Skip to content

sadiqsonalkar/Forensic

Repository files navigation

Forensic

Some of the way for computer forensic using autospy, wireshark, etc.

Following are the program or report

  1. Analyzing the packet using Wireshark
  2. Capturing and analyzing netwrok packet using Wireshark
  3. Creating a Forensic Image using FTK Imager/Encase Imager
  4. Perform data acquisition using - USB Write Blocker + FTK Imager
  5. Solve the Forensics Case study using Encase Investigator or Autopsy
  6. Using Sysinternals tools for Network Tracking and Process Monitoring:
  • Check Sysinternals tools
  • Monitor Live Processes
  • Capture RAM
  • Capture TCP/UDP packets
  • Monitor Hard Disk
  • Monitor Virtual Memory
  • Monitor Cache Memory