768w" alt="Virtual Box Remember to Add your Forensic VDMK File" width="768" height="511" data-attachment-id="1171" data-permalink="https://compute-forensics.com/how-to-make-a-computer-forensic-image-forensically-bootable/add-disk-to-virtual-box/" data-orig-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Add-Disk-to-Virtual-Box.jpg?fit=770%2C512&amp;ssl=1" data-orig-size="770,512" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1521134318&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Add-Disk-to-Virtual-Box" data-image-description="" data-medium-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Add-Disk-to-Virtual-Box.jpg?fit=300%2C199&amp;ssl=1" data-large-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Add-Disk-to-Virtual-Box.jpg?fit=770%2C512&amp;ssl=1" /></p>
<p>There you have it. Remember you can use iso’s such as<a href="http://www.piotrbania.com/all/kon-boot/"> Kon Boot</a> or others to bypass the Windows. The beauty of it is if you mess up the installation you can go back to default settings as you are not modifying the original copy, just the cache.</p>
<p>If you liked this guide please like, share and comment on this page.</p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-3 vc_hidden-sm vc_hidden-xs"><div class="vc_column-inner "><div class="wpb_wrapper">
<div class="stm_sidebar">

            <style type="text/css" scoped>
            .vc_custom_1452056597103{margin-right: 0px !important;margin-bottom: 30px !important;margin-left: 0px !important;}.vc_custom_1451998133493{margin-bottom: 30px !important;}.vc_custom_1452056633692{padding-top: 37px !important;padding-right: 30px !important;padding-bottom: 40px !important;padding-left: 30px !important;}.vc_custom_1527964913946{margin-bottom: 9px !important;}.vc_custom_1527964962623{margin-bottom: 17px !important;}.vc_custom_1527965000155{margin-bottom: 30px !important;}        </style>
        <div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1452056597103"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner vc_custom_1452056633692"><div class="wpb_wrapper"><div class="vc_custom_heading vc_custom_1527964913946 text_align_left" ><div style="font-size: 16px;color: #222222;text-align: left;font-family:Poppins;font-weight:600;font-style:normal" class="consulting-custom-title">Contact Us</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1527964962623" >
		<div class="wpb_wrapper">
			<p><span style="font-size: 13px; line-height: 22px;">Compute Forensics are based in London but are available for contracts and work in the global area. Please don’t hesitate to email us at expert@compute-forensics.com for a free online or call consultation.</span></p>

		</div>
	</div>
<div class="vc_btn3-container vc_btn3-inline vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-sm vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-left vc_btn3-color-white" href="https://compute-forensics.com/contact-us/" title=""><i class="vc_btn3-icon fa fa-phone-square"></i> contacts</a></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid vc_custom_1451998133493"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper"><div class="vc_btn3-container vc_btn3-left vc_custom_1527965000155 vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-lg vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-block vc_btn3-icon-left vc_btn3-color-theme_style_1" href="https://compute-forensics.com/pdf/" title="" target="_blank"><i class="vc_btn3-icon fa fa-file-pdf-o"></i> Computer Forensics Professional Services PDF</a></div></div></div></div></div>
</div>    
</div></div></div></div></div><div data-vc-full-width="true" data-vc-full-width-init="false" class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1459505959648"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper">
<section class="vc_cta3-container" >
    <div class="vc_general vc_cta3 third_bg_color vc_cta3-style-flat vc_cta3-shape-square vc_cta3-align-left vc_cta3-color-classic vc_cta3-icon-size-md vc_cta3-actions-right vc_custom_1530193131889 style=""">
                        <div class="vc_cta3_content-container">
                                    <div class="vc_cta3-content">
                <header class="vc_cta3-content-header">
                    <div class="vc_custom_heading" ><h2 style="font-size: 20px;color: #ffffff;line-height: 24px" class="consulting-custom-title">Are you looking for a Computer Forensic Expert?</h2></div>                                    </header>
                            </div>
                        <div class="vc_cta3-actions"><div class="vc_btn3-container vc_btn3-right vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-md vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-right vc_btn3-color-theme_style_2" href="https://compute-forensics.com/contact-us/" title="">get a quote <i class="vc_btn3-icon fa fa-chevron-right"></i></a></div></div>        </div>
                    </div>
</section></div></div></div></div><div class="vc_row-full-width vc_clearfix"></div>
</div>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Top Ten Free Computer Forensic/eDiscovery Software</title>
		<link>https://compute-forensics.com/top-ten-free-computer-forensic-software/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Tue, 05 Jun 2018 09:21:27 +0000</pubDate>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Free Software]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1768</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid vc_custom_1459507906849"><div class="wpb_column vc_column_container vc_col-sm-12 vc_col-lg-9 vc_col-md-9"><div class="vc_column-inner vc_custom_1452702342137"><div class="wpb_wrapper"><div class="vc_custom_heading no_stripe text_align_left" ><h2 style="color: #111111;text-align: left" class="consulting-custom-title">Top Ten Free Computer Forensic/eDiscovery Software</h2></div><div class="post_details_wr ">
    
<div class="stm_post_info">
	<div class="stm_post_details clearfix">
		<ul class="clearfix">
			<li class="post_date">
				<i class="fa fa fa-clock-o"></i>
				05/06/2018			</li>
			<li class="post_by">Posted by:				<span>Alistair Ewing</span>
			</li>
			<li class="post_cat">Categories:				<span>Computer Forensics, Software, Uncategorized</span>
			</li>
		</ul>
		<div class="comments_num">
			<a href="https://compute-forensics.com/top-ten-free-computer-forensic-software/#respond"><i class="fa fa-comment-o"></i>No Comments </a>
		</div>
	</div>
			<div class="post_thumbnail">
			<img loading="lazy" decoding="async" width="938" height="550" src="https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool-938x550.jpg" class="attachment-consulting-image-1110x550-croped size-consulting-image-1110x550-croped wp-post-image" alt="Caine free computer forensic tool" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool-938x550.jpg 938w, https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool-350x204.jpg 350w" sizes="auto, (max-width: 938px) 100vw, 938px" />		</div>
	</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1528114867951" >
		<div class="wpb_wrapper">
			<p>Compiled here is the <strong>Top Ten of FREE Computer Forensic/eDiscovery software picks for 2018</strong>. Sometimes you do not need to spend £1000’s to get the job done. Paid software has its place but sometimes when you want one particular function only or to test out a hypothesis. So get downloading and examining using the software! Please email me at <a href="mailto:expert@compute-forensics.com">expert@compute-forensics.com</a> with any suggestions for 2019. <a href="https://compute-forensics.com/contact-us/" target="_blank" rel="noopener">Contact us</a> should you have an enquiry! <em>Written by Alistair Ewing</em></p>
<h2><i class="fa fa-star-o fa- "></i> 1) <a href="https://www.sleuthkit.org/autopsy/">Autopsy</a> developed by Brian Carrier, Basis Technology, Dan Farmer and Wietse Venema</h2>
<p>Autopsy is The Sleuth Kit’s shiny Windows front-end offering. The features are impressive for a free program; some stand up there with the paid for forensic tools Encase, FTK, X-ways and more recently Nuix Investigator. The suite of tools includes:</p>
<ul>
<li><strong>Data Recovery </strong>using photorec as a carver module</li>
<li><strong>Indexing for Keyword Searching </strong>The program creates a text index for instantaneous keyword searches.</li>
<li><strong>Known Hash Set Filtering </strong>Do you have hash (SHA1/MD5) fingerprints for known noise files or known contraband files? These can be filtered in or out without having to examine the data yourself manually.</li>
<li><strong>Media Metadata </strong>EXIF metadata can be examined, sorted and filtered to find what device was used to make a recording or file, when and sometimes where using geotags.</li>
