Hi all,
I am currently doing a project named "Live forensics in a linux machine" and for it I wanted some advice as in what toolkits i should use. I was thinking to use 2 toolkits but i am unable to determine which one.
Also i m a bit newbie in linux so would really appreciate if i could now how to use them if they are in command format.
I have read about few commands like netcat, etc. but i dont how do i use them in the suspects machine and get its output on my pd which has the toolkit.
Thanks in advance.
Really need some help on it.
Well, there's a number of distros available. It all depends on your personal tastes.
Linux itself is built with a number of handy tools. Just running netstat can provide a lot of info. Fport (downloaded from http//
For a 'toolkit' there's Helix, or Deft (http//
Do you have to examine the 'live' system?
Any reason why you couldn't use a live boot disc like Paladin or any of the other Linux based live distros that are out there and then conduct the examination on the drive?
Much more forensically sound than running CLI strings on a live system.
Security Onion is a linux distro that has a ton of forensic tools built into it as does Backtrack 5. A combination of those two will get you most of the standard open source tools for forensic analysis. I would recommend building your own operating system based off of one of these distros and add all of your tools that you want in addition to what comes on your base image. Once you have created your own image I would put it on a hard drive and/or use drive depending on what you are planning on doing with it.
Have a look at