Talk With an Expert

Forensic Analysis of TAILs

Forensic Analysis of TAILs (PDF, 2.02MB)Last updated: 24 Jul, 2025
Presented by:
Aaron Sparling
Aaron Sparling

Adversaries leverage the TAILs (The Amnesic Incognito Live System) operating system for conducting criminal activity. This presentation will address forensic imaging and analysis issues and illustrate techniques which can be used to access and analyze the much needed data. TAILs runs within the physical memory (RAM) of the host system, which if imaged and analyzed can provide numerous valuable forensic artifacts. This talk will address issued faced when confronted with systems running TAILs, options for imaging the TAILs instance and methods which can be applied to locate artifacts of interest for forensic analysis.

SANS DFIR Summit 2025