With the help of this specialized utility forensic analysts can collect, preserve and process digital evidence from various sources like computers or smartphones.
SIFT Workstation
SIFT Workstation is a Windows program for working with digital forensic evidence. There are tools for copying personal information from any device or cloud service. Collected data can be used for investigating cybercrimes, malware attacks, network breaches, fraud, espionage, terrorism and other felonies.
Data collection
SIFt stands for SANS Investigative Forensic Toolkit. It is an operating system that comes preinstalled with hundreds of investigation devices for performing detailed and comprehensive examinations of digital evidence. The software supports a variety of forensic scenarios and workflows. You can analyze hard drives, memory modules, network devices, cryptographic hashes and other elements.
It is possible to install SIFT Workstation on a physical computer as well as run the OS as a virtual machine via VMware or VirtualBox. Please note that an account on the official website is necessary to download the application.
Advanced instruments
There is a framework for scanning memory dumps from various operating systems and extracting personal information such as processes, network connections, registry entries, passwords and other data. The integrated Wireshark protocol analyzer is capable of capturing and inspecting all web traffic.
Features
- free to download and use;
- contains instruments for collecting and analyzing digital forensic evidence;
- can be run on a physical device or as a virtual machine;
- it is possible to extract personal information from memory dumps;
- compatible with all modern versions of Windows.