In this chapter, you will learn how to
• Install and configure Forensic Toolkit and EnCase
• Create a case and add the data
• Analyze the data
• Generate the report
We’ve talked about individual analysis tools in a previous chapter. An alternative to creating your own forensic software toolkit is to use a software distribution specifically configured for forensic investigations, or to use a particular forensic software program.
A forensic software distribution combines a collection of programs with a host operating system. Many of these distributions are Linux based, and can be either installed to a hard disk or run “live” from a bootable medium such as a CD-ROM or a universal ...