<li><strong>Timeline Analysis </strong>Autopsy draws file MAC times (created, modified etc.) from files, website visits and other data such as GPS and EXIF. The program is also beginning to support ‘plaso’ files generated using log2timeline although the author states on their website that this time of writing this is in a BETA stage.</li>
<li><strong>Website Records </strong>Supports parsing of current browser records including Firefox, Chrome and Internet Explorer.</li>
</ul>
<p>Autopsy doesn’t have all the bells and whistles as some of the paid-for software, but don’t underestimate the tool’s features. Many of the features aren’t immediately apparent to the uninitiated, but this program has progressed by leaps and bounds.</p>
<p>I tested Autopsy 4.6.0 on a 1gb test image in the industry standard E01 format. The scanning engine quickly discovered signature mismatches (when someone tries to mask a file by changing its extension), file encryption, attached USB devices, web browsing history and more. The GUI interface is not unlike the functional but dated Encase v6 layout. (See Below). You may be a student or a ninja, in any case give Autopsy a whirl.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-1769" src="https://compute-forensics.com/wp-content/uploads/2018/06/Test-Case_Autopsy_NO1-Forensic-Tool-300x162.jpg" alt="" width="600" height="324" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/Test-Case_Autopsy_NO1-Forensic-Tool-300x162.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/Test-Case_Autopsy_NO1-Forensic-Tool-768x414.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/Test-Case_Autopsy_NO1-Forensic-Tool-1024x552.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/Test-Case_Autopsy_NO1-Forensic-Tool-600x324.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/Test-Case_Autopsy_NO1-Forensic-Tool.jpg 1715w" sizes="auto, (max-width: 600px) 100vw, 600px" />2) <a href="https://www.caine-live.net" rel="noopener">Caine</a> by Nanni Bassetti</p>
<p>Caine is a 64bit bootable Linux suite of tools that can be used to forensically image Mac’s and Windows Machines, triage machines without writing to the disk inside and perform partial and full analysis of forensic images and disks. Caine is loaded with Windows executable tools as well for use on a live system if a computer is discovered in a switched-on state and triage or unencrypted image is desired for acquisition. My personal experience is that Caine images most disks without error and has Veracrypt installed so you can package the forensic copies onto an encrypted disk as to remain compliant with your client’s data protection rules. The ISO can be downloaded from the website. The ISO can be made USB bootable by using UNETBOOTIN or <a href="https://rufus.akeo.ie">Rufus</a>. A must for any examiner’s toolkit.</p>
<h2><img loading="lazy" decoding="async" class="aligncenter wp-image-1770" src="https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool-300x193.jpg" alt="" width="600" height="387" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool-300x193.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool-768x495.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool-600x387.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/Caine_Linux_Forensic_Tool.jpg 938w" sizes="auto, (max-width: 600px) 100vw, 600px" />3) <a href="https://github.com/keydet89/RegRipper2.8">RegRipper</a> by Harlan Carvey</h2>
<p>Forged using python and operated user-side with an easy to use GUI frontend, Regripper parses registry hives (or even a mounted forensic image with a mod) and outputs the humanly readable data as a text file that can be searched using Notepad++ or similar. Want to find a user’s SID code, the Windows installation dates or MRU (most recently used/viewed items) fast? Then use RR.</p>
