官术网_书友最值得收藏!

Digital evidence and forensics toolkit Linux

Digital Evidence and Forensics Toolkit (DEFT) Linux comes in a full version and a lighter version called DEFT Zero. For forensic purposes, you may wish to download the full version as the Zero version, does not support mobile forensics and password-cracking features.

Like the other distros mentioned in this list, DEFT, as shown in the following screenshot, is also a fully capable live response forensic tool that can be used on the go in situations where shutting down the machine is not possible and also allows for on-the-fly analysis of RAM and the swap file:

When booting from the DEFT Linux DVD, bootable flash, or other media, the user is presented with various options, including the options to install DEFT Linux to the hard disk, or use as a live-response tool or operating system by selecting the DEFT Linux 8 live option, as shown here:

In the previous screenshot, it can be seen that there are several forensic categories in DEFT Linux 8 such as Antimalware, Data Recovery, Hashing, Imaging, Mobile Forensics, and Network Forensics, Password recovery, and Reporting tools. Within each category exist several tools created by various developers, giving the investigator quite a variety from which to choose.

For a full list of the features and packages included in the Digital Evidence Forensic Toolkit (DEFT) Linux OS at the time of this publishing, please visit the following link:

http://www.deftlinux.net/package-list/

主站蜘蛛池模板: 海盐县| 同仁县| 慈溪市| 抚顺市| 崇文区| 吴川市| 建昌县| 樟树市| 当雄县| 开原市| 南安市| 石首市| 胶州市| 汉阴县| 定西市| 大港区| 抚州市| 金华市| 教育| 前郭尔| 肥乡县| 精河县| 绩溪县| 滦平县| 交城县| 弥勒县| 曲阜市| 慈溪市| 鲁甸县| 大名县| 新邵县| 兴山县| 霍林郭勒市| 抚松县| 商丘市| 聂拉木县| 河南省| 长岛县| 永靖县| 绿春县| 昂仁县|