Skip to main content

linuxsleuthing code project

linuxsleuthing code project


Computers, iPods, Thumbdrives, oh My!

Ive been busy with a major case during which many smaller cases have walked through my door. I began longing for a way for criminal investigators to be able to conduct preview examinations of digital storage devices without having to drop the devices off at the computer lab.

Many of the questions I receive are relatively simple to answer:
  • "Who owns this computer/iPod?"
  • "Does this computer have any illegal images/videos/files?"
  • "Are there any emails/chats between X and Y stored on this device?"
While I understand a preview examination of a digital storage device is not the equivalent of full forensic examination, the plethora of storage devices and the dwindling number of public sector forensic computer examiners begs for an intermediate solution. And, while forensically sound boot-discs exist, e.g., CAINE or the FBIs ImageScan, they do not lend themselves to criminal investigators with little or no computer forensics training (CAINE) and/or they only do one thing well (ImageScan).

My idea is to modify a disc like CAINE to include scripts accessible through a right-click menu that make basic digital storage device examination simpler. Virtually anyone who uses a computer understands the basics of navigating a file system with a file browser, and Nautilus is the file browser of choice in CAINE which utilizes the Gnome desktop. Nautilus has a built-in option for right-click scripts, and youll find five already deployed in CAINE. The CAINE scripts have limitations and appear to have been obtained from g-scripts. When using them in a filtered file list (e.g., searching for documents in Nautilus), the scripts dont always work, nor are the scripts from a root Nautilus window.

My Solution

I created (and continue to create) a series of Nautilus scripts with which to remaster CAINE or add to an installed Linux distro. The problem has been that I do this across five different computer platforms, tweaking things as I go, to the point Im not sure on which computer any particular script resides. Plus, no one else has access to them for use/testing/improvement, at least until I remaster CAINE and release. Therefore I have created a the LinuxSleuthing Google Code Project. Ill be populating the site with the scripts I create and encourage any feedback in the form of requests, bugs, suggestions, or improvement to the code.

The HTCIA Central California Chapter will be conducting training in September in the use of CAINE with many of these scripts, with primary focus on finding and previewing images, basic keyword searching, and iPod ownership identification, so the immediate focus of the scripts posted to the code project will be on these topics.

The scripts will follow the unix principle of "do one thing and do it well." They are not designed to run blind, finding all occurrences of index.dat, for example, and parsing them for histories. It will be up to the user to find the files and apply the parsing script. While this might sound labor intensive, it allows the user to surgically strike at desired data as time allows rather than wait for whole disk searches. That said, this concept may morph as real world trials expose flaws or beg enhancements.

download file now

download
alternative link download

Popular posts from this blog

Mini Militia ReAL DuAL WiELD MOD 3 06 by ARSHAD

Mini Militia ReAL DuAL WiELD MOD 3 06 by ARSHAD Most of my friends and sites visitors request me to create a Dual Wield MOD + Pro pack... I DONE IT......... Features:- � Propack Unlocked � Unlimited Ammo OR Bullets � ReAL DuAL WiELD MOD ( Bugs fixed now its working) � No Reload � One shot Kill ( 4 Bullets per shot ) � Unlimited Boost � Unlimited Bombs � No one can see u in Solo Play Mod Screenshots:- Click below for Download Use Chrome or other default browser for download this mod Dont Use Uc Mini Wait 5 seconds and Skip ad download  file  now

Mini Militia MEGA MOD 3 0 27 by Arshad KMODS

Mini Militia MEGA MOD 3 0 27 by Arshad KMODS New MEGA MOD 3.0.27... � 4X Time To Refill Health :- ?If You Injured by Gun/Bomb Then Your Life Refill/Recharge In 4X. � Die Only By Guns:- ?Bombs Will Not Harm For You. � High Range Of Bullets:- ?All Guns Rage Is Increased. � Sniper Zoom:- ?All Weapons Have 7X Zoom. � Laser Sight:- ?All Weapons Have Laser Sight. � Dual Wield MOD:- ?Now You Can Take Any Weapon As Dual Weapon , Like Taking Rocket Launcher With Sniper Or Double Barrel With A Fire Sprayer Or With Same Weapons (Example :- AK47 With Another AK47) Too. ?Sometimes It Will Freeze The Game While Playing In Quick Play MOD. � Unlimited Flying Power :- ?Unlimited Boost. � Disabled Gravity :- ?You Will Float On Air Like Lunacy. � One Shot Mega MOD:- ?9 Bullets PerShot. � Unlimited Ammo Or Bullets :- ?Your Guns Will Get Unlimited Number Of Bullets. ?Now You Can Switch Weapons And Throw Grenades. ?You Want Freezes Or Crashes In Quick Play Or Online MOD. ?The Zero Ammo In Lan-Wifi MOD Is Al...

Mini Militia IRON MAN MOD

Mini Militia IRON MAN MOD Download Mini Militia IRON MAN MOD Features :- � Pro pack Unlock � Unlimited Boost � Unlimited Bomb � One shot death (4 bullets per shot) � Unlimited Ammo or Bullets � No Reload � No one can see u in Solo Play mod � HD backgrounds � Modded Guns � New Music � You Can see other players life � In multiplayer mod you get Commander in Chiefs Batch � Different IRON MAN suitwith different colors combination � Blue bars are now green � Invisible Avatar ( only work if you chose invisible avatar ) Click below for download Wait 5 seconds and Skip AD Note:-       If any one not find Iron Man Avatars pls read this.. If any one not find do this steps 1) Open Mini Militias this mod 2) Go to Setting 3) Chose Configure (  3rd Option ) 4) Now OFF HI-RES GFX ( 4th Option ) 5) Restart Game 6) Done!!! Enjoy Mini Militia Iron Man MOD!!!!!!! Screenshots?? Share maximum......?????????????? download  file  now