Open-Source or Freeware Tools
摘要
This chapter provides the reader with an overview to several forensic tools that are available for free use. The first sections of the chapter provide a listing of special purpose tools that can be useful for interpreting certain artifactsArtifact in a neat manner; this includes prefetchPrefetch data, shellbagsShellbags, and more. The chapter continues with an overview of the tool Registry Explorer which is an open-sourceOpen-source tool for browsing the Windows RegistryWindows Registry hives. The intent of providing this demonstration of tools is to introduce the reader to a toolset so you can start working with forensic products in a structured way.