to do what exactly?
Main Topics
Browse All TopicsWhat types of forensic investigation software programs and applications are the best to use?
I'm trying to get a list of what specific programs can be used to do effective forensic investigations on Windows XP, Windows Vista, Windows 7, Windows Server 2003, Windows Server 2008, Exchange Server, and SQL server computers.
I'm a network engineer with an excellent understanding of networking and computer concepts and am looking for information on what sort of forensic software will be the best to use whenever I am asked to do an IT forensic investigation.
I work as an IT consultant and am often asked to do these sorts of things and am looking for examples of what programs will be the best to use while doing IT forensic investigation
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Far, far more important than the tools you're using is how you're using them. There are different tools for different purposes and everyone has their favorites, what's important is that you have a process to follow, you document everything, and that you don't tamper evidence. If you have a live system you start with live analysis, if it's down you start by imaging/static analysis. Here are some sites that should get you started:
http://www.forensicswiki.o
http://www.cftt.nist.gov/P
http://www.computerforensi
Some tools worth looking into:
http://www.sleuthkit.org/
http://www.porcupine.org/f
http://www.digitalforensic
http://www.accessdata.com/
BTW Hiren's bootcd is some collection of warezed apps, it has really nothing to do with forensics analysis.
Check also this link with the solution mentioned:
http://www.exper
Business Accounts
Answer for Membership
by: krazyjakeePosted on 2009-10-27 at 14:58:46ID: 25678069
The internet is covered with so called "hackers boot disks" the top one is: http://www.ultimatebootcd. com
They are useful when you have direct access to these systems.