As digital evidences can be comparatively more fragile in nature and easier to alter and tamper with, there are various digital forensic tools that helps to simplify the process and gets the job done.
Digital forensic tools can either be open source or proprietary: open source tools are free and provides access to their source code whereas proprietary tools are costly and users either have limited or no access to their source code.
These digital forensic tools, whether hardware or software or a combination of both, perform various functions.
These includes write-blocking, i.e., permitting read-only access to data storage devices without compromising the integrity of the data; imaging and disk cloning or making bit stream copies of the original drive; authentication and evidence preservation using hash algorithms; recovery of files and folders, whether hidden or deleted; live acquisition (when the computer/device is in switched on mode) as well as RAM and swap/paging file analysis; keyword searching; metadata searches and filtering; carving or locating fragments or entire file structures; decrypting and password cracking; and ultimately automatic generation of the final report.
Some of the most prevalent tools, both open source and proprietary, with their features have been listed below:
1. FTK Imager
FTK Imager is a free data preview and imaging tool developed by AccessData that helps in assessing electronic evidence to determine if further analysis with a forensic tool such as AccessDataForensic Toolkit (FTK) will be required. FTK Imager can create forensic imagesof computer data without making changes to the original evidence. It also offers various options such as file size and the format of the images.
Features of FTK Imager:
- Create forensic images of local hard drives, CDs and DVDs, thumb drives or other USB devices, entire folders, or individual files from various places within the media.
- Preview files and folders on local hard drives, network drives, CDs and DVDs, thumb drives or other USB devices.
- Preview the contents of forensic images stored on the local machine or on a network drive.
- Export files and folders from forensic images.
- See and recover files that have been deleted from the Recycle Bin, but have not yet been overwritten on the drive.
- Create hashes of files to check the integrity of the data by using either of the two hash functions available in FTK Imager: Message Digest 5 (MD5) and Secure Hash Algorithm (SHA-1).
- Also gives you the option of memory capture including page files.
2.Magnet RAM Capture
Magnet RAM Capture is a free imaging tool designed to capture the physical memory or RAM of a suspect’s computer, allowing investigators to recover and analyse valuable artefacts that are often only found in memory.
Features
- Magnet RAM Capture has a small memory footprint, meaning investigators can run the tool while minimising the data that is overwritten in memory.
- Export the captured memory data in Raw (.DMP/.RAW/.BIN) format and easily upload into most of the leading analysis tools including Magnet AXIOM, Magnet IEF, Volatility, and Redline.
- It supports a wide range of 32- and 64-bit Windows operating systems.
3.FireEye Redline
FireEye’s Redline is another memory tool for collecting and analysing a potentially compromised endpoint memory and file structure.
Features
- Thoroughly audit and collect all running processes and drivers from memory, file-system metadata, registry data, event logs, network information, services, tasks and web history.
- Analyse and viewimporteddata,includingnarrowingandfilteringresultsaroundagiven timeframe using Redline’s TimeWrinkle and TimeCrunch features.
- Streamline memory analysis with a proven workflow for analysing malware based on relative priority.
- Perform Indicators of Compromise (IOC) analysis (Windows only).
- Use whitelists to filter out known valid data based on MD5 hash value.
- Redline 2.0 is now able to collect investigative artefacts available from OS X and Linux environments.
4.Volatility Framework
The Volatility Framework is an open source memory forensics tool developed by an independent non-profit organisation called the the Volatility Foundation. It can analyse memory images or RAM dumps from 32- and 64-bit Windows, Linux, MAC and Android systems.
Moreover, its modular design allows it to easily support new operating systems and architectures as they are released.
Features
- Extensible and scriptable API gives you the power to go beyond and continue innovating.
- Comprehensive coverage of file formats – volatility can analyse raw dumps, crash dumps, hibernation files, VMware .vmem, VMware saved state and suspended files (.vmss/.vmsn), VirtualBox core dumps, LiME (Linux Memory Extractor), expert witness (EWF), and direct physical memory over Firewire.
- Fast and efficient algorithms toanalyse RAM dumps from large systems without unnecessary overhead or memory consumption.
- Serious and powerful community of practitioners and researchers who work in the forensics, IR, and malware analysis fields.
- Forensics/IR/malware focus – Volatility was designed by forensics, incident response, and malware experts to focus on the types of tasks these analysts typically form.
5.Autopsy
Autopsy is the premier open source forensics platform developed by Basis Technology, which allows you to examine a hard drive or mobile device and recover evidence from it.
It’s plug-in architecture also enables extensibility from community-developed or custom-built modules.
Features
- It has an automated and intuitive workflow.
- Supports both hard drives and smartphones
- Extracts artifacts from web browsers
- MD5 hash lookup
- Indexed keyword search and Deleted file carving
- EXIF data extraction from JPEG images
- Timeline analysis for all events
- Standard Android database parsing
- Extension mismatch detection
- Email message extraction Network-based collaboration, i.e., forensic team members can collaborate by examining data from the same case at the same time.
6.FTK (Forensic Tool Kit)
AccessData FTK is a commercial analysis tool for forensic images of hard drives or other storage media that helps to find relevant evidence for speedy analysis.
Features
- URL detection and parsing capabilities across devices without regard to browser, neatly organised under one section to easily review the data
- FTK will ingest and support updated versions of LX01 and E01 images.
- Import and parse AFF4 images created from Mac computers which are usually generated by third-party solutions like MacQuisition by BlackBag.
- Automatically import and expand a nested forensic image with image within an image support.
- Export your data into a portable case for offline review.
- Locate, manage, and filter mobile data more easily with a dedicated mobile tab.
- View all associated EXIF data, including location, make and model of the device used to capture the images or video.
- Collect, process and analyse datasets containing Apple file systems that are encrypted, compressed or deleted.
- Decrypt a computer drive encrypted by the latest version of McAfee Drive Encryption and new L01 export support.
7.EnCase
EnCase is a proprietary tool developed by Guidance Software, built for deep-level digital forensic investigation, powerful processing and integrated investigation workflows with flexible reporting options.
Features
- Acquire data from the widest variety of devices, including over 25 types of mobile devices such as smartphones, tablets, and GPS
- Empowers investigators to conduct investigations with powerful processing speeds, advanced index searching and comprehensive language support
- Provides encryption support for Microsoft Windows 10 Bitlocker XTS-AES, DellData Protection 8.17 and SymantecTM PGP v10.3.
- Supports APFS and send the output as an EnCase logical evidence file
- Acquires machines equipped with Apple T2 Security chips without additional hardware, drive partitions, or hassle. And if the user is logged in, no credentials are required
- With EnCase Forensic, examiners can leverage credentials to collect from data repositories in the cloud, such as Microsoft O365 and SharePoint.
Mobile Forensic Tools: There are also a series of tools that are targeted towards performing various levels of extraction and analysis of evidences from mobile devices.
8.Cellebrite UFED
UFED is one of the most popular mobile evidence extraction tools. It is available on multiple platforms such as UFED 4PC, which is a software format with access and extraction capabilities on the existing PC or laptop; while UFED Touch2 is portable and enables comprehensive extraction capabilities anywhere, whether in the lab, a remote location, or in the field.
UFED Physical Analyzer then ingests data extractions from Cellebrite UFEDfor recovering and examining digital data from the broadest range of digital devices, applications and the cloud.
Features
- Bypass pattern, password or PIN locks and overcome encryption challenges quickly on popular Android and iOS devices.
- Perform logical, file system and physical extractions to get the most data out of the digital devices.
- Use exclusive bootloaders, automatic EDL capability, Smart ADB and more.
- Extract data from mobile phones, drones, SIM Cards, SD cards, GPSdevices and more.
- An advanced graphical timeline allows you to build a storyline of events, and zoom in on a specific timeframe of interest.
- Carve unallocated space in a device’s memory to recover deleted data and media files.
- Reassemble device and application data into readable formats with SQLite
- Capture private and public data from leading social media, cloud backup and cloud data sources using Cellebrite UFED Cloud.
- Each team member can use Cellebrite Reader, a complementary tool, to navigate and tailor reports to their specific requirements.
9.Oxygen Forensic Detective
Oxygen Forensic Detective is an all-in-one forensic software platform built to extract, decode, and analyse data from multiple digital sources such as mobile and IoT devices, device backups, UICC (SIM card) and media cards, drones, and cloud services.
It can also find and extract a vast range of artefacts, system files as well as credentials from Windows, macOS, and Linux machines.
Features
- Displays logins, passwords and tokens extracted from mobile devices by decrypting credentials from the iOS keychain and Android KeyStore and finding them in application databases and web forms.
- Provides advanced physical extraction for LG, Motorola, Samsung, MTK, Kirin, Spreadtrum and Qualcomm Android devices.
- It enables lock screen bypass and either requires no root rights or offers the ability to gain root rights and conduct a full physical extraction of Android devices with installed Android OS 7, 8, 9 and 10.
- Displays user data that has been extracted and parsed from popular Social Networks, Messengers, Web Browsers, Navigation, Productivity, Travel, Finance, Fitness, Drone and Multimedia apps. Investigators can view app account details, contacts, messages, calls, logs, cache, and other relevant data.
- Built-in Oxygen Forensic Cloud Extractor acquires data from the most popular cloud services to include: WhatsApp, iCloud, Google, Microsoft, Mi Cloud, Huawei, Samsung, E-Mail (IMAP) Servers and more.
- Collects geo data from various sources such as photo and video EXIF headers, web connections information and applications databases.
- Enables the export of data from any section to many popular file formats includingPDF, XLSX, XML, HTML, JSON Project VIC.
10. MSAB XRY
XRY is another powerful and efficient software application running on Windows operating system which provides secure extraction of high-quality data from mobile devices in less time while fully maintaining the integrity of the evidence.
Features
- Over 29,800 device and app profiles supported, including drones.
- Support for the latest Android and iOS version and the best available support on the market for Chinese Chipsets like MTK, Spreadtrum, Coolsand & Infineon.
- Image recognition engine, which classifies images into categories such as drugs, weapons and people
- Filter by location to find data within a selected geo-range.
- Deleted data from iCloud Backups
- Includes Android exploits for bypassing security locks
- Includes XRY Photon for acquiring unencrypted data from encrypted apps, when other methods don’t work
- Extract only selected file types from specified time frames
11.Paraben E3:DS
Paraben E3:DS provides everything for mobile forensics fromlogical imaging, physical imaging, chip dumps, bypass options, cloud, to App processing. It adds a large variety of evidence into a single interface to be able to search, parse, review and report on the digital data from most digital sources.
Features
- Mobile Data Imaging (Logical & Physical)
- JTAG & Chip Dump Processing
- Chip Bypass Acquisitions
- Android Root Imaging and iOS Jailbreak Processing
- Cloud Data Processing (Office365, Amazon Alexa, G-Suite, Twitter)
- IoT Data Processing (DJI Drone, Fitbit, Smartwatches)
- Automated malware ranking based on App access control
- 5+ Reporting Options (Localisation with Reports)
12. MOBILedit Forensic Express
MOBILedit Forensic Express by Compelson is an all in one solution for mobile phone investigations with phone and cloud extractor, data analyser and report generator.
Features
- The software supports thousands of handsets including popular operating systems such as iOS, Android , Blackberry, Windows Phone, Windows Mobile, Bada, Symbian, Meego, Mediatek, Chinese phones, and CDMA phones.
- It can bypass the lock-screen on a wide range of Android phones.
- In addition to advanced logical extraction, it also provides Android physical data acquisition, allowing you to extract physical images of investigated phones and have exact binary clones.
- Data is analysed for its meaning so you see it on a timeline as a note, a photo, a video or a flow of messages no matter what app was used to send them.
- MOBILedit Forensic Express retrieves the deleted data and presents it clearly in a special section of the report.
- Password breaker uses GPU acceleration and multi-threaded operations for maximum speed.
- Extract multiple phones at the same time, and generating multiple outputs for each one.
- Cloud Analyzer will locate all iOS backups in the cloud and let you choose which ones you want to extract, analyse and create reports for.
- Photo recogniser automatically locates and recognises suspicious content in photos such as weapons, drugs, nudity, currency and documents.
- Supply photos of faces you want to find, and let Face Matcher find right photos in a phone or PC.
- Import and analyse data files exported from Cellebrite UFED and Oxygen reports to get even more data.
- Export all data to UFED, so you can use the UFED Viewer or Analytics for further processing to move your investigation forward.
Leave a Reply