<p><a href="https://github.com/keydet89/RegRipper2.8.git"><img loading="lazy" decoding="async" class="aligncenter wp-image-1130 size-full" title="RegRipper Rips Registry Hives from Windows Machines " src="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/RegRipper_Registry-Analysis.jpg?resize=456%2C414&amp;ssl=1" sizes="auto, (max-width: 456px) 100vw, 456px" srcset="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/RegRipper_Registry-Analysis.jpg?w=456&amp;ssl=1 456w, https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/RegRipper_Registry-Analysis.jpg?resize=300%2C272&amp;ssl=1 300w" alt="" width="454" height="412" data-attachment-id="1130" data-permalink="https://compute-forensics.com/top-ten-free-computer-forensic-software/regripper_registry-analysis/" data-orig-file="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/RegRipper_Registry-Analysis.jpg?fit=456%2C414&amp;ssl=1" data-orig-size="456,414" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1520449263&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="RegRipper_Registry-Analysis" data-image-description="" data-medium-file="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/RegRipper_Registry-Analysis.jpg?fit=300%2C272&amp;ssl=1" data-large-file="https://i0.wp.com/compute-forensics.com/wp-content/uploads/2018/03/RegRipper_Registry-Analysis.jpg?fit=456%2C414&amp;ssl=1" /></a></p>
<h2>4) <a href="https://arsenalrecon.com/weapons/image-mounter/">Arsenal Image Mounter</a> by Arsenal Recon</h2>
<p>The function of mounting a forensic image in Windows is nothing new but AIM is especially proficient. FTK imager has a built-in image mounter, but this one is a little more advanced, and disks are seen in Windows where others have failed due to it’s faked SCSI driver. Arsenal mounts in many different and rarer image formats and even fakes disk serial number if required if mounting errors occur. <strong>*FREE for non-commercial use</strong></p>
<p><a href="https://arsenalrecon.com/weapons/image-mounter/"><img loading="lazy" decoding="async" class="aligncenter wp-image-1131 size-full" title="Arsenal Image Mounters Supported Formats" src="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/File-Types-Supported.jpg?resize=641%2C180&amp;ssl=1" sizes="auto, (max-width: 641px) 100vw, 641px" srcset="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/File-Types-Supported.jpg?w=641&amp;ssl=1 641w, https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/File-Types-Supported.jpg?resize=300%2C84&amp;ssl=1 300w" alt="" width="639" height="179" data-attachment-id="1131" data-permalink="https://compute-forensics.com/top-ten-free-computer-forensic-software/file-types-supported/" data-orig-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/File-Types-Supported.jpg?fit=641%2C180&amp;ssl=1" data-orig-size="641,180" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1520447766&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="File-Types-Supported" data-image-description="" data-medium-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/File-Types-Supported.jpg?fit=300%2C84&amp;ssl=1" data-large-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/File-Types-Supported.jpg?fit=641%2C180&amp;ssl=1" /></a></p>
<h2>5) <a href="https://www.nirsoft.net">Nirsoft</a> Tools by Nir Sofer</h2>
<p>A full suite of analysis tools for Windows artefacts. For forensic analysis, objects may have to be exported out, or examination must take place to a blocked mounted forensic image visible in Windows.</p>
<h2><img loading="lazy" decoding="async" class="aligncenter wp-image-1771" src="https://compute-forensics.com/wp-content/uploads/2018/06/Nirsoft-Tools-Free-Software-300x58.jpg" alt="" width="600" height="117" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/Nirsoft-Tools-Free-Software-300x58.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/Nirsoft-Tools-Free-Software-768x150.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/Nirsoft-Tools-Free-Software-1024x199.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/Nirsoft-Tools-Free-Software-600x117.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/Nirsoft-Tools-Free-Software.jpg 1833w" sizes="auto, (max-width: 600px) 100vw, 600px" />6) <a href="https://www.cgsecurity.org/wiki/PhotoRec">PhotoRec</a> Christopher Grenier</h2>
<p>Whether its a deleted Microsoft email PST item or a lost Encase E01 file, photorec is a data recovery tool that seems to perform well compared to the rest. The list of carvers preloaded is formidable, and the speed is swift. The carving can be completed on a mounted forensic image as to protect the integrity and only on the volumes free space to save time.</p>
<p>&nbsp;</p>
