defencia/knowledge/usb for live forensics
Acquisition · Live boot · Work in progress

USB for Live Forensics

A USB for live forensics needs the right, tested toolset. Use quality media, prepare it properly, and cover both *nix and Windows environments.

AcquisitionWIP

Build a live-forensics USB

Many programs are worth having on a USB for live forensics. Test what works for you and your environment first. Note there are fewer tools for *nix systems — the landscape skews Windows — but plenty of Linux/Unix servers still exist, so account for them.

Prepare the USB

Make sure the USB is completely erased and of good quality.

Two scenarios