티스토리 뷰
다음은 디지털포렌식 관련 도구로 사용해본 도구 중 유용하다고 판단되는 도구를 정리해 놓은 표이다. 소프트웨어는 필연적으로 오류를 포함하기 때문에 증거 분석에 사용하는 도구라면 반드시 2개 이상의 도구로 상호 검증을 수행하는 것이 바람직하다.
실제 분석을 수행하다 보면 인증 받은 도구의 기능적인 한계나 불편함으로 제3의 도구를 사용하는 경우가 있다. 이 경우에는 최종적으로 인증 받은 도구로 결과를 한 번 더 검증하는 작업이 요구된다. 도구의 장 · 단점은 목적에 따라 다르기 때문에 자신의 업무 목적에 맞는 적합한 도구를 사용하기 바란다.
목록은 다음과 같다.(최신 정보가 업데이트되지 않은 경우가 있다.)
통합 포렌식 도구 (Integrated Forensics Tools)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | Guidance Software | Commercial | |
GUI | Windows | AccessData | Commercial | |
GUI | Windows | GetData | Commercial | |
GUI | Windows | X-Way Software Technology AG | Commercial | |
GUI | Macintosh | Architecture Technology | Commercial | |
GUI | Anywhere | BlackBag Technologies | Commercial | |
GUI | Anywhere | Brian Carrier | Opensource |
라이브 CD/VM (Live CD/VM)
Name | Interface | Platform | Manufacturer | Licence |
– | – | SANS | Freeware | |
– | – | SAMURI | Freeware | |
– | – | DEFT Staff | Freeware | |
– | – | e-fense | Commercial | |
– | – | BackTrack Linux | Freeware | |
– | – | Caine | Freeware |
라이브 포렌식 (Live Forensics)
Name | Interface | Platform | Manufacturer | Licence |
CLI | Windows | JK Kim | Freeware | |
GUI | Windows | Dark Particle Labs | Freeware | |
CLI | Windows | FoolMoon | Free/Comm | |
CLI | Windows | Corey Harrell | Opensource | |
CLI | Windows | mcleodjp | Opensource | |
CLI | Windows | Microsoft | only Law enforcement | |
GUI | Windows | Mandiant | Commercial | |
CLI | Windows | CST | Commercial | |
GUI | Macintosh | AIS | Opensource |
이미징 하드웨어 (Imaging Hardware)
Name | Interface | Platform | Manufacturer | Licence |
– | – | Intelligent Computer Solutions, Inc. | Commercial | |
– | – | Logicube | Commercial | |
– | – | Tableau | Commercial | |
– | – | DataExpert | Commercial |
이미징 소프트웨어 (Imaging Software)
Name | Interface | Platform | Manufacturer | Licence |
FTK Imager (Lite) | GUI | Windows | AccessData | Freeware |
GUI | Windows | TABLEAU | Freeware | |
GUI | Windows | X-Ways Software Technology AG | Commercial | |
GUI | Windows | Guidance Software | Freeware | |
CLI | Windows | George M. Garner Jr. | Freeware | |
GUI | Windows | JensH | Opensource | |
CLI | Windows | PassMark Software | Opensource | |
CLI | Unix-based | Joachim Metz | Opensource | |
GUI | Linux | vogu00 | Freeware | |
CLI | Unix-based | Nick Harbour | Opensource | |
CLI | Macintosh | BlackBag Technologies | Opensource |
쓰기방지장치 (Write Blocker)
Name | Interface | Platform | Manufacturer | Licence |
– | – | Tableau | Commercial | |
– | – | Wiebetech | Commercial |
이미지 마운트 (Image Mounting)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | Arsenal Recon | Freeware | |
GUI | Windows | GetData | Commercial | |
GUI | Widows | PassMark Software | Freeware | |
CLI | Windows | Microsoft | Freeware | |
GUI | Win &Lin | CMU/td> | Freeware | |
GUI | Anywhere | Zapotek/td> | Freeware | |
GUI | Windows | AccessData | Freeware | |
GUI | Widows | Paraben | Freeware | |
GUI | Windows | LTRDATA | Opensource |
원격 포렌식 (Remote Forensics)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Anywhere | F-Response | Commercial |
메모리 획득 (Memory Acquisition)
Name | Interface | Platform | Manufacturer | Licence |
CLI | Windows | MoonSols | Freeware | |
CLI | Windows | MoonSols | Free/Comm | |
CLI | Windows | HBGary | Commercial | |
CLI | Windows | ManTech | Opensource | |
GUI | Windows | Mandiant | Freeware | |
