010-68421378
sales@cogitosoft.com
Categories
AddFlow  AmCharts JavaScript Stock Chart AmCharts 4: Charts Aspose.Total for Java Altova SchemaAgent Altova DatabaseSpy Altova MobileTogether Altova UModel  Altova MapForce Altova StyleVision Server Altova MapForce Server Altova Authentic Aspose.Total for .NET Altova RaptorXML Server ComponentOne Ultimate Chart FX for SharePoint Chart FX CodeCharge Studio ComponentOne Enterprise combit Report Server Combit List & Label 22 Controls for Visual C++ MFC Chart Pro for Visual C ++ MFC DbVisualizer version 12.1 DemoCharge DXperience Subscription .NET DevExpress Universal Subscription Essential Studio for ASP.NET MVC FusionCharts Suite XT FusionCharts for Flex  FusionExport V2.0 GrapeCity TX Text Control .NET for WPF GrapeCity Spread Studio Highcharts Gantt Highcharts 10.0 版 HelpNDoc Infragistics Ultimate  ImageKit9 ActiveX ImageKit.NET JetBrains--Fleet JetBrains-DataSpell JetBrains--DataGrip jQuery EasyUI jChart FX Plus Nevron Vision for .NET OPC DA .NET Server Toolkit  OSS ASN.1/C Oxygen XML Author  OSS 4G NAS/C, C++ Encoder Decoder Library OSS ASN.1 Tools for C with 4G S1/X2 OSS ASN.1/C# OSS ASN.1/JAVA OSS ASN.1/C++ OPC HDA .NET Server Toolkit OPC DA .Net Client Development Component PowerBuilder redgate NET Developer Bundle Report Control for Visual C++ MFC  Altova StyleVision Sencha Test Stimulsoft Reports.PHP Stimulsoft Reports.JS Stimulsoft Reports.Java Stimulsoft Reports. Ultimate Stimulsoft Reports.Wpf Stimulsoft Reports.Silverlight SPC Control Chart Tools for .Net SlickEdit Source Insight Software Verify .Net Coverage Validator Toolkit Pro for VisualC++MFC TeeChart .NET Telerik DevCraft Complete Altova XMLSpy Zend Server

PassMark OSForensics

OSForensics allows you to identify suspicious files and activity with hash matching, drive signature comparisons, e-mails, memory and binary data.

It lets you extract forensic evidence from computers quickly with advanced file searching and indexing and enables this data to be managed effectively.

Features

Discover Forensic Evidence Faster

•Find files faster, search by filename, size and time

•Search within file contents using the Zoom search engine

•Search through email archives from Outlook, ThunderBird, Mozilla and more

•Recover and search deleted files

•Uncover recent activity of website vists, downloads and logins

•Collect detailed system information

•Password recovery from web browsers, decryption of office documents

•Discover and reveal hidden areas in your hard disk

•Browse Volume Shadow copies to see past versions of files

Identify Suspicious Files and Activity

•Verify and match files with MD5, SHA-1 and SHA-256 hashes

•Find misnamed files where the contents don't match their extension

•Create and compare drive signatures to identify differences

•Timeline viewer provides a visual representation of system activity over time

•File viewer that can display streams, hex, text, images and meta data

•Email viewer that can display messages directly from the archive

•Registry viewer to allow easy access to Windows registry hive files

•File system browser for explorer-like navigation of supported file systems on physical drives, volumes and images

•Raw disk viewer to navigate and search through the raw disk bytes on physical drives, volumes and images

•Web browser to browse and capture online content for offline evidence management

•ThumbCache viewer to browse the Windows thumbnail cache database for evidence of images/files that may have once been in the system

•SQLite database browser to view the and analyze the contents of SQLite database files

•ESEDB viewer to view and analyze the contents of ESE DB (.edb) database files, a common storage format used by various Microsoft applications

•Prefetch viewer to identify the time and frequency of applications that been runnning on the system, and thus recorded by the O/S's Prefetcher

Manage Your Digital Investigation

•Case management enables you to aggregate and organize results and case items

•HTML case reports provide a summary of all results and items you have associated with a case

•Centralized management of storage devices for convenient access across all OSForensics' functionality

•Drive imaging for creating/restoring an exact copy of a storage device

•Rebuild RAID arrays from individual disk images

•Install OSForensics on a USB flash drive for more portability

•Maintain a secure log of the exact activities carried out during the course of the investigation

Professional and Bootable Editions

The professional and bootable editions of OSForensics have many features not available in the free edition, including;

•Import and export of hash sets

•Customizable system information gathering

•No limts on the amount of cases being managed through OSForensics

•Restoration of multiple deleted files in one operation

•List and search for alternate file streams

•Sort image files by colour

•Disk indexing and searching not restricted to a fixed number of files

•No watermark on web captures

•Multi-core acceleration for file decryption

•Customizable System Information Gathering

•View NTFS directory entries to identify potential hidden/deleted files

The bootable edition contains all the professional features plus the ability to be run on systems without a valid operating system.

 

Quick Navigation;

© Copyright 2000-2023  COGITO SOFTWARE CO.,LTD. All rights reserved