Precaution

Don't use these contents for malicious purpose. Intended for
- Individuals who understand network fundamentals
- Use in authorized environments only
- To improve security prosture

Navigation Menu

Tools

Forensics Tools


현재 국내는 별도의 디지털포렌식 인증 기관이 없어 해외에서 널리 인정된 도구를 많이 사용하고 있고, 또 인정해주는 편이다. 대표적인 해외 인증으로는 NIST의 CFTT(Computer Forensics Tool Testing)가 있다. 인증받은 도구의 목록은 CFTT Catalog에서 쉽게 확인할 수 있다.
실제 분석을 수행하다보면 인증받은 도구의 기능적인 한계나 불편함으로 제3의 도구를 사용하는 경우가 있다. 이 경우에는 최종적으로 인증받은 도구로 결과를 한번 더 검증하는 작업이 요구된다. 도구의 장.단점은 목적에 따라 다르기 때문에 자신의 업무 목적에 맞는 적합한 도구를 사용하기 바란다. 다음의 목록이 선택에 조금이나마 도움이 되길 바란다.
Last updated: 2013-09-14

통합 포렌식 도구 (Integrated Forensics Tools)
NameInterfacePlatformManufacturerLicence
EnCase ForensicGUIWindowsGuidance SoftwareCommercial
FTK (Forensic Toolkit)GUIWindowsAccessDataCommercial
Forensic ExplorerGUIWindowsGetDataCommercial
X-Ways ForensicsGUIWindowsX-Way Software Technology AGCommercial
Mac Marshal Forensic Edition™GUIMacintoshArchitecture TechnologyCommercial
BlackLightGUIAnywhereBlackBag TechnologiesCommercial
AutopsyGUIAnywhereBrian CarrierOpensource


라이브 CD/VM (Live CD/VM)
NameInterfacePlatformManufacturerLicence
SIFTSANSFreeware
PALADINSAMURIFreeware
DEFTDEFT StaffFreeware
Helixe-fenseCommercial
BackTrackBackTrack LinuxFreeware
C.A.IN.ECaineFreeware


라이브 포렌식 (Live Forensics)
NameInterfacePlatformManufacturerLicence
FPLive_winCLIWindowsJK KimFreeware
FRED (First Responder’s Evidence Disk)GUIWindowsDark Particle LabsFreeware
WFT (Windows Forensic Toolchest)CLIWindowsFoolMoonFree/Comm
Dual Purpose Volatile Data Collection ScriptCLIWindowsCorey HarrellOpensource
IRCR (Incident Response Collection Report)CLIWindowsmcleodjpOpensource
COFEE (Computer Online Forensic Evidence Extractor)CLIWindowsMicrosoftonly Law enforcement
MIR (MANDIANT Intelligent Response)GUIWindowsMandiantCommercial
OnLineDFS (OnLine Digital Forensic Suite)CLIWindowsCSTCommercial
MacResponse LE™GUIMacintoshAISOpensource


이미징 하드웨어 (Imaging Hardware)
NameInterfacePlatformManufacturerLicence
Image MASSter SeriesIntelligent Computer Solutions, Inc.Commercial
Dossier & FalconLogicubeCommercial
TD3TableauCommercial
MagicubeDataExpertCommercial


이미징 소프트웨어 (Imaging Software)
NameInterfacePlatformManufacturerLicence
FTK Imager (Lite)
CLI FTK Imager for Debian, Ubuntu, Fedora, RedHat, Mac OS.
GUIWindowsAccessDataFreeware
Tableau ImagerGUIWindowsTABLEAUFreeware
(need Tableau W/B)
X-Ways ImagerGUIWindowsX-Ways Software Technology AGCommercial
EnCase Forensic
Imager
GUIWindowsGuidance SoftwareFreeware
FAU DDCLIWindowsGeorge M. Garner Jr.Freeware
ODINGUIWindowsJensHOpensource
OSFCloneCLIWindowsPassMark SoftwareOpensource
ewfacquire, ewfacquirestreamCLIUnix-basedJoachim MetzOpensource
GuymagerGUILinuxvogu00Freeware
dcflddCLIUnix-basedNick HarbourOpensource
MacQuisitionCLIMacintoshBlackBag TechnologiesOpensource


