Developer(s) | Rob Lee Harbingers LLC |
---|---|
Initial release | December 13, 2008 |
Repository | github.com/sans-dfir/sift |
Operating system | Ubuntu |
Available in | English |
Type | Computer forensics |
Website | digital-forensics.sans.org |
SIFT is a computer forensics distribution that installs all necessary tools on Ubuntu to perform a detailed digital forensic and incident response examination. It is compatible with expert witness format (E01), advanced forensic format (AFF), raw (dd), and memory analysis evidence formats.
The toolkit has the ability to securely examine raw disks, multiple file systems, and evidence formats. It places strict guidelines on how evidence is examined (read-only), verifying that the evidence has not changed.
*Memory Forensics Images
1) Ubuntu LTS 16.04 Base
2) 64-bit base system
3) Auto-DFIR package update and customization.
4) VMware appliance ready to tackle forensics.
5) Cross-compatibility between Windows and Linux.
6) Choice to install stand-alone via (.iso) or use VMware player/Workstation.
Original source: https://en.wikipedia.org/wiki/SIFT (software).
Read more |