FTK Imager (Lite) | GUI | Windows | AccessData | Freeware |
CLI | Windows | Michael Cohen | Freeware | |
CLI | Linux | niekt0 | Freeware | |
CLI | Linux | Joe Sylve | Freeware | |
CLI | Linux | Raytheon Pikewerks | Commercial | |
CLI | Macintosh | Mac Marshal™ | Freeware | |
CLI | Macintosh | Michael Cohen | Freeware |
메모리 분석 (Memory Analysis)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | Mandiant | Freeware | |
CLI | Anywhere | Volatile Systems | Opensource | |
GUI | Windows | Mandiant | Freeware | |
GUI | Windows | HBGary | Commercial | |
CLI | Linux | Raytheon Pikewerks | Commercial | |
CLI | Mac OS | n0fate | Opensource | |
CLI | FreeBSD | n0fate | Opensource |
타임라인 분석 (Timeline Analysis)
Name | Interface | Platform | Manufacturer | Licence |
CLI | Linux &Mac | Kristinn Gudjonsson | Freeware | |
CLI | Win &Mac | Kristinn Gudjonsson | Freeware | |
GUI | Win &Mac | Kristinn Gudjonsson | Freeware | |
GLI | Windows | Woanware | Freeware/Opensource | |
GUI | EnCase-Based | Geoff Black | Opensource |
레지스트리 분석 (Registry Analysis)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | 4&6tech | Commercial | |
GUI | Windows | Arsenal Recon | Commercial | |
GUI | Windows | TorchSoft | Commercial | |
CLI | Windows | Harlan Carvey | Opensource | |
GUI | Windows | Didier Stevens | Freeware | |
GUI | Windows | woanware | Freeware/Opensource | |
GUI | Windows | woanware | Freeware/Opensource | |
GUI | Windows | woanware | Freeware/Opensource | |
GUI | Windows | woanware | Freeware/Opensource | |
CLI | Windows | TZWorks | Freeware/Commercial | |
CLI | Windows | TZWorks | Freeware/Commercial | |
CLI | Windows | TZWorks | Freeware/Commercial | |
CLI | Windows | TZWorks | Freeware/Commercial |
파일시스템 메타데이터 (File System Metadata)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | joakim | Freeware | |
CLI | Anywhere | David Kovar | Opensource | |
GUI | Windows | Sanderson Forensics | Freeware | |
CLI | Windows | TZWorks | Freeware/Commercial | |
CLI | Windows | TZWorks | Freeware/Commercial | |
CLI | Windows | TZWorks | Freeware/Commercial | |
CLI | Windows | TZWorks | Freeware/Commercial |
바로가기 파일 분석 (LNK Analysis)
Name | Interface | Platform | Manufacturer | Licence |
CLI | Windows | TZWorks | Freeware/Commercial | |
CLI | Windows | Woanware | Freeware |
로그 분석 (Log Analysis)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | FSPro Labs | Commercial | |
CLI | Windows | Microsoft | Freeware | |
GUI | Windows | blueangel | Freeware | |
CLI | Windows | David Cowen | Freeware | |
GUI | Windows | TZWorks | Freeware/Commercial | |
GUI | Windows | TZWorks | Freeware/Commercial | |
GUI | Windows | TZWorks | Freeware/Commercial | |
CLI | Windows | joakim | Freeware | |
CLI | Windows | joakim | Freeware |
악성코드 분석 (Malware Analysis)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | Marc Ochsenmeier | Freeware | |
GUI | Windows | Wayne J. Radburn | Freeware | |
CLI | Win &Lin | TEKDEFENSE | OpenSource | |
CLI | Windows | Rurik | OpenSource |
프리패치 분석 (Prefetch Analysis)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | NirSoft | Freeware | |
GUI | Windows | woanware | Freeware | |
GUI | Windows | Allan S Hay | Freeware | |
CLI | Windows | SANS | Freeware | |
CLI | Anywhere | TZWorks | Freeware/Commercial |
웹 브라우저 사용 흔적 (Web Browser Artifacts)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | 4&6 Tech | Commercial | |
