HomeinetContribute to digital forensics with CAINE

Contribute to digital forensics with CAINE

CAINE (Computer Aided INvestigative Environment) is an open source Live USB/DVD based on the GNU/Linux operating system.

It was created by the Italian Giancarlo Giustini as part of a computer forensics project.

The current head of CAINE is Nanni Bassetti.

Contribute to digital forensics with CAINE
Contribute to digital forensics with CAINE

CAINE offers the user a comprehensive graphical environment by integrating existing software to be used as tools in the 4 stages of a forensic investigation.

This specific environment is quite user-friendly and features semi-automatic processes for documenting and drafting reports.

It also features Write Block technology at both the software and hardware levels, thus ensuring that the device to be analyzed has not been changed, resulting in the data that will be extracted being unquestionable.

Main CAIN tools dealing with digital forensics

  • Abiword Text editor.
  • Autopsy is a command-line GUI for the Sleuth Kit digital forensics analysis tool. It can analyze Windows and Unix disks as well as file systems (NTFS, FAT, UFS1/2, Ext2/3).
  • Afflib (Advanced Forensics Format) is an extensible open format for storing disk images and forensic metadata.
  • AtomicParsley Easy-to-use command line for reading, parsing and configuring metadata in MPEG-4 files.
  • Bkhive Tool for extracting the Windows system key used to encrypt user password hash functions.
  • Bulk Extractor Bulk email and URL extraction.
  • Chntpw Mechanism for resetting/setting a user password if they have a valid account in Windows NT/2K/XP/Vista and other operating systems.
  • dos2unix Text file converter from DOS/MAC to UNIX.
  • Ddrescue Data recovery tool even in cases of read errors.
  • Dvdisaster Saves data to CD/DVD/BD so that it is fully recoverable even in cases of read errors.
  • FKLook Script which searches for a keyword in multiple files and saves only those in which the keyword was found in a directory of the user's choice.
  • Fatback Program for recovering files from FAT file systems.
  • Galleta Internet Explorer cookie forensic analysis tool. It analyzes the information contained in a cookie file and exports the results in a way that they can be used in a spreadsheet program. (e.g. Microsoft Excel)
  • HDSentinel Monitors the physical condition and temperature of the hard drive and is responsible for testing, repairing, and predicting its errors. Prevents data loss using automatic and scheduled backups.
  • Rifiuti-Rifiuti2 Recycle Bin forensic analysis tool. It analyzes the information contained in an INFO2 file and exports the results in a way that they can be used in a spreadsheet program. (e.g. Microsoft Excel). Rifiuti2 is an updated version that allows reading non-Latin characters and supports the “$Recycle.Bin” of Vista and Windows 2008 and can also export the results to XML.
  • TheSleuthKit A collection of UNIX command-line based tools that allows for the analysis of a computer.

Source: secnewsgr.kinsta.cloud

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS