Sorry for the overt title, but I really need your help.
I have been developing an Incident Reponse, Computer Forensics application for the Windows platform.
The tool has been tentatively called “wInvestigate”, however my creativity with names is rather poor, so other suggestions would be welcome.
To better explain the function of the tool, I’ve included the following loose summary:
wInvestigate is a Windows based application specifically designed to help administrators and security consultants assess the condition of a server or workstation prior to shutting it down and obtaining a forensic image of the server (a bit copy, perfect copy using specialized software). wInvestigate is capable of performing the following functions:
-
Offline forensic preview of filesystem content( NTFS and FAT)
-
Imaging (obtain perfect copy) of Physical System Memory
-
Dump the contents of Allocated or Unalloced Files (Regular or Deleted Files)
-
Dump a listing of current processes* and system settings
- Installed rootkits may not be detected.
The goals are simple, stay away for the typical items and terms associated with Computer Forensics and Incident Reponse. These would include, but are not limited to the following:
- Detective motif (pipe, hat, fingerprint, magnifying glass)
Please keep it clean, as the image and icon will be used in a professional setting, however all software will be open source licensed, images selected should be free of copyright restrictions.
So what do I need? I need an image suitable for presentation as a splash image (similar in dimensions to the Blender Splash) and I’ll need a windows icon (.ico). The two can be similar, or not, however make sure you follow the restrictions above.
Now, what will you win? Well I’ll make sure your name and email address, plus the name of your contribution appears in the About box and on the website for the application.
Seems to me the next logical thing would be to show you what the tool looks like…
Obtain a Forensic view of any system disk or Partition
Previewing the File System
Viewing the contents of a File
Snapshot Report of the Live Machine
Obtain a binary copy of Physical Memory (RAM)
Now, for the scheduling…
I think it’s fair to give two weeks for this contest(Deadline June 15, 2005: 09:00PM EST), as I plan on making some modifications and additions to the software over that time. Please post all official entries within this thread, if you have no server space to place the image, please PM me for assistance.
As for judging, I’ve decided to blend (pun intented) two worlds, I will be asking select members of the esteemed computer forensics community to help make the final decision. (Judging will last two weeks June 15 - 30th).
Not exactly sure how to I’m going to put that together, but we’ll make it work.
Lastly, I will notify the winner, and begin adding the new images to the software, I will also post a thread here at Elysiun with the winning image.
Best of luck to everyone, and thank you all in advance, I look forward to congratulating the winner!