File Formats and Common Forensic Software Programs Flashcards
The Advanced Forensic Format AFF
was invented by Basis Technology. It is an open file standard with three variations: AFF, AFM, and AFD. AFF stores all data and metadata in a single file. AFM stores the data and metadata in separate files, AFD stores the data and metadata in multiple small files. Sleuth Kit and Autopsy both support AFF.
EnCase
Is a proprietary format that is defined by Guidance Software for use in its EnCase tool to store hard drive images and individual files. It includes a hash of the file to ensure nothing was changed when it was copied from the source.
EnCase Software
very widely used forensic toolkit. This allows the examiner to connect an Ethernet cable or null modem cable to a suspect machine and to view the data on that machine.
Forensic Toolkit FTK
Forensic analysis tool that is very popular with law enforcement. Can select which hash to use to verify the drive when you copy it, which features you want to use on the suspect drive, and how to search.
Sleuth Kit
A collection of command-line tools that are available as a free download.
Autopsy
A free download, cost effect option for a forensics toolkit.
Disk Investigator
Free utility that comes as GUI for use with Windows operating systems. Not as full featured as EnCase, but remarkably easy to use.