Forensics Tools for Linux
You will quickly discover that while most of the major forensics tools meant to examine Windows machines will work on a Linux disk image, they will provide far less information. For this reason, it may be necessary to examine the image directly. Now, I am not suggesting that you simply start poking around on a live Linux machine. You still need to create a forensic image of the machine and verify that image using an appropriate hashing algorithm. But once you have such an image, you might find that the forensics tools you have used don’t provide much information. At that point, the next step would be to mount that image as if it were a virtual machine.
However, you cannot simply mount an image file as if it were a virtual ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access