Welcome to the Steganography Analysis and Research Center
A Backbone Security Center of Excellence
Products > Steganography Analyzer Artifact Scanner (StegAlyzerAS)
StegAlyzerAS
Steganography Analyzer Artifact Scanner
Detect files and registry entries associated with steganography applications!
This seemingly innocuous image looks like an innocent picture of F-22 Raptors. Actually, it contains the text of a 121-page terrorist training manual. Use of specialized steganalysis tools would have detected InPlainView, a steganography application, on the suspects computer—alerting the forensics examiner that hidden information is likely present in carrier files on the storage media being examined.
"Whether I am performing a quick triage or extensive computer forensic examination, StegAlyzerAS rapidly and accurately identifies files and registry keys associated with steganography applications. The bad guys are increasingly using anti-forensic tools, such as digital steganography, to fly under the radar of traditional forensic tools." -- Computer Forensics Professional

BENEFITS
•Search for artifacts of digital steganography applications
•Detect insiders using digital steganography to steal sensitive or proprietary information
•Enforce organizational policy prohibiting use of digital steganography or other data-hiding applications
•Search for Microsoft Windows registry artifacts, a feature exclusive to StegAlyzerAS
•Search for file artifacts using the largest steganography application hash set commercially available anywhere
•Verify file artifacts with any of seven different hashing algorithms
DESCRIPTION:
StegAlyzerAS is a digital forensic analysis tool designed to extend the scope of traditional digital forensic examinations by allowing the examiner to scan suspect media or forensic images of suspect media for known artifacts of over 900 steganography applications.
Artifacts may be identified by scanning the file system as well as the registry on a Microsoft Windows system. StegAlyzerAS allows for identification of files by using CRC-32, MD5, SHA-1, SHA-224, SHA-256, SHA-384, and SHA-512 hash values stored in the Steganography Application Fingerprint Database (SAFDB). SAFDB is the largest commercially available steganography hash set. Known registry keys are identified by using the Registry Artifact Key Database (RAKDB) distributed with StegAlyzerAS.
StegAlyzerAS was found to be effective for identifying file and registry artifacts by the Defense Cyber Crime Institute (DCCI) and the CyberScience Laboratory (CSL).
Product highlights in StegAlyzerSS:
•Versions available for both 32-bit and 64-bit forensic workstations
•Case generation and management
•Mount and scan forensic images of storage media in EnCase, ISO, RAW (dd), SMART, SafeBack, Paraben Forensic Replicator, and Paraben Forensic Storage formats
•Automated scanning of an entire file system, individual directories, or individual files on suspect media for the presence of steganography application file artifacts
•Automated scanning of the Microsoft Windows Registry for the presence of registry artifacts associated with particular steganography applications
•File and registry artifact evidence viewers allow the examiner to view evidence according to the percentage of artifacts that were discovered for each steganography application detected
•Scan summary viewer allows the examiner to quickly view a statistical summary of any previous scan performed during a particular examination
•Extensive report generation in HTML format
•Automated logging of key events and information of potential evidentiary value
•Integrated help feature to explain specific features and functions
StegAlyzerAS is available for a license fee of $995.00. The license includes all product
updates for one year from date of license purchase. License extension agreements available.
Volume license, government, and educational discounts are available. For more information, please call or email us at
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------