The Best Computer Forensics Tools | Explained

Process Explorer : Process Explorer keep an eye on the processes running on your computer. The display is split into two parts. The top part lists all the processes currently active on your computer and tells you who owns each one. The bottom part changes depending on what mode you’re in. If you’re in handle mode, you’ll see all the handles that the selected process in the top window has opened. If you’re in DLL mode, you’ll see all the DLLs and memory-mapped files that the process has loaded. Additionally, Process Explorer has a search function that allows you to quickly find out which processes have particular handles or DLLs loaded.

Link : https://filehippo.com/download_process-explorer/

Autoruns: Autoruns shows you what programs are configured to run during system bootup or login, and shows you the entries in the order Windows processes them. These programs include ones in your startup folder, Run, RunOnce, and other Registry keys.

Link : https://filehippo.com/download_autoruns/

Irfan View : IrfanView is a very fast and small Freeware (for non-commercial use) graphic viewer for Windows.

Link : https://www.irfanview.com/

Fport: Shows which applications are using which open ports for communication. It gives you the same information as the ‘netstat -an’ command, but with additional details like the process ID, name and path. It’s helpful for figuring out which programs are using unknown open ports."

Adapterwatch : AdapterWatch displays useful information about your network adapters: IP addresses, Hardware address, WINS servers, DNS servers, MTU value, Number of bytes received or sent, The current transfer speed, and more. In addition, it displays general TCP/IP/UDP/ICMP statistics for your local computer.

Link : http://www.nirsoft.net/utils/awatch.html

Visual TimeAnalyzer: Visual TimeAnalyzer automatically tracks all computer usage and presents detailed, richly illustrated reports.

Link https://www.neuber.com/timeanalyzer/download.html

SIW: SIW is an advanced System Information for Windows tool that analyzes your computer and gathers detailed information about system properties and settings and displays it in an extremely comprehensible manner.

Link : https://www.gtopala.com/siw/siw-trial.php

Happy learning!

6 Likes