Artifact Analysis  Registry/Event Analysis  NTFS Analysis  Network Utilities  PE Utilities  Miscellaneous



Artifact Analysis  (top)

   Windows Prefetch Parser (pf)
32-bit Version 64-bit Version
Windows:pf32.v.1.08.win.zippf64.v.1.08.win.zipmd5/sha1
Linux:pf32.v.1.08.lin.tar.gz*pf64.v.1.08.lin.tar.gzmd5/sha1
Mac OS X:pf.v.1.08.osx.tar.gzpf.v.1.08.osx.tar.gzmd5/sha1
   Windows 'index.dat' Parser (id)
32-bit Version 64-bit Version
Windows:id32.v.0.67.win.zipid64.v.0.67.win.zipmd5/sha1
Linux:id32.v.0.67.lin.tar.gz*id64.v.0.67.lin.tar.gzmd5/sha1
Mac OS X:id.v.0.67.osx.tar.gzid.v.0.67.osx.tar.gzmd5/sha1
   Windows LNK Parsing Utility (lp)
32-bit Version 64-bit Version
Windows:lp32.v.0.69.win.ziplp64.v.0.69.win.zipmd5/sha1
Linux:lp32.v.0.69.lin.tar.gz*lp64.v.0.69.lin.tar.gzmd5/sha1
Mac OS X:lp.v.0.69.osx.tar.gzlp.v.0.69.osx.tar.gzmd5/sha1
   Windows USB Storage Parser (usp)
32-bit Version 64-bit Version
Windows:usp32.v.0.33.win.zipusp64.v.0.33.win.zipmd5/sha1
Linux:usp32.v.0.33.lin.tar.gz*usp64.v.0.33.lin.tar.gzmd5/sha1
Mac OS X:usp.v.0.33.osx.tar.gzusp.v.0.33.osx.tar.gzmd5/sha1
   Windows Jump List Parser (jmp)
32-bit Version 64-bit Version
Windows:jmp32.v.0.32.win.zipjmp64.v.0.32.win.zipmd5/sha1
Linux:jmp32.v.0.32.lin.tar.gz*jmp64.v.0.32.lin.tar.gzmd5/sha1
Mac OS X:jmp.v.0.32.osx.tar.gzjmp.v.0.32.osx.tar.gzmd5/sha1
   Windows Shim Database (SDB) Parser (shims)
32-bit Version 64-bit Version
Windows:shims32.v.0.10.win.zipshims64.v.0.10.win.zipmd5/sha1
Linux:shims32.v.0.10.lin.tar.gz*shims64.v.0.10.lin.tar.gzmd5/sha1
Mac OS X:shims.v.0.10.osx.tar.gzmd5/sha1


Registry and Event Log Analysis  (top)

   Yet Another Registry Utility (yaru)
32-bit Version 64-bit Version
Windows:yaru32.v.1.41.win.zipyaru64.v.1.41.win.zipmd5/sha1
Linux:yaru32.v.1.41.lin.tar.gz*yaru64.v.1.41.lin.tar.gzmd5/sha1
Mac OS X:Not Availableyaru.v.1.41.osx.tar.gzmd5/sha1
   Windows Event Log Viewer (evtx_view)
32-bit Version 64-bit Version
Windows:evtx_view32.v.0.83.win.zipevtx_view64.v.0.83.win.zipmd5/sha1
Linux:evtx_view32.v.0.83.lin.tar.gz*evtx_view64.v.0.83.lin.tar.gzmd5/sha1
Mac OS X:Not Availableevtx_view.v.0.83.osx.tar.gzmd5/sha1
   Windows ShellBag Parser (sbag)
32-bit Version 64-bit Version
Windows:sbag32.v.0.41.win.zipsbag64.v.0.41.win.zipmd5/sha1
Linux:sbag32.v.0.41.lin.tar.gz*sbag64.v.0.41.lin.tar.gzmd5/sha1
Mac OS X:sbag.v.0.41.osx.tar.gzsbag.v.0.41.osx.tar.gzmd5/sha1
   Computer Account Forensic Artifact Extractor (cafae)
32-bit Version 64-bit Version
Windows:cafae32.v.0.28.win.zip cafae64.v.0.28.win.zipmd5/sha1
Linux:cafae32.v.0.28.lin.tar.gz*cafae64.v.0.28.lin.tar.gzmd5/sha1
Mac OS X:cafae.v.0.28.osx.tar.gzcafae.v.0.28.osx.tar.gzmd5/sha1
   Windows Event Log Parser (evtwalk)
32-bit Version 64-bit Version
Windows:evtwalk32.v.0.23.win.zipevtwalk64.v.0.23.win.zipmd5/sha1
Linux:evtwalk32.v.0.23.lin.tar.gz*evtwalk64.v.0.23.lin.tar.gzmd5/sha1
Mac OS X:evtwalk.v.0.23.osx.tar.gzevtwalk.v.0.23.osx.tar.gzmd5/sha1
   Windows AppCompatibility Cache Utility (wacu)
32-bit Version 64-bit Version
Windows:wacu32.v.0.16win.zipwacu64.v.0.16.win.zipmd5/sha1
Linux:wacu32.v.0.16.lin.tar.gz*wacu64.v.0.16.lin.tar.gzmd5/sha1
Mac OS X:wacu.v.0.16.osx.tar.gzwacu.v.0.16.osx.tar.gzmd5/sha1


NTFS Filesystem Analysis  (top)

