Free forensic tool used to analyze disk images for potential evidence, extracting deleted files, scanning for malware, finding hidden data, and building a timeline of system activity.
DiskTriage is a free, portable forensic analysis tool used to analyze disk images like those created by FTK Imager or EnCase. It is designed to automatically scan a disk image and extract key evidence to help investigators quickly determine if a disk image contains relevant data for an investigation.
Some of the key features of DiskTriage include:
DiskTriage produces HTML reports detailing its findings like deleted files, installed programs, file timestamps, file hashes, keyword searches, and more. It has an intuitive graphical interface but also supports command line usage for automation.
While it does not replace a full forensic investigation and analysis, DiskTriage aims to streamline and speed up the triage process at the early stages of an investigation. With DiskTriage, examiners can quickly spot disks that warrant deeper analysis and discard those that do not.
Here are some alternatives to DiskTriage:
Suggest an alternative ❐