Australian university students have developed a Linux-based data forensics tool to help police churn through a growing backlog of computer-related criminal investigations. The tool was developed by students from Edith Cowan University's School of Computing and Information Sciences and will help the Western Australian Police Computer Crime Squad process their forensic investigations. Called Simple (for Simple Image Preview Live Environment), the software allows investigators to view and acquire forensic data at the scene of the crime without compromising the integrity of data as it is collected. There are tons of Linux forensics LiveCD distributions available, but what is your favorite?. The link for this article located at ZDNetAsia is no longer available. . Uncover the Linux-centric investigative software that supports law enforcement in evidence gathering while maintaining authenticity.. Linux Forensics Tool, Data Integrity, Forensics Software, LiveCD Tool. . LinuxSecurity.com Team
Stage 1: Network-capable initial analysis products for first responders, such as Guidance's EnCase Enterprise Edition and Technology Pathway's ProDiscover. These two products can acquire drive images remotely in a live environment, and their use eliminates the need for the Stage 2 tools. . • Stage 2: Primary analysis and drive-image acquisition. This stage usually entails obtaining the hard disk of a suspect machine and investigating it in a controlled (not live) environment. AccessData Forensic Toolkit, Encase Forensic Edition and the open-source Sleuth Kit fit this stage. Any one can be used as the primary investigative tool in environments that don't require a network-capable acquisition application. All these products can acquire a full sector-by-sector drive image of any hard disk under investigation; additional sleuthing functionality varies by application. • Stage 3: Fine-grained keyword searches through disk or partition contents, e-mail-specific searches or Internet history analysis. Paraben's NetAnalysis, E-Mail Examiner and Net E-Mail Examiner, and dtSearch's dtSearch excel here. These tools operate on disk images created by any of the applications from Stages 1 or 2. The link for this article located at Marisa Mack is no longer available. . • Stage 2: Primary analysis and drive-image acquisition. This stage usually entails obtaining the . stage, network-capable, initial, analysis, products, first, responders, guidance's, encase. . Joe Shakespeare
Get the latest Linux and open source security news straight to your inbox.