Notifications
Clear all

Options for "Live Host forensics" other than using EnCase

3 Posts
3 Users
0 Reactions
1,316 Views
alveylee
(@alveylee)
Active Member
Joined: 13 years ago
Posts: 6
Topic starter   [#15863]

Scenario
A forensics shop that uses EnCase Enterprise is looking for another method of pulling data over the wire in the event EnCase fails. The server must stay online and not experience any disruption in services. The situation could also be resolved by physical access to the server if necessary. Extracting key artifacts would be the initial goal and then possibly imaging the disk would be secondary.

What software tools, hardware, and methods would other digital forensics experts recommend?

Other alternatives thus far include;
1) Using F-Response and then launching EnCase or IEF.
2). Using EnCase Portable

Thanks for any and all recommendations in advance.



   
Quote
jpickens
(@jpickens)
Estimable Member
Joined: 19 years ago
Posts: 130
 

As an alternate to tools, having procedures in place will also be helpful. You can use FTK or FResponse since both have remote agent capability. However, remote access tools like Powershell, SysInternals, Robocopy, PSTools, etc.. could be used as long as you have a SOP in place that outlines how they should be used in a response scenario. It may not be as forensically sound, but you are following an internal method that can be repeatable and documented (which can identify it as an alternate investigation capability).



   
ReplyQuote
binarybod
(@binarybod)
Reputable Member
Joined: 18 years ago
Posts: 272
 

And the venerable 'netcat' too.



   
ReplyQuote
Share: