Metasploit Anti-Forensic Investigation Arsenal (MAFIA)

  1. Timestomp – First ever tool that allows you to modify all four NTFS timestamp values: modified, accessed, created, and entry modified.
  2. Slacker – First ever tool that allows you to hide files within the slack space of the NTFS file system.
  3. Sam Juicer – A Meterpreter module that dumps the hashes from the SAM, but does it without ever hitting disk.

These are not new tools, they have been around for a couple of years already and they are still as useful as when they came out. You can download them at Metasploit website, a highly recommended place for all those interested in antiforensics.

Updated link: