Computer Forensics and Data Analysis
Software Training Services  
      Search:

What's New

New software and services from The Norcross Group

Now available: Hpa

Hpa is a free program which is useful on forensic boot disks. It will help identify IDE drive parameters including: serial number; manufacturer; number of sectors on the drive; and whether the Host Protected Area (HPA) has been set or not.

Learn more about Hpa

Top

Now available: Imaging Drive under the NT OS

A new program called Ntimage is available. . If the suite is purchased, this program is available at a significant discount. This program will allow you to make a disk image while running under the NT or Windows 2K, XP operating system. It is helpful if you must image a live system, or only have NT as your forensic OS. The program also wipes and calculates hash values of hard drives.

Top

Now available: Performing String searches under the NT OS

A new program called NT_SS is available. This program will allow you to perform string searches of a disk at the sector level while running under the NT or Windows 2K, XP operating system. Because it runs under the NT Operating System, it is extrememly fast.

Top

Now available: Custom Processing Protocols

Our contract clients have been so pleased with our custom Processing Protocols that we decided to make this service available to everyone. On a project where you're working in a tight time frame or attempting something new, let us expedite your work with our complete processing protocol. You get detailed instructions, with sequential procedures and batch files. We tailor the process to your existing software, when possible.
At a very reasonable cost your project is quickly underway. This service can usually be handled entirely by phone and email. You get the protocol, software(only if you need it), and our support throughout the process.

Learn more about Custom Processing Protocols

New: Maresware Updates

The latest...

Other recent updates:

  • Declasfy is available on a bootable CD rom.
  • Hash, and Md5 will also compute the SHA2 of files.
  • Mdir and Diskcat programs will identify encrypted files in the NTFS encrypted file system (EFS).
  • Bates_no has been ported to Linux. (This program adds Bates numbers to filenames for easy identification.)
  • Bates_no provides the option to place the Bates number before the filename or before the filename extension.
  • More free  programs available--all new

Top

Now: Online Ordering &Training Registration

Know what you want already? Then go directly to Order: online

Top

Home  |  Whats New  |  How to Order  |  Training  |  Services  |
About Us  |  FAQs  |  Articles  |  Resources  |  Legal Notices  |  Contact Us  |
Files A-C  |  Files D-F  |  Files G-K  |  Files L-O  |  Files P-S  |  Files T-Z  |
 |  SoftwareData Analysis Software  |  Forensic Processing Software  |  Linux Processing Software  |
Complete helpfile.zip  | Complete pdf_s.zip  | Complete 16 bit software.zip  | Complete 32 bit software.zip  |
 
copyright © 1998-2008 by Mares and Company, LLC