[sleuthkit-users] Microsoft's USB thumb drive forensic tool
Brought to you by:
carrier
From: DePriest, J. R. <jrd...@gm...> - 2008-04-29 21:07:46
|
On Tue, Apr 29, 2008 at 9:23 PM, Tom Goldsmith <> wrote: > From the last time I saw COFEE, think pretty much "Windows Forensic > Toolchest". Of course, they may have changed it now, but basically there is > no magic voodoo that some sites are alluding to. > > Cheers, > > Tom Goldsmith > I was wondering if they are using any GPL code on it. If Microsoft is actually using WFT, then they are hopefully making Monty McDougal's wallet fat in the process. If it is just a work-a-like clone, then I suppose Monty's out of luck. Although, WFT uses a large number of third party tools with scads of different licenses. Really, I just want to know what's so special about Microsoft's magic USB drive that slinks through a suspects system with no interaction or footprint. -Jason |