GUI | Windows | Mandiant | Freeware | |
GUI | Windows | Magnet Forensics | Commercial | |
GUI | Windows | woanware | Freeware | |
GUI | Windows | woanware | Freeware | |
GUI | Windows | woanware | Freeware | |
CLI | Windows | TZWorks | Freeware/Commercial | |
GUI | Windows | NirSoft | Freeware | |
GUI | Windows | NirSoft | Freeware | |
GUI | Windows | NirSoft | Freeware | |
GUI | Windows | NirSoft | Freeware | |
GUI | Windows | NirSoft | Freeware | |
GUI | Windows | NirSoft | Freeware | |
GUI | Windows | NirSoft | Freeware | |
GUI | Windows | NirSoft | Freeware | |
GUI | Windows | NirSoft | Freeware | |
GUI | Windows | NirSoft | Freeware | |
GUI | Windows | NirSoft | Freeware | |
GUI | Windows | NirSoft | Freeware | |
GUI | Windows | NirSoft | Freeware | |
GUI | Windows | NirSoft | Freeware |
데이터베이스 분석 (Database Analysis)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | Lepide Software | Freeware | |
GUI | Windows | NirSoft | Freeware | |
GUI | Windows | woanware | Freeware | |
GUI | Windows | Bogdan Ureche | Commercial | |
GUI | Windows | Oxygen Forensic | Commercial | |
GUI | Win &Mac | Tabuleiro | Opensource | |
– | – | – | – |
이메일 분석 (Email Analysis)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | Paraben | Commercial | |
GUI | Windows | MiTeC | Freeware | |
GUI | Windows | Stellar Information Systems | Commercial | |
GUI | Windows | Lepide Software | Commercial |
포맷 분석 (Format Analysis)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | SweetScape Software | Commercial | |
GUI | Windows | McAfee | Freeware | |
GUI | Windows | MiTeC | Freeware | |
GUI | Windows | Microsoft | Freeware | |
GUI | Windows | TZWorks | Freeware/Commercial | |
CLI | Anywhere | Didier Stevens | Freeware | |
CLI | Anywhere | Jose Miguel Esparza | Freeware | |
GUI | Windows | David Zimmer | Freeware |
복원지점/볼륨섀도복사본 분석 (Restore Point/VSC)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | blueangel | Freeware | |
CLI | Windows | Joachim Metz | Freeware | |
GUI | Windows | ShadowExplorer | Freeware | |
GUI | Windows | David Dym | Freeware | |
GUI | Windows | Jason Hale | Freeware | |
GUI | Windows | Sanderson Forensics | Commercial |
자바 IDX 분석 (Java IDX Analysis)
Name | Interface | Platform | Manufacturer | Licence |
CLI | Anywhere | Brian Baskin | OpenSource | |
CLI | Windows | Mark Woan | OpenSource | |
CLI | Windows | Harlan Carvey | OpenSource |
추가적인 아티팩트 분석 (Any Other Artifacts)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | MiTeC | Freeware | |
CLI | Windows | TZWorks | Freeware/Commercial | |
CLI | Windows | TZWorks | Freeware/Commercial | |
GUI | Windows | woanware | Freeware | |
GUI | Windows | woanware | Freeware | |
GUI | Windows | woanware | Freeware | |
GUI | Windows | woanware | Freeware | |
GUI | Windows | Filesig Software | Commercial | |
GUI | Windows | Igor Tolmache | Freeware | |
GUI | Windows | Chris Mayhew | Freeware |
네트워크 포렌식 (Network Forensics)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Anywhere | WireShark | Freeware | |
GUI | Windows | NETRESEC | Commercial | |
GUI | Win &Lin | RSA | Commercial | |
GUI | Anywhere | Pstavirs | Opensource | |
GUI | Windows | Colasoft | Freeware | |
CLI | Windows | NETRESEC | Opensource | |
CLI | Anywhere | WireShark | Freeware | |
CLI | Anywhere | Philippe Biondi | Opensource | |
CLI | Anywhere | – | Freeware | |
CLI | Windows | TZWorks | Freeware/Commercial | |
