How to become a computer detective
How to become a computer detective

In the detective series, the researcher sitting in front of the suspect’s computer, press four keys and get all the information sought . In real life is not so simple, but with the right tools it is possible to scan a computer in a few hours.
Looking for what? For images, text, deleted files, chat logs, web history, passwords and all files that can track a person’s activity on a computer . Of course, many of these utilities can also be used to rescue your own information.
Recover deleted files and emails
Unless someone perform periodic cleaning of empty space (for example, Disk Wipe ) or working in temporary environments (eg Live-CD or virtual machines), recovering deleted files is not only possible but simple.
DiskDigger
Some of the most effective tools for this task are DiskDigger , Recuva , Pandora Recovery and TestDisk , which rescues even lost partitions and boot sectors.
If the data is unreadable CDs and DVDs, worth trying a low-level reading ISOBuster . For deleted emails in Outlook Express, Format Recovery is a good free option.
Rescue Passwords
The password protection is a system used by many websites, messengers and office tools. Collect existing keys can save much valuable information.
* BrowserPasswordDecryptor recovers all passwords stored in web browsers
* MessenPass does the same to users and passwords Messenger, ICQ, Yahoo …
* Mail PassView rescues key local mail accounts (Outlook, Eudora, Thunderbird, etc.).
* BulletsPassView , showin and AsteriskKey reveal passwords hidden behind asterisks
* WirelessKeyDump get the passwords for WiFi networks
* FireMaster attempts to recover the master password for Firefox
Mail Passview
Nirsoft and SecurityXploded have many tools designed exclusively for password recovery, almost all executables from USB sticks. It should be remembered that only get passwords stored without protection and that to break the encryption is necessary to use cryptographic attacks (for example, Cain & Abel ).
Digging in caches and histories
When we are using computers, spend much of our time surfing and chatting. This creates products in the form of text and images: the "trash" (cache) and activity logs (records) that are automatically stored (unless cleaned regularly or use private modes ).
* Sniper Chat collects records, pictures and contacts from Messenger, AIM and Yahoo Messenger
* IECacheView, MozillaCacheView, OperaCacheView y ChromeCacheView exploran la caché
* VideoCacheView is dedicated to Flash videos that are stored in the cache
* MyLastSearch collects recent searches performed on Google, Yahoo and Bing
* SkypeLogView used to see which were the last calls made on Skype
* LiveContactsView lists the contact details of Windows Live Messenger
* FlashCookieView analiza las cookies Flash
skypelogview
There are also utilities for specific scenarios. WinPrefetchView , for example, discusses the Prefetch folder for data related to the programs that run more frequently, while Rifiuti delves into the Recycle Bin.
Search documents and email attachments
Search documents is a logical step in any investigation. FI Tools is able to find more than 4,000 types of files and browse its contents. On the other hand, with the help of DocFetcher and Metadata Extractor can search for text and metadata of the documents on the hard disk. To find text, Look Drive is particularly effective.
Drive Look
To rummage in Outlook attachments, OutlookAttachView is incredibly useful. For a quick backup of emails and attachments from Mozilla Thunderbird MozBackup is the first choice. And if you want a quick viewer, low Viewer Mail .
Search, sort and retrieve images
A portable version of Picasa is the best partner to find and organize photos quickly, even Adobis Photo Sorter and Media Event Organizer also serve to classify the images into groups.
Media Event Organizer
To recover deleted photos (Sean honest node ), we recommend Adroit Photo Recovery and Forensic Photo Adroit , the tools of computer forensics specialist in the recovery of images produced.
Explore your hard disk and memory
When considering a computer, you need an overview of folders and files; SpaceSniffer , scanner or Portable WinDirStat offer quick summaries of sharing space on hard drives. To create a database folder, use getFolder and FileList .
SpaceSniffer
Finally, it may happen that the computer you’ve accessed is still on and with open programs. Check out what files are in use with OpenedFilesView and analyzes the memory with the help of a hex editor (eg WinHex or HxD ).
Más avanzados son MoonSols Windows Memory Toolkit y Volatility Framework, que analizan volcados de memoria y ficheros de hibernación de Windows, trozos de memoria "congelados" que pueden contener información valiosa.
Suites: OSForensics y Windows File Analyzer
OSForensics is a suite of computer forensics with a series of unique utilities: text search, contents of the disc, recent activity analyzer, search for deleted files or discordant display of memory and disk.
OSForensics
The particularity of OSForensics, it concentrates several tools in one window, it is your case manager, useful for organizing data from different investigations.
The simplest is Windows File Analyzer , which explores in miniature databases (Thumbs.db files) files, preload (Prefetch), Recent Documents, Internet Explorer history and trash from the Trash.
Windows File Analyzer
An important warning …
These tools are distributed freely, but the legitimacy of their use depends on you. Unless you are authorized to access a computer and extract information, they should not use them.
More Resources:
* Forensics Wiki
* Computer Forensics en Wikipedia
* E-Evidence Tools
* Digital Investigation Journal
Other Electronics News:
- acer btp-43d1 battery
- lenovo thinkpad t500 battery
- lenovo laptop batteries
- canon eos 40d battery grip
- laptop battery

