SANS Investigative Forensic Toolkit Workstation Version 3 is a Virtual Machine i.e. VMWare for Computer Forensics operations. This free download is a standalone ISO installer of SIFT Workstation Version 3.
SANS Investigative Forensic Toolkit Workstation Version 3 Overview
For computer forensics operations this VMWare helps you to perform detailed digital forensics analysis rebuilt on Ubuntu and many advanced tools. This Virtual Machine is capable doing all the forensics operations with ultimate level performance. It can securely examine all the File Systems (DOS, FAT, VFAT, NTFS, HFS, UFS, Ext2/3 etc), Evidence formats, and RAW disks as well. Examine the evidence and also verify the integrity of the evidence. Moreover, it also supports evidence images including Expert Witness E01/L01, RAW, Advanced Forensic Format AFF.
It is continuously updated by a team of forensic experts and incident response. A wide range of tools is added to it for advanced forensics analysis including Timeline Generation Tool, Memory Analysis tools, Autopsy, Image and disk management tools, SluethKit, Wireshark, and many others. For analyzing malicious artifacts you can use the combination of SIFT and REMnux to get the most powerful environment for incident response and digital forensics.
Features of SANS Investigative Forensic Toolkit Workstation Version 3
Some of the features of SIFT3 are:
- Detailed forensic analysis
- Rebuilt on Ubuntu
- Supports all the file systems
- Analyze RAW disk images
- Check for the integrity of the evidence
- Expert Witness Support
- Various forensic tools
- Timeline Generation Tools
- Memory Analysis Tools (Rekall Framework and Volatility)
- Disk Examination Tools
- Automated Forensic Processing Tools
- File System Analysis Tools (SleuthKit)
- Network Analysis Tools (WireShark)
- File Carving Tools
- Different Files Examination Tools
- Memory Analysis Tools and many others
- Continuous Updates
- Compatible with REMnux to provide a more powerful environment
- Many other advanced tools and features
System Requirements for SANS Investigative Forensic Toolkit Workstation Version 3
Before you download and install SANS Investigative Forensic Toolkit Workstation Version 3, make sure that your system meets the given requirements.
- Free Disk Space: Minimum 20 GB of free space required
- Installed Memory: 1 GB of minimum RAM required
- Processor: Multicore Processor with virtualization technology enabled
SIFT V3 Credentials
After installation, you can use the given credentials to log into the Workstation
- Login: sansforensics
- Password: forensics
Use $ sudo su – to elevate privileges to root while mounting images
SANS Investigative Forensic Toolkit Workstation (SIFT) Version 3 Free Download
Click the below link to download SANS Investigative Forensic Toolkit Workstation (SIFT) Version 3 one-click standalone ISO Image file. Visit https://digital-forensics.sans.org/ for more details.