Bootable Linux CD / PXE for the remote acquisition of multiple computers Dennis Cortjens
[email protected] REPORT 5th of July, 2014 Abstract In the field of digital forensics the acquisition of multiple computers in large IT infrastructures have always been a complex and time consuming task. Especially when one doesn't know which computer to investigate and therefore needs to acquire them all. Triage software has increased the efficiency in cases like this. The software gives an indication which computers to acquire, but one still needs to disassemble and acquire storage devices of the specific computers on the crime scene. In this study two concepts of automated remote acquisition of multiple computers are researched and tested on performance. One of the concepts (based on iSCSI) is developed into a proof concept, called the Remote Acquisition Boot Environment (RABE). Although it is not yet feasible for the remote acquisition to succeed the traditional method of acquiring computers, it could make the remote acquisition a time efficient solution in the near future. Acknowledgement I would like to thank the Netherlands Forensic Institute's digital technology team for their hospitality and pleasant and stimulating work environment. I want to extend my gratitude to Zeno Geradts and Ruud Schramp for their trust and support. Contents 1 Introduction 3 1.1 Problem . .3 1.2 Position . .3 1.3 Scope . .3 1.4 Hypothesis . .4 2 Background 4 2.1 Bootable Linux CD . .4 2.2 Preboot eXecution Environment (PXE) . .5 2.3 Network File System (NFS) . .6 2.4 Internet Small Computer System Interface (iSCSI) .