CAINE provides software tools that support
database,
memory, forensic and network analysis.
File system image analysis of NTFS, FAT/ExFAT, Ext2, Ext3, HFS and ISO 9660 is possible via command line and through the graphic desktop. Examination of Linux, Microsoft Windows and some Unix platforms is built-in. CAINE can import disk images in raw (dd) and expert witness/advanced file format. These may be obtained from using tools that are included in CAINE or from another platform such as
EnCase or the
Forensic Tool Kit. Some of the tools included with the CAINE Linux distribution include: •
The Sleuth Kit – open source command line tools that support forensic inspection of disk volume and file system analysis. • RegRipper – open source tool, written in Perl, extracts/parses information (keys, values, data) from the Registry database for data analysis. • Tinfoleak – open source tool for collecting detailed Twitter intelligence analysis. •
Wireshark – supports interactive collection of network traffic and non real-time analysis of data packet captures (*.pcap). •
PhotoRec – supports recovery of lost files from hard disk, digital camera and optical media. • Fsstat – displays file system statistical information about an image or storage object. • [TORTURE] not intentional, : Wait- : == References ==