Dfda1 Compressed
Dfda1 Compressed
DIGITAL ASSIGNMENT 1
1. Study exercise on various Forensic tools (Min. 15) with Tool Name, Purpose,
Supportive OS, Category, Type, Logo and Source for documentation, downloads, etc .
1.GHIRO
2. Autopsy
Source: https://www.sleuthkit.org/autopsy/
3.RegRipper
5.EnCase
Source: https://www.guidancesoftware.com/encase-forensic
6.Forensic Toolkit (FTK)
Source: https://accessdata.com/products-services/forensic-toolkit-ftk
7.Volatility
Source: https://www.volatilityfoundation.org/
8.Wireshark
9.OSForensics
Source: https://www.osforensics.com/
10.Cellebrite UFED
Source: https://www.cellebrite.com/en/home/
11.1X-Ways Forensics
Source: https://www.x-ways.net/forensics/
Source: https://dff.readthedocs.io/en/latest/
13.PALADIN Toolbox
Source: https://www.sumuri.com/software/paladin/
Source: https://www.caine-live.net/
File Viewer
You can view over 150 different file types with File Viewer Lite. Simply drag and drop
a file onto File Viewer Lite to display the native view of the file.
Play Multimedia Files
File Viewer Lite supports a large number of audio and video formats. If you have a
song or movie file that Windows Media Player does not recognize, chances are you can
open it with File Viewer Lite.
View File Information
Use the Info panel to view information about each file, such as the file type, file size,
and location. The Info panel also displays hidden metadata stored in the file. You can
export the file information to a text file by selecting File -> Export File Info.
Copy File Data
You can copy text and image data from files opened with File Viewer Lite. The data is
stored in the Windows clipboard so you can paste into into another application.
Four Different Types of Views
File Viewer Lite allows you to view file contents in Native View, Text View, Hex View,
and Icon View
1. Native View
Native view displays the standard view for supported file formats.
2. Text View
Text view displays the textual data of both text and binary files.
3. Hex View
Install R-Drive Image:Download and install R-Drive Image from the official website:
R-Drive Image.Launch R-Drive Image:Open the R-Drive Image application.
Choose Destination:
Select where you want to save the disk image. This could be an external hard drive,
network location, or another storage device.
Configure Image Options:
Set the image file name and specify additional options such as compression level and
splitting the image into smaller files if needed.
Verify Options:
Review the selected source, destination, and image options to make sure everything
is configured correctly.
Click the "Start" or "Create Image" button to initiate the imaging process.
Monitor Progress:R-Drive Image will display a progress bar indicating the status of
the imaging process. You can monitor the progress in real-time.
Complete the Imaging Process:Once the imaging process is complete, you'll receive a
notification indicating the success.
RECUVA
Recuva accommodates both newcomers and experienced professionals, facilitating
an efficient recovery process.One of its key features is the ability to selectively
recover files, allowing users to specify the types of files they intend to retrieve.
Alternatively, users can opt for a comprehensive recovery of all file types. Recuva
offers two scanning modes: Quick Scan and Deep Scan. The Quick Scan option
swiftly identifies recently deleted files, while the Deep Scan mode meticulously
searches for more intricate and potentially fragmented files.Recuva addresses data
security with its "Secure Overwrite" feature, which enables the permanent deletion of
sensitive files by overwriting them with random data. Moreover, the software offers a
preview function, enabling users to view images and text files before initiating the
recovery process, enhancing accuracy and reducing unnecessary recovery
attempts.Efficient file management is another highlight of Recuva. The software
includes filtering and sorting options that allow users to sift through search results
based on various parameters, such as file name, size, modification date, or file path.
This assists in streamlining the selection of desired files for recovery.
2. Perform recovery of deleted files in a specific drive
File recovered: tile.png
Before Recovery:
File deleted from C drive:
File deleted from recycle bin:
BEFORE:
Hash obtained:
AFTER:
HASH OBTAINED: