Difference between revisions of "Live CD"

From ForensicsWiki
Jump to: navigation, search
(See Also)
(See Also)
Line 17: Line 17:
== See Also ==
== See Also ==
* [[:Tools:Live CD|Forensics Live CDs]]
* [[:Category:Live CD|Forensics Live CDs]]

Revision as of 09:56, 28 July 2012

Information icon.png

Please help to improve this article by expanding it.
Further information might be found on the discussion page.

A live CD is a CD containing a bootable computer operating system. Live CDs are widely used in computer forensics and incident response.


  • Physical memory of a computer can be imaged by performing cold boot attack without running tools on an untrusted OS;
  • Acquisition over a network connection without running tools on an untrusted OS;
  • No need to reconstruct RAID arrays;
  • etc.


  • Out-of-date software;
  • No simple way to reconfigure Live CD: you cannot easily rebuild foo to support bar (e.g. rebuild Sleuthkit to support AFF).

See Also