Book Image

Digital Forensics with Kali Linux - Third Edition

By : Shiva V. N. Parasram
Book Image

Digital Forensics with Kali Linux - Third Edition

By: Shiva V. N. Parasram

Overview of this book

Kali Linux is a Linux-based distribution that's widely used for penetration testing and digital forensics. This third edition is updated with real-world examples and detailed labs to help you take your investigation skills to the next level using powerful tools. This new edition will help you explore modern techniques for analysis, extraction, and reporting using advanced tools such as FTK Imager, Hex Editor, and Axiom. You’ll cover the basics and advanced areas of digital forensics within the world of modern forensics while delving into the domain of operating systems. As you advance through the chapters, you'll explore various formats for file storage, including secret hiding places unseen by the end user or even the operating system. You’ll also discover how to install Windows Emulator, Autopsy 4 in Kali, and how to use Nmap and NetDiscover to find device types and hosts on a network, along with creating forensic images of data and maintaining integrity using hashing tools. Finally, you'll cover advanced topics such as autopsies and acquiring investigation data from networks, memory, and operating systems. By the end of this digital forensics book, you'll have gained hands-on experience in implementing all the pillars of digital forensics: acquisition, extraction, analysis, and presentation – all using Kali Linux's cutting-edge tools.
Table of Contents (24 chapters)
1
Part 1: Blue and Purple Teaming Fundamentals
7
Part 2: Digital Forensics and Incident Response Fundamentals and Best Practices
10
Part 3: Kali Linux Digital Forensics and Incident Response Tools
15
Part 4: Automated Digital Forensics and Incident Response Suites
18
Part 5: Network Forensic Analysis Tools

Installing a pre-configured version of Kali Linux in VirtualBox

Kali can also be installed in VirtualBox using a much simpler method by using the pre-configured versions of Kali, built specifically for VirtualBox:

  1. If you haven’t already downloaded the Kali VirtualBox image in Chapter 3, Installing Kali Linux, you can do so at https://kali.download/virtual-images/kali-2022.3/kali-linux-2022.3-vmware-amd64.7z.
  2. You must extract the image with 7Zip, which can be downloaded for Windows at https://www.7-zip.org/a/7z2201-x64.exe.

Once extracted, you should see the same files shown in the following screenshot.

Figure 4.1 – The Downloads folder showing the pre-configured Kali images for VirtualBox

Figure 4.1 – The Downloads folder showing the pre-configured Kali images for VirtualBox

  1. Double-click on the .vbox file, which is 3 KB in size, and it should immediately open within VirtualBox.
Figure 4.2 – VirtualBox Manager

Figure 4.2 – VirtualBox Manager

  1. Click on the Settings icon at the top of the VirtualBox...