For Mozilla: http://www.nirsoft.net/utils/mzcv.html
For IE: http://www.nirsoft.net/utils/iecookies.html
Saturday, July 9, 2011
Registry
http://www.systemtools.com/download/dumpreg.zip
This tool will just dump the Registry.
http://www.nirsoft.net/utils/usb_devices_view.html
This can show us all the details about the USB key which was plugged in.
USBDeview.exe /stext c:\txt.txt
==================================================
Device Name : USB Network Controller
Description : USB Network Controller
Device Type : Unknown
Connected : No
Safe To Unplug : No
Disabled : No
USB Hub : No
Drive Letter :
Serial Number :
Created Date : 7/9/2011 3:14:34 AM
Last Plug/Unplug Date: 7/9/2011 3:14:34 AM
VendorID : bla bla bla
ProductID : number bla bla bla
Firmware Revision : 1.01
USB Class : 00
USB SubClass : 00
USB Protocol : 00
Hub / Port : Hub 0, Port 1
Computer Name :
Vendor Name :
Product Name :
ParentId Prefix :
Service Name :
Service Description:
Driver Filename :
Device Class :
Device Mfg :
Power :
Driver Description:
Driver Version :
Instance ID : USB\Vid_bla bla bla bla p;0&1
==================================================
This tool will just dump the Registry.
http://www.nirsoft.net/utils/usb_devices_view.html
This can show us all the details about the USB key which was plugged in.
USBDeview.exe /stext c:\txt.txt
==================================================
Device Name : USB Network Controller
Description : USB Network Controller
Device Type : Unknown
Connected : No
Safe To Unplug : No
Disabled : No
USB Hub : No
Drive Letter :
Serial Number :
Created Date : 7/9/2011 3:14:34 AM
Last Plug/Unplug Date: 7/9/2011 3:14:34 AM
VendorID : bla bla bla
ProductID : number bla bla bla
Firmware Revision : 1.01
USB Class : 00
USB SubClass : 00
USB Protocol : 00
Hub / Port : Hub 0, Port 1
Computer Name :
Vendor Name :
Product Name :
ParentId Prefix :
Service Name :
Service Description:
Driver Filename :
Device Class :
Device Mfg :
Power :
Driver Description:
Driver Version :
Instance ID : USB\Vid_bla bla bla bla p;0&1
==================================================
Examining File System
http://www.ntsecurity.nu/toolbox/macmatch/
MACMatch lets you search for files by their last write, last access or creation time without changing any of these times.
macmatch.exe H:\Tools -c 2011-07-09:02.00 2011-07-09:02.15
MACMatch lets you search for files by their last write, last access or creation time without changing any of these times.
macmatch.exe H:\Tools -c 2011-07-09:02.00 2011-07-09:02.15
Examine the File System
http://www.foundstone.com/us/resources/proddesc/forensictoolkit.htm
hfind and sfind can be used to find hidden files and alternate stream files.
http://technet.microsoft.com/en-us/sysinternals/bb897440.aspx
Streams.exe can find alternate data streams.
hfind and sfind can be used to find hidden files and alternate stream files.
http://technet.microsoft.com/en-us/sysinternals/bb897440.aspx
Streams.exe can find alternate data streams.
Sunday, July 3, 2011
Thursday, June 23, 2011
Saturday, June 11, 2011
Subscribe to:
Posts (Atom)





