Skip to content

SIFT Workstation

SANS collection of free and open-source incident response and forensic tools on Ubuntu.

When I Use It

  • A ready-made Linux analysis environment with Volatility, The Sleuth Kit, log2timeline/Plaso, and many other tools already installed
  • Training and practice, since many SANS and community exercises assume it

Installation

Common Tasks

Task Tools on SIFT
Memory analysis Volatility
File system and disk image analysis The Sleuth Kit (fls, icat, mmls)
Super timelines log2timeline / Plaso
Mounting images read-only ewfmount, mount -o ro,loop
Carving Scalpel, Foremost, bulk_extractor

Reading the Output

Each tool has its own output; see the tool pages in this section. Keep evidence on a separate, read-only mounted volume rather than copying it into the VM's home directory.

Resources