Project Cyber Security Forensics
Project Cyber Security Forensics
Project Cyber Security Forensics
Utilities
IECacheView: - IECacheView extracts information from the cache files (index.dat) of Internet
Explorer. The information provided by IECacheView is somewhat similar to IEHistoryView.
However, while the history file (IEHistoryView) stores only one record fro every Web page visit,
the cache file stores multiple records for every Web page, including all images and other files
loaded by the Web page.
IECookiesView: - IECookiesView extracts the content of all cookie files stored by Internet
Explorer.
IE PassView: - IE PassView extracts the Web site passwords stored by Internet Explorer.
MozillaCacheView: - MozillaCacheView extracts the details of all cache files stored by Mozilla
Firefox.
MozillaHistoryView: - MozillaHistoryView extracts the details of all browsing history stored by
Mozilla Firefox. Starting from Mozilla Firefox 3, MozillaHistoryView requires that Firefox 3 will
be installed on the computer that you run it, because it uses the sqlite3.dll library to read the
SQLite history database of Firefox.
MozillaCookiesView: - MozillaCookiesView extracts the content of all cookie files stored by
Mozilla Firefox. Starting from Mozilla Firefox 3, MozillaCookiesView requires that Firefox 3
will be installed on the computer that you run it, because it uses the sqlite3.dll library to read the
SQLite cookies database of Firefox.
PasswordFox: - PasswordFox extracts the Web site passwords stored by Firefox Web browser.
PasswordFox requires that Firefox will be installed on the computer that you run it, because it
uses the decryption library of Firefox to decrypt the passwords.
ChromeCacheView: - ChromeCacheView extracts the details of all cache files stored by Google
Chrome Web browser.
MyLastSearch: - MyLastSearch utility scans the cache and history files of 4 Web browsers (IE,
Firefox, Opera, and Chrome), and locate all search queries made with the most popular search
engines (Google, Yahoo and MSN) and with popular social networking sites (Twitter, Facebook,
MySpace). The search queries are displayed in a table with the following columns: Search Text,
Search Engine, Search Time, Search Type (General, Video, Images), Web Browser, and the
search URL.
LiveContactsView: - Extracts the contacts of Windows Live Messenger stored inside the
contacts.edb file.
This tool works on Internet Exploere, Fire Fox, Opera and Chrome, and it has specific
utilities for each, for search history, cookies, cache.
Hands on Lab : - We will be testing all the utilities on the three browsers, and the windows
operating system.
Task 1: -
Utility Credentials File View