Re: Forensics CD (was: Re: Strange Folder

From: Chet Uber (chet.uberat_private)
Date: Mon Oct 07 2002 - 22:32:20 PDT

  • Next message: Ryan McBride: "Re: Forensics CD (was: Re: Strange Folder"

    > REAL good suggestion!  Any specific recommendations as to what should be
    > on the CD?
    >
    > Jim
    >
    > Neil Dickey wrote:
    >
    > > It's a good idea to have a kit of such tools on a read-only
    > > CD in advance of an incident like this, so that you have
    > > tools you know you can trust -- that haven't been trojanned
    > > -- ready to use.  It's rather like the instructions in a
    > > snake-bite kit.  You want to be familiar with them *before*
    > > Mr. Snake has his way with you.
    
    I think you would be very impressed with the SpareMe! Super CD found at
    http://www.securityposture.com, which is based on the WG distribution from
    Fred Cohen and Associates at http://www.all.net. It is specifically designed
    for these tasks and is a mature distribution which includes wireless
    support. We have a version with with the ForensiX toolkit and training CD as
    well.
    
    Regards,
    
    Chet Uber
    
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Tue Oct 08 2002 - 19:50:44 PDT