SMART

SMART is the only commercial Linux forensic suite available today. Written by ASRdata and found at http://www.asrdata.com, SMART performs all of the common forensic tasks that the other products, such as EnCase do, but additionally gives you the power of the Linux operating system. When an image is accessed through SMART, it can be mounted as a local file system and browsed and searched with all of the open -source tools available to the investigator .

Implementation

To image a drive in SMART, follow these steps:

  1. Power down the Linux system.

  2. Attach the suspect drive to the Linux system.

  3. Power up the Linux system.

  4. Load SMART.

  5. Choose the device you want to acquire; then right-click it and choose Acquire, as shown here:

  6. In the Acquire window, select the number of copies of the device you want to make and the hashing algorithm you would like to use. As shown next , one copy will be made using the MD5 hashing algorithm.

  7. Click the Image 1 tab and type the name of the image and its description. Now click the area next to Save Data To and choose the directory where this data should be stored, as shown next.

  8. Click Okay and the imaging begins.



Anti-Hacker Tool Kit
Anti-Hacker Tool Kit, Third Edition
ISBN: 0072262877
EAN: 2147483647
Year: 2006
Pages: 175

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net