Digital Evidence and Forensic Toolkit (DEFT)
While performing computer forensics, it is important that the software being used is able to ensure the integrity of file structures. It should also be able to analyze the system being investigated, without any alteration, deletion, or change of data.
DEFT is designed for forensics and is based on Lubuntu, which is itself based on Ubuntu.
DEFT can be downloaded from this link: http://www.deftlinux.net/download/.
Once downloaded, we can burn the image file on CD/DVD media or create a live bootable USB media.
To use DEFT, we need to get an overview about what is included in the OS and we will do that next.
Once we boot the DEFT CD/DVD or USB media, we get the boot screen. Firstly, we need to select the language. Once done, we can choose to either run DEFT live or else we can install DEFT on our system.
In our example, we have chosen to boot DEFT live. We should be presented with the DEFT desktop after the boot process completes.
Now let's understand what...