쓰기방지장치 (Write Blocker)
NameInterfacePlatformManufacturerLicence
Tableau Forensic BridgeTableauCommercial
Wiebetech DockWiebetechCommercial


이미지 마운트 (Image Mounting)
NameInterfacePlatformManufacturerLicence
Arsenal Image MounterGUIWindowsArsenal ReconFreeware
Mount Image ProGUIWindowsGetDataCommercial
OSFMountGUIWidowsPassMark SoftwareFreeware
VHD toolCLIWindowsMicrosoftFreeware
LiveViewGUIWin & LinCMU/td>
Freeware
raw2vmdkGUIAnywhereZapotek/td>
Freeware
FTK ImagerGUIWindowsAccessDataFreeware
P2 eXplorerGUIWidowsParabenFreeware
ImDiskGUIWindowsLTRDATAOpensource


원격 포렌식 (Remote Forensics)
NameInterfacePlatformManufacturerLicence
F-Response SeriesGUIAnywhereF-ResponseCommercial


메모리 획득 (Memory Acquisition)
NameInterfacePlatformManufacturerLicence
DumpItCLIWindowsMoonSolsFreeware
win(32/64)ddCLIWindowsMoonSolsFree/Comm
FastDump ProCLIWindowsHBGaryCommercial
mddCLIWindowsManTechOpensource
Memorize (for Mac)GUIWindowsMandiantFreeware
FTK Imager (Lite)
CLI FTK Imager for Debian, Ubuntu, Fedora, RedHat, Mac OS.
GUIWindowsAccessDataFreeware
WinPmemCLIWindowsMichael CohenFreeware
fmemCLILinuxniekt0Freeware
LiMECLILinuxJoe SylveFreeware
Second Look® Linux Memory AcquisitionCLILinuxRaytheon PikewerksCommercial
Mac Memory Reader™CLIMacintoshMac Marshal™Freeware
OSXPMemCLIMacintoshMichael CohenFreeware


메모리 분석 (Memory Analysis)
NameInterfacePlatformManufacturerLicence
RedlineGUIWindowsMandiantFreeware
VolatilityCLIAnywhereVolatile SystemsOpensource
Memorize & Audit ViewerGUIWindowsMandiantFreeware
Responder ProGUIWindowsHBGaryCommercial
Second Look® Linux Memory AnalysisCLILinuxRaytheon PikewerksCommercial
VolafoxCLIMac OSn0fateOpensource
VolafunxCLIFreeBSDn0fateOpensource


타임라인 분석 (Timeline Analysis)
NameInterfacePlatformManufacturerLicence
log2timelineCLILinux & MacKristinn GudjonssonFreeware
plasoCLIWin & MacKristinn GudjonssonFreeware
4n6timeGUIWin & MacKristinn GudjonssonFreeware
TimelinerGLIWindowsWoanwareFreeware/Opensource
Timeline ReportGUIEnCase-BasedGeoff BlackOpensource


레지스트리 분석 (Registry Analysis)
NameInterfacePlatformManufacturerLicence
REGA(REGistry Analyzer)GUIWindows4&6techCommercial
Registry ReconGUIWindowsArsenal ReconCommercial
Registry WorkshopGUIWindowsTorchSoftCommercial
RegRipperCLIWindowsHarlan CarveyOpensource
UserAssistGUIWindowsDidier StevensFreeware
Registry Binary ParserGUIWindowswoanwareFreeware/Opensource
RegRipperRunnerGUIWindowswoanwareFreeware/Opensource
ForensicUserInfoGUIWindowswoanwareFreeware/Opensource
USBDeviceForensicsGUIWindowswoanwareFreeware/Opensource
Windows USB Storage Parser (usp)CLIWindowsTZWorksFreeware/Commercial
Yet Another Registry Utility (yaru)CLIWindowsTZWorksFreeware/Commercial
Windows ShellBag Parser (sbag)CLIWindowsTZWorksFreeware/Commercial
Computer Account Forensic Artifact Extractor (cafae)CLIWindowsTZWorksFreeware/Commercial


