DEFT (Digital Evidence & Forensic Toolkit)


is a distribution Live CD (bootable from CD) with kernel based on Ubuntu 06.02.1935, easy to use, with a huge list of forensic tools and excellent hardware detection.

DEFT is a forensic distributions that have advanced most in recent years (you can see for yourself from the entry that was created when only the version 3), not only add a lot of forensic tools to your list but have adapted to their environment and to emulate the characteristics of other similar distributions CAINE where are inspired to get the Extra DEFT.

DEFT (Digital Evidence & Forensic Toolkit) is divided in two, their environment and bootable tools that collect the best free software for forensic analysis and DEFT Extra set of free tools for forensic analysis on Windows.

In DEFT we find the following tools to perform forensic analysis:

SleuthKit 3.2.0, collection of UNIX-based command line tools allow you to Investigate That a computer
autopsy 2.24, graphical interface to the command line digital investigation tools in The Sleuth Kit
0.8 DFF
dhash 2.0.1, multi hash tool
aff lib 3.6.4, advanced forensic format
2.30.1 disk utility to partition manager tool
guymager 0.5.7, a fast and user friendly MOST forensic imager
dd rescue 1.14, copy data from one file or block device to Another
dcfldd 1.3.4.1, copy data from one file or block device with more functions to Another
dc3dd 7, patched version of GNU dd to include a number of features Useful for computer forensics
Xmount 0.4.4, convert on-the-fly multiple input and output entre hard disk image types
1.5.6 foremost, console program to recover files based on Their headers, footers, and internal Data Structures
photorec 6.11, easy carving tool
mount manager 0.2.6, advanced and user friendly mount manager
1.60 scalpel, carving tool
wipe 0.21
hex dump, hex and ascii dump Combined of Any File
outguess 0.2, Steganos tool
ophcrack 3.3.0, Windows password recovery
DEFT Xplico edition 0.6.1, advanced network analyzer
Wireshark 1.2.11, network sniffer
ettercap 0.7.3, network sniffer
nmap 5.21, the best network scanner
dmraid, Discover software RAID devices
testdisk 6.11, tool to recover Damaged partitions
GHEx, light hex editor gtk
Vinetto 0.6, tool to examine Thumbs.db files
DEFT TrID edition 2.2, tool to Identify file types from Their binary signatures
0.6.41 readpst to tools to read ms-Outlook pst files
chkrootkit, Checks for signs of rootkits on the local system
1.3.4 rkhunter, rootkit, backdoor, sniffer and exploit scanner
1.7.2 john, John the Ripper password cracker
catfish, file search
Galletta 1.0
Pasco 1.0
md5sum, sha1sum, sha224sum, sha256sum, sha512sum
md5deep, sha1deep, sha256deep
view log skype, skype chat conversation viewer
Xnview, graphics viewer, picture and photo files
IE, Mozilla, Opera and Chrome cache viewer
IE, Mozilla, Opera and Chrome history viewer
Index.dat file analyzer
pdfcrack, cracking tool
fcrackzip, cracking tool
clam, antivirus 4.15
mc, UNIX file manager

And the extra DEFT we have the following list of tools for analyzing Windows environments:

