Talk With an Expert

Pros and Cons of using Linux and Windows Live CDs in Incident Handling and Forensics

Pros and Cons of using Linux and Windows Live CDs in Incident Handling and Forensics (PDF, 6.32MB)Published: 09 Feb, 2007
Created by:
Ricky Smith

This paper describes the examination of the use of five different live CDs in the six-step incident handling process and the subsequent forensic examination of the machines. A brief synopsis of the six step incident handling process to provide the background for the testing conducted. The first part of the examination will be an evaluation of the ability of the live CD to be used for incident response by a first responder. After the first response capability is evaluated, an examination of the capability of the live CDs to carry out the initial forensics imaging will be conducted. The test procedures used on a Windows XP and Linux machines are described including the sets of commands that simulate the first responder actions each operating system. The advantages and disadvantages of using each live CD for incident response and their effect on the forensic process are examined on the basis of the testing.