Graphics
SANS_Investigative_Forensic_Toolkit_Workstation_2.0_VMware_Appliance_2011
SANS_Investigative_Forensic_Toolkit_Workstation_2.0_VMware_Appliance_2011 Free & Full Download

Basic Configuration Information
Recommend to increase VMware Options for
* Download VMworkstation, Player, or Fusion
* Memory (Currently 1024K, increase to add more RAM as needed)
* CPUs (Currently 1, increase as needed for more power)
SIFT Login/Password
After downloading the toolkit, use the credentials below to gain access.
* Login "sansforensics"
* Password "forensics"
* $ sudo su -
o Use to elevate privileges to root while mounting disk images.
PTK login
* Login "admin"
* Password "forensics"
Host Machine Connectivity
Enable SHARED FOLDERS
* VM -> SETTINGS -> OPTIONS -> Shared Folders -> Always Enabled (Check)
* Access to Host System Found on Desktop
* VMware-Shared-Drive
Access from a Windows Machine
* Filesystem Shares \\SIFTWORKSTATION
o or use ifconfig and connect to eth0 IP Address listed (e.g. \\192.168.1.12)
o /mnt - Mount point for read-only examination of digital forensic evidence
o /cases - Directory to store evidence
SIFT Workstation Recommended Software Requirements
* VMware Player, Workstation, or Fusion (Free From www.vmware.com)
* SANS SIFT Workstation Capabilities
SIFT Workstation 2.0 Capabilities
Ability to securely examine raw disks, multiple file systems, evidence formats. Places strict guidelines on how evidence is examined (read-only) verifying that the evidence has not changed
File system support
* Windows (MSDOS, FAT, VFAT, NTFS)
* MAC (HFS)
* Solaris (UFS)
* Linux (EXT2/3)
Evidence Image Support
* Expert Witness (E01)
* RAW (dd)
* Advanced Forensic Format (AFF)
Software Includes
* The Sleuth Kit (File system Analysis Tools)
* log2timeline (Timeline Generation Tool)
* ssdeep & md5deep (Hashing Tools)
* Foremost/Scalpel (File Carving)
* WireShark (Network Forensics)
* Vinetto (thumbs.db examination)
* Pasco (IE Web History examination)
* Rifiuti (Recycle Bin examination)
* Volatility Framework (Memory Analysis)
* DFLabs PTK (GUI Front-End for Sleuthkit)
* Autopsy (GUI Front-End for Sleuthkit)
* PyFLAG (GUI Log/Disk Examination)
Key Directories in SANS SIFT Workstation
* /forensics
o Location of the files used for the Autopsy Toolset
* /usr/local/src
o Source files for Autopsy, The Sleuth Kit, and other tools
* /usr/local/bin
o Location of the forensic pre-compiled binaries
* /cases
o Location of your collected evidence
* /mnt/hack
o Location of the mount points for the file system images
Homepage: http://computer-forensics.sans.org/
Download:
http://hotfile.com/dl/89418140/cb9bca2/1.2.SANS_Forensics_Investigation.part1.rar.html
http://hotfile.com/dl/89418204/24a25a0/1.2.SANS_Forensics_Investigation.part2.rar.html
http://hotfile.com/dl/89418287/6cccd85/1.2.SANS_Forensics_Investigation.part3.rar.html
http://hotfile.com/dl/89418364/d0d0720/1.2.SANS_Forensics_Investigation.part4.rar.html
http://hotfile.com/dl/89418487/cbbc014/1.2.SANS_Forensics_Investigation.part5.rar.html
http://hotfile.com/dl/89418523/cf01dc3/1.2.SANS_Forensics_Investigation.part6.rar.html
http://hotfile.com/dl/89418595/286e14a/1.2.SANS_Forensics_Investigation.part7.rar.html
http://hotfile.com/dl/89418745/52784eb/1.2.SANS_Forensics_Investigation.part8.rar.html
Mirror 1:
http://www.fileserve.com/file/nQhAdNp/1.2.SANS_Forensics_Investigation.part1.rar
http://www.fileserve.com/file/SKCZYAb/1.2.SANS_Forensics_Investigation.part2.rar
http://www.fileserve.com/file/D3EhpJK/1.2.SANS_Forensics_Investigation.part3.rar
http://www.fileserve.com/file/HPu6WUz/1.2.SANS_Forensics_Investigation.part4.rar
http://www.fileserve.com/file/HPQZU7B/1.2.SANS_Forensics_Investigation.part5.rar
http://www.fileserve.com/file/Gj5PmBn/1.2.SANS_Forensics_Investigation.part6.rar
http://www.fileserve.com/file/T4X2FMV/1.2.SANS_Forensics_Investigation.part7.rar
http://www.fileserve.com/file/4C8R6JG/1.2.SANS_Forensics_Investigation.part8.rar
Mirror 2:
http://www.filesonic.com/file/42594453/1.2.SANS_Forensics_Investigation.part1.rar
http://www.filesonic.com/file/42594385/1.2.SANS_Forensics_Investigation.part2.rar
http://www.filesonic.com/file/42594509/1.2.SANS_Forensics_Investigation.part3.rar
http://www.filesonic.com/file/42594583/1.2.SANS_Forensics_Investigation.part4.rar
http://www.filesonic.com/file/42594745/1.2.SANS_Forensics_Investigation.part5.rar
http://www.filesonic.com/file/42594823/1.2.SANS_Forensics_Investigation.part6.rar
http://www.filesonic.com/file/42595255/1.2.SANS_Forensics_Investigation.part7.rar
http://www.filesonic.com/file/42594927/1.2.SANS_Forensics_Investigation.part8.rar
Recommend to increase VMware Options for
* Download VMworkstation, Player, or Fusion
* Memory (Currently 1024K, increase to add more RAM as needed)
* CPUs (Currently 1, increase as needed for more power)
SIFT Login/Password
After downloading the toolkit, use the credentials below to gain access.
