Steganography
Analyzer Artifact Scanner
Detect
files and registry entries associated with steganography
applications!
StegAlyzerAS
is a steganalysis tool designed to extend the scope of
traditional computer forensic examinations by allowing the
examiner to scan suspect media or forensic images of suspect
media for known artifacts of over 1050steganography
applications.
Artifacts
may be identified by scanning the file system as well as the
registry on a Microsoft Windows system. StegAlyzerAS allows
for identification of files by using CRC-32, MD5, SHA-1,
SHA-224, SHA-256, SHA-384, and SHA-512 hash values stored in
the Steganography Application Fingerprint Database (SAFDB).
SAFDB is the largest commercially available steganography
hash set. Known registry keys are identified by using the
Registry Artifact Key Database (RAKDB). RAKDB is the only
commercially available steganography registry key database.
Product
highlights in StegAlyzerAS:
Versions
available for both 32-bit and 64-bit forensic workstations
Case
generation and management
Mount
and scan forensic images of storage media in EnCase, ISO,
RAW (dd), SMART, SafeBack, Paraben Forensic Replicator, and
Paraben Forensic Storage formats
Automated
scanning of an entire file system, individual directories,
or individual files on suspect media for the presence of
steganography application file artifacts
Automated
scanning of the Microsoft Windows Registry for the presence
of registry artifacts associated with particular
steganography applications
File
and registry artifact evidence viewers allow the examiner to
view evidence according to the percentage of artifacts that
were discovered for each steganography application detected
Scan
summary viewer allows the examiner to quickly view a
statistical summary of any previous scan performed during a
particular examination
Extensive
report generation in HTML format
Automated
logging of key events and information of potential
evidentiary value
Integrated
help feature to explain specific features and functions
BENEFITS
Search
for artifacts associated with over 1050 steganography
applications
Detect
insiders using digital steganography to steal sensitive or
proprietary information
Enforce
organizational policy prohibiting use of digital
steganography or other data-hiding applications
Search
for Microsoft Windows registry artifacts, a feature
exclusive to StegAlyzerAS
Search
for file artifacts using the largest steganography
application hash set commercially available anywhere
Verify
file artifacts with any of seven different hashing
algorithms
|