   Windows Journal Parser (jp)
32-bit Version 64-bit Version
Windows:jp32.v.1.13.win.zipjp64.v.1.13.win.zipmd5/sha1
Linux:jp32.v.1.13.lin.tar.gz*jp64.v.1.13.lin.tar.gzmd5/sha1
Mac OS X:jp.v.1.13.osx.tar.gzjp.v.1.13.osx.tar.gzmd5/sha1
   NTFS Directory Enumerator (ntfsdir)
32-bit Version 64-bit Version
Windows:ntfsdir32.v.1.13.win.zipntfsdir64.v.1.13.win.zipmd5/sha1
Linux:ntfsdir32.v.1.13.lin.tar.gz*ntfsdir64.v.1.13.lin.tar.gzmd5/sha1
Mac OS X:ntfsdir.v.1.13.osx.tar.gzntfsdir.v.1.13.osx.tar.gzmd5/sha1
   NTFS File Copy Utility (ntfscopy)
32-bit Version 64-bit Version
Windows:ntfscopy32.v.0.81.win.zipntfscopy64.v.0.81.win.zipmd5/sha1
Linux:ntfscopy32.v.0.81.lin.tar.gz*ntfscopy64.v.0.81.lin.tar.gzmd5/sha1
Mac OS X:ntfscopy.v.0.81.osx.tar.gzntfscopy.v.0.81.osx.tar.gzmd5/sha1
   Windows $MFT and NTFS Metadata Extractor Tool (ntfswalk)
32-bit Version 64-bit Version
Windows:ntfswalk32.v.0.57.win.zipntfswalk64.v.0.57.win.zipmd5/sha1
Linux:ntfswalk32.v.0.57.lin.tar.gz*ntfswalk64.v.0.57.lin.tar.gzmd5/sha1
Mac OS X:ntfswalk.v.0.57.osx.tar.gzntfswalk.v.0.57.osx.tar.gzmd5/sha1
   Windows INDX Slack Parser (wisp)
32-bit Version 64-bit Version
Windows:wisp32.v.0.25.win.zipwisp64.v.0.25.win.zipmd5/sha1
Linux:wisp32.v.0.25.lin.tar.gz*wisp64.v.0.25.lin.tar.gzmd5/sha1
Mac OS X:wisp.v.0.25.osx.tar.gzwisp.v.0.25.osx.tar.gzmd5/sha1
   Graphical Engine for NTFS Analysis (gena)
32-bit Version 64-bit Version
Windows:gena32.v.0.25win.zipgena64.v.0.25.win.zipmd5/sha1
Linux:gena32.v.0.25.lin.tar.gz*gena64.v.0.25.lin.tar.gzmd5/sha1
Mac OS X:Not Availablegena.v.0.25.osx.tar.gzmd5/sha1


Network Support Utilities  (top)

   DNS Query Utility (dqu)
32-bit Version 64-bit Version
Windows:dqu32.v.0.24.win.zipdqu64.v.0.24.win.zipmd5/sha1
Linux:dqu32.v.0.24.lin.tar.gz*dqu64.v.0.24.lin.tar.gzmd5/sha1
Mac OS X:dqu.v.0.24.osx.tar.gzdqu.v.0.24.osx.tar.gzmd5/sha1
   Packet Capture ICMP Carver (pic)
32-bit Version 64-bit Version
Windows:pic32.v.0.15.win.zippic64.v.0.15.win.zipmd5/sha1
Linux:pic32.v.0.15.lin.tar.gz*pic64.v.0.15.lin.tar.gzmd5/sha1
Mac OS X:Not AvailableNot Available
   Network Xfer Client/Server Utility (nx)
32-bit Version 64-bit Version
Windows:nx32.v.0.18.win.zipnx64.v.0.18.win.zipmd5/sha1
Linux:nx32.v.0.18.lin.tar.gz*nx64.v.0.18.lin.tar.gzmd5/sha1
Mac OS X:nx.v.0.18.osx.tar.gznx.v.0.18.osx.tar.gzmd5/sha1


Portable Executable Utilities  (top)

   Windows Portable Executable Viewer (pe_view)
32-bit Version 64-bit Version
Windows:pe_view32.v.0.95.win.zippe_view64.v.0.95.win.zipmd5/sha1
Linux:pe_view32.v.0.95.lin.tar.gz*pe_view64.v.0.95.lin.tar.gzmd5/sha1
Mac OS X:Not Availablepe_view.v.0.95.osx.tar.gzmd5/sha1
   Portable Executable Scanner (pescan)
32-bit Version 64-bit Version
Windows:pescan32.v.0.28.win.zippescan64.v.0.28.win.zipmd5/sha1
Linux:pescan32.v.0.28.lin.tar.gz*pescan64.v.0.28.lin.tar.gzmd5/sha1
Mac OS X:pescan.v.0.28.osx.tar.gzpescan.v.0.28.osx.tar.gzmd5/sha1


Miscellaneous Tools  (top)

   Volume Shadow Snapshot Enumerator (vssenum)
32-bit Version 64-bit Version
Windows:vssenum32.v.0.12.win.zipvssenum64.v.0.12.win.zipmd5/sha1
Linux:Not AvailableNot Available
Mac OS X:Not AvailableNot Available
   Windows Symbol Fetch Utility (sf)
32-bit Version 64-bit Version
Windows:sf32.v.0.35.win.zipsf64.v.0.35.win.zipmd5/sha1
Linux:Not AvailableNot Available
Mac OS X:Not AvailableNot Available


Package Builds  (top)

   Mar/Apr 2015 build (package)
32-bit Version 64-bit Version
Windows:2015.04.20.win32.zip2015.04.20.win64.zipmd5/sha1
Linux:Not Available2015.04.20.lin64.zipmd5/sha1
Mac OS X:Not Available2015.04.20.osx.zipmd5/sha1
*32bit apps can run in a 64bit linux distribution if "ia32-libs" (and dependencies) are present.