CAINE Linux Distribution Helps Investigators With Forensic Analysis | eWeek

CAINE Linux Distribution Helps Investigators With Forensic Analysis

CAINE Linux
Oct 13, 2014
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More


CAINE Linux Distribution Helps Investigators With Forensic Analysis

1 - CAINE Linux Distribution Helps Investigators With Forensic Analysis

by Sean Michael Kerner


CAINE Can Be Used as a Live System

2 - CAINE Can Be Used as a Live System

For cases where an operating system cannot be installed onto a machine, CAINE can be run as a live system directly for a CD or USB device.


The MATE Linux Desktop Is the Default

3 - The MATE Linux Desktop Is the Default

CAINE 6 uses the MATE desktop environment, providing users with main operating system navigation items along the bottom of the screen.


Memory, Database, Mobile and Network Forensics Tools Are Included

4 - Memory, Database, Mobile and Network Forensics Tools Are Included

Forensic investigations typically involve multiple forms of analysis and data collection. To that end, CAINE 6 includes multiple sets of tools to assist investigators with memory, mobile and network forensics as well as database analysis.


Advertisement

Analyze Memory With the Volatility Memory Forensics Analysis Platform

5 - Analyze Memory With the Volatility Memory Forensics Analysis Platform

The Volatility Memory Forensics Analysis Platform included in CAINE 6 enables users to examine system memory.


Inception Is a Memory Manipulation Tool

6 - Inception Is a Memory Manipulation Tool

Different types of investigations sometime require investigators to be able to manipulate physical memory, which is where the Inception tool comes into play.


Mobile Forensics Tools Include an iOS Backup Analyzer

7 - Mobile Forensics Tools Include an iOS Backup Analyzer

CAINE 6 includes the iP Backup Analyzer 2.0, which is an open-source tool for Apple iOS backup data analysis.


Autopsy Provides Forensic Browsing Capabilities

8 - Autopsy Provides Forensic Browsing Capabilities

Autopsy is a forensic browsing tool to help investigators find out what happened on a given system.


Data Recovery Is a Key Part of Forensic Investigations

9 - Data Recovery Is a Key Part of Forensic Investigations

In many types of forensic investigations, there is a need to recover data. CAINE 6 includes the PhotoRec data recovery utility to help investigators get data back.


Guymager Captures Forensic Images

10 - Guymager Captures Forensic Images

The Guymager application in CAINE 6 enables researchers to grab a data image of a target device or hard drive location.


Network Forensics Is Enabled With Wireshark

11 - Network Forensics Is Enabled With Wireshark

Network analysis is a key part of many forensic investigations. The open-source Wireshark application is a network packet sniffer that can collect packets for protocol analysis.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.