Live Forensics Tools

29/12/2020
Chưa phân loại
Computer forensics is the research of  evidence within technological devices such as computers, tablets, cell phones for legal or investigative purposes. Through computer forensics evidence can be recovered even after deletion, physical presence of the investigated suspect or victim can be traced and more. This article focuses on a few of the most popular tools which are listed below.

Computer Forensics Tools

Deft/Deft Zero live forensic tool: is an Ubuntu based Linux distribution oriented to computer forensics and evidence harvesting which allows to block writing permissions on hard disks to prevent their modification in the process of recovering evidence. It is open source and live, so there is no need to install it.  In the main menu you can access disks utilities from which you can see the storage devices connected.
DEFT contains over 1 GB of free and open source software to afford incidents in Microsoft Windows systems. You can get Deft Zero from http://na.mirror.garr.it/mirrors/deft/zero/.

Santoku live forensic tool: Santoku is a Linux distribution which, additionally to security features includes mobile forensics tools such as firmware flashing, ram, media cards and NAND imaging tools, brute forcing Android encryption, analysing Iphone backups and more. It auto detects connected mobile devices. You can run Santoku live also from a virtual machine with VMware or Virtualbox. Santoku is among the best tools for mobile forensics. You can download Santoku Linux at https://santoku-linux.com, from Lubuntu installations you can run the script https://santoku-linux.com/wp-content/uploads/build.sh_.txt to add Santoku features to your current system.

CAINE live forensic tool:  CAINE is  another computer forensics Linux live distro, it is among the most popular tools in computer forensics and includes top level forensics tools such as Autopsy, Dcfldd, dc3dd, Ddrescue, Dvdisaster, Exif, Foremost, FileInfo, FiWalk, Fundl 2.0, FKLook, Fod, Fatback, GCalcTool, Geany, Gparted,gtk-recordmydesktop, Galleta, Gtkhash, Guymager, HDSentinel, Hex Editor (Ghex), HFSutils, Libewf, Lnk-parse,  lnk.sh,  Log2Timeline, liveusb, mork.pl, MC, MD5deep, md5sum, Nautilus Scripts, NBTempo,  ntfs-3g, Offset_Brute_Force, Pasco, Photorec, Read_open_xm, Reglookup, Rifiuti, Rifiuti2, Readpst, Scalpel, SQLJuicer, SFDumper 2.2 , SSDeep, Stegbreak, Smartmontools, Shred and more tools.

You can get CAINE from the official website at https://www.caine-live.net/page5/page5.html.

Volatility forensic tool: Volatility is an interesting tool to analyze and diagnose devices health after the attack was detected, it is widely used for malware and memory forensics. Despite its not a live tool itself, it is already included in all Linux distributions focused on computer forensics listed above. Volatility can be downloaded from its official website at https://www.volatilityfoundation.org/.

The Sleuth Kit forensic tool: The Sleuth Kit is a text mode suite of tools for computer forensics which allows to analyze storage device images to research and recover evidence. Despite its not a live tool itself, it is already included in all Linux distributions focused on computer forensics listed above. It supports plugins allowing you to  add modules. The Sleuth Kit can be integrated with other forensic tools. While it works from the terminal there is an intuitive user friendly graphical interface Autopsy which runs The Sleuth Kit on the background. You can get The Sleuth Kit from its official website at  https://www.sleuthkit.org/sleuthkit/download.php.

Autopsy forensic tool: Autopsy contains a graphical interface for the The Sleuth Kit, allows to carry out analysis and create visually friendly reports on forensic research. It is easy to use and its features include: timeline analysis with graphical event interface, keyword research to find files with relevant terms, web artifacts to extract history, bookmarks, cookies from Firefox, Chrome and Internet Explorer. Autopsy also brings tools for data carving allowing to recover files removed from unallocated space among more. while its not a live tool itself, it is already included in all Linux distributions focused on computer forensics listed above. Autopsy is available for Linux, Mac and Windows. You can download Autopsy from its official website at https://www.autopsy.com/download/.

Conclusion

Computer forensics evolved really fast, what was formerly an impossible task today became an accessible action for regular desktop users. Most tools listed in this article have a user friendly interface making it possible for any user to carry out computer forensic tasks with the same credibility an specialist would do, credibility backed by the open source characteristic of the tools described above. Open source tools can’t be easily rejected by forensic counterpart specialists because they are transparent.

I hope you found this brief article on Live Forensic Tools useful, thank you for reading it.

ONET IDC thành lập vào năm 2012, là công ty chuyên nghiệp tại Việt Nam trong lĩnh vực cung cấp dịch vụ Hosting, VPS, máy chủ vật lý, dịch vụ Firewall Anti DDoS, SSL… Với 10 năm xây dựng và phát triển, ứng dụng nhiều công nghệ hiện đại, ONET IDC đã giúp hàng ngàn khách hàng tin tưởng lựa chọn, mang lại sự ổn định tuyệt đối cho website của khách hàng để thúc đẩy việc kinh doanh đạt được hiệu quả và thành công.
Bài viết liên quan

How to Install PostgreSQL on Ubuntu Linux: The Easy Way

PostgreSQL is a top ranked open source Relational Database Management System that was created in 1996 originally at the...
28/12/2020

Best Ubuntu Laptops

For many Linux users, installing their favorite Linux distribution is the first thing they do when they purchase a new...
29/12/2020

Build, Distribute & Run Sandboxed apps on Linux with Flatpak

Flatpak is the next generation technology for building and installing desktop applications. It is a system for building,...
28/12/2020
Bài Viết

Bài Viết Mới Cập Nhật

mua Proxy riêng ở đâu, và nó đem lại lợi ích gì cho người sử dụng
22/11/2022

Hướng dẫn sử dụng Proxy Helper Fakeip khi thuê proxy
21/11/2022

PROXY NUÔI TÀI KHOẢN FACEBOOK – KINH NGHIỆM FAKE IP – THUÊ PROXY GIÁ RẺ
14/11/2022

Mua Proxy Nuôi Zalo Giá Rẻ Tại Onet.com.vn
14/11/2022

BẢNG GIÁ MUA PROXY VIỆT NAM và PROXY US Onet.com.vn
14/11/2022