All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 2 posts ] 
Author Message
 Post subject: Open Source Forensics.
PostPosted: March 24th, 2014, 6:58 
Offline
User avatar

Joined: December 4th, 2012, 1:35
Posts: 3844
Location: Adelaide, Australia
I was listening to the Cyberjungle and was reminded about the free Open Source The Sleuth kit and Autopsy. I guess you guys in Forensics already know about it, but I know some shops just have some tools and buy products like encase, and may not "get out" enough to see if there is anything else useful...

Quote:
The Sleuth Kit

The Sleuth Kit® (TSK) is a library and collection of command line tools that allow you to investigate disk images. The core functionality of TSK allows you to analyze volume and file system data. The plug-in framework allows you to incorporate additional modules to analyze file contents and build automated systems. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.


Quote:
Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law enforcement, military, and corporate examiners to investigate what happened on a computer.


As always there are some other things peripheral to the pages to check out.


Top
 Profile  
 
 Post subject: Re: Open Source Forensics.
PostPosted: March 24th, 2014, 15:54 
Offline
User avatar

Joined: August 26th, 2012, 19:18
Posts: 293
Location: England
Eeeh nostalgia TSK / Autopsy =)

Other Distro's also worth a look:

Sift http://digital-forensics.sans.org/community/downloads
Deft http://www.deftlinux.net/ site also contains a windows live response Win-UFO
and
Caine http://www.caine-live.net/

Kali more leaning towards pentest but still a useful distro.

Usual DIY'er warnings:
Not forgetting "Forensic" is in compliance with the law, DIY'er sysadmins messing with a "suspect" PC could actually render it inadmissible and themselves liable to prosecution. Always check your country/state laws.

iirc, some parts of the US were pushing for all computer investigators to have PI licensing.

K

_________________
Когда хочется кушать – съешь всё.
Голод не тётка!


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 2 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 6 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group