Wireshark will be handy to investigate network related incident. Wireshark is a network capture and analyzer tool to see what’s happening in your network. It supports TrueCrypt, PGP, Bitlocker, Safeboot encrypted volumes. Autospy is used by thousands of users worldwide to investigate what actually happened in the computer.Įncrypted Disk Detector can be helpful to check encrypted physical drives. AutopsyĪutopsy is a GUI-based open source digital forensic program to analyze hard drives and smart phones effectively. As such, they all provide the ability to bring back in-depth information about what’s “under the hood” of a system. Whether it’s for an internal human resources case, an investigation into unauthorized access to a server, or if you just want to learn a new skill, these suites and utilities will help you conduct memory forensic analysis, hard drive forensic analysis, forensic image exploration, forensic imaging and mobile forensics. Here are some of the computer forensic investigator tools you would need. Forensic investigations are always challenging as you may gather all the information you could for the evidence and mitigation plan.