If you uncover a break-in, proceed carefully, stay hidden, gather information, and make sure you don’t disturb any evidence. This month we explore some tools and technologies for finding the footprints of thieves.
Topics covered in this issue include BackTrack and Sleuth Kit, Foremost, Scalpel, PhotoRec, the Open Computer Forensics Architecture, openSUSE 11.0, TorK, OpenWrt, DCCP, Totem, recordMyDesktop, BackupPC, soundKonverter, eyeOS and Ulteo, process control, Drupal Camp Toronto, photo stitching, and more.
Modern filesystems make forensic file recovery much more difficult. Tools like Foremost and Scalpel identify data structures and carve files from a hard disk image.