파일시스템 메타데이터 (Filesystem Metadata)
NameInterfacePlatformManufacturerLicence
mft2csvGUIWindowsjoakimFreeware
anlyzeMFTCLIAnywhereDavid KovarOpensource
MFTViewGUIWindowsSanderson ForensicsFreeware
NTFS Directory EnumeratorCLIWindowsTZWorksFreeware/Commercial
Windows $MFT and NTFS Metadata Extractor ToolCLIWindowsTZWorksFreeware/Commercial
Windows INDX Slack ParserCLIWindowsTZWorksFreeware/Commercial
Graphical Engine for NTFS Analysis (gena)CLIWindowsTZWorksFreeware/Commercial


바로가기 파일 분석 (LNK Analysis)
NameInterfacePlatformManufacturerLicence
Windows LNK Parsing Utility (lp)CLIWindowsTZWorksFreeware/Commercial
lnkanalyserCLIWindowsWoanwareFreeware


로그 분석 (Log Analysis)
NameInterfacePlatformManufacturerLicence
Event Log ExplorerGUIWindowsFSPro LabsCommercial
Log ParserCLIWindowsMicrosoftFreeware
NTFS Log TrackerGUIWindowsblueangelFreeware
NTFS TriForceCLIWindowsDavid CowenFreeware
Windows Journal Parser (jp)GUIWindowsTZWorksFreeware/Commercial
Windows Event Log ViewerGUIWindowsTZWorksFreeware/Commercial
Windows Event Log ParserGUIWindowsTZWorksFreeware/Commercial
UsnJrnl2CsvCLIWindowsjoakimFreeware
LogFile ParserCLIWindowsjoakimFreeware


악성코드 분석 (Malware Analysis)
NameInterfacePlatformManufacturerLicence
PeStudioGUIWindowsMarc OchsenmeierFreeware
PEViewGUIWindowsWayne J. RadburnFreeware
AutomaterCLIWin & LinTEKDEFENSEOpenSource
NoribenCLIWindowsRurikOpenSource


프리패치 분석 (Prefetch Analysis)
NameInterfacePlatformManufacturerLicence
WinPrefetchViewGUIWindowsNirSoftFreeware
PrefetchForensicsGUIWindowswoanwareFreeware
APFA(Advanced Prefetch File Analyzer)GUIWindowsAllan S HayFreeware
Prefetch ParserCLIWindowsSANSFreeware
Windows Prefetch ParserCLIAnywhereTZWorksFreeware/Commercial


웹 브라우저 사용 흔적 (Web Browser Artifacts)
NameInterfacePlatformManufacturerLicence
WEFA(WEb browser Forensic Analyzer)GUIWindows4&6 TechCommercial
Web HistorianGUIWindowsMandiantFreeware
IEF(Internet Evidence Finder)GUIWindowsMagnet ForensicsCommercial
ChromeForensicsGUIWindowswoanwareFreeware
FireFoxForensicsGUIWindowswoanwareFreeware
firefoxsessionstoreextractorGUIWindowswoanwareFreeware
Windows ‘index.dat’ Parser (id)CLIWindowsTZWorksFreeware/Commercial
BrowsingHistoryViewGUIWindowsNirSoftFreeware
IECacheViewGUIWindowsNirSoftFreeware
IECookiesViewGUIWindowsNirSoftFreeware
IEHistoryViewGUIWindowsNirSoftFreeware
ChromeCacheViewGUIWindowsNirSoftFreeware
ChromeHistoryViewGUIWindowsNirSoftFreeware
MozilaCacheViewGUIWindowsNirSoftFreeware
MozilaCookieViewGUIWindowsNirSoftFreeware
MozilaHistoryViewGUIWindowsNirSoftFreeware
SafariCacheViewGUIWindowsNirSoftFreeware
SafariHistoryViewGUIWindowsNirSoftFreeware
OperaCacheViewGUIWindowsNirSoftFreeware
WebBrowserPassViewGUIWindowsNirSoftFreeware
MyLastSearchGUIWindowsNirSoftFreeware


