User:JaceGo1/Books/Digital Forensics Tools

Team 2

 * Acquistion (MAKING A COPY OF THE ORGINAL DRIVE)
 * Extraction (RETRIVING BINARY DATA
 * EnCase
 * Wireshark
 * SANS Investigative Forensics Toolkit
 * Registry Recon
 * ElcomSoft
 * Digital Forensics Framework
 * Forensic Toolkit
 * PTK Forensics
 * The Coroner's Toolkit
 * Computer Online Forensic Evidence Extractor
 * The Sleuth Kit
 * Open Computer Forensics Architecture
 * Windows To Go
 * Netherlands Forensic Institute


 * Reconsruction (RECREATE SUSPECT DRIVE TO SHOW WHAT HAPPENED)
 * Reporting
 * Other considerations