Tools

584 results - showing 181 - 200
« 1 ... 5 6 7 8 9 10 11 12 13 14 ... »

Tools

License Type
Free
Developer
Guidance/OpenText

Registry File Exporter will export registry files from Windows OS from the default locations. EnScript is tested on Windows XP, Vista, 7 and 8.

Tools

License Type
Free
Developer
Guidance/OpenText

This is a self-installing viewer for Windows Registry-hive files. Once installed, it is invoked using the CTRL+SHIFT+Y keyboard shortcut.

Tools

License Type
Free
Developer
Guidance/OpenText

“RegRipper is the fastest, easiest and best tool for registry analysis in forensic examinations.”

 

Tools

License Type
Free
Developer
Guidance/OpenText

This script parses RDP cache files selected by the user.

Tools

License Type
Free
Developer
Guidance/OpenText

Use Records2Excel to export records to Microsoft Excel. This script works with any records list which can be tagged and export all record's properties (fields values): emails, internet history, mobile phone processing results ....
ie : Export SMS, MMS, Calls and Contact names from your mobile phone's Case to Microsoft Excel and perform sorts on phone numbers, create timelines mixing SMS MMS and phone calls...

Tools

License Type
Free
Developer
Guidance/OpenText

This script will attempt to mount the highlighted PST/OST file and display its contents so that messages can be previewed and/or extracted to *.MSG files.

Tools

License Type
Free
Developer
Guidance/OpenText

Quickly make bookmark folders for each device in your case. Automate making bookmark folders and subfolders for each device in your case. Along with bookmarking each device and each volume in the case. User configurable subfolders.

Tools

License Type
Free
Developer
Guidance/OpenText

Allows the examiner to quickly view data in the highlighted Registry file.

Tools

License Type
Free
Developer
Guidance/OpenText

The script is designed to quickly decode Base64-encoded data.

Tools

License Type
Free
Developer
Guidance/OpenText

This script is designed to find deleted prefetch files in both compressed and uncompressed formats.

Tools

License Type
Free
Developer
Guidance/OpenText

Print Spool - Parse Data From SHD and SPL Files (V1.3.1)

Tools

License Type
Free
Developer
Guidance/OpenText

This EnScript is designed to parse the prefetch files created by the MS Windows Task Scheduler service.  Windows XP to Windows 10 file formats are supported. It's worth noting that Windows 10 prefetch files are compressed using the Xpress+Huffman compression algorithm.

Tools

License Type
Free
Developer
Guidance/OpenText

This is an XML and binary property list viewer plugin EnScript.

Tools

License Type
Free
Developer
Guidance/OpenText

This EnScript is designed to be run before the Evidence Processor. This EnScript does three things:

Tools

License Type
Free
Developer
Guidance/OpenText

This EnScript decodes binary and XML plist files that are extensively used by Apple computer software and hardware to store configuration data.

 

Tools

License Type
Free
Developer
Guidance/OpenText

EnScript to extract & display information about wireless networks that have been connected to. Supports analysis of Windows Vista, 7 & 8.

Tools

License Type
Free
Developer
Guidance/OpenText

This EnCase EnScript was written to parse the Vista/7 'setupapi.dev.log' for USB events. This log contains a lot of information about hardware events, including when USB devices are attached and can be useful to compare to file metadata to see what filesystem activity was also happening at the same time as when USB devices were connected.

Tools

License Type
Free
Developer
Guidance/OpenText

This EnScript was designed as a "quick hit" to parse and show the MRU values for the Terminal server client for each user. The EnScript checks the Software\Microsoft\Terminal Server Client\Default for each NTUSER.DAT and displays/bookmarks any values.

Tools

License Type
Free
Developer
Guidance/OpenText

Parses the original path, logical size, and date-deleted information from $I $Recycle.Bin files.

Tools

License Type
Free
Developer
Guidance/OpenText

Most executables contain a resource known as "VS_VERSION_INFO". This structure contains metadata about the specific executable, including the manufacturer name, original filename, version info and other useful information. This EnScript specifically targets this resource instead of just running a "strings" search across the entire executable, which often leads to lots of noise. The information in this resource is what is displayed if/when you right-click on an executable in Windows and choose the "details" tab. Looking at this information, while not authoritative or definitive, can commonly give you some initial hints about the legitimacy of a file and/or if it has been renamed from when it was originally compiled. The EnScript is designed to be able to check any executable(s) and then run the EnScript. It will then print out the information from this resource to the console tab (and make a bookmark).

584 results - showing 181 - 200
« 1 ... 5 6 7 8 9 10 11 12 13 14 ... »