RIP (Remote Information Probe)
Sometimes you need to examine the state of a remote system to determine if you need to investigate it further. In many cases, you need to check what ports are open, what processes are running and you don't want to load an agent on the system to examine it. That is where RIP (remote information probe) comes in. With RIP, you can remotely examine a system that you have administrative privileges over and receive all the information available from Sys Internals directly from your location. And best of all, RIP is free!
ZeroView
"Ever worry that the system you are seizing uses whole disk encryption? Use ZeroViewTM freeware to find out." Burn ZeroView to a CD then pop it into the CD drive of the suspect machine and it will load into memory only and display the contents of Sector 0 allowing you to determine if whole disk encryption is employed on the suspect system. Once you know, then you can take the appropriate steps to capture and preserve the data you need.
ProDiscover Basic Edition
ProDiscover Basic is a complete GUI based computer forensic software package. It includes the ability to image, preserve, analyze and report on evidence found on a computer disk drive. It is freeware and may be used and shared without charge. Support is available only through the On-line Community Forum in the Online ProDiscover Community Forum. For information of training, please contact us by email at sales@techpathways.com.
ProDiscover Basic is a member of the ProDiscover family of Computer forensic software. If you need additional features, such as registry viewer, event log viewer, internet history viewer, or access to the Host Protected Area (HPA) of a disk, you may wish to consider purchasing ProDiscover for Windows. To see other features available from the ProDiscover family of computer forensic, please review the ProDiscover Family Guide in the Software Section of this web site.