Live Forensics Tools

29/12/2020
Chưa phân loại
Computer forensics is the research of  evidence within technological devices such as computers, tablets, cell phones for legal or investigative purposes. Through computer forensics evidence can be recovered even after deletion, physical presence of the investigated suspect or victim can be traced and more. This article focuses on a few of the most popular tools which are listed below.

Computer Forensics Tools

Deft/Deft Zero live forensic tool: is an Ubuntu based Linux distribution oriented to computer forensics and evidence harvesting which allows to block writing permissions on hard disks to prevent their modification in the process of recovering evidence. It is open source and live, so there is no need to install it.  In the main menu you can access disks utilities from which you can see the storage devices connected.
DEFT contains over 1 GB of free and open source software to afford incidents in Microsoft Windows systems. You can get Deft Zero from http://na.mirror.garr.it/mirrors/deft/zero/.

Santoku live forensic tool: Santoku is a Linux distribution which, additionally to security features includes mobile forensics tools such as firmware flashing, ram, media cards and NAND imaging tools, brute forcing Android encryption, analysing Iphone backups and more. It auto detects connected mobile devices. You can run Santoku live also from a virtual machine with VMware or Virtualbox. Santoku is among the best tools for mobile forensics. You can download Santoku Linux at https://santoku-linux.com, from Lubuntu installations you can run the script https://santoku-linux.com/wp-content/uploads/build.sh_.txt to add Santoku features to your current system.

CAINE live forensic tool:  CAINE is  another computer forensics Linux live distro, it is among the most popular tools in computer forensics and includes top level forensics tools such as Autopsy, Dcfldd, dc3dd, Ddrescue, Dvdisaster, Exif, Foremost, FileInfo, FiWalk, Fundl 2.0, FKLook, Fod, Fatback, GCalcTool, Geany, Gparted,gtk-recordmydesktop, Galleta, Gtkhash, Guymager, HDSentinel, Hex Editor (Ghex), HFSutils, Libewf, Lnk-parse,  lnk.sh,  Log2Timeline, liveusb, mork.pl, MC, MD5deep, md5sum, Nautilus Scripts, NBTempo,  ntfs-3g, Offset_Brute_Force, Pasco, Photorec, Read_open_xm, Reglookup, Rifiuti, Rifiuti2, Readpst, Scalpel, SQLJuicer, SFDumper 2.2 , SSDeep, Stegbreak, Smartmontools, Shred and more tools.

You can get CAINE from the official website at https://www.caine-live.net/page5/page5.html.

Volatility forensic tool: Volatility is an interesting tool to analyze and diagnose devices health after the attack was detected, it is widely used for malware and memory forensics. Despite its not a live tool itself, it is already included in all Linux distributions focused on computer forensics listed above. Volatility can be downloaded from its official website at https://www.volatilityfoundation.org/.

The Sleuth Kit forensic tool: The Sleuth Kit is a text mode suite of tools for computer forensics which allows to analyze storage device images to research and recover evidence. Despite its not a live tool itself, it is already included in all Linux distributions focused on computer forensics listed above. It supports plugins allowing you to  add modules. The Sleuth Kit can be integrated with other forensic tools. While it works from the terminal there is an intuitive user friendly graphical interface Autopsy which runs The Sleuth Kit on the background. You can get The Sleuth Kit from its official website at  https://www.sleuthkit.org/sleuthkit/download.php.

Autopsy forensic tool: Autopsy contains a graphical interface for the The Sleuth Kit, allows to carry out analysis and create visually friendly reports on forensic research. It is easy to use and its features include: timeline analysis with graphical event interface, keyword research to find files with relevant terms, web artifacts to extract history, bookmarks, cookies from Firefox, Chrome and Internet Explorer. Autopsy also brings tools for data carving allowing to recover files removed from unallocated space among more. while its not a live tool itself, it is already included in all Linux distributions focused on computer forensics listed above. Autopsy is available for Linux, Mac and Windows. You can download Autopsy from its official website at https://www.autopsy.com/download/.

Conclusion

Computer forensics evolved really fast, what was formerly an impossible task today became an accessible action for regular desktop users. Most tools listed in this article have a user friendly interface making it possible for any user to carry out computer forensic tasks with the same credibility an specialist would do, credibility backed by the open source characteristic of the tools described above. Open source tools can’t be easily rejected by forensic counterpart specialists because they are transparent.

I hope you found this brief article on Live Forensic Tools useful, thank you for reading it.

ONET IDC thành lập vào năm 2012, là công ty chuyên nghiệp tại Việt Nam trong lĩnh vực cung cấp dịch vụ Hosting, VPS, máy chủ vật lý, dịch vụ Firewall Anti DDoS, SSL… Với 10 năm xây dựng và phát triển, ứng dụng nhiều công nghệ hiện đại, ONET IDC đã giúp hàng ngàn khách hàng tin tưởng lựa chọn, mang lại sự ổn định tuyệt đối cho website của khách hàng để thúc đẩy việc kinh doanh đạt được hiệu quả và thành công.
Bài viết liên quan

Cách sử dụng proxy để tăng tốc độ truy cập internet của bạn.

Trong thế giới của công nghệ thông tin hiện đại, Proxy đã trở thành một công cụ không thể thiếu...
27/02/2023

PostgreSQL vs MySQL 2018

In this article, we compare one of the most popular database management systems (DBMS) in the world, MySQL, with DB-Engines’...
28/12/2020

Best Text Editors for Ubuntu

If you are an application developer and perform all your coding on Ubuntu then this post can be very useful for you. Today...
28/12/2020
Bài Viết

Bài Viết Mới Cập Nhật

Cách gắn set proxy cho điện thoại android, oppo, giả lập android, Ldplayer Bằng Proxydroid
20/09/2023

Mua Proxy Socks5 VN Chơi Game Gia Lập Tăng Cường Trải Nghiệm Chơi Game
22/06/2023

Mua Proxy Mỹ, Us Nuôi Tài Khoản Etsy, eBay Tìm Hiểu Về Mua Proxy Mỹ tại Onet.com.vn
22/06/2023

Mua Proxy Game – Giải pháp tuyệt vời cho việc chơi game trên mạng mà không bị giới hạn về vị trí địa lý
03/06/2023

Sử dụng Proxy để Quản Lý Tài Khoản Quảng Cáo Ads Một Cách An Toàn
27/05/2023