<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; law enforcement</title>
	<atom:link href="http://www.ghacks.net/tag/law-enforcement/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 23:31:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Evidence Collector</title>
		<link>http://www.ghacks.net/2008/06/05/evidence-collector/</link>
		<comments>http://www.ghacks.net/2008/06/05/evidence-collector/#comments</comments>
		<pubDate>Thu, 05 Jun 2008 07:56:22 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[computer analysis]]></category>
		<category><![CDATA[evidence collector]]></category>
		<category><![CDATA[forensic software]]></category>
		<category><![CDATA[law enforcement]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=4869</guid>
		<description><![CDATA[Have you ever asked yourself what law enforcement agencies would find when analysing your computer ? How their tools would look like and what they would be checking ? If you answered the questions with yes you might want to try out Evidence Collector (via Techtrends) which is a forensic computer program. Evidence Collectors main [...]]]></description>
			<content:encoded><![CDATA[<p>Have you ever asked yourself what law enforcement agencies would find when analysing your computer ? How their tools would look like and what they would be checking ? If you answered the questions with yes you might want to try out <a href="http://www.security-database.com/evidence.php">Evidence Collector</a> (via <a href="http://jayaprakashkv.blogspot.com/2008/06/evidence-collector-free-forensics.html">Techtrends</a>) which is a forensic computer program. Evidence Collectors main purpose is to help with IT incidents but it can give a solid impression on how such tools work generally.</p>
<p>It&#8217;s a standalone tool which means it can be run from external devices connected to the computer which is definitely a prerequisite for all forensic tools. It analyses the user level at startup and displays information like the local IP and hostname. A click on Start Collecting processes 14 sequences, some with subsequences, that collect data and write that data into logfiles in the Evidence Collector directory.</p>
<p>The software did write 25 different log files into the log directory including a list of opened files, installed applications and processes. Evidence Collector concentrates on hardware and software only while law enforcement agencies would definitely scan the computer for files as well, probably using a software like Locate to find information in filenames and contents.</p>
<p><span id="more-4869"></span><img src="http://www.ghacks.net/wp-content/uploads/2008/06/evidence_collector.gif" alt="evidence collector" title="evidence collector" width="150" height="165" class="alignnone size-medium wp-image-4870" /></p>
<p>A detailed list of what is analysed:</p>
<ul>
<li>Shares and policies applied on shares</li>
<li>Started and stopped services</li>
<li>Installed software</li>
<li>Installed Hotfixes</li>
<li>Enumerated Processes</li>
<li>Events logs</li>
<li>TCP / UDP mapping endpoints</li>
<li>Process handles tracking</li>
<li>List start-up programs</li>
<li>Suspected modules</li>
<li>Users policies</li>
<li>USB history</li>
</ul>
<p>Evidence Collector is a free software currently in beta. There is no information on the homepage about compatibility, it runs fine on my Windows XP Service Pack 3 system.</p>

	Tags: <a href="http://www.ghacks.net/tag/computer-analysis/" title="computer analysis" rel="tag">computer analysis</a>, <a href="http://www.ghacks.net/tag/evidence-collector/" title="evidence collector" rel="tag">evidence collector</a>, <a href="http://www.ghacks.net/tag/forensic-software/" title="forensic software" rel="tag">forensic software</a>, <a href="http://www.ghacks.net/tag/law-enforcement/" title="law enforcement" rel="tag">law enforcement</a>, <a href="http://www.ghacks.net/tag/software/" title="software" rel="tag">software</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/11/09/let-the-computer-make-decisions-for-you/" title="Let The Computer Make Decisions For You (November 9, 2008)">Let The Computer Make Decisions For You</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/06/08/zip-repair/" title="Zip Repair (June 8, 2008)">Zip Repair</a> (3)</li>
	<li><a href="http://www.ghacks.net/2007/04/09/zip-file-recovery-with-object-fix-zip/" title="Zip File Recovery with Object Fix Zip (April 9, 2007)">Zip File Recovery with Object Fix Zip</a> (6)</li>
	<li><a href="http://www.ghacks.net/2008/07/15/zen-key-an-all-purpose-application-manager/" title="Zen Key An All Purpose Application Manager (July 15, 2008)">Zen Key An All Purpose Application Manager</a> (3)</li>
	<li><a href="http://www.ghacks.net/2008/05/13/youtube-batch-downloader/" title="Youtube Batch Downloader (May 13, 2008)">Youtube Batch Downloader</a> (13)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/06/05/evidence-collector/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