CLI | Windows | TZWorks | Freeware/Commercial | |
CLI | Windows | TZWorks | Freeware/Commercial | |
CLI | Windows | Woanware | Freeware | |
CLI | Windows | Woanware | Freeware | |
CLI | Windows | Woanware | Freeware |
패스워드 공격(Password Attack)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | ElcomSoft | Commercial | |
GUI | Windows | Passware | Commercial | |
GUI | Windows | InsidePro | Freeware | |
GUI | Anywhere | OBJECTIF SECURITE | Freeware | |
GUI | Windows | L0pht Holdings | Commercial |
윈도우 패스워드(Windows Password)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | Massimiliano Montoro | Freeware | |
GUI | Windows | Passcape Software | Freeware | |
CLI | Windows | Tarasco | Freeware | |
CLI | Windows | Truesec | Freeware | |
CLI | Windows | Reed Arvin | Freeware | |
CLI | Windows | izar | Freeware | |
CLI | Windows | mooyix | Opensource | |
GUI | Windows | Vadim Druzhin | Freeware | |
CLI | Windows | Pogostick | Freeware |
모바일 포렌식 (Mobile Forensics)
Name | Interface | Platform | Manufacturer | Licence |
– | – | GMDSystem | Commercial | |
– | – | Cellebrite | Commercial | |
– | – | Paraben | Commercial | |
– | – | Micro Systemation | Commercial | |
GUI | Windows | Oxygen Software | Commercial | |
GUI | Windows | Access Data | Commercial | |
GUI | Mac | KatanaForensics | Commercial | |
GUI | Windows | rene.devichi | Commercial |
헥스 편집기 (Hex Editor)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | SweetScape | Commercial | |
GUI | Windows | X-Ways Software Technology AG | Commercial | |
GUI | Windows | HexWorkshop | Commercial | |
GUI | Windows | Mael Horz | Freeware |
해쉬 분석 (Hash Analysis)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Win &Mac | Implbits | Free/Comm | |
CLI | Anywhere | Jesse Kornblum | Freeware | |
CLI | Anywhere | ManTech | Freeware | |
– | – | NIST | Freeware |
완전삭제 (Wipe/Sanitization)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | The Eraser Project | Freeware | |
GUI | Win &Lin | Jetico | Commercial | |
CLI | Windows | Sysinternals | Freeware | |
CLI | Win &Lin | CMRR | Freeware |
데이터 복구 (Data Recovery)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | GetData | Commercial | |
GUI | Anywhere | R-Tools Technology | Commercial | |
GUI | Windows | MiniTool® Solution | Commercial |
그 밖에… (Other Tools)
Name | Interface | Platform | Manufacturer | Licence |
GUI | Windows | Mandiant | Freeware | |
GUI | Windows | McAfee | Freeware | |
GUI | Windows | Digital Detective | Freeware | |
GUI | Windows | Harry Parsonage | Freeware | |
GUI | Windows | DUZON | Commercial |
포렌식 도구 사이트 (dForensics Tool Sites)
Site | |
|
출처 - http://forensic-proof.com/tools
'Project' 카테고리의 다른 글
Forensic Tools -2 (0) | 2017.10.19 |
---|---|
Git library 사용을 위한 절차 (2) | 2017.07.06 |
PUP 분석 - 2 (0) | 2017.05.04 |
GRR 프로젝트 (0) | 2017.04.24 |
PUP(Potentially Unwanted Program) 분석 - 1 (0) | 2017.04.23 |
- Total
- Today
- Yesterday
- ethereumj
- #Chrome
- #수정
- #이미지 수정
- #tool
- blockchain
- #포렌식
- 이더리움
- #메모리
- #GRR
- #캐시
- #WinPmem
- #Forensic Tools
- #FTK
- #WireShark
- #ReKall
- #크롬
- #DEFT
- ethereum
- #Volatility
- #Forensic
- Fin Tech
- #Pmem
- #tcpdump
- 4차 산업혁명
- #WinHex
- #EnCase
- #디지털 포렌식
- #Security
- #010 Editor
일 | 월 | 화 | 수 | 목 | 금 | 토 |
---|---|---|---|---|---|---|
1 | 2 | 3 | ||||
4 | 5 | 6 | 7 | 8 | 9 | 10 |
11 | 12 | 13 | 14 | 15 | 16 | 17 |
18 | 19 | 20 | 21 | 22 | 23 | 24 |
25 | 26 | 27 | 28 | 29 | 30 | 31 |