{"id":64,"date":"2012-12-17T17:48:59","date_gmt":"2012-12-17T09:48:59","guid":{"rendered":"http:\/\/blog.esafeinfo.com\/?p=64"},"modified":"2012-12-17T17:57:00","modified_gmt":"2012-12-17T09:57:00","slug":"linux-live-cd-distributions-for-forensics-investigation","status":"publish","type":"post","link":"https:\/\/blog.esafeinfo.com\/?p=64","title":{"rendered":"Linux Live CD Distributions for Forensics Investigation"},"content":{"rendered":"<p>I was preparing a course material for one of my training programs about digital forensics that I thought it should be a good idea to write a post about available bootable Live CDs for use by digital forensic investigators. These Live CDs have a set of forensic tools and can be deployed to a running suspect system or we can boot the suspect system using them. I have listed only well-known Live CDs that are widely used.<\/p>\n<p><a href=\"http:\/\/computer-forensics.sans.org\/community\/downloads\">SIFT<\/a> (SANS Investigative Forensic Toolkit) Workstation is my favorite one. It is created by <a href=\"http:\/\/www.sans.org\/instructors\/rob-lee\">Rob Lee<\/a> at <a href=\"http:\/\/www.sans.org\/\">SANS Institute<\/a> on top of Ubuntu and pre-configured with several digital forensic examination tools. Its current version is 2.14 and it\u2019s available to download at no charge in two different flavors; <a href=\"https:\/\/computer-forensics32.sans.org\/community\/download-sift-kit\/2.1\">VMware Appliance<\/a> and <a href=\"https:\/\/computer-forensics31.sans.org\/community\/download-sift-kit\/2.1\/iso\">Installation DVD<\/a> (.iso file).<\/p>\n<p><a href=\"http:\/\/www.e-fense.com\/helix\">Helix3<\/a> is another famous Linux distribution built on top of Ubuntu that focuses on incident response and computer forensics. It is developed by <a href=\"http:\/\/www.e-fense.com\/\">e-fense<\/a> and. The most recent release of Helix3 is 2009R1 and can be downloaded from e-fense <a href=\"https:\/\/www.e-fense.com\/store\/index.php?_a=viewProd&amp;productId=11\">store<\/a>. In 2009 e-fense announced that Helix3 would no longer be free to download and there is no plan to update the free version. The paid version is called <a href=\"http:\/\/www.e-fense.com\/helix3pro.php\">Helix3 Pro<\/a> and the <a href=\"http:\/\/www.e-fense.com\/news.php\">latest<\/a> version of Helix3 Pro is 2009R3 that was released on December 2009. At this time, e-fense is no longer planning on developing the Helix3 Pro. \u00a0Although the tool is not updated for a long period but it is used widely by the digital forensic practitioners. While it can be used as a bootable live CD, It also provides a collection of\u00a0executables that can be run on live system.<\/p>\n<p><a href=\"http:\/\/www.caine-live.net\/\">CAINE<\/a> (Computer Aided Investigative Environment) is another forensics distro based on Ubuntu and looks like the Helix3 in functionality and environment. CAINE is developed by Tony Brijeski and provides a friendly Windows autorun GUI and a number of analysis tools. The ISO image of current version is available for free download at <a href=\"http:\/\/www.caine-live.net\/Downloads\/caine3.0.iso\">cain3.0<\/a>.<\/p>\n<p><a href=\"http:\/\/www.deftlinux.net\/\">DEFT<\/a> (Digital Evidence &amp; Forensic Toolkit) is based on Linux Kernel 3 and the DART (Digital Advanced Response Toolkit). It is developed and maintained by an Italian team in .iso file format and virtual appliance configure. The current version which is distributed free of charge is 7.2. DEFT includes the best up-to-date forensic specific tools that you may get to work on imaging, processing, and or analyzing cases.<\/p>\n<p><a href=\"http:\/\/www.raptorforensics.com\/\">Raptor<\/a> is another forensics bootable CD from <a href=\"http:\/\/forwarddiscovery.com\/\">Forward Discovery<\/a>. It is based on Ubuntu distro and the latest free version of Raptor is 2.5. It is available for sale as a pre-installed USB device.<\/p>\n<p><a href=\"http:\/\/www.backtrack-linux.org\/\">BackTrack<\/a> is a well-known full fledge penetration testing Linux distro that can be utilized for forensics purposes as well. It\u2019s based on Ubuntu Lucid and you can choose either GNOME or KDE console to download. The Backtrack is forensically sound if it boot up in \u201cStart BackTrack Forensics\u201d mode, so the file systems would not be mounted and swap space would not be used.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I was preparing a course material for one of my training programs about digital forensics that I thought it should be a good idea to write a post about available bootable Live CDs for use by digital forensic investigators. These Live CDs have a set of forensic tools and can be deployed to a running [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-64","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blog.esafeinfo.com\/index.php?rest_route=\/wp\/v2\/posts\/64","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.esafeinfo.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.esafeinfo.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.esafeinfo.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.esafeinfo.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=64"}],"version-history":[{"count":3,"href":"https:\/\/blog.esafeinfo.com\/index.php?rest_route=\/wp\/v2\/posts\/64\/revisions"}],"predecessor-version":[{"id":66,"href":"https:\/\/blog.esafeinfo.com\/index.php?rest_route=\/wp\/v2\/posts\/64\/revisions\/66"}],"wp:attachment":[{"href":"https:\/\/blog.esafeinfo.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=64"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.esafeinfo.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=64"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.esafeinfo.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=64"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}