<h2><img loading="lazy" decoding="async" class="aligncenter wp-image-1772" src="https://compute-forensics.com/wp-content/uploads/2018/06/Photorec-Recovery-300x157.jpg" alt="" width="600" height="315" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/Photorec-Recovery-300x157.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/Photorec-Recovery-768x403.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/Photorec-Recovery-600x315.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/Photorec-Recovery.jpg 974w" sizes="auto, (max-width: 600px) 100vw, 600px" />7) <a href="https://github.com/log2timeline/plaso/wiki">Log2timeline</a> maintained by Kristinn Gudjonsson</h2>
<p>This parser is the no one supertimeline tool and can be used in an advanced forensic analysis to extract event times from 1000’s of log/database filetypes and place them into one plaso file output or CSV spreadsheet for analysis natively or using a graphical program. Most paid for or built-in timeline tools just take into account MAC times and can’t parse as many file, registry or database types as log2timeline. If you need to put together times, user actions and other artefacts in one place then log2timeline is the tool of choice.</p>
<h2>8) <a href="https://accessdata.com/product-download">FTK Imager</a> by AccessData</h2>
<p>Imager needs no introduction. Imager does what it says on the tin and more! FTK imager has little-known eDiscovery uses as the software can image by SID owner, create directory listings and image logically to an AD1 format by folder location. Additionally, the tool includes a hex viewer. In incident response, the suite can be used to collect volatile memory as well as a live registry.</p>
<h2><img loading="lazy" decoding="async" class="aligncenter wp-image-1773" src="https://compute-forensics.com/wp-content/uploads/2018/06/FTK_Imager-Free-Forensic-Software-300x158.jpg" alt="" width="600" height="316" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/FTK_Imager-Free-Forensic-Software-300x158.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/FTK_Imager-Free-Forensic-Software-768x404.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/FTK_Imager-Free-Forensic-Software-1024x539.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/FTK_Imager-Free-Forensic-Software-600x316.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/FTK_Imager-Free-Forensic-Software.jpg 1425w" sizes="auto, (max-width: 600px) 100vw, 600px" />9) <a href="https://www.gnu.org/software/ddrescue/">ddrescue</a> GUI by Hamish McIntyre-Bhatty</h2>
<p>This Linux GUI tool that simply put “copies data from one file or block device (hard disc, cd-rom, etc) to another, trying to rescue the good parts first in case of read errors.” ddrescue also produces a map file so you can go back to reimage the old parts of the disk that didn’t copy the first time in order to get a full transversal. It won’t only create an image filled 0s on the parts it can’t read as most imaging tools do. <strong>*Available on Caine</strong></p>
<h2>10) <a href="https://www.magnetforensics.com/magnet-acquire/">Acquire</a> by Magnet Forensics</h2>
<p>To get this hidden gem, you will have to register on Magnets website. Aquire has the imaging functions you find typically in FTK imager and others. MA shines when collecting from smartphones such as Apple and Android devices (forget about Blackberry!) The program will also take a full physical image of rooted android devices and output the data in an agnostic format. The items are best examined using Magnet’s Axiom or IEF.</p>
<p><a href="https://www.magnetforensics.com"><img loading="lazy" decoding="async" class="aligncenter wp-image-1134 size-full" title="Magnet Forensics Acquire can image Phones as well as Computers" src="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Magnet_Aquire_for_iOS-or-Smartphones.jpg?resize=747%2C498&amp;ssl=1" sizes="auto, (max-width: 747px) 100vw, 747px" srcset="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Magnet_Aquire_for_iOS-or-Smartphones.jpg?w=747&amp;ssl=1 747w, https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Magnet_Aquire_for_iOS-or-Smartphones.jpg?resize=300%2C200&amp;ssl=1 300w" alt="" width="745" height="497" data-attachment-id="1134" data-permalink="https://compute-forensics.com/top-ten-free-computer-forensic-software/magnet_aquire_for_ios-or-smartphones/" data-orig-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Magnet_Aquire_for_iOS-or-Smartphones.jpg?fit=747%2C498&amp;ssl=1" data-orig-size="747,498" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1520447623&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Magnet_Aquire_for_iOS-or-Smartphones" data-image-description="" data-medium-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Magnet_Aquire_for_iOS-or-Smartphones.jpg?fit=300%2C200&amp;ssl=1" data-large-file="https://i1.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Magnet_Aquire_for_iOS-or-Smartphones.jpg?fit=747%2C498&amp;ssl=1" /></a></p>
<p>In real cases these tools require specialist training, don’t hesitate to <a href="https://compute-forensics.com/contact-us/">contact us</a> should you have an enquiry!</p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-3 vc_hidden-sm vc_hidden-xs"><div class="vc_column-inner "><div class="wpb_wrapper">
<div class="stm_sidebar">

            <style type="text/css" scoped>
            .vc_custom_1452056597103{margin-right: 0px !important;margin-bottom: 30px !important;margin-left: 0px !important;}.vc_custom_1451998133493{margin-bottom: 30px !important;}.vc_custom_1452056633692{padding-top: 37px !important;padding-right: 30px !important;padding-bottom: 40px !important;padding-left: 30px !important;}.vc_custom_1527964913946{margin-bottom: 9px !important;}.vc_custom_1527964962623{margin-bottom: 17px !important;}.vc_custom_1527965000155{margin-bottom: 30px !important;}        </style>
        <div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1452056597103"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner vc_custom_1452056633692"><div class="wpb_wrapper"><div class="vc_custom_heading vc_custom_1527964913946 text_align_left" ><div style="font-size: 16px;color: #222222;text-align: left;font-family:Poppins;font-weight:600;font-style:normal" class="consulting-custom-title">Contact Us</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1527964962623" >
		<div class="wpb_wrapper">
			<p><span style="font-size: 13px; line-height: 22px;">Compute Forensics are based in London but are available for contracts and work in the global area. Please don’t hesitate to email us at expert@compute-forensics.com for a free online or call consultation.</span></p>

		</div>
	</div>
<div class="vc_btn3-container vc_btn3-inline vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-sm vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-left vc_btn3-color-white" href="https://compute-forensics.com/contact-us/" title=""><i class="vc_btn3-icon fa fa-phone-square"></i> contacts</a></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid vc_custom_1451998133493"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper"><div class="vc_btn3-container vc_btn3-left vc_custom_1527965000155 vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-lg vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-block vc_btn3-icon-left vc_btn3-color-theme_style_1" href="https://compute-forensics.com/pdf/" title="" target="_blank"><i class="vc_btn3-icon fa fa-file-pdf-o"></i> Computer Forensics Professional Services PDF</a></div></div></div></div></div>
</div>    
</div></div></div></div></div><div data-vc-full-width="true" data-vc-full-width-init="false" class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1459505959648"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper">
<section class="vc_cta3-container" >
    <div class="vc_general vc_cta3 third_bg_color vc_cta3-style-flat vc_cta3-shape-square vc_cta3-align-left vc_cta3-color-classic vc_cta3-icon-size-md vc_cta3-actions-right vc_custom_1530194067346 style=""">
                        <div class="vc_cta3_content-container">
                                    <div class="vc_cta3-content">
                <header class="vc_cta3-content-header">
                    <div class="vc_custom_heading" ><h2 style="font-size: 20px;color: #ffffff;line-height: 24px" class="consulting-custom-title">Are you looking for a Computer Forensic Consultant?</h2></div>                                    </header>
                            </div>
                        <div class="vc_cta3-actions"><div class="vc_btn3-container vc_btn3-right vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-md vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-right vc_btn3-color-theme_style_2" href="https://compute-forensics.com/contact-us/" title="">get a quote <i class="vc_btn3-icon fa fa-chevron-right"></i></a></div></div>        </div>
                    </div>
</section></div></div></div></div><div class="vc_row-full-width vc_clearfix"></div>
</div>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
