https://github.com/ctfs/write-ups-2015/tree/master/insomni-hack-ctf-2015/forensic/lost-in-memorieshttps://trailofbits.github.io/ctf/forensics/https://github.com/ctfs/write-ups-2015/tree/master/insomni-hack-ctf-2015/forensic/elysium-ropchainForensics
Tools used for solving Forensics challenges
Aircrack-Ng — Crack 802.11 WEP and WPA-PSK keys
Audacity — Analyze sound files (mp3, m4a, whatever)
Bkhive and Samdump2 — Dump SYSTEM and SAM files
CFF Explorer — PE Editor
Creddump — Dump windows credentials
DVCS Ripper — Rips web accessible (distributed) version control systems
Exif Tool — Read, write and edit file metadata
Extundelete — Used for recovering lost data from mountable images
Fibratus — Tool for exploration and tracing of the Windows kernel
Foremost — Extract particular kind of files using headers
Fsck.ext4 — Used to fix corrupt filesystems
Malzilla — Malware hunting tool
NetworkMiner — Network Forensic Analysis Tool
PDF Streams Inflater — Find and extract zlib files compressed in PDF files
ResourcesExtract — Extract various filetypes from exes
Shellbags — Investigate NT_USER.dat files
UsbForensics — Contains many tools for usb forensics
Volatility — To investigate memory dumps