05-10-2021

Jan 08, 2021 A good starting point for trying out digital forensics tools is exploring one of the Linux platforms mentioned at the end of this article. These platforms have a range of free tools installed and configured, making it possible to try out the various options without a significant investment of licensing fees or setup time. Autopsy is a GUI-based open source digital forensic program to analyze hard drives. Browser History Capturer is a free digital forensic tool. It is a portable software and is designed to capture a web browser history from a computer. Following are the web browsers supported by this software: Mozilla Firefox (version 3 or higher), Google Chrome (all versions), Internet Explorer (version 10 or higher), and Microsoft Edge (all versions). Memoryze for the Mac. Memoryze for the Mac is free memory forensic software that helps incident responders find evil in memory on Macs. Memoryze for the Mac can acquire and/or analyze memory images. Analysis can be performed on offline memory images or on live systems. Mac Marshal is a tool to analyze Mac OS X file system images.

Lantern 3 – A Mac based tool that analyzes iPhones, Androids and Macs.

Lantern Lite – the free iOS Imager for Law Enforcement

Mac Forensics Tools Free Downloads

Mac Marshall – Excellent Mac Triage tool (Free to LE)

Mac forensics tools free trial

Www.digitalforensics.com › Blog › Forensic-tools-forForensic Tools For Your Mac | Digital Forensics | Computer ...

The Mac – The Mac itself is the best platform to conduct Mac exams.

dc3dd – A command line binary to create images. Also A GUI version as well for Mac.

Md5deep – A command line binary to hash file(s)

File Salvage from Subrosasoft – Great Utility for carving on the Mac

Show All Files – A free app from Version Tracker to show hidden files on Macs

Navicat for SQLIte – A great SQLite Builder application. Also available from the Mac App Store

Forensic Softwares

Mac forensics tools free trial

Www.kitploit.com › 2017 › 10OSXAuditor - Free Mac OS X Computer Forensics Tool

Base2 – An SQLite Database Viewer application

Cached

Disk Arbitrator – A cool tool to selectively mount and unmount devices from an easy to use GUI