PTK DFLabs
Follow DFLabs on twitter Follow DFLabs on YouTube

border_sx   Italian  Russian border_dx

PTK section:

New Articles rss

  • 2010-07-21 - Robust Process Scanner in PTK Forensics: done!

  • 2010-06-01 - Meet the PTK team at The Sleuth Kit and Open Source Digital Forensics Conference

  • 2010-05-14 - SANS Investigative Forensic Toolkit e PTK Forensics: made simple!

  • 2010-04-26 - DFLabs PTK Forensics new version is available Thru SANS Institute's SIFT Virtual Machine

  • 2010-04-24 - New PTK and IncMan suite Video Available for your demo purposes.

  • 2010-02-20 - New DFLabs YoutTube Channel.

  • 2010-02-04 - PTK Forensics: New Webinar session.

  • 2010-02-01 - PTK Forensics, the new website is online.

  • 2009-11-14 17:31:11 - New PTK roadmap

  • 2009-09-30 14:10:01 - DFLabs is proud to announce that the data carving is available

Validator:

Keyword Search

 

The keywords search section offers primarily two features:


  • Indexed Search: consists of a thorough search among keywords obtained from indexing operations.
  • Live Search: runs a direct search on the evidence.


The keywords search section supports the use of regular expressions and offers the possibility to save the most used regexp on a file.


The results are bookmarked for subsequent analysis.


Keaywords search is supported by two tools:

 

  • Live Search: dls + srch_strings + grep
  • Information gathered from Live Search: ifind + istat + grep

 

 



  main search host

 

 

main search host

 

 

KEYWORDS SEARCH – DFTT TEST


TEST

PASSED

Extended Partition Test

x

FAT Keywords search

x

NTFS Keywords search

x

EXT3FS Keywords search

x

FAT Daylight saving test

x

FAT Undeleted test

x

NTFS Undeleted test

x

JPEG Search test

x