데이터베이스 분석 (Database Analysis)
NameInterfacePlatformManufacturerLicence
Exchange EDB ViewerGUIWindowsLepide SoftwareFreeware
ESEDatabaseViewGUIWindowsNirSoftFreeware
EseDbViewerGUIWindowswoanwareFreeware
SQLite ExpertGUIWindowsBogdan UrecheCommercial
Oxygen SQLite ViewerGUIWindowsOxygen ForensicCommercial
SQLite Database BrowserGUIWin & MacTabuleiroOpensource
OracleForensics Tools


이메일 분석 (Email Analysis)
NameInterfacePlatformManufacturerLicence
E-mail ExaminerGUIWindowsParabenCommercial
Mail ViewerGUIWindowsMiTeCFreeware
Email UtilitiesGUIWindowsStellar Information SystemsCommercial
Email Recovery ToolsGUIWindowsLepide SoftwareCommercial


포맷 분석 (Format Analysis)
NameInterfacePlatformManufacturerLicence
010Editor TemplatesGUIWindowsSweetScape SoftwareCommercial
FileInsightGUIWindowsMcAfeeFreeware
Structed Storage ViewerGUIWindowsMiTeCFreeware
OffVisGUIWindowsMicrosoftFreeware
Windows Portable Executable Viewer (pe_view)GUIWindowsTZWorksFreeware/Commercial
PDF ParserCLIAnywhereDidier StevensFreeware
peedpdfCLIAnywhereJose Miguel EsparzaFreeware
PDF Stream DumperGUIWindowsDavid ZimmerFreeware


복원지점/볼륨섀도복사본 분석 (Restore Point/VSC))
NameInterfacePlatformManufacturerLicence
RP Log TrackerGUIWindowsblueangelFreeware
libvshadowCLIWindowsJoachim MetzFreeware
ShadowExplorerGUIWindowsShadowExplorerFreeware
ShadowKitGUIWindowsDavid DymFreeware
VSC ToolsetGUIWindowsJason HaleFreeware
ReconnoitreGUIWindowsSanderson ForensicsCommercial


자바 IDX 분석 (Java IDX Analysis))
NameInterfacePlatformManufacturerLicence
RP Log TrackerCLIAnywhereBrian BaskinOpenSource
JavaidxCLIWindowsMark WoanOpenSource
IdxparserCLIWindowsHarlan CarveyOpenSource


추가적인 아티팩트 분석 (Any Other Artifacts)
NameInterfacePlatformManufacturerLicence
Windows File AnalyzerGUIWindowsMiTeCFreeware
Windows Jump List Parser (jmp)CLIWindowsTZWorksFreeware/Commercial
Portable Executable Scanner (pescan)CLIWindowsTZWorksFreeware/Commercial
autorunnerGUIWindowswoanwareFreeware
exefinderGUIWindowswoanwareFreeware
JumpListerGUIWindowswoanwareFreeware
shimcacheparserGUIWindowswoanwareFreeware
Windows Search Index ExtractorGUIWindowsFilesig SoftwareCommercial
Thumbnail Database ViewerGUIWindowsIgor TolmacheFreeware
SFP(Simple File Parser)GUIWindowsChris MayhewFreeware


네트워크 포렌식 (Network Forensics)
NameInterfacePlatformManufacturerLicence
WireSharkGUIAnywhereWireSharkFreeware
NetworkMinerGUIWindowsNETRESECCommercial
RSA NetWitnessGUIWin & LinRSACommercial
OstinatoGUIAnywherePstavirsOpensource
Packet BuilderGUIWindowsColasoftFreeware
SplitCapCLIWindowsNETRESECOpensource
tsharkCLIAnywhereWireSharkFreeware
ScapyCLIAnywherePhilippe BiondiOpensource
tcpdumpCLIAnywhereFreeware
DNS Query Utility (dqu)CLIWindowsTZWorksFreeware/Commercial
Packet Capture ICMP Carver (pic)CLIWindowsTZWorksFreeware/Commercial
Network Xfer Client/Server Utility (nx)CLIWindowsTZWorksFreeware/Commercial
snorbertCLIWindowsWoanwareFreeware
SessionViewerCLIWindowsWoanwareFreeware
enumdotnetCLIWindowsWoanwareFreeware


