Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 12

CAINE Investigative

environment
• CAINE Linux stands for Computer Aided Investigative Environment.
• It is an Italian Linux live distribution, a digital forensics project that
was started in 2008.
• It uses an old-school desktop environment complemented with top-
notch specialty tools.
https://www.caine-live.net/
CAINE (Computer Aided Investigative
Environment)
• Provides tight security and built-in forensic investigation tools.
• CAINE is built around a complete investigative environment that is
organized to integrate existing software tools as software modules
and to provide a friendly graphical user interface.
• Currently, the project manager of CAINE Linux is Nanni Bassetti (Bari –
Italy).
Objectives
• Its operation environment is designed to provide all the forensic tools
that are required to perform digital forensic investigative processes
like preservation, collection, examination, and analysis.
• It provides a user-friendly graphical user interface with user -friendly
forensic tools.
• It can be booted from the removable media like flash drives or from
an optical disk and run in memory.
• It can be easily installed onto a physical or a virtual system.
• In LIVE mode, CAINE can operate on data storage objects without
having to boot up the operating system.
Supported platforms
• CAINE Linux has several software applications, libraries, and scripts
that can be used in a command-line or graphical environment to
perform forensic activities.
• It can perform data analysis on the data objects created on Microsoft
Windows, Linux, and some Unix Systems.
• One of the interesting features of CAINE Linux version 9.0 is that it
sets all the block devices to read-only mode by default.
Forensic Tools
• CAINE Linux provides a variety of software tools that can be used for
memory, database, network, and forensic analysis.
• The File Image System analysis of File Systems like FAT/ExFAT, NTFS,
Ext2, Ext3, HFS, and ISO 9660 is possible using command-line mode as
well as Graphical user interface mode.
• CAINE Linux support disk imaging in raw(dd) and expert witness/
advanced file format also.
• Disk images may be obtained using the tools that built-in the CAINE or
using third-party tools like EnCase, or Forensic Tool Kit.
List of tools that are included with CAINE
Linux
• Autopsy
• The Sleuth Kit
• Wireshark
• PhotoRec
• Fsstat
• RegRipper
• Tinfoleak (collecting detailed Twitter intelligence analysis)

You might also like