Live Forensics Tools

29/12/2020
Chưa phân loại
Computer forensics is the research of  evidence within technological devices such as computers, tablets, cell phones for legal or investigative purposes. Through computer forensics evidence can be recovered even after deletion, physical presence of the investigated suspect or victim can be traced and more. This article focuses on a few of the most popular tools which are listed below.

Computer Forensics Tools

Deft/Deft Zero live forensic tool: is an Ubuntu based Linux distribution oriented to computer forensics and evidence harvesting which allows to block writing permissions on hard disks to prevent their modification in the process of recovering evidence. It is open source and live, so there is no need to install it.  In the main menu you can access disks utilities from which you can see the storage devices connected.
DEFT contains over 1 GB of free and open source software to afford incidents in Microsoft Windows systems. You can get Deft Zero from http://na.mirror.garr.it/mirrors/deft/zero/.

Santoku live forensic tool: Santoku is a Linux distribution which, additionally to security features includes mobile forensics tools such as firmware flashing, ram, media cards and NAND imaging tools, brute forcing Android encryption, analysing Iphone backups and more. It auto detects connected mobile devices. You can run Santoku live also from a virtual machine with VMware or Virtualbox. Santoku is among the best tools for mobile forensics. You can download Santoku Linux at https://santoku-linux.com, from Lubuntu installations you can run the script https://santoku-linux.com/wp-content/uploads/build.sh_.txt to add Santoku features to your current system.

CAINE live forensic tool:  CAINE is  another computer forensics Linux live distro, it is among the most popular tools in computer forensics and includes top level forensics tools such as Autopsy, Dcfldd, dc3dd, Ddrescue, Dvdisaster, Exif, Foremost, FileInfo, FiWalk, Fundl 2.0, FKLook, Fod, Fatback, GCalcTool, Geany, Gparted,gtk-recordmydesktop, Galleta, Gtkhash, Guymager, HDSentinel, Hex Editor (Ghex), HFSutils, Libewf, Lnk-parse,  lnk.sh,  Log2Timeline, liveusb, mork.pl, MC, MD5deep, md5sum, Nautilus Scripts, NBTempo,  ntfs-3g, Offset_Brute_Force, Pasco, Photorec, Read_open_xm, Reglookup, Rifiuti, Rifiuti2, Readpst, Scalpel, SQLJuicer, SFDumper 2.2 , SSDeep, Stegbreak, Smartmontools, Shred and more tools.

You can get CAINE from the official website at https://www.caine-live.net/page5/page5.html.

Volatility forensic tool: Volatility is an interesting tool to analyze and diagnose devices health after the attack was detected, it is widely used for malware and memory forensics. Despite its not a live tool itself, it is already included in all Linux distributions focused on computer forensics listed above. Volatility can be downloaded from its official website at https://www.volatilityfoundation.org/.

The Sleuth Kit forensic tool: The Sleuth Kit is a text mode suite of tools for computer forensics which allows to analyze storage device images to research and recover evidence. Despite its not a live tool itself, it is already included in all Linux distributions focused on computer forensics listed above. It supports plugins allowing you to  add modules. The Sleuth Kit can be integrated with other forensic tools. While it works from the terminal there is an intuitive user friendly graphical interface Autopsy which runs The Sleuth Kit on the background. You can get The Sleuth Kit from its official website at  https://www.sleuthkit.org/sleuthkit/download.php.

Autopsy forensic tool: Autopsy contains a graphical interface for the The Sleuth Kit, allows to carry out analysis and create visually friendly reports on forensic research. It is easy to use and its features include: timeline analysis with graphical event interface, keyword research to find files with relevant terms, web artifacts to extract history, bookmarks, cookies from Firefox, Chrome and Internet Explorer. Autopsy also brings tools for data carving allowing to recover files removed from unallocated space among more. while its not a live tool itself, it is already included in all Linux distributions focused on computer forensics listed above. Autopsy is available for Linux, Mac and Windows. You can download Autopsy from its official website at https://www.autopsy.com/download/.

Conclusion

Computer forensics evolved really fast, what was formerly an impossible task today became an accessible action for regular desktop users. Most tools listed in this article have a user friendly interface making it possible for any user to carry out computer forensic tasks with the same credibility an specialist would do, credibility backed by the open source characteristic of the tools described above. Open source tools can’t be easily rejected by forensic counterpart specialists because they are transparent.

I hope you found this brief article on Live Forensic Tools useful, thank you for reading it.

ONET IDC thành lập vào năm 2012, là công ty chuyên nghiệp tại Việt Nam trong lĩnh vực cung cấp dịch vụ Hosting, VPS, máy chủ vật lý, dịch vụ Firewall Anti DDoS, SSL… Với 10 năm xây dựng và phát triển, ứng dụng nhiều công nghệ hiện đại, ONET IDC đã giúp hàng ngàn khách hàng tin tưởng lựa chọn, mang lại sự ổn định tuyệt đối cho website của khách hàng để thúc đẩy việc kinh doanh đạt được hiệu quả và thành công.
Bài viết liên quan

Docker Image vs Container

Understanding the process Docker uses to store data through images and containers will help you better design your Docker...
28/12/2020

Best 20 Fonts for Ubuntu

In recent years, many business firms including non software development companies are leaning towards Ubuntu which is a...
28/12/2020

Microsoft Office Alternatives for Linux Platform 2017 List

Microsoft Office is no doubt the most widely used office suite in generations to come and this could be attributed to its...
28/12/2020
Bài Viết

Bài Viết Mới Cập Nhật

Dịch Vụ Xây Dựng Hệ Thống Peering Với Internet Exchange (IXP)
04/04/2025

Dịch Vụ Triển Khai VPN Site-to-Site & Remote Access
04/04/2025

Dịch Vụ Thiết Lập Hệ Thống Tường Lửa (Firewall)
04/04/2025

Dịch Vụ Triển Khai Hệ Thống Ảo Hóa & Cloud
04/04/2025

Dịch Vụ Triển Khai Hệ Thống Ceph
04/04/2025