Results 1 to 7 of 7

Thread: Kali graphical installion in forensic mode

  1. #1
    Join Date
    2018-Aug
    Posts
    4

    Kali graphical installion in forensic mode

    I know there is a Forensic mode live boot, but I need to install Kali Linux to make forensic images of disks and analyze them.

    I would like to know if the graphical installion of Kali Linux is forensic.
    I mean, if there is a swap partition it will not be used, no internal disk will be auto mounted and auto-mounting of removable media will be disabled.

    In case graphical installion of Kali Linux is not forensic, could this feature be configured? How?

  2. #2
    Join Date
    2016-Dec
    Location
    Canada
    Posts
    326
    Quote Originally Posted by gif View Post
    I know there is a Forensic mode live boot, but I need to install Kali Linux to make forensic images of disks and analyze them.

    I would like to know if the graphical installion of Kali Linux is forensic.
    I mean, if there is a swap partition it will not be used, no internal disk will be auto mounted and auto-mounting of removable media will be disabled.

    In case graphical installion of Kali Linux is not forensic, could this feature be configured? How?
    I think i saw somwwhre the usage of forensic mode is via usb, to boot to machine with it. Then examine from there.
    easy to start; hard to finish

  3. #3
    Join Date
    2016-Dec
    Posts
    806
    I can't answer that but an additional hardware tool you might want to buy before doing any imaging is a write blocker. Something like that:
    - https://www.amazon.com/SiForce-Prote...dp/B07BSXGLNY/
    - https://www.amazon.com/Tableau-TK8u-...dp/B00YDEM30O/

  4. #4
    Join Date
    2018-Aug
    Posts
    4
    Quote Originally Posted by Mister_X View Post
    I can't answer that but an additional hardware tool you might want to buy before doing any imaging is a write blocker. Something like that:
    - https://www.amazon.com/SiForce-Prote...dp/B07BSXGLNY/
    - https://www.amazon.com/Tableau-TK8u-...dp/B00YDEM30O/
    Yes, that's an option, but it also can be done with forensic mode. Also, I need to make images of M.2 SSD disks that generally are not supported by write blockers.

  5. #5
    Join Date
    2018-Aug
    Posts
    4
    Quote Originally Posted by bigbiz View Post
    I think i saw somwwhre the usage of forensic mode is via usb, to boot to machine with it. Then examine from there.
    Yes, I know I can do that. But I would like to have a forensic installation, similar to CAINE or DEFT.

  6. #6
    Join Date
    2016-Dec
    Posts
    806
    Tableau has some hardware to handle them:https://www.guidancesoftware.com/tab...ardware/tda7-2

  7. #7
    Join Date
    2018-Aug
    Posts
    4
    Quote Originally Posted by Mister_X View Post
    Tableau has some hardware to handle them:https://www.guidancesoftware.com/tab...ardware/tda7-2
    Thanks for your answer. I know about write blockers and I also have some of them. I'm trying to do a different thing, without hardware write blockers, similar to CAINE or DEFT.

Similar Threads

  1. Forensic Mode Questions
    By DamienCortez in forum General Archive
    Replies: 3
    Last Post: 2017-11-17, 02:43
  2. Replies: 1
    Last Post: 2015-10-21, 02:22
  3. Forensic mode
    By prh514 in forum General Archive
    Replies: 0
    Last Post: 2014-08-02, 22:21
  4. Can't boot into persistent mode live USB only forensic.
    By perception in forum Installing Archive
    Replies: 1
    Last Post: 2013-11-27, 22:51

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •