A curated list of Digital Forensics Tools with some useful links & usage.
To get information about any other tool please visit the Forensic Wiki.
๐ข Some Important Concepts
Digital Forensics: An applicaiton of science to uncover facts, solve crime by acquiring the evidence analyzing the evidence and finally prepping it for any court of law. All the steps must be completed while maintaining the chain of custody and integrity.
Forensic Image/Copy: This term refers to a bit perfect copy/clone of any storage device.
It is important to understand that any forensic cloning tool worth it's salt would ensure integrity of evidence.
This is why in forensic terms a simple backup is not enough.
Data recovery tools look into unallocated sectors to find the files that were thought to be lost. They reach out
to a very low level, below all the abstraction layers.
I am not able to find any good open source MFT Parsing/Analysis Tools. Calling the open source community! Please, in the spirit of Hacktoberfest find and add good MFT Analysis Tools here ^.^
Create a new file to explain File System in depth . That how it's a layout and how it interacts with the OS through a driver and everything about it to make this concept super clear and not just a superfluous idea that is taught in Unis.
We need to make it clear, to the point where everyone who reads the document can theoretically devise their own File System.