Thursday December 4, 2008 8:23 AM AEST
Latest Comments
"You've been warned don´t look to UF0´s in NASA computer, don´t try it! The dream of everyone ..."
by UNDERC0VER | Dec 4, 2008 7:45 AM
 
"its gud"
by Mahesh | Dec 3, 2008 5:59 PM
 
"I like this"
by nanwin | Dec 3, 2008 3:05 PM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM

ProDiscover IR v 4.9

  • Email a Friend
  • Print Page
ProDiscover IR v 4.9
Product Info
Product Rating
Features:  5
Ease of Use:  5
Performance:  5
Documentation:  4
Support:  4
Value for Money:  5
Overall Rating:  Overall Rating
 
For: A solid over-the-network computer forensics and incident response tool.
Against: We'd like more extensive documentation to help users exploit the power of the product.
Verdict: If you need an over-the-network forensics tool at an affordable price - and virtually all mid- to large-size organisations do - this is just the ticket. Recommended.
We like ProDiscover IR for its flexibility and simplicity. For example, the notion of using Perl as the basis for ProScript makes sense because many IT professionals already are proficient in Perl. A simple console-to-agent connection also provides simplicity and reduced cost over more complicated over-the-network acquisition schemes.

Of all of the computer forensic products we tested, we found ProDiscover IR to be the easiest to use.

We found in earlier tests and in day-to-day use that this product really exploits ProScript for its true power. We have scripted common requirements, such as periodic remote acquisition and analysis, as well as exotic ones, such as performing vulnerability analysis during a forensic scan. ProScript is remarkably robust and flexible.

ProDiscover IR does a lot more than collect images or parts of images from remote computers. It can collect volatile data, such as open and hidden files, running processes and open ports. It can run ongoing hash comparisons that help spot changes to critical files. Additionally, it can perform full live forensic analysis over the network.

The product is capable of handling most common file systems, including Windows, Linux and Solaris Unix. It accepts DD images and can image RAM memory and, of course, can capture and analyze the Windows registry. In general, this is a powerful incident response and proactive forensics tool.

At US$7,995 for the complete over-the-network product, ProDiscover IR is a good buy. Support is solid, though it is an extra cost option. We never have had a complaint about support in the two years that we have reviewed the product.

Documentation is good, though not as extensive as we would like. For its very high value, ease of use and solid functionality we award ProDiscover IR our Recommended rating.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Biometrics & Forensics Whitepapers