<
>
Intereliant
     Home   Contact us  
  Services     Domain Names     Investments     Travel     Web Links    Table of Contents 
Services
Privacy
 Browser Detection 
 Forensics 
 Spam 

Get free software


Get free software

Forensics

    The wide variety of useful Linux utilities exist for desktop computers can also be used on Linux-based PDAs. These utilities can often be used as a part of the forensics investigation process.

Disk Cloning

    dd, or duplicate disk, is a Unix and Linux utility that allows the user to create a bitstream image of a disk or device. Once the Linux-based PDA is connected to another device and the dd utility is run, the mirror image can be uploaded onto memory cards or even an external desktop workstation connected via a network. Images created by dd are readable by forensics software tools such as EnCase and Forensic Toolkit. Since the device uses a Linux filesystem, the image may also be mounted and examined on a Linux workstation.

Undeleting Files

    foremost is a Linux based program data for recovering deleted files and served as the basis for the more modern Scalpel. The program uses a configuration file to specify headers and footers to search for. Intended to be run on disk images, foremost can search through most any kind of data without worrying about the format.

Free Software

    You can download a Live CD with a bootable fornesics system from e-fense.com which gives you many high-end tools for forensics and data rescue.

    Helix is a customized distribution of Ubuntu Linux. Helix is more than just a bootable live CD. You can still boot into a customized Linux environment that includes customized linux kernels, excellent hardware detection and many applications dedicated to Incident Response and Forensics.

    Helix has been modified very carefully to NOT touch the host computer in any way and it is forensically sound. Helix wil not auto mount swap space, or auto mount any attached devices. Helix also has a special live side for Incident Response and Forensics.

    Helix focuses on Incident Response & Forensics tools. It is meant to be used by individuals who have a sound understanding of Incident Response and Forensic techniques.

    www.e-fense.com