DataLifter.Net Bonus Tools comes with the first version of
"C-Hash". This tool lets you search for file fragments
on any media. Artifact Finder takes this procedure
to the next level.
Why would you use a tool like this?
Here is the most common scenario; As an examiner you are given
multiple pieces of digital evidence to search. The main piece
of media, the hard drive reveals circumstantial evidence only.
Deleted Internet Favorites, Link files and installed or uninstalled
applications supporting illicit activity. Your other evidence,
floppy disks, CDR's or DVD's contains explicit content that
is illegal or indictable.
Artifact Finder was designed for this. The
new version of Artifact Finder is faster and
supports more target media than the previous version included
with DataLifter.Net Bonus Tools. Artifact Finder
takes your source files and creates multiple keywords based
on their contents. These keywords are then used to search your
target media. The results of Artifact Finder
provide you with a sector map of your file artifacts letting
you link your two pieces of evidence.
Artifact Finder works on raw bit-stream images
such as DD output. It also works on Encase E01 files and Logical
drives, where each sector can be examined.
|