패스워드 공격(Password Attack)
NameInterfacePlatformManufacturerLicence
EPRB(ElcomSoft Password Recovery Bundle)GUIWindowsElcomSoftCommercial
PPR(Passware Password Recovery)GUIWindowsPasswareCommercial
SAMInsideGUIWindowsInsideProFreeware
ophcrackGUIAnywhereOBJECTIF SECURITEFreeware
L0PHTCRACKGUIWindowsL0pht HoldingsCommercial


윈도우 패스워드(Windows Password)
NameInterfacePlatformManufacturerLicence
Cain & AbelGUIWindowsMassimiliano MontoroFreeware
Windows Password RecoveryGUIWindowsPasscape SoftwareFreeware
pwdump7CLIWindowsTarascoFreeware
gsecdumpCLIWindowsTruesecFreeware
PWDumpXCLIWindowsReed ArvinFreeware
lsadump2CLIWindowsizarFreeware
creddumpCLIWindowsmooyixOpensource
NTPWEditGUIWindowsVadim DruzhinFreeware
NTPasswordCLIWindowsPogostickFreeware


모바일 포렌식 (Mobile Forensics)
NameInterfacePlatformManufacturerLicence
MD SeriesGMDSystemCommercial
Cellebrite Mobile ForensicsCellebriteCommercial
Device SeizureParabenCommercial
XRY SeriesMicro SystemationCommercial
Oxygen Forensic® SuiteGUIWindowsOxygen SoftwareCommercial
MPE+GUIWindowsAccess DataCommercial
LanternGUIMacKatanaForensicsCommercial
iPhone Backup BrowserGUIWindowsrene.devichiCommercial


헥스 편집기 (Hex Editor)
NameInterfacePlatformManufacturerLicence
010EditorGUIWindowsSweetScapeCommercial
WinHexGUIWindowsX-Ways Software Technology AGCommercial
HexWorkshopGUIWindowsHexWorkshopCommercial
HxDGUIWindowsMael HorzFreeware


해쉬 분석 (Hash Analysis)
NameInterfacePlatformManufacturerLicence
HashTabGUIWin & MacImplbitsFree/Comm
md5deep/hashdeepCLIAnywhereJesse KornblumFreeware
ssdeepCLIAnywhereManTechFreeware
NSRL HashsetsNISTFreeware


완전삭제 (Wipe/Sanitization)
NameInterfacePlatformManufacturerLicence
EraserGUIWindowsThe Eraser ProjectFreeware
BCWipeGUIWin & LinJeticoCommercial
SDeleteCLIWindowsSysinternalsFreeware
Secure EraseCLIWin & LinCMRRFreeware


데이터 복구 (Data Recovery)
NameInterfacePlatformManufacturerLicence
RMF(Recover My Files)GUIWindowsGetDataCommercial
R-StudioGUIAnywhereR-Tools TechnologyCommercial
Power Data RecoveryGUIWindowsMiniTool® SolutionCommercial


그 밖에… (Other Tools)
NameInterfacePlatformManufacturerLicence
HighlighterGUIWindowsMandiantFreeware
BinTextGUIWindowsMcAfeeFreeware
DCodeGUIWindowsDigital DetectiveFreeware
TimeLordGUIWindowsHarry ParsonageFreeware
ArgosDFASGUIWindowsDUZONCommercial


포렌식 도구 사이트 (dForensics Tool Sites)
Site
MiTeC
TZWorks
Software for Computer Forensics
Woanware
NirSoft
CFTT Catalog
mft2csv
Open Source Digital Foresncis
RCE Tool Libary
Sysinternals
ForensicKB
Tools Tools Reviewed by Polynomeer on 오후 8:32 Rating: 5

댓글 없음:

Like Us

Powered by Blogger.