[Grml] grml and forensics

Michael Prokop mika at grml.org
Tue Jan 31 23:07:13 CET 2006

* Kevin Jones <kevin at kevinrj.net> [20060131 22:55]:

> Hello, I'm in a college computer forensics class. The students are all using
> the nopix helix live cd and most of the tools are gui. Was wondering what
> grml had for forensics, or what some users have done in that area. I'm
> hoping grml on a pendrive so i can install additional packages is a good
> solution.

Well, applications like sleuthkit autopsy, wipe, foremost, md5deep,
sdd, chkrootkit, stegdetect, chntpw,... are available.

Take a look at the package list, available at http://grml.org/files/ ->

Please let me know if you miss any apps you think grml should ship
as well.

> Pendrive problems, I bought the sandisc minicruiser and found they have a
> hidden partition with their launchpad program so you cant boot into grml
> from the drive. Have any users had this problem?

Most computers can boot only from the first partition (which
probably corresponds to the hidden partition on your pendrive) on
external devices. Or did you boot - using another distribution -
with your pendrive already?

> Also, how can I make the grml live cd boot up talking with software speech
> without entering the bootup options?

Either via using a hack like:

Or copy the ISO to harddisk, adjust boot/isolinux/isolinux.cfg, recreate
the ISO using mkisofs and burn the ISO then again.

> With nopix becomming so popular among computer professionals, it's great to
> see grml providing similar capabilities to blind users.

Great you like it. :)

You like grml?  Help us!      http://grml.org/donations/
Already on the grml-user-map? http://www.frappr.com/grmlusers
Grml Solutions                http://solutions.grml.org/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
URL: <http://ml.grml.org/pipermail/grml/attachments/20060131/916172ea/attachment-0003.pgp>

More information about the Grml mailing list