2.28.2 WinAudit
Windows Registry Recovery 1.5.1.0 Mitec
1.0 Zeroview
FTK Imager 3
0.1 Nigilant32
Windows Forensic Toolchest 3.0.05
Win32dd MoonSols 1.0.2.20100417
Win64dd MoonSols 1.0.2.20100417
Windows File Analyzer 1.0
1.40 ultrasearch
Pre-Search xx.08
XnView 1.97.8
X-AgentRansackk 2010 (build 762)
Index.dat Analyzer 2.5
1.2 AccessEnum
Autoruns 10.03
2.4 DiskView
Filemon
Process Explorer 12.04
1.1 RAM Map
Regmon
Rootkit Revealer 1.71
2.62 VMMap
2.15 WinObj
1.15 AlternateStreamView
1.25 ChromeCacheView
1.83 x86 and x64 CurrPorts
1.13 CurrProcess
1.21 FoldersReport
IE Cache View 1.32
IE Cookies View 1.74
IE History View 1.50
Inside Clipboard 1.11
Contacts Live View 7.1
Mozilla Cache View 1.30
Mozilla History View 1.25
MUI Cache View 1.1
1.37 MyEventView
1.44 MyLastSearch
Mozilla Cookies View 1.30
Opened File View 1.46
Opera Cache View 1.37
Outlook Attack View x86 and x64 1.35
Process Activity View x86 and x64 1.11
Recent File View 1.20
RegScanner x86, x64 and win98 1.82
1.40 ServiWin
1.15 SkypeLogView
1.71 x86 and x64 SmartSniff
1.22 StartupRun
1.80 x86 and x64 USBDeview
Assist 1.1 User View
1.1 View User Profile
Video Cache View 1.78
1.25 WhatInStartup
1.10 WinPerfectView
Password Tool
1.10 ChromePass
3.10 Dialupass
IE PassView 1.20
Dump LSA Secrets x86 and x64 1.21
LSA Secrets View 1.21 x86 and x64
Mail PassView 1.65
MessenPass 1.35
Network PassRecovery 1.30 x86 and x64
Opera 1.1 PassView
1.25 PasswordFox
AnyPass PC 1.12
1.63 Pass Protected View
PST Password 1.12
Remote Desktop PassView 1.1
PassView 2.1 VNC
Win9x PassView 1.1
1.34 x86 and x64 WirelessKeyView
AviScreen 3.2.2.0 Portable
0.8 Hoverdesk
File Restore Plus 3.0.1.811
WinVNC 3.3.3.2
2.40 TreeSizeFree
PCTime
5.2 LTFViewer
Sophos Anti-Rootkit 1.5.4
Terminal with command line tools
Spartakus 1.0
Testdisk 6.11.3
6.11.3 Photorec

credit: Thomas Hawk

Downloads: ftp://ftpmirror.your.org/pub/deft/
 http://www.deftlinux.net/download/
.................................................

es una distribución Live CD (booteable desde el CD) basada en Ubuntu con kernel 2.6.35, muy fácil de usar, con un grandísimo listado de herramientas forenses y con una excelente detección del hardware.

DEFT es una de las distribuciones de análisis forense que mas han avanzado en estos últimos años (puedes verlo tu mismo desde la entrada que creamos cuando solo estaba en su versión 3), no solo han añadido una gran cantidad de herramientas forenses a su lista, sino que se han sabido adaptarse a su entorno y emular las características de otras distribuciones similares CAINE de donde se han inspirados para sacar el DEFT Extra.

DEFT (Digital Evidence & Forensic Toolkit) esta dividida en dos, su entorno y herramientas booteables que recogen lo mejor del software libre para el análisis forense y DEFT Extra un conjunto de herramientas gratuitas para análisis forense en entornos Windows.

En DEFT podemos encontrar las siguientes herramientas para realizar Análisis Forense:


sleuthkit 3.2.0, collection of UNIX-based command line tools that allow you to investigate a computer
autopsy 2.24, graphical interface to the command line digital investigation tools in The Sleuth Kit
DFF 0.8
dhash 2.0.1, multi hash tool
aff lib 3.6.4, advanced forensic format
disk utility 2.30.1, a partition manager tool
guymager 0.5.7, a fast and most user friendly forensic imager
dd rescue 1.14, copy data from one file or block device to another
dcfldd 1.3.4.1, copy data from one file or block device to another with more functions
dc3dd 7, patched version of GNU dd to include a number of features useful for computer forensics
Xmount 0.4.4, convert on-the-fly between multiple input and output hard disk image types
foremost 1.5.6, console program to recover files based on their headers, footers, and internal data structures
photorec 6.11, easy carving tool
mount manager 0.2.6, advanced and user friendly mount manager
scalpel 1.60, carving tool
wipe 0.21
hex dump, combined hex and ascii dump of any file
outguess 0.2 , a stegano tool
ophcrack 3.3.0, Windows password recovery
Xplico 0.6.1 DEFT edition, advanced network analyzer
Wireshark 1.2.11, network sniffer
ettercap 0.7.3, network sniffer
nmap 5.21, the best network scanner
dmraid, discover software RAID devices
testdisk 6.11, tool to recover damaged partitions
ghex, light gtk hex editor
vinetto 0.6, tool to examine Thumbs.db files
trID 2.02 DEFT edition, tool to identify file types from their binary signatures
readpst 0.6.41, a tools to read ms-Outlook pst files
chkrootkit, Checks for signs of rootkits on the local system
rkhunter 1.3.4, rootkit, backdoor, sniffer and exploit scanner
john 1.7.2, john the ripper password cracker
catfish, file search
galletta 1.0
pasco 1.0
md5sum, sha1sum, sha224sum, sha256sum, sha512sum
md5deep, sha1deep, sha256deep
skype log view, skype chat conversation viewer
Xnview, viewer graphics, picture and photo files
IE, Mozilla, Opera and Chrome cache viewer
IE, Mozilla, Opera and Chrome history viewer
Index.dat file analyzer
pdfcrack, cracking tool
fcrackzip, cracking tool
clam, antivirus 4.15
mc, UNIX file manager

Y en el DEFT extra contamos con el siguiente listado de herramientas para análisis de entornos Windows:

WinAudit 2.28.2
MiTeC Windows Registry Recovery 1.5.1.0
Zeroview 1.0
FTK Imager 3
Nigilant32 0.1
Windows Forensic Toolchest 3.0.05
MoonSols Win32dd 1.0.2.20100417
MoonSols Win64dd 1.0.2.20100417
Windows File Analyzer 1.0
UltraSearch 1.40
Pre-Search xx.08
XnView 1.97.8
X-AgentRansackk 2010 (build 762)
Index.dat Analyzer 2.5
AccessEnum 1.2
Autoruns 10.03
DiskView 2.4
Filemon
Process eXPlorer 12.04
RAM Map 1.1
Regmon
Rootkit Revealer 1.71
VMMap 2.62
WinObj 2.15
AlternateStreamView 1.15
ChromeCacheView 1.25
CurrPorts x86 e x64 1.83
CurrProcess 1.13
FoldersReport 1.21
IE Cache View 1.32
IE Cookie View 1.74
IE History View 1.50
Inside Clipboard 1.11
Live Contacts View 1.07
Mozilla Cache View 1.30
Mozilla History View 1.25
MUI Cache View 1.01
MyEventView 1.37
MyLastSearch 1.44
Mozilla Cookie View 1.30
Opened File View 1.46
Opera Cache View 1.37
Outlook Attack View x86 e x64 1.35
Process Activity View x86 e x64 1.11
Recent File View 1.20
Regscanner x86, x64 e win98 1.82
ServiWin 1.40
SkypeLogView 1.15
SmartSniff x86 e x64 1.71
StartupRun 1.22
USBdeview x86 e x64 1.80
User Assist View 1.01
User Profile View 1.01
Video Cache View 1.78
WhatInStartup 1.25
WinPerfectView 1.10
Password Tool
ChromePass 1.10
Dialupass 3.10
IE PassView 1.20
LSA Secrets Dump x86 e x64 1.21
LSA Secrets View x86 e x64 1.21
Mail PassView 1.65
MessenPass 1.35
Network PassRecovery x86 e x64 1.30
Opera PassView 1.01
PasswordFOX 1.25
PC AnyPass 1.12
Protected Pass View 1.63
PST Password 1.12
Remote Desktop PassView 1.01
VNC PassView 1.02
Win9x Passview 1.1
WirelessKeyView x86 e x64 1.34
AViScreen Portable 3.2.2.0
Hoverdesk 0.8
File Restore Plus 3.0.1.811
WinVNC 3.3.3.2
TreeSizeFree 2.40
PCTime
LTFViewer 5.2
Sophos Anti-Rootkit 1.5.4
Terminal with tools command line
Spartakus 1.0
Testdisk 6.11.3
Photorec 6.11.3

creditos: Thomas Hawk

Descarga ftp://ftpmirror.your.org/pub/deft/
http://www.deftlinux.net/download/

No hay comentarios:

Protected by Copyscape Original Article Checker