Release CAINE 11.0, a distribution for uncovering hidden data

Came to light release CAINE 11.0 (Computer Aided INvestigative Environment), a specialized live distribution designed for conducting forensic analysis, searching for hidden and deleted data on disks, and identifying residual information to reconstruct the system breach. The distribution is based on Ubuntu and equipped with a unified graphical interface based on the MATE shell to manage a variety of utilities for examining Unix and Windows systems. Support for loading a live image into RAM is included. The size of the bootable ISO image 4.1 GB (x86_64).

Release CAINE 11.0, a distribution for uncovering hidden data

finalrd are such tools as GtkHash, Air (Automated Image & Restore), SSdeep, HDSentinel (Hard Disk Sentinel), Bulk Extractor, Fiwalk, ByteInvestigator, Autopsy, Foremost, Scalpel, Sleuthkit, Guymager, DC3DD. It is also worth noting the specially developed system within the project WinTaylor for thorough analysis of Windows systems and generating detailed reports on all recorded anomalies. It also includes a selection of auxiliary scripts for the Caja file manager (a fork of Nautilus), enabling a wide range of checks on disk partitions or directories, as well as viewing the list of deleted files and analyzing structured content such as browser history, the Windows registry, and images with EXIF metadata.

Release CAINE 11.0, a distribution for uncovering hidden data

Key innovations:

  • The release is built on the Ubuntu 18.04 package base, supports UEFI Secure Boot, and comes with Linux kernel 5.0;
  • To prevent accidental write operations, all block devices are now mounted by default in read-only mode. A utility called BlockON is provided in the graphical interface to switch to write mode;
  • Boot time has been shortened;
  • Added the ability to load by copying the boot image into RAM;
  • New versions of OSINT, Autopsy 4.13, APFS, BTRFS forensic tool;
  • Added support for NVME SSD;
  • SSH server is disabled by default;
  • Integrated tool scrcpy, for controlling Android devices (screen capture) via USB or TCP/IP;
  • Added X11VNC Server for remote access to CAINE;
  • Added AutoMacTc tool for forensic analysis of macOS-based systems;
  • A new utility has been added Autotimeliner for automatic extraction of user activity information from memory dumps;
  • Added firmware analyzer Firmwalker;
  • A new utility has been added CDQR (Cold Disk Quick Response) for extracting residual data from disk images;
  • Added a set of utilities for Windows.
    Release CAINE 11.0, a distribution for uncovering hidden data

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster