A specialized Linux distribution CAINE 11.0 has been released, designed for forensic analysis and hidden information retrieval. This live build is based on Ubuntu 18.04, supports UEFI Secure Boot, and comes with Linux kernel 5.0.
The distribution allows for the analysis of residual information post-hack on Unix and Windows systems. It includes a wide range of utilities for various tasks. Notably, there is a specialized tool called WinTaylor for analyzing the OS from Redmond.
Other utilities include GtkHash, Air, SSdeep, HDSentinel, Bulk Extractor, Fiwalk, ByteInvestigator, Autopsy, Foremost, Scalpel, Sleuthkit, Guymager, DC3DD, as well as scripts for the Caja file manager that enable checking all components of the filesystem, including disk partitions, the Windows registry, metadata, and deleted files.
The new system defaults to mounting partitions as read-only. Additionally, the distribution has reduced boot time, and the boot image can be copied to RAM. Utilities have been added to extract data from memory dumps and residual information from disk images.
You can download the new version via the link. This distribution will be useful for system administrators, computer forensic experts, judicial experts, and specialists in information security.
Source: linux.org.ru
