Forums: Windows Forensic Toolkit - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Windows Forensic Toolkit Bundled Forensic tools for Win NT

#1 Guest_coder_*

  • Group: Guests

Posted 21 November 2003 - 06:28 AM

Compiled Download: ftp://ftp.cerias.pur...nsicToolkit.exe
Source Code: ftp://ftp.cerias.pur...lkit/ftksrc.zip (looks like Microsoft C)...

Quote

  Forensic Toolkit
 
  The Forensic ToolKit contains several Win32 Command line
  tools that can help you examine the files on a NTFS disk partition
  for unauthorized activity. We built these tools to help us do our
  job, we hope they can help you as well.
 
  AFind  is the only tool that lists files by their last access time
  without tampering the data the way that right-clicking on file
  properties in Explorer will. AFind allows you to search for access
  times between certain time frames, coordinating this with logon info
  provided from ntlast, you can to begin determine user activity even if
  file logging has not been enabled.

  HFind scans the disk for hidden files. It will find files that have
  either the hidden attribute set, or NT's unique and painful way of
  hiding things by using the directory/system attribute combination.
  This is the method that IE uses to hide data. HFind lists the last
  access times.

  SFind scans the disk for hidden data streams and lists the last access
  times.

  FileStat is a quick dump of all file and security attributes. It works
  on only one file at a time but this is usually sufficient.
  Hunt is a quick way to see if a server reveals too much info via NULL
  sessions.
 
  Command line switches
  afind [dir]/f [filename] /ns=no subs /a after /b before /m
  between
time format =
  hfind [dir] /hd=find dir/system attribs /ns=no subs
  sfind [dir] /ns=no subs
  filestat [filename]
  hunt [\\servername]
 
  COMMAND PROMPT MUST BE A MINIMUM OF 80 CHARACTERS
 
  A REMINDER. AS STATED IN OUR LICENCE, WE PRESENT THESE TOOLS AS IS.
  NO WARRENTY EXPRESSED OR IMPLIED. THIS TOOL IS UNSUPPORTED.
 
  System Requirements:
 
  Windows NT 4.0 SP3
  16MB Memory
  Administrator privileges
  Audit log enabled with searchable records
  Set NT command line buffer to 500 or more lines. 1200 lines works
  well

  Copyright 1998-99, NT OBJECTives, Inc. All Rights Reserved.
  All trademarks are the property of their respective owners.
  Read our Legal Notice & Terms of Use and Privacy Policy

0

#2 User is offline   flame 

  • Staff Sergeant
  • Icon
  • Group: Members
  • Posts: 272
  • Joined: 06-August 03

Posted 21 November 2003 - 08:03 AM

broken link...
0

#3 Guest_UNDERTAKER_*

  • Group: Guests

Posted 21 November 2003 - 10:59 AM

10x... going to have a look on that...
0

#4 Guest_wicked_*

  • Group: Guests

Post icon  Posted 21 November 2003 - 01:59 PM

Cheerz Bud Looks Good

Wkd..
0

#5 Guest_coder_*

  • Group: Guests

Posted 21 November 2003 - 07:35 PM

flame, on Nov 21 2003, 04:03 PM, said:

broken link...

works great for me, and everyone else?
0

#6 User is offline   neoragexxx 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 56
  • Joined: 05-October 03

Posted 22 November 2003 - 02:17 AM

Extremely useful and the link worx fine , thx a ton m8 ;)
0

#7 Guest_jak3c_*

  • Group: Guests

Posted 22 November 2003 - 02:44 AM

thanks u dude for this tools package!....
soudns good!
0

#8 User is offline   apusnaias 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 40
  • Joined: 31-August 03

Posted 22 November 2003 - 06:30 AM

thx a lot for sharing
0

#9 Guest_grabel_*

  • Group: Guests

Posted 22 November 2003 - 06:35 AM

its great dude...
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting