Ask Operating System Expert

Assignment

Instructions: Add additional insight to these opinions or challenge the opinions. Use real world experience to support your views, as appropriate.

1) For my investigative toolkit I would choose CAINE, this is not just a single tool butbut an entire linux OS that integrates many of the software tools in a GUI. This means that you will have a user friendly interface to utilize all of the tools in one place. The second reason is because it is open source, just starting my career and being a student utilizing open source tools is a must.

There are many different features included with this OS, one is the block device in read-only mode which allows the drive to be preserved. Mobile Forensics is a feature that implies what it does with its name, mobile forensics is a different OS so that needs a different software to accomplish. Features are also included to do all different kinds of memory and network forensics.

Another big feature is that CAINE comes with scripts that allow the examination of any files simply without having to manual search through all of the files. Manually searching browser history, registries and deleted files can be done but with these scripts it will automatically search and find useful information.

Another useful feature is that it allows the ability to run on a live system that grabs browser history, passwords, cookies with little to no effort.

All in all, there may be more specialized tools but none that I could see that come in a user friendly way with many of the tools and features that you can get piece meal from a bunch of different software that you can get by just acquiring this OS toolkit.

The downsides that come with this software suite or toolbox is that there is a lack of support and documentation for this toolbox. Which means that any issues that arise with the software will not be fixed and learning the software will have to be done be self teaching.

2) One of the most intriguing parts about computer forensics are the tools used conduct investigations. There are several open source tools, but most are only available to law enforcement. Law enforcement and the companies marketing these forensics products don't want every criminal to know the ins and outs of the tools, so they are less likely to know how to defeat them. These tools may also pose a privacy concern to the everyday citizen, and to quench any outcry, the company only provides them to trusted partners.

Being that I'm not in law enforcement many of these tools I am just now learning about. There may be better choices, but I have no practical experience yet. My choices also are not limiting only open source, so assuming I have access to restricted tools and money is no object.

DEFT Linux Live CD- Provides tools for almost any job. This tool is the Swiss Army knife of tools, because it incorporates almost everything I can think, from bitstream file copy (dc3dd), network analysis (WireShark), supports bit locker drives and includes many cracking tools. If I could only choose one tool to have on me, it would be a live cd like DEFT. Downside is its free for anyone, giving the criminal the ability to try and use the tools to their advantage. The upside is its free for anyone, so anyone can use the tools and learn them at no cost.

COFEE is a free tool to law enforcement that provides over 150 commands and is reportedly was released to allow law enforcement to work on systems using bit-locker. Of note is that the system has to already be running which suggest the encryption key has already been entered, and the tool is not some sort of back door into bit locker.

Still Running- E-fense Live Response allows first responders to quickly copy useful system information including the contents of RAM. The product is a USB that when inserted allows you to select which items you would like copied from an GUI menu. There are many useful items such as the registry, network connections, logged on user and other user accounts, internet history and many more. The disadvantage of this tool is it doesn't seem to do a bitstream copy of the storage device, which would provide much more information. The advantage though is the device is small and works much faster than a copy would which allows it many more use cases, such as parole officers. Cost $675.

Because it was in the syllabus- AccessData FTK is a toolkit that facilitates the collection and analysis of evidence, can help crack passwords, recover deleted data, and build reports. The tool claims to be able to recover passwords to over 100 applications and have a KFF hash library. Customer needs to

These are some of the tools I would choose. In reality I would use what I was provided and trained on. There might be better tools for the job, but they are of not use if they are cost prohibitive or If the investigator isn't trained on the tool adequately to where it will hold up to scrutiny in court.

Number of Pages: 2 Pages.

Operating System, Computer Science

  • Category:- Operating System
  • Reference No.:- M92708013
  • Price:- $30

Priced at Now at $30, Verified Solution

Have any Question?


Related Questions in Operating System

Research types of operating systems that are currently

Research types of operating systems that are currently available and provide a scenario in which the operating system you chose would be appropriate to be used in this situation. Explain why you think the choice you made ...

Question research hex editors available for mac os and

Question : Research hex editors available for Mac OS and Linux. Based on the documentation, how easy would validating these tools be? Select at least two hex editors for each OS, and discuss what you would do to validate ...

Foundation of information technologyresearch types of

Foundation of Information Technology Research types of operating systems that are currently available and provide a scenario in which the operating system you chose would be appropriate to be used in this situation. Expl ...

Assignment -building a multi-threaded web server using c

Assignment - Building a multi-threaded web server using C and p threads, following the model from the lecture. Your program will have one thread acting as a dispatcher thread, listening fornetwork connections with reques ...

Question you are a security administrator responsible for

Question: You are a security administrator responsible for providing secure configuration requirements for new laptop deployments. After reading Module 2 of Certified Secure Computer User v2exercises, apply the configura ...

Question what do you see as the major differences between

Question : What do you see as the major differences between UNIX/Linux and other operating systems, such as Windows and Mac OS X? The response must be typed, single spaced, must be in times new roman font (size 12) and m ...

Question description of lasa in this assignment you will

Question: Description of LASA: In this assignment, you will select a real-world operating system (can be for a PC, server, tablet, handheld, or embedded device). You will introduce the operating system and its components ...

Discussion question this research assignment will give

Discussion Question : This research assignment will give further information on the nature and workings of multi-tasking and multi-processing operating systems. All information reported in this assignment is to be in the ...

Taskyour job in this assignment is to create two virtual

Task Your job in this assignment is to create two Virtual machines each running a different but the latest distribution of Linux e.g. Ubuntu Server and CentOS. Each of these VM's is to offer services to a user base. The ...

State the required answer precisely and then provide proper

State the required answer precisely and then provide proper explanation. It is not enough to provide one- word or one-line answers. Briefly describe the following concepts and indicate how they are related in the context ...

  • 4,153,160 Questions Asked
  • 13,132 Experts
  • 2,558,936 Questions Answered

Ask Experts for help!!

Looking for Assignment Help?

Start excelling in your Courses, Get help with Assignment

Write us your full requirement for evaluation and you will receive response within 20 minutes turnaround time.

Ask Now Help with Problems, Get a Best Answer

Why might a bank avoid the use of interest rate swaps even

Why might a bank avoid the use of interest rate swaps, even when the institution is exposed to significant interest rate

Describe the difference between zero coupon bonds and

Describe the difference between zero coupon bonds and coupon bonds. Under what conditions will a coupon bond sell at a p

Compute the present value of an annuity of 880 per year

Compute the present value of an annuity of $ 880 per year for 16 years, given a discount rate of 6 percent per annum. As

Compute the present value of an 1150 payment made in ten

Compute the present value of an $1,150 payment made in ten years when the discount rate is 12 percent. (Do not round int

Compute the present value of an annuity of 699 per year

Compute the present value of an annuity of $ 699 per year for 19 years, given a discount rate of 6 percent per annum. As