Difficulty
Very easy
Steps
2
Time Required
2 minutes
Sections
1
- How to launch Kali Linux Forensics Mode
- 2 steps
Flags
Member-Contributed Guide
An awesome member of our community made this guide. It is not managed by iFixit staff.
BackKali
Full Screen
Options
History
Save to Favorites
Download PDF
Edit
Translate
Get Shareable Link
Embed This Guide
Notify Me of Changes
Stop Notifications
Introduction
The following guide was made with the purpose of educating others on cyber security tools, technologies, and techniques with the intention of educating others on better protecting their own technologies and data. Please use the knowledge gained from this guide responsibly.
This guide will demonstrate how a user can use the integrated ‘Forensic Mode’
Forensic Mode is used by security researchers and pen-testers for the explicit purpose of digital forensics. What is particularly useful about this feature is that it can be booted from a USB device containing a Kali ISO.
Booting into this mode will not mount any system hard drives, that way the operations you preform on the system will not leave any trace.
This guide does require you to have a Bootable USB Drive with Kali Linux written to it. If you don’t already have one, you can follow this guide to create one.
=== ===
What you need
Step 1
Plug in your Live Kali Linux USB
- Plug in your Live Kali Linux USB into your computer and restart your PC.
- Once your machine is finished restarting you should see Kali’s Boot Loader.
Plug in your Live Kali Linux USB into your computer and restart your PC.
Once your machine is finished restarting you should see Kali’s Boot Loader.
1024
Step 2
Choose Live (Forensic mode)
- Choose Live (forensic mode) from the list of options.
- This will take you into the forensics mode, which contains the tools and packages needed to preform system forensic needs.
Choose Live (forensic mode) from the list of options.
This will take you into the forensics mode, which contains the tools and packages needed to preform system forensic needs.
Kali’s Forensics Mode can be used for the following purposes…
Copy data from a systems driveVerify image integrityUse the included forensic tools to examine files that might cause a systems error, or recover data
Official Kali Linux Forensics Mode Page
The most important thing you should take away from this guide, is to remember to use this information responsibly. Obtaining unauthorized access to another’s computer system or systems is illegal under the Computer Fraud & Abuse Act.
Please use the knowledge gained from this guide responsibly.
Cancel: I did not complete this guide.
One other person completed this guide.
Author
with 1 other contributor
Jacob Mehnert
Member since: 10/18/2021
12,621 Reputation
31 Guides authored
Badges:
42
+39 more badges
Team
iFanatics
Member of iFanatics
Community
49 Members
102 Guides authored