官术网_书友最值得收藏!

Digital evidence and forensics toolkit Linux

Digital Evidence and Forensics Toolkit (DEFT) Linux comes in a full version and a lighter version called DEFT Zero. For forensic purposes, you may wish to download the full version as the Zero version, does not support mobile forensics and password-cracking features.

Like the other distros mentioned in this list, DEFT, as shown in the following screenshot, is also a fully capable live response forensic tool that can be used on the go in situations where shutting down the machine is not possible and also allows for on-the-fly analysis of RAM and the swap file:

When booting from the DEFT Linux DVD, bootable flash, or other media, the user is presented with various options, including the options to install DEFT Linux to the hard disk, or use as a live-response tool or operating system by selecting the DEFT Linux 8 live option, as shown here:

In the previous screenshot, it can be seen that there are several forensic categories in DEFT Linux 8 such as Antimalware, Data Recovery, Hashing, Imaging, Mobile Forensics, and Network Forensics, Password recovery, and Reporting tools. Within each category exist several tools created by various developers, giving the investigator quite a variety from which to choose.

For a full list of the features and packages included in the Digital Evidence Forensic Toolkit (DEFT) Linux OS at the time of this publishing, please visit the following link:

http://www.deftlinux.net/package-list/

主站蜘蛛池模板: 乐昌市| 罗江县| 晋宁县| 玛曲县| 神农架林区| 高密市| 阿鲁科尔沁旗| 伊宁市| 武邑县| 沂水县| 绵竹市| 博白县| 南部县| 嘉义市| 巴马| 金山区| 绥棱县| 茌平县| 永川市| 拜泉县| 瓦房店市| 滦平县| 海南省| 永登县| 潞西市| 南开区| 贺兰县| 巧家县| 诏安县| 襄汾县| 石家庄市| 广安市| 利辛县| 黔南| 江华| 湟源县| 巴林右旗| 德惠市| 武定县| 新闻| 英德市|