CFTT Computer Forensics Tool Testing HandBook - 08.11.2015.pdf
(
900 KB
)
Pobierz
Contact: James Lyle
Computer Forensics Tool Testing Program
Office of Law Enforcement Standards
National Institute of Standards and
Technology
HAVE YOUR COMPUTER FORENSICS TOOLS BEEN TESTED?
NIJ, DHS, and other LE practitioners partnered with NIST to create a testing
program for computer forensics tools. It is called the Computer Forensics Tool
Testing (CFTT) program. The CFTT tests tools to determine how well they perform
core forensics functions such as imaging drives and extracting information from
cell phones.
Benefits:
When you use a tested tool, you can be assured what the tool’s
capabilities really are.
If a tool has limitations, you will know what they are so you can take
appropriate action (e.g., use another tool, use additional procedures,
etc.)
You have a head start on validating the tool for use in your lab
This booklet contains the results for tests performed under the CFTT program. The
tests are organized by functional area tested (e.g., disk imaging tools or cell
phone acquisition tools). Within each functional area, the tools are listed
alphabetically.
The CFTT continues to test tools. See
http://www.ojp.usdoj.gov/nij/publications/welcome.htm
(select computer
forensics tools testing) or
www.cftt.nist.gov
for the current list. The CFTT site also
contains the specification against which the tools are tested and the testing
software and complete methodology.
Revised Date: 8/6/2015
TABLE OF CONTENTS
Disk Imaging
Tableau TD3 Forensic Imager 1.3.0
MacQuisition 2013R2
Paladin 4.0
DCFLDD 1.3.4-1
X-Ways Forensics 16.2 SR-5
Image MASSter Solo-4 Forensic
IXImager v3.0.nov.12.12
Fast Disk Acquisition System (FDAS) 2.0.2
FTK Imager CLI 2.9.0 Debian
Paladin 3.0
Paladin 2.06
X-Ways Forensic 14.8
ASR Data SMART version 2010-11-03
VOOM HardCopy 3P – Firmware Version 2-04
Imager MASSter Solo-3 Forensics, Software Version 2.0.10.23f
Tableau TD1 Forensic Duplicator, Firmware Version 2.34 Feb. 17,
2011
Tableau Imager (TIM) Version 1.11
SubRosaSoft MacForensics Lab 2.5.5
Logicube Forensic Talon Software Version 2.43
BlackBag MacQuisition 2.2
EnCase 6.5
EnCase LinEn 6.01
EnCase 5.05f
FTK Imager 2.5.3.14
DCCIdd (Version 2.0)
EnCase 4.22a
EnCase LinEn 5.05f
IXimager (Version 2.0)
dd FreeBSD
EnCase 3.20
Safeback 2.18
Safeback (Sydex) 2.0
dd GNU fileutils 4.0.36
Forensic Media Preparation
dc3dd: Version 7.0.0
Image MASSter Solo-4 Forensics, Software Version 4.2.63.0
Tableau TDW1 Drive Tool/Drive Wiper; Firmware Version 04/07/10
18:21:33
Disk Jockey PRO Forensic Edition (version 1.20)
Drive eRazer Pro SE Bundle 12/03/2009
Tableau Forensic Duplicator Model TD1 (Firmware Version 3.10)
Logicube Omniclone 2Xi
Darik’s Boot and Nuke 1.0.7
Voom HardCopy II (Model XLHCPL-2PD Version 1.11)
WiebeTech Drive eRazer: DRZR-2-VBND & Drive eRazer PRO Bundle
Write Block (Software)
ACES Writeblocker Windows 2000 V5.02.00
ACES Writeblocker Windows XP V6.10.0
PDBLOCK Version 1.02 (PDB_LITE)
PDBLOCK Version 2.00
PDBLOCK Version 2.10
RCMP HDL V0.4
RCMP HDL V0.5
RCMP HDL V0.7
RCMP HDL V0.8
Write Block (Hardware)
T4 Forensic SCSI Bridge (FireWire Interface)
T4 Forensic SCSI Bridge (USB Interface)
Tableau T8 Forensic USB Bridge (FireWire Interface)
Tableau T8 Forensic USB Bridge (USB Interface)
FastBloc FE (USB Interface)
FastBloc FE (FireWire Interface)
Tableau T5 Forensic IDE Bridge (USB Interface)
Tableau T5 Forensic IDE Bridge (FireWire Interface)
Tableau Forensic SATA Bridge T3u (USB Interface)
Tableau Forensic SATA Bridge T3u (FireWire Interface)
Tableau Forensic IDE Pocket Bridge T14 (FireWire Interface)
WiebeTech Forensic SATADock (FireWire Interface)
WiebeTech Forensic SATADock (USB Interface)
WiebeTech Forensic ComboDock (USB Interface)
WiebeTech Forensic ComboDock (FireWire Interface)
WiebeTech Bus Powered Forensic ComboDock (USB Interface)
WiebeTech Bus Powered Forensic ComboDock (FireWire Interface)
Digital Intelligence UltraBlock SATA (FireWire Interface)
FastBloc IDE (Firmware Version 16)
MyKey NoWrite (Firmware Version 1.05)
ICS ImageMasster DriveLock IDE (Firmware Version 17)
WiebeTech FireWire DriveDock Combo (FireWire Interface)
Digital Intelligence Firefly 800 IDE (FireWire Interface)
Digital Intelligence UltraBlock SATA (USB Interface)
Mobile Devices
Device Seizure v6.8
Lantern v4.5.6
EnCase Smartphone Examiner v7.10.00.103
Oxygen Forensics Suite 2015 – Analyst v7.0.0.408
Secure View v3.16.4
viaExtract v2.5
Mobile Phone Examiner Plus v5.5.3.73
iOS Crime Lab v1.0.1
UFED Physical Analyzer v3.9.6.7
XRY/XACT v6.10.1
EnCase Smartphone Examiner v7.0
Device Seizure v5.0 build 4582.15907
Lantern v2.3
Micro Systemation XRY v6.3.1
Secure View 3v3.8.0
CelleBrite UFED 1.1.8.6 – Report Manager 1.8.3/UFED Physical
Analyzer 2.3.0
Mobile Phone Examiner Plus (MPE+) 4.6.0.2
AFLogical 1.4
Mobilyze 1.1
iXAM Version 1.5.6
Zdziarski’s Method
WinMoFo Version 2.2.38791
SecureView 2.1.0
Device Seizure 4.0
Plik z chomika:
WMatrixie
Inne pliki z tego folderu:
Cyber Spying - Tracking Your Familys (Sometimes) Secret Online Lives.pdf
(108419 KB)
Digital Evidence & Computer Crime - Forensic Science, Computers and the Internet - 2nd Edition.chm
(31781 KB)
A Guide to Forensic Testimony.chm
(2725 KB)
A Survey about Impacts of Cloud Computing on Digital Forensics.pdf
(2956 KB)
Investigative Data Mining for Security & Criminal Detection.chm
(26013 KB)
Inne foldery tego chomika:
Hacking
Humble Books
Humble Bundle
humble-hacking-bundle-1
Kali Linux
Zgłoś jeśli
naruszono regulamin