* Login "sansforensics"
* Password "forensics"
* $ sudo su -
o Use to elevate privileges to root while mounting disk images.
PTK login
* Login "admin"
* Password "forensics"
Host Machine Connectivity
Enable SHARED FOLDERS
* VM -> SETTINGS -> OPTIONS -> Shared Folders -> Always Enabled (Check)
* Access to Host System Found on Desktop
* VMware-Shared-Drive
Access from a Windows Machine
* Filesystem Shares \\SIFTWORKSTATION
o or use ifconfig and connect to eth0 IP Address listed (e.g. \\192.168.1.12)
o /mnt - Mount point for read-only examination of digital forensic evidence
o /cases - Directory to store evidence
SIFT Workstation Recommended Software Requirements
* VMware Player, Workstation, or Fusion (Free From www.vmware.com)
* SANS SIFT Workstation Capabilities
SIFT Workstation 2.0 Capabilities
Ability to securely examine raw disks, multiple file systems, evidence formats. Places strict guidelines on how evidence is examined (read-only) verifying that the evidence has not changed
File system support
* Windows (MSDOS, FAT, VFAT, NTFS)
* MAC (HFS)
* Solaris (UFS)
* Linux (EXT2/3)
Evidence Image Support
* Expert Witness (E01)
* RAW (dd)
* Advanced Forensic Format (AFF)
Software Includes
* The Sleuth Kit (File system Analysis Tools)
* log2timeline (Timeline Generation Tool)
* ssdeep & md5deep (Hashing Tools)
* Foremost/Scalpel (File Carving)
* WireShark (Network Forensics)
* Vinetto (thumbs.db examination)
* Pasco (IE Web History examination)
* Rifiuti (Recycle Bin examination)
* Volatility Framework (Memory Analysis)
* DFLabs PTK (GUI Front-End for Sleuthkit)
* Autopsy (GUI Front-End for Sleuthkit)
* PyFLAG (GUI Log/Disk Examination)
Key Directories in SANS SIFT Workstation
* /forensics
o Location of the files used for the Autopsy Toolset
* /usr/local/src
o Source files for Autopsy, The Sleuth Kit, and other tools
* /usr/local/bin
o Location of the forensic pre-compiled binaries
* /cases
o Location of your collected evidence
* /mnt/hack
o Location of the mount points for the file system images
Homepage: http://computer-forensics.sans.org/
Download:
http://hotfile.com/dl/89418140/cb9bca2/1.2.SANS_Forensics_Investigation.part1.rar.html
http://hotfile.com/dl/89418204/24a25a0/1.2.SANS_Forensics_Investigation.part2.rar.html
http://hotfile.com/dl/89418287/6cccd85/1.2.SANS_Forensics_Investigation.part3.rar.html
http://hotfile.com/dl/89418364/d0d0720/1.2.SANS_Forensics_Investigation.part4.rar.html
http://hotfile.com/dl/89418487/cbbc014/1.2.SANS_Forensics_Investigation.part5.rar.html
http://hotfile.com/dl/89418523/cf01dc3/1.2.SANS_Forensics_Investigation.part6.rar.html
http://hotfile.com/dl/89418595/286e14a/1.2.SANS_Forensics_Investigation.part7.rar.html
http://hotfile.com/dl/89418745/52784eb/1.2.SANS_Forensics_Investigation.part8.rar.html
Mirror 1:
http://www.fileserve.com/file/nQhAdNp/1.2.SANS_Forensics_Investigation.part1.rar
http://www.fileserve.com/file/SKCZYAb/1.2.SANS_Forensics_Investigation.part2.rar
http://www.fileserve.com/file/D3EhpJK/1.2.SANS_Forensics_Investigation.part3.rar
http://www.fileserve.com/file/HPu6WUz/1.2.SANS_Forensics_Investigation.part4.rar
http://www.fileserve.com/file/HPQZU7B/1.2.SANS_Forensics_Investigation.part5.rar
http://www.fileserve.com/file/Gj5PmBn/1.2.SANS_Forensics_Investigation.part6.rar
http://www.fileserve.com/file/T4X2FMV/1.2.SANS_Forensics_Investigation.part7.rar
http://www.fileserve.com/file/4C8R6JG/1.2.SANS_Forensics_Investigation.part8.rar
Mirror 2:
http://www.filesonic.com/file/42594453/1.2.SANS_Forensics_Investigation.part1.rar
http://www.filesonic.com/file/42594385/1.2.SANS_Forensics_Investigation.part2.rar
http://www.filesonic.com/file/42594509/1.2.SANS_Forensics_Investigation.part3.rar
http://www.filesonic.com/file/42594583/1.2.SANS_Forensics_Investigation.part4.rar
http://www.filesonic.com/file/42594745/1.2.SANS_Forensics_Investigation.part5.rar
http://www.filesonic.com/file/42594823/1.2.SANS_Forensics_Investigation.part6.rar
http://www.filesonic.com/file/42595255/1.2.SANS_Forensics_Investigation.part7.rar
http://www.filesonic.com/file/42594927/1.2.SANS_Forensics_Investigation.part8.rar
Download
Share This Post :
Information
Members of Guest cannot leave comments.
